Privacy Policy
Last updated: 7 October 2026
1. Data Controller
Victoria von Schmettow
Gabelsbergerstraße 9, 80333 München, Germany
Email: hey@1found1.com
2. Scope
This policy explains what personal data we process when you use the 1found1 app and website (the "Service"), why, on what legal basis, who we share it with, and your rights.
3. What data we process
- Account data: your email address (via Google, LinkedIn or email sign-up) and an account identifier. If you sign in with Google or LinkedIn, the provider also sends us your name and the link to your profile picture there. We use both only to pre-fill your profile during onboarding: the picture is copied once into our storage, stays hidden until a match like any profile photo, and you can change or remove your name and photo at any time. If you sign up with email, your password is stored only in encrypted (hashed) form by our auth provider.
- Profile data: first and last name, photo(s), location, study background, work background and work stations (up to four companies or places with how long), industries, associations, strengths/weaknesses, answers to profile questions, time commitment, and any LinkedIn or GitHub link. Work background and work stations are visible on your card before a match, like your study background.
- CV (optional): if you upload one, your CV as a PDF or Word file, with its file name and the time of upload. It is kept in private storage and is visible only to you and to the people you have matched with, once you have both messaged each other and your profiles are revealed to each other. Those people can open and download the file. In an event pool the same applies only if that pool uses the CV, and only once your profiles are revealed under that pool's rule. It never appears in the swipe deck, before a match, or to investors or recruiters.
- Usage data: swipes, matches, chat messages including replies to individual messages and emoji reactions, and reports you make.
- Event-space data: if you join an event pool (space), your pool profile (pre-filled from your 1found1 profile with the details that pool uses, editable for that pool), your answers to the pool's questions and extra fields, whether you asked to join, and your activity scoped to that pool (swipes, matches, messages).
- Matchmaker data: if you are or become a matchmaker: your email address, first and last name, your organisation, who invited you (1found1 or a colleague), status and pool allowance, the pools you create (name, date, place, type, rules, questions, picture), and a note if you request access yourself. If a colleague invites you, we receive your email address from that person.
- Verification: if you verify a university or initiative email address, we send a one-time code to it and store the address, its domain, a hash of the code (never the code itself) and the time of verification. We also use the domain of your sign-in email to check whether you belong to a partner initiative, which places you in the exclusive pool. Opening a partner initiative’s access link does the same. Other users see that you are verified, but never your address or its domain.
- Notification data: your push-notification consent status, (if you opt in) your push subscription, and your settings for which kinds of notifications you want to receive.
- Technical data: IP address and server log data generated automatically on access.
- Anonymous usage statistics: aggregated, anonymous measurement of active usage time (duration only, with no link to your identity) to improve the Service.
- Product analytics (only with consent): if you accept the analytics banner, we collect pseudonymous usage events (pages visited, clicks, screen interactions) under a random identifier, with no link to your name or email address. We use this data solely to improve the product.
- Investor and recruiter enquiries: if you submit the form on the investor or recruiter page: name, email address, whether you act privately or for a firm (and its name, if given), the industries you picked, the credit plan you selected, and whether you pressed continue on the checkout step. We collect no payment data there. The details reach us by email.
4. Purposes and legal bases
- Providing the Service (profile, matching, chat): performance of contract, Art. 6(1)(b) GDPR.
- Making your profile visible to other users in your matching pool or event space: your consent, Art. 6(1)(a) GDPR.
- Service & waitlist emails (e.g. sign-up confirmation and the notification once matching is opened for you): performance of contract / legitimate interests, Art. 6(1)(b) and (f) GDPR.
- When you join an event pool created on or after 7 October 2026: creating your 1found1 profile, showing it in the main pool and adding the details you enter when joining to that profile: performance of the contract you enter by creating your profile, Art. 6(1)(b) GDPR.
- Push notifications: your consent, Art. 6(1)(a) GDPR.
- Matchmaker accounts and running event pools (switching the account on, setup, pool allowance, join requests, welcome and invite emails): performance of contract, Art. 6(1)(b) GDPR. We send the email to an invited colleague on the basis of our legitimate interest and the inviting organisation's legitimate interest in adding its matchmakers, Art. 6(1)(f) GDPR; the invite stays valid until revoked and only takes effect if the invited person signs up themselves.
- Showing a distance ("12 km away") instead of your location before a match: performance of contract, Art. 6(1)(b) GDPR. The distance is calculated only from the cities in the profiles, not from your device's location; we collect no GPS data.
- Verification and placing you in the exclusive pool of our partner initiatives (one-time code, email-domain check, access link): performance of contract, Art. 6(1)(b) GDPR, as this is how we provide the pools and the badge you ask for. Unconfirmed codes expire after 10 minutes; the verified address is kept while your account exists.
- Storing your CV and showing it to your matches: your consent, Art. 6(1)(a) GDPR, which you give by uploading the file. If your CV contains special categories of personal data (for example about health or religion), that is your choice, and processing that information is based on your explicit consent, Art. 9(2)(a) GDPR. You can withdraw consent at any time by removing the CV from your profile.
