Informational translation. The binding version is the Spanish one. View Spanish version
Privacy Policy
Last updated: 16 July 2026
This Privacy Policy explains how Mon (the “Platform”) processes the personal data of its users, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018, of 5 December, on the Protection of Personal Data and guarantee of digital rights (LOPDGDD).
Mon is a social application for adults that allows you to create a profile, discover and meet other people (Explore), post photos and ephemeral stories, chat (text, photos, video and notes), create and take part in communities (with channels, galleries and meetups), organise or attend meetups and events, book individual services (1:1 sessions) and browse third-party events (e.g. Ticketmaster). This policy covers all of those features.
1. Data controller
- Controller: Francisco Rodríguez (natural person)
- Privacy email: monsocial@rodriguezstudio.es
- Website:
https://rodriguezstudio.es - Data Protection Officer (DPO): none appointed (data protection enquiries at monsocial@rodriguezstudio.es)
2. Data we process
Mon is a dating and social life application. By its nature, some data may reveal sexual orientation, gender identity or sex life, which are special category data (art. 9 GDPR) and are processed solely with your explicit consent. We may also process biometric data in the optional “real person” verification (see section 2.2 and point 3).
2.1. General categories
| Category | Examples |
|---|---|
| Account data | Email address, password (encrypted), sign-in identifiers, acceptance of the Terms (date and version) |
| Profile data | Name/alias, date of birth and age, gender, orientation and identity (if you choose to display them), description, interests, “moods” and tags |
| Photographs and content | Profile photos, albums, community photos, stories (ephemeral content), images, videos and messages that you post or send |
| Stories data | Story content, publication duration (they expire after 24 h) and viewing statistics (“insights”: who has seen your story) |
| Communities data | Communities you belong to, role (member, moderator, administrator, owner), channel messages, gallery content and access requests |
| Meetups and services data | Meetups created or attended, tickets, capacity, 1:1 service bookings (date, slot, format), attendance and validation (check-in) |
| Special category data | Information you choose to display that may reveal your sexual orientation, gender identity or sex life; biometric data from the optional verification (see 2.2) |
| Location data | Approximate or precise location to show nearby people, communities, meetups and events (subject to device permissions) |
| Usage and interaction data | Likes, matches, messages, profile visits, stories viewed, blocks, mutes, ratings and filter preferences |
| Payment and billing data | Data needed to manage subscriptions, Boost, meetup tickets and paid services; handled by the stores and by our payment providers. We do not store your full card details |
| Organiser data (payouts) | If you charge for meetups or services, the identity verification (KYC) and payout data required by Stripe Connect |
| Technical data | Device model, operating system, app identifiers, IP address, logs, push notification tokens, advertising identifier (if you authorise personalised ads) |
| Moderation and security data | Content analysed to detect prohibited material, reports made and received, appeals, sanctions and security measures |
2.2. Biometric data — “real person” verification (optional)
Mon offers an optional and free verification to obtain the “real person” badge, based on a liveness check (blink, smile, head turn) and, where appropriate, on comparing the selfie with your profile photo.
- The whole process runs on your device (on-device). The images and biometric computations (the facial “embedding”) are not sent to our servers or to third parties.
- The intermediate biometric result is computed and discarded immediately: we do not store any template or biometric data at rest.
- We only keep the result of the verification (verified yes/no, method and date) and the reference to the verified profile photo, in order to display the badge. If you delete that photo, the verification is automatically revoked.
- Verification is voluntary. Its legal basis is your explicit consent (art. 9.2.a GDPR), which you can withdraw by ceasing to use the feature or by deleting the verified photo.
