Komby Privacy Statement
Version: 25 August 2026
This Privacy Statement explains how Trofsof Group B.V. processes personal data when you use Komby, including the Komby mobile app, getkomby.app, and related services.
We consider it important that you understand what data we process, why we do so, how long we retain it, and what rights you have.
This English text is a translation of the Dutch original for convenience. In the event of any inconsistency, the Dutch version prevails.
1. Who is responsible for your personal data?
The controller for Komby is:
Trofsof Group B.V.
Bargelaan 200
2333 CW Leiden
The Netherlands
Chamber of Commerce (KvK) number: 95131396
Email: [email protected]
Where this Privacy Statement refers to "Komby", "we", "us" or "our", this means Trofsof Group B.V., unless the context indicates otherwise.
2. Who is Komby intended for?
Komby is intended only for people aged 18 and over.
People under 18 may not create an account or use Komby.
Where we have reasonable grounds to believe a user is under 18, we may restrict, block or delete the account.
If you suspect that a minor is using Komby, you can report this at [email protected].
3. What personal data do we process?
The data we process depends on how you use Komby.
3.1 Account data
We may process, among other things:
- name;
- email address;
- date of birth;
- age;
- internal user ID;
- account status;
- authentication provider;
- account creation date;
- technical authentication data.
An account can be created, among other things, via:
- email address;
- Google;
- Sign in with Apple.
Authentication is supported via Firebase Authentication.
Where you use Google or Apple, we may receive data that the relevant provider shares with us according to your settings, such as your name and email address.
We do not receive your Google or Apple password.
4. Profile data
Depending on what you add we may process:
- name;
- profile video;
- video thumbnail or poster frame;
- any legacy profile photos;
- bio;
- occupation;
- location;
- intent, such as romance, friendship or networking;
- profile prompts;
- profile preferences;
- verification status;
- other information you voluntarily add to your profile.
Some of this information is visible to other Komby users.
We do not give other users direct access to your exact GPS coordinates.
5. Profile videos and media
Komby is a video-first platform.
Profile videos are stored via Firebase Storage / Google Cloud Storage within the infrastructure of the Komby Firebase project.
Profile videos are linked to the user's account.
Komby may perform technical operations necessary to:
- store media;
- play media;
- generate thumbnails;
- moderate media;
- make media securely available.
We do not sell your profile videos to third parties.
6. Automated moderation of photos and videos
To make Komby safer, uploaded profile media is subject to automated safety review.
For images Komby may use Google Cloud Vision SafeSearch.
For profile videos, representative frames may be extracted from the video and automatically checked for potentially explicit or unsafe content.
Where automated systems classify content as inappropriate or prohibited with sufficient likelihood, we may:
- automatically delete the file;
- flag the account for review;
- create a moderation record;
- place the case in our administrative moderation queue with high priority;
- perform a human review;
- take further measures where necessary.
Automated moderation is not error-free.
Where automated moderation is not technically available or fails to detect content, that content can still be investigated via user reports.
Komby therefore uses both automated moderation and human moderation and user reports.
7. Location data
Komby uses location data to be able to show users in a relevant geographic area.
Where you consent, Komby may use the location services of your device.
Your device may initially provide an accurate GPS location.
Before location coordinates are written to the profile in our database, Komby reduces the precision of the coordinates to two decimals.
As a result no exact GPS location is stored, but a location area with a precision of roughly around one kilometre, depending on the geographic position.
This location is used, among other things, to:
- calculate distances between users;
- filter Discovery results;
- find relevant profiles within a certain distance.
Other users do not receive your exact GPS coordinates.
You can manage location access through your device settings.
If you turn off location access, location-dependent Komby features may be limited.
8. Compatibility Quiz
Komby may ask you to complete a Compatibility Quiz.
The answers are linked to stable internal question and answer identifiers and may be stored with your user profile.
The answers are used to analyse compatibility between users.
Compatibility data may relate to, among other things:
- values and priorities;
- communication style;
- social preferences;
- lifestyle;
- emotional preferences;
- handling of disagreements;
- future expectations;
- connection intent.
The Compatibility Quiz is not intended as a medical, psychological or diagnostic test.
9. Special categories of personal data
Komby is not designed to require special categories of personal data such as medical records, political views or religious beliefs in order to provide the basic service.
Nevertheless, information a user voluntarily provides may in certain circumstances reveal information that is considered a special category of personal data under the GDPR.
We ask users not to share sensitive information that is not necessary to use Komby.
Where a future Komby feature deliberately requires the processing of special categories of personal data for which explicit consent is legally required, we will seek that consent separately.
10. Compatibility Score and artificial intelligence
Komby uses automated processing to analyse compatibility between users.
This may involve comparing Compatibility Quiz answers and related profile information of two users.
For certain AI functionality Komby uses technology from Anthropic.
This technology may be used for, among other things:
- compatibility analysis;
- reasoning behind a compatibility score;
- expanded paid Compatibility Reports;
- personalised conversation icebreakers.
