Safety & trust

How Candor earns trust, layer by layer

The safety model has four layers: verification before anyone participates, detection running behind the scenes, moderation that shows its work, and privacy choices made for you by default. Here's exactly how each one works.

Layer 1: the gate

Photo verification, required

Before your profile can take part in discovery at all, you take a live selfie. It gets compared against your profile photos using face comparison. Pass and your profile goes live. Fail or land somewhere uncertain, and it goes to a human reviewer. The system fails closed.

The router has four states and no ambiguity: signed out, no profile, pending verification, full app. You can't browse while you wait, because an unverified pool would just be every other app with extra steps.

Your verification selfie lives in private storage and never appears on your profile. After a decision, it becomes eligible for deletion after 24 hours and is removed through retention cleanup. Pending selfies remain available for review; account deletion also removes them. Government IDs are never collected.

Verification states
No profile yet. Onboarding asks intent first, then who you are.
Selfie taken. Comparing against my photos...
Pending review. A human checks anything the automation couldn't confirm. Nobody can see you yet.
Verified. Visible only to people in my intent pool.
Layer 2: detection

Catfishing gets expensive

Duplicate photo fingerprints. Every uploaded photo is fingerprinted perceptually. Measured on real images: the same photo re-uploaded at a different size and quality scored a Hamming distance of 3 from its original, while genuinely different photos scored 18 to 19. The duplicate threshold sits at 8, comfortably between the two groups, and matches surface for moderators.

Camera-only video intros. A photo can be stolen from anywhere. A live clip recorded in the app is much harder to fake, which is why gallery import is deliberately not offered for this step.

Nudity screening. Profile photos get screened automatically for sexual content before they're published, and anything flagged goes to review instead of quietly through.

3
Hamming distance: same photo, re-sized and re-compressed
18-19
Hamming distance: genuinely different photos
8
duplicate threshold, measured between the two groups
0
government IDs collected, ever
Layer 3: moderation

Reports get outcomes you can see

Report someone and a human moderator decides between ban, warn, or no action. You see the outcome either way. Almost no competitor does this, and we think that says something.

Enforcement comes with an explanation and an appeal path. There are no shadowbans: if your visibility or features are limited, you're told why and given a way to appeal. A ban also revokes verification, so a banned account can't just wander back in through settings.

You can block anyone instantly. Blocking is symmetric, so neither side sees the other again, and openers between blocked accounts get rejected at the database level.

What happens after you report
Reported: impersonation. Evidence attached.
A moderator reviewed the account.
Outcome: account banned. I can track this under "My reports."
Disagree? Contact Candor support by email to appeal a restriction.
Layer 4: privacy defaults

Privacy decisions made for you, correctly

Location is fuzzed before storage. Your precise coordinate is rounded on your device and rounded again when stored, reducing location precision. Candor never asks for background location and keeps no history of precise coordinates.

Sensitive data needs explicit consent. Dating intention, sex, and who you seek can reveal sex-life information. Where EU or UK law applies, that data is processed only under separate explicit consent collected at onboarding, worded plainly, stored verbatim, and withdrawable any time.

Data portability and exit. Export everything as JSON in one tap. Delete your account in two taps: authentication identity, records, photos, selfie, and video all leave active systems. No retention offer, no survey.

~1 mile location fuzz, before storage No background location No precise-location history No behavioral advertising No sale of personal data No ad-model training on profiles One-tap JSON export Two-tap deletion

Date-plan sharing

Candor has a built-in way to share where you'll be with a friend when you go meet someone. You choose a recipient in your phone's share sheet. Candor does not store the shared details; copies received by your friend are outside Candor's control. It's the safety habit people should already have, made effortless.

Honest limits

Candor doesn't run criminal-background checks or collect identity documents, and it can't guarantee anyone's behavior. Keep early conversations in the app, meet in public, and call emergency services if anyone is in danger.

Talk to a person

See something off? Report it in the app and watch what happens. Email works too: valdrexphi@gmail.com, with "Candor" in the subject so it lands in the right queue.

The full picture

Read exactly what we collect, and what we never touch.

The Privacy Policy is written in plain language. It covers every layer above, including sensitive-data handling and your rights wherever you live.