Privacy Policy
Stackmate ("we", "our", or "us") operates the Stackmate mobile application and website at stackmateapp.com. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
By using Stackmate, you agree to the collection and use of information as described in this policy.
1. Information we collect
| Category | Data collected | Source |
|---|---|---|
| Account information | Name, email address, profile photo | Google sign-in, Sign in with Apple, or an email verification code |
| Profile data | Role (Founder/Candidate), skills, startup stage, commitment level, timezone, bio, project description | You provide directly |
| Face verification | The result of an on-device liveness check (blink, head turn, smile) — pass or fail, and which challenges were completed | Analysed on your device; only the outcome reaches us |
| Professional data | GitHub username, public repository language breakdown, commit cadence | GitHub (with your permission) |
| Photos | Profile photo you choose to upload | You provide directly |
| Messages | Real-time chat messages between matched users | Generated by you within the app |
| Device identifiers | Firebase Cloud Messaging (FCM) token for push notifications | Your device |
| Usage data | App interactions, swipe actions, connection requests, meeting schedules | Automatically collected |
| Connected AI clients | For each AI client you connect: a name you or the client supplies (e.g. "Claude Desktop"), when it was connected, and when it last used your account. The access credential itself is stored only as an irreversible hash. | Created when you connect a client |
Face verification note: The liveness check runs entirely on your device using Google ML Kit, which analyses the camera feed locally. No face image, video, or biometric template is uploaded to us or to any third party, and none is stored on our servers. We receive only which challenges you completed and whether the check passed. We do not use a biometric identity-verification vendor.
2. How we use your information
We use the information we collect to:
- Create and manage your account
- Compute compatibility match scores between founders and candidates
- Display your profile to other users in the discovery feed
- Facilitate real-time messaging between matched users
- Send push notifications about connection requests, messages, and meeting reminders
- Verify your identity and prevent fraudulent accounts
- Improve our matching algorithm and platform features
- Comply with legal obligations
- Issue, check, and revoke access for AI clients you have connected
We do not use your data for advertising purposes and do not sell your personal data to third parties.
AI / matching algorithm: Our "compatibility score" is computed by an internal, rule-based weighted-scoring algorithm running on our own servers — it is not a third-party AI/ML service, and it does not train, fine-tune, or improve any machine-learning model on user data. It scores profile fields you provide directly (skills, commitment level, timezone, startup stage) and never processes Google Calendar or other Google Workspace data. Google user data obtained via Calendar integration is used solely to check meeting availability and create calendar events, is never transmitted to any AI/ML service or used to train any model, and is never shared with third parties. The use of raw or derived user data received from Google Workspace APIs adheres to the Google User Data Policy, including the Limited Use requirements.
4. Data retention
We retain your personal data for as long as your account is active. Upon account deletion:
- Your profile is removed from the discovery feed immediately
- Your account data is permanently deleted within 30 days
- Chat messages in active conversations are deleted within 30 days
- Reviews you submitted may remain in anonymized, aggregated form
- Access for every connected AI client stops working immediately, and its record is deleted with your account
Certain data may be retained longer where required by law or for fraud prevention purposes.
5. Security
We implement industry-standard security measures to protect your data:
- All data in transit is encrypted using TLS
- Database access is protected by Row-Level Security (RLS) policies
- Authentication tokens are stored in device secure storage
- Biometric data never leaves your device
If you believe your account has been compromised, contact us immediately at privacy@stackmateapp.com.
6. Your rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your account and associated data
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to processing of your data in certain circumstances
- Restriction: Request that we restrict processing of your data
- Withdraw AI client access: Disconnect any or all connected AI clients at any time in the app, without contacting us. Withdrawal takes effect immediately.
To exercise any of these rights, contact us at privacy@stackmateapp.com. We will respond within 30 days. If you are in the EEA, you have the right to lodge a complaint with your local data protection authority.
7. Children's privacy
Stackmate is not intended for users under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, contact us at privacy@stackmateapp.com and we will delete it promptly.
8. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via push notification or in-app message and update the "Last updated" date at the top of this page. Continued use of Stackmate after changes constitutes acceptance of the updated policy.
9. Contact
If you have questions about this Privacy Policy or how we handle your data:
Stackmate
Email: privacy@stackmateapp.com
Website: stackmateapp.com