Nine improvements went live in the app today — safer, fairer, and clearer. No jargon below: every change is written the way you'd explain it to a friend, with a real-life example for each.
Dating apps ask people to trust strangers. These make that trust safer to give.

Photos taken on a phone often secretly store exactly where they were taken. Now, the moment someone uploads a photo, we strip that hidden information out before anyone else can ever see the picture.
It's like a camera quietly writing your home address on the back of every print. We now peel that label off before the photo ever leaves your hands.

Tap the green Verified badge and it tells you plainly: we confirm a person is who they say they are, but we do not run criminal background checks — so always meet in public.
Like the fine print on a "verified reviewer" tag. Tap it, and it's honest about what was and wasn't checked, so nobody assumes more safety than we actually promise.
When someone deletes their account, we make sure their paid subscription is cancelled and their videos are removed too — not only their photos.
Like closing a gym membership: walking out the door should also stop the monthly charge and empty your locker, not quietly leave either one behind.
Before an offer sends, we quietly check that you both fit what the other is looking for — the same rule the main browsing screen already followed.
Like a mixer where you can only pass a note to someone who is also open to meeting someone like you — so no one gets mismatched or unwanted offers.
Some iPhone users found the "use this clip" button stayed greyed out, so they could never add a profile video. That's fixed — and if a phone can't preview the clip, we simply keep the first 30 seconds instead of blocking them.
Like a "Submit" button that refused to light up no matter what you tapped. Now it lights up and works.
The app is meant to allow up to 6 profile photos. There was a gap where editing a profile could sneak in a 7th; we closed it, on the screen and behind the scenes.
Like a form that says "6 photos max" while the edit page quietly let a 7th slip through. Now it stops at 6 for everyone, politely.
Three changes so the numbers we look at reflect real members, not our own testing.
The "members by type / by gender" charts included people who signed up but never actually built a profile — so the totals were inflated.
Now the charts count only completed profiles, and we show a clear "Completed Profiles" number right next to total sign-ups.
We tagged all of our internal test profiles and added a simple switch: view "real members only," "test accounts only," or "everyone."
Like a store's sales report having a toggle to leave out the staff's own test purchases, so the real numbers stay clean.
Old "beta" labels have been cleaned out, so the app reads as the finished product it now is.
Like taking the "under construction" sign off a shop that's actually fully open for business.
Our nine internal demo and test profiles are now hidden from the live app, so real members only ever see real people.
These aren't app features — they're the "in case of emergency" procedures a real dating platform is expected to have. Both are drafts for the team to review with a lawyer. Read each once, keep it findable.
Because Greenlight hosts photos and chat, US law makes us — the operators — responsible for acting if this ever happens. This is the calm, step-by-step plan: lock the account (never delete — that would be destroying evidence), report it to the national CyberTipline, preserve everything for a year, keep it confidential, and log it.
Like the fire-evacuation plan posted on a wall. You hope to never use it, but when seconds matter you follow the steps instead of panicking.
If someone uploads a photo they don't own, this policy is what legally shields Greenlight — as long as we take reported material down. It sets up an official "copyright agent" (a $6, one-afternoon registration), the exact wording for our Terms of Service, and the steps to handle a takedown request.
Like the posted rules and a lost-and-found desk at a venue: because you have a clear, official way to handle complaints, you're not on the hook for what a guest brought in.
A quick, non-technical tour of what happens when someone opens Greenlight — told as if the app were a restaurant.
Instead of building a kitchen from scratch on Google's property, we pack our entire kitchen — the stove, the recipes, every ingredient the app needs — into one sealed, standardized box called a container. That box runs exactly the same way anywhere. We hand the box to Google, and Google plugs it in and runs it.
Cloudflare is fast and cheap at serving the website worldwide and shielding us. Google is great at running live code that does real work. We use each for what it does best. Cloudflare sits in front and only forwards the "real order" requests to Google — everything else it serves itself.
How the kitchen scales. Google's kitchen is elastic. If ten thousand people open the app at once, Google instantly clones our sealed kitchen-box to handle the rush, then puts the clones away when it's quiet — so we only pay for what we actually use, and never babysit a physical server.
How we stay in control. We hold the keys through our Google account. Any time we improve the app, we hand Google a fresh sealed box and say "run this version now" — and if anything looks wrong, we can switch back to the previous box in seconds. The sensitive keys (the database password, the payment keys) live in Google's locked safe and are slipped into the box only while it runs, never written on the outside.
Why it feels like one app. A member only ever sees one address — greenlightdate.com. They never know that some taps are quietly served by Cloudflare at the door while others are cooked by Google in the back. That seamless handoff is the whole trick.