The essentials
MateIt is a habit tracker for two people. For that reason your entries, streaks, proofs and chats are deliberately visible to your challenge partner; your display name and avatar also appear in the leaderboard and the community. We show no ads and do not track you across other apps or websites. We only collect usage statistics with your consent. App data is stored in Switzerland; some services (including statistics, email and push delivery) process data in the USA (sections 19–20). You can delete your account in the app at any time. The website sets no cookies; you are only added to our waitlist if you sign up and confirm your address (section 4a).
1. Controller
The controller responsible for data processing under the GDPR is:
Finn Herzig
Im Eichbäumle 65
76139 Karlsruhe, Germany
Email: contact@mateit.org
Part A — Website (mateit.org)
2. Hosting and server logs
The website is hosted by Cloudflare, Inc. (USA). When you visit it, Cloudflare processes technically necessary connection data (IP address, time, page requested, browser identifier) to deliver the page and fend off attacks. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, working operation).
3. Cookies and audience measurement
The website itself sets no cookies and uses no analytics, advertising or tracking services. Fonts and all other content are loaded from our own server, not from third parties. Cloudflare may set technically necessary cookies to defend against bots and attacks; these are strictly necessary (Section 25(2) no. 2 TDDDG, German Telecommunications Digital Services Data Protection Act) and do not require consent.
4. Contact by email
If you email us, we process your details to handle your request. The legal basis is Art. 6(1)(b) GDPR if your request relates to your use of MateIt, otherwise Art. 6(1)(f) GDPR (answering your request). Incoming emails are forwarded via Cloudflare Email Routing (which, according to Cloudflare, does not store their content) and handled in a Gmail mailbox provided by Google Ireland Limited (Ireland), which acts as an independent controller under its own privacy terms.
4a. Waitlist and news by email
Until MateIt is in the stores, you can join a waitlist on the home page. You choose one or more lists: Launch email (a single email when the app launches), Updates (occasional news from development) and Insider (invitations to beta tests and short surveys).
Data processed: email address, chosen lists, language, times of sign-up and confirmation, the version of the consent text and the confirmation code, which we only store as a non-reversible hash. When you submit, your browser sends the details directly to server functions of our database provider Supabase; this technically involves your IP address. To prevent abuse we store only a non-reversible hash of it, never the IP address itself, and delete it after one day.
Confirmation (double opt-in): After you sign up, we send you a 6-digit code. You are only on the list once you enter it. Without confirmation we delete the details after 7 days.
Legal basis for the emails of the lists you chose is your consent (Art. 6(1)(a) GDPR, Section 7(2) no. 2 German Unfair Competition Act). We base the confirmation code, the record of your consent and abuse prevention on our legitimate interest (Art. 6(1)(f) GDPR) and the duty to demonstrate consent under Art. 7(1) GDPR. The data is stored with Supabase and sent via Resend (sections 16 and 19). We do not track opens or clicks. The website sets no cookies for this and stores nothing in your browser.
Unsubscribing: Every email to one of the lists contains an unsubscribe link; an email to contact@mateit.org works just as well. You can also leave individual lists only. If you leave all lists, we delete your address together with the record of your consent. If you only chose the launch email, we delete your address once it has been sent.
Part B — The “MateIt” app
5. Getting the app from the App Store and Google Play
You get the app from the Apple App Store or Google Play. Apple (Apple Distribution International Ltd., Ireland) or Google (Google Ireland Limited, Ireland) process data such as your store account as independent controllers under their own privacy policies. We have no influence on this.
6. Providing the app, on-device storage and permissions
Every connection to our servers technically involves your IP address and timestamps; we also process your device and operating system type, app version and language setting. On launch the app checks for an update of its content (over-the-air update via Expo). Expo receives connection data in the process (IP address, operating system, app version and a random installation identifier). Legal basis: Art. 6(1)(b) GDPR.
On your device the app stores, in its protected app storage: your sign-in session, your language, your choices on consents and the terms of use, whether you have already been asked for a rating, your user ID, caches of your profile (including profile picture links), challenge, streak and leaderboard data, and chat messages not yet sent; with your consent also a PostHog identifier and statistics events not yet transmitted (section 13). This is strictly necessary for the features you use (Section 25(2) no. 2 TDDDG). The caches are deleted when you sign out; messages not yet sent stay on the device until you sign in again with the same account and they are sent.
