Legal

Privacy Policy

Last updated: August 7, 2026  ·  Effective: August 7, 2026

Contents
  1. Information we collect
  2. How we use your information
  3. Sharing and disclosure
  4. Data retention
  5. Security
  6. Your rights
  7. Children's privacy
  8. Changes to this policy
  9. Contact

Stackmate ("we", "our", or "us") operates the Stackmate mobile application and website at stackmateapp.com. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.

By using Stackmate, you agree to the collection and use of information as described in this policy.

1. Information we collect

Category Data collected Source
Account information Name, email address, profile photo Google sign-in, Sign in with Apple, or an email verification code
Profile data Role (Founder/Candidate), skills, startup stage, commitment level, timezone, bio, project description You provide directly
Face verification The result of an on-device liveness check (blink, head turn, smile) — pass or fail, and which challenges were completed Analysed on your device; only the outcome reaches us
Professional data GitHub username, public repository language breakdown, commit cadence GitHub (with your permission)
Photos Profile photo you choose to upload You provide directly
Messages Real-time chat messages between matched users Generated by you within the app
Device identifiers Firebase Cloud Messaging (FCM) token for push notifications Your device
Usage data App interactions, swipe actions, connection requests, meeting schedules Automatically collected
Connected AI clients For each AI client you connect: a name you or the client supplies (e.g. "Claude Desktop"), when it was connected, and when it last used your account. The access credential itself is stored only as an irreversible hash. Created when you connect a client

Face verification note: The liveness check runs entirely on your device using Google ML Kit, which analyses the camera feed locally. No face image, video, or biometric template is uploaded to us or to any third party, and none is stored on our servers. We receive only which challenges you completed and whether the check passed. We do not use a biometric identity-verification vendor.

2. How we use your information

We use the information we collect to:

  • Create and manage your account
  • Compute compatibility match scores between founders and candidates
  • Display your profile to other users in the discovery feed
  • Facilitate real-time messaging between matched users
  • Send push notifications about connection requests, messages, and meeting reminders
  • Verify your identity and prevent fraudulent accounts
  • Improve our matching algorithm and platform features
  • Comply with legal obligations
  • Issue, check, and revoke access for AI clients you have connected

We do not use your data for advertising purposes and do not sell your personal data to third parties.

AI / matching algorithm: Our "compatibility score" is computed by an internal, rule-based weighted-scoring algorithm running on our own servers — it is not a third-party AI/ML service, and it does not train, fine-tune, or improve any machine-learning model on user data. It scores profile fields you provide directly (skills, commitment level, timezone, startup stage) and never processes Google Calendar or other Google Workspace data. Google user data obtained via Calendar integration is used solely to check meeting availability and create calendar events, is never transmitted to any AI/ML service or used to train any model, and is never shared with third parties. The use of raw or derived user data received from Google Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements.

3. Sharing and disclosure

We share your information only in the following circumstances:

  • Other users: Your profile is visible to other Stackmate users in the discovery feed. Chat messages are visible only to your matched connection.
  • Service providers: We use Supabase (database and authentication), Google Firebase (push notifications), Railway (backend infrastructure), and Resend (transactional email). These providers process data only as necessary to deliver the service.
  • Legal requirements: We may disclose information if required by law, court order, or government authority.
  • Business transfers: In the event of a merger or acquisition, your data may be transferred to the successor entity.

We never sell, rent, or share your personal data with advertisers or data brokers.

AI clients you connect

Stackmate can be connected to an AI client you use — for example an AI assistant running on your own computer. This is off by default. It happens only if you complete a sign-in that names the client and grant it access, and you can withdraw that access at any time from the app.

What a connected client can reach. A connected client acts as you, and sees what the app already shows you — including the profiles and project descriptions of the people in your discovery feed and your existing connections. It cannot see anything the app would not show you. It cannot read your chat messages, and it cannot delete your account.

What this means for other people. Because a connected client sees your feed, the profile and project description of another Stackmate user may be transmitted to the AI provider you have chosen, on your instruction. That provider is not our service provider and we have no contract with them about your use of it; their handling of that data is governed by your agreement with them. For the same reason, other users' AI clients may receive your profile and project description. We ask both sides for consent before enabling this, and you can decline or withdraw it and keep using Stackmate normally.

Stackmate itself does not send your data to any AI or machine-learning service, and no AI provider receives your data through us unless you connect a client yourself.

4. Data retention

We retain your personal data for as long as your account is active. Upon account deletion:

  • Your profile is removed from the discovery feed immediately
  • Your account data is permanently deleted within 30 days
  • Chat messages in active conversations are deleted within 30 days
  • Reviews you submitted may remain in anonymized, aggregated form
  • Access for every connected AI client stops working immediately, and its record is deleted with your account

Certain data may be retained longer where required by law or for fraud prevention purposes.

5. Security

We implement industry-standard security measures to protect your data:

  • All data in transit is encrypted using TLS
  • Database access is protected by Row-Level Security (RLS) policies
  • Authentication tokens are stored in device secure storage
  • Biometric data never leaves your device

If you believe your account has been compromised, contact us immediately at privacy@stackmateapp.com.

6. Your rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your account and associated data
  • Portability: Request your data in a structured, machine-readable format
  • Objection: Object to processing of your data in certain circumstances
  • Restriction: Request that we restrict processing of your data
  • Withdraw AI client access: Disconnect any or all connected AI clients at any time in the app, without contacting us. Withdrawal takes effect immediately.

To exercise any of these rights, contact us at privacy@stackmateapp.com. We will respond within 30 days. If you are in the EEA, you have the right to lodge a complaint with your local data protection authority.

7. Children's privacy

Stackmate is not intended for users under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, contact us at privacy@stackmateapp.com and we will delete it promptly.

8. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via push notification or in-app message and update the "Last updated" date at the top of this page. Continued use of Stackmate after changes constitutes acceptance of the updated policy.

9. Contact

If you have questions about this Privacy Policy or how we handle your data:

Stackmate
Email: privacy@stackmateapp.com
Website: stackmateapp.com