Skip to content
Wisteria
  • Consent
  • Discover
  • The Scene
  • Safety
  • Pricing
Get the app
  • 01Consent
  • 02Discover
  • 03The Scene
  • 04Safety
  • 05Pricing
Get the app

18+ · Coming to iOS and Android

Legal

Privacy Policy

Wisteria is built for a community where being seen can carry real professional and family risk. This policy explains, in plain English, what we hold, who decides who sees it, and what we will never do with it.

Last updated 13 August 2026 Wisteria wisteriasocial.com

On this page

  1. The short version
  2. Who we are
  3. What we collect
  4. How we use it
  5. Consent and visibility
  6. What we never do
  7. Clubs, applications and tickets
  8. Verification
  9. Subscriptions and payments
  10. Safety and moderation
  11. Who we share with
  12. Deleting your account
  13. Your rights and choices
  14. How long we keep things
  15. Security
  16. International transfers
  17. This website
  18. Wisteria is 18+
  19. Changes to this policy
  20. Contact us
Please read this first

This policy describes Wisteria’s privacy practices for version 1 of the app at launch. Wisteria has not launched yet. We are publishing this now so that anyone considering the product — and anyone reviewing it — can read exactly what we intend to do before we do it. We will update this document as the product ships and as features change, and we will change the “last updated” date at the top when we do.

The short version

In plain English

We hold as little about you as we can get away with. Your phone number is your account. Your date of birth is used to check you are an adult and is never shown to anyone. If you ever give us a legal name, it never appears on any social part of the product. You decide what is visible, field by field, and any consent you give can be withdrawn at any time. We do not sell your data, we do not run ads, and we do not use what you post to target you.

This policy applies to the Wisteria mobile app for iOS and Android, this website, and the support channels we run at the email addresses listed at the end. It describes how Wisteria (“Wisteria”, “we”, “us”) handles information about you.

Who we are

Wisteria is operated by Wisteria, a company registered in the United States, at [Wisteria registered address]. For privacy questions, write to privacy@wisteriasocial.com.

Wisteria is a community platform for the ethically non-monogamous and lifestyle community. Members create a profile, follow people and venues, read a chronological feed, message one another, and — where a club has integrated with us — apply for membership and get tickets to that club’s events inside the app.

What we collect

In plain English

A phone number, a date of birth, whatever you choose to put on your profile, what you post and who you connect with, and the ordinary technical information any app needs to run. A legal name only if you choose to verify or to join a club — and it is never shown to other members.

Information you give us to have an account

  • Your phone number. It is how you sign in — there is no password. Wisteria has no passwords. You sign in with a one-time passcode sent by text, which means there is no password for us to store or for anyone to steal. We use your number to authenticate you and to send you those codes.
  • Your date of birth. We use it to confirm you are 18 or older — and, if you link a club membership, to match against the club’s own record of you. Your date of birth is never shown anywhere other members can see. Other members do not see it.
  • An optional legal name. We only ask for one if you choose to verify your identity, or if you link or apply to a club that needs to match you against its own records. If you never do either, we never ask, and the field stays empty. Your legal name is never shown anywhere other members can see it. Not on your profile, not in Explore, not in the feed, not in a message. Ever. Display names on Wisteria are always aliases you choose.

Information you choose to publish

  • Your profile. A display name, a bio, pronouns, identity and orientation selections, what you are looking for, and up to six photos. Every one of these fields has its own visibility switch, controlled by you.
  • What you post. Posts, photos, comments and appreciations, along with who they were shared with.
  • Your connections. Who you follow, who follows you, accepted relationships, and the shared cards (couples, throuples, wider groupings) you are part of. Follower and following lists are private per person by default.
  • Your messages. Chat requests, conversations, and their contents. We hold a record of who your messages were between, when they were sent, and what they say in order to run the service, respond to reports, and comply with law.
  • An approximate location, if you enable distance features. We store your location deliberately imprecisely — close enough for a rough distance, never close enough to point at your home — plus country and region. We do not store a precise location. Distance in discovery is worked out from that imprecise version only. For a product where “where do you live” is dangerous information, not holding it beats protecting it.

