Lingua Match

Privacy Policy

Last updated: Version: 2026-10-08-draft.3

This notice explains the personal data processed when you use Lingua Match, the purposes of that processing, and your rights. It covers the website, its installable web app, and the Android app that opens the same website. It reflects the features reviewed on 8 October 2026. The German Datenschutzerklärung is the primary editorial edition of this draft.

At a glance

1. Controller and privacy contact

The controller (Verantwortlicher) under Article 4(7) GDPR is the person or organisation identified below, who determines why and how personal data is processed. Lingua Match is the product name, not a substitute for the controller's legal identity.

Use the contact details below for privacy requests. Whether a data protection officer must be appointed, and their contact details where applicable, needs a separate assessment. An empty field does not mean that assessment has been completed.

Controller

Legal name
Anday Sahin Kahveci
Postal address
Wundtstr. 5 01217 Dresden Deutschland
Email
contact@linguamatch.online
Privacy email
contact@linguamatch.online
Data protection officer
Appointment requirement and contact details need assessment
contact@linguamatch.online

2. Scope, minimum age, and sources of data

Lingua Match helps people find language partners, meet others, and practise languages. It is for adults aged 18 or over. Age entries are checked during registration and profile completion; the current app does not verify identity or age against an official document.

Most information comes directly from you: account registration, profile entries, uploaded photos, messages, and exercise answers. Other users may provide information about you through corrections or reports about your conduct. Match dates, exercise results, and XP are generated as you use the service.

If you choose a configured Google or Apple sign-in option, the provider supplies the identity information authorised for that login, such as a provider identifier and, where shared, an email address, name, or profile image. The actual fields depend on the provider's permissions and deployed configuration. We do not use public personal-data databases for ordinary account registration.

3. Data categories and purposes

These activities are identified from the current code and database schema. Section 4 sets out the proposed legal bases for review; it does not substitute for consent or for implementing appropriate deletion and protection measures.

  • Accounts and authentication: email, internal user identifier, authentication records including a password hash for password sign-in, verification/session records, and any OAuth provider information. These enable account creation, email confirmation, and secure sign-in.
  • Profiles and preferences: first name, date of birth, adult confirmation, city/country, biography, intentions, native/learning languages and self-assessed level, interests, and age/country preferences. These enable profile presentation and partner suggestions. Other users receive your calculated age, not your date of birth.
  • Photos: uploaded images, resized versions and thumbnails, storage paths, order, and upload times. These illustrate profiles, discovery, matches, conversations, and rankings.
  • Connections and communication: likes/passes, matches and their status, message sender/content/time and reply references, corrections and notes, and mission progress. These enable mutual contact and collaborative practice.
  • Learning and progress: exercise/game sessions, submitted answers, grading results, completion times, review scheduling, concept/lesson progress, XP events, levels, streaks, and rankings. Selecting a learned phrase for a chat and using it are recorded for progress and rewards.
  • Safety and reports: blocking relationships, report reasons and free text, references to affected profiles/messages, review status, and account status. These support complaint handling and protection against unwanted contact and misuse. Learning content may also be flagged for review.
  • Technical operation: requests necessarily transmit connection information such as IP address, time, requested URL, and browser/device information to the relevant servers. Whether and how long hosting, authentication, or security logs are retained depends on the deployed infrastructure and has not been confirmed.

5. Dating intentions and sensitive information

Dating intentions and the content of photos, biographies, or messages may, depending on the context, reveal sex life, sexual orientation, health, religion, or other special categories of personal data. An ordinary profile photo is not inherently biometric data used for unique identification; that type of facial identification is not implemented in the reviewed app.

Sensitive processing cannot rely solely on a contract or a general legitimate interest. Where explicit consent under Article 9(2)(a) is required for the dating feature, it must be separately obtained, evidenced, and withdrawable. Choosing “Open to Dating” or reading this notice does not replace such consent. We do not assume that making information visible automatically supplies a valid public-disclosure exception.

