BrainMatch — privacy and how your data is used
Run by: Turing Creative LLC Questions: zachary@brainmatch.app
What BrainMatch is
A place to get to know yourself, one ordinary day at a time. If you're with someone, you watch the two of you grow. If you're single, you work out what you actually want. Nothing here gives you a compatibility number or scores your relationship.
How your data is used
- To help you get to know yourself. Everything you answer builds your own record: your brain map, your journal, your monthly recap. It's there so you can see your own journey, and it's yours to export or delete at any time.
- To help you and your partner now. If you're in a couple, the reports, things to say, and songs work from what each of you chooses to share. Your partner never sees anything you haven't shared.
- To match future couples well. Questionnaire and check-in answers are analysed together to learn what good matches look like and to build BrainMatch's matching. We call this **matching data**. It's filed under a random id, never your name or email, alongside your birth year, whether you're single or in a couple, when your relationship started, how you met (if you meet someone here). That makes it pseudonymised, not anonymous: the id links your answers over time and to your partner's, so it's still treated as your personal data. It never includes your writing, your email, or your gender and the gender you're looking for. "Help build matching" controls whether yours is used to build matching features.
Please keep very sensitive things out
Please don't put very sensitive things in BrainMatch, like passwords, account or card numbers, your address, health details, private details about other people, or anything you wouldn't want stored.
The app says this when you join, next to your choices, and again in Privacy. Everything you write is kept for you as described below, and you can delete any of it; this is about what's best never written down in an app at all.
Your words, in your hands
If you need to keep your words for any reason, download a copy regularly. You -> Your data -> Export your words gives you everything, any time; delete your account there too, and every word goes with it.
Every deletion is your choice, named first (owner, 2026-09-30). Nothing you wrote is deleted because you changed where you are (single, seeing someone, together), linked, or unlinked; the app asks in place before anything is removed, and says what goes. Turning Writing off deletes everything you've written: your journal answers, two things, letters to later, the jar and your replies to Megan; the notes, thank-yous and songs you sent a partner, and your copies of them in past chapters; your firsts, surprises and bucket list; free notes and Five senses; the songs you added to a couple's playlist; and your next date, if you set it last.
What you'll do
- A 15-minute personality questionnaire now, and again every few months.
- A daily check-in: a few quick taps, about 30 seconds: your mood and, if you're in a couple, how appreciated you felt and your time together. If you're in a couple, it also covers the state of us: three taps once a week on how the two of you are doing (how close you feel, time together, and what would help). Your partner sees yours only once they've given theirs. Both are under the check-in permission, and turning it off deletes both.
- Counted across everyone. Your questionnaire answers and check-ins are also counted with everyone else's: how many people gave each answer, per question and per month. Those counts never carry your id or a day, and a group of fewer than 10 people is left out, so nothing in them is yours on its own. Your answers themselves go into the owner-only research export only if you turn on "Help build matching" (see "The owner-only research export").
- If you choose: open questions, what-would-you-do scenarios, Two things a day, Taste, and the questions the app builds from your own answers.
If you're in a couple, your partner joins separately on their own phone. Neither of you can see the other's answers unless one of you shares something.
Optional: what you're looking for
You can answer eight questions about what you need from a partner (or, if you're in a couple, how your relationship actually runs). You can also say your gender and the gender you're looking for.
Your gender and the gender you're looking for are sensitive information (under GDPR they can reveal sexual orientation). They are stored separately from everything else, never included in matching data, never shown to your partner, and entirely optional. Turning this section off deletes all of it: what you need, who you want, your Taste picks, your gender answers, your green flags and dealbreakers, and your sealed "Before you met".
The archive, the journal, and Two things
One question a day, answered by tapping, writing, or dropping a pin on a grid, kept with its date so you can look back. Two things a day: something you did, an idea, or something to get better at, with an optional mood. All of it collects in your journal, a day at a time. Only today's archive entry can be changed. Each archive entry has its own share switch, off by default; Two things are never shown to a partner.
When you answer the archive question, a look-back is booked for that answer: about six weeks later, the same question is asked again on Today, and only after you've answered it does your earlier answer appear beside the new one. We keep the date it's due and the answer you give when it comes round, under the Writing permission, like the archive itself: only you see it, it's in your data export, and it's deleted if you turn Writing off or delete your account.
Bucket list
Things you'd like to do one day with a partner, each tagged with the kind of thing it is, and ticked off with the date when you do them. It's covered by the "Writing and scenarios" permission, private to you (never shown to a partner, never in matching data), and it stays with you if you meet someone.
Things to say, and the answers you write back
The app takes answers you've already given and hands them back as a question. You can write an answer to any of them. They're covered by the "Writing and scenarios" permission, private by default, and your partner sees one only if you turn on its share switch.
Sending a song
If you're in a couple, you can send your partner a song with a reason and a short line. It goes to them and nobody else, is not included in matching data, and the app never counts how many songs go each way.
If you're single and meet someone
- How you met (through friends, online, at work, out somewhere, or elsewhere) is recorded with the date and included in matching data: how people meet, and how it goes from there, is how BrainMatch learns what good matches look like. Nothing else about the person is asked.
- What you had said you were looking for is sealed, dated, and opens on a date you choose. It is yours alone: the person you met can never see it, it is not in matching data, and the app never compares them with it. If you meet someone again later, the first sealed note is kept as it was (the app says so, and from when); a new one never writes over it.
