Privacy Policy

Last updated: September 6, 2026

INTRODUCTION

This Privacy Policy explains how FulgentFlow OÜ ("FulgentFlow", "we", "us", "our"), a company registered in Estonia, collects, uses, shares and protects your personal information when you: • use the MatchLab mobile application for iOS or Android (the "App"); • visit our website at www.matchlab.studio (the "Website"); • contact us for support. The App and the Website together are the "Services". MatchLab is an AI dating trainer: you practise conversations with AI-generated personas, get AI feedback on your photos, and read our guides and tips. No real person is on the other side of a conversation. If you do not agree with this Policy, please do not use the Services. Questions: matchlab@fulgentflow.com.

SUMMARY

• We collect what you give us — your email address, username, optional avatar, the photos you submit for review and the messages you send to AI personas — plus a small amount of technical data: IP address, device platform, push token and app version, and records of how you use the App. • We do not collect your precise location, your contacts or your card details, and the App contains no advertising or tracking SDKs. We do not sell your personal information. • Your photos and messages are sent to our AI provider, OpenAI, to produce the feedback you asked for. Under OpenAI's API terms this content is not used to train its models. • Payments are processed by Apple (App Store) or Stripe. We receive confirmation of the purchase, never your card number. • You can delete individual photos and conversations at any time, and delete your whole account in Settings → Danger zone. • The Services are for adults aged 18 and over.

1. INFORMATION WE COLLECT

Information you provide • Account details: your email address, a password (stored only as a salted hash) and a username. If you sign in with Google or Apple we keep only your email address, whether it is verified, and the provider's account identifier — nothing else from your Google or Apple profile. With Sign in with Apple you may choose to share a private relay address instead of your real email. • Avatar: an optional profile photo. • Photos for Photo Audit: the photos you choose to submit for AI feedback. • Trainer conversations: the messages you type to AI personas, the personas' replies, and the scored feedback ("chat analysis") generated about those conversations. • Consent record: when you complete onboarding we store that you confirmed you are 18 or older and accepted our Terms, together with the version you accepted, the app version, your IP address and your device's user agent. • Support communications: anything you send us by email. Information collected automatically • Security and rate-limiting data: the IP address and email address used in sign-in and sign-up attempts, kept briefly to prevent abuse. • Device and app data: platform (iOS or Android), app version and — only if you turn notifications on — a push notification token. • Usage records: which features you use and when, tokens earned and spent, guides read and unlocked, streaks, and which in-app notifications you have read. • Server logs: standard request logs (time, endpoint, response status, IP address) kept for troubleshooting and security. Information from third parties • Purchase confirmations from Apple or Stripe: transaction identifiers, the product bought and its status, including refunds or revocations. We never receive your card number. What we do not collect We do not collect precise geolocation, your contacts, any photos beyond the ones you pick, health data or advertising identifiers. The App contains no advertising, analytics or tracking SDKs. Sensitive information The photos and messages you choose to share may reveal information about you that is treated as sensitive in some jurisdictions, for example sexual orientation or health. We process such content only because you submit it for the feature you have chosen, and only to provide that feature. Please do not submit anything you do not want analysed.

2. HOW WE USE YOUR INFORMATION

• To provide the Services: run trainer conversations, review your photos, generate feedback, show your progress and unlock guides. • To operate your account and wallet: sign you in, keep your token balance, credit purchases and rewards, and restore purchases. • To keep the Services safe: detect abuse, enforce our House Rules and Terms, and rate-limit suspicious activity. • To communicate with you: verification and password-reset codes, service notices and — if you opt in — push notifications about your training. You can turn notifications off in your device settings at any time. • To respond to support and legal requests. • To improve the Services using aggregated or de-identified information. We do not use your content to train AI models, and we do not make decisions with legal or similarly significant effects about you by automated means. The scores and feedback the App gives you are suggestions for you alone.

3. LEGAL BASES (EEA, UK AND SWITZERLAND)

• Performance of a contract: providing the Services you signed up for, including the AI processing of the content you submit. • Consent: sending push notifications, and processing content that may reveal sensitive information, which you provide by choosing to submit it. You can withdraw consent at any time by deleting the content or turning notifications off; this does not affect processing that has already taken place. • Legitimate interests: security, fraud and abuse prevention, rate limiting, service diagnostics and defending our legal rights. • Legal obligation: keeping records required by tax, accounting or consumer law, and responding to lawful requests.

4. HOW THE AI PROCESSES YOUR CONTENT

Our AI features run on OpenAI's API (OpenAI, L.L.C., United States), which acts as our processor. To generate a reply or a review we send OpenAI only what that request needs: your message and the conversation so far, or the photo you submitted, together with the persona's instructions and a hashed identifier that lets OpenAI attribute abuse without learning who you are. Under OpenAI's API terms this content is not used to train OpenAI's models and is retained by OpenAI for up to 30 days for abuse monitoring, then deleted. AI output can be wrong, incomplete or inappropriate. Treat it as one opinion, not as professional advice. Where our safety systems flag a conversation, a member of our team may review the relevant messages to enforce the House Rules.

