Privacy

Effective date: 4 August 2026

This Privacy Policy explains how YOKUDU trading as Oohlala (“Oohlala”, “we”, “us”, or “our”) collects, uses, stores, shares, and protects personal information when you use the Oohlala website, web-based or in-app couples quizzes, participant and result links, the Oohlala iOS app, optional Partner Sync, transactional emails, support channels, and related services (together, the “Service”).

For purposes of the Protection of Personal Information Act, 2013 (“POPIA”), Oohlala is the responsible party where we determine why and how personal information is processed. Our contact details appear in section 21.

1. Who this Policy applies to

This Policy applies to:

  • a person who starts or completes a web quiz;
  • the partner invited to complete the other part of a quiz;
  • a person who starts or completes a quiz in the iOS app, opens a result link, or imports completed results using a quiz code;
  • a person who uses app features such as Partner Sync, shared quizzes, matches, bucket lists, notes, ratings, or the intimacy calendar; and
  • anyone who contacts us for support or a privacy request.

2. Adults only and sensitive information

The Service is intended only for consenting adults aged 18 or older. Some quizzes and app features concern relationships, intimacy, sexual preferences, and a person’s sex life. This can be sensitive or special personal information under applicable law.

Participation is voluntary. By choosing to submit quiz answers after being given access to this Policy and the relevant notices, you request that we process those answers to compare both participants’ responses and generate shared results. Where consent is the required legal basis, you consent to that processing. If you do not want this information processed or included in shared results, do not start or complete a quiz.

You must not use the Service with a person under 18, submit information about a minor, or enter another adult’s details without their knowledge. Each participant should review this Policy before submitting their own answers.

3. Information processed by the quiz service

The web quiz and quizzes started inside the iOS app use Oohlala’s Supabase-hosted quiz service. When either is used, we may process:

  • Participant details: each participant’s name or nickname, selected gender, participant role, and an email address when a web-quiz participant uses the result-email flow;
  • Quiz data: quiz type and version, answers, skipped questions, progress, completion status, timestamps, and the questions applicable to the participants;
  • Generated data: compatibility calculations, shared matches, conditional matches, scores, result summaries, and suggested bucket-list items;
  • Access and session data: quiz, dataset and participant identifiers, six-digit quiz code, secret participant and result-link tokens, browser- or app-stored session state, app-import status, and result-access status;
  • Paired-quiz data: when paired app users start a shared in-app quiz, the couple identifier, anonymous installation user identifiers, shared-quiz session identifier and status, quiz title and version, and which installation is assigned to each quiz role;
  • Email-delivery data: recipient name, email address, result URL, quiz code, delivery status, retry information, and provider message events when result email is requested; and
  • Technical, import, referral and security data: IP address, user-agent or app information, app platform and version, request and import timestamps, referral code where used, service logs, error information, and rate-limit or security counters. For quiz-code abuse prevention, the Service stores a one-way hash derived from IP address and user-agent information in the rate-limit record.

A participant who starts a web quiz enters both participants’ names or nicknames and selected genders so that the two-person flow can be created. Each web participant supplies their own email address after completing their part if they continue through the result-email flow. The iOS app does not ask for an email address when an in-app quiz is completed.

4. Information processed by the iOS app

The iOS app does not require a conventional Oohlala account or an email login. By default, app data is stored locally on the device in encrypted application storage. Server processing still occurs when you start or complete a quiz, import results, use Partner Sync, purchase or restore Premium, or contact support. Local app data includes:

  • participant names or nicknames and selected genders;
  • in-app and imported quiz identifiers, quiz codes, participant and result-access tokens, quiz progress, summaries, matches, question information, answer levels used for matches, and generated bucket-list items;
  • custom bucket lists and items, ordering, completion history, ratings, and private notes;
  • intimacy-calendar entries such as dates, titles, categories, ratings, notes, time, duration, location text entered by the user, activities, moods, and other optional details; and
  • app settings, onboarding state, and biometric-lock preference.

When you start or take a quiz inside the app, the app sends participant names or nicknames, selected genders, answers, progress, completion state, and ordinary technical request information to Oohlala’s quiz service. The service saves each participant’s answers privately, compares them after both participants complete the quiz, and returns the shared report and public quiz dataset to the app. Quiz access is controlled using secret participant tokens and, for paired quizzes, the user’s anonymous Partner Sync identity.

When a user submits a six-digit quiz code, the app sends the code and ordinary technical request information to Oohlala’s Supabase-hosted service. If the code is valid and still available, the service returns the completed shared quiz report and the public quiz dataset needed to display it. The app then saves the imported results on the device.