Question of the day, time capsules, nudges and appreciations
A short either/or question each day; in a couple, you also say which one you think your partner would pick, and neither of you sees anything until you've both answered; then you see both picks side by side. Time capsules (a letter to later) stay sealed until the date you choose, at least a week ahead; the server keeps the words and hands them back only on or after that day by its own clock, once, when you open the envelope, and it remembers when you did. After that the letter is a keepsake in your journal. A capsule is one of your written answers (that permission), and is deleted with it. A nudge is a wave with no message, at most once a day, and can be switched off in Reminders. An appreciation is one of our fixed kind lines ("Thank you for today"), one a day, sent to your partner. For nudges and appreciations we keep who sent it, the day, and when it was seen; your "nudges off" choice is kept as a setting.
Notes to your partner
In a couple, you can leave a short note (up to 140 characters) on your partner's Today. It's your own words, so it's under the writing permission: only your partner can read it, and turning writing off deletes the notes you sent. Notes your partner sent you are theirs, and go if they turn writing off or delete their account.
Optional: Moments (couples)
You can keep photos of moments you want to remember, each with a title, a date and an optional note. Only you and your partner can see them. They are stored for the two of you alone, never used for matching, never analysed, never in matching data, and never shared or sold. You can delete any moment you added, and turning Moments off deletes every moment you added, photos included.
Optional: Notifications from your partner
If you turn on "Tell me when my partner sends something" in Reminders, your phone is told when your partner sends a heartbeat, a note, a letter or a song, or answers today's question. The notification only ever says that something is waiting, in fixed words we wrote; nothing anyone wrote is in it. To reach your phone it passes through Expo's push service and Apple or Google. Reminders are different: they're scheduled on your phone and never touch the server.
Couples: thank-yous, your next date, and long distance
Under the writing permission: the thank-yous you write to your partner (they see them; you never see whether they've been read) and the next date you set (both of you see it; it's deleted two days after; calling it off or clearing it is asked first, because it goes for both of you). Turning writing off removes your thank-yous from their jar and the next date only if you were the one who set it last; one your partner set stays. If you switch on long-distance mode, each phone sends its time zone offset (how many hours it is ahead of or behind UTC, like "+1"), so the other can see your local time and a "good night" can arrive in their evening (and a "good morning" in their morning). It's the offset only, never the name of your time zone or anything about where you are. It's only kept while the mode is on: it's deleted when either of you turns long-distance mode off, or when you delete your account. A good night or good morning itself carries no words and is deleted 30 days after it's sent.
Singles: dealbreakers and green flags
Under "What you're looking for": your private list of dealbreakers and green flags. Only you see it. It's never shared or used for matching; if dating ever uses it, that will be a separate choice you make. The profile in your words is stitched only from what you've already given (your trait headlines, Taste picks, a line you wrote, a bucket-list item, your green flags) and is shown only to you.
Couples: firsts, surprises, the Sunday ritual and your shared garden
Under the writing permission: firsts you log (shared with your partner's timeline unless you switch that off for one) and surprises you plan (your partner never sees any of it until you choose to reveal it, and then only its title). The Sunday ritual stores only a yes for each week each of you did it, nothing about what you said. The shared garden is drawn only from what both of you have already chosen to share on the "two of you" map.
Optional: your birthday
If you add it, we keep only the month and day (your birth year is already known from sign-up), so Today can celebrate with you. Your partner sees only "It's their birthday today", and only if you tick "let my partner know"; never the date. Remove it any time in Settings; it's included in your export and deleted with your account. We also remember which look you chose for your own brain drawing; only you see it.
Rooms and chapter titles
Under the questionnaires permission: your answers in Rooms (question packs). The sensitive rooms (money and security, family and roots, health and energy) are taps only: no free text, and never amounts, accounts, employers, diagnoses, medication, names or places. Those answers are stored encrypted with their own key, never go into matching data, and can each be deleted. Under the writing permission: your monthly chapter titles, made only from your own words and days; words that look like names, numbers or places are never used.
Asking your friends, and BrainMatch on a computer
If you ask your friends about today's this-or-that, we make a link that shows only the question: never your name, your pick or anything about you. Friends' picks come back to you only as counts. We don't keep a visitor's internet address: to allow one pick per visitor, we keep a scrambled code made from their address and the link, with a random key that changes daily, so it can't be turned back into the address. Links close after 7 days and the picks and codes go with them; each day's key is deleted a day after that. The links are under the writing permission. If you sign in on a computer (brainmatch.app/me), we keep a scrambled record of that browser's session for up to 30 days, deleted when you sign out or delete your account. The web shows only your own journal and brain map.
What matters to you
Under the questionnaires permission: a "What matters to you" card sort (16 values, your top three), kept with dates so you can redo it every few months. Your "really matters" values light spots on your own brain map; they're filed with the trait they're closest to, which is a layout choice, not a claim about your personality. Turning the permission off deletes them.
Optional: Faith & spirit
If you practise a religion or a spirituality, you can add a Faith chapter: the tradition you choose, the daily practices you tick, the good deeds you log, the prayers, mantras and readings you keep in your own words, and your reminder times. Only you can see it. It is never shown to a partner, a friend who introduces you, or anyone else; it is never used for matching, never in matching or research data, never read by AI, and never shared or sold. Reminders are scheduled on your own phone; nothing is sent. Turning Faith & spirit off deletes all of it.
Optional: Couples answers with your partner
One question a night for the two of you, answered alone. Your answer is sealed on our server until your partner has answered too; then you both see both, and each of you keeps your own. Only the two of you ever see them: never anyone else, never used for matching, never in matching or research data, never shared or sold. Turning this off deletes your answers; your partner's stay theirs.
