Privacy
Your private life is not product analytics.
This notice describes the current Matchelier website, access queue, and connected private launch app.
The private-launch app creates an account and securely stores your conversation, private working brief, voice transcripts, and photos on Matchelier’s server so you can continue across devices. Selected AI providers process the minimum conversation context needed to reply, only after you give explicit in-app permission for AI processing. Human matchmakers may review information when the service requires it. Your conversation and private working notes are not shown to potential matches. After a clear in-app disclosure and your consent, selected profile photos may be shown privately in a curated introduction proposal. We do not sell personal information or use advertising trackers.
1. Who is responsible
Ivana Soria, trading as Matchelier, is the controller responsible for the personal information described in this notice.
Postal address: Friesenbergstrasse 108, 8055 Zürich, Switzerland
Privacy: privacy@matchelier.ch
Support: support@matchelier.ch
2. Sensitive information and the basis for using it
Swiss data-protection law gives particular protection to information about a person's intimate sphere. Most of what you tell Matchelier is exactly that: your dating history, what you want from a relationship, and how closeness and conflict work for you. We treat your private conversation, working brief, and the notes drawn from them as sensitive personal information, not ordinary product data.
Operating your account and conversation is how we provide the service you asked for. Beyond that, we rely on your explicit consent for the two steps that need it: sending conversation context to AI providers, and showing selected photos and matchmaker-approved introduction details to a potential match. You give those separately in the app, we record when you gave them, and you can withdraw either one without closing your account. We do not use this information for advertising, for profiling unrelated to matchmaking, or for any purpose outside this notice.
3. Your account and private conversation
You can sign in using a code sent to your email address or, on iOS, Sign in with Apple. For Apple sign-in, Apple processes the authentication request. Matchelier receives a stable app-specific identifier and, when Apple provides one, your email address or an Apple private-relay address. We store the provider identifier only as a non-reversible keyed value and store the email address in encrypted form. Matchelier also stores account and device-session records, your conversation, and the private notes and coverage used to build your working brief. The server is authoritative: closing, reinstalling, or opening the app on another device does not erase the account or restart the conversation.
Messages are encrypted at rest. The concierge uses them to understand you, maintain a correctable private brief, and support human-reviewed matchmaking. Matchelier does not publish member profiles. A human operator may open a private conversation for a stated service reason; that access is time-limited and recorded in an audit trail.
Refresh credentials are stored in iOS Keychain. Keychain items can sometimes remain after an app is deleted and reinstalled. You can sign out or revoke another device session. The current app contains no advertising or cross-app tracking technology.
4. Voice, photos, and optional research
If you record a voice answer, the recording is uploaded over an encrypted connection, isolated for processing, and transcribed. You review the transcript before it becomes conversation evidence. Raw audio configured for transcription-only retention is deleted after processing; the confirmed transcript remains with your private conversation.
Photos you choose or take are uploaded, decoded and re-encoded to remove embedded metadata, and stored encrypted for the private service. When you add a profile photo, the app explains that selected profile photos may be shown privately to a potential match as part of a curated introduction proposal. That use requires your recorded consent. Photos are never public, and contact details are not released unless both people express interest. Photo and voice processing use separate in-app permission and consent steps.
Public-profile research is optional. Matchelier searches or reviews a LinkedIn, Instagram, or X link only after you expressly opt in and provide the link. Withdrawing that permission stops future research; it does not silently turn public material into a match-facing profile.
5. AI and human processing
Matchelier uses OpenAI language and transcription models to conduct onboarding, create proposed private notes, transcribe voice answers, and provide limited local or public research. Before OpenAI receives your information, the app asks for your explicit permission and names the processing involved. You can decline and still use the app to review service information or request support, although the AI concierge cannot operate. OpenAI receives only the context needed for that task, not the full member pool merely because it is speaking with you. Matchelier configures Responses API requests not to store response application state. OpenAI states that API data is not used to train its models unless the customer opts in; under its default controls, prompts, responses, and related metadata may remain in abuse-monitoring logs for up to 30 days. Matchelier does not currently claim Zero Data Retention or European data residency. Model output does not by itself authorize an introduction or disclosure.
Human matchmakers supervise the service, review potential introductions, correct or reject model suggestions, respond to requests for help, and may send messages in your service conversation. Human access is limited to operational purposes and audited.
6. Access queue, beta requests, website, notifications, and email
Our hosting provider necessarily processes ordinary network information, such as an IP address and request headers, to deliver and protect the website. Limited request metadata may appear temporarily in security and server logs. Matchelier does not place analytics or advertising cookies on the current site.