Information that comes from using the app

  • Event attendance. If you get a ticket to a club event through Wisteria and are checked in at the door by the club, that check-in is recorded and becomes part of a private attendance record. Attendance is only ever built from real check-ins going forward — we do not import historical attendance from clubs. You control whether your attendance is visible to others.
  • Subscription status. Whether you hold an active subscription, which store it came from, and when the current period ends.
  • Device and log data. Device model, operating system version, app version, language, IP address, crash reports, and timestamps of requests. We use this to keep the service running, to secure accounts and sessions, and to investigate abuse.
  • Sessions. A record of the devices signed in to your account. You can see every one of them in the app and end any of them.

How we use it

We use the information above to do these things and nothing else:

  1. Sign you in, keep you signed in, and let you end sessions you no longer want.
  2. Confirm you are 18 or older.
  3. Show your profile, posts and shared cards to exactly the people you have allowed to see them.
  4. Build the feed — everything from everyone you follow, newest first.
  5. Power discovery, including the filters and trust rings you choose.
  6. Deliver chat requests and messages, and let you decline or block.
  7. Show club pages and events, hand off applications and ticket purchases to the club, and display the tickets you hold.
  8. Check whether your subscription is active — that is the only question we ask of it: “does this member have access.”
  9. Investigate reports, run integrity checks, and enforce our Terms and Community Guidelines.
  10. Send you service messages such as one-time passcodes, ticket confirmations and notifications you have opted into.
  11. Meet legal obligations, and keep the records law requires us to keep.

Where the law requires a legal basis (for example in the EU and UK), we rely on performance of a contract for running the service you signed up for, consent for optional things like identity verification and location features, legitimate interests for security, abuse prevention and service improvement, and legal obligation for the records we are required to keep.

Consent and visibility

In plain English

Nothing about you appears anywhere because someone else agreed to it. A shared card — a couple, a throuple, a wider grouping — is visible only while every single person in it is currently saying yes. Any one of you can say no at any time, and the card is gone on the next screen anyone loads. Nobody is told whose switch moved.

Visibility on Wisteria is four independent decisions, each owned by one person, each revocable without collapsing the others.

  1. You. Every identity field on your profile carries its own visibility switch, and you alone control it. Privacy defaults are conservative: where a control can sensibly default to more private, it does.
  2. A relationship. A relationship between two people is mutually accepted and deliberately untyped — there is no primary or secondary label built into the system. Each side independently holds two separate things: a willingness (“I am happy to list you on my profile”) and a permission (“you may list me on yours”). Display requires both, and the permission always wins. If you withdraw permission, nobody can name you on their profile, no matter how willing they are.
  3. A shared card. A couple or group card is discoverable only if every current member of it has said yes. Withdraw your yes and the card leaves discovery immediately — without ending the relationship, without deleting anything, and without telling the other people which switch changed. Your own individual card is unaffected: declining to appear as a couple is not declining to exist.
  4. Everywhere you appear. Discovery, profiles, the feed, chat, events and club pages all read from the three layers above rather than keeping their own copy. Each of them checks your current answers every time someone looks. None of them keeps an old copy, so turning something off takes effect the next time anyone opens the screen — no delay, nothing to wait for overnight.

Nothing cascades. Leaving a conversation does not leave the shared card. Hiding a card does not end a relationship. Ending a relationship does not delete history. Each switch does one thing and only that thing.

What we never do

  • We do not sell your personal information to anyone, for any price, in any form.
  • We do not use member data for advertising. Wisteria carries no ads, and we do not build advertising profiles or share data with ad networks or data brokers.
  • We do not import a club’s records about you. Identity information reaches us from you, never from a club. If you link an existing club membership, your details are compared against the club’s record at that moment — we do not receive or keep a copy of the club’s file on you.
  • We never show a legal name anywhere other members can see. Not on a profile, not in discovery, not in a feed, not in a message. Display names are aliases, always.
  • We never show your date of birth to other members.
  • We do not manufacture engagement. No fake likes, no fake view counts, no fake notifications, no bot accounts run by us.
  • We do not store precise location.
  • We do not sell, rent or trade your contact details for marketing by anyone else.