Optional: Friends as matchmakers
Ask a friend who knows you to be your matchmaker, with one link you send them yourself (BrainMatch never emails your friend and never asks for their name or address). For an ask you make we keep the first name you chose, your one line about yourself, and when you made it; anyone with the link can read those two things. Nothing about your friend is kept until they say yes in the app under this same permission; then their chosen first name and when. A matchmaker can introduce you to someone they trust with an ordinary introduction (above): you see their note in the app and say hello or not now, and nothing opens until both of you have said yes. If you say yes to being someone's matchmaker, we keep the first name you chose and that you said yes. A partner never sees any of it, and none of it is used for matching, never in matching or research data, never shared or sold. Turning this off deletes your asks and your yeses; introductions already open carry on.
Optional: Hobby chapter
One hobby, one question a night about it, kept as a chapter of your own. We keep the hobby you picked, or for a hobby of your own, the hobby's name in your own words and a photo you choose as its logo; your buddy sees the name and the logo. We also keep the first name you choose to show a buddy, your answers, and which ones you chose to share. Your one buddy is someone you connected with by code (never anyone's email): they see only the entries you share, and only while you keep them as your buddy. A cheer from a buddy is one tap, kept as the day it came. The logo photo is checked to be a real JPEG or PNG, kept on our server like your other photos, never analysed, and in your export. Nothing here is a score or a streak, a partner never sees it, and none of it is used for matching, never in matching or research data, never shared or sold. Turning this off deletes your chapter, the photo you chose as its logo, and your cheers. (Version 2026-09-30.4 added the hobby of your own and its logo.)
Passkeys
If you add a passkey (sign in with Face ID or your phone's lock), we store only its public key, a label you choose, and when it was added and last used. The private key never leaves your phone. Passkeys are deleted with your account, and you can remove any of them in Settings.
Small things you keep
Under the writing permission: the songs you add to your couple's date playlist (your partner sees the one list while you're linked; each of you takes off only your own; each song belongs to the couple it was added in, so a later partner never sees it, and after an unlink it stays with you in that past chapter); when an answer lights a spot on your map for the first time, the day and up to one line of those words, so the app can tell you which spot and why; a free-write note (a journal entry with no prompt, filed under a chapter, Faith, Hobbies or nothing; only you see it, and it is deleted when the writing permission is turned off); the notes in your gratitude jar, the days you star in your journal, and how you feel about a spot on your own brain map (one tap on the spot's page: "That's me", "It surprised me" or "Still working it out"; never a score, never shown to a partner, never in matching data). Only you see them, and turning the writing permission off deletes them. If you take a break (pause mode), we keep only the dates of the break, so the app knows to stay quiet; reminders pause on your phone and partner notifications pause on the server.
If you unlink: past chapters, and your own copy
Either of you can unlink at any time, in Privacy ("Unlink from your partner"). When the link ends, whether one of you unlinks or one of you deletes their account:
- **Each of you keeps your own copy of what you shared, and deleting your copy never deletes theirs.** Theirs never deletes yours either. Nobody is asked, and nobody is told who unlinked.
- Your side stays in your Journal, under Past chapters: the day the link began and the day it ended, what you wrote in those days (your Tonight-together answers included), the moments you added, the firsts you logged, the surprises you planned and the songs you put on your couple's playlist. Your writing stays where it already is, under the same permissions.
- You get your own copy of anything that lived in a place the two of you shared: the notes, thank-yous and songs you sent them, and the notes, thank-yous and songs they sent you (given to you, like a posted letter; since 2026-09-30), under the writing permission like the originals, and a letter they gave you, written before you met (already yours once given). So one of you deleting an account, or turning a permission off, never takes the other person's copy with it.
- What else they added stays with them. Their moments and their answers, even ones they shared with you, are not copied to you. Nothing either of you kept private ever is. Once the link ends, what they sent you shows only in your own past chapter (and your export), marked as theirs to you, never anywhere else.
- A letter to later you wrote in those days stays sealed until its own date, by our server's clock. Unlinking never opens anything early.
- You can delete your copy of a chapter at any time, asked in place first. That deletes the chapter, the copies kept in it, and the moments (photos included), firsts, surprises and playlist songs you added while you were linked. What you wrote in your journal stays in your journal. The other person's copy isn't touched, and they aren't told. Or delete only some of it (the moments you added, the firsts you logged, your copies of the notes, thank-yous and songs, or the letter given to you) and keep the rest: the "That's allowed" page offers this after a link ends, before it asks where you are now.
- If a plan-a-date connection ends, the dates you logged stay in your journal like anything else you wrote, and you can delete any one of them on the same page. Two dates logged the same day, from two connections, are two entries.
- Past chapters are in your export (Privacy → "Show everything you store about me") and are deleted with your account.
Things with no switch of their own
A few small records aren't anything you've said; they're how the app keeps track, like settings. They're part of your account (the "Join BrainMatch" permission), you can see them all in your export, and they're deleted with your account:
- Settings and choices: nudges on or off, long-distance mode on or off and the day you'll next be together, whether your bucket list is on your shared wall, the look you chose for your brain drawing, your birthday (month and day, if you added it), and pause dates.
- What's already been shown: which milestones, occasions (anniversaries, months together, seasons) and "waiting for you" cards you've seen, and the pulls you've earned in the gratitude jar, so nothing is shown twice.
- Small wordless signals: evenings you tapped Lights out, Sunday-ritual yeses, heartbeats (deleted once seen, or after 30 days), good nights and good mornings, nudges and appreciations.
- How you met, if you were single and met someone (see above; it's in matching data).
- Tell a friend: your six-character code, if you've opened "Tell a friend", and a count of friends who joined on it. If you joined on a friend's code, we keep that link (their account and yours) so that, after your first day, each of you gets one extra pull from the gratitude jar. Neither of you is ever shown the other: the friend never learns whose code it was, and the referrer sees only a number of friends, never who. A week with at least three active days (any check-in or answer) earns the same kind of extra pull too, whether or not you've ever referred anyone. These are shown together as one plain credit balance - a number of extra gratitude-jar pulls, never money, and never treated as scarce.
