Privacy Policy
This Policy sets out how Human Match collects, uses, retains and safeguards your personal data when you use the Agapone application (the "App"). It complements the Terms & Conditions and must be read in conjunction with them. For any privacy-related enquiry, please write to support@agapone.com.
In summary: we process your data solely to operate and improve the App. We do not sell your data and we do not disclose it to third parties for advertising or marketing purposes. The technical providers listed below (Supabase, Firebase, and others) act exclusively as our processors within the meaning of Article 28 GDPR.
1. Data Controller
Controller: Human Match Privacy Department, reachable at support@agapone.com.
All requests concerning the exercise of GDPR rights, as well as any data-protection enquiry, should be directed to support@agapone.com.
2. Data We Collect
2.1. Data you provide
- Account: email address, display name, password (stored in hashed form by the Supabase authentication layer — the plaintext is never accessible to us), and preferred language.
- Core identity: age (derived from your date of birth), self-declared gender, and full name (optional, used for Numerology computations).
- Cosmic data: date, time and place of birth, required to compute Astrology, Human Design, Numerology and Chinese Zodiac charts. These data may be partial — where the exact time is unknown, charts default to 12:00 and are flagged as lower-precision.
- Profile: description, interests, profile and album photographs, test responses, and visibility preferences.
- Location: city (via geocoding) and a geohash whose precision depends on your settings, used to determine the search radius for community and cross. We do not collect location history or precise background coordinates.
- Communications: text and audio messages, photographs shared in chat, and WebRTC video-call metadata (start, end, duration). Video-call content is never recorded or stored — our STUN/TURN servers only broker the signalling required to establish the peer-to-peer connection.
- Payments: the subscription or receipt identifier returned by the App Store or Google Play. We never receive or store card numbers, IBANs or any banking data — payment is processed entirely by the store where the purchase is made.
2.2. Data generated through use
- Anonymous product analytics: each relevant action is recorded in our internal datastore as an event identified by a short name and a small set of non-identifying properties. The full list of events currently collected is as follows:
user_signed_up— propertyprovider(google/apple/email)profile_completed— no properties; signals completion of the registration wizardtest_completed— propertytest_slug(e.g.mbti,disc)unlock_purchased— propertycategoryorslugof the unlocked itemcross_viewed— propertycontext(mate/date/colleague)chat_message_sent— propertyroom_typeorhashed_peer(third-party id hashed with a per-session salt, non-reversible across sessions)referral_redeemed— propertiestype(referral/promo) andis_registrationsubscription_started— propertytier(spark/pulse)essence_purchase_completed— propertiespack_id(e.g.starter) andamount
These events contain no message text, photographs, email addresses or third-party identifiers in a re-identifiable form. They serve a purely operational purpose — informing product decisions such as which tests are most engaged with, how the upgrade funnel performs, or where users drop out of onboarding. You may disable analytics at any time under Settings → Privacy → Usage analytics; the toggle also prevents the device itself from emitting new events.
- Technical logs: device type, operating system, App version, system language and error timestamps. Retained for a maximum of 30 days, strictly for diagnostic purposes.
- Push tokens: the FCM (Firebase Cloud Messaging) token issued by your device, required to deliver push notifications.
2.3. Data we do not collect
- We do not collect health, biometric, sexual orientation or racial/ethnic origin data as structured categories. Any voluntary disclosure of such information in your profile description is made on your own initiative and under your sole responsibility.
- We do not access your contacts, calendar, photographs other than those you choose to upload, background microphone or browsing history.
- We do not use advertising identifiers (IDFA / GAID) for profiling. The App does not display third-party advertising in this release; any future integration will be communicated with appropriate notice.
3. Purposes and Legal Bases of Processing
| Purpose | Data types | Legal basis (GDPR) |
|---|---|---|
| Create and maintain your account, authenticate you | Email, password, push token | Contract performance (art. 6/1/b) |
| Compute DNA, cosmic charts and cross-compatibility | Birth, test answers, location | Contract performance (art. 6/1/b) |
| Show profiles and photos to other users within your filters | Profile, photos, approximate location | Contract performance (art. 6/1/b) |
| Enable chat and calls | Messages, call metadata | Contract performance (art. 6/1/b) |
| Automated moderation + human review of photos | Photos and metadata | Legitimate interest (art. 6/1/f) — community safety |
| Product analytics events to improve the App | Events with name + non-identifying properties | Legitimate interest (art. 6/1/f); opt-out in Privacy |
| Push notifications (system, chat, calls, campaigns) | Push token + minimal payload | Contract performance and/or OS permissions consent |
| Fraud prevention, abuse, bans | Logs, reports, account data | Legitimate interest (art. 6/1/f) and legal obligation (art. 6/1/c) |
| Tax and accounting compliance | Store receipts | Legal obligation (art. 6/1/c) |
Human Match does not take solely automated decisions producing legal effects, or similarly significant effects, in respect of users within the meaning of Article 22 GDPR. Compatibility scores and automated photo moderation are recommendations and filters with no legal effect — any suspension or ban decision is preceded by human review.
4. Recipients of the Data
4.1. Other users
The data you choose to make visible on your profile — photograph, display name, description, interests, age and approximate distance, where enabled — are accessible to users who fall within your radius, gender and minimum mastery filters. Messages are accessible only to the participants in the conversation. Full cross-compatibility detail between two users requires mutual consent (see Terms, Clause 8).
