Privacy Policy
Last updated: June 24, 2026What we collect
We collect the information needed to create your account, run Wanderkin, keep the community safer, and help travelers find each other.
- Account details: name, email address or phone number, date of birth, and login information.
- Profile details: pronouns, optional identity tags, bio, photos, interests, languages, and verification status.
- Verification records: Didit session ID, verification result, verification timestamp, and biometric-consent record. The selfie image is processed by Didit and is never stored by Wanderkin.
- Travel details: current city, trip destinations, trip dates, and trip visibility choices.
- App activity: messages, meetup activity, city feed posts, reports, blocks, support requests, and safety actions.
- Technical data: device information, app version, IP address, approximate region, diagnostics, crash logs, and basic analytics events.
Why we collect it
We collect different data for different purposes. We do not collect information just because it might be useful later.
- Name, photos, pronouns, identity tags, bio, and interests help you create a profile and help other travelers understand who they are meeting.
- Date of birth helps us enforce the 18+ requirement.
- Email address or phone number lets you sign in, recover your account, receive important notices, and contact support.
- Selfie verification helps us confirm that members are real people and reduce impersonation, catfishing, and abuse. Wanderkin stores verification metadata on your user record, not the selfie image.
- Current city, trip destinations, and trip dates power destination matching, city feeds, meetups, and local recommendations.
- Device information, IP address, diagnostics, and analytics help us prevent abuse, secure accounts, understand product performance, and fix bugs.
- Push notification tokens, if you enable notifications, let us send messages, report updates, meetup activity, and account notices.
Selfie Verification
Selfie verification is one of the most sensitive things we process, so we treat it with extra care.
Wanderkin is the data controller for selfie verification. That means we decide why and how verification data is collected, and we are responsible for user-facing disclosures, consent, and the legal basis for processing.
Didit is our verification data processor. Didit processes selfie verification data on Wanderkin's behalf and does not decide how or why Wanderkin uses that data.
Didit uses passive liveness detection. Your selfie image is analyzed server-side by Didit's AI models to confirm that a live human is present; you do not need to complete a head-turn, blink, or other active challenge.
Processing happens in Didit's EU-based AWS infrastructure. Data is encrypted in transit using TLS 1.3 and encrypted at rest using AES-256.
Wanderkin does not store, cache, or log the selfie image at any point. The image is captured on-device, transmitted directly to Didit's API, and processed within Didit's infrastructure.
Wanderkin stores only verification metadata on your user record: the Didit session ID, the verification result such as pass or fail, the verification timestamp, and the biometric-consent timestamp and consent-text version.
Your selfie is never shown on your profile, never shown to other users, and never used for matching or recommendations. Verification status may be used to unlock trust-gated features and decide whether your profile can appear in destination matching results.
After Wanderkin receives the verification result, our backend asks Didit to delete the hosted verification session. Didit retention is configured to delete selfie and session data within 30 days maximum if immediate deletion has not already completed.
Wanderkin relies on explicit consent for biometric processing under GDPR Article 9(2)(a), and legitimate interest for community safety under GDPR Article 6(1)(f). You can request access, correction, or deletion of verification data by deleting your account or contacting privacy@usewanderkin.com.
- Didit collects the selfie image and facial biometric data for liveness detection, to confirm that a real human is present and not a photo, video, mask, or deepfake.
- Didit collects device metadata such as IP address and user agent for fraud signals and abuse prevention.
- Didit returns a liveness result, such as pass or fail, to Wanderkin through the verification flow or webhook.
- Wanderkin does not enable document verification in V1, so Didit does not collect passport, ID, or other document images for Wanderkin verification.
- Wanderkin does not use Didit to collect name, date of birth, or other personal information from identity documents in V1.
Location data
Wanderkin does not track your real-time location.
We do not use GPS tracking, background location access, or live location sharing. Other users only see the current city or trip city information you enter and choose to make visible.
Your trip destinations and dates are used for destination matching, city feeds, and meetup planning. You can hide or remove trips from your profile.
Messaging data
Messages are stored on our servers so they can be delivered, synced across devices, and shown in your conversation history.
Messages are encrypted in transit using TLS. Wanderkin V1 is not end-to-end encrypted. That means our systems store message content, and our moderation team may access messages when needed to investigate reports, enforce our Community Guidelines, respond to safety concerns, or comply with valid legal process.
Data sharing
We do not sell your personal data. We do not share your data with advertising partners.
We share data only where it is needed to run Wanderkin, protect the community, or comply with the law.
- Infrastructure providers, such as hosting, database, storage, CDN, analytics, diagnostics, and notification services.
- Didit, our verification processor, which processes selfie images, facial biometric data, device metadata, and liveness results for the liveness-only verification flow.
- Payment processors and app stores. In-app purchases are handled by Apple or Google. Wanderkin does not receive your full payment card details.
- Law enforcement, regulators, courts, or other authorities only when we believe disclosure is required by valid legal process or necessary to protect someone from harm.
Data retention
We keep account data while your account is active and for as long as needed to provide Wanderkin, protect users, resolve disputes, and meet legal obligations.
When you request account deletion, your account enters a 30-day grace period. If you log back in during that period, you can cancel deletion. After 30 days, we permanently delete your profile, photos, trips, verification record, messages, and account identifiers from active systems, unless limited retention is legally required. At deletion finalization, Wanderkin also asks Didit to delete any remaining hosted verification session tied to your account.
Some public or community content may be anonymised instead of deleted. For example, city feed posts may remain without your profile attached if removing them would break community context. Reports and moderation records may be retained in limited form to prevent abuse, enforce bans, and protect users.
Cookies and analytics
The Wanderkin website uses privacy-respecting analytics to understand aggregate site usage. We do not use tracking cookies for advertising.
The Wanderkin app does not use cookies. The app may use analytics and diagnostics events to understand reliability, feature usage, crashes, and performance.
Your rights
You can access, correct, delete, or export your personal data. You can also withdraw consent where processing is based on consent.
If you are in the UK, EU, or another region with privacy rights, you may also have the right to object to certain processing, restrict processing, and lodge a complaint with your local data protection authority.
To exercise these rights, email support@usewanderkin.com. We may need to verify your identity before responding.
Children
Wanderkin is not intended for users under 18. If we learn that a user is under 18, we will terminate the account and delete associated personal data unless we are legally required to retain limited information.
Changes to this policy
We may update this Privacy Policy as Wanderkin changes. If we make material changes, we will notify users by in-app notification and email where appropriate. The updated policy will always show the latest effective date.
Contact
Data controller: Regulus Framework Limited, registered in England and Wales under company number 16998528. Registered office: 124-128 City Road, London, EC1V 2NX.
For privacy questions or requests, email privacy@usewanderkin.com. For general support, email support@usewanderkin.com.