TraitMatch Privacy Policy
Version 1.4 — Effective 24 September 2026
This Privacy Policy explains how TraitMatch (“TraitMatch”, “we”, “us”, “our”) collects, uses, shares, and protects personal data when you use the TraitMatch mobile application and related services (the “Service”).
Our commitment to you
• Privacy by design — product, security, and legal reviews consider your privacy before shipping features.
• Transparency — this Policy prefers plain language over jargon.
• Security investment — we maintain technical and organisational measures and update them as threats evolve.
• Your control — Settings include data export, deletion, discovery pauses, and visibility toggles.
Controller
Controller: TraitMatch
Registered address: Bratislava, Slovak Republic
Privacy contact: privacy@traitmatch.app
Data Protection Officer (if designated): dpo@traitmatch.app
Website: https://traitmatch.pages.dev
Imprint: https://traitmatch.pages.dev/imprint
Company registration and VAT details (when available): see Imprint.
If you live in the EEA/UK, TraitMatch is the data controller for the Service. If we appoint an EU/UK representative, those details will be published at https://traitmatch.pages.dev/privacy.
California / similar US state residents: see Regional Privacy Addendum in Settings → Legal.
1. Scope
This Policy applies to personal data processed through the Service, including profile information, personality/trait assessments, matching, messaging, Ponds (group rooms), purchases, and safety/moderation features.
2. Categories of personal data we process
Depending on how you use the Service, we may process:
A. Account and identity data
• Email address and/or phone number
• Authentication credentials / tokens (hashed passwords or provider tokens)
• Account identifiers and device identifiers needed for security
B. Profile data you provide
• Display name, date of birth / age, photos, bio, interests
• Gender identity, sexual orientation, looking-for preferences
• Lifestyle attributes (e.g. drinking, smoking, children preferences, religion, ethnicity, activity, education, occupation, languages)
• City / approximate location used for distance matching
C. Special category data (GDPR Article 9)
Dating profiles may include special categories of personal data, in particular data concerning sexual orientation and, where you choose to provide them, data revealing religious or philosophical beliefs or ethnic origin. We process such data only where you provide it and with your explicit consent (Article 9(2)(a)), or where another Article 9 condition applies (for example establishing, exercising or defending legal claims).
D. Trait / assessment data
• Answers to personality and values tests
• Derived trait scores and labels used for compatibility and Premium filters
These are for matching and self-description, not medical diagnosis.
E. Usage, device and technical data
• App interactions, crash logs, approximate network information, device type/OS, language and unit preferences
• Push notification tokens
F. Communications and safety data
• End-to-end encrypted match direct messages: ciphertext, cryptographic nonces, and conversation metadata (participants, timestamps, delivery/read indicators, mute/pin/block flags). We do not hold keys that decrypt 1:1 message plaintext on our servers.
• Message plaintext exists only on participants’ devices (and cannot be recovered by us if you lose your device keys).
• Ponds / group messages and other non-E2E surfaces (if offered) may be processed in a readable form to deliver the Service and for abuse investigation, as disclosed for those features.
• Reports, blocks, and related evidence you submit (including category, details, and any message excerpt you choose to share)
• In-app reports are stored on our servers when you are signed in; we prioritise child-safety categories for human review
• Verification materials if you use profile verification
• Chat media files you upload may be stored on our hosting providers; captions for match DMs are encrypted like text. Image bytes are protected in transit (TLS); additional file-level E2E for media may be expanded over time.
G. Payment data
• Purchase status and entitlements. Payment card details are processed by Google Play / the store; we receive confirmation of purchase, not full card numbers.
H. Third-party / sign-in data
• If you sign in with Google (or another provider we enable), we receive identifiers and basic account details the provider shares with your permission (for example email and name), which we use to create or link your TraitMatch account
• Reports or safety tips other users submit that mention you
I. Customer support data
• Messages you send to support or privacy inboxes, and related ticket metadata needed to help you
J. Inferences and derived data
• Compatibility rankings, trait labels, and similar insights generated from your tests, preferences, and activity solely to operate matching and filters
3. Purposes and legal bases (GDPR Article 6 / 9)
We process data for the following purposes:
• Provide the Service (account, profile, matching, messaging, Ponds) — contract (Art. 6(1)(b))
• Age gate (18+) and fraud/security — legitimate interests / legal obligation (Art. 6(1)(f)/(c))
• Trait tests and compatibility ranking — contract and, for special-category profile fields, explicit consent (Art. 6(1)(b); Art. 9(2)(a))
• Location-based distance filters — contract / consent where required by local law
• Safety, moderation, and prevention of illegal content — legitimate interests and legal obligation (Art. 6(1)(f)/(c)). For end-to-end encrypted match DMs we cannot scan message plaintext on our servers; we rely on user reports, metadata, account signals, and content you voluntarily provide when reporting.
• Notifications you enable — consent and/or contract depending on notification type
• Analytics to improve reliability and features — legitimate interests (Art. 6(1)(f)); where required, consent
• Premium / Boost billing entitlement — contract (Art. 6(1)(b))
• Legal compliance, disputes, and regulatory requests — legal obligation / legitimate interests (Art. 6(1)(c)/(f)). Where we receive a lawful request, we can disclose account data and encrypted message ciphertext we store; we cannot provide decrypted 1:1 DM plaintext we do not possess.