4.2. The Human Match team
Internal access to account data is restricted to a small number of Human Match personnel across engineering, moderation and user support, strictly for the purposes of operating and protecting the service, under confidentiality undertakings and the principle of need-to-know. All critical account actions — suspensions, bans, administrative edits — are recorded in a dedicated audit log.
4.3. Subprocessors
We engage the technical providers listed below to host and operate the App. They act exclusively on our behalf, under written contract and pursuant to our instructions, within the meaning of Article 28 GDPR. We do not share data with these providers for their own purposes, for marketing or for monetization — only for the delivery of the service.
| Vendor | Role | Region | Policy |
|---|---|---|---|
| Supabase | Primary database (profiles, messages, events), authentication, photo storage, Edge Functions | EU (Frankfurt) | supabase.com/privacy |
| Firebase Cloud Messaging (Google) | Push notification delivery | Google multi-region | firebase.google.com/support/privacy |
| Firebase Auth / Cloud Functions (Google) | Legacy moderation and compute functions (being migrated to Supabase) | Google multi-region | firebase.google.com/support/privacy |
| Cloud Firestore (Google) | Legacy data being migrated; no new writes | Google multi-region | firebase.google.com/support/privacy |
| Firebase Storage (Google) | Legacy photo storage being migrated | Google multi-region | firebase.google.com/support/privacy |
| Google Sign-In | Federated auth when you pick "Continue with Google" | Google multi-region | policies.google.com/privacy |
| Apple App Store / Google Play | Subscription and Essence-pack processing; we only receive confirmation and transaction id | Per store policy | apple.com/legal/privacy · policies.google.com/privacy |
| Google Mobile Ads SDK | SDK bundled into the App. It is not actively serving ads in this version. When activated for rewarded ads it will be announced in this policy and subject to Google's terms. | Per Google policy | policies.google.com/technologies/ads |
| Google Cloud Vision API | Automated SafeSearch moderation of profile photos — receives only the image under review and returns suitability classifications (adult/medical/violence/racy/spoof). Google does not retain the images for its own purposes beyond what is required for the analysis. Invoked by the moderate-photo Edge Function. | Google Cloud (EU/US multi-region) | cloud.google.com/vision |
| RevenueCat | Manages in-app subscriptions and Essence packs — receives an anonymised user identifier, the platform (iOS/Android) and the purchase / restore events returned by the App Store or Google Play. It does not receive your email, profile, messages or photos. | USA (covered by Standard Contractual Clauses) | revenuecat.com/privacy |
4.4. Public authorities
We may disclose data to public authorities where legally compelled to do so — in particular, in compliance with a valid court order, a request from a competent authority or a tax obligation. Wherever the law permits, we will inform the user of any such disclosure.
5. International Transfers
Your data is hosted, by default, on infrastructure located within the European Union (Supabase, Frankfurt region). Certain operations performed by the Google/Firebase subprocessors may occur in regions outside the EU. In such cases, we ensure an adequate level of protection through the European Commission's Standard Contractual Clauses or equivalent safeguards.
6. Retention Periods
- Account and profile data: for the lifetime of the account.
- Messages: for the lifetime of the account, or until you manually delete your history.
- Analytics events: up to 24 months in aggregated form; raw events for 90 days.
- Technical logs: 30 days.
- Following account deletion: directly identifying personal data is erased within 30 days. We retain, for up to 12 months, minimal records relating to moderation, security, fraud prevention and legal compliance. Tax receipts are retained for the statutory period — typically 10 years in Portugal.
7. Data Subject Rights (GDPR / CCPA)
As a data subject, you are entitled to the following rights:
- Access to your personal data and a copy thereof (portability);
- Rectification of inaccurate or outdated data, directly within your profile or by contacting us;
- Erasure ("right to be forgotten") — available under Settings → Account → Delete account or via support@agapone.com;
- Restriction of, or objection to, processing carried out on the basis of legitimate interest;
- Withdrawal of consent — by disabling analytics under Privacy settings, denying operating-system permissions (notifications, location, camera, microphone) or deleting the account;
- Lodging a complaint with the competent supervisory authority. In Portugal: Comissão Nacional de Protecção de Dados (CNPD) — cnpd.pt. Within the European Union, with the authority of your country of residence.
Requests are addressed within 30 days, extendable up to 90 days for particularly complex matters, subject to prior notice to the data subject. Requests are handled free of charge, save where manifestly unfounded or repetitive.
Users resident in California (United States) are afforded equivalent rights under the CCPA/CPRA — access, deletion, rectification and opt-out of "sale" and "sharing". Human Match does not sell or share personal information within the meaning of the CCPA.
8. Security
We implement appropriate technical and organisational measures to safeguard your data, including: encryption in transit (TLS), at-rest encryption at the database layer, Row-Level Security in Supabase, role-based access control, access auditing, isolation between the administrative project and the App project, periodic key rotation and regular security testing. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify you without undue delay and report the incident to the CNPD within the timeframes prescribed by law (≤72 hours).
9. Minors
The App is intended exclusively for users aged 18 or over. We do not knowingly collect data from minors. Should we become aware that a minor has created an account, we will promptly delete the associated data.
10. Cookies and Local Storage
The mobile App relies on on-device storage (SharedPreferences, Hive, Isar and image cache) to retain session state, user preferences and application cache. We do not use advertising or behavioural-tracking cookies. The administrative panel, accessible exclusively to Human Match staff via the web, uses strictly necessary session cookies for authentication.
11. Changes to this Policy
This Policy may be updated from time to time. On any material change, the LegalVersions.currentPrivacyVersion value is incremented and you are notified within the App. The version in force is permanently available under Settings → Privacy → View Privacy Policy.