Legal
Privacy policy
Last updated: 2 September 2026
The short version: what you post is meant to be seen, what identifies you is kept to the minimum the app needs, none of it is sold, and you can delete your account from inside the app. The rest of this page is the detail, written against what the app actually does rather than from a template.
Who is responsible for your data
The data controller for Find Me Matcha is Mads Petersen, Copenhagen, Denmark — an individual established in the EU, not a company. For any privacy question or request, write to support@matcha.smedje.com.
TODO: confirm the controller name above is the name that should appear on a public legal page for this product, and that support@matcha.smedje.com is a mailbox that exists and is monitored. Both are carried over from the project’s shared configuration and have not been independently confirmed for Find Me Matcha.
What we collect, and why
Your account
To create an account you give us an email address and a password, or you sign in with Apple or Google, in which case we receive the identifier those services return rather than a password. Sign-in is operated for us by Amazon Cognito (Amazon Web Services). We use it to sign you in, to keep your reviews and lists attached to you, and to email you a confirmation or password-reset code when you ask for one.
Your profile
A handle, and optionally a display name, a short bio, an avatar photo, an Instagram handle and a home city. Your handle and anything else you fill in are shown to other people — that is what a profile is for.
Your date of birth
Asked once, when you claim your handle. It is never shown anywhere, there is no birthday feature behind it, and it is not sent back to the app. It exists so we can tell whether an account is old enough to post: the minimum age is 13, which is Denmark’s digital-consent age under Article 8 of the GDPR. If you tell us you are younger, we do not give you an account, and we delete the one you had started — including the email address attached to it.
What you post — public by design
Reviews (a rating, the tags you tick, what you ordered, and any note you write), photos and their captions, the café facts you confirm or correct, cafés you propose, your lists, the cafés you save, who you follow, and your likes and comments.
This is the product, and most of it is public. Photos and reviews appear on the café’s page and in the app’s feed with your handle on them. Lists you make can be private, unlisted, or public — you choose, and the app says which is which before you share one. Assume that anything you post other than a private list can be seen by anyone using the app.
Your location — used on your device
With your permission, the app reads your location only while it is open, to centre the map on you and show cafés near you. There is no background tracking. Your coordinates are used on your device and are not stored on our servers: when you confirm a fact or post a review, what we store is which café it was about, not where you were standing.
The purpose string iOS shows you says exactly this: “Find Me Matcha uses your location to show cafés near you and centre the map on where you are.”
Camera and photo library
The app asks for the camera so you can photograph your matcha when you post a review, and for your photo library so you can pick a photo you already have. Both are asked for at the moment you use them, and nothing is read from your library except the photo you choose. Photos you post are uploaded to our storage and shown on the café’s page.
Notifications
You can choose which kinds of notification you want — follows, likes, comments, mentions, agreements, and reviews of cafés you saved — and that choice is stored on your account. Turning one off means it is never written, so nothing already in your notifications changes.
The app does not currently register a push token with Apple or Google, so we hold no device push identifier for you.
Product analytics
We use PostHog to understand how the app is used. What it receives:
- A small set of usage events. Today these cover the sign-in and sign-up flow only — which screen was reached, whether a submission succeeded or failed, and the error code when it failed. No email address, handle, café, search term or free text is sent as an event property.
- App lifecycle events — installed, updated, opened, backgrounded.
- Device and app information attached to every event — app version and build, device manufacturer, model and type, operating system and version, your phone’s language and time zone, and whether the app is running on a simulator.
- An anonymous identifier generated on your device. We never tell PostHog who you are: your account, email and handle are not sent to it, and no person profile is created.
- Your IP address, because any connection to the internet carries one. PostHog is configured not to derive a location from it, so no country, region or city is attached to your events. We do not store your IP address ourselves.
- Session recordings. The app records what happens on screen so we can see where it goes wrong. Images and photos are masked in these recordings, and so is everything you type — the email address you enter when signing in, what you search for, and the notes you write in a review are all hidden before the recording leaves your phone. Password fields are masked by the operating system as well. What a recording does show is the shape of the screen and how you moved through it: which cafés were listed, which rows you tapped, where you scrolled.