We use a self-hosted Umami installation to understand aggregate website use and where visitors found Matchelier. It records page paths, referrer and campaign parameters, successful queue or beta-request steps, browser language, device and browser type, and approximate country. It does not receive names, phone numbers, email addresses, conversation content, or app activity. Query parameters other than the standard UTM campaign fields and a short referral code are removed before collection. First-touch campaign fields, the referring hostname, and the landing path may be associated with later website actions in the same browser session, such as opening a beta-download link. The tracker uses no cookies, respects your browser’s Do Not Track setting, and does not identify you across websites. The analytics service and its separate database run on Matchelier’s existing host in Germany; session replay and heatmaps are disabled.
When you join the website access queue, we collect the phone number you enter and use it to send a one-time queue confirmation and later access information. We store it immediately so refreshing or closing the follow-up step does not lose your place. We then ask for your name. Supplying a name is part of this short queue flow; a first name is sufficient. These fields are encrypted by the server application before they are written to the database and are used only to manage the Zürich private launch and contact you about access.
If you opt into app notifications, we collect and encrypt an Expo push token. It is used only for discreet service updates. Notification text will not name a proposed match or reveal private matchmaking details on the lock screen. You can revoke notification permission in device settings.
When you request Android beta access, we collect the Google-account email address you enter. The server sends that address and the fact that it is an Android beta request to a private Matchelier operations group on Telegram so an authorized beta administrator can add the account. We do not add this address to your matchmaking profile or the matchmaking database. Telegram processes this operational alert as a cloud-chat message under its service and privacy terms. Please do not enter anything beyond the Google account email needed for beta access.
If you email us, we receive your email address, the contents of your message, and normal email delivery metadata. We use that information to answer you or manage your request for private-launch access. Please keep intimate matchmaking details inside the private app rather than ordinary email.
7. Retention, locations, and sharing
Account, conversation, brief, consent, media, queue, notification, audit, support, and aggregate website-analytics records are retained while needed to operate and secure the private launch, understand website performance, provide matchmaking, handle requests, meet legal obligations, or resolve disputes. Encrypted database backups may retain an older copy for up to 7 days, and encrypted mail backups for support or authentication mail may retain an older copy for up to 14 days. We do not sell personal information, use it for targeted advertising, or publish it as a dating profile.
Primary hosting, database, encrypted file storage, email delivery, and host-local encrypted backups are in Germany. OpenAI processing is not configured for European data residency and may occur outside Switzerland. Apple and Expo may also process app-store, authentication, and push-delivery information outside Switzerland under their applicable service terms. Telegram also processes the Android beta alert as a cloud-chat message. For transfers outside Switzerland, we use the safeguard made available under the applicable provider terms. Depending on the provider and destination, that safeguard may be an adequacy decision, the European Commission Standard Contractual Clauses used for Swiss transfers, or another mechanism permitted by Swiss law. We also consider any additional measures the information involved calls for. Write to privacy@matchelier.ch if you want to know which safeguard applies to a particular provider. Service-provider access is limited to the function described here. A potential match may receive the matchmaker-approved introduction copy and selected profile photos covered by your recorded photo-sharing consent. Your conversation, private notes, and contact details are not included; contact details are released only after mutual interest and the applicable service steps.
8. Your choices
Matchelier is intended only for adults aged 18 or older. In the app you can review your working brief, correct information, revoke optional consent, pause and return later, or start a new onboarding conversation while preserving the account history needed for audit and recovery.
You can initiate account deletion from the information screen inside the app. The app immediately signs you out, revokes active device sessions, Apple authorization where applicable, and notification tokens, and places the account into deletion processing. A person completes erasure from active systems after checking legal, safety, dispute, and backup-retention obligations. You may also ask us to remove a queue entry or withdraw from the private launch by contacting privacy@matchelier.ch.
Under Swiss data-protection law you can ask us for a copy of the personal information we hold about you, have inaccurate information corrected, have information deleted, and receive the information you gave us in a common electronic format so that it can be handed over or transferred. You can withdraw a consent at any time without giving a reason. Write to privacy@matchelier.ch to exercise any of these. We normally answer within 30 days, and an ordinary first request costs nothing.
If you think we are handling your information wrongly and we have not put it right, you can raise the matter with the Federal Data Protection and Information Commissioner (FDPIC) in Bern, and you may bring a civil claim.
9. Information about other people
Dating stories may naturally mention an ex-partner, family member, colleague, or friend. Please avoid unnecessary identifying details. Matchelier treats incidental third-party information as private context, does not use it to create an account or searchable dossier about that person, and does not disclose whether someone else is a member.
10. Contact
Ivana Soria, trading as Matchelier
Friesenbergstrasse 108, 8055 Zürich, Switzerland
Privacy questions: privacy@matchelier.ch
General support: support@matchelier.ch