Legal

Privacy policy

Last updated: 2 September 2026

The short version: what you post is meant to be seen, what identifies you is kept to the minimum the app needs, none of it is sold, and you can delete your account from inside the app. The rest of this page is the detail, written against what the app actually does rather than from a template.

Who is responsible for your data

The data controller for Find Me Matcha is Mads Petersen, Copenhagen, Denmark — an individual established in the EU, not a company. For any privacy question or request, write to support@matcha.smedje.com.

TODO: confirm the controller name above is the name that should appear on a public legal page for this product, and that support@matcha.smedje.com is a mailbox that exists and is monitored. Both are carried over from the project’s shared configuration and have not been independently confirmed for Find Me Matcha.

What we collect, and why

Your account

To create an account you give us an email address and a password, or you sign in with Apple or Google, in which case we receive the identifier those services return rather than a password. Sign-in is operated for us by Amazon Cognito (Amazon Web Services). We use it to sign you in, to keep your reviews and lists attached to you, and to email you a confirmation or password-reset code when you ask for one.

Your profile

A handle, and optionally a display name, a short bio, an avatar photo, an Instagram handle and a home city. Your handle and anything else you fill in are shown to other people — that is what a profile is for.

Your date of birth

Asked once, when you claim your handle. It is never shown anywhere, there is no birthday feature behind it, and it is not sent back to the app. It exists so we can tell whether an account is old enough to post: the minimum age is 13, which is Denmark’s digital-consent age under Article 8 of the GDPR. If you tell us you are younger, we do not give you an account, and we delete the one you had started — including the email address attached to it.

What you post — public by design

Reviews (a rating, the tags you tick, what you ordered, and any note you write), photos and their captions, the café facts you confirm or correct, cafés you propose, your lists, the cafés you save, who you follow, and your likes and comments.

This is the product, and most of it is public. Photos and reviews appear on the café’s page and in the app’s feed with your handle on them. Lists you make can be private, unlisted, or public — you choose, and the app says which is which before you share one. Assume that anything you post other than a private list can be seen by anyone using the app.

Your location — used on your device

With your permission, the app reads your location only while it is open, to centre the map on you and show cafés near you. There is no background tracking. Your coordinates are used on your device and are not stored on our servers: when you confirm a fact or post a review, what we store is which café it was about, not where you were standing.

The purpose string iOS shows you says exactly this: “Find Me Matcha uses your location to show cafés near you and centre the map on where you are.”

Camera and photo library

The app asks for the camera so you can photograph your matcha when you post a review, and for your photo library so you can pick a photo you already have. Both are asked for at the moment you use them, and nothing is read from your library except the photo you choose. Photos you post are uploaded to our storage and shown on the café’s page.

Notifications

You can choose which kinds of notification you want — follows, likes, comments, mentions, agreements, and reviews of cafés you saved — and that choice is stored on your account. Turning one off means it is never written, so nothing already in your notifications changes.

The app does not currently register a push token with Apple or Google, so we hold no device push identifier for you.

Product analytics

We use PostHog to understand how the app is used. What it receives:

Analytics are on by default, and you can turn them off in the app at Settings → Privacy → Share usage data. Turning that switch off stops the events and stops screen recording immediately; recording starts again only if you switch it back on and reopen the app. The choice is stored on your phone, so it applies straight away and works offline. You can also object by writing to support@matcha.smedje.com; see Your rights. PostHog is a processor acting on our instructions and does not use your data for its own purposes.

Crash and error reports

We use Sentry to receive crash and error reports. A report contains the error and where in the app it happened, the app version and build, and device context such as model, operating system version and available memory. Sentry is configured not to attach your IP address, email or username, and we do not attach your account id, so these reports are not linked to you. Requests to our own API that fail with a server error are reported too.

What we never do

Where your data is, and who else touches it

Your account, your reviews and your photos are stored on cloud infrastructure in the European Union (Amazon Web Services, Ireland, with a Postgres database hosted in the EU). We share data only with the providers needed to run the app, each acting on our instructions under a data-processing agreement:

WhoWhat forWhere
Amazon Web ServicesServers, storage for photos, and the email that sends your confirmation and reset codesEU (Ireland)
Amazon Cognito (AWS)Sign-in, including Apple and Google sign-inEU (Ireland)
NeonThe Postgres database behind the appEU
PostHogProduct analytics and session recordingsUnited States
SentryCrash and error reportsEU (Germany)
AppleApp distribution, and Sign in with Apple if you use itGlobal
GoogleSign in with Google, if you use itGlobal

We do not share your personal data with anyone else unless the law requires it.

International transfers

Your account, reviews and photos stay in the European Union. Analytics data is processed in the United States by PostHog, and sign-in with Apple or Google involves those companies’ own global infrastructure. Those transfers rely on the safeguards required by Chapter V of the GDPR, including the European Commission’s Standard Contractual Clauses or an adequacy decision where one applies.

Legal bases (GDPR)

How long we keep it

For as long as you have an account. When you ask us to delete it, your account is deactivated immediately and everything scheduled for erasure is erased after a seven-day window in which signing back in restores it. What survives, and why, is on the account deletion page — in short, your reviews stay but stop being yours.

Email you send to our support address is stored for 90 days and then deleted. Analytics and crash data are kept according to our providers’ retention settings and are not linked to your account.

Your rights

Under the GDPR you can:

Objecting to analytics is built into the appSettings → Privacy → Share usage data. That switch is how you exercise the right to object described above, and it takes effect on your phone the moment you use it.

Deletion is built into the appSettings → Delete account, explained in full on the account deletion page. There is no self-service export in the app yet; ask us at support@matcha.smedje.com and we will send you a copy of what we hold. We answer within one month, as the GDPR requires.

Children

Find Me Matcha is not for children under 13, and we do not knowingly keep their data. If you believe a child has an account, tell us and we will delete it.

Security

Traffic between the app and our servers is encrypted in transit, storage is encrypted at rest, and photo files are served through short-lived signed links rather than public URLs. No system is perfect; if something goes wrong that affects you, we will tell you and the supervisory authority as the GDPR requires.

Changes to this policy

If we change this policy in a way that matters, we will say so in the app before the change takes effect. The date at the top of this page is always the date of the latest revision.

Contact

Mads Petersen, Copenhagen, Denmark · support@matcha.smedje.com