Privacy Policy

Who we are

Our website address is: https://2within.com.

2Within is operated by Adriano James Piras, the controller responsible for your personal information. For privacy questions, data requests or the exercise of your rights, contact hello@2within.com

Contact email: hello@2within.com

This policy explains how we handle personal information when you request access, use your account, complete questionnaires, share results, or use other available features.

2Within is intended exclusively for adults aged 18 or over.

Information we collect

Account and access information

When you request access or create an account, we process information such as your name, username, email address, date of birth, age confirmation, preferred language and any message you submit. We also record information about account approval and acceptance of applicable community rules.

WordPress stores your account password in hashed form.

Questionnaire answers and results

We process the information you enter into your Compatibility Profile, including ratings, preferences, boundaries, experience indicators, interests, notes, skipped-answer reasons and activities you mark for further exploration.

We also process questionnaire progress, D/s Profile answers, saved results and summaries generated from your answers.

This information may reveal details about your sex life, sexual orientation or other sensitive personal matters.

Information shared between members

When you share or import a profile, we process the shared answers, results and associated comments needed to provide the comparison.

Other members may provide information relating to you through shared profiles, messages or safety reports. Please avoid including unnecessary identifying or sensitive information about other people.

Dating and messaging information

Where these features are available and you choose to use them, we process the profile information you provide, which may include photographs, age, gender, location, biography, relationship intentions and partner preferences.

We also process relevant waitlist entries, discovery settings, likes, passes, matches, messages, timestamps, read status and notification preferences.

Support and safety information

We process correspondence sent to us, blocking choices, safety reports and information needed to investigate concerns or administer the service.

Technical information

The website and its hosting infrastructure process technical information needed to deliver and protect the service. This may include IP addresses, browser information, request times, requested pages and error records.

The access-request system also uses a hash derived from an email address and IP address to limit repeated submissions.

Why we use your information

We use personal information to:

  • Assess access requests and administer accounts.
  • Check eligibility for the service.
  • Save your answers and allow you to continue across devices.
  • Generate preference summaries and compatibility comparisons.
  • Provide sharing, Dating and messaging features that you choose to use.
  • Send account, password-recovery and relevant service notifications.
  • Respond to enquiries and privacy requests.
  • Investigate reports, prevent misuse and protect members.
  • Meet applicable legal obligations.

Information required for account creation and age eligibility is necessary to obtain access. Leaving optional information unanswered may limit the completeness of your results or access to particular features.

Legal grounds and sensitive information

For ordinary account information and requested functionality, we rely on taking steps at your request or performing our agreement with you under Article 6(1)(b) GDPR.

For proportionate security, administration and abuse prevention, we may rely on legitimate interests under Article 6(1)(f), taking account of your rights and expectations.

Where a specific legal obligation requires processing, we rely on Article 6(1)(c).

Processing information about your sex life or sexual orientation for questionnaire analysis, related profiling and optional sharing requires explicit consent, under Articles 6(1)(a) and 9(2)(a). Reading this policy, confirming your age or accepting Community Guidelines does not itself provide that consent.

You may withdraw consent by contacting hello@2within.com. Withdrawal does not affect processing that was lawful before withdrawal. Features dependent on the withdrawn consent will no longer be able to use the relevant information.

Where sensitive information must be processed for another purpose, such as a legal claim, an applicable special-category condition is required in addition to an ordinary legal basis. Legitimate interests alone are insufficient.

How results and comparisons work

2Within uses rules and scoring to generate summaries from your answers, including preference measures, Erotic Style descriptions and partner comparisons.

Comparisons take account of complementary roles, such as giving and receiving. Strong interest, boundaries and unanswered or skipped questions are treated differently.

This involves profiling of preferences. Results are intended to support personal reflection and communication. They are not medical diagnoses, guarantees of compatibility, or permission to engage in an activity.

Eligibility and feature availability may also depend on age, profile completion, launch availability and moderation status.

Sharing your results

Your detailed questionnaire is not intended to be publicly searchable. However, when you share a result code or link, an eligible recipient can retrieve the information available through it.

Shared profiles can include your answers and written comments, not only summary scores.

An active sharing code may remain usable over time, and the information accessible through it may change when you save newer results. Treat codes and links as confidential.

Recipients may retain imported results, take screenshots or download information. Changing a code or deleting your own result does not necessarily remove copies already obtained by another person.

Contact us about personal information retained within another member’s account. We will assess the request under applicable data-protection requirements. We cannot remotely erase screenshots or files held outside the service.

If you generate a shareable image, it is downloaded to your device. You decide whether to distribute it. The generated summary image does not include the detailed private notes contained in your full profile.

Where Dating discovery is available and enabled, selected profile information and approved photographs may be visible to eligible members. Detailed questionnaire answers are separate from the ordinary Dating profile.

Who can access your information

Information may be accessed by:

  • Members to whom you make information available through sharing, Dating or messaging.
  • Authorised administrators where needed for operation, support, security or moderation.
  • Hosting, email and other necessary infrastructure providers.
  • Professional advisers or competent authorities where disclosure is necessary and legally justified.

We use DreamHost to host the website. WordPress email delivery is configured through WP Mail SMTP, which passes outgoing messages to the configured email service for delivery. Email processing includes recipient addresses, message content and delivery information.

Service-provider access does not make your questionnaire publicly available. However, the service is not end-to-end encrypted, and authorised access to server-side information remains technically possible.

