Privacy Policy
Last updated: 13 August 2026
1. Data Controller
The controller responsible for processing your personal data is:
MMJ Solutions UG (haftungsbeschränkt)
Flößergasse 30, 81369 München, Germany
Email: support@metchr.com
2. Data Protection Officer
We are not legally required to appoint a Data Protection Officer and have not appointed one. For all data protection matters you can reach us at support@metchr.com.
3. Data We Collect
3.1 Account Data
You can sign in in three ways: with an email address and password, with your Google account, or with your Apple ID. In every case the sign-in is handled by our authentication provider Auth0 (Section 5.1). If you choose Google or Apple, we receive the account data below from the provider you selected (Sections 5.8 and 5.9). We collect:
- Email address — for account management and communication
- Name — display name from your Auth0 profile, or from Google or Apple
- Nickname — display name you choose within the app
- Profile picture — optional, uploaded by you; if you upload none, the app displays your initials instead
- Bio — optional free text about yourself, up to 200 characters, visible to all users of the app; stored until you clear it or delete your account
If you sign in with your Apple ID and choose "Hide My Email", we receive an anonymised relay address from Apple (ending in @privaterelay.appleid.com) instead of your actual address. We use it like any other email address; your actual address is not known to us in that case. Apple transmits your name only on the very first sign-in.
If you later sign in by a different route based on the same verified email address, we automatically associate that sign-in with your existing account so that no second profile is created. The match is made solely on the verified email address held by our authentication provider Auth0 (Section 5.1), which thereby learns that the sign-in routes concerned belong to the same person. No association is made if the address is unverified on either side, if you use "Hide My Email", if more than one account holds the same verified address, or if the association fails technically. In those cases two separate profiles exist; write to us at support@metchr.com and we will merge the accounts or delete the surplus profile.
3.2 Birthday
We collect your date of birth at registration for age verification. The minimum age to use this app is 18 years. In addition, you actively confirm that you are of age during registration; this confirmation is recorded in the consent log (Section 3.6).
The full date of birth is stored because the app displays your age (in whole years) as part of your profile. Your exact date of birth is visible only to you; other users see at most your age. You can disable showing your age to other users at any time in the privacy settings (Settings → Privacy).
3.3 Location Data
The app collects GPS coordinates via your device's geolocation feature. This data is:
- Held in memory to show you nearby places
- Not persistently stored in our database
- Transmitted to Google Maps to render the map view (see Sections 5 and 8)
3.4 Content You Create
- Places ("Metches") — title, description, coordinates, images/videos
- Chat messages — text messages you send in a place's group chat or in a one-to-one conversation with another user, stored in our database
- Media — uploaded images and videos, stored in Azure Blob Storage
Chat messages are visible to the other participants of the respective conversation: in a place's chat to that place's members, in a one-to-one conversation only to the other person (a preview of the message is additionally transmitted as a push notification — see Section 5.5). If a message is reported, its content is made available to our moderation team for review. This applies to one-to-one conversations as well as place chats — a report is the only circumstance in which we read the content of a private conversation. The legal basis is our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR, see Section 4).
When you create or edit a place, the title and description are sent to Microsoft Azure OpenAI Service for automatic category classification (e.g., "Sports", "Music", "Food & Drinks"). Only the title and description are transmitted — no location coordinates, no media, and no other account data. These fields are not intended for entering personal data. The assigned categories are stored alongside the place in our database. Microsoft does not use this data to train AI models. See Section 5.4 for details.
3.5 Social Data
- Friendships — friend requests and connections
- Place memberships — which places you have joined
- Categories — automatically assigned categories for places you create (see Section 3.4)
Your friend list is visible to other users by default. You can disable showing your friend list to other users at any time in the privacy settings (Settings → Privacy); the number of friends remains visible either way. Your name may also appear in the friend lists of other users; whether that list is shown is controlled by that user's own setting.
You control who may start a one-to-one conversation with you — everyone, friends only, or nobody — at any time in the privacy settings (Settings → Privacy). The setting applies to new and existing conversations. People you have blocked can never message you regardless of this setting.