Language-partner features are distinct from dating intentions. You can change your intention in your profile and exclude dating profiles from discovery. Changes do not undo information already shared. Avoid including sensitive information about yourself or others unless it is needed for the exchange.

6. Who can see your information

Signed-in users receive selected profile details according to the feature and access rules: first name, calculated age, city/country, languages, interests, biography, intentions, and images. Rankings show eligible active profiles with name, image, XP, level, and rank. Blocking in either direction is respected in discovery and rankings.

In-app messages and corrections are accessible to the participants of the relevant match. Content is stored in the database; authorised technical or administrative access by the operator or providers is not thereby excluded. Chat is not end-to-end encrypted. Relevant information may be reviewed when a report is handled.

Profile images currently use public storage. Anyone with the image URL can access the file without signing in, including after that URL has been shared. Blocking does not invalidate an already known image URL. Other users can also copy content or take screenshots; the current technology cannot prevent this.

Blocking ends the active match but does not automatically delete stored messages or reports under the current schema. It does not substitute for an erasure request.

7. Recipients and service providers

External providers help operate the service. Processing performed on our behalf requires an Article 28 GDPR agreement (Auftragsverarbeitungsvertrag). A provider may act as a separate controller for its own processing; its privacy information applies to that activity.

  • Supabase provides the database, authentication/session management, photo storage, and realtime chat delivery. It processes account, profile, communication, learning, and required technical data. The contracting entity and this project's region still need confirmation.
  • Vercel hosts and delivers the website and runs server-side app functions. It receives request data and may handle application data loaded for server-rendered screens. Function locations, logging configuration, and the actual contractual arrangements are unconfirmed.
  • Google / Apple are involved only if you choose a provider enabled in the deployed environment. The provider receives the sign-in request and returns authorised identity information. You do not enter a provider password into a Lingua Match form. A visible button alone does not prove that a provider is enabled in production.
  • Email is sent through the authentication infrastructure for verification and other account messages. The SMTP provider, if any, and delivery/log records need confirmation.
  • Browser/device services: the Android Trusted Web Activity opens the same website. Browser and installation services may process their own data under their terms. Listening exercises use browser speech synthesis, preferring local voices but allowing a suitable remote voice. In that case the browser may transmit exercise text to its speech provider. The app does not record your voice.

8. Processing locations and international transfers

This Supabase project's storage region and the Vercel deployment's execution/logging locations have not been verified. We therefore do not promise processing exclusively in Germany or the EU. Choosing an EU database region does not, by itself, exclude access from elsewhere or processing by subprocessors.

Transfers outside the European Economic Area require compliance with Articles 44 onward GDPR. Depending on the recipient, an applicable adequacy decision or appropriate safeguards may be used, including the European Commission's standard contractual clauses and any necessary supplementary measures. The actual mechanism for each recipient must be evidenced before approval. Reliance on the EU–US Data Privacy Framework requires the specific recipient and processing to fall within the applicable decision and a valid certification.

You may request details and a copy or reference to the safeguards using the contact in section 1.

9. Cookies and access to your device

Supabase session cookies support sign-in and session continuity. They hold authentication and potentially short-lived login-flow information. Project-specific names may begin with “sb-”, and larger values can be split across cookies. Exact lifetimes depend on the libraries and authentication configuration and must be documented from the production environment.

Storage/access strictly necessary for a sign-in service you expressly request may fall within section 25(2)(2) TDDDG. Non-essential storage or access generally needs prior consent under section 25(1); subsequent processing of personal data also needs a GDPR basis.

Installation guidance inspects device category and standalone display state in the active browser. Its reviewed implementation keeps state in memory, without its own persistent localStorage, sessionStorage, or IndexedDB entries. The repository contains no app service worker, analytics tracker, or marketing tracker. Appearance follows the system preference. This code finding does not establish which hosting extensions may be enabled outside the repository.

10. Retention and deletion

Personal data should be retained only while needed for its purpose or where a relevant legal obligation or the establishment, exercise, or defence of legal claims justifies retention. It must then be erased or effectively anonymised. Suspending an account or ending a match does not anonymise the data.

