Table of Contents
- Introduction & Privacy Philosophy
- What Data We Collect — And What We Don't
- How We Use Your Data
- Our Infrastructure & Privacy Guarantees
- Payment Processing
- Data Security & Protection
- Data Retention Periods
- Your Data Rights (GDPR/FADP)
- Children's Privacy
- Changes to This Policy
- Contact Information
1. Introduction & Privacy Philosophy
At MATE, privacy is not just a feature; it is our architecture. We operate on the principle of data minimization: we do not store your data or build profiles, we do not track your behavior, and we do not sell your information.
Our core mission is to provide powerful AI capabilities while ensuring that your most sensitive data remains under your direct control. To achieve this, we use a strict data separation model:
| Concept | What It Means for You |
|---|---|
| Identity vs. Content | Your account identity (email) is completely separated from your prompts and outputs. We have no technical ability to link who you are to what you say. |
| Local Storage | Your content is stored on your device only. We do not store or save your conversation history on our servers. |
| No Behavioral Tracking | We do not track individual user behavior, usage patterns, or build profiles of your interests. |
| Swiss Jurisdiction | All MATE Cloud data is processed under the Swiss Federal Act on Data Protection (FADP). |
| Offline Privacy | You can run local LLM models (On-device Mode) directly on your device for complete offline privacy. |
2. What Data We Collect — And What We Don't
2.1 Personal Information You Provide Directly
When you create an account through Sign in with Apple, Google, or email/password via web browser:
| Data Type | Purpose | Linked to User Content? |
|---|---|---|
| Email address (Apple, Google, or user-provided) | Account authentication and subscription billing only | NO — completely separate system from prompts/outputs |
| Encrypted password (email/password sign-in only) | Secure login verification | NO — never linked to prompts/outputs |
2.2 Data Collected Through Apple In-App Purchase (iOS app Only)
When you subscribe through Apple's In-App Purchase system within the MATE iOS app, we receive:
| Data Type | Purpose | Linked to User Content? |
|---|---|---|
| Apple ID email address | Account linking & subscription verification | NO — not connected to prompts/outputs |
| Subscription status (active/expired) | Feature access management | NO — separate from prompts/outputs |
| Transaction identifiers | Billing records (via Apple) | NO — payment data processed independently by Apple/Stripe |
2.3 Data Collected Through Google Play In-App Purchase (Android app Only)
When you subscribe through Google Play's In-App Purchase system within the MATE Android app, we receive:
| Data Type | Purpose | Linked to User Content? |
|---|---|---|
| Google Account email address | Account linking & subscription verification | NO — not connected to prompts/outputs |
| Subscription status (active/expired) | Feature access management | NO — separate from prompts/outputs |
| Transaction identifiers | Billing records (via Google) | NO — payment data processed independently by Google/Stripe |
2.4 Technical & Usage Data (Minimal Collection)
We collect minimal technical data necessary for app functionality — and we do NOT track individual users:
| Data Type | Purpose | Tracked Per User? |
|---|---|---|
| Device type and OS version | App compatibility checks | NO — only platform-level metrics, no user profiling |
| Error logs & crash reports | Bug fixing & stability | NO — anonymized aggregate data only |
2.5 What We Do NOT Collect or Share
We DO NOT collect, store, or share the following:
- Your AI prompts, conversation history, or search queries linked to your account (stored separately from authentication)
- Payment card details (Apple/Stripe process this independently; we never see them)
- Data used for advertising, tracking across apps, or selling to data brokers
- Individual user behavior analytics — only platform-level metrics without any personal linkage
- Third-party SDKs that track individual users (we use no such tools)
2.6 Our Anonymity-by-Design Architecture
The Core Privacy Guarantee: MATE is architecturally designed so that user authentication and user content systems are completely separate. This means:
- When you authenticate to access the app, we have NO technical ability to link your identity to your prompts or outputs
- We cannot identify which user generated which content — this is intentional by design for maximum privacy protection
This architecture ensures: Even if compelled by legal process, we simply do not possess the technical ability to link your account identity to your conversation history or search queries.