3.6 Usage Data
- Last login timestamp
- Account creation timestamp
- Consent log — timestamp and version of accepted policies (IP address and user agent for audit trail)
- Technical diagnostics data — server-side error and performance data for service stability (see Section 5.7)
3.7 Interaction & Preference Data
To improve content recommendations, we record the following interactions with places:
- Place views — when you open a place's detail page
- Place joins — when you join a place
- Place leaves — when you leave a place
- Chat participation — whether you sent a message in a place's chat (not the message content; content is covered in Section 3.4)
From these interactions, we derive category preference scores that indicate your interest in different types of places (e.g., sports, food, music). These scores are used solely to improve the relevance of places shown in your feed. No automated decisions producing legal or similarly significant effects are made based on these scores.
The legal basis is our legitimate interest in relevant content recommendations (Art. 6(1)(f) GDPR). You can disable personalization at any time in the settings and object to this processing under Art. 21 GDPR; the app remains usable without a personalized feed.
All interaction data and preference scores are included in your data export (Section 7) and permanently deleted upon account deletion (Section 7).
4. Legal Basis for Processing
| Data / Processing | Legal Basis | Explanation |
|---|---|---|
| Account data, content, social features | Art. 6(1)(b) GDPR | Contract performance — necessary to provide app functionality |
| Signing in with Google or Apple | Art. 6(1)(b) GDPR | Contract performance — only if you choose that sign-in method yourself; the email-and-password alternative remains available at all times (see Sections 5.8, 5.9) |
| Automatic association of sign-in routes sharing the same verified email address | Art. 6(1)(b) GDPR | Contract performance — maintaining exactly one account per person and access via the sign-in route you chose (see Section 3.1) |
| Date of birth (age check) | Art. 6(1)(b) and (f) GDPR | Pre-contractual step (18+ requirement) and legitimate interest in age-gating the platform |
| Location data for the map view | Art. 6(1)(b) GDPR | Showing nearby places — core app function; only transient processing, no persistent storage |
| Google Maps (access to device, transfer of IP address/coordinates to Google) | § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR | Your consent via the separate map dialog before the map first loads (see Section 8) |
| AI-based place categorization | Art. 6(1)(f) GDPR | Legitimate interest in content discoverability — only place title and description are processed (see Sections 3.4, 5.4) |
| Interaction tracking, preference scores | Art. 6(1)(f) GDPR | Legitimate interest in relevant content recommendations; opt-out and right to object in Section 3.7 |
| Server diagnostics (Application Insights) | Art. 6(1)(f) GDPR | Legitimate interest in the stability and security of the service (see Section 5.7) |
| Security, abuse prevention | Art. 6(1)(f) GDPR | Legitimate interest in the security of our services |
5. Recipients and Third-Country Transfers
5.1 Auth0 (Okta, Inc.)
Authentication service. Processes: email, name. Auth0 also composes and sends account-related service emails on our behalf (email verification, password reset); for delivery see Section 5.6. Our tenant is operated in Auth0's EU region; the data is stored and processed in EU data centres. The provider is Okta, Inc., headquartered in the USA; for any access from the USA (for example in the course of support), the EU-US Data Privacy Framework and, additionally, the EU Standard Contractual Clauses apply as safeguards. When you delete your Metchr account, we also delete your account at Auth0, so the email address and name held there are erased as well.
5.2 Google Maps Platform (Google LLC)
Map service. Receives: IP address, location coordinates when using map features. Location: USA; Google LLC is certified under the EU-US Data Privacy Framework, and the EU Standard Contractual Clauses apply in addition. Transfer only after your consent (Section 8). Google's privacy policy: https://policies.google.com/privacy
5.3 Microsoft Azure
Cloud hosting for database, compute, file storage (Blob Storage), and the web app.
The database and Blob Storage are operated in the Azure region Germany West Central (Frankfurt am Main, Germany); the server application and the web app (Azure Static Web Apps) run in the region West Europe (Netherlands). All of your data is therefore stored and processed exclusively within the European Union. Data processor: Microsoft Ireland Operations Limited, under a data processing agreement per Art. 28 GDPR.
