Version 2026-09-01 · Effective 1 September 2026
Aura Match reads a colour from a photograph and matches people by that colour. Doing so means processing a picture of your face — this page says exactly what we process, why, and for how long. We have aimed for accurate rather than short.
The party named above is the data controller under the General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law No. 6698 (KVKK).
The table below is the complete set of fields the application actually stores. If it is not listed here, we do not collect it.
| Category | Data | Source |
|---|---|---|
| Account | Email address, a hash of your password, name, date of birth | From you, at sign-up |
| Profile | Gender, who you are interested in, what you are looking for, bio, work, education, height, drinking and smoking habits | From you, optional |
| Location | The name of your city, nothing finer | Derived from your device's location on the device itself |
| Photographs | The pictures you upload, their dimensions, a perceptual hash, and the moderation outcome | From you |
| Aura reading | Three colour values, four numeric traits (energy, warmth, depth, clarity) and the archetype they match | Computed on your phone; the result is sent to us |
| Activity | Likes and passes, matches, messages | From using the app |
| Device | Operating system, app version, language, notification token, last seen | From the app |
| Safety | Reports you file and reports about you, blocks, your verification selfie | From you and from other users |
| Subscription | Plan, status, store transaction id | From Apple or Google |
| Consent records | Which version of which document you agreed to, and when | From the app |
Some data carries additional protection under GDPR Art. 9 and KVKK Art. 6. In Aura Match that means:
This data is processed on the basis of your explicit consent alone (GDPR Art. 9(2)(a); KVKK Art. 6(2)). You can withdraw that consent at any time from inside the app: Settings → Privacy and my data. Withdrawal takes effect going forward and does not make lawful processing already carried out unlawful.
We record consent together with the version of the text. "The user agreed" is not a defence; "the user agreed to this text, on this date" is. You can see every consent you have given, and when, under Settings → Privacy and my data.
| Purpose | GDPR basis | KVKK basis |
|---|---|---|
| Creating and running your account | Art. 6(1)(b) — contract | Art. 5(2)(c) |
| Reading your aura and ranking who you are shown | Art. 9(2)(a) — explicit consent | Art. 6(2) |
| Screening photographs before they appear | Art. 6(1)(f) — legitimate interest in user safety | Art. 5(2)(f) |
| Reviewing reports and preventing abuse | Art. 6(1)(f) — legitimate interest | Art. 5(2)(f) |
| Enforcing the age limit | Art. 6(1)(c) — legal obligation | Art. 5(2)(ç) |
| Sending notifications | Art. 6(1)(a) — consent | Art. 5(1) |
| Running your subscription | Art. 6(1)(b) — contract | Art. 5(2)(c) |
| Seeing errors and keeping the service working | Art. 6(1)(f) — legitimate interest | Art. 5(2)(f) |
There are two automated steps and we name both:
This is the question we are asked most, so it gets its own section:
We do not sell your data and we share none of it for advertising. The processors we use to run the service are:
| Who | For what | Where |
|---|---|---|
| Hetzner Online GmbH | Server and database | Germany |
| Cloudflare, Inc. | Photograph and backup storage (R2) | EU / US |
| Resend, Inc. | Verification and service email | US |
| Google (Firebase Cloud Messaging) | Delivering notifications | EU / US |
| Functional Software, Inc. (Sentry) | Error reports only — no session replay, tracing or profiling | EU / US |
| Apple, Google | Sign-in providers and payment, if you subscribe | Global |
Beyond these, we may share data with public authorities where we are legally required to. When such a request arrives we will tell you, unless the law forbids it.
Our servers are in Germany; some providers are based in the United States. Transfers outside the EEA rely on the European Commission's Standard Contractual Clauses. Under KVKK Art. 9, transfers abroad are subject to the standard contract / undertaking process, to be completed.
| Data | Retention |
|---|---|
| Account and profile | For as long as your account exists |
| Photographs and aura records | Deleted immediately when the account is deleted |
| Devices and sessions | Deleted immediately when the account is deleted |
| Reports | 2 years after the report is closed |
| Blocks | Indefinitely — a block protects the other person and survives deletion |
| Consent records | 5 years after deletion, to evidence that consent was given |
| Audit log | 3 years |
| Database backups | 14 days on the server, 30 days in remote storage |
You delete your account from inside the app: Settings → Delete my account. Then:
Under GDPR Art. 15–22 and KVKK Art. 11 you have the right to:
Write to support@auramatchapp.com. We answer GDPR requests within one month and KVKK requests within 30 days.
If our answer does not satisfy you, you may complain to the data protection authority of your country of residence in the EU, or to the Turkish Personal Data Protection Board.
In the event of a personal data breach we will notify the relevant supervisory authority and affected users within the periods the law requires.
Aura Match is for people aged 18 and over. The age check runs both in the app and on the server. If we learn that an account belongs to someone under 18 we close it and delete the data. If you become aware of such an account, please tell us.
When we update this text the version at the top changes. For significant changes we notify you in the app and ask for your consent again where it is needed — because consent records are tied to a version, agreement to a new version is a separate record.