Compatibility results are intended as an aid.
A score such as 87% compatibility is not a guarantee that two people will:
- experience attraction;
- have a successful relationship;
- be safe for each other;
- be suited to each other;
- actually put the same values into practice.
A Compatibility Score is not a medical, psychological or professional assessment.
Komby does not use Compatibility Scores to make decisions that have legal consequences for a user.
11. Deep Compatibility Insights
Komby may offer paid, more detailed compatibility analyses.
Where a user purchases such a report, existing compatibility data and quiz answers may be used to generate additional explanation.
This may include, for example:
- strongest similarities;
- potential differences;
- communication insights;
- conversation starters;
- possible points of attention.
AI-generated information may be incomplete or incorrect and should not be treated as professional advice.
12. Discovery and recommendations
Komby determines which profiles are shown in Discovery on the basis of various factors.
These may include, among other things:
- location and distance;
- configured distance;
- intent;
- user preferences;
- block status;
- eligibility;
- availability;
- compatibility.
Not every factor need carry the same weight.
The precise operation of Discovery may be changed to improve Komby, prevent abuse and deliver more relevant results.
13. Connections and connection requests
When you send or receive a connection request, we process data about:
- sender;
- recipient;
- date and time;
- intent;
- request status;
- acceptance or rejection;
- active connection;
- related compatibility data.
Komby may limit the number of simultaneous active connections as part of the product model.
14. Messages
Komby enables communication between certain connected users.
Chat messages are stored server-side in Firebase Firestore.
Komby chat is currently not end-to-end encrypted.
Messages are protected by technical access rules that determine which accounts have access to a conversation.
Connections to our infrastructure are protected in transit and Google provides infrastructure security for stored data.
Nevertheless, this does not mean that only the sender and recipient can technically access the readable content.
Authorised systems or personnel may gain access where necessary, for example, for:
- security;
- legal obligations;
- investigation of serious abuse;
- technical support;
- enforcement of our Terms.
15. Push notifications
If you allow push notifications, we may process technical identifiers necessary to deliver notifications.
Komby uses for this:
- Firebase Cloud Messaging;
- Apple Push Notification Service.
You can manage push notifications through your device settings.
16. Reports and blocks
Komby users can block and report other users.
For a report we may process, among other things:
- reporter ID;
- reported user;
- reason for report;
- any additional notes;
- date and time;
- related content;
- moderation status;
- moderation decision.
Where you block someone, technical data about that block may be processed to prevent you from encountering each other again in relevant parts of the service or sending each other messages.
17. Safety and moderation retention
To prevent repeated abuse, ban evasion, fraud and serious safety violations, we may retain limited moderation and enforcement data for longer than regular profile data.
Where content or an account has breached our rules, limited data about that breach and the measure taken may be retained for up to 24 months after the relevant moderation decision or account termination.
We aim to retain no more data than reasonably necessary.
Where possible, we retain only a limited enforcement record instead of the full original content.
Certain information may be retained longer where necessary for:
- compliance with a legal obligation;
- an ongoing investigation;
- protection against serious fraud or abuse;
- a lawful claim;
- the establishment, exercise or substantiation of legal claims.
18. Payments
Komby may offer paid digital functionality.
Depending on the feature, platform and available payment method, a payment may be processed, among other things, via:
- Apple In-App Purchase / StoreKit;
- Stripe.
For certain in-app digital purchases, Apple may perform payment processing.
In that case Komby does not receive your full payment card details.
For certain permitted web or other payment flows, Stripe may process payment data as an independent or separate controller/processor as the circumstances require.
19. Technical and operational data
To operate and secure Komby, technical data may be processed, such as:
- IP address;
- device or platform data;
- app version;
- server logs;
- error logs;
- security events;
- authentication events;
- push token;
- time of technical actions.
Komby currently does not use a general third-party product analytics service such as Google Analytics, Mixpanel, Amplitude or PostHog.
We may generate aggregated or internal operational statistics for our own management and product monitoring.
20. Crash data
Komby currently does not use a separate service such as Firebase Crashlytics or Sentry.
Apple may, at platform level, make aggregated crash and diagnostic information available to us, subject to Apple's settings and services.
21. Why do we process personal data?
We process personal data, among other things, to:
- create and manage accounts;
- authenticate users;
- apply age restrictions;
- display profiles;
- make profile videos available;
- operate Discovery;
- calculate distance;
- calculate compatibility;
- provide AI compatibility functionality;
- enable connections;
- enable messages;
- process purchases;
- send push notifications;
- moderate content;
- process reports and blocks;
- combat fraud and abuse;
- secure our systems;
- investigate technical issues;
- comply with our legal obligations;
- establish, exercise or defend legal claims.
22. Legal bases
Depending on the purpose, we process personal data on the basis of one or more of the following legal bases.
Performance of the contract
Where data is necessary to provide the Komby service to you.