The app only asks for device permissions when you use the relevant feature: camera and photos for your avatar and proofs, microphone for proof videos with sound, notifications for push (section 11). If you decline, only that feature is unavailable. The app does not access your location, contacts or the operating system’s health data (Apple Health, Google Fit).
7. Registration and account
You need an account to use the app. For this we process your email address, your password (only as a cryptographic hash), your display name and technical account data (user ID, sign-in method, timestamps, language, time zone for time-of-day features, chosen accent colour, premium status). You confirm your email address with a code we send you. An account cannot be created without an email address and display name.
When registering you confirm that you are at least 16 years old and accept the terms of use. The time and version of this confirmation are stored on your device and in your account as proof.
You can optionally upload a profile picture (avatar). Before upload it is resized and re-encoded, which removes embedded metadata (e.g. location); only if this fails on your device is the original file uploaded.
You can optionally sign in with Google. We then receive from Google Ireland Limited your Google account identifier, email address, name and, where applicable, the link to your Google profile picture.
Legal basis: Art. 6(1)(b) GDPR; for the record of your confirmation Art. 6(1)(f) GDPR (proof of contract conclusion).
Withdrawal from the contract: If you withdraw from the contract in the app (Profile → “Withdraw from contract”), we store your name, the email address for the acknowledgement, the email address and user ID of your account, the contract details, your statement, the date and time of receipt, and the app version and platform. We send you the acknowledgement of receipt by email (section 16) and a copy to our mailbox (section 4). We then delete your account (see Terms of Use). Legal basis: Art. 6(1)(c) GDPR in conjunction with Section 356a of the German Civil Code (withdrawal function and acknowledgement of receipt) and Art. 6(1)(f) GDPR (proof of receipt and timing of the withdrawal).
8. Challenges, entries and streaks
We process your challenges with their settings and free-text content (title, description, agreed stakes), your entries including optional notes, scores and streaks, invite codes, votes on ending a challenge and timestamps of your activity. Legal basis: Art. 6(1)(b) GDPR.
9. Visibility to other users
MateIt is built on mutual commitment. That is why some data is visible to others:
- To your challenge partner: display name, avatar and premium status, your entries, scores, streaks and your “done today” status, your chat messages and proofs and, through the delivered and read ticks in the chat, when you last opened the app or read the chat. Your time zone, language, sign-in method, accent colour and registration date are also technically retrievable by them. This is the core of the app (Art. 6(1)(b) GDPR) and cannot be switched off.
- To all signed-in users: the leaderboard shows your display name, avatar, premium status and current streak once you are among the top ten. Your avatar is also technically retrievable by all signed-in users. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in motivating competition); you can object under Art. 21 GDPR (section 22). If you publish a challenge in the community marketplace, its title, description, stakes and settings as well as your display name, avatar and premium status are visible (Art. 6(1)(b) GDPR, at your request).
If you leave a challenge, the shared content (e.g. chat, scores) remains visible to your partner. If you delete your account, all challenges you took part in, including entries, chats and proofs, are deleted for both sides.
10. Chat and proof photos/videos
Within a challenge you can chat with your partner and upload photos or videos as proof. Only the two participants can see this content (exception: reports, section 17).
- Proofs are compressed before upload; photos are re-encoded, which removes embedded metadata; only if this fails on your device is the original file uploaded. Photo and video files are automatically deleted after 7 days; the review (accepted/rejected, possibly with your partner’s reason) is kept for the score.
- Deleting a chat hides the history only for you. Once both of you have deleted the chat, the messages are permanently removed from the server; otherwise they are deleted with the challenge or the account.
Legal basis: Art. 6(1)(b) GDPR.
11. Push notifications
If you enable push, we store a push token for your device and the device type. Delivery runs via the Expo Push Service (650 Industries, Inc., USA) and the platform services: Firebase Cloud Messaging (Google) on Android, which processes a Firebase installation identifier, or Apple Push Notification service on iOS. The content, such as your partner’s name, a challenge name or, for chat messages, roughly their first 120 characters, passes through Expo, Google or Apple.
