Privacy Policy
Last updated: August 7, 2026
1. Who we are, and what this policy covers
MatchGrade is operated by Toonbaar, registered with the Dutch Chamber of Commerce under number 85189022 (VAT identification number NL863540119B01). Toonbaar is the controller for the personal data described in this policy, and you can reach us about any of it at support@matchgrade.app.
Toonbaar is established at Werdorperwaard 7, 3984 PR Odijk, Netherlands.
This Privacy Policy explains what information MatchGrade ("we," "us," or "our") collects when you use our profile-analysis service, how we use it, and the rights you have under the General Data Protection Regulation (GDPR) and Dutch data-protection law.
2. What we collect
• Profile content: the photos (two to six) and bio text you submit to be analyzed.
• Contact information: your email address, collected when you buy credits, used for passwordless sign-in and to send you your report link.
• Payment metadata: billing information handled by Mollie (see "Payment data" below) and records of what you purchased, when, and for how much.
• Withdrawal-declaration record: which declarations you made at checkout about immediate delivery and your right of withdrawal, the timestamp, the IP address you made them from, and the version of the Terms then in force, kept as evidence of consent.
• Technical data: standard web request metadata (such as IP address and browser user agent) generated when you use the Service, used for security and abuse prevention.
We do not use cookies for advertising or third-party tracking. Supabase, our authentication provider, sets a session cookie strictly to keep you signed in. We also store a cookie that remembers your language choice, and if you arrive through a referral link a cookie that records which referrer sent you so their commission can be attributed. These are strictly necessary to deliver what you asked for, so under Article 11.7a of the Dutch Telecommunications Act we do not need to ask your consent to place them.
We use Vercel Web Analytics and Vercel Speed Insights to measure how the site is used and how fast it loads. These do not set cookies and do not track you across other websites; they derive an anonymous, non-persistent visitor identifier from request data such as your IP address and browser type, which we see only in aggregate.
3. How we use your information
We use the information above to: generate your report; authenticate you and give you access to your reports on the dashboard; process payments; send transactional emails (sign-in links, report-ready notifications, and the purchase confirmation consumer law requires us to provide on a durable medium); measure aggregate site usage and performance; prevent fraud and abuse; and comply with legal obligations, including consumer-protection recordkeeping for your withdrawal declarations.
4. Our legal bases for processing
Under Article 6 GDPR we only process your personal data where we have a legal basis for it:
• Performance of a contract (Article 6(1)(b)): generating and delivering your report, giving you access to it on the dashboard, and handling your purchase. Your photos and bio text are processed on this basis — analyzing them is the service you asked us for.
• Legal obligation (Article 6(1)(c)): keeping payment and withdrawal-waiver records for consumer-protection, accounting, and tax purposes.
• Legitimate interests (Article 6(1)(f)): keeping the Service secure, preventing fraud and abuse, and understanding aggregate usage and performance so we can improve the Service. We weigh these interests against your rights and use the least intrusive data that does the job.
• Consent (Article 6(1)(a)): only where we ask you for it specifically. You can withdraw consent at any time, which does not affect processing that already took place.
Your photos show your face, but we do not run facial recognition or any other technique that identifies you from them, so we do not process them as biometric data within the meaning of Article 9 GDPR. We do not ask for, and ask that you do not submit, information revealing health, religion, political opinions, sexual orientation, or other special categories of data.
5. How photos are used and stored
Uploaded photos are stored in a private storage bucket and are accessed only through short-lived signed URLs. They are never publicly listed or browsable. Photos are used solely to generate your own MatchGrade report. They are not shared with any third party for their own purposes, are not sold, and are not used to train any AI model.
Photos are automatically deleted 90 days after upload. You can also request earlier deletion of your photos and report data at any time. See "Your rights" below.
6. How bio text is used
If you submit bio text, it is sent to Anthropic's Claude API solely to generate your report's written feedback. It is not used for any other purpose, is not combined with other users' data, and is not used by us or, per Anthropic's API terms, by Anthropic to train AI models.
