Project AG Privacy Policy

Effective Date: June 13, 2026. Version 1.4.0.

This Privacy Policy describes how S8 Investment Holdings, LLC ("Project AG", "we", "us", or "our") collects, uses, shares, and protects personal information when you use the Project AG mobile application and any related websites, APIs, communications, and services (collectively, the "Service").

Project AG is a travel-companion social application that connects adult travelers visiting the same destinations. Because we operate in this category, we process information that is sometimes sensitive — including precise travel plans, photographs, and identity-verification data. This Policy is designed to be clear about exactly what we do with it, and to comply with the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") and the other comprehensive U.S. state privacy laws listed in Annex B. The Service is currently offered only to users in the United States; state-specific terms appear in dedicated annexes at the end of this Policy.

You must be 18 or older to use the Service. We do not knowingly collect personal information from anyone under 18. See Section 9.


1. Who is the controller of your personal information?

The data controller (or, where applicable, the "business" under CCPA/CPRA) responsible for your personal information is:

2. The personal information we collect

We collect personal information in three ways: (a) information you provide directly, (b) information generated by your use of the Service, and (c) information from limited third parties (for example, your phone carrier when you receive an SMS one-time passcode, or Apple/Google when you sign in).

2.1 Information you provide

2.2 Information generated by your use of the Service

2.3 Information we receive from third parties

2.4 Sensitive categories of personal information

Some of the information you choose to share is treated as "sensitive personal information" under CCPA/CPRA and the other U.S. state privacy laws listed in Annex B: (i) biometric data processed transiently by Persona for identity verification, (ii) precise geolocation, (iii) the contents of your communications, and (iv) information you may volunteer in your bio or messages about your health or sexual orientation. We process these categories only with your consent, given through specific in-app prompts at the point of collection, and only for the limited purposes permitted by Cal. Civ. Code §1798.121 (see Annex A). You can withdraw consent at any time as described in Section 11. Withdrawing consent for identity verification means we cannot continue to provide the Service to you and your account will be deactivated.

3. The purposes for which we process your personal information

The table below sets out our purposes and the categories of data involved.

3.1 Operating your account and authenticating you

Categories: account identifiers, profile, device data. Purpose: to deliver the Service you have requested.

3.2 Matching you with other travelers

Categories: profile, travel plans, location, activity. Purpose: to power the matching algorithm and surface candidate profiles based on your stated preferences.

3.3 Sending you transactional and service notifications

Categories: account identifiers, activity. Purpose: service-essential notifications (e.g., new matches, message receipts, subscription renewals). Marketing or promotional push notifications are sent only with your consent, which you can withdraw at any time in Settings → Notifications.

3.4 Identity verification and fraud prevention

Categories: identity-verification data (including biometric data processed by Persona), device data, IP address. Purpose: to confirm that an account belongs to a real adult person and to protect the community from impersonation, romance fraud, and account-takeover attacks.

Persona processes the biometric template under a Data Processing Addendum signed with us. We instruct Persona to delete the biometric template and the source ID images on a fixed retention schedule (see Section 7). We do not use Persona's output to make automated decisions that produce legal or similarly significant effects on you (see Section 12 on automated decision-making).

3.5 Safety, moderation, and enforcement

Categories: photos, messages, reports, activity, device data. Purpose: to keep the community safe, to enforce our published Community Guidelines, and to comply with mandatory reporting obligations (for example, reporting of child sexual abuse material to the National Center for Missing & Exploited Children).

Photo moderation is performed by Amazon Web Services, Inc. ("AWS") via the Amazon Rekognition service. Rekognition returns a category-by-category confidence score (for example, "Explicit Nudity", "Violence"). A human moderator on our trust-and-safety team reviews any photo flagged by Rekognition before it is removed from circulation, except in the case of CSAM, where we follow mandatory reporting procedures.

3.6 Billing and subscription administration

Categories: account identifiers, subscription metadata. Purpose: to administer your subscription and to maintain tax and accounting records as required by law.

3.7 Customer support

Categories: communications, account identifiers, device data. Purpose: to respond to your support requests efficiently.

3.8 Analytics and product improvement

Categories: device data, activity, performance metrics. We use this data on an aggregated, pseudonymized basis to understand which features work and where the Service has bugs. We do not use this data to build advertising profiles of you, and we do not sell or rent it to third parties. You may opt out of non-essential analytics at any time in Settings → Privacy.

