Privacy Contract

Mythic Match is built around fictional creature personas, not real-world identity.

Last updated / July 10, 2026

Not requested as dedicated fields

The profile model does not ask for real name, email, phone, address, real photos, social login, date of birth, exact location, contacts, browser fingerprint, advertising ID, or analytics ID. Free-text fields can still contain identifying details, so keep them out of lore, labels, reports, and screenshots.

What the app stores

The app stores Creature ID, recovery hash, persona fields, lore, generated avatar URLs/history, draft generation records, symbolic reactions, matches, cards/reactions, blocks, reports, and moderation states. Pass phrases are shown once and only their server-side hash is stored.

Custom input handling

Custom realm, archetype, affinity, intent, boundary, and related labels are saved in separate moderation tables. They are not mixed into the official deterministic taxonomy unless the operator deliberately promotes them in a future code or data update.

AI and storage providers

When configured, Gemini processes profile inputs for moderation, lore, translation, avatar generation, and image quality checks. Supabase stores PostgreSQL app records and generated avatar objects. Raw provider payloads, raw avatar prompts, and provider debug responses are not intentionally persisted in profile records.

Communication limits

Direct match interaction is limited to symbolic reactions and preset cards. There is no unrestricted private text chat in the beta, which reduces pressure to share real identity, contact details, or sexual content.

Production handling

Production has no analytics or ad-tech trackers and does not log request bodies or private debug payloads. Short-retention Apache logs include a client address, time, method, path without query, status, and bytes; rate-limit keys are HMAC-derived rather than stored as raw addresses. Server errors are sanitized before reaching the browser.

Retention

Profiles remain until the user hides or deletes them. Reports are retained for moderation and abuse-trend review for up to 18 months unless a concrete safety or legal reason requires longer. Referenced avatar history is retained; newly unreferenced managed avatars enter guarded asynchronous cleanup. Backups expire on the documented schedule.

Profile controls

Recovered profiles can export app records, edit persona fields, manage avatar history, and hide from active surfaces after verification. Explicit hard deletion removes the profile and associated app records; unreferenced managed avatars are deleted asynchronously, and backups age out under the retention schedule. Never put pass phrases or real identity/contact details into feedback, reports, labels, lore, or screenshots.