Clubs, applications and tickets

In plain English

When you apply to a club inside the app, you are filling in that club’s own form. Your answers go straight to the club. We never see them and never store them. When you buy a ticket, your card details go straight from your device to the club’s payment processor. Wisteria never touches the money and never sees a card number.

Membership applications

Some clubs integrate with Wisteria so that you can apply for membership without leaving the app. When you do, the form you fill in is the club’s own application form, presented inside our app. Everything you enter in it — including any identity details the club asks for — goes directly to that club. Those answers never enter Wisteria’s systems. We receive only the state of the application: that you applied, and later whether the club approved or denied it.

Tickets and dues

Clubs sell their own tickets. When you get a ticket in the app, the club’s own systems price it, take payment through the club’s own payment processor, and issue the ticket. Your card details are encrypted on your own phone by the club’s payment company and sent straight to them. Wisteria never sees a card number. Wisteria never receives a card number and never handles club money. Saved cards are held in the club’s payment vault, per club — there is no platform-wide Wisteria wallet.

What we do keep is a receipt: which event, which ticket type, the line items the club actually charged, and the ticket code you show at the door. If the club scans you in, we record the check-in.

What a club can see

A club sees what you send to it — your application, your ticket purchases, and your check-ins — and, if you are an approved member, the fact of that membership. A club does not get access to your Wisteria profile, your messages, your connections, or your activity elsewhere on the platform. Whether other members of a club can see you on that club’s member list is a switch you control, and it is off by default.

Verification

In plain English

Verification is optional. If you choose to verify with an ID document, a specialist provider checks it and tells us pass or fail. We keep the result and the date — not your document, not a photo of your face, not a biometric template.

Wisteria has two optional trust markers: ID-verified and club-verified. Neither is required. An unverified account is a full account — it can post, follow, discover, message and get tickets. What verification unlocks is mature content in direct messages and inclusion in other members’ verified-only filters.

ID verification is carried out by a third-party identity verification provider — [provider to be named at launch] — not by us. You submit your document to the provider, the provider performs the check, and we receive only the outcome: whether the check passed, whether it matched the name you gave us, and the date. We do not receive or retain a copy of your document, a verification selfie, or any biometric template, except where we are specifically required by law to retain something, in which case we keep it only for as long as that requirement lasts. The provider handles your document under its own privacy terms, which we will link from the verification screen in the app.

Biometric information

In plain English

If ID verification asks you for a selfie, that selfie is compared against your document by the verification provider — a process that may count as biometric under some state laws. Wisteria never receives or stores it. It is optional, you are asked first, and you can use Wisteria without ever doing it.

Some identity verification methods include a selfie or liveness check, where an image of your face is compared against the photograph on your document to confirm they are the same person. Depending on the method used, this may involve processing a facial geometry scan or biometric identifier within the meaning of state biometric privacy laws, including the Illinois Biometric Information Privacy Act and comparable statutes in Texas and Washington.

  • It is entirely optional. Verification is optional, and this step happens only if you begin it. An unverified account is a full account.
  • You are asked before it happens, on a screen that explains what is captured and who processes it. You give consent to the verification provider directly, under its own biometric policy, before any capture occurs.
  • Wisteria never receives it. We do not collect, capture, receive, store, or have access to your selfie, your facial geometry, or any biometric identifier or biometric information derived from it. We receive only pass or fail, whether the name matched, and the date.
  • We never sell, lease, trade, or otherwise profit from biometric information, and we never disclose it — we do not hold any to disclose.
  • Retention and destruction are the provider’s, governed by its published biometric retention schedule, which we will link from the verification screen. We ask our provider to destroy biometric data once the check is complete, and in any case within the period its governing law requires.

If you would rather not undergo a biometric check at all, you can simply not verify, or use club verification instead where your club offers it.

Changing your profile photo re-runs an identity check and the badge is withheld until it passes again.

Club verification carries no document at all. It means only that a club that has integrated with Wisteria has confirmed you are an approved member of that club. If that membership lapses, the marker drops.

Subscriptions and payments

The Wisteria subscription is sold and billed exclusively through the Apple App Store and Google Play. There is no web checkout anywhere in the product.