3.9 Legal and regulatory compliance

Categories: any data necessary to comply with applicable law, and to establish, exercise, or defend legal claims.

4. The third parties with whom we share personal information

We share personal information only with the categories of recipient listed below, and only to the extent strictly necessary for the purpose stated. We do not sell or rent your personal information to data brokers, advertising networks, or any other third party for monetary or non-monetary consideration. We do not "share" your personal information for cross-context behavioral advertising as that term is defined under CCPA/CPRA.

4.1 Service providers (processors)

Each of these providers is bound by a written data-processing agreement that imposes confidentiality, security, sub-processor, and cross-border-transfer safeguards. An up-to-date sub-processor list is available on request from privacy@s8projectag.com.

4.2 Other Project AG users

Profile information you mark as visible — your photos, first name, age, bio, interests, and current trip — is shown to other adult users of the Service for matching purposes. Your phone number, email address, exact home address, and identity-verification status are never disclosed to other users. Your verification badge (a generic indicator that you have passed identity verification) is shown if you have completed the optional verification flow.

4.3 Law enforcement and legal process

We will disclose personal information to law-enforcement, courts, regulators, or other public authorities when we are compelled to do so by valid legal process (such as a subpoena, warrant, or court order issued by a court of competent jurisdiction), or where we believe in good faith that disclosure is necessary to (a) protect the safety of any person, (b) investigate or prevent fraud or security incidents, or (c) comply with applicable law. Where the law permits us to notify the affected user before disclosing, we will do so.

4.4 Corporate transactions

If Project AG or substantially all of its assets are acquired by, merged with, or transferred to another entity, personal information may be transferred to the acquirer subject to the same protections set out in this Policy. We will notify you of any change in controller and, where required, provide an opportunity to object.

5. International transfers of personal information

Project AG is operated from the United States. All personal information we collect is processed in the United States by our service providers, who are bound by data-processing agreements that impose contractual safeguards on confidentiality, security, sub-processor approval, and breach notification.

6. How we protect your personal information

We implement and maintain technical and organizational measures designed to protect personal information against unauthorized or unlawful access, disclosure, alteration, loss, or destruction. These include:

No security measure is perfect. If you become aware of a security issue affecting Project AG, please report it to security@s8projectag.com.

7. How long we keep your personal information

We retain personal information only for as long as necessary for the purposes for which it was collected.

You can delete your account at any time from Settings → Account → Delete account in the app. Deletion is irreversible.

8. Tracking, advertising identifiers, and cross-context behavioral advertising

Project AG does not display behavioral advertising inside the app and does not "sell" or "share" personal information for cross-context behavioral advertising under CCPA/CPRA or any other U.S. state privacy law. We do not participate in the IAB Transparency and Consent Framework.

Global Privacy Control (GPC). We honor browser- and OS-level opt-out preference signals, including the Global Privacy Control (GPC), as a valid request to opt out of "sale" and "sharing" for purposes of CCPA/CPRA and the analogous opt-out rights under the Colorado Privacy Act, Connecticut Data Privacy Act, and the other U.S. state privacy laws listed in Annex B. Because we do not sell or share personal information for cross-context behavioral advertising in the first place, the GPC signal is acknowledged automatically and no further action is required from you.

Apple's App Tracking Transparency (ATT) prompt is shown only if we ever introduce a feature that would require it; today, we do not access the Identifier for Advertisers (IDFA) and we have not enabled any such feature. If this changes, we will update this Policy and obtain your explicit ATT consent before processing the IDFA.

Our marketing website (when launched) uses only strictly-necessary first-party cookies. We do not deploy advertising cookies or third-party trackers on our website.

9. Children

Project AG is intended for adults aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact privacy@s8projectag.com and we will delete the information promptly. We comply with the Children's Online Privacy Protection Act (COPPA) in the United States.

10. Cookies and similar technologies

The Project AG mobile application does not use HTTP cookies. The app does use local on-device storage (UserDefaults, Keychain, and an encrypted Core Data store) to maintain your session, cache your profile, and store your preferences. This data is local to your device and is removed when you uninstall the app.

When we operate a marketing website, it will use only the strictly-necessary cookies required to deliver the page (e.g., session and CSRF tokens). A separate cookie notice will be published at that time.