The reviewed code has no automated retention schedule by data category. Account, profile, chat, and learning records generally remain until a deletion is actually performed. Database cascades remove many dependent records on account deletion, but photo files also need removal through the storage service. Deleting a database reference does not reliably delete its file.

Periods for inactive accounts, messages after a match ends, reports, security logs, and backup rotation have not been determined. Any continued retention in backups must be limited and handled through a verifiable process.

11. Data protection measures

Database access rules and shaped read functions limit the information ordinary app users can read or change. Exercises are graded and XP is awarded by database functions; users cannot write their own rewards directly. These safeguards are distinct from infrastructure or administrator access.

Section 6 explains public photo storage and the absence of chat end-to-end encryption. No absolute security guarantee is made. Production access controls, transport settings, incident procedures, and technical/organisational measures still require verification.

12. Automated suggestions, grading, and decisions

Profile suggestions are filtered or ordered using languages, age/country preferences, swipe history, and blocks. Exercises are automatically graded; review dates, XP, levels, and rankings are calculated from learning/activity records. Such evaluation of preferences or performance may amount to profiling.

The reviewed app contains no identified solely automated decision producing legal effects or similarly significantly affecting a person within Article 22(1) GDPR. In particular, automatic AI photo moderation and sanctions based solely on a user report are not implemented. This assessment must be revisited if moderation or evaluation systems change.

13. Required and optional information

You are not legally obliged to open a Lingua Match account. The selected sign-in method needs its identity information; without it, sign-in is unavailable. The regular onboarding flow requires a first name, date of birth/adult confirmation, country, at least one native and one learning language, at least one intention, and a profile photo. These inputs are needed to complete that flow.

City, biography, interests, additional photos, and a dating intention are optional profile entries. Screens indicate other required inputs. Messages, corrections, and exercise answers arise when you use those features. You do not need to choose “Open to Dating” to use language-partner features. An interface requiring an input does not, on its own, establish that collecting it is legally necessary.

14. Your rights and how to exercise them

The following rights apply subject to their statutory conditions. Contact the controller using section 1. If there are reasonable doubts about identity, a proportionate check may be required to avoid disclosure to an unauthorised person; it must not collect more information than necessary.

  • Access under Article 15 GDPR, including a copy of the personal data processed about you.
  • Rectification and completion under Article 16. You can change many profile entries through “Profile → Edit profile”.
  • Erasure under Article 17, subject to lawful exceptions, and restriction of processing under Article 18.
  • Portability under Article 20 in a structured, commonly used, machine-readable format for data you provided that is processed automatically on the basis of consent or contract, including direct transmission where technically feasible.
  • Objection under Article 21(1), on grounds relating to your particular situation, to processing based on Article 6(1)(e) or (f), including associated profiling. Continuation then requires the statutory conditions to be met. Article 21(2) provides an unconditional right to object to direct marketing; the reviewed app has no own direct-marketing feature.
  • Withdrawal of consent under Article 7(3) for future processing, without affecting the lawfulness of prior processing. Withdrawal must be as easy as giving consent.
  • Rights concerning Article 22 decisions where such processing is introduced and the statutory conditions apply.

15. Response deadlines and supervisory complaints

Information about action on a request is generally due without undue delay and within one month. Where the law permits up to two additional months, the controller must notify you within the initial month and explain the extension. A refusal is subject to the explanation and remedy requirements of Article 12 GDPR.

You may complain under Article 77 to a supervisory authority, particularly in the Member State of your habitual residence, workplace, or an alleged infringement. You need not contact us first, and other remedies remain available.

For the stated Dresden establishment, the competent state authority is the Sächsische Datenschutz- und Transparenzbeauftragte. Its official complaint page and the directory of other authorities are linked below.

16. Version, changes, and outstanding approval

The version and review date appear at the top of this notice. Changes in features, recipients, or purposes require the text to be reviewed. Updating this text does not create a legal basis or replace consent required for a new purpose.

German is the primary editorial edition; this English version describes the same reviewed implementation. That editorial order does not limit statutory rights or mandatory information duties in a language people can understand.