We only send functional notifications (your partner’s activity, reminders based on your device time zone), never advertising. You can switch them off in the app by category or entirely, and in your system settings. We also store in-app notifications about events in your challenges (e.g. someone joining, a new proof, being overtaken, a challenge ending). Legal basis: Art. 6(1)(b) GDPR (a feature you enabled); the push token is strictly necessary for it (Section 25(2) no. 2 TDDDG).
12. Health-related content
MateIt is not a health app and does not analyse your content for health information. Because you word challenges, notes and chats freely, your input (e.g. “smoke-free”, “take medication”) may allow conclusions about your health. Like all other content, it is visible only to you and your partner, unless you publish the challenge in the marketplace (section 9), and is stored solely to provide the app. You decide whether to enter it, and you can delete it at any time.
13. Usage statistics (PostHog)
Only if you consent on first launch or later in the settings do we record pseudonymous usage events via PostHog (PostHog, Inc., USA), e.g. “app opened” or “challenge created”, together with device model, operating system, app version, language, accent colour and premium status. Events are linked to your user ID, not to your name or email. The content of your challenges, chats or proofs and screen recordings are not collected. The data is processed in the USA; your IP address is transmitted, from which PostHog may derive an approximate location (country/city). Events are deleted after 12 months.
Consent is voluntary; you can use the app fully without it. You can withdraw it at any time in the settings, which stops collection immediately; on request we also delete the data collected so far. We store your choice on your device. Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
14. Crash reports (Sentry)
So that we can fix errors, the app sends a report to Sentry (Functional Software, Inc., USA; storage in the EU region Frankfurt) when it crashes or hits an error. It contains the error message, technical trace, device model, operating system and app version, the technical steps shortly before the error (e.g. screens opened, network requests) and whether an app session crashed, linked to a random installation identifier. We do not send your name or email address; the app is configured not to send your IP address. Logged network requests and individual error reports (e.g. when resending chat messages) may contain technical identifiers such as your user or challenge ID.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a stable app); reading the device information needed for this serves solely to provide the app without errors (Section 25(2) no. 2 TDDDG).
15. Premium
Your premium status is stored in your account and shown as a badge to your partner and in the leaderboard and community (section 9). We may unlock premium with one-time codes; we store who redeemed the code and when and, for a code bound to an email address, that address to assign the code. Legal basis: Art. 6(1)(b) GDPR.
16. Sending emails (Resend)
We send confirmation codes (e.g. at registration or password reset), acknowledgements of receipt for a withdrawal as well as feedback and reports to our support mailbox as well as the waitlist emails (section 4a) via Resend (Plus Five Five, Inc., USA). The recipient address and the content of the email are processed; opens and clicks are not tracked. Legal basis: Art. 6(1)(b) GDPR, for acknowledgements of a withdrawal point (c) in conjunction with Section 356a(4) German Civil Code, for feedback and reports point (f), for the waitlist as described in section 4a (list emails point (a), confirmation code point (f)).
17. Feedback, reports and suspensions
Feedback: If you send us feedback in the app, we process your message, an optional attached image (kept in our file storage), app version, platform, language and your user ID and forward them to our support mailbox (section 4). Legal basis: Art. 6(1)(f) GDPR (support and improving the app).
Reports: You can report your challenge partner from the chat or the proof view. A report contains the reason and context (chat or proof), the challenge, the display names and identifiers of both people involved, app version, platform, language and, for chats, up to the last 25 messages of the chat with sender and time. It is stored and sent to our support mailbox for review. The data about the reported person comes from another user’s report.
Suspensions: For breaches of the law or of our rules of conduct we may suspend accounts temporarily or permanently, depending on severity, and store the reason, which is shown to you in the app. Suspensions are decided by a person, not automatically. Legal basis for reports and suspensions: Art. 6(1)(f) GDPR (a safe platform, protecting other users).
18. Minimum age
MateIt is intended for people aged 16 and over. If we learn that an account is run by a younger person, we delete it.
