Privacy Policy
Last updated: June 2026
1. Who we are
UniMatch Germany ("we", "us") helps students explore study and university options in Germany. The data controller is UniMatch Germany, operated by [Your full legal name], [postal address in Germany]. Contact: unimatch182@gmail.com.
2. What data we collect
- Account data: email, display name, and (for Google sign-in) your Google profile name and photo. Passwords are handled by Google Firebase Authentication — we never see or store your raw password.
- Assessment data: your answers to the study-fit questionnaire and the generated report.
- Contact data (optional): name, email, WhatsApp number, and country if you choose to save your report or request help.
- Technical data: standard log/usage data and cookies set by our hosting and authentication providers.
3. Why we use it & legal basis (GDPR Art. 6)
- To generate and show your study-fit report and university matches — based on your consent and to provide the service you requested.
- To let you create an account and return to saved results — to perform the service.
- To contact you about your results or application help, only if you opt in — based on your consent.
- To keep the service secure and improve accuracy — based on our legitimate interest.
4. Who we share it with (sub-processors)
We use trusted third parties to run the service. Your data may be processed by:
- Google Firebase (authentication, database, hosting) — Google LLC.
- OpenAI — used to process programme text and matching.
- Google Gemini — used to generate report narratives.
Some of these providers are based in the United States, so your data may be transferred outside the EU/EEA under appropriate safeguards (e.g. Standard Contractual Clauses). We do not sell your personal data.
5. Cookies
We use essential cookies needed for sign-in and core functionality (set by Firebase Authentication). We ask for your consent before using any non-essential cookies. You can withdraw consent at any time by clearing cookies in your browser.
6. How long we keep it
We keep your data only as long as needed for the purpose it was collected:
- Account & saved reports: while your account is active. If your account is inactive for 24 months, we may delete the associated reports.
- Assessment answers & generated report: up to 24 months, then deleted or anonymized.
- Contact data (if you opted in): up to 12 months after our last contact, unless you ask us to delete it sooner.
You can delete your data at any time — signed-in users from their account page, or by emailing us. We delete on request without undue delay.
7. Your rights
Under the GDPR you have the right to access, correct, delete, restrict, or port your data, and to withdraw consent at any time. To exercise any of these, email unimatch182@gmail.com. You may also complain to your local data protection authority.
8. Minors
Some of our users are under 18. We only process a minor's data with appropriate consent. If you are a parent or guardian and believe we hold a minor's data without proper consent, contact us and we will delete it.
9. Changes
We may update this policy. We will post the new version here with an updated date.