Optional Partner Sync. When you choose to pair the app with your partner, Supabase creates a random anonymous installation user identifier; no email address or password is required. The app then uploads and synchronizes the shared couple profile, participant names and genders, bucket-list collections and items, completion history, ratings and notes, quiz summaries and shared-match answer values, and intimacy-calendar activities, including any dates, titles, ratings, notes, time, duration, location text, activities, moods, or other details entered in those records. The service also processes couple and membership identifiers, display names, record identifiers and revisions, change timestamps, deletion markers, app version, and platform. Each active member of the paired couple can receive and store this shared data on their own device.

Partner pairing uses an eight-character code that expires after 15 minutes. The database stores a one-way hash of that pairing code together with invite status, attempt counters, and timestamps. When paired users start a shared in-app quiz, the service links the quiz session to both anonymous installation identities so either app can discover and continue its assigned part.

Disconnecting Partner Sync ends the pairing for both installations and permanently deletes the shared Partner Sync server copy, linked shared in-app quiz records, and both disposable anonymous Partner Sync identities. Each device retains the local copy it had already downloaded, and Oohlala cannot remotely erase the other partner’s device copy. Pairing again creates new anonymous identities and a new shared server space. Reset All Data first performs this disconnect and then deletes the local app copy on the device where the reset was requested. Other server-data requests are explained in section 16.

The app is free to download and offers an optional monthly Oohlala Premium subscription. Apple processes the purchase. RevenueCat, our subscription-management provider, receives and processes purchase history, the Apple transaction receipt or signed transaction information, product and entitlement status, price and currency information, last-seen time, limited technical information such as device type, operating system, platform and locale, and a randomly generated anonymous app user identifier. We use this information to offer the correct subscription, validate purchases, prevent purchase fraud, unlock Premium features, and restore access. Oohlala does not require an account for this process and does not send quiz answers, bucket-list content, calendar entries, names, email addresses, or notes to RevenueCat.

Face ID, Touch ID, or device-passcode checks are performed by Apple’s operating system. Oohlala receives only the success or failure of the authentication attempt and does not receive or store biometric templates.

The current iOS app does not request access to contacts, photos, the camera, microphone, precise location, or advertising identifiers. It contains no third-party advertising or cross-app tracking SDK.

5. How we collect information

We collect personal information:

  • directly from you when you enter details, submit quiz answers, provide an email address, use a quiz code, enable or use Partner Sync, make a purchase, or contact us;
  • from the other participant when they start a shared quiz, enter your name or nickname and selected gender, pair their app with yours, or add or change a synchronized record;
  • automatically from browsers, devices, hosting systems, Edge Functions, and security logs when the Service is requested;
  • from Apple and RevenueCat when they provide subscription transaction, purchase-validation, entitlement, restoration, and related service events; and
  • from service providers when they provide delivery, hosting, security, or support events to us.

When you use the Oohlala contact form, we process the name, email address, subject, message, submission time, and ordinary technical information needed to deliver, secure, and respond to the request.

6. How we use personal information

We use personal information to:

  • create and operate a two-participant quiz session;
  • identify the correct participant and load or save quiz progress;
  • compare answers and generate compatibility summaries, shared matches, result reports, and bucket-list suggestions;
  • provide result links and allow completed results to be imported into the iOS app using a quiz code;
  • create an anonymous app-installation identity when Partner Sync is enabled, pair two installations, synchronize shared records between the paired devices, and make shared in-app quizzes available to both participants;
  • display subscription products, process and validate Oohlala Premium purchases, prevent purchase fraud, unlock subscribed features, and restore subscription access;
  • send transactional result emails when email is provided;
  • prevent code guessing, fraud, abuse, unauthorized access, and attacks;
  • operate, secure, troubleshoot, back up, and improve the Service;
  • respond to support, privacy, and legal requests;
  • comply with law and establish, exercise, or defend legal rights; and
  • produce aggregated or properly de-identified operational statistics where lawful.

We do not use intimate quiz information for advertising, data-broker activity, or cross-app tracking.

7. Shared results, links, and quiz codes

Oohlala is designed to create shared results for two participants. The Service compares both sets of answers and generates combined outputs such as compatibility summaries, shared or conditional matches, and bucket-list suggestions. These outputs include information derived from both participants.

The result-generation system also creates an underlying report containing the answer values used to calculate the shared outputs. The current result and import APIs may transmit those report values to an authorized result-link or quiz-code request, even though the user-facing experience is designed primarily around shared matches and summaries.

