Thoughtful by design
Your answers deserve care.
Private by default, shared by choice.
Who is responsible
. This local demonstration is for fictional test data and has no public service operator configured.
What we use
Your account uses an email, password hash and date of birth. Your profile includes your chosen name, introduction, gender, optional pronouns, family situation, city, distance settings, relationship preferences, questionnaire answers and optional photo. We use those data to provide your chosen dating service. Dating preferences may reveal sensitive information about sexual orientation; account consent explicitly covers processing these preferences for the service.
What other people can see
Eligible members see your name, age, city, approximate distance, public introduction, interests and stated relationship wishes. Five personality summaries are shared only if you opt in. Approved photos appear to mutual connections. Your exact birth date, email, raw questionnaire answers, private capacity and communication reflections, and feedback are not shown on your public profile.
How information is handled
Questionnaires, messages, photos, feedback and report details are encrypted in storage. The service decrypts them to operate; this is not end-to-end encrypted messaging. Passwords use a salted scrypt hash. Session cookies are essential for signing in. No advertising trackers, analytics SDKs or third-party fonts are included in the website. Account-email delivery is described separately below. City search uses a bundled GeoNames dataset.
Authorized moderators review public text, photos and submitted reports. A conversation report includes an encrypted snapshot of up to the last 50 messages between the reporter and reported member, with names recorded when they connected. Only a recently signed-in administrator can open that evidence, and each access is audited. This does not provide general chat browsing or access to private questionnaire answers.
Services that help run MatchSelf
- Vercel hosts the website and server functions. Requests can include your IP address, session information and the data needed for the feature you use.
- Supabase hosts the PostgreSQL database. MatchSelf uses a private schema and restricted login within CatchSelf’s database project. CatchSelf profiles are not imported into MatchSelf.
- Brevo delivers account verification and password-reset emails. It receives your email address, the account link and delivery information; questionnaire answers and conversations are not included in those emails. Brevo rewrites email links and can record email opens and link clicks, including information needed to operate its tracking links. We use account-email delivery information to investigate delivery and verification problems, not to rank your profile or choose introductions.
- Cloudflare supplies DNS for the CatchSelf domain. The MatchSelf hostname uses DNS-only mode, rather than routing app requests through a Cloudflare proxy.
- If you email support or privacy, the operator receives your message in the business Gmail inbox. Include only what is needed to explain the request; use the in-app report flow for a safety report about a connection.
The application functions and primary database are configured in Frankfurt. Hosting delivery, support and subprocessors can involve other countries; this is not a promise that all processing stays in Germany. Provider terms and safeguards are described in Vercel’s terms, Supabase’s data-processing guidance and Brevo’s terms. The operator must verify the applicable agreements and transfer arrangements before opening public registration.
Control and retention
You can edit or pause your profile, remove your photo, download your data, withdraw and delete optional feedback, or delete your account from My profile. Account deletion removes linked active records, including ordinary conversations. Submitted reports and their limited conversation evidence remain for safety review even after either account is deleted; live account references are removed. Session records expire after seven days; verification and password links expire after one hour. The maintenance worker removes expired credentials and rate limits, all email queue records after seven days, and optional feedback after 180 days. All reports and evidence, open or resolved, are deleted 180 days after submission and cannot be opened for review after that limit. Encrypted backups can retain an expired copy until their separate 30-day expiry; restored data must run retention cleanup before service resumes.
Production backups must be encrypted and expire within 30 days under the supplied operating policy. The supplied restore procedure reapplies the deletion ledger after restoration. The local demo does not schedule backups or send email.
Your rights and choices
Where applicable, you may request access, correction, erasure, restriction or portability; withdraw consent; object to processing based on legitimate interests; and complain to a supervisory authority. Withdrawal does not affect the lawfulness of earlier consented processing. Contact the privacy address above. Matching suggestions support your choice and do not make a legal or similarly significant decision about you.
Optional product feedback is a separate, revocable choice. It is not required to date and is not shared with the other person.
Policy version 2026-09-08. Production operator details, processor contracts and legal review are required before accepting real members.