- Suggestions and bug reports you send us (see "Bug reports, suggestions, crash reports and our website forms" below).
- Shop quote requests (the Shop isn't open yet): when you ask for a quote on something in the Shop, we keep which product, how many, whether it's to go to someone else (a yes or no, never an address), the quote and its status. Nothing you've made or written is sent anywhere by asking, and nothing is bought. You can withdraw a request; withdrawn ones are deleted a month later. Kept with your account (deleted with it) and in your export. We see only how many requests each product has, never what you asked for.
- A letter you gave your partner. Once given, like a posted letter, it's theirs: turning writing off deletes your own copy and anything not yet given, but not the one you handed over. Deleting their account deletes theirs. Deleting your account deletes your own copy, never theirs: when the link ends that way, the one you handed over stays with them, in their Past chapters (see "If you unlink" above).
- Past chapters: the day a link began and the day it ended, for each of you (see "If you unlink" above). Nothing in it says who unlinked.
- A request to link: linking asks both of you. When you enter someone's invite code, we keep which code, that it was you, and when, until the person who made the code says yes (it then becomes your link) or no, you take it back, or the code runs out after seven days; then it's deleted. The person who made the code is shown only when it was used, never who, and gets one notification saying so if they've turned notifications on. It's in your export and deleted with your account.
Optional: A photo a day
You can keep one photo a day in your journal, in place of writing. Only you can see them, unless you're in a couple and tick "share with my partner" on a particular photo, in which case your partner sees that one. They are never used for matching, never analysed, never in matching data, and never shared or sold. You can delete any photo, and turning this off deletes all of them.
Five senses, and optional: Your avatar
Five senses (on the You tab) keeps a small line of gratitude for any of the senses: something you saw, heard, tasted, touched or smelled today. Those lines are writing, kept under the writing permission like the gratitude jar: only you see them, each one lights a spot on your own map, they're in your export, and turning writing off deletes them.
Your avatar is a little drawing of you that you build yourself from a few choices: the gender you choose, a skin tone, a hairstyle and its colour, a top, and extras like glasses or freckles. We keep only those choices, not a picture; the app draws it. Because a skin tone can say something about you, it has its own permission, off until you turn it on. Only you see it. No AI draws it or reads it, it's never used for matching, and it's never shared. You can delete it at any time, and turning the permission off deletes it.
Optional: Connecting by code
You can have a code of your own (a QR on the You tab, separate from your Tell-a-friend code) to show someone in person. Only the BrainMatch app can read it, and you can replace it with a new one at any time. When someone scans it, each of you says why, on your own phone: plan a date, share a hobby, or you're in a relationship. Nothing is set up until you both picked the same thing; until then you both see only "You've connected. Nothing's set up yet.", and neither of you is ever told what the other picked. What we store, under this permission:
- Your code, and each connection: the two accounts, what each of you picked, when it was made and last used.
- Share a hobby ("Alongside"): one short hobby tag each, and the small posts you each add about it. The two of you see one list; there is no chat and no reply thread. No AI reads these posts. Before a tag, a post or a playlist song is saved, fixed word lists (no AI) check it on your phone and on our server: insults, sexual words, threats, slurs, contact details and private things like health or religion can't go on it. Report is beside each of the other person's posts, their tag and their songs, and on the person (see "Reports" below).
- Plan a date: which of your Taste picks you chose to show that one person. Each pick has its own switch, off until you turn it on, and they see only what you switch on. From those, the app shows one thing you both picked (never how many, never a score), a kind of place from the bucket-list kinds, and one fixed question for the walk home. It predicts nothing. While a plan-a-date connection is open, the app asks you once a day "Still good?" (yes, not sure, or end this); your answer is yours and is never shown to them. A short first-date note (meet somewhere public, tell a friend, keep your own way home) is shown once. A date playlist: a song each of you adds (title and artist, typed in), on one list you both see while the date is set up. Nobody is told when one is added, you can take off only your own, and it's deleted with the connection (your own songs are kept for you; see "Ending and blocking").
- "You're in a relationship" hands you to the ordinary partner link, described above.
- Ending and blocking: either of you can end a connection at any time, with no reason asked; the app names what goes before you confirm. It ends for both of you at once, the shared list under it is deleted, and the other person sees only "This connection has ended." Blocking does the same and also keeps that person's account id so their code can never connect to yours again, in either direction. A scan nobody set anything up on (no reason picked, or the two never matched) closes itself after 14 days untouched; **a date or hobby that's set up never closes on its own.**
- Your own words are kept when a connection ends, however it ends (you end it, they end or block it, they turn this permission off or delete their account): the songs you added, your date idea, your hobby tag and your posts are copied for you alone, shown in your Journal under Past chapters as "From a connection that ended", in your export (
connections.kept), and deleted when you turn this permission off or delete your account. Never their words, never who they were. (Version 2026-09-30.5 added these kept words.) - Logging a date puts a private note in your own journal (under the writing permission), and a photo if you add one (that day's photo, under "A photo a day"; if that day already has one, the app asks before replacing it). Nobody else sees it: not them, and not a partner.
A partner never sees any of this, none of it is used for matching or in matching data, and turning this off ends every connection you're in and deletes all of it.