Part C — For website and app
19. Recipients
We use the following service providers. They process data on our behalf and are contractually bound to a level of protection equal to that described in this policy. Apple and Google as store operators, and Google for the Gmail mailbox, act as independent controllers.
| Service | Purpose | Location | Safeguard for third countries |
|---|---|---|---|
| Supabase (Supabase Pte. Ltd., Singapore) | Database, sign-in, file storage, server functions (including the waitlist) | Data: Switzerland (Zurich); server functions run in the data centre closest to the caller | Adequacy decision for Switzerland; standard contractual clauses for access from elsewhere |
| Cloudflare (Cloudflare, Inc., USA) | Website hosting, email forwarding | worldwide | Data Privacy Framework, standard contractual clauses |
| Google (Google Ireland Limited; Google LLC, USA) | Google sign-in, Android push, support mailbox | EU / USA | Data Privacy Framework |
| Apple (Apple Distribution International Ltd., Ireland) | iOS push | EU / USA | Standard contractual clauses |
| Expo (650 Industries, Inc., USA) | Push delivery, app updates | USA | Data Privacy Framework |
| PostHog (PostHog, Inc., USA) | Usage statistics (consent only) | USA | Data Privacy Framework, standard contractual clauses |
| Sentry (Functional Software, Inc., USA) | Crash reports | EU (Frankfurt) | Data Privacy Framework, standard contractual clauses |
| Resend (Plus Five Five, Inc., USA) | Sending emails | USA | Data Privacy Framework, standard contractual clauses |
| Apple App Store / Google Play | Distributing the app | per their own privacy policy | independent controllers |
Other recipients are, as described in section 9, your challenge partner and, for the data named there, all signed-in users.
20. Transfers to third countries
The EU Commission has issued an adequacy decision for Switzerland. We base transfers to the USA on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR) where the provider is certified, and otherwise on EU standard contractual clauses (Art. 46(2)(c) GDPR). You can request a copy of the standard contractual clauses by email.
21. Retention and deletion
| Data | Retention |
|---|---|
| Account, profile, challenges, entries, chats | until your account is deleted (chats possibly earlier, see section 10) |
| Proof photos/videos | 7 days |
| In-app notifications | read: 30 days, unread: at most 90 days |
| Push token | until you sign out, delete your account or the push service reports the token as invalid |
| Suspension reason | as long as the account exists |
| Withdrawal statements | 3 years from receipt (based on the regular limitation period), also after the account is deleted |
| Account after termination by us for good cause | suspended until the six-month objection period has expired or your objection has been decided (Terms of Use section 14) |
| Content you ask us to provide when the contract ends | until it has been provided |
| Reports | at most 12 months after the review is completed, even after an involved account is deleted |
| Feedback (incl. image) | at most 12 months, even after your account is deleted |
| Usage statistics (PostHog) | 12 months |
| Crash reports (Sentry) | at most 90 days |
| Waitlist (confirmed) | until you unsubscribe; launch email only: until it has been sent |
| Waitlist (unconfirmed) | 7 days (deleted in the next daily clean-up run) |
| Hash of the IP address (waitlist abuse prevention) | 1 day (deleted in the next daily clean-up run) |
| Email delivery logs (Resend) | 30 days |
| Server logs (Cloudflare) | only as long as needed for delivery and attack defence |
| Caches on your device | until you sign out |
You can delete your account at any time in the app under Profile → Delete account (also under Profile → Account) or by email (see Delete account). We then delete your account and the associated data; backups kept by our database provider are overwritten after at most 7 days. Reports and feedback to the extent stated above are exempt: we keep them to prevent abuse and to be able to defend legal claims (Art. 6(1)(f), Art. 17(3)(e) GDPR).
22. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can withdraw consent at any time with effect for the future (Art. 7(3)).
Right to object (Art. 21 GDPR): You can object at any time, on grounds relating to your particular situation, to processing we base on Art. 6(1)(f) GDPR, such as your appearance in the leaderboard. We will then stop processing the data unless we can demonstrate compelling legitimate grounds.
To exercise your rights, write to contact@mateit.org; you can also delete your account directly in the app. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example the authority where you live or the one responsible for us: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (State Commissioner for Data Protection and Freedom of Information), Heilbronner Straße 35, 70191 Stuttgart, Germany, www.baden-wuerttemberg.datenschutz.de.
23. Data security
All connections are TLS-encrypted and passwords are stored only as a hash. Row-level access rules in the database (Row Level Security) ensure that each user can only retrieve their own data, the data of their challenges and the visible data named in section 9. Certain actions are rate-limited to prevent abuse.
24. Changes
We update this policy when the app, the services we use or the law change. We will inform you in good time about material changes.