One technical qualification, for the sake of completeness: Azure Static Web Apps delivers the web app's static files (HTML, CSS, JavaScript, images) over a globally distributed delivery network, so that they load from a server near you. These files contain no personal data. If you access the app from outside the European Union, your IP address may be processed by a delivery node in that region for the purpose of delivering the files; when accessed from within the EU, delivery takes place from within the EU.
5.4 Microsoft Azure OpenAI Service
AI-based classification service. When you create or edit a place, the title and description are sent to Microsoft Azure OpenAI Service to automatically assign categories. No location coordinates, media, or account data are transmitted. Microsoft does not use submitted data to train or improve AI models. Data processor: Microsoft Ireland Operations Limited, subject to a data processing agreement per Art. 28 GDPR and EU Standard Contractual Clauses.
The Azure OpenAI Service is operated as an EU Data Zone deployment; the submitted data is processed within the European Union. Microsoft may temporarily store submitted inputs for up to 30 days for abuse monitoring; no storage beyond this takes place.
5.5 Push Notifications (Microsoft, Google, Apple)
For push notifications we use Azure Notification Hubs (Microsoft, region Germany West Central) and the delivery services of the respective device platform: Firebase Cloud Messaging (Google LLC, USA) for Android and the Apple Push Notification service (Apple Inc., USA) for iOS. The push token of your device and the content of the respective notification are processed. Transfer safeguards for the USA: EU-US Data Privacy Framework and, additionally, EU Standard Contractual Clauses. You can disable push notifications at any time in your device's system settings.
5.6 Email Delivery (Azure Communication Services)
For sending service emails (e.g., links to verify your email address or to reset your password) we use Azure Communication Services (Microsoft). Your email address and the content of the respective message are processed. The service is configured with the Europe data location, so delivery itself takes place within the European Union. Data processor: Microsoft Ireland Operations Limited, under a data processing agreement per Art. 28 GDPR; the EU Standard Contractual Clauses of the Microsoft data processing agreement apply additionally to any support access.
These emails are triggered and composed by our authentication service Auth0 (Section 5.1); the links they contain also point to Auth0. The Auth0 tenant is operated in the EU region, where the data is stored and processed in EU data centres. As Okta, Inc. is headquartered in the USA, access from the USA (for example in the course of support) cannot be ruled out; the safeguards named in Section 5.1 apply to it.
Only account-related service emails are sent; no open or click tracking takes place. The legal basis is performance of the contract (Art. 6(1)(b) GDPR).
5.7 Error and Performance Diagnostics (Azure Application Insights)
To monitor the stability, security, and performance of our service, we use Azure Application Insights (Microsoft, region Germany West Central). Technical diagnostics data from our servers is processed, e.g., response times, error messages, and accessed endpoints with pseudonymous user identifiers. IP addresses are masked at collection time and are not stored; location coordinates are removed from the diagnostics data before transmission. The legal basis is our legitimate interest in stable and secure operations (Art. 6(1)(f) GDPR). Diagnostics data is retained for 90 days. Data processor: Microsoft Ireland Operations Limited (Art. 28 GDPR).
5.8 Signing in with Google (Google LLC)
Applies only if you choose to sign in with Google. For authentication you are redirected to Google, which thereby receives your IP address and the information that you are signing in to Metchr. Google then provides us with your email address, your name, a Google user identifier and a link to your Google profile picture, which we do not use in the app. We do not access any further Google services (such as Contacts, Calendar or Drive) and request no permissions for them.
The purpose is solely to authenticate you and set up your account; the legal basis is Art. 6(1)(b) GDPR (Section 4). Where information is stored on or read from your device in the course of signing in (sign-in state and session data), this is strictly necessary for the sign-in you expressly requested and therefore requires no consent (§ 25(2) no. 2 TDDDG); Google is responsible for information it stores on your device within its own service. For users in the European Economic Area, Google Ireland Limited (Ireland) is an independent controller for Google's processing of your data, not our processor; any onward transfer to Google LLC (USA) takes place under Google's own responsibility. Google LLC is certified under the EU-US Data Privacy Framework, and the EU Standard Contractual Clauses apply in addition. You can end the connection at any time in your Google account's security settings, under your connections to third-party apps. Google's privacy policy: https://policies.google.com/privacy
5.9 Signing in with Apple (Apple Distribution International Limited)
Applies only if you choose "Sign in with Apple". For authentication you are redirected to Apple, which thereby receives your IP address and the information that you are signing in to Metchr. Apple provides us with an Apple user identifier and your email address — at your option as an anonymised relay address (see Section 3.1). Apple transmits your name only on the very first sign-in.