Optional: Introductions
You can introduce two friends you think should know each other, with one link you send them yourself, from your phone's own share sheet. BrainMatch never sees who you sent it to, never reads your contacts, and never asks for, or keeps, either friend's name, email or number. What we store, under this permission:
- An introduction you make: the first name you chose for them to see you by, your reason in your own words, when you made it, and when it closes. **Anyone with the link can read your first name and your reason**, so send it only to the two of them, and write only what you'd say with both of them in the room. Your reason is checked by fixed rules (no AI) on your phone and on our server before it's saved: it can't hold insults, sexual words, threats or slurs, mention money, arguing, anyone's looks or past, anything private about them (their health, sexuality, religion, a pregnancy or a loss), or carry a phone number, email, link or handle. The first names you and your friends choose get the same check for insults, sexual words, threats and slurs, and a swapped contact line has to be a number, an email address or an @handle.
- Nothing about either friend is stored until that friend says yes, in the app. Opening the link on the web or in the app stores nothing: no visit, no count, no address. The page's "Become a beta tester" button never carries the link's code, so the beta list is never tied to you.
- If a friend sends you one and you say yes: the first name you choose to show, and when you said yes. Until both friends have said yes, nobody is told anything: the one who made it sees only "Sent. Waiting on them.", whatever either of you did.
- The room for three, once both friends have said yes: each person's own pick in one this or that (nobody's shows until all three have answered); for the two friends only, **a first coffee**: when you're free (a few fixed choices; you see only whether a time suits you both), and a way to reach you only if you choose to swap it, shown to the other friend only while you both have. The one who made the introduction never sees the coffee plan or a swapped contact. "Stay connected" hands the two of you to Connecting by code, under that permission and its rules, only if you both tap it and both have it on.
- No thanks is one tap, on the web page (no account needed) or in the app, and deletes the introduction. Leaving, blocking and reporting: either friend can leave or block at any time, which ends the room; the one who made it can leave (the room carries on for the two of you) or say "That's not who I sent it to", which ends it for everyone. A block keeps the two of you apart from then on. Report, in the room, on the coffee page and before you answer, covers the reason, a name, a swapped contact line or a person (see "Reports" below). Anyone who had said yes is told only "This introduction has closed." or "This introduction has ended.", never who or why.
- It lasts 14 days: a link closes 14 days after it was made unless both friends said yes; a room closes 14 days after anyone last used it.
A partner never sees any of it, none of it is used for matching or in matching data, and nobody earns anything or is counted for making one. Turning this off closes every introduction you made or said yes to, and deletes all of it: a room you made carries on for the two friends, without your words.
Optional: monthly Complementary Report
This switch turns on what you and your partner see about each other:
- A monthly PDF comparing your personality results with your partner's.
- Your Taste picks (the quick-fire either/ors), with the pick each of you thought the other would make, side by side, and your scenario picks, shown the same way.
- Date ideas from picks you've both made or shared.
- The "two of you" map and your shared garden, drawn only from answers you each chose to share.
And:
- It only works if both of you turn it on.
- Your partner will see your five trait levels in their copy, written as words (for example "Planning ahead" or "Going with the flow"). There are no numbers, scores or percentages in it, and it never ranks one of you against the other.
- It never includes your check-ins or anything you wrote and didn't share.
- It describes your answers. It does not predict whether your relationship will last.
- Nothing is stored for it: it's made when you open it, from answers kept under your other switches. Turning it off stops it for both of you, with the date ideas and garden made with it, and deletes nothing; your answers stay yours.
Megan, and how AI is used
Megan is not an AI. She's a set of written replies picked by simple rules that look at the shape of what you wrote. Nothing you write is sent anywhere to produce them. She can be turned off anywhere.
- Her voice is AI-generated: a text-to-speech voice, recorded in advance from lines the BrainMatch team wrote. It never hears or reads anything you write.
- An AI writes your prompts and insights (since 30 September 2026; the permission "An AI reads your answers to write your prompts and insights", version 2026-09-30.3). To write tonight's question and what each spot on your map means, BrainMatch sends your own written answers to an AI model run by Anthropic (the Claude API). What is sent: your written answers to the daily question and the Monday Mix questions, with the question each one answered: at most eight excerpts of up to 280 characters for one spot's insight, and your last five answers for tonight's question. Only yours: never a partner's, a buddy's or a friend's, and never your name, email or account id. Anthropic processes them under a data-processing agreement and doesn't use them to train its models. What comes back is a short text in plain words: kept with your account, shown to you and no one else, in your export (
aiTexts) and deleted with your account. It is written once per spot (again when a new answer lights it) and once per night, at most twenty a day. Whenever no key is set on our server, the model is slow, or its text would break our rules (no numbers about people, no money or conflict, no diagnosis, no brain regions), the human-written version is used and the app says so. This is your choice (since 30 September 2026, later the same day): the switch starts off everywhere, and you turn it on at Join or later in Privacy, or never. Off, nothing of yours is sent to any AI, and tonight's question and what each spot means are written from your own words by fixed rules; on, they're a little more on the money. Turning it off deletes nothing: what the AI already wrote stays in your account and your export, shows again if you turn it back on, and is deleted only with your account. Nothing else you write goes to any AI: not photos, not letters, not notes to a partner, not what the two of you share. - Matching models: only if you turn on "Help build matching", your pseudonymised answers (under a random id, never your name or email) may be used to train the models behind future matching. Today that means the owner-only research export, analysed on BrainMatch's own computer after the owner downloads it; no outside AI or model service receives it.
- Keep out of AI: a list of whole sections (your journal, day notes, photo captions, Taste, brain answers, letters, things you wrote for the two of you) or single things (one journal day) that the AI above never reads. The server honours it before reading anything; the list is kept with your account, included in your export and deleted with it. (The screen to edit it was taken out of this build's Settings; email us to change yours until it returns.)