3. How We Use Your Data
We process your data for the following purposes:
| Purpose | Legal Basis (GDPR/FADP) | Notes |
|---|---|---|
| Account creation & authentication | Contractual necessity | Required to provide service you requested — billing/subscription management only |
| Subscription management & billing | Contractual necessity | Syncs subscription status for feature access |
| App functionality & feature delivery | Contractual necessity | Enables chat, search, image generation features |
| Security monitoring & abuse prevention | Legitimate interest | Platform-level metrics only; NOT individual user profiling or behavioral tracking |
We Do NOT Use Your Data For:
- Marketing communications (unless you explicitly opt-in separately)
- Selling or sharing with advertising partners
- Training external AI models on user content
- Profiling, automated decision-making beyond service delivery
- Cross-device tracking across apps or websites
- Individual user behavior analytics — we do not track which user did what
4. Our Infrastructure & Privacy Guarantees
4.1 Self-Hosted AI Models (Not Third-Party APIs)
Unlike many competitors that rely on third-party AI providers, MATE runs AI processing on fully self-managed infrastructure:
| Component | Implementation |
|---|---|
| Model Hosting | Our own Swiss datacenters with dedicated GPU resources for text and image generation computation |
| Models Used | Open-source models modified by our team (not Google Gemini, OpenAI GPT, Meta AI or xAI) |
| Data Processing Location | 100% within Swiss jurisdiction for hosted inference mode |
| Local Inference Option | Apple MLX runtime on your iOS/macOS device and Google AI Edge LiteRT-LM on your Android device for complete offline privacy |
| Third-Party Access | None – no external AI API calls for user content processing |
4.2 Private Search Engine
MATE routes web search through its own search system, operated by our team:
| Feature | Privacy Guarantee |
|---|---|
| Search services never learn who is asking | External search services may be queried for web results. The request carries neither your account nor your identity. |
| No dependence on any single provider | The search services we use can change at any time. Your privacy stays the same: no tracking, no profiling. |
| Search queries anonymous by design | No search query can be linked to your identity. Not by us, and not by any search service. |
4.3 Data Sovereignty Commitment
All stored user data remains under Swiss jurisdiction:
| Aspect | Our Guarantee |
|---|---|
| Physical server location | Switzerland (our dedicated datacenters for backend/GPU/computation) |
| Legal framework | Swiss Federal Act on Data Protection (FADP) + EU GDPR for EU customers |
4.4 Client-Side & Local Data Storage
To ensure maximum privacy, the following data is stored locally on your device only (iOS, macOS, or Android). Swisswise GmbH does not access, collect, or transmit this information to our servers:
- Conversation History: Your chats and AI memory files.
- Generated Media: Images or resources you have downloaded.
- App or Website Preferences: UI settings, such as language, theme, and layout.
- Local Models: Any LLM models downloaded for offline use.
Note: You can clear this data at any time by clearing your app data or cache.
5. Payment Processing
5.1 Apple In-App Purchase (iOS and macOS app)
| Requirement | Details |
|---|---|
| Required for: | All subscriptions purchased within the MATE iOS app |
| Location of processing: | Apple Inc. servers (global, with EU data residency options available) |
| Payment data handling: | Apple processes all payment information; we never see card details |
| Subscription management: | Via device settings: Settings > [Your Name] > Subscriptions on iOS devices |
For iOS users, ALL paid subscriptions must go through Apple's billing system per App Store Review Guidelines Section 3.1.1. We do not offer Stripe as an in-app payment option for digital goods within the iOS application.
5.2 Google Play Billing (Android app)
| Requirement | Details |
|---|---|
| Required for: | All subscriptions purchased within the MATE Android app |
| Location of processing: | Google LLC servers (global, with regional data center options) |
| Payment data handling: | Google processes all payment information; we never see card details |
| Subscription management: | Via Google Play Store app: Profile Icon > Payments & subscriptions > Subscriptions |
For Android users, ALL paid subscriptions must go through Google Play's billing system to comply with Google Play Developer Program policies regarding digital goods and services.
5.3 Web-Based Stripe Payments (Browser Only)
| Requirement | Details |
|---|---|
| Allowed for: | Users who sign up via email on our website or browser-based portal only |
| Location of processing: | Stripe Inc. servers (global, with regional data centers) |
| Payment data handling: | Stripe tokenizes payment info; we never store card numbers |
| Subscription management: | Via Stripe dashboard or customer support |
Important Distinction: Stripe is ONLY available when accessing MATE through a web browser (not within the iOS, macOS or Android app). This complies with Apple's and Google's policy that external payments are only permitted for content/services delivered outside the App Store ecosystem.
5.4 Which Method Applies to You?
| Your Access Method | Payment System Required |
|---|---|
| MATE iOS and macOS app (iPhone/iPad and Mac) | Apple In-App Purchase ONLY |
| MATE Android app | Google Play Billing ONLY |
| MATE Website or Web Browser Sign-in | Stripe OR sign-in with Apple/Google (user's choice) |
6. Data Security & Protection
MATE employs a multi-layered security strategy combining industry-standard technical safeguards with rigorous operational controls.
6.1 Technical Safeguards
- Data in Transit: All network communications are protected via high-grade encryption (HTTPS/TLS).
- Data at Rest: Stored personal information is secured using advanced AES-level encryption standards.
- Credential Security: Passwords are never stored in plain text; we utilize industry-leading hashing and salting protocols.
- API Integrity: All programmatic access is managed through secure, token-based authentication frameworks.
6.2 Infrastructure & Network Security
Swiss infrastructure with the following protections:
- Physical Security: Strict data center controls, including biometric entry and 24/7 surveillance.
- Network Segmentation: Isolation of authentication systems from content storage to minimize attack surfaces.