Analytics are on by default, and you can turn them off in the app at Settings → Privacy → Share usage data. Turning that switch off stops the events and stops screen recording immediately; recording starts again only if you switch it back on and reopen the app. The choice is stored on your phone, so it applies straight away and works offline. You can also object by writing to support@matcha.smedje.com; see Your rights. PostHog is a processor acting on our instructions and does not use your data for its own purposes.
Crash and error reports
We use Sentry to receive crash and error reports. A report contains the error and where in the app it happened, the app version and build, and device context such as model, operating system version and available memory. Sentry is configured not to attach your IP address, email or username, and we do not attach your account id, so these reports are not linked to you. Requests to our own API that fail with a server error are reported too.
What we never do
- No advertising, and no ad-tracking or attribution SDKs.
- We do not sell your personal data, and we do not share it for advertising.
- We do not translate your reviews or bio ourselves. When the app offers to translate somebody’s text it hands it to your phone, which does the work on the device, and the app says so.
- We do not use what you post to train someone else’s models.
Where your data is, and who else touches it
Your account, your reviews and your photos are stored on cloud infrastructure in the European Union (Amazon Web Services, Ireland, with a Postgres database hosted in the EU). We share data only with the providers needed to run the app, each acting on our instructions under a data-processing agreement:
| Who | What for | Where |
|---|---|---|
| Amazon Web Services | Servers, storage for photos, and the email that sends your confirmation and reset codes | EU (Ireland) |
| Amazon Cognito (AWS) | Sign-in, including Apple and Google sign-in | EU (Ireland) |
| Neon | The Postgres database behind the app | EU |
| PostHog | Product analytics and session recordings | United States |
| Sentry | Crash and error reports | EU (Germany) |
| Apple | App distribution, and Sign in with Apple if you use it | Global |
| Sign in with Google, if you use it | Global |
We do not share your personal data with anyone else unless the law requires it.
International transfers
Your account, reviews and photos stay in the European Union. Analytics data is processed in the United States by PostHog, and sign-in with Apple or Google involves those companies’ own global infrastructure. Those transfers rely on the safeguards required by Chapter V of the GDPR, including the European Commission’s Standard Contractual Clauses or an adequacy decision where one applies.
Legal bases (GDPR)
- Contract (Article 6(1)(b)) — your account, your profile, and everything you post. We process it to give you the service you signed up for.
- Legitimate interest (Article 6(1)(f)) — analytics, session recordings, crash reports, and preventing abuse of the shared map. Our interest is in an app that works and data other people can rely on. You can object; see below.
- Consent (Article 6(1)(a)) — your location, the camera, your photo library, and notifications. Your phone asks you, and you can withdraw permission at any time in your device settings.
- Legal obligation (Article 6(1)(c)) — checking that you are old enough to have an account.
How long we keep it
For as long as you have an account. When you ask us to delete it, your account is deactivated immediately and everything scheduled for erasure is erased after a seven-day window in which signing back in restores it. What survives, and why, is on the account deletion page — in short, your reviews stay but stop being yours.
Email you send to our support address is stored for 90 days and then deleted. Analytics and crash data are kept according to our providers’ retention settings and are not linked to your account.
Your rights
Under the GDPR you can:
- ask what we hold about you, and get a copy of it;
- have it corrected;
- have it deleted;
- restrict or object to processing based on legitimate interest — including analytics and session recordings;
- withdraw a permission you gave, at any time, in your device settings;
- complain to a supervisory authority. In Denmark that is Datatilsynet.
Objecting to analytics is built into the app — Settings → Privacy → Share usage data. That switch is how you exercise the right to object described above, and it takes effect on your phone the moment you use it.
Deletion is built into the app — Settings → Delete account, explained in full on the account deletion page. There is no self-service export in the app yet; ask us at support@matcha.smedje.com and we will send you a copy of what we hold. We answer within one month, as the GDPR requires.
Children
Find Me Matcha is not for children under 13, and we do not knowingly keep their data. If you believe a child has an account, tell us and we will delete it.
Security
Traffic between the app and our servers is encrypted in transit, storage is encrypted at rest, and photo files are served through short-lived signed links rather than public URLs. No system is perfect; if something goes wrong that affects you, we will tell you and the supervisory authority as the GDPR requires.
Changes to this policy
If we change this policy in a way that matters, we will say so in the app before the change takes effect. The date at the top of this page is always the date of the latest revision.
Contact
Mads Petersen, Copenhagen, Denmark · support@matcha.smedje.com