Skip to content

Privacy Policy

Effective from 11. September 2026

Couple MATCH is an app for two people, so we necessarily know one thing: who is paired with whom. What you write and draw together is encrypted with your couple’s own key, which our server does not hold. This page says what is readable, what is not, and why.

Does the app need an account?

For a couple, yes. Chat, shared quests and games need two accounts, because without them there is nobody to pair with.

You sign in with Apple or Google. You can look around without an account — as a guest, or through the demo — but the shared features do not work in that mode.

What is encrypted with your couple’s key

All of this leaves your device already encrypted, and the server holds no key to it: the content of your chat, the name and photo in your profile, your answers to shared quests, the daily drawing, the state of your games, and the trace of a past relationship kept in the archive.

The couple key is created on your two devices and exists nowhere else. We use XChaCha20-Poly1305, X25519 and Argon2id.

In practice this means we cannot read your conversation either. It is not a promise that we will not look — we have nothing to look with.

What the server can read, and why

Some things have to stay readable or the app could not do the thing you have it for. Readable are: who is paired with whom, the date your relationship started, both birthdays and name days, the time zone, points and streaks, notification settings, and device tokens for push.

There is one reason: anniversaries and birthdays are scheduled by the server. A phone could only do it if it happened to be awake with the app open at the right moment — which is exactly the day you do not want to rely on that.

The pairing itself says something about your relationship and cannot be encrypted, because it is the fact the server uses to know who to send what to. The gender you set in your profile, which the app needs for correct Czech grammar, sits in the locked part of the profile and the server does not read it.

What a notification never contains

Notification text passes through Apple’s and Google’s servers, and the couple key is not on it. So it contains no name — not yours, not the sender’s, and none of the message.

An automated test enforces this, not good intentions.

What stays only on your device

The app lock code (in the Keychain or Keystore), your own wallpaper, and the demo data. The couple key lives only in the running app’s memory; the device’s private key lives in the keychain.

The app does not collect location. It has no geolocation access at all; a time zone is not a location.

Photos and backups

Chat photos vanish within 24 hours — the object is deleted and its key thrown away. Evidence you attach to a shared quest stays, because it is part of that quest.

Your backup code is stored encrypted in your iCloud Keychain or Android backup; we hold the salt for it. So neither Apple or Google alone, nor we alone, can open it.

What usage data we measure

The app uses Google Analytics for Firebase so we can see which features people use and where the app fails. We measure use in categories — screens opened, quests completed, games started, settings changed — never the content of what you write. That is encrypted and we have no access to it.

Your identity in this data is a pseudonymous app instance identifier generated by Firebase. No name or e-mail belongs to it.

Statistics are kept for the period configured in the service, 2 months by default. After that only aggregate reports remain.

You can switch the measurement off at any time under Settings → General.

Advertising

The app shows advertising through Google AdMob.

The ad system works with technical device identifiers and the advertising identifier. We pass it nothing from inside the app — no messages, no profile, not who you are paired with.

In the European Economic Area we ask you first about personalised advertising — consent is collected through the Google User Messaging platform and you can change it at any time in the app’s settings. Until you give it, only non-personalised ads are shown. On iOS the system tracking prompt is shown as well; if you decline it, the advertising identifier is not used.

Purpose and legal basis

Purpose: running an app for two — pairing, delivering notifications, scheduling anniversaries and birthdays, providing the shared features — plus improving the app from anonymous statistics and funding it through advertising.

Legal basis: performance of a contract for the app itself; your consent for notifications and for personalised advertising; and our legitimate interest (Article 6(1)(f) GDPR) in anonymous usage statistics and in securing the service.

The pairing of two people says something about your relationship. We process it only so the app works, we pass it to nobody, and it is not used for advertising.

Sharing and processors

We do not sell your data and do not share it with anyone beyond the processors listed below.

Google Firebase — sign-in, database, storage, notification delivery (FCM) and server functions. The functions run in the europe-west3 region.

Google Analytics for Firebase — anonymous usage statistics.

Google AdMob — serving advertising.

Apple — Apple ID sign-in, notification delivery (APNs) and processing of any App Store purchases.

App Check (App Attest on iOS, Play Integrity on Android) verifies that a request comes from the genuine app rather than something impersonating it. It attests the device and the app, not you.

Data may be transferred outside the EU under Standard Contractual Clauses (SCC).

How long we keep data

We keep your couple’s data for as long as you use the account. Chat photos vanish within 24 hours.

Anonymous statistics in Google Analytics for Firebase are kept for the period configured in the service, 2 months by default.

When an account is deleted we remove the readable data and discard the ciphertext nobody holds a key to any more.

Your rights and how to ask for deletion

Within the scope of applicable law (GDPR in particular) you have the right of access, rectification, erasure, restriction of processing, portability and objection.

You can delete your account inside the app. Notification consent is withdrawn in your device settings, personalised-advertising consent in the app’s settings.

You may object to the anonymous usage measurement carried out on the basis of legitimate interest — or simply switch it off under Settings → General.

Data controller: Aleš Urbánek
Contact: email@ales-urbanek.cz

Changes to this policy

If the way we process data changes, we update this page and move the last-updated date. Significant changes are announced in the app.