11. Your privacy rights

Subject to the U.S. state in which you reside, you have some or all of the following rights with respect to your personal information. To exercise any of these rights, contact us at privacy@s8projectag.com or use the in-app tools described below. We will respond within the timeframes required by applicable law (in California, 45 days, extendable by 45 days; in other U.S. states with comprehensive privacy laws, generally 45 days). We will not discriminate against you for exercising any of these rights.

Many of these rights can be exercised directly in the app:

We may need to verify your identity before fulfilling a rights request, particularly for access, portability, and deletion. We will use the minimum data necessary to do so — typically a confirmation code sent to the phone number or email on file.

12. Automated decision-making and profiling

We use automated systems in two places:

If you would like to contest the outcome of any automated decision, or request human review, contact privacy@s8projectag.com.

13. Data-breach notification

In the unlikely event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant state regulator and the affected users without undue delay, in accordance with applicable U.S. state breach-notification laws (including Cal. Civ. Code §1798.82).

14. How to contact us, and how to complain

If you have a question about this Policy or wish to exercise a right, please contact us first at privacy@s8projectag.com. We are committed to resolving complaints directly.

If you are not satisfied with our response, you have the right to lodge a complaint with a regulator:

15. Changes to this Policy

We may update this Privacy Policy from time to time. The "Effective Date" and "Version" at the top of the document indicate when this Policy was last revised. If we make material changes, we will notify you in the app at least 14 days before the change takes effect, and (where required by law) ask you to acknowledge the new Policy. Older versions are available on request from privacy@s8projectag.com.


Annex A — California, United States (CCPA / CPRA)

This Annex supplements the Policy if you are a California resident. Capitalized terms have the meaning given in the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, the "CCPA").

Categories of personal information collected, sources, purposes, and disclosures. In the preceding 12 months we have collected the categories listed in Cal. Civ. Code §1798.140(v): identifiers; customer-records information; commercial information (subscription transactions); internet or network activity information; geolocation; sensory information (photographs and, transiently, biometric identifiers via Persona); inferences (matching signals); and sensitive personal information (precise geolocation, account log-in credentials in transit, contents of communications). Sources, purposes, and disclosures are as described in Sections 2–4 of this Policy.

Sale and "sharing" of personal information. We do not sell personal information and we do not share personal information for cross-context behavioral advertising, as those terms are defined in the CCPA. We have not done so in the preceding 12 months.

Sensitive personal information. We use sensitive personal information (notably, photographs, precise geolocation, biometric identifiers transiently processed for verification, and the contents of your communications) only for the limited purposes permitted by Cal. Civ. Code §1798.121 and the implementing regulations, namely: to provide the services you have requested; to detect security incidents; to verify or maintain the quality of the service; and to comply with law. You have the right to limit our use of sensitive personal information; write to privacy@s8projectag.com to exercise it. We will action a verified request within 45 days (extendable by 45 days for complex requests).

Rights of California consumers. You have the right to know, the right to delete, the right to correct, the right to limit use of sensitive personal information, the right to opt out of sale/sharing (we do neither), the right to portability, and the right not to receive discriminatory treatment for exercising any of the foregoing. To submit a request, email privacy@s8projectag.com. Authorized agents may submit requests on your behalf with proof of authorization. We honor browser- and OS-level Global Privacy Control (GPC) signals as a valid opt-out request — see Section 8.

Retention. As described in Section 7 of this Policy.

"Shine the Light" (Cal. Civ. Code §1798.83). We do not disclose personal information to third parties for their direct-marketing purposes.

Annex B — Other U.S. State Privacy Laws

If you are a resident of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MTCDPA), Iowa (ICDPA), Delaware (DPDPA), New Hampshire (NHDPA), New Jersey (NJDPA), Tennessee (TIPA), Minnesota (MCDPA), or Maryland (MODPA), you have rights of access, correction, deletion, portability, and to opt out of "targeted advertising", "sale", and certain forms of "profiling" in furtherance of decisions producing legal or similarly significant effects. We do not engage in any of these practices. To exercise an applicable right, email privacy@s8projectag.com.


Document identifier: privacy-policy. Version 1.4.0. Effective 2026-06-13. Locale en-US. Authoritative version.