Privacy Policy
What we collect, why, and what other people can see
This Privacy Policy explains what information the MoiMatch service collects about you, why we collect it, who else can see it, how long we keep it and what choices you have. It applies to every client we publish: the website, the Android and iOS applications and the Telegram bot (together, the “Service”).
The Service is operated by LoadStar Games, the operator of the MoiMatch project (the “Service Provider”, “we”, “us”). For the purposes of data protection law, we act as the controller of the personal data described here. You can reach us at any time at info@moimatch.org.
MoiMatch is a dating service. By its nature it makes part of your information visible to strangers. Please read section 5 before you fill in your profile, and remember that whatever you choose to publish or send is your own decision and your own responsibility.
Contents
- Information we collect
- How we use information
- Grounds for processing
- Location data
- What other users can see
- Who else receives information
- International transfers
- Retention and deletion
- Security
- Your choices and rights
- Children
- Cookies and similar technologies
- Advertising
- Changes to this Policy
- Contact
1. Information we collect
1.1. Information you give us
- Account data: your e-mail address and a password. We never store the password itself — only an irreversible hash of it. We also store a normalised form of your e-mail address to prevent duplicate accounts.
- Profile data: your name, date of birth (from which your age is shown), gender, a free-text description, your city or a point you place on the map, your interests, and optional personal facts you choose to add — such as height, weight, body type, hair and eye colour, occupation, education, star sign, attitude to smoking and alcohol, children, pets, religion, sport, languages and what you are looking for.
- Photographs you upload to your album. Uploaded images are re-encoded on our servers, which removes all embedded metadata, including EXIF GPS tags.
- Messages and files you send in chats: text, photographs and voice messages (voice is converted to MP3 on our servers).
- Your actions in the Service: likes and passes, matches, hidden and blocked people, deleted dialogues, search filters, notification settings and interface language.
- Reports and correspondence: reports you submit about other Users, and the messages you send to our contact address.
1.2. Information collected automatically
- Session and device data: the platform (web, Android, iOS, Telegram), the device model and application version reported by the client, the IP address of the last request, and the times a session was created and last used. This is what you see in the “active sessions” list in the menu.
- Push token of each device on which you allow notifications, issued by the push service of your platform.
- Activity signals: the time you were last seen online, used to show your online status and to order search results.
- Anti-abuse data: the IP address associated with a captcha request, sign-in attempts and rate-limit counters.
- Technical logs of requests and errors, kept for a limited period to keep the Service working and secure. We do not write the text of Users’ messages to our logs.
- Telegram identifier if you use the Telegram bot.
1.3. What we do not do
We do not use advertising networks, marketing trackers or analytics services in the Service. We do not build advertising profiles, do not sell personal data, do not use artificial intelligence to analyse your content or your conversations, and do not use your content to train machine-learning models.
2. How we use information
We use the information described above only to run and protect the Service:
- to create and maintain your account, sign you in and keep your sessions valid;
- to build your profile and show it to other Users of the Service;
- to find people near the location you have chosen and to show how far away they are;
- to record likes, create matches and let matched people write to each other;
- to deliver messages, photographs and voice recordings to their recipients and to show delivery and read status;
- to send service notifications — new matches, new messages, likes, account status — by push, in the application and, where necessary, by e-mail (e-mail confirmation, password reset, security notices);
- to moderate the Service: to examine reports, detect abuse, apply restrictions and blocks, and keep an audit trail of administrative actions;
- to protect the Service against fraud, spam, automated access and attacks, including through captcha and rate limits;
- to diagnose faults, restore data from backups and improve the Service;
- to answer your questions and requests;
- to comply with the law and to respond to lawful requests from competent authorities.
3. Grounds for processing
Where the law that applies to you requires a legal ground for processing personal data, we rely on the following:
- Performance of our agreement with you — everything needed to give you the Service you asked for: your account, profile, search, matches and chat.
- Your consent — for the use of your device location, for push notifications, for access to your camera, gallery and microphone, and for the special categories of information you voluntarily disclose in your profile or messages (for example about your religion, health or sexual orientation). You may withdraw consent at any time in your device or account settings; withdrawal does not affect processing that already took place.
- Our legitimate interests — keeping the Service secure, preventing fraud and abuse, investigating reports, defending legal claims and maintaining backups. We balance these interests against your rights and freedoms.
