Privacy Policy

Privacy Policy

v7 · in force since 25 May 2026

This Policy sets out how Human Match collects, uses, retains and safeguards your personal data when you use the Agapone application (the "App"). It complements the Terms & Conditions and must be read in conjunction with them. For any privacy-related enquiry, please write to support@agapone.com.

In summary: we process your data solely to operate and improve the App. We do not sell your data and we do not disclose it to third parties for advertising or marketing purposes. The technical providers listed below (Supabase, Firebase, and others) act exclusively as our processors within the meaning of Article 28 GDPR.

1. Data Controller

Controller: Human Match Privacy Department, reachable at support@agapone.com.

All requests concerning the exercise of GDPR rights, as well as any data-protection enquiry, should be directed to support@agapone.com.

2. Data We Collect

2.1. Data you provide

2.2. Data generated through use

These events contain no message text, photographs, email addresses or third-party identifiers in a re-identifiable form. They serve a purely operational purpose — informing product decisions such as which tests are most engaged with, how the upgrade funnel performs, or where users drop out of onboarding. You may disable analytics at any time under Settings → Privacy → Usage analytics; the toggle also prevents the device itself from emitting new events.

2.3. Data we do not collect

3. Purposes and Legal Bases of Processing

PurposeData typesLegal basis (GDPR)
Create and maintain your account, authenticate youEmail, password, push tokenContract performance (art. 6/1/b)
Compute DNA, cosmic charts and cross-compatibilityBirth, test answers, locationContract performance (art. 6/1/b)
Show profiles and photos to other users within your filtersProfile, photos, approximate locationContract performance (art. 6/1/b)
Enable chat and callsMessages, call metadataContract performance (art. 6/1/b)
Automated moderation + human review of photosPhotos and metadataLegitimate interest (art. 6/1/f) — community safety
Product analytics events to improve the AppEvents with name + non-identifying propertiesLegitimate interest (art. 6/1/f); opt-out in Privacy
Push notifications (system, chat, calls, campaigns)Push token + minimal payloadContract performance and/or OS permissions consent
Fraud prevention, abuse, bansLogs, reports, account dataLegitimate interest (art. 6/1/f) and legal obligation (art. 6/1/c)
Tax and accounting complianceStore receiptsLegal obligation (art. 6/1/c)

Human Match does not take solely automated decisions producing legal effects, or similarly significant effects, in respect of users within the meaning of Article 22 GDPR. Compatibility scores and automated photo moderation are recommendations and filters with no legal effect — any suspension or ban decision is preceded by human review.

4. Recipients of the Data

4.1. Other users

The data you choose to make visible on your profile — photograph, display name, description, interests, age and approximate distance, where enabled — are accessible to users who fall within your radius, gender and minimum mastery filters. Messages are accessible only to the participants in the conversation. Full cross-compatibility detail between two users requires mutual consent (see Terms, Clause 8).

4.2. The Human Match team

Internal access to account data is restricted to a small number of Human Match personnel across engineering, moderation and user support, strictly for the purposes of operating and protecting the service, under confidentiality undertakings and the principle of need-to-know. All critical account actions — suspensions, bans, administrative edits — are recorded in a dedicated audit log.

4.3. Subprocessors

We engage the technical providers listed below to host and operate the App. They act exclusively on our behalf, under written contract and pursuant to our instructions, within the meaning of Article 28 GDPR. We do not share data with these providers for their own purposes, for marketing or for monetization — only for the delivery of the service.

VendorRoleRegionPolicy
SupabasePrimary database (profiles, messages, events), authentication, photo storage, Edge FunctionsEU (Frankfurt)supabase.com/privacy
Firebase Cloud Messaging (Google)Push notification deliveryGoogle multi-regionfirebase.google.com/support/privacy
Firebase Auth / Cloud Functions (Google)Legacy moderation and compute functions (being migrated to Supabase)Google multi-regionfirebase.google.com/support/privacy
Cloud Firestore (Google)Legacy data being migrated; no new writesGoogle multi-regionfirebase.google.com/support/privacy
Firebase Storage (Google)Legacy photo storage being migratedGoogle multi-regionfirebase.google.com/support/privacy
Google Sign-InFederated auth when you pick "Continue with Google"Google multi-regionpolicies.google.com/privacy
Apple App Store / Google PlaySubscription and Essence-pack processing; we only receive confirmation and transaction idPer store policyapple.com/legal/privacy · policies.google.com/privacy
Google Mobile Ads SDKSDK bundled into the App. It is not actively serving ads in this version. When activated for rewarded ads it will be announced in this policy and subject to Google's terms.Per Google policypolicies.google.com/technologies/ads
Google Cloud Vision APIAutomated SafeSearch moderation of profile photos — receives only the image under review and returns suitability classifications (adult/medical/violence/racy/spoof). Google does not retain the images for its own purposes beyond what is required for the analysis. Invoked by the moderate-photo Edge Function.Google Cloud (EU/US multi-region)cloud.google.com/vision
RevenueCatManages in-app subscriptions and Essence packs — receives an anonymised user identifier, the platform (iOS/Android) and the purchase / restore events returned by the App Store or Google Play. It does not receive your email, profile, messages or photos.USA (covered by Standard Contractual Clauses)revenuecat.com/privacy

4.4. Public authorities

We may disclose data to public authorities where legally compelled to do so — in particular, in compliance with a valid court order, a request from a competent authority or a tax obligation. Wherever the law permits, we will inform the user of any such disclosure.

5. International Transfers

Your data is hosted, by default, on infrastructure located within the European Union (Supabase, Frankfurt region). Certain operations performed by the Google/Firebase subprocessors may occur in regions outside the EU. In such cases, we ensure an adequate level of protection through the European Commission's Standard Contractual Clauses or equivalent safeguards.

6. Retention Periods

7. Data Subject Rights (GDPR / CCPA)

As a data subject, you are entitled to the following rights:

Requests are addressed within 30 days, extendable up to 90 days for particularly complex matters, subject to prior notice to the data subject. Requests are handled free of charge, save where manifestly unfounded or repetitive.

Users resident in California (United States) are afforded equivalent rights under the CCPA/CPRA — access, deletion, rectification and opt-out of "sale" and "sharing". Human Match does not sell or share personal information within the meaning of the CCPA.

8. Security

We implement appropriate technical and organisational measures to safeguard your data, including: encryption in transit (TLS), at-rest encryption at the database layer, Row-Level Security in Supabase, role-based access control, access auditing, isolation between the administrative project and the App project, periodic key rotation and regular security testing. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify you without undue delay and report the incident to the CNPD within the timeframes prescribed by law (≤72 hours).

9. Minors

The App is intended exclusively for users aged 18 or over. We do not knowingly collect data from minors. Should we become aware that a minor has created an account, we will promptly delete the associated data.

10. Cookies and Local Storage

The mobile App relies on on-device storage (SharedPreferences, Hive, Isar and image cache) to retain session state, user preferences and application cache. We do not use advertising or behavioural-tracking cookies. The administrative panel, accessible exclusively to Human Match staff via the web, uses strictly necessary session cookies for authentication.

11. Changes to this Policy

This Policy may be updated from time to time. On any material change, the LegalVersions.currentPrivacyVersion value is incremented and you are notified within the App. The version in force is permanently available under Settings → Privacy → View Privacy Policy.