- Proactive Defense: Regular vulnerability assessments and penetration testing to identify and remediate risks.
- System Integrity: Continuous monitoring of backend models and upstream service health.
6.3 Access Controls & Governance
- Least-Privilege Access: User data access is strictly limited to authorized personnel required for specific operational tasks.
- Administrative MFA: Multi-factor authentication is mandatory for all production infrastructure access.
- Security Auditing: Comprehensive logging of system access events; logs are used for security monitoring and do not include individual behavioral tracking.
- Compliance Oversight: Periodic internal and external security reviews to ensure alignment with industry best practices.
7. Data Retention Periods
We retain your personal data only as long as necessary for the purposes outlined in this policy:
| Data Type | Retention Period | Linked to Content? |
|---|---|---|
| Account credentials & email | Duration of account + 6 months after closure | NO — completely separate from prompts/outputs |
| Subscription records (transaction IDs) | 3 years for tax/legal compliance in Switzerland | NO — not linked to prompts/outputs |
Account Deletion Process
Upon account deletion request:
- All authentication data is removed within 30 days
- Anonymized platform-level statistics may be retained indefinitely for aggregate metrics only
- Subscription records anonymized after 3 years (tax compliance)
- You will receive confirmation email upon completion of deletion process
Important: Because authentication and content systems are architecturally separate, deleting your account does NOT erase content stored on your device. Deleting the app will delete your content on device.
8. Your Data Rights (GDPR/FADP)
If you are located in Switzerland or the European Economic Area, you have the following rights under Swiss FADP and EU GDPR:
| Right | How to Exercise It | Response Time |
|---|---|---|
| Access – Request a copy of all data we hold about you | Use the contact form on swissmate.ai/contact | 30 days |
| Correction – Update inaccurate or incomplete information | Via app settings or use the contact form on swissmate.ai/contact | 15-30 days |
| Deletion ("Right to be Forgotten") – Remove your account and data | Delete account in app (Settings > Delete Account) or contact form deletion request | 30 days from confirmation |
| Portability – Receive your data in machine-readable format | Use the contact form on swissmate.ai/contact; we provide subscription data we hold | 30 days |
| Objection – Object to processing for legitimate interest purposes | Use the contact form on swissmate.ai/contact stating grounds; we review and respond within 30 days | 30 days |
| Withdraw Consent – Revoke previously granted consent at any time | By deleting account and deleting the app | Immediate effect |
9. Children's Privacy
MATE is designed for users aged 16 years and older in accordance with Swiss FADP and EU GDPR requirements:
- We do not knowingly collect data from children under 16
- Users who indicate they are under 16 during sign-up will be denied access to the App
- If we discover a user account belongs to someone under 16, we will delete their authentication data promptly upon discovery (within 30 days)
If you believe your child has created an account without parental consent, please contact us immediately by using the contact form swissmate.ai/contact. We will investigate and take appropriate action.
10. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in law, technology, or business practices (e.g., new SDK integrations, infrastructure upgrades). When we make material changes:
- We will post the updated policy on our website with a new "Last Updated" date
- We will notify users via email (if contact information is available) and/or in-app notification for significant changes
- Continued use of MATE after the effective date constitutes acceptance of revised terms
We encourage you to review this policy regularly to stay informed about how we protect your data.
11. Contact Information
For questions, concerns, or to exercise your data rights:
| Method | Details |
|---|---|
| Website Contact Form | swissmate.ai/contact |
| Legal Address | Swisswise GmbH Weltpoststrasse 8b CH-3015 Bern |
| Data Protection Officer (DPO) – GDPR-specific concerns | swissmate.ai/contact |
App Store Privacy Nutrition Labels (Apple App Only)
When submitting MATE to the App Store, we complete Apple's privacy labels disclosing data categories collected. These appear on your App Store listing under App Privacy. You can view these labels in App Store Connect under your app listing.
Data Categories Declared:
| Category | Linked to User? | Used for Tracking? | Purpose |
|---|---|---|---|
| Contact Info (email address) | Yes | No | Account authentication & subscription billing only — NOT linked to content |
| Identifiers (Apple ID when applicable) | Yes | No | Subscription verification & account linking — NOT connected to prompts/outputs |
| Usage Data (platform-level metrics, error logs) | No (aggregate only) | No | Service improvement; no individual user tracking |
| Device Information (device type, OS version) | No | No | App compatibility checks — platform level only |
| Payment Info (via Apple IAP only; not stored by us directly) | No (Apple stores this) | No | Billing records via subscription sync endpoint — NOT linked to content systems |
Privacy Manifest File: We include PrivacyInfo.xcprivacy in our app bundle declaring required API usage reasons per Apple's Spring 2024 requirements. Third-party SDKs used have their own privacy manifests bundled with the app. We do not use any third-party SDKs that track individual user behavior.
By using MATE, you acknowledge that you have read, understood, and agree to this Privacy Policy.