- Compliance with legal obligations — where the law requires us to retain or disclose information.
A dating profile often reveals sensitive information by implication. Publish only what you are content for strangers to see: you decide what to disclose, and you are responsible for that decision.
4. Location data
Finding people nearby is the core function of the Service, so the Service processes a location for every profile. You choose how it is set: by selecting a city, by placing a point on the map yourself, or by allowing the application to use your device location. Access to device location is requested at the moment you use the feature and can be refused or withdrawn at any time in the settings of your device — in that case you set your location manually.
We deliberately limit what other people learn from it:
- in profiles, other Users never receive your coordinates — the Service returns only a distance (for example “about 30 km away”, or “nearby” under one kilometre);
- if you set your location by selecting a city, the Service stores a point drawn at random inside that city, not the address you live at, and that is the point other Users see on the map;
- if you place a point on the map yourself, the Service stores and shows exactly that point — how precise it is, is your decision: you may mark your street, your district, or any place in your city;
- outside the map, your coordinates are visible only to you and to authorised administrators;
- GPS tags are stripped from every photograph you upload.
We do not track your movements in the background and do not keep a history of your locations: the profile stores the last location you set.
5. What other users can see
The following is shown to other Users of the Service:
- your name, age, gender, photographs, description, interests and the facts you filled in;
- your approximate distance from the person looking at your profile, and your marker on the map;
- whether you are online now or when you were last seen;
- in a dialogue: your messages, photographs and voice recordings, and whether you are typing.
Your e-mail address, date of birth, password, exact coordinates, device data, IP address, sessions, filters and settings are never shown to other Users.
Anything you make visible may be copied, screenshotted or republished by the people who see it. We cannot control what another person does with the content you sent them, and we are not responsible for it.
Administrators of the Service can see profiles, reports, restrictions and, when investigating a report, dialogues. Every such administrative action — including viewing a profile or a dialogue — is recorded in an audit log.
7. International transfers
The Service is available worldwide, and our servers and service providers may be located in countries other than yours. Where information is transferred across borders, the law of the destination country may differ from the law of your own. Where the law that applies to you requires safeguards for such a transfer, we rely on the mechanisms it recognises — such as standard contractual clauses with our providers, transfers to countries recognised as offering an adequate level of protection, or the transfer being necessary to perform our agreement with you.
8. Retention and deletion
Please read this section carefully: it describes a deliberate design choice of the Service.
MoiMatch is a moderated dating service. To be able to investigate abuse reported weeks or months later, to answer lawful requests and to keep an auditable record of what administrators did, the Service does not erase content when it disappears from view. Instead, deletion marks the item as deleted and removes it from the interface:
- a deleted photograph disappears from your album, but the image file remains in our storage;
- a deleted dialogue disappears for both participants, but the messages and their files remain stored;
- a deleted match, a hidden profile or a withdrawn like disappears from the lists, but the record of the action remains;
- a deleted account can no longer sign in and is no longer shown to anyone, but the account record, its content and its history remain;
- authorised administrators can see all of the above, including deleted items; every such view is logged.
Backups of the database are kept for operational recovery and are overwritten in rotation. Technical logs are kept for a limited period. Captcha records and e-mail links expire automatically (minutes to days). Sessions end when they are revoked, when you sign out or when the refresh period expires.
Where the law that applies to you gives you a right to have your personal data erased, restricted or exported, that right prevails over the retention practice described above. Write to info@moimatch.org from the address linked to your account and we will assess and answer your request under that law within a reasonable time.
9. Security
We apply technical and organisational measures appropriate to the risk, including:
- encryption of all traffic in transit (HTTPS / TLS, secure WebSocket);
- passwords stored only as strong one-way hashes (Argon2id); sign-in tokens stored as hashes and rotated on every refresh, with reuse of an old token revoking the whole session;
- changing your password revokes your other sessions; a password reset revokes all of them;
- uploaded files are validated by content, re-encoded (which destroys embedded payloads and metadata) and stored under unguessable 64-character random names; directory listing of the storage is disabled;
- captcha and rate limits on registration, sign-in, password reset, account deletion and messaging;
- a strict content security policy on our web pages, and no third-party scripts;
- separate accounts and sessions for administrators, with every administrative action written to an audit log.
