Tab for Two
Privacy Policy
Last updated
Tab for Two turns your bank transaction history into a small set of coarse lifestyle signals, and uses those signals to suggest people you might get along with. This policy explains exactly what that means for your data.
1. Who we are
Tab for Two is an iPhone dating app for adults in the United States. This policy covers the app and this website. We do not currently offer the service outside the United States, and you must be 18 or older to use it.
Tab for Two is operated by a very small team. A single operator is responsible for security and privacy and handles privacy requests directly.
| Operator | NUBEEM, Inc. |
| Notice address | 103 Ames Ave, Leonia, NJ 07605 |
| Privacy contact | jay.jung@nubeem.com |
2. Account identity
We never receive or store a password for Tab for Two. Sign-in is handled entirely by Apple or Google.
| What | Why | How long | Ever shared? |
|---|---|---|---|
| Apple ID from Sign in with Apple, including a private relay email if you hide your address | To create and authenticate your account. | Life of account; deleted when we carry out your deletion request. | No. |
| Google account identifier and email, if you sign in with Google | The same, as an alternative sign-in choice. | Life of account; deleted when we carry out your deletion request. | No. |
| Display name | Shown to people you match with or who appear in your Likes list. | Life of account; deleted when we carry out your deletion request. | Yes — visible to other members. |
| Date of birth | To confirm you are 18 or older and to apply age-range filtering. | Life of account; deleted when we carry out your deletion request. | No. We never show it. Age filtering happens on our servers. |
| Short bio | Shown on your profile. | Life of account; deleted when we carry out your deletion request. | Yes — visible to other members. |
| Gender, and the orientations you are open to | To build a candidate list that makes sense for you and for the people we show you. | Life of account; deleted when we carry out your deletion request. | Only your gender, and only if you turn on the show-gender setting. Your orientation is never shown to anyone. |
| Age range preference | To filter who can appear as a candidate, in both directions. | Life of account; deleted when we carry out your deletion request. | No. |
| Distance preference | Stored as your stated preference. We do not currently apply it, because we hold no location data to measure distance against. | Life of account; deleted when we carry out your deletion request. | No. |
3. Financial data from Plaid
Connecting a bank account is optional, and we use Plaid to do it. You can use the app without connecting a bank, though the personalized parts will stay empty until you do.
We never see or store your bank username, password, or MFA codes. You enter those directly into Plaid. Plaid returns an access token to us; that token is encrypted before it is stored, and our database has no column capable of holding it in plain text.
| What | Why | How long | Ever shared? |
|---|---|---|---|
| Plaid access token and bank/institution identifiers | To keep the connection alive and fetch transactions on your behalf. | Until you disconnect or delete; deleted when we carry out your request. | No. Never leaves our servers. |
| The complete transaction payload Plaid returns, stored as an encrypted archive | So we can re-derive your signals later without asking your bank for your history again. | Until you disconnect or delete; deleted when we carry out your request. | No. Excluded from the app, analytics, logs, error reports, and any AI processing. |
| A narrow approved subset of each transaction: merchant name and identifier, amount, currency, date, pending status, category, account identifier | To derive your lifestyle signals, and so you can export your own transaction history. | Until you disconnect or delete; deleted when we carry out your request. | No. Merchants and amounts are never shown to another member. |
| Account name, official name, a mask of up to four characters, and account type | So you can tell your connected accounts apart. | Until you disconnect or delete; deleted when we carry out your request. | No. |
We do not collect your account balances, your full account number, or your routing number. These are not merely withheld from storage — we never ask your bank for them. We request transaction history only, and the code that writes account and transaction records rejects the entire request if any field outside the approved list appears.