- Security, abuse prevention, rate-limiting: legitimate interests, Art. 6(1)(f) GDPR.
- Anonymous usage statistics (active usage time): legitimate interests, Art. 6(1)(f) GDPR. Collected anonymously and in aggregate, with no profiling and no additional cookies.
- Product analytics (PostHog): your consent, Art. 6(1)(a) GDPR and section 25(1) of the German TDDDG. Without your acceptance in the analytics banner no collection takes place; you can withdraw consent at any time (see section 8).
- Making your profile visible to investors and recruiters: solely your separate, explicit consent, Art. 6(1)(a) GDPR. It is off by default, is given separately for investors and for recruiters, and is not covered by your consent to pool visibility (see section 5).
- Revealing your name and contact details to an individual investor or recruiter: your consent in that individual case, given by accepting that specific intro request, Art. 6(1)(a) GDPR.
- Handling investor and recruiter enquiries: steps taken at your request before entering into a contract, Art. 6(1)(b) GDPR.
5. Profile visibility
1found1 organises matching into pools. Your profile is only shown to other users in the same pool as you, and you only see users in that pool. Members of a curated community are, by default, in a community-only pool (the "exclusive pool"), where visibility is limited to fellow members of that community; other users are in the open pool (the "public pool"), which is visible to all approved users. Where you have the choice, you can switch pools in your settings. In every case, your photo and full name stay hidden until you and another user mutually match. This visibility is based on your consent (Art. 6(1)(a) GDPR); you can change your pool where available, withdraw consent, pause your profile, or delete it at any time.
You only appear in the founders’ pools if you choose to: with the "Enter the main pool" button or by finishing founder onboarding. One exception: if we removed you from the main pool, our team can let you back in; members of an event space are never added without their own choice. Joining an event space created before 7 October 2026, or opening an invite or initiative link, never adds you to them (for newer event pools see the next paragraph). An initiative link (or a partner initiative’s email domain) only decides that you belong to the exclusive pool once you choose to enter.
For event pools created on or after 7 October 2026, joining creates or uses your 1found1 profile and makes it visible in the main 1found1 pool as well (in the exclusive or the public pool, as described above). Details you enter while joining such a pool are also stored in your 1found1 profile where it does not have them yet. Your name and profile photo are the same there and in these event pools. Legal basis: performance of the contract you enter by creating your profile, Art. 6(1)(b) GDPR. You can pause your profile in the main pool at any time in the settings, or delete your account.
If you have not opened 1found1 for two months, we pause your profile automatically and tell you by email; one tap makes you visible again. Your matches, chats and account stay as they are.
Event pools (spaces) are separate, sealed pools. When you join an event pool, your pool profile is pre-filled from your 1found1 profile with only the details that pool uses; you can change it for that pool. Your swipes, matches and messages there are visible only to members of that pool and stay separate from the main pools and from every other pool. What other members see before a match is set by the pool: in anonymous pools they see an astronaut and an alias instead of your name and photo until your profiles are revealed under the pool's rule (at the match, after a set number of messages from each person, or on the day of the event); in open pools they see your name, photo and links from the start. If you leave or are removed from a pool, that visibility ends.
A pool's matchmakers or organisers see who has joined (first name and alias). In pools that approve each request to join, they also see the first and last name and alias of the people asking to join, so they can decide. Public pools are shown to every signed-in account under "Spaces" (name, date, place, picture and number of members, never the members themselves). Matchmakers of an organisation see the names and email addresses of the other matchmakers of that organisation.
Investors and recruiters
Investors and recruiters are not users in a pool. They see nothing of you unless you explicitly switch it on. Your consent to pool visibility does not cover this, because it only applies to other founders looking for co-founders. Visibility to investors and visibility to recruiters are two separate switches, both off by default. If you switch one on, the respective recipients see a version of your profile without name, photo, contact details and links. If you switch it off again, you are no longer shown to them from that moment on.
To be honest about it: in legal terms this version is pseudonymous, not anonymous, and that is exactly why we ask for your consent first. We remove name, photo, contact details and links. What you wrote yourself stays. If your answers, your initiatives or your idea describe you recognisably, someone who knows the scene may still guess who you are. Investors and recruiters are contractually forbidden from trying (see Terms, section 5), but we cannot rule it out technically.
Your name and contact details are only revealed to an investor or recruiter when you accept a specific intro request from that person. Before you decide, you see who is asking and what it is about. If you decline or do not respond, that person learns nothing about your identity. From the moment of the reveal, the recipient is responsible in their own right for how they handle your data (a separate controller within the meaning of the GDPR).
Investors and recruiters pay 1found1 for intro credits, that is, for the chance to send you a request. We do not sell, rent or export profile data or contact lists.
