Privacy Policy
Last updated: 13 July 2026
1. Data Controller
The controller responsible for processing your personal data is:
MMJ Solutions UG (haftungsbeschränkt)
Flößergasse 30, 81369 München, Germany
Email: support@metchr.com
2. Data Protection Officer
We are not legally required to appoint a Data Protection Officer and have not appointed one. For all data protection matters you can reach us at support@metchr.com.
3. Data We Collect
3.1 Account Data
When you register via Auth0, we collect:
- Email address — for account management and communication
- Name — display name from your Auth0 profile
- Nickname — display name you choose within the app
- Profile picture — from Auth0 or uploaded by you
3.2 Birthday
We collect your date of birth at registration for age verification. The minimum age to use this app is 18 years. In addition, you actively confirm that you are of age during registration; this confirmation is recorded in the consent log (Section 3.6).
The full date of birth is stored because the app displays your age (in whole years) as part of your profile. Your exact date of birth is visible only to you; other users see at most your age. You can disable showing your age to other users at any time in the privacy settings (Profile → Privacy).
3.3 Location Data
The app collects GPS coordinates via your device's geolocation feature. This data is:
- Held in memory to show you nearby places
- Not persistently stored in our database
- Transmitted to Google Maps to render the map view (see Sections 5 and 8)
3.4 Content You Create
- Places ("Metches") — title, description, coordinates, images/videos
- Chat messages — text messages within places, stored in our database
- Media — uploaded images and videos, stored in Azure Blob Storage
When you create or edit a place, the title and description are sent to Microsoft Azure OpenAI Service for automatic category classification (e.g., "Sports", "Music", "Food & Drinks"). Only the title and description are transmitted — no location coordinates, no media, and no other account data. These fields are not intended for entering personal data. The assigned categories are stored alongside the place in our database. Microsoft does not use this data to train AI models. See Section 5.4 for details.
3.5 Social Data
- Friendships — friend requests and connections
- Place memberships — which places you have joined
- Categories — automatically assigned categories for places you create (see Section 3.4)
3.6 Usage Data
- Last login timestamp
- Account creation timestamp
- Consent log — timestamp and version of accepted policies (IP address and user agent for audit trail)
- Technical diagnostics data — server-side error and performance data for service stability (see Section 5.7)
3.7 Interaction & Preference Data
To improve content recommendations, we record the following interactions with places:
- Place views — when you open a place's detail page
- Place joins — when you join a place
- Place leaves — when you leave a place
- Chat participation — whether you sent a message in a place's chat (not the message content; content is covered in Section 3.5)
From these interactions, we derive category preference scores that indicate your interest in different types of places (e.g., sports, food, music). These scores are used solely to improve the relevance of places shown in your feed. No automated decisions producing legal or similarly significant effects are made based on these scores.
The legal basis is our legitimate interest in relevant content recommendations (Art. 6(1)(f) GDPR). You can disable personalization at any time in the settings and object to this processing under Art. 21 GDPR; the app remains usable without a personalized feed.
All interaction data and preference scores are included in your data export (Section 7) and permanently deleted upon account deletion (Section 10).
4. Legal Basis for Processing
| Data / Processing | Legal Basis | Explanation |
|---|---|---|
| Account data, content, social features | Art. 6(1)(b) GDPR | Contract performance — necessary to provide app functionality |
| Date of birth (age check) | Art. 6(1)(b) and (f) GDPR | Pre-contractual step (18+ requirement) and legitimate interest in age-gating the platform |
| Location data for the map view | Art. 6(1)(b) GDPR | Showing nearby places — core app function; only transient processing, no persistent storage |
| Google Maps (access to device, transfer of IP address/coordinates to Google) | § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR | Your consent via the separate map dialog before the map first loads (see Section 8) |
| AI-based place categorization | Art. 6(1)(f) GDPR | Legitimate interest in content discoverability — only place title and description are processed (see Sections 3.4, 5.4) |
| Interaction tracking, preference scores | Art. 6(1)(f) GDPR | Legitimate interest in relevant content recommendations; opt-out and right to object in Section 3.7 |
| Server diagnostics (Application Insights) | Art. 6(1)(f) GDPR | Legitimate interest in the stability and security of the service (see Section 5.7) |
| Security, abuse prevention | Art. 6(1)(f) GDPR | Legitimate interest in the security of our services |
5. Recipients and Third-Country Transfers
5.1 Auth0 (Okta, Inc.)
Authentication service. Processes: email, name, profile picture. Location: USA. Transfer safeguards: EU-US Data Privacy Framework and, additionally, EU Standard Contractual Clauses.
5.2 Google Maps Platform (Google LLC)
Map service. Receives: IP address, location coordinates when using map features. Location: USA. Transfer only after your consent (Section 8). Google's privacy policy: https://policies.google.com/privacy
5.3 Microsoft Azure
Cloud hosting for database, compute, and file storage (Blob Storage).