International processing

Our hosting provider, DreamHost, is based in the United States. Hosting and related support may therefore involve processing outside Italy and the European Economic Area.

Transfers subject to GDPR require an appropriate transfer mechanism and any necessary supplementary safeguards. DreamHost’s Customer Data Processing Addendum includes Standard Contractual Clauses.

You may contact us for information about the safeguards applicable to your data and how to obtain a copy, subject to appropriate redaction.

Cookies and browser storage

WordPress uses cookies to support login, authentication and protected sessions. Their duration depends on the login options and site configuration.

The twowithin_lang cookie remembers your language preference for up to one year.

The application also uses browser local storage to retain language preferences and application state, including questionnaire answers and saved partner information. Session storage helps remember navigation state.

Local browser data may remain after you close the browser or log out. It is not protected by the application-level encryption used for selected server records.

On a shared device, use a separate browser profile or private browsing and clear site data when finished. Clearing browser storage does not delete your server account or copies already shared with others.

Blocking cookies or browser storage may prevent login or affect saving and other functionality.

How long we retain your information

Our retention schedule is based on the purpose of each category of information.

  • Active accounts and profiles: retained while the account remains active and the information is needed for the features used, subject to earlier deletion or withdrawal requests.
  • Inactive accounts: deleted after 12 consecutive months without a successful login or deliberate authenticated use. Background polling, receiving emails and another member viewing your results do not count as activity. A reminder is sent approximately 30 days before deletion.
  • Pending access requests: retained for up to 90 days after submission.
  • Rejected or withdrawn access requests: retained for up to 30 days after closure, normally no later than 90 days after submission.
  • Approved access-request forms: deleted within 30 days after account creation. Necessary account and age-confirmation information remains with the account.
  • Saved Compatibility Profile results: up to ten snapshots per account. Saving another replaces the oldest. Account-deletion rules also apply.
  • Sharing records: retained while needed for the active sharing function. Account closure ends further retrieval through its codes.
  • Imported partner results: retained until removed, the receiving account is deleted, or an applicable erasure or withdrawal request requires their removal.
  • Dating waitlist entries: retained while membership remains active, then removed within 30 days after leaving the waitlist or obtaining Dating access.
  • Messages: retained for no more than 12 months after each message is sent, subject to earlier applicable deletion.
  • Likes and passes: retained for up to 90 days. Separately created matches remain while active and are removed within 30 days after ending.
  • Removed or rejected photographs: removed from live storage within 30 days.
  • Blocking records: retained while needed to maintain the block, normally until it is removed or either account is deleted.
  • Routine safety reports and moderation records: retained while the case is open and for up to 12 months after resolution.
  • Ordinary support correspondence: retained for up to 12 months after resolution.
  • Routine technical and email-delivery logs: retained for up to 30 days.
  • Minimal consent and privacy-request records: retained while needed to administer the account and for up to 12 months after withdrawal, closure or resolution.
  • Website and database backups: retained on a rolling basis for up to 30 days from creation.

Open support and safety cases are reviewed periodically to avoid unnecessary retention.

Specific information may be retained longer where necessary for a legal obligation or an active legal claim. Such retention must be limited, justified and subject to restricted access.

Deleted information may remain in restricted backups until they expire. If a backup is restored, completed deletion requests must be reapplied before normal processing resumes.

Server-side retention does not automatically remove copies stored on your device or independently downloaded by another member.

How we protect your information

We use HTTPS, account access controls and application-level encryption for selected stored information, including questionnaire state, result snapshots and message content.

Other information, including account records and certain operational or Dating fields, is stored separately and is not covered by the same application-level encryption.

The server holds the means to decrypt encrypted records. Encryption does not eliminate all administrative or infrastructure access, and no online service can guarantee absolute security.

Please protect your login details and share result codes only with people you intend to receive the information.

Your privacy rights

Subject to applicable conditions, you may request:

  • Access to your personal information.
  • Correction of inaccurate information.
  • Erasure of information.
  • Restriction of processing.
  • Portability of information.
  • An objection to processing based on legitimate interests.
  • Withdrawal of consent.

Contact hello@2within.com to exercise these rights. We may request proportionate information to verify your identity.

We normally respond within one month. Where a lawful extension is necessary, we will explain the reason and expected timeframe.

You may complain to the Garante per la protezione dei dati personali, the Italian supervisory authority, or another competent supervisory authority. You do not need to contact us first. Information is available on the Garante’s website.

Account deletion and consent withdrawal

You may request account deletion or withdraw consent by emailing hello@2within.com. You do not need to wait for the inactivity period.

Please indicate whether your request concerns your entire account, questionnaire, sharing, Dating information or another specific category.

We aim to complete routine live-data deletion within 30 days after any necessary identity verification, subject to applicable legal requirements. We will explain any justified exception.

Deletion requests also require consideration of associated records and copies held within the service. Copies independently held by other people, such as screenshots or downloaded images, cannot be remotely erased by us.

External websites

Learning Guides and other content may contain links to external websites. When you follow a link, the destination website processes information under its own privacy practices.

Avoid providing personal or sensitive information to external services without checking how it will be handled.

Changes to this policy

We may update this policy to reflect changes in the service, processing practices or applicable requirements.

Material changes will be brought to members’ attention as appropriate. An updated policy does not itself authorise a new use of sensitive information or replace any consent required for that use.

For questions about this policy, contact hello@2within.com.