Last updated: April 2026
Match ("we", "us", "our") is the data controller responsible for your personal data. We are committed to protecting your privacy in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR). This app is intended for users aged 18 and over. We do not knowingly collect personal data from persons under 18. For data protection enquiries, contact our data controller at aaron.am.sc@gmail.com. As a small-scale data controller, we are not required to appoint a Data Protection Officer under GDPR Art. 37.
We collect and process the following personal data: • Account information: display name, email address, date of birth, gender, biography, and profile photos • Personality data: answers to a five-question personality questionnaire (shyness, indoor/outdoor preference, spontaneity, social energy, relationship seriousness, each rated 1-5) • Interests: categorised lists (e.g. Movies & Shows, Music, Books, Sports, Games, Food) including specific titles or items you select • Location data: GPS coordinates and/or city name (only when you grant permission) used exclusively for proximity-based matching • Matching preferences: desired age range, preferred genders, maximum search distance, match goal (friends / relationship / both), and important interest categories • Match interaction data: daily match results, like/pass decisions, and mutual-match status • Authentication data: Firebase UID and sign-in data provided by Google Sign-In • Push notification token: FCM device token stored to deliver match notifications (only if permission is granted; deleted on sign-out) • Subscription status: whether you hold an active premium subscription (no payment card data is stored by us; payments are handled by Google Play / Apple App Store) • Chat messages: text messages exchanged with your daily match. When end-to-end encryption is enabled, messages are encrypted on your device before being sent; we store only the encrypted ciphertext and cannot read message content. • Photos and images: profile photos and images shared in conversations. These may be encrypted at rest. • Match feedback: optional ratings you provide after a match interaction, including trait reactions and category reactions, used to improve future match quality • E2E encryption keys: a public encryption key is stored in your profile to allow your match to establish a secure channel. Your private key never leaves your device. • App settings: dark-mode preference and notification-enabled flag (stored locally on your device only; not sent to our servers)
We process your personal data based on: • Consent (Art. 6(1)(a) GDPR): You provide explicit consent when creating your account and granting location access. • Contractual necessity (Art. 6(1)(b) GDPR): Processing is necessary to provide our matchmaking services. • Legitimate interest (Art. 6(1)(f) GDPR): To improve our services and ensure platform safety.
Your personal data is used exclusively to: • Create and manage your user profile • Run our automated matchmaking algorithm to generate daily compatible matches based on interests, personality, location, and preferences • Display your profile information (name, age, bio, photos, interests, city) to your daily match • Record your like/pass decisions and notify you of mutual matches • Send push notifications about new matches (only if you grant notification permission) • Validate and manage your premium subscription via in-app purchases processed by Google Play / Apple App Store • Maintain account security and prevent fraudulent activity We do NOT sell, rent, or share your personal data with third parties for marketing purposes.
Your data is stored securely using Google Firebase services (Cloud Firestore and Firebase Storage) within the European Economic Area or under adequate safeguards as required by GDPR. We implement appropriate technical and organisational measures to protect your data against unauthorised access, alteration, or destruction. Where end-to-end encryption is enabled, message content is encrypted using AES-256-GCM before transmission and can only be decrypted by the conversation participants.
We retain your personal data only for as long as your account is active. When you delete your account, all personal data, including your profile, preferences, photos, and match history, is permanently deleted from our systems within 30 days.
As a data subject in the EU, you have the following rights: • Right of access: Request a copy of your personal data. • Right to rectification: Correct inaccurate data via the Edit Profile screen. • Right to erasure: Delete your account and all associated data at any time from the app menu. • Right to data portability: Request your data in a machine-readable format. • Right to restrict processing: Limit how we use your data. • Right to object: Object to processing based on legitimate interests. • Right to withdraw consent: Withdraw consent at any time without affecting the lawfulness of prior processing. To exercise any of these rights, please contact us at aaron.am.sc@gmail.com.
On the web version of our app, we use local browser storage and cookies solely to maintain your authenticated session and store your preferences (such as dark mode). These are strictly necessary cookies as defined by GDPR and do not require separate consent.
We use the following third-party services: • Google Firebase (Auth, Firestore, Storage, Cloud Messaging): Core infrastructure for authentication, data storage, file storage, and push notifications • Google Sign-In: Account authentication • Google Play / Apple App Store: In-app purchase processing. They manage payment data; we only receive subscription status • Spotify API: Music interest search. Only search queries are sent; no personal data is shared • TMDb / IMDB API: Movie & show interest search. Only search queries are sent; no personal data is shared • Google Books API: Book interest search. Only search queries are sent; no personal data is shared Data transferred to Google Firebase may be processed outside the EEA. Google LLC participates in the EU-US Data Privacy Framework and uses Standard Contractual Clauses, providing adequate safeguards under GDPR Art. 46. Each third-party service has its own privacy policy governing the data they process.
Our matchmaking feature uses automated processing (profiling) to generate a daily match. The algorithm scores compatibility based on shared interests, personality alignment, age range, gender preferences, location proximity, and match goal. This constitutes automated decision-making with significant effect under GDPR Art. 22. You have the right to: • Obtain a human review of an automated matching decision • Express your point of view regarding the outcome • Contest the decision To exercise this right, contact us at aaron.am.sc@gmail.com.
If you have questions about this policy or wish to exercise your data rights, contact us at: aaron.am.sc@gmail.com You also have the right to lodge a complaint with your local data protection supervisory authority (e.g. the ICO in the UK, or the relevant national DPA in your EU member state).
Use of this app is subject to our Terms of Service, available at /terms-of-service.html within the app and on our website.