This may apply, for example, to:
- account management;
- profile;
- Discovery;
- connections;
- messaging;
- compatibility functionality.
Consent
Where consent is required by law.
This applies, for example, to access to your device's location services.
You can always withdraw consent.
Withdrawal does not have retroactive effect.
Legitimate interest
We may process personal data where necessary for a legitimate interest and your interests or fundamental rights do not override that interest.
This may relate, for example, to:
- security;
- fraud prevention;
- abuse detection;
- enforcement;
- protection of other users;
- limited operational improvement.
Legal obligation
We may process or retain data where legally required.
23. Service providers and recipients
We do not sell your personal data.
To provide Komby, we may use external service providers.
Google / Firebase / Google Cloud
Among other things for:
- authentication;
- Firestore database;
- cloud storage;
- Cloud Functions;
- Firebase Cloud Messaging;
- media safety analysis;
- infrastructure.
Anthropic
For certain AI functionality, including compatibility analysis, reports and icebreakers.
We limit the data sent to AI services to what is reasonably necessary for the feature in question.
Apple
Among other things for:
- Sign in with Apple;
- App Store distribution;
- In-App Purchases;
- push notifications;
- platform services.
Google Sign-In
For authentication where you choose to sign in with Google.
Stripe
For certain payment flows.
In addition, personal data may be provided where this is:
- legally required;
- necessary in response to a valid order;
- necessary for safety;
- necessary to protect against fraud;
- necessary for legal proceedings.
24. International data transfers
Some service providers may process personal data in countries outside the Netherlands or outside the European Economic Area.
Where personal data is transferred outside the EEA, we take appropriate measures where legally required.
Such measures may include, for example:
- an adequacy decision;
- Standard Contractual Clauses;
- other lawful transfer safeguards.
We aim to configure core infrastructure EU-first where practically possible, but we do not guarantee that every processing operation takes place physically only in the Netherlands.
25. Security
We take appropriate technical and organisational measures to protect personal data.
These measures may include, among other things:
- access control;
- Firebase Security Rules;
- encrypted network connections;
- infrastructural encryption at rest;
- limited administrative access;
- media moderation;
- block and report systems;
- logging of security events;
- automated cleanup processes.
However, no system is completely secure.
We therefore cannot guarantee absolute security.
26. Deleting your account
You can delete your account from within Komby via the settings.
Where you request account deletion, we start deleting or anonymising personal data linked to the account.
A lot of data is technically deleted almost immediately.
However, to account for distributed systems and technical processes, we apply the following maximum time frames.
Active production systems
Personal data is deleted from active production systems as soon as possible and no later than within 30 days, unless we are lawfully required or permitted to retain certain information longer.
Backups
Copies may temporarily remain in secured backups.
This data is not intended for normal product use and is deleted or overwritten in accordance with the backup lifecycle.
The maximum period is in principle 90 days.
Safety and enforcement data
Limited moderation or enforcement data may be retained for up to 24 months as described above.
Legal exceptions
Certain data may be retained longer where this is necessary due to:
- legislation;
- tax obligations;
- payment administration;
- fraud;
- a safety investigation;
- legal claims.
27. Your rights under the GDPR
Depending on the circumstances, you have under the GDPR, among other things, the right to:
- access;
- rectification;
- erasure;
- restriction of processing;
- data portability;
- object to certain processing;
- withdraw consent;
- information about certain automated processing;
- protection against certain decisions based solely on automated processing.
A request can be submitted via [email protected].
We may ask for information that is reasonably necessary to confirm your identity.
We handle requests within the statutory time limit.
28. Objection to processing
Where processing is based on our legitimate interest, you may object in certain circumstances on grounds related to your specific situation.
We will then assess the processing in accordance with the GDPR.
29. Automated decision-making and profiling
Komby uses profiling in a broad sense because data and preferences may be analysed to, for example:
- personalise Discovery;
- calculate compatibility;
- rank profiles.
Komby's compatibility and Discovery functionality is not intended to make solely automated decisions that have legal consequences for you or similarly significantly affect you.
Where we introduce such decision-making in the future, we will apply the additional statutory safeguards.
30. Lodging a complaint
You have the right to lodge a complaint with a supervisory authority.
In the Netherlands that is the Autoriteit Persoonsgegevens.
You are of course also welcome to contact us first so we can investigate your question or complaint.
31. Links and external services
Komby may link to third-party websites or services.
Those parties may apply their own privacy policies.
We are not responsible for the privacy practices of independent external services.
32. Changes to this Privacy Statement
We may amend this Privacy Statement where:
- Komby changes;
- new functionality is added;
- our data processing changes;
- law or regulation changes.
In the case of material changes we inform users in an appropriate manner.
The date at the top of this Privacy Statement indicates when this version was last updated.
33. Contact
For privacy questions, requests or complaints you can contact:
Trofsof Group B.V.
Bargelaan 200
2333 CW Leiden
The Netherlands
Chamber of Commerce (KvK): 95131396
Email: [email protected]