Privacy notice
Last updated: 11 October 2026
Matchiversary lets couples make each other a loving "dating profile" and share it privately. This notice explains which personal data we process, why, and what rights you have. The Swiss Federal Act on Data Protection (FADP) applies, and for people in the EU/EEA, the General Data Protection Regulation (GDPR).
1. Controller
schimo Informatik GmbH, Kirchweg 5, 8755 Ennenda, Schweiz / Switzerland
Contact for all privacy matters: contact@schimo.ch
2. What we process
- Account: your email address, chosen language and technical sign-in data (e.g. time of last sign-in).
- Profiles you create: names, nickname, age, place of residence, job, height, match date, photos, photo texts, answers and anything else you enter.
- Photos: resized and re-saved in your browser. This removes all metadata, including location (GPS), before anything is uploaded.
- Sharing: whether a profile is shared, its random link, and your confirmation that everyone shown is an adult and has agreed.
- Technical data: IP address, browser type and time of requests, briefly logged by our service providers to run and protect the service.
- Visitor statistics: anonymous page views via Cloudflare Web Analytics, without cookies and without profiling.
- Reports: when someone reports a shared profile, we store the chosen reason, any message and the time. Reporters do not need to sign in, and we store no contact details for them.
3. Data about other people
A profile usually describes someone else, typically your partner. Only upload photos and details that the people concerned agree to, and only of adults. Photos and personal details can reveal sensitive information (e.g. about a relationship or sexual orientation). We use them solely to display the profile.
Are you shown on a profile and want it removed? Email us at contact@schimo.ch. You can also use "Report this profile" at the bottom of a shared profile; it is hidden immediately. We review every report promptly and remove the profile where the request is justified.
4. Purposes and legal bases
- Providing the service: account, creating, storing and sharing profiles (GDPR Art. 6(1)(b)).
- Sensitive content you choose to enter: based on your consent (GDPR Art. 9(2)(a)). You can withdraw it anytime by deleting the content.
- Security, abuse prevention, handling reports and anonymous statistics: our legitimate interest in a safe, working service and in protecting the people shown (GDPR Art. 6(1)(f)).
- Sign-in emails: to perform our contract with you. We send no marketing emails.
5. Who sees your data
Profiles are private until you create a link. Anyone with the link can view the profile. Links are random, not indexed by search engines, and you can turn them off at any time. Note that recipients can pass a link on.
6. Service providers and transfers abroad
- Supabase Inc. (USA): database, sign-in and photo storage. Data is stored in a data centre in the EU (Ireland).
- Cloudflare Inc. (USA): website hosting, protection against attacks, sending emails (sign-in, report notifications), and anonymous visitor statistics.
- Both providers process data only on our behalf. As they are based in the US, access from there cannot be ruled out. We rely on the Data Privacy Framework (EU-US and Swiss-US) where the provider is certified, and otherwise on the European Commission’s Standard Contractual Clauses with the amendments for Switzerland.
7. Retention
- We keep profiles and photos until you delete them. Under "My profiles" you can delete single profiles or your whole account, including all photos, at any time.
- Our providers’ technical logs are deleted automatically after a short time, usually within days to weeks.
- We keep reports while we handle them, at most 12 months. When a profile is deleted, its reports are deleted too.
- Data we must keep for legal reasons is kept only as long as required.
8. Cookies and local storage
We use no tracking or advertising cookies. We only store what the service needs: your sign-in (in your browser’s local storage) and your language choice (cookie "lang"). Visitor statistics work without cookies.
9. Your rights
You have the right to access, rectify and erase your data, to restrict processing, to receive your data or have it transferred, and, where the GDPR applies, to object to processing based on legitimate interests. Contact contact@schimo.ch.
You can also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch) or, if you live in the EU/EEA, to the data protection authority of your country.
10. Minimum age
Matchiversary is for people aged 18 and over.
11. Security
Connections are encrypted (HTTPS). Database access rules ensure only you can edit your profiles. Photos are kept in private storage and shown only through time-limited links.
12. Changes
We update this notice when the service changes. The version published here applies.