• Marketing communications — consent (Art. 6(1)(a)); you may withdraw anytime in Settings
• Optional surveys or product research you choose to join — consent / legitimate interests as disclosed at the time
Where we rely on legitimate interests, we balance our interests against your rights. You may object as described in Section 9.
4. Automated matching and profiling
TraitMatch uses automated processing (including profiling) to suggest compatible profiles based on your preferences, filters, trait scores, and activity. This is necessary to provide matching. It does not produce legal or similarly significant effects solely by automated means without human involvement in safety enforcement. You may adjust filters, pause discovery (“Show me in Match”), or request human review of moderation decisions via support@traitmatch.app.
5. How we share data
We do not sell your personal data.
We share data only as follows:
• Other users — according to your profile visibility and privacy settings (photos, bio, traits you display, looking-for, etc.)
• Service providers (processors) — hosting, databases, push delivery, authentication, content delivery, under data processing agreements. Current list: https://traitmatch.pages.dev/subprocessors
• Payment platforms — Google Play for subscriptions and one-time purchases
• Authorities — when required by law or to protect rights, safety, or integrity of the Service
• Corporate transactions — if we merge or transfer assets, under appropriate safeguards
5a. International transfers
Some processors (for example Firebase / Google, Cloudflare) may process data outside the EEA/UK. Where required, we rely on adequacy decisions, Standard Contractual Clauses, or equivalent transfer tools. See https://traitmatch.pages.dev/subprocessors.
6. Retention
• Account and profile data: while your account is active
• After account deletion request: we schedule deletion promptly. A short recovery window (typically up to 7 days) may apply so you can reinstate by signing in again; irreversible deletion or anonymization of personal data is completed within 30 days of the request, except where retention is required by law (e.g. billing records, unresolved abuse reports, security logs) for a limited period disclosed on request
• Messages: encrypted match DM ciphertext and metadata retained while needed to provide chat and for limited security/abuse windows; we do not retain 1:1 DM plaintext on our servers because we do not receive it
• Safety reports and enforcement records: kept as long as needed for investigation, legal claims, and child-safety duties
• Purchase / entitlement records: kept as required for accounting and store reconciliation
• Backups: rotated and purged on a limited schedule after deletion
• Inactive accounts may be removed after a long dormancy period as described in the Terms / Community Guidelines
Account freezing is not used as a substitute for deletion.
7. Security
We implement appropriate technical and organisational measures, including encryption in transit (TLS), access controls, least-privilege administration, and secure storage practices. Match 1:1 direct messages use client-side end-to-end encryption (ECDH key agreement + authenticated encryption) so message plaintext is not available to our servers under normal operation. Chat image bytes for match DMs are encrypted on-device before upload. End-to-end encryption does not hide chat metadata (participants, timestamps, delivery indicators), does not protect compromised devices, and does not prevent a peer from copying or screenshotting content. We minimise unnecessary plaintext exposure (for example inbox previews never show ciphertext or message content). Losing your device or encryption keys may make prior ciphertext permanently unreadable. Illegal-content duties still apply: we cannot scan E2E plaintext, so we rely on user reports (including optional shared excerpts), metadata, and account signals. No method of transmission or storage is 100% secure; please use strong credentials and report suspected compromise to support@traitmatch.app.
8. Children
The Service is strictly for adults aged 18+. We do not knowingly collect data from children. If we learn that a user is under 18, we will delete the account and associated data.
9. Your rights
Subject to applicable law (including GDPR), you may have the right to:
• Access your data
• Rectify inaccurate data
• Erase data (“right to be forgotten”)
• Restrict or object to certain processing
• Data portability
• Withdraw consent at any time (without affecting prior lawful processing)
• Lodge a complaint with a supervisory authority (in the Slovak Republic: Úrad na ochranu osobných údajov SR; or your local EEA/UK authority)
How to exercise rights:
• In-app: Settings → Download my data; Settings → Delete account
• Web deletion request page (Google Play requirement): https://traitmatch.pages.dev/account-deletion
• Email: privacy@traitmatch.app
We will respond within the statutory timeframe (generally one month under GDPR).
10. Cookies and similar technologies
The mobile app and website use essential local storage for authentication, security, and preferences. Non-essential analytics or marketing technologies run only with your consent (see Cookie Policy: https://traitmatch.pages.dev/cookies). You can change cookie/SDK preferences in Settings (app) or via the website cookie banner. Marketing push notifications are separate and default off.
Named processors: https://traitmatch.pages.dev/subprocessors.
For California and similar US state rights, see the Regional Privacy Addendum in Settings → Legal.
11. Third-party links and content
Profiles and Ponds rooms may contain user content. We are not responsible for third-party sites linked by users. Report illegal or harmful content using in-app reporting.
12. Changes to this Policy
We may update this Policy. We will change the version and effective date above and, where required, notify you in-app or by email. Continued use after the effective date constitutes acknowledgment of the updated Policy where permitted by law; where consent is required, we will request it.
13. Contact
Privacy: privacy@traitmatch.app
Support: support@traitmatch.app
Postal: Bratislava, Slovak Republic