Matcha Privacy Policy
Matcha is operated by Yildiz Labs AB. This Privacy Policy explains what information Matcha collects, how it is used, when it may be shared, and what choices users have. It also explains how Matcha works with AI providers and messaging services such as iMessage and Telegram, plus connected services such as Apple Health, Google Calendar, Gmail, Google Places, Strava, and wearable platforms.
1. Who we are
Matcha is operated by Yildiz Labs AB. In this Privacy Policy, "Matcha," "we," "our," and "us" refer to Yildiz Labs AB and the Matcha product and services.
2. Information we collect
We may collect information you provide directly, including your name, email address, phone number, account details, messages you send to Matcha, and support requests.
When you connect third-party services, we may receive user-authorized data such as Apple Health records, activity history, workouts, sleep and recovery information, wellness metrics, calendar availability, and similar account or profile data needed to provide the service.
If you connect Google Calendar, Matcha may access the Google Calendar data you authorize, which may include calendar lists, event titles, event times, descriptions, locations, attendees, availability, and calendar metadata. We use this data to help plan around your schedule, suggest reminders, generate coaching, and create or update calendar-related actions you request or authorize.
If you connect Gmail, Matcha may access only the Gmail data and permissions you authorize, which may include email messages, message metadata, sender and recipient information, subject lines, labels, attachments, and draft or sent-message actions depending on the permissions you approve. We use Gmail data only to provide user-facing Matcha features you request or authorize, such as ingesting relevant emails, summarizing messages, identifying action items, helping draft replies, and supporting planning, reminders, and coaching.
If you use features that rely on Google Places or similar location services, Matcha may process search queries, selected places, place names, addresses, place metadata, and location context you provide or authorize. We use this information to support planning, recommendations, reminders, and other user-facing Matcha features.
We may also collect technical information such as device, browser, approximate location from IP address, usage events, and other diagnostic information related to how Matcha is accessed and used.
3. How we collect information
We collect information directly from you, automatically when you use Matcha, and from third-party services you choose to connect.
For example, if you connect services such as Apple Health, Strava, Google Calendar, Gmail, Google Places, calendar providers, or health and wearable platforms, we may receive tokens, profile details, and account data necessary to deliver Matcha features.
When you connect a Google account, we receive authorization tokens that allow Matcha to access only the Google data and permissions you approve. We store these tokens securely and use them only to maintain the connected Google features.
4. How we use information
We use information to operate Matcha, personalize recommendations, provide reminders and coaching, support connected integrations, improve product performance, maintain security, communicate with users, and respond to support, account, and privacy requests.
We may also use information to debug, monitor reliability, prevent abuse, and understand how Matcha is being used so we can improve the experience.
We do not use connected Google user data, including Gmail data, for advertising, data brokerage, creditworthiness, lending eligibility, or generalized profiling unrelated to the user-facing Matcha service.
5. Connected services and permissions
Connected accounts such as Strava, Apple Health, Google Calendar, Gmail, calendar providers, or health and wellness platforms are only accessed after user authorization. Matcha uses connected data to provide a more relevant and personalized experience for the user who connected it.
If you connect Apple Health through the iOS app, Matcha may access only the health categories you authorize, such as activity, sleep, workouts, body measurements, and similar wellness records. Apple Health data is used to provide user-facing Matcha features such as summaries, coaching, reminders, and planning support.
We do not sell Apple Health data, use Apple Health data for advertising, or share Apple Health data with data brokers or advertising networks. You can revoke Apple Health permissions in iOS Health or Settings, disconnect other integrations where available, and request deletion by contacting us.
You can revoke Matcha's Google access, including Gmail access, through your Google Account permissions, disconnect the integration where available, or contact us to request deletion.
If you disconnect an integration, Matcha may stop accessing new data from that source, though some previously received data may remain for a period of time as described below.
6. Google API data and Limited Use
Matcha's use and transfer of information received from Google APIs, including Google Calendar, Gmail, and Google Places APIs where applicable, will adhere to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
We do not sell Google user data, use it for advertising, share it with data brokers, or use it to determine creditworthiness or eligibility for lending.
Google Workspace API data, including Gmail and Google Calendar data, is not used to develop, improve, or train generalized AI or machine learning models. We do not transfer Google Workspace API data to third parties for advertising, data brokerage, creditworthiness, lending eligibility, or generalized AI or machine learning model training.
When Google Calendar or Gmail context is needed to provide a user-facing Matcha feature requested or authorized by the user, we may process the minimum relevant context through AI service providers acting on our behalf to generate responses, reminders, summaries, drafts, or planning support for that user. We require those providers to process Google user data only for the purposes described in this policy and not for their own advertising, model training, or other independent purposes.
Matcha personnel do not read Gmail or Google Calendar content unless you ask us to help with specific content, access is needed for security or abuse investigation, access is required by law, or access is necessary for internal operations using aggregated or de-identified data where appropriate.
7. Service providers and how we share information
We do not sell personal information. We may share information with service providers that help us operate Matcha, including providers that support hosting, storage, security, AI response generation, analytics, and message delivery.
For example, user messages and relevant context, including connected-service data when needed for a requested feature, may be processed by AI model providers such as OpenAI, Anthropic, and Google Gemini so Matcha can generate responses and personalized guidance. Matcha may also use messaging services such as iMessage and Telegram, together with the providers that enable those messaging experiences, to deliver messages, reminders, and account-related communications.
Some service providers may process data outside your country. Where required, we use appropriate safeguards for international transfers.
We may also share information when required by law, to respond to valid legal requests, or when reasonably necessary to protect users, rights, safety, or the service.
8. Data retention
We retain information for as long as reasonably necessary to provide Matcha, maintain the service, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods may vary depending on the type of information and whether a user maintains an active account.
If you disconnect Google Calendar, Gmail, or revoke Google access, Matcha will stop collecting new data from those Google services. We delete or de-identify previously received Google data when it is no longer needed for the purposes described in this policy, unless we need to retain limited information for security, legal compliance, dispute resolution, or backup integrity.
9. Security
We take reasonable administrative, technical, and organizational measures to protect information. Where stored by Matcha, health-related information, conversation content, messages, conversation-derived memories, daily events, OAuth tokens, and connected-service credentials are encrypted at rest. We also use other technical safeguards for connected-service credentials. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security.
11. Your choices and rights
You may request access, correction, deletion, or disconnection of certain data or connected services by contacting us. You can also stop using Matcha or stop connecting third-party services at any time.
For users in the EEA, UK, or Switzerland, we process personal data based on your consent, our contract with you, our legitimate interests in operating and securing Matcha, and legal obligations where applicable. Where connected health, wellness, or biometric data is treated as special category data, we process it only with your explicit consent or another lawful basis permitted by law. You may withdraw consent by disconnecting the relevant integration or contacting us, without affecting processing that occurred before withdrawal. You may have rights to access, correct, delete, restrict, object to, or export your personal data, to withdraw consent where processing is based on consent, and to lodge a complaint with your local data protection authority.
12. Children and age limits
Matcha is not intended for users under 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a user under 18, we will take reasonable steps to delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we may update the effective date and take additional steps when appropriate.
14. Contact
For support, privacy, deletion, or account-related questions, contact Yildiz Labs AB at: