A rigorous, audit-ready statement of how MatchGen.ai processes personal data across every category. Written for regulators, corporate due-diligence teams, and any user who wants the full picture.
Account creation, authentication, chat + memory functionality, subscription fulfilment, payment settlement.
We can't process your subscription or serve replies from a companion without executing our Terms of Service.
Long-term memory extraction, marketing emails, non-essential cookies, any processing of preference data linked to gender/orientation.
A tick-box during onboarding. Withdrawable at any time from Settings, with no impact on core functionality.
Service security (fraud/abuse detection), performance analytics, debugging, direct marketing of our own similar products to existing customers.
A balancing test is performed and documented for each use. Users can object at privacy@matchgen.ai.
Tax and accounting records, age-verification records, responding to lawful requests from courts or supervisory authorities.
Overrides erasure requests where retention is mandated by law (e.g. financial records must be kept for 10 years).
| Category | Legal basis | Retention |
|---|---|---|
| Account Data | Contract | 3 years standard — shortened to 1 year on inactivity |
| Content Data | Contract + consent (memory) | For the life of the account; deleted on account closure |
| Generated Media | Contract | For the life of the account, cached in MongoDB GridFS |
| Payment Data | Contract + legal obligation | 10 years (tax law) |
| Technical Data | Legitimate interest | 30 days |
| Marketing Data | Consent | 2 years from last engagement, or until consent is withdrawn |
| Sensitive Data | Explicit consent (Art. 9(2)(a)) | Deleted immediately on consent withdrawal |
Some processing happens outside the European Economic Area (mainly the US, for AI inference). Every transfer is covered by Standard Contractual Clauses (SCCs) approved by the European Commission, or by an active adequacy decision, plus technical safeguards (encryption in transit + at rest).
| Sub-processor | Purpose | Jurisdiction | Safeguard |
|---|---|---|---|
| Groq | Primary LLM inference (chat) | USA | SCCs |
| Google (Gemini API) | Secondary LLM inference | USA | SCCs |
| Pollinations | Fallback LLM + image inference | EU | EU direct |
| ElevenLabs | Text-to-speech synthesis | USA | SCCs |
| Fal.ai | High-quality image generation (LoRA) | USA | SCCs |
| MongoDB Atlas | Application database + file storage (GridFS) | EU (primary) | EU direct |
| Paystack | Payment processing (Africa) | Nigeria (adequate) | Contract |
| Razorpay | Payment processing (India) | India | SCCs |
| Stripe | Payment processing (Global) | USA | SCCs |
Substantial changes to this document are notified to logged-in users at least 30 days before taking effect. Minor editorial changes are logged in a public changelog available on request.
Data Protection Officer: dpo@matchgen.ai · General: privacy@matchgen.ai