Last updated: 28 August 2026
Victoria von Schmettow
Gabelsbergerstraße 9, 80333 München, Germany
Email: hey@1found1.com
This policy explains what personal data we process when you use the 1found1 app and website (the "Service"), why, on what legal basis, who we share it with, and your rights.
1found1 organises matching into pools. Your profile is only shown to other users in the same pool as you, and you only see users in that pool. Members of a curated community are, by default, in a community-only pool (the "exclusive pool"), where visibility is limited to fellow members of that community; other users are in the open pool (the "public pool"), which is visible to all approved users. Where you have the choice, you can switch pools in your settings. In every case, your photo and full name stay hidden until you and another user mutually match. This visibility is based on your consent (Art. 6(1)(a) GDPR); you can change your pool where available, withdraw consent, pause your profile, or delete it at any time.
Event spaces are separate, sealed pools. If you join a 1found1 event space, you create a space profile (a persona) used only within that space. Your swipes, matches, and messages there are visible only to members of that space and stay separate from the main pools and from every other space. If you leave or are removed from a space, that visibility ends.
All personal data is securely stored with our infrastructure provider Supabase. The servers and databases used are physically located in Frankfurt, Germany (AWS eu-central-1 region). Your core personal data is therefore hosted within the European Union.
Your core data (profiles, answers, messages) stays in the EU with Supabase. Where a provider used for authentication, email or hosting processes limited data outside the EU/EEA, such transfers are safeguarded by appropriate measures (e.g., EU Standard Contractual Clauses).
We use only technically necessary cookies (sign-in/session). No tracking, analytics, or advertising cookies, so no cookie banner is required.
We implement robust, industry-standard administrative, technical, and physical security measures, including encryption (in transit and at rest) and database-level Row Level Security (RLS), to protect your data against unauthorized access, alteration, disclosure, or destruction.
However, no system is 100% secure or impenetrable, and we cannot guarantee absolute security. In the unlikely event of a data breach that is likely to result in a risk to your rights and freedoms, Victoria von Schmettow will act strictly in accordance with the GDPR (Art. 33, 34): we will contain and mitigate the breach without delay, investigate its cause, and notify the competent supervisory authority and affected users without undue delay (and, where required, within 72 hours of becoming aware of it).
We keep your data as long as your account exists. You can delete your profile and account at any time ("Delete profile"); your data is then erased unless statutory retention obligations require otherwise.
You have the right to access, rectification, erasure, restriction, data portability, and objection. You may withdraw any consent at any time with effect for the future. You also have the right to lodge a complaint with a data-protection supervisory authority.
The Service is not intended for persons under 18, and we do not knowingly process their data.
We may update this policy to reflect changes to the Service or legal requirements. The current version is always available in the app.
Questions about this policy or your data: hey@1found1.com