3. Purposes and legal bases
| Purpose | Legal basis (art. 6 / art. 9 GDPR) |
|---|---|
| Creating and managing your account and profile | Performance of the contract (art. 6.1.b) |
| Showing you people, communities, meetups and events, and showing you to other people | Performance of the contract (art. 6.1.b) |
| Publishing and displaying your photos, stories and content | Performance of the contract (art. 6.1.b) |
| Processing data revealing sexual orientation, gender identity or sex life | Explicit consent (art. 9.2.a) |
| “Real person” biometric verification (on-device) | Explicit consent (art. 9.2.a) |
| Geolocation for proximity features | Consent (art. 6.1.a) + operating system permission |
| Content moderation, age verification and community safety | Legitimate interest and compliance with legal obligations (art. 6.1.f and 6.1.c) |
| Managing subscriptions, Boost, meetups and paid services | Performance of the contract (art. 6.1.b) |
| Payout distribution to organisers (Stripe Connect) and fraud prevention | Performance of the contract and legal obligation (art. 6.1.b and 6.1.c) |
| Push notifications and service communications | Performance of the contract / operating system consent |
| Advertising in the app (for non-Premium users) | Consent (art. 6.1.a) managed by the consent platform (UMP/ATT) |
| Marketing communications (if any) | Consent (art. 6.1.a), revocable at any time |
| Analytics and product improvement | Legitimate interest or consent, depending on the tool |
4. Recipients and processors
We share data with providers acting as processors under contract (art. 28 GDPR), exclusively in order to provide the service:
- Supabase — authentication, database, storage, realtime and server functions. Data region: the European Union (Ireland, AWS eu-west-1).
- Stripe (Stripe Payments Europe) — payment processing and distribution for paid meetups and services (Stripe Connect), including organisers’ identity verification (KYC).
- RevenueCat — management of Premium subscriptions and in-app purchases.
- Apple App Store / Google Play — in-app purchases (subscriptions and Boost).
- Sightengine — automated image moderation.
- Google (Google AdMob / Google Mobile Ads and its UMP consent platform) — advertising in the app for non-Premium users, when you authorise it.
- Expo (push notifications) and the messaging services of Apple (APNs) and Google (FCM) — sending push notifications to your device.
- IONOS — website hosting and sending of transactional emails (verification, password recovery, payment and moderation notices).
Third-party content (external events). The events section may show third-party events (for example Ticketmaster). The purchase of tickets takes place on the third party’s site, under their own conditions and privacy policy; Mon acts merely as a link and, where applicable, as an affiliate (see Legal Notice and Payment Terms). We do not share your profile data with those third parties; if you follow a purchase link, they will process your data in accordance with their own policies.
We do not sell your personal data. We only disclose it to authorities where there is a legal obligation.
5. International transfers
Some providers (e.g. Stripe, RevenueCat or Google) may process data outside the European Economic Area. In those cases, transfers are covered by appropriate safeguards: the European Commission’s Standard Contractual Clauses (SCCs) and/or the EU-US Data Privacy Framework where applicable.
6. Automated decisions
We use automated systems to moderate content (image analysis) and to block the registration of minors and detect possible fraud or abuse. Decisions that significantly affect you (for example, the restriction or cancellation of an account) can be reviewed by a person through the complaints procedure described in the Moderation and DSA Policy.
7. Retention periods
We keep your data while your account is active. Stories are automatically deleted 24 hours after publication. After account closure, we delete or anonymise your data within 30 days, except for data we must retain due to legal obligations (billing, fraud prevention, judicial requirements) or for the defence against claims, for the legally required periods. Technical backups may take additional time to be purged completely.
8. Your rights
You can exercise at any time your rights of access, rectification, erasure, objection, restriction of processing, portability and to withdraw consent by writing to monsocial@rodriguezstudio.es, or by deleting your account from the app (see Account and data deletion).
If you consider that the processing does not comply with the regulations, you can lodge a complaint with the Spanish Data Protection Agency (AEPD) — www.aepd.es.
9. Security
We apply technical and organisational measures to protect your data: encryption in transit, database access control through row-level security policies (RLS), content moderation, report management and incident monitoring. No system is completely infallible; see also the Safety Tips.
10. Minors
Mon is reserved for people over 18. We do not knowingly process minors’ data. If we detect a minor’s account, we delete it. More information in Protection of minors.
11. Changes to this policy
We may update this Privacy Policy. We will notify you of substantial changes through the app or by
email. The version in force is always the one published at rodriguezstudio.es with its update
date.