That means Apple or Google collects and holds your payment details, under their own privacy policies. Wisteria does not receive or store payment card details for subscriptions. What we receive from the store is a subscription receipt and status: that a subscription is active, which store it came from, when the current period ends, and whether it is set to renew.

Cancellation is handled by the store, not by us — see Support for how.

A member can cover a partner’s subscription, at a reduced rate, for someone they hold an accepted relationship with. The exact partner-seat price is [not yet set — founder decision] and will be shown to you in the app before you buy anything.

Safety and moderation

Report and block work everywhere in the app of the product — profile, post, comment, message, photo and chat request. When you report something, we keep the report, the content it points at, and the record of what we did about it, so that decisions are reviewable and repeat behaviour is visible. We commit to a 24-hour response time from report to resolution.

Because membership is open, we run automated integrity checks that look for patterns associated with image harvesting, accounts misrepresenting who they are, and scams. These checks compute signals from account activity and file anything above a threshold into a queue that a person reads. They never ban anyone automatically. A false accusation against a real member of this community is a serious harm, so a human always makes the final call.

Photos you post publicly are checked by an automated photo check so that our content rules can be applied consistently. Images shared in direct messages are checked on your device where the platform supports it, so that privately shared images are never leave your device for that check.

Automated and AI-assisted systems, and the permission we ask for

In plain English

Two of our safety systems are automated and use machine learning. One looks at photos you post publicly; the other looks at patterns in account activity. The photo check runs through an outside company, so we ask your permission separately before you post — it is not buried in the Terms. Neither system is used to profile you, target you, or train a general-purpose AI model.

We want to be specific about this, because “automated” can mean many things. Wisteria uses machine-learning-based classification in exactly two places:

  • Image content classification. An automated, AI-assisted photo check looks at photos you post publicly and returns a category — for example, whether an image appears to contain nudity — so our content rules are applied consistently rather than by mood. This runs through a third-party provider, which means the image is transmitted outside Wisteria for that check.
  • Integrity pattern detection. An automated, AI-assisted system looks for the patterns behind to spot likely image-harvesting, misrepresentation and scam patterns. This runs on our own infrastructure. Its only output is a place in a queue that a human being reads.

We ask for your explicit permission before any photo of yours is sent to the outside company that runs that photo check. This is a distinct, separate choice presented to you in the app — not something bundled into accepting the Terms of Service, and not a pre-ticked box. You are told what is being checked, who checks it, and why, and you choose. If you decline, you can still use Wisteria; you will not be able to post photos publicly, because we are not willing to publish unreviewed images to a community that trusts us to apply the rules. You can change this choice at any time in your privacy settings.

What we do not do with these systems. We do not use your content or your activity to train a general-purpose or third-party AI model. We do not send your direct messages to any third-party AI system. We do not use automated systems to build advertising or interest profiles — there is no advertising on Wisteria. And no automated system produces a final decision about your account on its own: every enforcement outcome is made by a person, and you can appeal it (see Your rights and choices).

Child sexual abuse material. Every image uploaded anywhere in the product is checked automatically against the standard industry databases of known illegal images. If a match is found we are legally required to report it and to preserve the associated records. Those records are held separately from the rest of our systems, under restricted access, for the period the law requires, and are removed when that period ends. This happens regardless of any deletion request.

Who we share information with

In plain English

Other members see only what your own settings allow. Clubs see only what you send them. A handful of companies we pay help run the service, and they cannot use your information for anything else. We do not sell anything to anyone — and there are no advertisers here to sell it to.

We share information only in these situations:

  • With other members, exactly as your own visibility settings allow — and never further.
  • With a club, when you apply to it, buy a ticket from it, or link a membership with it, and only what that action requires.
  • With service providers who run parts of the service for us under contract, and who may use the information only to provide that service to us. These are our cloud hosting and database provider, our text-message delivery provider (for one-time passcodes), the company that carries messages between members, our company that runs our automatic photo check (see Automated and AI-assisted systems), our error and crash reporting tools, and our identity verification provider if you choose to verify.
  • With Apple and Google, for subscription billing and for age-assurance signals their platforms provide.
  • Where the law requires it — in response to valid legal process, or where we are under a reporting duty. We will tell you about a legal request for your information unless we are prohibited from doing so or where doing so would put someone at risk.
  • To protect people — where we reasonably believe disclosure is necessary to prevent imminent physical harm.
  • In a business transfer — if Wisteria is acquired or merges, information may pass to the successor, who will remain bound by this policy or give you notice before anything changes.

