Privacy Policy

Last updated: 28 August 2026

1. Data Controller

Victoria von Schmettow
Gabelsbergerstraße 9, 80333 München, Germany
Email: hey@1found1.com

2. Scope

This policy explains what personal data we process when you use the 1found1 app and website (the "Service"), why, on what legal basis, who we share it with, and your rights.

3. What data we process

  • Account data: your email address (via Google or email sign-up) and an account identifier. If you sign up with email, your password is stored only in encrypted (hashed) form by our auth provider.
  • Profile data: first and last name, photo(s), location, study background, industries, associations, strengths/weaknesses, answers to profile questions, time commitment, and any LinkedIn link.
  • Usage data: swipes, matches, and chat messages.
  • Event-space data: if you join an event space, the space profile (persona) you create for it and your activity scoped to that space (swipes, matches, messages).
  • Notification data: your push-notification consent status and (if you opt in) your push subscription.
  • Technical data: IP address and server log data generated automatically on access.
  • Anonymous usage statistics: aggregated, anonymous measurement of active usage time (duration only, with no link to your identity) to improve the Service.

4. Purposes and legal bases

  • Providing the Service (profile, matching, chat): performance of contract – Art. 6(1)(b) GDPR.
  • Making your profile visible to other users in your matching pool or event space: your consent – Art. 6(1)(a) GDPR.
  • Service & waitlist emails (e.g. sign-up confirmation and the notification once matching is opened for you): performance of contract / legitimate interests – Art. 6(1)(b) and (f) GDPR.
  • Push notifications: your consent – Art. 6(1)(a) GDPR.
  • Security, abuse prevention, rate-limiting: legitimate interests – Art. 6(1)(f) GDPR.
  • Anonymous usage statistics (active usage time): legitimate interests – Art. 6(1)(f) GDPR. Collected anonymously and in aggregate, with no profiling and no additional cookies.

5. Profile visibility

1found1 organises matching into pools. Your profile is only shown to other users in the same pool as you, and you only see users in that pool. Members of a curated community are, by default, in a community-only pool (the "exclusive pool"), where visibility is limited to fellow members of that community; other users are in the open pool (the "public pool"), which is visible to all approved users. Where you have the choice, you can switch pools in your settings. In every case, your photo and full name stay hidden until you and another user mutually match. This visibility is based on your consent (Art. 6(1)(a) GDPR); you can change your pool where available, withdraw consent, pause your profile, or delete it at any time.

Event spaces are separate, sealed pools. If you join a 1found1 event space, you create a space profile (a persona) used only within that space. Your swipes, matches, and messages there are visible only to members of that space and stay separate from the main pools and from every other space. If you leave or are removed from a space, that visibility ends.

6. Where your data is stored

All personal data is securely stored with our infrastructure provider Supabase. The servers and databases used are physically located in Frankfurt, Germany (AWS eu-central-1 region). Your core personal data is therefore hosted within the European Union.

7. Other processors

  • Vercelhosting, delivery & cookieless, aggregated analytics (Vercel Web Analytics, no cookies, no personal profiling).
  • Googleauthentication (OAuth).
  • Resendsending emails.
  • Upstashabuse protection (rate-limiting).
  • Push-services (Google, Mozilla, Apple) – only if you enable notifications.

Your core data (profiles, answers, messages) stays in the EU with Supabase. Where a provider used for authentication, email or hosting processes limited data outside the EU/EEA, such transfers are safeguarded by appropriate measures (e.g., EU Standard Contractual Clauses).

8. Cookies

We use only technically necessary cookies (sign-in/session). No tracking, analytics, or advertising cookies, so no cookie banner is required.

9. Data security and data breaches

We implement robust, industry-standard administrative, technical, and physical security measures, including encryption (in transit and at rest) and database-level Row Level Security (RLS), to protect your data against unauthorized access, alteration, disclosure, or destruction.

However, no system is 100% secure or impenetrable, and we cannot guarantee absolute security. In the unlikely event of a data breach that is likely to result in a risk to your rights and freedoms, Victoria von Schmettow will act strictly in accordance with the GDPR (Art. 33, 34): we will contain and mitigate the breach without delay, investigate its cause, and notify the competent supervisory authority and affected users without undue delay (and, where required, within 72 hours of becoming aware of it).

10. Retention and deletion

We keep your data as long as your account exists. You can delete your profile and account at any time ("Delete profile"); your data is then erased unless statutory retention obligations require otherwise.

11. Your rights

You have the right to access, rectification, erasure, restriction, data portability, and objection. You may withdraw any consent at any time with effect for the future. You also have the right to lodge a complaint with a data-protection supervisory authority.

12. Minimum age

The Service is not intended for persons under 18, and we do not knowingly process their data.

13. Changes

We may update this policy to reflect changes to the Service or legal requirements. The current version is always available in the app.

14. Contact

Questions about this policy or your data: hey@1found1.com