The safety model has four layers: verification before anyone participates, detection running behind the scenes, moderation that shows its work, and privacy choices made for you by default. Here's exactly how each one works.
Before your profile can take part in discovery at all, you take a live selfie. It gets compared against your profile photos using face comparison. Pass and your profile goes live. Fail or land somewhere uncertain, and it goes to a human reviewer. The system fails closed.
The router has four states and no ambiguity: signed out, no profile, pending verification, full app. You can't browse while you wait, because an unverified pool would just be every other app with extra steps.
Your verification selfie lives in private storage and never appears on your profile. After a decision, it becomes eligible for deletion after 24 hours and is removed through retention cleanup. Pending selfies remain available for review; account deletion also removes them. Government IDs are never collected.
Duplicate photo fingerprints. Every uploaded photo is fingerprinted perceptually. Measured on real images: the same photo re-uploaded at a different size and quality scored a Hamming distance of 3 from its original, while genuinely different photos scored 18 to 19. The duplicate threshold sits at 8, comfortably between the two groups, and matches surface for moderators.
Camera-only video intros. A photo can be stolen from anywhere. A live clip recorded in the app is much harder to fake, which is why gallery import is deliberately not offered for this step.
Nudity screening. Profile photos get screened automatically for sexual content before they're published, and anything flagged goes to review instead of quietly through.
Report someone and a human moderator decides between ban, warn, or no action. You see the outcome either way. Almost no competitor does this, and we think that says something.
Enforcement comes with an explanation and an appeal path. There are no shadowbans: if your visibility or features are limited, you're told why and given a way to appeal. A ban also revokes verification, so a banned account can't just wander back in through settings.
You can block anyone instantly. Blocking is symmetric, so neither side sees the other again, and openers between blocked accounts get rejected at the database level.
Location is fuzzed before storage. Your precise coordinate is rounded on your device and rounded again when stored, reducing location precision. Candor never asks for background location and keeps no history of precise coordinates.
Sensitive data needs explicit consent. Dating intention, sex, and who you seek can reveal sex-life information. Where EU or UK law applies, that data is processed only under separate explicit consent collected at onboarding, worded plainly, stored verbatim, and withdrawable any time.
Data portability and exit. Export everything as JSON in one tap. Delete your account in two taps: authentication identity, records, photos, selfie, and video all leave active systems. No retention offer, no survey.
Candor has a built-in way to share where you'll be with a friend when you go meet someone. You choose a recipient in your phone's share sheet. Candor does not store the shared details; copies received by your friend are outside Candor's control. It's the safety habit people should already have, made effortless.
Candor doesn't run criminal-background checks or collect identity documents, and it can't guarantee anyone's behavior. Keep early conversations in the app, meet in public, and call emergency services if anyone is in danger.
See something off? Report it in the app and watch what happens. Email works too: valdrexphi@gmail.com, with "Candor" in the subject so it lands in the right queue.
The Privacy Policy is written in plain language. It covers every layer above, including sensitive-data handling and your rights wherever you live.