Participant links and quiz codes act as access credentials. Anyone who obtains a valid link or code may be able to access or import the associated shared report while that credential is accepted. Keep them private, share them only with the intended partner, and contact us immediately if you believe they have been exposed. Oohlala applies rate limiting and other controls, but no access code is a substitute for careful sharing.

By default, completed quiz results remain available through participant links, result links, and the six-digit app-import code for 24 hours after the second participant finishes. Authorized Oohlala administrators can extend the deadline or approve an exception where reasonably necessary for support, recovery, security, or another documented lawful purpose. Once the applicable deadline passes, the customer-facing quiz, result, and import endpoints reject the expired credentials.

How completed quiz records are de-identified after the access period. During the expiry cleanup following the applicable deadline, Oohlala removes both participants’ email addresses, the six-digit quiz code, participant invitation and verification tokens, and queued result-email records. The quiz is marked expired and cannot be restored for customer access. The retained answer and report data is then referenced by randomly generated internal quiz and participant identifiers for restricted operational and statistical use.

This process removes the direct contact details and credentials that connected a person to the customer-facing quiz. It does not currently remove participant names or nicknames, selected genders, answers, or generated report content from every retained database record. Retained quiz content must therefore still be treated as personal information and is not guaranteed to be fully anonymous in every circumstance. We restrict access to that retained content, do not use it for advertising, and accept deletion requests as explained in section 16.

8. Lawful grounds and consent

Depending on the context and applicable law, we process personal information:

  • with consent, including consent to process intimate or sex-life-related quiz responses where consent is required;
  • to take steps requested by you and provide the Service;
  • to comply with legal obligations;
  • to protect legitimate interests in operating and securing the Service, preventing abuse, and handling legal claims, where those interests are not overridden by your rights; or
  • on another ground permitted by applicable law.

You may withdraw consent for future processing by stopping use and contacting us. Withdrawal does not affect processing already carried out lawfully. Because sensitive answers are necessary to compare the quiz, withdrawing consent may mean that we cannot continue to provide the affected quiz or results.

9. When we share personal information

We may disclose personal information:

  • to the other quiz participant through the shared result experience;
  • to the other active member of a paired couple through Partner Sync, including the synchronized profile, bucket-list, quiz-result, shared-match, note, rating, completion, and intimacy-calendar information described in section 4;
  • to operators and service providers that host, secure, support, or deliver the Service for us;
  • to professional advisers, auditors, insurers, or similar recipients where reasonably necessary and subject to confidentiality duties;
  • where required by law, court order, regulation, or a lawful request from an authority;
  • where reasonably necessary to investigate fraud, abuse, a security incident, or a breach of our terms; and
  • as part of a merger, acquisition, restructuring, financing, or sale of all or part of the business, subject to appropriate safeguards.

We do not sell personal information. We do not share intimate quiz information with advertisers or data brokers.

We select service providers that offer privacy and security protections appropriate to the information they process. We require operators acting on our behalf to process personal information only for authorized purposes, protect it using appropriate safeguards, and provide the same or equivalent protection described in this Policy and required by applicable law.

10. Service providers

We currently use the following main providers:

  • Supabase for the database, Edge Functions, anonymous app authentication, Partner Sync, shared in-app quiz sessions, quiz data, reports, security controls, service logs, and related backend infrastructure;
  • Brevo for transactional result-email delivery and associated delivery events;
  • Hostinger for website hosting, DNS, server, and related website infrastructure;
  • Apple for App Store distribution, displaying localized subscription terms, processing Oohlala Premium purchases and renewals, and handling subscription management and refunds under Apple’s own terms and privacy notice; and
  • RevenueCat for retrieving subscription offerings, validating Apple transactions, preventing purchase fraud, maintaining anonymous entitlement status, restoring purchases, and providing subscription reporting.

These providers may process personal information on our behalf. They may also process limited information for their own security, compliance, or operational purposes under their respective privacy notices and legal obligations.

The iOS app is free to download. Oohlala Premium is an optional monthly auto-renewable subscription purchased through Apple’s in-app purchase system. Apple processes the payment, and Oohlala does not directly receive your full payment-card or bank-account details. RevenueCat processes the limited purchase and entitlement information described above on our behalf. The app does not use PayPal or another external checkout for Premium access.

11. International processing

Our providers may process personal information outside South Africa. Before transferring personal information across borders, we take reasonable steps to use a transfer mechanism permitted by applicable law and to ensure that the recipient is subject to a law, binding agreement, corporate rules, consent, or other safeguard that provides an adequate level of protection as required by POPIA and other applicable law.