The purpose is solely to authenticate you and set up your account; the legal basis is Art. 6(1)(b) GDPR (Section 4). Where information is stored on or read from your device in the course of signing in (sign-in state and session data), this is strictly necessary for the sign-in you expressly requested and therefore requires no consent (§ 25(2) no. 2 TDDDG); Apple is responsible for information it stores on your device within its own service. For users in the European Economic Area, Apple Distribution International Limited (Ireland) is an independent controller for Apple's processing of your data, not our processor; any onward transfer to Apple Inc. (USA) takes place under Apple's own responsibility and in accordance with Apple's privacy policy. For the separate transmission of push tokens to Apple Inc., see Section 5.5. You can end the connection at any time in your Apple ID settings under "Sign in with Apple". Apple's privacy policy: https://www.apple.com/legal/privacy/
6. Retention Periods
- Account data — retained until you delete your account
- Login data held by Auth0 (email address, name) — your Auth0 account is deleted together with your Metchr account, so this data is erased at the authentication service as well (Section 5.1)
- Connection to Google or Apple — the connection ends when your Auth0 account is deleted. We have no access to data held by Google or Apple themselves; revoke the authorisation there in the settings of the respective account (Sections 5.8 and 5.9)
- Created places and media — retained until the place or your account is deleted
- Chat messages — messages in a place's chat are retained until that place or your account is deleted; in other users' places they are anonymized upon account deletion. One-to-one conversations, including all their messages, are deleted entirely as soon as either participant deletes their account
- Interaction and preference data — until account deletion or until you disable personalization (Section 3.7)
- Friendship data — retained until your account is deleted
- Consent logs — until your account is deleted; they are erased together with the account. If you revoke an individual consent without deleting your account, that log entry is retained for 3 years for audit purposes
- Service emails — your email address and the message content are processed solely for delivery; we do not store them beyond that (Section 5.6)
- Server diagnostics data (Application Insights) — 90 days (Section 5.7)
7. Your Rights
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR) — request a copy of your stored data
- Right to rectification (Art. 16 GDPR) — correct inaccurate data
- Right to erasure (Art. 17 GDPR) — delete your account and all associated data. In the app under Settings → Account & Data.
- Right to data portability (Art. 20 GDPR) — export your data in machine-readable format. In the app under Settings → Account & Data.
- Right to restriction of processing (Art. 18 GDPR)
- Right to object (Art. 21 GDPR) — you can object to processing based on legitimate interest; this applies in particular to the interaction/preference profiling (Section 3.7)
- Right to withdraw consent (Art. 7(3) GDPR) — at any time, with effect for the future, e.g. for the Google Maps consent
- Right to lodge a complaint with a supervisory authority
To exercise these rights, a message to support@metchr.com is sufficient. We respond within the statutory period of one month.
Competent supervisory authority: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, https://www.lda.bayern.de.
8. Google Maps (§ 25 TDDDG)
This app uses the Google Maps JavaScript API to display maps and location data. When the map loads, your IP address and location data are transmitted to Google LLC.
Before the map is first loaded, we ask for your consent via a separate notice. You can withdraw this consent at any time with effect for the future (Settings → Privacy). Without consent, the map view is not loaded; the other functions of the app remain usable.
Google's privacy policy: https://policies.google.com/privacy
9. Cookies & Local Storage
This app uses browser localStorage to store your session and preferences. This access is strictly necessary to provide the service you have expressly requested and therefore does not require consent (§ 25(2) no. 2 TDDDG). No tracking cookies or third-party analytics cookies are used.
The server-side error and performance diagnostics (Section 5.7) does not set cookies and does not read information from your device.
10. Changes to This Policy
We reserve the right to update this Privacy Policy to reflect changes in the law or in the service or data processing. The current version is always available in the app. For material changes, we will inform you in good time, e.g. by email or a prominent notice in the app. Where processing is based on your consent, we will obtain fresh consent for changes affecting that processing.