- Megan follows up: if something you write in Two things names a day ahead ("interview Thursday", "big day tomorrow"), Megan asks how it went on that day. It's a simple rule that looks only for "tomorrow" or a day's name. Your answer is kept in your journal, under the writing permission, and deleted with it.
Bug reports, suggestions, crash reports and our website forms
- Bug reports you send from the app: what you wrote, which screen you were on, the app's build and your phone type, and, only if you tick "you can reply", your email address. We keep it with your account (deleted with it), and email a copy to our inbox so we can fix it.
- Suggestions you send from "Suggest something": what you wrote, the app's build and your phone type, and, only if you tick "you can email me about it", your email address. Kept with your account (deleted with it, and in your export, with the status we gave it: new, planned, done or no), and emailed to our inbox the same way as a bug report.
- "Something my partner sent": if your partner sends you something that isn't ok, you can tell us from the report screen or from Settings. It's kept and emailed exactly like a suggestion, marked so we read it first. A person reads it, never a machine, and nothing you write there is ever used for anything else. **Your partner is never told you wrote it and never sees it.** If you'd like the link with them ended, say so and we'll end it; you can also end it yourself at any time (see "Your choices").
- Reports (Apple asks every app where people's words reach each other for this). Wherever someone else's words reach you (an introduction, a list you share with someone you connected with by code, something a partner sent), Report is there, beside Block, for the words or for the person. A report keeps: who reported, whose words they were (worked out by our server from what was reported, never typed by you), what kind of thing it was and where (the introduction's code or the connection), the words as you saw them, anything you add, when, and what we did about it. The words are copied into the report so that a block, a leave or a deleted post afterwards doesn't erase what we need to read. It's emailed to our inbox, and it's on the owner's own list of reports even when email isn't working. **A person reads every report within 24 hours, never a machine.** When something breaks the Terms, we remove it, and we can suspend or close the account that sent it: a suspended account can still export or delete its data, and what it wrote is hidden from everyone else until the suspension is lifted. The person you report is never told who reported them, and never sees your report. Reporting doesn't end anything by itself; Block, on the same screen, does.
- Reports about you: if someone reports your words, the report keeps them, and your account id, as above. Your export shows reports about you (what, the words, when, what we did), never who made them or what they said. Reports are kept on our legitimate interest in keeping BrainMatch safe, not under a permission of their own, so switching a permission off doesn't delete a report made under it. If you delete your account, reports you made keep the words that were reported but lose anything you added, and reports about you lose your account id.
- Counting, not tracking: brainmatch.app uses no analytics service, no pixels and no advertising cookies. We count, on our own server, how many times each page of our site was opened each day and which site the browser said it came from (its domain only, such as a search engine, never the full address), and how many different visitors there were that day: for that, each visit is turned into a code made from the day, the connection and the browser with a secret; the connection and browser are never kept, and the code can't be turned back into either or matched across days. We also count how many times a shared this-or-that link was opened each day, how many times a page of our site was opened from each printed QR code (a poster, a card), how many times the public question of the day (brainmatch.app/q/today) was opened and how many taps each of its two sides got, and how many beta sign-ups came through which page of our site or which friend's code. These are daily totals with nobody in them: no address, no name, no id is kept with a count.
- Crash reports: if the app crashes, it sends what went wrong (with anything that looks like an email, a code, a number or a sentence removed), the screen, the app version, your phone type and a random id made only for crash reports. They're not linked to your account and are deleted after 90 days. The first report of each crash each day is emailed to us.
- The beta and investor forms on brainmatch.app: what you type in (name, email, and your answers or message). It's emailed to us, we send you one welcome email, and the form entry is deleted automatically after 12 months, or sooner if you ask.
- Our inbox (currently Gmail, run by Google) is where these copies arrive, along with alerts about the service. Emails there aren't deleted automatically; ask and we'll delete yours.
The newsletter
If you give us your email for the newsletter on brainmatch.app, we send one confirmation email, and you're on the list only once you tap the link in it. An address that's never confirmed is deleted after 7 days. Every issue carries a one-click unsubscribe link and our postal address; an unsubscribed address is deleted within 30 days. The list is its own thing: email only, kept apart from the app and never linked to an app account, even if you added the same address in the app, and never used for sign-in or matching. Issues are sent through Resend. We never sell or share the list.
Where your data is
BrainMatch's server is moving to Cloudflare, in the United States, in October 2026. Until the day of the move, which we announce in the app, everything below is held on one computer that Turing Creative LLC controls, in the United States, exactly as before; from that day, this is where it is. In plain terms:
- Your account, answers, journal and everything else you write are in one database held by Cloudflare in a "Durable Object", a kind of storage Cloudflare lets us restrict to the United States. We chose that restriction when we set it up; it can't be changed later.
- The photos you add (Moments, your photo a day) and the files of each encrypted backup are in Cloudflare's R2 storage, which isn't open to the public: photos are served only through the app, after sign-in.
- Cloudflare is our processor. It handles this data only to run BrainMatch for us, under the data-processing addendum named in "Who it's shared with". Like any company that hosts data for someone else, its systems and staff can technically reach what is stored on them. The few especially personal Rooms answers (money and security, family and roots, health and energy) are also stored encrypted with their own key, but the app needs that key to show them to you, so it is kept with the server's secret settings on Cloudflare too.
- A copy comes home. Every few hours an encrypted copy of the database and your photos is taken on Cloudflare, sealed with a public key so that Cloudflare cannot open it, and brought to BrainMatch's own computer, where it is checked, locked again with a key only the owner holds and kept (see "Backups" below). That way a billing problem or a locked account at a provider can cost us availability but never your data.