5. WHO WE SHARE INFORMATION WITH

We share personal information only with service providers that process it on our behalf under contract, and only as needed: • OpenAI (USA) — AI processing of your photos and conversations, as described above. • Google Cloud (USA, us-east1 region) — hosting of our servers, databases and file storage. • Apple (USA) — Sign in with Apple, App Store purchases and subscriptions, and delivery of push notifications on iOS. • Google (USA) — Google Sign-In and, on Android, delivery of push notifications. • Expo (650 Industries, USA) — routing of push notifications to Apple and Google, and delivery of app updates. • Stripe (USA and Ireland) — payment processing on Android and the web; Stripe receives your email address and a reference to your account. • Resend (USA) — delivery of verification and password-reset emails. • Vercel (USA) — hosting of the Website. We may also disclose information when required by law, to protect the safety of any person, to enforce our Terms, or as part of a merger, acquisition or sale of assets, in which case this Policy continues to apply until you are told otherwise. We do not sell personal information and we do not share it for advertising.

6. INTERNATIONAL TRANSFERS

Our servers are in the United States and our providers process data there. If you are in the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant) and, where a provider is certified, the EU-U.S. Data Privacy Framework to protect your information.

7. HOW LONG WE KEEP INFORMATION

• Account, wallet, usage and consent records: for as long as your account exists. They are deleted when you delete your account. • Photos, conversations and analyses: until you delete them in the App, or until you delete your account. • Security and rate-limiting records and verification codes: for a short period, until they expire. • Sign-in sessions: until they expire or you sign out. • Backups: encrypted database backups are kept for 7 days and then overwritten. • Payment records: our payment processors keep transaction records under their own legal obligations; we keep a purchase ledger only while your account exists. After you delete your account, de-identified processing records that can no longer be linked to you may remain, for example an AI persona's own replies keyed by a random conversation identifier.

8. HOW WE PROTECT INFORMATION

Data is encrypted in transit (TLS) and at rest on Google Cloud. Passwords are stored as salted hashes. Sign-in tokens are kept on your device in the platform's secure storage (Keychain on iOS, Keystore on Android). Photos and avatars are served over HTTPS from unlisted, unguessable links. Access to production systems is limited to the people who need it. No system is perfectly secure; if you believe your account has been compromised, contact us immediately.

9. YOUR RIGHTS AND CHOICES

In the App you can: • edit your username and avatar; • delete any photo review or conversation; • turn push notifications on or off in your device settings; • delete your account in Settings → Danger zone. This removes your profile, photos, conversations, analyses, wallet and consent records from our active systems and revokes your Sign in with Apple grant. Deleting your account does not cancel an active subscription — cancel it in your Apple ID settings. Depending on where you live you may also have the right to access, correct, port, restrict or object to the processing of your personal information, and to withdraw consent. Email matchlab@fulgentflow.com; we respond within one month (extendable where the law allows) and may need to verify your identity. If you are in the EEA, the UK or Switzerland you may complain to your local data protection authority; our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee).

10. UNITED STATES STATE PRIVACY RIGHTS

If you live in a US state with a comprehensive privacy law (such as California, Colorado, Connecticut, Texas or Virginia), you have the right to know what personal information we collect and how we use it, to access and correct it, to obtain a copy, to delete it, and not to be discriminated against for exercising these rights. In the past 12 months we have collected these categories of personal information: identifiers (email address, username, account and device identifiers, IP address); account credentials; user content (photos and messages); commercial information (token purchases and spending); internet activity (feature usage); and inferences (the scores and feedback generated about your photos and conversations). We disclose these categories only to the service providers listed in section 5, for business purposes. We do not sell personal information, do not share it for cross-context behavioural advertising, and do not use sensitive personal information to infer characteristics about you. To exercise your rights, use the tools in the App or email matchlab@fulgentflow.com. If we decline a request you may appeal by replying to our response; if the appeal is denied you may contact your state attorney general. We do not respond to browser Do-Not-Track signals because no standard for them exists.

11. CHILDREN

The Services are only for people aged 18 or older. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we delete the account and its data. If you believe a minor is using MatchLab, email matchlab@fulgentflow.com.

12. COOKIES, LOCAL STORAGE AND THE WEBSITE

The App does not use cookies. It stores your sign-in token and preferences locally on your device so that you stay signed in. The Website uses Vercel Web Analytics, which counts page views without cookies or cross-site identifiers, and loads fonts from Google Fonts, so Google receives your IP address when a page loads. The Website sets no advertising cookies.

13. CHANGES TO THIS POLICY

We may update this Policy. The date at the top shows when it last changed. If a change is material we will tell you in the App or by email before it takes effect.

14. CONTACT US

FulgentFlow OÜ, Estonia Email: matchlab@fulgentflow.com