No service can be completely secure. You are responsible for choosing a strong, unique password, for keeping it secret, for the security of the devices on which you are signed in, and for signing out of devices you no longer use (the “active sessions” list in the menu lets you do that). If you notice anything suspicious, change your password and write to us.
10. Your choices and rights
You control most of your data directly in the Service:
- view and correct — your profile, photographs, facts, interests and location can be edited at any time;
- notifications — switch categories of push notification on or off in the menu, or revoke the permission in your device settings;
- location — refuse or withdraw the permission and set your city manually;
- sessions — see where you are signed in and revoke a session;
- other Users — hide a profile, delete a dialogue (which also blocks the other person) or report abuse;
- account — delete it from the menu or at moimatch.org/delete-account.
Depending on where you live, the law may also grant you the right to access a copy of your data, to have it corrected or erased, to restrict or object to certain processing, to portability, to withdraw consent, and to lodge a complaint with your national supervisory authority. To exercise any of these, write to info@moimatch.org from the address linked to your account. We may ask you to confirm your identity before we act, and we answer within a reasonable time and in any case within the period set by the law that applies to you.
11. Children
The Service is intended for adults only and is not directed at anyone under 18. We do not knowingly collect personal data from minors. Accounts that appear to belong to a minor are blocked, and their data is retained only as long as needed to deal with the violation and any report to the authorities.
If you believe that a minor is using the Service or that a minor’s personal data has been published in it, report the profile in the application or write to info@moimatch.org immediately. Parents and guardians are encouraged to supervise their children’s use of connected devices.
12. Cookies and similar technologies
The website uses a small number of cookies and browser storage entries — to keep you signed in, to remember your language and a few interface preferences. There are no analytics or advertising cookies. The full list, with names, lifetimes and purposes, is in the Cookie Policy.
13. Advertising
The Service shows advertising of its own. Ad blocks appear on the map, in the card deck and in the Telegram bot, and every one of them is marked as advertising.
13.1. No third-party ad networks
We do not use advertising networks, advertising SDKs, tracking pixels or cross-site identifiers. Ad images are stored on our own file storage and are delivered by our own servers, so displaying an ad sends no request to anyone else and no third party learns that you saw it.
13.2. What we record
When an ad block is actually displayed on your screen, we record the ad, the time, your account, and the platform you used (Android, iOS, web or Telegram), together with whether you tapped the ad. We use these records to count impressions and clicks and to report totals to the advertiser.
13.3. Targeting stays with us
An advertiser may ask us to show an ad only to people who match certain criteria — platform, gender, age range, distance from a city, or interface language. Those criteria are evaluated on our servers at the moment the ad is selected. The advertiser never receives your profile, your location, your identifier or any other personal data, and never learns who was shown the ad. Advertisers receive only aggregate figures: how many impressions and how many clicks there were.
13.4. Tapping an ad
Tapping an ad opens the advertiser’s website in your device’s browser. From that point you are on someone else’s site, under their terms and their privacy policy, and we have no control over what they collect. In the Telegram bot the link passes through our own redirect, which records the click and immediately forwards you to the destination; the destination address is taken from our database, not from the link you tap.
13.5. Turning advertising off
There is no per-account setting to disable advertising. Ads are part of how the Service stays free.
14. Changes to this Policy
We may update this Policy as the Service develops or the law changes. The current version is always published at moimatch.org/docs/privacy with the date of the last update in its header. We will notify you of material changes through the Service or by another reasonable means before they take effect. Continued use of the Service after that means you accept the updated Policy.
15. Contact
For any question about this Policy, about how your data is processed, or to exercise your rights, write to info@moimatch.org. This is also the address for reports of abuse and for requests from competent authorities.
A short summary: we collect what the Service needs to work, we never sell it, other Users see only your profile and a distance, and everything you choose to publish or send is your own decision — and your own responsibility.
Related documents
- Terms of Use — Rules of the service, your responsibility for content and conduct.
- Platform Policy — Content standards, moderation, enforcement and technical limits.
- Cookie Policy — The few identifiers we store in your browser and on your device.
- Privacy Policy — Privacy notice for the Android and iOS apps (app store version).
- Child Safety Policy — Zero tolerance rules, reporting channels and our commitments.
Contact: info@moimatch.org
MoiMatch · moimatch.org