6. Where your data is stored
All personal data is securely stored with our infrastructure provider Supabase. The servers and databases used are physically located in Frankfurt, Germany (AWS eu-central-1 region). Your core personal data is therefore hosted within the European Union.
7. Other processors
- Vercel, hosting, delivery & cookieless, aggregated analytics (Vercel Web Analytics, no cookies, no personal profiling).
- Google, authentication (OAuth).
- LinkedIn Ireland Unlimited Company: authentication (OAuth), only if you sign in with LinkedIn.
- Resend: sending emails, including the welcome and invite emails for matchmakers.
- Upstash, abuse protection (rate-limiting).
- Cloudflare (Turnstile): bot protection for the forms that can be reached without an account (signup, login, password reset, contact, feedback, investor and recruiter enquiries). When you open one of these forms, Cloudflare checks that a human is submitting it and processes technical data such as your IP address and browser characteristics to do so. No advertising cookies, no cross-site tracking. The legal basis is our legitimate interest in preventing spam and abuse (Art. 6(1)(f) GDPR).
- Cal.com: scheduling calls with investors and recruiters. Only if you click "Book a call" after submitting the form does the Cal.com booking page open; your name and email address are passed along to prefill it. The booking itself takes place at Cal.com under their privacy terms.
- Push-services (Google, Mozilla, Apple), only if you enable notifications.
- PostHog Inc. (only with your consent): product and session analytics to improve the product. Processing in the USA, safeguarded by appropriate measures (EU Standard Contractual Clauses). In session recordings everything you type and all personal content is masked, in particular chat messages, profile content and names. No advertising use, no sale of data.
Your core data (profiles, answers, messages, CVs) stays in the EU with Supabase. Where a provider used for authentication, email or hosting processes limited data outside the EU/EEA, such transfers are safeguarded by appropriate measures (e.g., EU Standard Contractual Clauses).
8. Cookies and local storage
Cookies are small text files that your browser stores on your device when you visit a website. Cookies cannot run programs or transfer viruses to your device; they only allow the party that set the cookie to recognise your device on a later visit, for example so that you stay signed in between visits.
Without your consent we use only technically necessary cookies (sign-in/session, section 25(2) of the German TDDDG). No tracking or advertising cookies.
If you open a partner initiative’s link, we store its code on your device (local storage in the browser, app storage in the app) and, if you sign up with email, also in your account data, until it has been applied to your account. This is strictly necessary for the link to keep working through sign-up and onboarding (section 25(2) no. 2 of the German TDDDG).
Only if you accept the analytics banner does PostHog store a random identifier in your browser (cookie/local storage) to recognise returning visits pseudonymously. The legal basis for this storage and the associated analytics is your consent (Art. 6(1)(a) GDPR, section 25(1) of the German TDDDG). If you decline, nothing of the sort is stored and no analytics are collected. You can withdraw consent at any time with effect for the future by clearing this browser's site data or by contacting us.
Independently of this, you can restrict or prevent the setting of cookies in your browser settings at any time, for example by blocking only third-party cookies or all cookies, and you can delete cookies that have already been set. If you block all cookies, some functions of this website (such as staying signed in) may no longer be usable.
9. Data security and data breaches
We implement robust, industry-standard administrative, technical, and physical security measures, including encryption (in transit and at rest) and database-level Row Level Security (RLS), to protect your data against unauthorized access, alteration, disclosure, or destruction.
Protection against scraping: so that nobody can copy other members’ profiles in bulk, we log which account loaded which profile cards in the deck and how often, and we limit how many new cards an account can load without deciding on them. We use this data only to detect and stop automated access, and we delete the per-card entries after 30 days and the daily counters after 90 days. The legal basis is our legitimate interest, and our members’, in protecting their profiles (Art. 6(1)(f) GDPR).
However, no system is 100% secure or impenetrable, and we cannot guarantee absolute security. In the unlikely event of a data breach that is likely to result in a risk to your rights and freedoms, Victoria von Schmettow will act strictly in accordance with the GDPR (Art. 33, 34): we will contain and mitigate the breach without delay, investigate its cause, and notify the competent supervisory authority and affected users without undue delay (and, where required, within 72 hours of becoming aware of it).
10. Retention and deletion
We keep your data as long as your account exists. You can delete your profile and account at any time ("Delete profile"); your data is then erased unless statutory retention obligations require otherwise. Your CV is deleted as soon as you remove it from your profile or delete your account.
We keep investor and recruiter enquiries for as long as we are handling them and delete them no later than 12 months after the last contact, unless a contract is concluded. You can ask us to delete them earlier at any time.
11. Your rights
You have the right to access, rectification, erasure, restriction, data portability, and objection. You may withdraw any consent at any time with effect for the future. You also have the right to lodge a complaint with a data-protection supervisory authority.
12. Minimum age
The Service is not intended for persons under 18, and we do not knowingly process their data.
13. Changes
We may update this policy to reflect changes to the Service or legal requirements. The current version is always available in the app.
14. Contact
Questions about this policy or your data: hey@1found1.com