The database and Blob Storage are operated in the Azure region Germany West Central (Frankfurt am Main, Germany); the server application runs in the region West Europe (Netherlands). Hosting of your data therefore takes place entirely within the European Union. Data processor: Microsoft Ireland Operations Limited, under a data processing agreement per Art. 28 GDPR.
5.4 Microsoft Azure OpenAI Service
AI-based classification service. When you create or edit a place, the title and description are sent to Microsoft Azure OpenAI Service to automatically assign categories. No location coordinates, media, or account data are transmitted. Microsoft does not use submitted data to train or improve AI models. Data processor: Microsoft Ireland Operations Limited, subject to a data processing agreement per Art. 28 GDPR and EU Standard Contractual Clauses.
The Azure OpenAI Service is operated as an EU Data Zone deployment; the submitted data is processed within the European Union. Microsoft may temporarily store submitted inputs for up to 30 days for abuse monitoring; no storage beyond this takes place.
5.5 Push Notifications (Microsoft, Google, Apple)
For push notifications we use Azure Notification Hubs (Microsoft, region Germany West Central) and the delivery services of the respective device platform: Firebase Cloud Messaging (Google LLC, USA) for Android and the Apple Push Notification service (Apple Inc., USA) for iOS. The push token of your device and the content of the respective notification are processed. Transfer safeguards for the USA: EU-US Data Privacy Framework and, additionally, EU Standard Contractual Clauses. You can disable push notifications at any time in your device's system settings.
5.6 Email Delivery
For sending service emails (e.g., registration confirmations) we may engage an email delivery provider as a data processor per Art. 28 GDPR. Your email address and the content of the respective message are processed. As soon as such a provider is engaged, we will name it here, including the safeguards for any third-country transfers.
5.7 Error and Performance Diagnostics (Azure Application Insights)
To monitor the stability, security, and performance of our service, we use Azure Application Insights (Microsoft, region Germany West Central). Technical diagnostics data from our servers is processed, e.g., response times, error messages, and accessed endpoints with pseudonymous user identifiers. IP addresses are masked at collection time and are not stored; location coordinates are removed from the diagnostics data before transmission. The legal basis is our legitimate interest in stable and secure operations (Art. 6(1)(f) GDPR). Diagnostics data is retained for 90 days. Data processor: Microsoft Ireland Operations Limited (Art. 28 GDPR).
6. Retention Periods
- Account data — retained until you delete your account
- Created places and media — retained until the place or your account is deleted
- Chat messages — retained until the associated place or your account is deleted; in other users' places they are anonymized upon account deletion
- Interaction and preference data — until account deletion or until you disable personalization (Section 3.7)
- Friendship data — retained until your account is deleted
- Consent logs — 3 years after revocation or account deletion (for audit purposes)
- Server diagnostics data (Application Insights) — 90 days (Section 5.7)
7. Your Rights
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR) — request a copy of your stored data
- Right to rectification (Art. 16 GDPR) — correct inaccurate data
- Right to erasure (Art. 17 GDPR) — delete your account and all associated data. In the app under Profile → Account & Data.
- Right to data portability (Art. 20 GDPR) — export your data in machine-readable format. In the app under Profile → Account & Data.
- Right to restriction of processing (Art. 18 GDPR)
- Right to object (Art. 21 GDPR) — you can object to processing based on legitimate interest; this applies in particular to the interaction/preference profiling (Section 3.7)
- Right to withdraw consent (Art. 7(3) GDPR) — at any time, with effect for the future, e.g. for the Google Maps consent
- Right to lodge a complaint with a supervisory authority
To exercise these rights, a message to support@metchr.com is sufficient. We respond within the statutory period of one month.
Competent supervisory authority: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, https://www.lda.bayern.de.
8. Google Maps (§ 25 TDDDG)
This app uses the Google Maps JavaScript API to display maps and location data. When the map loads, your IP address and location data are transmitted to Google LLC.
Before the map is first loaded, we ask for your consent via a separate notice. You can withdraw this consent at any time with effect for the future (Profile → Privacy). Without consent, the map view is not loaded; the other functions of the app remain usable.
Google's privacy policy: https://policies.google.com/privacy
9. Cookies & Local Storage
This app uses browser localStorage to store your session and preferences. This access is strictly necessary to provide the service you have expressly requested and therefore does not require consent (§ 25(2) no. 2 TDDDG). No tracking cookies or third-party analytics cookies are used.
The server-side error and performance diagnostics (Section 5.7) does not set cookies and does not read information from your device.
10. Changes to This Policy
We reserve the right to update this Privacy Policy to reflect changes in the law or in the service or data processing. The current version is always available in the app. For material changes, we will inform you in good time, e.g. by email or a prominent notice in the app. Where processing is based on your consent, we will obtain fresh consent for changes affecting that processing.
