GETMATE

Privacy Policy

The German version is legally governing; this translation is provided for convenience.

Status & note

Last updated: June 2026. The German version prevails; translations are for convenience. Provider details: see Legal Notice (Impressum).

1. Controller

Christopher Seidemann (sole proprietorship), Dietmannsried (see Legal Notice). Privacy contact: privacy@getmate.app.

2. Overview & principles (Privacy by Design)

GETMATE is a friendship app — not dating. We process as little data as possible:

  • No mandatory profile photos.
  • Free-text and values answers are never shown to other users — used only for internal, automated evaluation.
  • Chat images are automatically deleted 48 hours after sending.
  • Voice recordings for verification are processed only transiently and deleted immediately.

Your Compass (free text & values) is seen by no one but you and the AI.

3. What data, why, on what basis

Legal bases: Art. 6(1)(b) GDPR (contract), (a) (consent), (f) (legitimate interest). Consent can be withdrawn anytime.

  • Account/login data (email, possibly OAuth) — account/login/security (contract).
  • Profile free text, values, hobbies, social energy — Compass & matching (contract; values possibly consent).
  • Derived personality traits & vector embeddings — matching (contract/legitimate interest).
  • Coarse location (~1 km rounded) — distance/geo matching (consent).
  • Chat messages, images (48h deletion), voice messages — communication (contract).
  • Voice recording for verification (transient) — liveness check (consent).
  • Push token (Expo) — notifications (consent/legitimate interest).
  • Log/diagnostic data (Sentry, server logs, may include a user ID) — stability/security (legitimate interest).

4. AI-assisted processing (OpenAI)

For Compass & matching we send your profile free text to OpenAI: model "gpt-5-nano" estimates personality axes, "text-embedding-3-small" creates a similarity vector. Provider: OpenAI, L.L.C., USA (processor, DPA). API data is NOT used to train the models. Transfer to the USA, safeguarded via EU SCCs or the EU-US Data Privacy Framework. Results stay internal.

Your free text goes to OpenAI (USA) for evaluation, but is not used for training.

5. Profiling & automated matching

We compute a compatibility score and suggest up to 5 matches (profiling, Art. 13 GDPR). It has no legal/similarly significant effect under Art. 22 — selection & contact are up to you.

6. Voice verification ("Verified Human")

You read out given words. The audio is processed only transiently, automatically transcribed, and deleted immediately. Only the result (verified: yes/no) is stored. It serves solely as a liveness check, not biometric identification.

7. Special categories (Art. 9 GDPR)

Free text/values may reveal special categories (e.g. beliefs, health, sexual orientation). Such processing occurs only on your explicit consent (Art. 9(2)(a)), stays strictly internal, and is never disclosed.

8. Recipients / processors (Art. 28)

  • Supabase Inc. — database, auth, storage (AWS eu-central-1, Frankfurt/EU).
  • OpenAI, L.L.C. — personality analysis & embeddings (USA).
  • Railway Corp. — backend hosting.
  • Vercel Inc. — web hosting (USA/global edge).
  • Expo (650 Industries, Inc.) — push delivery (USA).
  • Resend, Inc. — delivery of system/auth emails (e.g. signup confirmation, password reset) (USA).
  • Stripe Payments Europe, Ltd. / Stripe, Inc. — web-subscription payment processing (EU/USA).
  • RevenueCat, Inc. — App Store / Play subscription management (USA).
  • Sentry (Functional Software, Inc.) — error monitoring (if enabled).
  • Apple Inc. / Google LLC — app distribution, push transport, in-app/store payments (USA).

We do not sell personal data and do not share it for advertising.

9. International transfers

Where processing occurs outside the EU/EEA (esp. USA), we rely on EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework, with additional safeguards.

10. Retention

  • Account/profile data: until account deletion.
  • Chat images: 48 hours from sending.
  • Voice verification: deleted immediately after transcription.
  • Resolved matches: 30-day cooldown before re-matching.
  • Reports: until the case is resolved, then per statutory retention/limitation periods.
  • Blocks: until you remove them.
  • Log/diagnostic data: up to 90 days.

Images disappear from the chat after 48h — but the recipient can save them locally beforehand.

11. Your rights

You have the right to access, rectification, erasure, restriction, data portability and objection, and to withdraw consent. Delete your account in Settings. After deletion your account is deactivated immediately and invisible to others; it is permanently erased after 30 days. Within that window you can restore it (log in again or support@getmate.app). On explicit request (privacy@getmate.app) we erase immediately.

Exercise: privacy@getmate.app. Complaints to the supervisory authority (LDA Brandenburg).

12. International users

EU/EEA, UK, Switzerland: GDPR / UK GDPR / Swiss FADP. USA: In California (CCPA/CPRA) and other US states with privacy laws (incl. Virginia, Colorado, Connecticut, Utah, Texas, Oregon) you have rights to access, deletion, correction, portability and to opt out; we do not "sell" or "share" personal data for targeted advertising and do not process sensitive data for advertising. Japan (APPI): we process personal data for the purposes stated above, disclose it to the processors listed, and transfer it across borders (esp. the USA and EU/Germany); you may request disclosure, correction, deletion and cessation of use (privacy@getmate.app). Worldwide we generally apply this standard; additional local rights may apply by residence.

Contact for all privacy rights worldwide: privacy@getmate.app.

13. Minors

GETMATE is exclusively for persons aged 18+. We do not knowingly collect data from minors.

14. Security & changes

We take appropriate technical/organisational measures (Art. 32, incl. TLS). We notify material changes to this policy in the app.

15. Reports, blocking & moderation

You can block other users and report individual chats. When you report a chat, we process the reported conversation (the text messages of that chat), the chosen report reason and the accounts involved, so we can review the incident and decide on any action (e.g. a warning or a ban). The legal basis is our legitimate interest in safety and abuse prevention and the enforcement of our Terms (Art. 6(1)(f) GDPR). Only in the event of a report can the operator view that specific conversation for review — no broader access to chats takes place. Chat images remain subject to automatic 48-hour deletion even when a chat is reported. Blocks hide profiles mutually and prevent further matching.

Only when you report a chat can the operator see that one specific conversation for review.

15a. Drawings in the drawing game (ephemeral)

Drawings from the drawing game are not stored. They exist only during the running round and for a short visibility window afterwards (group rounds: 5 minutes; 1:1 drawings: until first viewed plus the guessing time and 5 minutes, at most 24 hours if never viewed) — exclusively in our server's working memory, with no logging of the image content. After that the drawing is irretrievably gone. Only if a drawing is reported within this window do we create an encrypted copy solely for moderation purposes; it is bound to the moderation case and permanently deleted after 30 days at the latest, or when the case is decided (Art. 6(1)(f) GDPR — safety and abuse prevention). Only an image-free system line remains in the chat (e.g. "the word was …"). If an account is deleted while a moderation case is open, we keep the encrypted copy until the case is decided and then delete it permanently.

Drawings are never stored — unless you report one; then encrypted only, for moderation only, max. 30 days.

16. Planning a meet ("Meet")

The Meet feature lets you arrange a real-life meetup. We store the time, place (free text) and the two participating accounts — visible only to the two of you. Legal basis is performance of the contract (Art. 6(1)(b) GDPR). Once both of you confirm the meet happened, we promptly delete the exact place; only a minimal record remains (that a meet was arranged on that date). An optional calendar entry is created locally on your device only and is not stored by us.

Meet places are deleted once both sides confirm it happened.

17. Contact

Privacy requests: privacy@getmate.app