12. Email communications

If you provide your email address after completing a quiz, we use it to send the result link and related transactional messages. Result emails can contain the participant name, a link containing a secret access token, and the six-digit quiz code. Email is not completely private; anyone with access to the inbox or a forwarded message may be able to use those credentials.

We do not currently use quiz emails for direct marketing. If we introduce marketing, we will do so only where lawful, provide any required notice or consent, and provide an unsubscribe method. Essential service or legal messages are not marketing.

13. Cookies and device storage

The web quiz uses browser local storage and similar strictly necessary technology to remember the active participant token, quiz details, answers, progress, email entry, and cached public quiz data so that a participant can continue. The current quiz code does not include advertising or cross-site tracking technology.

The iOS app stores its app data locally using encrypted application storage, with key material protected using the device’s secure storage facilities. Operating-system backups or device-management settings may affect how local data is backed up or restored.

If Partner Sync is enabled, the anonymous Supabase authentication session is stored using the device’s secure storage facilities and automatically refreshed while needed. Pairing, synchronization, shared quizzes, and result imports use encrypted network connections to communicate with Oohlala’s backend.

14. Retention, access expiry, de-identification, and deletion

We retain personal information for as long as reasonably needed to operate and protect the Service, provide shared and synchronized features, handle a request or dispute, or comply with law. Customer-access expiry, de-identification, record retention, and deletion are separate events. The main retention approach is:

InformationRetention approach
Participant links, result links, and six-digit app-import codeBy default, these credentials stop working 24 hours after the second participant completes the quiz. An authorized administrator may extend or exempt a quiz for a documented support, recovery, security, or other lawful reason. After the applicable deadline, the credentials are rejected and the expiry cleanup removes the quiz code and participant access and verification tokens.
Completed quiz participant records, answers, and generated reportsAfter the applicable access deadline, the expiry cleanup removes participant email addresses and access credentials as described in section 7. Answers and generated report data may be retained under randomly generated internal identifiers for restricted operational and statistical use. Names or nicknames and selected genders currently remain in some retained participant and report records, so the retained content is still handled as personal information and may be deleted on a verified request unless a lawful reason requires or permits continued retention.
Incomplete quiz sessionsQuiz sessions that have not been completed by both participants remain available so the participants can continue. A participant can reset an in-progress quiz, which deletes that quiz session and its dependent records, or may submit a verified deletion request.
Partner Sync identity, membership, shared records, and shared-quiz metadataPartner Sync records remain on Oohlala’s servers only while the pairing is active so the devices can stay synchronized. If either partner disconnects, Oohlala deletes the couple’s shared Partner Sync server copy, pairing invitations, membership and synchronization records, linked shared in-app quiz records, and both disposable anonymous Partner Sync identities. Disconnecting does not remotely delete copies already stored locally on either device. Restricted security and service logs may remain for the period described below, and properly de-identified or aggregated information may be retained where lawful.
Pairing invitations and rate-limit recordsA pairing code expires after 15 minutes and is stored by the database only as a one-way hash. Invite status, attempt counters, and related security records may remain after the code expires to prevent abuse, troubleshoot pairing, and maintain service integrity.
Browser local storageRemains in that browser until the user starts over, clears Oohlala site data, clears browser storage, or the browser/device removes it. Server expiry does not automatically clear browser storage.
iOS app dataRemains on the device until the user deletes relevant items, uses Reset All Data, or removes the app, subject to operating-system backup and restore behavior. Local partner notifications are normally pruned after 90 days. Deleting a local copy does not delete a copy already synchronized to the other partner’s device.
Apple and RevenueCat subscription recordsPurchase, renewal, refund, and entitlement records are retained as reasonably necessary to administer and restore Oohlala Premium, prevent fraud, resolve purchase issues, meet accounting or legal obligations, and provide subscription reporting. Apple and RevenueCat also retain information under their respective privacy notices and legal obligations.
Transactional email queue and delivery eventsQueued result-email rows linked to an expiring quiz are deleted during the quiz-expiry cleanup. Other delivery events are retained for 24 months after the last delivery attempt, unless needed longer for a complaint or security investigation.
Quiz-code rate-limit records and security/service logsRetained for 24 months after the last relevant request or event, unless needed longer to investigate an incident or comply with law.
Support and privacy-request recordsRetained for 24 months after closure, unless law or an ongoing dispute requires longer retention.
BackupsRemoved or overwritten through the normal backup cycle within 24 months unless preserved for a documented legal or security reason.