7. Payment data
Payments are processed by Mollie B.V., a payment service provider established in the Netherlands, so your payment data stays within the EU. When you check out, your bank or card details are entered directly into Mollie's secure, PCI-compliant checkout, or with iDEAL into your own bank's environment. MatchGrade does not receive or store your full bank account number, card number, CVC, or other sensitive payment data. We retain the payment records Mollie provides us (such as the amount charged, currency, and a reference ID) to fulfill your order, handle refunds, and meet accounting and tax obligations. We also record the country your purchase is treated as coming from, together with the two signals it is based on: the country your connection resolved to when you started checkout, and the country Mollie reports the payment came from. EU VAT rules on digital services require us to establish and be able to evidence where our customer is, and this is the minimum that does it — we derive a two-letter country code and do not store your IP address for this purpose. See Mollie's own privacy policy for how it handles your payment details.
8. Automated processing and AI
Your report is produced automatically by an AI model, with no person reviewing it before you see it. That automation is the service you are buying, and it produces a scored opinion on photos and text — it has no legal effect on you and no comparable significant impact, so it is not automated decision-making of the kind Article 22 GDPR restricts. We do not build a profile of you, and we do not use your data to make decisions about you outside your own report.
If you think a report got something badly wrong, email support@matchgrade.app and a person will look at it.
9. Data retention
Photos: deleted automatically 90 days after upload, or sooner on request.
Bio text and report results: kept for as long as your account/report history is active so you can view past reports, or until you request deletion.
Waiver acceptance records and payment records: retained for as long as required by applicable consumer-protection, accounting, and tax law, even if you otherwise request deletion of your account.
10. Third-party service providers
We share data with the following providers, each of which processes it only on our behalf, under a data processing agreement and its own security and privacy commitments: Supabase (database, authentication, and file storage), Anthropic (AI analysis of photos and bio text), Vercel (website hosting and usage measurement), and Mollie (payment processing, established in the EU). We do not sell your personal information to anyone, and we do not share it for anyone else's own purposes.
11. Transfers outside the EEA
We keep your data in the European Economic Area wherever we can. Supabase hosts our database and file storage in the EU, and Mollie processes payments in the Netherlands.
Anthropic, which runs the AI analysis, is established in the United States, so the photos and bio text sent for analysis are transferred outside the EEA. That transfer takes place under the European Commission's Standard Contractual Clauses in Anthropic's data processing addendum, together with supplementary measures such as encryption in transit and at rest, so your data keeps a level of protection essentially equivalent to EU law. Vercel, our hosting and analytics provider, is also US-established and relies on the same Standard Contractual Clauses.
You can ask us for more detail about these safeguards at support@matchgrade.app.
12. How we protect your data
Data is transmitted over encrypted connections and stored in access-controlled infrastructure. Uploaded photos live in a private bucket that is never publicly listed, reachable only through short-lived signed URLs, and access to production data is limited to the people who need it to run the Service.
No system is perfectly secure. If a personal data breach ever occurs that is likely to risk your rights and freedoms, we will report it to the Dutch Data Protection Authority within 72 hours and, where the risk to you is high, tell you directly, as Articles 33 and 34 GDPR require.
13. Your rights
Under the GDPR you have the right to access the personal data we hold about you, to have inaccurate data corrected, to have your data deleted, to receive it in a portable format, to restrict how we process it, to object to processing we base on our legitimate interests, and to withdraw any consent you have given (which does not affect processing that already happened).
To exercise any of these rights, email support@matchgrade.app from the address associated with your report or account. Exercising them is free, and we will respond within one month as Article 12 GDPR requires; for complex or numerous requests we may extend that by up to two further months, and we will tell you if we do. Deleting your data will remove your stored photos, bio text, and report results; records we are legally required to keep (such as waiver and payment records) may be retained as described above.
If you are unhappy with how we handle your data we would like the chance to put it right, but you also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or with the supervisory authority in the EU country where you live or work.
14. Children's privacy
The Service is not directed to, and may not be used by, anyone under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, contact us and we will delete it.
15. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and tell you before they take effect, so that you can exercise your rights under Section 13 first. A change to this policy never widens what we may do with data we already hold beyond what the GDPR allows.
16. Contact
Questions about this Privacy Policy or your data can be sent to support@matchgrade.app. We have not appointed a data protection officer, as we are not required to; that address reaches the people responsible for privacy at MatchGrade.