Privacy policy

Last updated 10 September 2026

Who we are

LINK is operated by Thena Holdings Limited (company number 17091225), registered at The Dye House, Thunderbridge, Kirkburton, Huddersfield HD8 0PU. We are the data controller for the personal data described here.

For anything about your data, contact hello@findyourlink.co.uk.

We are not affiliated with, endorsed by, or connected to the University of York or York St John University.

What this app is

LINK introduces University of York and York St John University students to each other, either for dating or to find study partners. You choose which. It is for adults only — you must be 18 or over.

What we collect, and why

When you sign up: your email address, a password (stored by our authentication provider as a hash — we never see it), and your date of birth.

Your date of birth is used to check you are 18 or over and to show your age to other users. Your actual date of birth is never shown to anyone else — other users only ever see your age in years. It cannot be changed after sign-up, because it is what our age check relies on.

Your profile: display name, course, year of study, college, a short bio, your module codes, your interests, answers to a few personality questions, and one to four photos. You also choose which modes you appear in and whether you are discoverable in each.

If you use dating mode: your gender and which genders you want to see. Together these can reveal your sexual orientation, which UK data protection law treats as a "special category" needing extra protection. We ask for it only because dating mode cannot work without it, we use it only to decide who sees whom, and you can turn dating mode off at any time, which stops us using it for matching.

If you say you belong to a society: which societies you tell us you are in. This is personal data in its own right, and for some societies it is more than that: a faith society, a political society, an LGBTQ+ society or a disability network can reveal your religion, political opinion, sexual orientation or health, which UK data protection law treats as a "special category" needing extra protection. Joining a society never tells anyone you joined it: for each society separately, you choose whether other members of that society can see you're one of them, that choice is off by default, and you can switch it off again at any time — we stop showing it to anyone else immediately. We do not verify that you actually belong to any society you say you're in; see "Who else sees your data" for exactly what a switched-on membership shows, and to whom.

How you use the app: who you have liked or passed on, who you have matched with, who you have blocked, and any reports you make. Likes and passes are never shown to the person concerned unless you both like each other.

If you check in at a venue on the Mini Map: which venue, and when. To check in, the app asks iOS for your location once, only while you are using it, and sends that one position to our server to confirm you are actually at the venue. The position itself is not stored — only the fact of the check-in is: you, the venue, the time. Other users only ever see check-ins as counts ("5 in town", "9 check-ins this week"), never as names, and never at all until enough different people have checked in that nobody could be identified from the number. We do not track your location at any other time, and the map works without location: if you say no, you can still browse every venue.

Your profile insights. You can see which of your own photos and prompts people react to most. This is shown only as a comparison between your own things — never a number, never a name, and nothing at all until enough people have reacted that no single person's reaction could be identified from it. We do not tell you who liked you, or how many people did.

If you chat with a match: the messages you send and receive, stored for as long as the match exists. We also record when you last opened each conversation, so the app can show you which messages are unread — that timestamp is private to you and is never shown to the other person, and it is not a read receipt: the other person cannot tell whether or when you have read what they sent.

Automatically: we do not use advertising identifiers, analytics SDKs, or tracking of any kind. We do not track you across other apps or websites.

Verifying your identity

You can choose to get a verified tick. To do it, you photograph a form of ID and take a selfie, and both images are sent to a verification partner to check that the face matches, and that the name and date of birth on the ID match your account.

We do not keep either image. They go to the verification partner and we receive only the result — whether you passed — and an internal reference to that check. LINK never stores your ID document or your selfie.

A check of your face against a document is biometric data, which UK data protection law treats as a special category needing extra protection. We use it only to verify you, only when you ask, and it is never shown to anyone. Verification is optional — the app works fully without it — and the name on your ID is used only for the check and is never displayed on your profile.

Automated content screening, and AI features

Text you write — your bio, your questionnaire answers and any interest tags you add yourself — is sent to a third-party AI provider to be checked for unsafe content before it is published. Content that fails the check is rejected and never appears on your profile. A human does not review this decision. If your text is rejected and you think that is wrong, email us and we will look at it.

The app also offers optional AI features:

Your photos are sent to the AI provider to be checked before anyone else can see them. A photo you upload is visible only to you until that check passes; if it does not pass, we tell you why and it is never shown to anyone. As with text, a human does not review this decision — if you think it is wrong, email us and a person will look at it.

We do not send your email address or your date of birth to the AI provider.

Our AI provider is Mistral AI, a French company. Your data is processed in the European Economic Area, not the United Kingdom. The UK recognises the EEA as providing adequate protection, so this transfer needs no additional safeguard from you or from us.

We are completing the data-processing agreement with Mistral, and we will not accept real users until it is in place.

Your photos

Photos are stored privately. They are not on a public URL and cannot be found by guessing an address. When someone is allowed to see your profile, the app generates a temporary link that expires after about an hour. Photos are visible only to people who can already see your profile in a mode you have both enabled, and never to anyone you have blocked.

Who else sees your data

We do not sell your data. We do not share it for advertising. We have no advertisers.

How long we keep it

We keep your profile while your account exists. When you delete your account, your profile, photos, likes, matches, messages, questionnaire answers and check-ins are deleted along with it.

Check-ins are kept for seven days and are then deleted, whether or not your account still exists. Nothing reads one older than that — "this week" is the longest window the map ever shows.