- Where it ran before: until the move to Cloudflare the server ran on BrainMatch's own computer. For up to 30 days after the move that computer keeps its old copy as a way back; then the old copy is wiped, and the computer keeps only the encrypted backups.
Security and backups
- Signing in: we store only a scrambled form (a hash) of each phone's sign-in, never the sign-in itself. A phone that hasn't used BrainMatch for 180 days is signed out and has to sign in again; phones in use are never affected. Signing in on a computer lasts up to 30 days.
- Limits on repeated tries use your internet address, held in memory only and forgotten within a day. The one exception is the lock after twenty wrong sign-in attempts in a row from one address: that is kept as a scrambled code in place of the address, with the time, for fifteen minutes at most, so a restart of our server can't lift the lock early.
- A security log records when the owner-only tools were used (pulling matching data, the sign-up list, the owner's dashboard), with a scrambled code in place of the internet address, and a few internal events. It holds no answers. One kind of entry, that we emailed you your own personality PDF, carries your random account id so the app can show it was sent. The log is built so that nobody, including us, can edit or delete an entry for 12 months; after that it's deleted automatically. Once your account is deleted, that random id links to nothing.
- Backups: the database and photos are copied every 6 hours into encrypted backups (AES-256), each kept for 35 days: first on Cloudflare in a private store, then brought to BrainMatch's own computer (and an encrypted copy in the owner's cloud drive), as set out in "Where your data is". If we ever restore one, accounts deleted since it was made are deleted again before it's used. Data removed by switching a permission off isn't yet re-applied automatically after a restore.
- Cloudflare's own history: besides our backups, Cloudflare keeps a change history of the database that lets us rewind it to any moment in the last 30 days. If you delete your account, what you deleted can therefore still sit in that history for up to 30 days, and in our encrypted backups for up to 35, after which it's gone. A list of accounts deleted is kept so that if we ever rewind or restore, you're deleted again before anything is used.
How long we keep things
- Your account and everything in it: until you delete it. We don't delete accounts for being inactive, so if you stop using BrainMatch, delete your account (or email us) to have it removed.
- Anything under a permission: until you switch that permission off or delete your account.
- Past chapters: until you delete your copy of a chapter, or your account.
- Sign-in codes: 15 minutes. Couple invite codes: 7 days, or until used.
- Heartbeats: until seen, or 30 days. Good nights: 30 days. Your next date: until the day after it. Ask-your-friends links: 7 days.
- Time zone offset: only while long-distance mode is on.
- Connections by code: until either of you ends it; a scan nothing was set up on, 14 days after both of you last touched it. Your own words from one that ended: until you turn Connecting by code off or delete your account. The "this connection has ended" line: until you tap it away.
- Introductions: a link, until someone says no thanks, it's closed, or 14 days after it was made; a room for three, until someone leaves or 14 days after anyone last touched it. The 'this introduction has closed' line: until you tap it away.
- Computer sign-ins: 30 days. Phone sign-ins: 180 days without use.
- Crash reports: 90 days. Beta and investor form entries: 12 months.
- Reports: until a person has dealt with it, then 12 months from when it was closed.
- Newsletter: an address never confirmed, 7 days; an unsubscribed one, 30 days; otherwise until you unsubscribe. Daily counts of link opens and sign-ups (nobody in them): 24 months.
- Backups: 35 days. The security log: 12 months (see above).
- Matching and research exports: you're left out of every export made after you turn "Help build matching" off or delete your account; a file made before stays as it was.
Risks
- Some questions about your relationship may feel personal. Every question can be skipped.
- As with any stored data, there's a risk of a breach. We limit it by collecting as little as possible: no names in matching data, no messages, no location, no contacts.
What we collect and what we don't
We collect: your birth year, whether you're single or in a couple, the month your relationship started, your email address, your questionnaire answers, your daily check-ins and state-of-us taps, anything you write in the app (including notes to your partner), and, if you turn them on, the photos you add to Moments, and your photo a day. In long-distance mode, your phone's time zone offset (not your location). And the small records described under "Things with no switch of their own", bug reports and suggestions you send, and crash reports.
Your email address is used for signing in, sending you your own PDFs, and replying if you contact us. If you turn on Follow-up, we may also email you about new features and occasional follow-up questions; turning it off stops that. It is never part of matching data, never shared, and never used for advertising. Signing in uses a six-digit code; there's no password to steal.
We never collect: your messages, contacts, location, microphone, or what you do in other apps, and no photos except the ones you choose to add to Moments or as your photo a day. We read nothing from Apple Health, Health Connect, a watch or any other health app or device: no sleep, no steps, no readings of any kind.
Who it's shared with
- We don't sell your data or share it with advertisers or data brokers.
- Service providers process data only on our instructions and only to run BrainMatch: Cloudflare (it runs our server and holds your data, in the United States: Workers run the app's code, a Durable Object holds the database, and R2 storage holds your photos and the encrypted backup files, as set out in "Where your data is"; it also provides the secure connection to our server and serves the pages of this website), Resend (email, like sign-in codes, and the copies of bug reports, crash alerts and form entries sent to us), Expo and Apple or Google (push notifications, if you turn them on; fixed words only), Expo's update service (the app checks it for updates, which shares your phone's internet address and app version with Expo), Apple or Google (app delivery), Google (Gmail, our inbox, where those copies arrive), and Anthropic (the Claude API: your own written answers, to write your nightly question and your spot insights; see "Megan, and how AI is used"). Each of them may use what passes through it only to provide its service to us, under its own data-processing terms, and we'll name the formal agreements here as they're signed. **With Cloudflare** that is its customer data-processing addendum (version 6.4), which its standard terms bring into our agreement and which includes the EU standard contractual clauses and the UK addendum for transfers out of the EU, the EEA and the UK. **Each of these providers is bound to protect your data at least as well as this policy does**: the same or equal protection this policy promises and the app stores require. Our server, your data and these providers are in the United States; if you're outside the US, your data is transferred there, with safeguards we'll name here as they're put in place (for Cloudflare, the clauses above).