We periodically review retained information and restrict its use when it is no longer needed for the active Service. Properly de-identified or aggregated information may be retained for longer where lawful. Disconnecting Partner Sync automatically deletes the active shared Partner Sync server copy as described above. Other deletion requests are handled separately under section 16 and are not triggered automatically by expiry of customer access, local app reset when no pairing is active, removing the app, or clearing browser storage.

15. Security

We use reasonable technical and organizational measures designed to protect personal information. These include encrypted network connections, restricted backend access, row-level database controls, token hashing, local app encryption, rate limiting, and service monitoring. We review safeguards in light of the sensitivity of the information and reasonably foreseeable risks.

No website, app, email system, or storage system is completely secure. If we have reasonable grounds to believe that personal information has been accessed or acquired by an unauthorized person, we will investigate and make the notifications required by applicable law.

16. Your controls and deletion choices

  • iOS app: delete individual bucket-list or calendar items where available, or use Settings > Reset All Data to delete the Oohlala data stored by the app on that device. If the app is paired, it must disconnect before the local reset can complete.
  • Partner Sync: either partner can disconnect in the app. Disconnecting ends synchronization for both installations and deletes the shared Partner Sync server copy, pairing records, linked shared in-app quiz records, and both disposable Partner Sync identities. It does not delete copies already stored locally on either device. Pairing again creates a new server space and new anonymous identities.
  • Subscription: manage or cancel Oohlala Premium through your Apple Account subscription settings. Use Restore Purchases in Oohlala Settings to re-check an existing entitlement.
  • Important: Reset All Data first performs the Partner Sync deletion described above and then deletes the local app copy on that device. It does not cancel Oohlala Premium, delete Apple or RevenueCat transaction records, delete unrelated web-quiz data, delete the other partner’s device copy, or delete email-provider records.
  • Web browser: clear Oohlala’s site data/local storage using browser settings. This deletes that browser’s copy but does not delete server records.
  • Server data: contact us using section 21 to request access, correction, withdrawal of consent, or deletion. Include the quiz code, result link, participant email, couple or shared-quiz reference, approximate dates, or other information reasonably needed to locate the record. Do not send quiz answers, pairing codes, or participant access tokens in the request unless we specifically ask for them.

We may need to verify that a requester is entitled to act for the relevant participant before disclosing or deleting shared data. Because a quiz contains information about two people, we will consider both participants’ rights and any applicable legal duties when responding.

17. Your privacy rights

Subject to applicable law and any lawful limits, you may have the right to:

  • ask whether we hold personal information about you;
  • request access to that information;
  • request correction, deletion, destruction, or restriction;
  • object to processing in the circumstances provided by law;
  • withdraw consent for future processing where processing is based on consent;
  • request information about cross-border processing or service providers;
  • opt out of direct marketing; and
  • lodge a complaint with the Information Regulator or another competent authority.

We will not charge for a request unless a fee is permitted by law, and we will explain any lawful refusal or limitation.

18. Automated calculations

Oohlala automatically compares answer values and calculates matches, rankings, and compatibility summaries according to predefined quiz logic. These outputs are for entertainment and relationship-communication purposes. They are not professional advice and are not used by Oohlala to make a decision that produces legal or similarly significant effects about a participant.

19. Children

The Service is not directed to anyone under 18, and we do not knowingly permit minors to participate. If you believe a minor’s information has been submitted, contact us immediately. We will investigate, restrict access, and delete the information where required.

20. Third-party links and policy changes

The Service may open third-party websites or services in the system browser. Their privacy practices are governed by their own notices. We are not responsible for third-party content or practices that are outside our control.

We may update this Policy when the Service, providers, law, or our processing changes. We will post the updated Policy with a new effective date and provide any additional notice required by law. If a material change requires consent, we will request it before relying on the change for future processing.

21. Contact us and make a privacy request

Responsible party: YOKUDU trading as Oohlala
Privacy requests and contact form: https://oohlala.app/contact/
Help: https://oohlala.app/help/

Use the subject “Privacy Request” in the contact form. To help us locate data, include the relevant quiz code, participant email, result-link reference, couple or shared-quiz reference, and approximate dates where available. Do not include quiz answers, pairing codes, or secret participant tokens in the first message.

You may also contact or lodge a POPIA complaint with the Information Regulator (South Africa) at POPIAComplaints@inforegulator.org.za or telephone 010 023 5200.