Every service provider we use is contractually required to protect your information to at least the same standard this policy sets, to use it only to perform the service they provide to us, and never for their own purposes. A provider that will not agree to that does not get your data.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising — not to anyone, not for any price. There is no advertising on Wisteria, so there is nothing to sell it for.

We do not share member information with advertisers, data brokers, or analytics companies that would combine it with data from elsewhere.

Deleting your account

In plain English

Deleting your account erases you and detaches the things other people are part of. Your identity, your profile and your content are gone. A conversation you had with someone else does not vanish from their phone — it is simply no longer connected to you.

You can delete your account from inside the app at any time. You do not need to email us, and we will not ask you to explain why. If you would rather write to a person, send the request from the phone number on the account to privacy@wisteriasocial.com and we will handle it.

Deletion does two different things, deliberately:

  • Erased. Your identity details, your profile, your photos, your devices and your sessions. Gone — not hidden, not deactivated.
  • Detached, not erased. The things other people are part of: their copy of a shared conversation, their comments on your posts, and the shared record of who attended an event together. These stay, disconnected from you, because deleting everything a person ever touched would tear holes in other members’ own history. Someone should not lose their side of a conversation because the other person left.
  • Retained only where safety or law requires it, for a defined period per category. The clearest example is the preservation obligation described in Safety and moderation, which runs on its own legal clock regardless of what you request.

Deleting your Wisteria account does not cancel a store subscription. Cancel that through the App Store or Google Play — see Support.

Your rights and choices

Wherever you live, you can:

  • Access the information we hold about you.
  • Correct anything that is wrong — most of it directly in the app.
  • Delete your account and the personal information attached to it.
  • Export a copy of your information in a portable format.
  • Object to a particular use, or withdraw a consent you gave — for example, turning off location features or removing a verification.
  • End sessions on any device, from inside the app.

California residents

Under the California Consumer Privacy Act as amended by the CPRA, you have the right to know what personal information we collect and why, to access and delete it, to correct it, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of those rights. We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by California law, so there is no “Do Not Sell or Share” process to opt into — there is nothing to opt out of. Some of what we hold (your date of birth, and identity or orientation selections you choose to enter) may be “sensitive personal information” under that law; we use it only to run the service you asked for, never to infer characteristics for advertising. You may use an authorised agent to make a request; we will ask for proof of authorisation.

Other US states

If you live in a state with a comprehensive privacy law — Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and the others now coming into force — you have substantially the same rights described above: confirmation and access, correction, deletion, a portable copy, and the right to opt out of targeted advertising, sale, and profiling with legal or similarly significant effects. We do none of those three things at all, so there is nothing to opt out of. Where your state gives you the right to appeal a decision we make on your request, see If we say no below.

Nevada residents. Nevada law (NRS 603A) lets you tell a business not to sell certain personal information. We do not sell personal information to anyone, but if you want to submit a Nevada opt-out for the record, email privacy@wisteriasocial.com and we will log it.

Global Privacy Control. Where our website receives an opt-out preference signal such as Global Privacy Control, we honour it as a valid request to opt out of sale and sharing. In practice this changes nothing about what we do, because we do not sell or share personal information in the first place — but the signal is recognised rather than ignored.

EU, UK and other GDPR-style regimes

If you are in the EU, the UK, or another jurisdiction with equivalent law, you have the rights to access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests, and the right to withdraw consent at any time without affecting anything done before you withdrew it. You also have the right to complain to your local data protection authority. Wisteria is the controller of the information described in this policy. If we are required to appoint a representative in the EU or UK, we will name them here: [EU/UK representative — to be appointed].

How to exercise any of this

Most of it is a switch in the app. For anything else, email privacy@wisteriasocial.com from the address or phone number associated with your account. We will acknowledge within 7 days and respond substantively within 30 days, or tell you if we need longer and why. We do not charge for this.