Reports you have made about other users, and records of moderation action, are kept for 12 months from the date the report was made, and are then deleted. They outlive the accounts involved, so that deleting an account does not destroy the record of what was reported. Those records keep the reported account's identifier and the display name it used at the time. They do not let us recognise someone who deletes their account and signs up again with a new email — we hold nothing that would link the two.

When you report someone, we keep a copy of your conversation with them. It is taken at the moment you file the report and stored with it, so that we can actually review what you are telling us about. This includes messages that would otherwise have been deleted: a Casual chat closes 48 hours after you match and its messages are removed, but a copy of one you have reported is retained with the report, and is deleted with it after 12 months. We keep only the conversation between you and the person you reported — not their conversations with anyone else.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or send it to another service. You can object to processing based on our legitimate interests, and you can withdraw consent for dating-mode data at any time by turning dating mode off, or for a society by turning its visibility off — in both cases we stop straight away.

To exercise any of these, email hello@findyourlink.co.uk. We will respond within one month.

If you think we have handled your data badly, you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first.

Children

This service is for adults. You must be 18 or over to use it, and we block sign-ups with a date of birth under 18. We do not knowingly hold data about under-18s; if you believe we do, email us and we will delete it.

Our website, and the waitlist

Everything above is about the app. This section is about findyourlink.co.uk itself, including the waitlist, the shop and the advertising pages. One document, because one company runs both and you should not have to read two.

If you join the waitlist. We store your email address, so we can tell you when LINK opens; your phone number, if you gave us one (it is optional); your place in the queue and your referral code, so the queue has an order and your link works; which poster or link you came from (the src and utm_* tags in the address, if any), which tells us the posters in the library did better than the ones in Derwent and nothing about you; the referral code of whoever invited you, so we can move them up the queue; and the date you joined. That is the entire list. No IP address is stored against your record, no device fingerprint, no profile.

We email you once, when LINK opens, and text you once at the same time if you gave a number. That is the whole purpose. No newsletter, no selling or sharing the list, no advertisers. Legal basis: your consent, given by submitting the form, withdrawable at any time through the one-click unsubscribe in the email or by emailing us. We keep the list until we have sent that message and for no more than six months after; if launch is called off we delete it and tell you; if you unsubscribe or ask, we delete your row.

Measurement. We count what happens on the site (visits, pages, which posters worked, shop orders, advertising bookings) with our own measurement, on our own domain. Nothing is loaded from anyone else: no Google Analytics, no tag manager, no advertising trackers, no social media pixels. For each page view or action we keep the time, the page's address on this site and what happened; whether the device was a phone or a computer, not which one; the country the request came from, not anywhere finer; an order or booking amount where there was one; and a scrambled version of a random session id, so two clicks in one visit count as one visitor. The id is random, lives only until you close the tab, and the scrambling key changes daily, so we cannot tell that today's visitor is yesterday's. We never record your IP address, precise location, browser fingerprint, email or any account identity, and the system refuses values shaped like those even if sent by mistake. Nothing in it identifies you, which is why there is no cookie banner. Legal basis: our legitimate interest in measuring our own site, which we can rely on precisely because the data identifies nobody.

Opting out of measurement. The switch on this page turns it off for this browser: the counting script sends nothing and our server ignores anything it might still receive. It works by setting one cookie, optout=1, which covers all of findyourlink.co.uk for five years; clearing your cookies clears it. With JavaScript off, the script never runs and the site sends nothing at all.

Your choices need JavaScript to show here. With it off, nothing is on and nothing asks.

Cookies and local storage. The site sets at most three cookies, all its own: optout=1 above, which tells us to leave you alone; lc, which records the two choices above (a version, two yes/no answers and a date — nothing else); and, only if you said yes to being remembered, lid, the random id. Measurement itself sets no cookies. The site uses your browser's own storage for two small things: which poster you arrived from, so it survives a tap through to the download page, and the measurement session id, which disappears when you close the tab. Both stay on your device.

Purchase records. If you buy from the shop or book advertising, we keep a record of the purchase: what was bought, when, for how much, the payment reference Stripe gives it, and the email address you paid with. That is what lets us fulfil the order, answer a question about it, and honour a refund. Legal basis: the contract you made with us when you bought. We also look at those records together — which surfaces someone has bought from, how much over time — to understand who our customers are. Legal basis: our legitimate interest in running a business that sells things, which involves no cookie, no tracking and nothing from outside our own records. You can object to that use at any time by emailing hello@findyourlink.co.uk, and we will stop. If your app account and a purchase share an email, we treat them as one person; that is the whole extent of it. We keep financial records for six years, as HMRC requires. Asking us to erase you does not delete the record of a sale — it removes you from it: the order stays, with nobody attached, and everything else we knew you by goes.

Erase your purchase data. Enter the email you paid with and we will send one email with one link. Open it within 24 hours and you are removed from every purchase record we hold, along with any consent, identity or journey data attached to you. We do not say on this page whether we hold anything for an address — the email is the answer, and only its owner gets it. Three requests an hour per address.

Who else sees website data. Cloudflare hosts the site, the waitlist database and the measurement data, as our processor; like every web host its servers log requests, including IP addresses, for security and uptime, and we do not join those logs to your waitlist entry or to the measurement data. Our email provider sends the one launch message. No measurement data leaves our own systems. Your rights over website data are the same as over app data, above, and the same email address answers both.

Changes

If we change this policy in a way that affects you, we will tell you in the app before the change takes effect.