- Anything reported outside BrainMatch is group-level only, never about an individual.
The owner-only research export
This is how "to match future couples well" happens today. Only the owner can make it, it's logged each time. It's made from the database on Cloudflare, downloaded by the owner and kept on BrainMatch's own computer: it isn't shared with anyone. It never includes test accounts, your email, anything you wrote, your Rooms answers, or your gender and the gender you're looking for. It has two parts:
- Your answers, under your random id, only if "Help build matching" is on: your birth year, whether you're single or in a couple, how you met (if you meet someone here), your questionnaire answers and your check-ins. Your couple link and when your relationship started are included only when both of you have it on, so nobody is ever joined to a partner who said no.
- Counts across everyone: how many people gave each answer, per question and per month. No ids, no days, and any group of fewer than 10 people is left out.
Turning "Help build matching" off, or deleting your account, leaves you out of every export made after that. An export made before isn't changed.
Help build matching: the trade-off
BrainMatch learns what makes a good match from couples who are already together. Your questionnaire and check-in answers, under a random id rather than your name or email, are the only way it can learn, and it's how the app stays free, with no ads.
- Where the law and the app stores allow it, this is part of using BrainMatch: the switch is on and can't be turned off; if you'd rather not, you can delete your account at any time. We tell you this before you join.
- Where consent must be freely given (the EU/EEA, the UK and Switzerland), it's a plain choice, off until you turn it on, and nothing else in the app depends on it.
- Everywhere else, until that's settled, it's on by default with the reason shown, and the join screen says so, and you can turn it off, there or later in Privacy. Turning it off stops your answers being used to build matching from then on: you're left out of every matching export made after that. Nothing is deleted, because the same answers are your own record; an export made before stays as it was.
Which of these applies is decided once, by the country your internet connection comes from when you join (we don't collect your location, and we keep only which of the three applies, not the country), and the app tells you which. It stays with your account: travelling or using a VPN later never changes it, and a later change to where it applies only affects people who join after. If the country can't be told, it's the plain choice, off until you turn it on.
Your choices
- Every kind of data is its own switch under Privacy. Turning one off stops collection and deletes what we already have of that kind, after the app has named what goes (a "no" to a switch that was already off deletes nothing more). Three switches store nothing of their own, so turning them off stops something and deletes nothing, and the app says so: the **Monthly Complementary Report (it stops for both of you), Help build matching** (you're left out of matching exports from then on) and Follow-up (we won't email you about new features or follow-up questions), and An AI reads your answers (nothing more of yours is sent; what the AI already wrote stays, and goes only with your account). One switch is part of using BrainMatch and can't be turned off on its own: Join BrainMatch; the way off it is deleting your account.
- Unlink from your partner (Privacy) ends the link between your two accounts. It ends it for both of you, straight away: everything that took the two of you (notes, thinking of you, the state of us, the Complementary Report, Moments and the shared list) stops for both. It deletes nothing either of you wrote: your check-ins, journal, questionnaires and photos stay with you, and theirs stay with them. **Each of you keeps your own copy of what you shared, and deleting your copy never deletes theirs** (see "If you unlink"). Your partner sees that the link has ended, and nothing else; nobody is told who unlinked. Either of you can link with someone new afterwards.
- Delete my account and data removes your account and everything in it at once, and the encrypted backups that still hold it age out within 35 days. Your partner's data stays unless they delete theirs too, including their own copy of what the two of you shared.
- Show everything you store about me shows your full record at any time: your email and whether it's confirmed, your couple link and relationship start, your settings, what you've written and tapped, nudges and appreciations, where you're signed in, and a list of your photos (each photo can be downloaded in the app, or email us for a copy of them all). It never includes anything your partner hasn't shared with you.
- You can also email zachary@brainmatch.app to have everything deleted.
Your rights
Wherever you live, you can:
- see everything we keep about you (Privacy → Export), and get it in a portable format;
- correct anything that's wrong: most things you can edit yourself, and for anything else, email us;
- delete any kind of data (turn its switch off) or everything (Delete my account);
- withdraw consent at any time, for any switch, without affecting anything done before;
- object to or ask us to restrict any use of your data, by emailing us.
We answer requests within one month. If you're in the EU, the UK or elsewhere with a data protection authority, you can also complain to it. We don't make decisions about you by automated means that have legal or similarly significant effects. The rights Washington, Nevada and Connecticut give you over health-related data (your mood check-in and the like) are the same ones listed above; brainmatch.app/health-privacy says what changed on 24 September 2026.
Contact: Turing Creative LLC, zachary@brainmatch.app. BrainMatch is not offered in the EU or the UK yet; before it is, our EU and UK representative will be named here. More help: brainmatch.app/support · Terms: brainmatch.app/terms.
Agreeing
By tapping Join BrainMatch, you confirm that you're 18 or older, have read this, and agree to BrainMatch using your data as described above. Join also asks you to tick that you agree to the Terms of Use and this privacy policy; we keep which version of the Terms you agreed to, and when, with your account (in your export). If the Terms change in a way that matters, the app asks you once before the change applies.
If you sign up as a beta tester
The form on the beta testers page collects your first name, email, whether you're single or in a relationship, your phone type, whether a partner would join, and anything you choose to tell us. Turing Creative LLC uses it only to invite you to the beta and to tell you when BrainMatch launches. It is kept apart from the app's data and never shared. Email zachary@brainmatch.app and we'll delete it.