4. Derived signals
These are what we compute from your transactions. They are the actual product, and they are deliberately coarse.
| What | Why | How long | Ever shared? |
|---|---|---|---|
| Taste signals — a category family such as quick bites or wine and drinks, a strength value, and the window it was measured over | To describe your habits to you, and to score how well they line up with someone else's. | Recomputed daily; deleted when we carry out your deletion request. | Only after you confirm a signal. Unconfirmed signals are never shown to another member. |
| Brand suggestions — a brand name Plaid identified, its category family, and a rank | To let you say that a place is genuinely yours, so it can become part of how you are described. | Recomputed daily; deleted when we carry out your deletion request. | Only after you confirm it. Held privately until then. |
| Neighborhood suggestions — a broad City, ST label and a rank | To weight candidates who spend time in the same broad area. | Recomputed daily; deleted when we carry out your deletion request. | Only after you confirm it. Held privately until then. |
| Candidate scores and your Keep or Pass decisions | To generate your daily candidates and to remember who you already decided on. | Life of account; deleted when we carry out your deletion request. | No. Scores are never shown to anyone, including you. |
Three things here are enforced in our database rather than merely promised:
- We do not store how many times you went somewhere, when you went, the venue, the street address, or coordinates. The tables holding your neighborhood and brand suggestions have no columns for any of it, and automated tests assert their absence.
- A signal is private until you confirm it. Derived signals start in a privately suggested state, nothing reaches another member's screen until you approve it, and this fails closed — if we are unsure, we show nothing.
- Scoring and display are separate. To rank your daily candidates we compare your signals to theirs, including signals you have not yet confirmed. The result is a single number. The unconfirmed signals themselves are never displayed to anyone, and neither is the number.
- We exclude sensitive categories entirely. Political, religious, health, gambling, adult, and luxury or discount spending categories are blocked at the point a signal is derived. We do not infer or match on protected or sensitive characteristics.
5. Photos
| What | Why | How long | Ever shared? |
|---|---|---|---|
| The original photos you upload, up to six, including any camera metadata such as GPS coordinates embedded by your phone | So we can produce the stylized version shown on your profile, and so you can manage your gallery. | Life of account; deleted when we carry out your deletion request, unless preserved for an open safety report or legal hold. | Originals stay in private storage and are not readable by any member — not even by you, once uploaded. |
| A stylized halftone version of each photo | This is what other members actually see. | Life of account; deleted when we carry out your deletion request. | Yes — this is your public profile image. |
| The result of an automated safety check on each photo | To keep prohibited images off the service before they are ever visible. | Life of account; deleted when we carry out your deletion request. | No. |
Photos taken on a phone often carry embedded metadata, sometimes including the exact coordinates where the picture was taken. We keep that metadata on the private original, because stripping it would quietly destroy evidence we may need for a safety investigation. We remove it from the stylized version other people can see. The copy visible to another member carries no location metadata, and the copy that carries it is visible to no member.
Safety screening runs on your device before an image is published, and we do not use your photos to train any model.
6. Device, notifications, and diagnostics
| What | Why | How long | Ever shared? |
|---|---|---|---|
| A push notification token for your device, and which install, environment, and app build it belongs to | So we can tell you about a new match, a first message, or a bank connection needing attention. | Until you log out, the token is replaced, or you delete your account. | Sent to Apple and Google push infrastructure to deliver the message. Nothing else. |
| Crash and error reports | To find and fix bugs that break the app. | Per our error reporting provider's retention settings. | No. |
| Product analytics about which features are used | To understand what works and what does not. | 12 months. | No. |
Notification text comes from a fixed set of pre-approved templates. We never put a merchant name, an amount, a personal trait, a location, or the contents of a message into a notification, because a notification can appear on a locked screen.
We ask for your location once, during sign-up, and we keep your time zone — not your position. The app asks for “while using the app” location so it can work out which time zone you are in, because your daily candidates arrive on your local morning and we will not ask you to pick a time zone off a list. The coordinate is used inside a single reverse-geocode call and never leaves that step: it is not stored on your device, not sent to our servers, and not written to any log. What we store is a time zone name such as America/New_York, and nothing more precise. The neighborhood signal above is a separate thing and still comes from your transaction data, not from your phone.
Diagnostics are deliberately stripped. Our crash reporter is configured not to send personal information and to scrub request bodies, headers, and query strings; screenshots, view hierarchies, attachments, and session replay are off across the entire app. Our analytics never receives your email, gender, orientation, financial categories, or neighborhood. Financial, chat, photo, and report screens record only the route name.