If we say no — how to appeal

In plain English

If we refuse a request, we have to tell you why, and you can ask us to think again. A different person reviews it. If we still say no, we will tell you how to complain to your state.

Sometimes we have to decline a request — for example where we cannot reasonably verify that you are who you say you are, where the law requires us to keep something, or where acting would erase or expose another member’s information. If we decline, we will tell you which of those reasons applies.

You may appeal that decision. Reply to our response, or email privacy@wisteriasocial.com with the word Appeal in the subject line, within a reasonable period of our decision. The appeal is reviewed by someone other than the person who made the original decision. We will inform you in writing of the outcome, and our reasoning, within 45 days of receiving the appeal, or tell you if we need a permitted extension and why.

If we deny your appeal, we will give you a means of contacting your state Attorney General to submit a complaint, and you may also contact them directly. Nothing here takes away any right you have to complain to a regulator at any time.

How long we keep things

  • Account and profile information — for as long as your account exists, then erased on deletion.
  • Posts, comments and photos — until you delete them or delete your account.
  • Messages — until the conversation is closed by both sides or an account is deleted; other participants keep their own copy of the conversation, detached from you.
  • Raw door check-in records — kept for [retention period — founder decision], then discarded, leaving only the attendance record itself. The attendance record does not need years of raw scans, and we would rather not be holding them.
  • Moderation records — reports, decisions and account standing history are retained after deletion where they are needed to enforce our rules against repeat behaviour.
  • Security and access logs — a rolling [retention period — founder decision], then discarded.
  • Legal preservation records — for the period the law requires, and removed automatically when it closes.

Our full category-by-category retention schedule is [to be published at launch]. Where a period is not fixed by law, we keep information only as long as it is needed for the purpose it was collected for.

Security

Data is encrypted in transit and at rest. Access to production systems is limited to the people who need it and is logged. Sessions are per device and revocable by you. Because authentication is by one-time passcode, there is no password database to breach and no password reset flow to social-engineer.

Payment card details for club purchases never reach our servers, and payment card details for subscriptions never reach us at all, which keeps entire categories of risk outside our systems by design rather than by policy.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal information we will notify you and the relevant regulators as required by law, and we will tell you what actually happened.

International transfers

Wisteria is operated from the United States and our infrastructure is hosted there. If you use Wisteria from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection law from your own country. Where we transfer personal information out of the EU or UK, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable) together with additional safeguards where they are needed.

This website

This marketing website is deliberately simple. It sets no cookies, runs no analytics, no tracking pixels and no advertising tags, and there is nothing to sign up for here. Our web host records standard server logs, including IP addresses, for security and reliability. The only third-party request the site makes is to Google Fonts to load the two typefaces it uses; your browser’s request to that service is subject to Google’s own privacy policy. If you email one of the addresses on this site, we hold that correspondence in order to reply to you.

Wisteria is 18+

Wisteria is for adults only. It is not directed at anyone under 18, and anyone under 18 may not use it. We check age at signup using the age-assurance signals the app stores provide, together with the date of birth you give us. We do not knowingly collect information from anyone under 18. If we learn that an account belongs to someone under 18, we close it and delete the information. If you believe a minor has an account, tell us at safety@wisteriasocial.com and we will act on it immediately.

Changes to this policy

We will update this policy as Wisteria ships and changes. When we make a material change, we will change the “last updated” date at the top and give notice in the app before the change takes effect. If a change would require your consent, we will ask for it rather than assume it. Previous versions are available on request from privacy@wisteriasocial.com.

Contact us

A real person reads these addresses.

  • Privacy privacy@wisteriasocial.com
  • Support support@wisteriasocial.com
  • Safety safety@wisteriasocial.com
  • Legal legal@wisteriasocial.com
  • Post Wisteria, [registered address]
Terms of Service Community Guidelines Support
Wisteria

A community platform for the ethically non-monogamous.

Product

  • Consent
  • Discover
  • The Scene
  • Safety
  • Pricing

Legal

  • Privacy Policy
  • Terms of Service
  • Community Guidelines

Company

  • Support
  • Contact
  • Press

© 2026 Wisteria. All rights reserved.

wisteriasocial.com 18+