7. What we do not do
This is a commitment, not a summary.
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We never have. Under California law you may opt out of sale or sharing; there is nothing to opt out of, because we do not do it.
- We do not show other members your merchants, amounts, balances, transaction history, or how often you go anywhere. Other members see confirmed coarse signals, never the underlying evidence.
- We do not send marketing email. The only email we send is a verification code when you connect a bank, plus essential account and security messages. Open and click tracking is turned off.
- We do not store your bank login credentials. We never receive them.
- We do not use the content of your messages for anything beyond delivering them. Chat content is not used to build your signals, is not used for matching, and is not sent to analytics.
- We do not put your personal data into AI or large language model systems. Raw transactions, photos, message content, and report evidence are prohibited from any such processing.
- We do not infer or match on sensitive or protected characteristics.
- We do not track you across other companies' apps and websites.
8. Third parties, and why each one exists
We use a small number of vendors, each because it does something we cannot responsibly build ourselves. None may use your data for their own advertising.
| Vendor | Why it exists | What reaches it |
|---|---|---|
| Supabase | Our database, authentication, file storage, and server functions. | Everything described above, under the access controls in section 10. Hosted in the United States. |
| Plaid | The bank connection itself. Plaid, not us, handles your bank credentials. | Your credentials go to Plaid directly and never to us. Plaid returns transactions to us, and its own handling is governed by Plaid's end user privacy policy. |
| Apple | Account sign-in, and the option to hide your real email address. | Your Apple ID and, if you choose, a private relay email address. |
| Alternative account sign-in. | Your Google account identifier and email, only if you choose this option. | |
| Resend | Sends the verification code required before connecting a bank, plus essential account email. | Your email address at the moment of sending. The code is never stored in readable form, and tracking is disabled. |
| Firebase Cloud Messaging and Apple Push Notification service | Delivers push notifications to your phone. | A device token and a pre-approved template identifier. No message content, no merchant, no amount. Firebase Analytics is not enabled. |
| Sentry | Crash and error reporting. | Scrubbed, de-identified error events, configured to exclude personal information. |
| PostHog | Product analytics. | De-identified usage events from an approved list. Never your email, gender, orientation, financial categories, or neighborhood. Hosted in the United States. |
| RevenueCat | Subscription management, if you subscribe. | Your subscription status and a pseudonymous identifier. Apple processes your payment; we never see your card. |
| Cloudflare R2 | Encrypted off-site backups. | Encrypted database and file backups. |
| Vercel | Hosts this website. | Standard web request data for the marketing and legal pages. This site needs no account and carries no app data. |
We may also disclose information where legally required, or where necessary to investigate a safety report, prevent fraud, or protect someone from harm. If we are ever part of a merger or acquisition, we will tell you before your information becomes subject to a different policy.
9. Your rights
If you live in California, the CCPA and CPRA give you the rights below. We extend the same rights to everyone using Tab for Two, anywhere in the United States. We will not discriminate against you for exercising them — using these rights will never degrade your matches, your visibility, or your subscription.
| Right | What it means here |
|---|---|
| Know and access | You can ask what we hold about you and receive a copy. |
| Export | You can download your own transaction history — merchant, exact amount, date, account mask, category, and exclusion status — as CSV or JSON. Your Plaid token, our internal scores, and the raw provider archive are excluded, because they are not meaningfully yours to read and exporting them would create new risk. |
| Delete | You can delete your account. Deletion starts immediately and cannot be undone. |
| Correct | You can fix your display name, bio, date of birth, identity and preference settings, and photos. |
| Opt out of sale or sharing | We do not sell or share your personal information, so there is nothing to opt out of. We offer no financial incentives for your data. |
| Limit use of sensitive information | We use your financial data only for the signals described above and for your own export, and we exclude sensitive categories from those signals entirely. |
| Authorized agent | You may use an authorized agent. We will ask for proof of authority and verify your identity directly. |
In the app: most of these are settings, not requests. You can edit your profile, identity, and preferences, add or remove photos, and disconnect a bank at any time. Deletion and export are both there too, under Account on your own tab, and both ask you to prove it is you first — we email you a code and you enter it, and that permission is good for that one request only.
By email: you can always write to jay.jung@nubeem.com and ask. We will verify the request genuinely comes from you — normally by confirming you control the account's sign-in — before acting, because acting on an unverified deletion or export request would itself be a privacy failure. We respond within 45 days, and will tell you if we need the extension the law allows.
When you delete your account, your account is disabled and your profile stops being shown immediately; your bank connection is revoked at Plaid; and your raw transactions, encrypted provider archive, derived signals, photos, and profile are permanently deleted seven days after you ask. This is a physical deletion, not a flag, and it includes the image files behind your photos, not only the database rows that pointed at them. Encrypted backups age out within 30 days. In any conversation you were part of, you appear to the other person as a deleted member.
We do not keep a copy of your data under a different identifier so it can be reattached to you later. That is prohibited outright. Three narrow exceptions, stated honestly:
- We may retain the minimum evidence needed for an open safety or fraud investigation, kept separately with its own purpose and expiry.
- We retain aggregate statistics that cannot be traced back to any individual.
- Our servers keep short-lived technical receipts confirming that your bank notified us of an update, deleted within 30 days once handled and within 90 days otherwise. They record that an event happened for a bank connection, and contain no name, email, merchant, amount, or transaction.
10. Security
We do not treat encryption in transit and at rest as a complete answer, so here is what we actually do.
- Encryption in transit and at rest. All traffic uses TLS, and our database and file storage are encrypted at rest by our infrastructure provider.
- Envelope encryption for financial data specifically. Your Plaid access token and the complete provider payload are encrypted with AES-256-GCM before being written, bound to your specific environment, bank item, and sync cursor. Our schema physically cannot hold a plaintext access token — the column does not exist, and an automated test proves both that it does not exist and that a plaintext token is rejected.
- Default-deny database access. Every server-side table has row level security enabled and forced with no access policies at all, which denies every role including the table owner. Your own tables let you read only your own rows. No permission of any kind is granted to anonymous or public database roles. More than a thousand automated assertions switch to a real user role and prove another user's data is unreachable.
- A verification step before bank linking. Before you can connect or reconnect a bank we send a six-digit code to your verified sign-in email and require it. The code expires in five minutes, is single-use, is rate limited, and is never stored in readable form — only a keyed digest is kept for comparison. You cannot supply your own destination address; the server resolves it.
- Amounts are reduced before they are used. The process that derives your lifestyle signals never receives the amount itself, only whether it was money in or money out. The exact figure stays inside the database.
- Separation, not just encryption. Raw provider payloads live in a different table from the approved fields we use, so isolated data — original descriptions, exact locations, account and routing details — cannot exist as readable columns in the path everyday queries touch.
- Sessions stay on your device. Your session is stored in the iOS Keychain in a way that does not sync to iCloud and does not travel to another device through a backup.
- A minimal supply chain. Our server functions have zero third-party imports, and every dependency the app uses is pinned to an exact version.
No system is perfectly secure and we will not claim otherwise. If you find a security problem, please email jay.jung@nubeem.com.
Routine access to your raw financial data, photos, and messages is not available to anyone through a normal administrative screen. There is no administrative export of your transactions — the only way raw transaction data leaves our systems is when you export it yourself.
11. Children
Tab for Two is for adults aged 18 and over. It is a dating service and is not directed to children. We ask for your date of birth during sign-up and reject any date that would make you under 18; this check is enforced by the database itself, not only by the app.
We do not knowingly collect personal information from anyone under 18. If we learn that someone under 18 has created an account, we will terminate it and delete the data. If you believe a minor is using Tab for Two, email jay.jung@nubeem.com and we will act.
12. Changes and contact
If we change this policy in a way that materially affects you, we will update the date at the top of this page and notify you in the app before the change takes effect. We will not apply a materially different use to data we already collected from you without asking you first.
For privacy questions and requests, email jay.jung@nubeem.com, or write to NUBEEM, Inc., 103 Ames Ave, Leonia, NJ 07605.