Legal
Privacy Policy
- Effective date:
- 30 July 2026
- Last updated:
- 14 August 2026
You retain ownership and control of the information you store in Matricula. This policy explains how the operator of Matricula identified in our Legal Notice (“Matricula”, “we”, “us”, or “our”) collects, uses, stores, and protects personal data when you visit our website or use the Matricula service.
1. Introduction
This Privacy Policy describes how Matricula handles personal data when you:
- Visit matricula.io
- Use the Matricula mobile or web application
- Create or manage a Matricula account
- Contact Matricula for support or feedback
Matricula is a family information and asset-management service that helps households organise people, assets, documents, obligations, and related context in one place. In this policy, “Matricula”, “we”, “us”, and “our” refer to the service provider / operator identified in our Legal Notice, which is the data controller for personal data processed to operate the Matricula service, except where another party is independently a controller (for example, a payment provider for payment data it processes as Merchant of Record).
If you do not agree with this policy, please do not use the service.
2. Core privacy principles
These principles guide how Matricula handles personal data:
- Information you enter into Matricula remains your information.
- Matricula does not sell personal data.
- Matricula does not rent personal data.
- Matricula does not share personal data with advertisers or data brokers.
- Matricula does not use private family information for targeted advertising.
- User content is processed only to provide, secure, maintain, support, and improve the service, or when legally required.
- Matricula personnel do not routinely inspect private user content.
Access to private user content is restricted. Administrative access may occur only when reasonably necessary to provide support requested by the user, investigate security or reliability issues, maintain the service, prevent abuse, or comply with applicable law.
Infrastructure and service providers may process limited data on Matricula’s behalf under appropriate contractual and confidentiality obligations, solely to operate the service.
3. Information you provide
Depending on how you use Matricula, you may provide categories of information such as:
- Account information, including email address and authentication identifiers from your chosen sign-in provider, and any name or profile details associated with that provider account.
- Family and household information, such as family or workspace names and membership roles.
- Information about people, including family members and dependants (for example display names, dates of birth, photo references, and related notes).
- Information about vehicles, pets, properties, assets, documents, obligations, activities, and important locationsthat you choose to record.
- Uploaded references, photographs, notes, and document references. Matricula is designed primarily to store meaning, metadata, and references to external files rather than to host complete copies of your documents.
- Support requests and correspondence, including feedback you submit through the product.
- Subscription and billing status, such as plan tier, trial state, and entitlement information needed to operate your account.
Payments for applicable paid plans are processed by Paddle as Merchant of Record / payment provider. Matricula normally does not receive complete payment-card details. We receive subscription and billing status information needed to manage access to the service. Paddle’s processing of payment data for those transactions does not make Paddle the operator of Matricula or the controller of all Matricula account or family data.
4. Information collected automatically
When you use Matricula or visit our website, we may automatically collect limited technical and operational data, including:
- IP address
- Browser and device information
- Operating-system and application version
- Login, request, diagnostic, security, and operational logs needed to run and protect the service
- Approximate location inferred from IP address (for example for security, rate limiting, or infrastructure routing)
- Cookie or local-storage information required for authentication sessions and essential site or app functionality
Essential operational data is collected to authenticate users, deliver the service, diagnose errors, and protect Matricula and its users.
Optional analytics on the marketing website: the public marketing site at matricula.io may use privacy-oriented web analytics (currently Vercel Analytics in production) to understand aggregate traffic and page performance. This is distinct from advertising trackers. The Matricula product applications do not currently integrate third-party product-analytics or crash-reporting SDKs for marketing purposes.
5. Authentication providers
Matricula uses Supabase Authentication with the following sign-in options:
- Sign in with Google
- Sign in with Apple
- Email and password
When you sign in, Matricula receives basic account information from the authentication provider, such as a stable user identifier and email address, and may receive related profile attributes the provider makes available. Matricula does not receive your Google or Apple password. For email sign-in, your password is handled by Supabase Auth — Matricula does not store passwords on its own servers.
Google and Apple process information under their own privacy policies. Supabase processes authentication data (including email confirmation and password reset messages) as our identity provider under its own terms and privacy practices.
6. How information is used
We use personal data to:
- Create and operate accounts
- Store, organise, search, and display the information you choose to keep in Matricula
- Synchronise information between supported devices
- Provide reminders, notifications, search, maps, document access, and other requested features
- Power optional AI assistance features by sending filtered, permission-scoped context needed to answer your questions or propose actions for your confirmation
- Authenticate users and prevent unauthorised access
- Provide support and respond to feedback
- Diagnose errors and improve reliability
- Protect Matricula and its users from fraud, abuse, and security threats
- Comply with legal obligations
- Process subscriptions and payments through our payment provider, where applicable
Matricula does not use private family content for third-party advertising or for selling audience profiles.
7. Legal bases under GDPR
If you are in the European Economic Area, the United Kingdom, or another jurisdiction that requires a legal basis for processing, we rely on the following bases where applicable:
- Performance of a contract — when processing is necessary to provide the Matricula service you request, including account creation, content storage, synchronisation, reminders, and subscription management.
- Legitimate interests — for security, fraud prevention, service reliability, support, abuse prevention, limited product improvement, and privacy-oriented marketing-site analytics that help us understand aggregate traffic, where those interests are not overridden by your rights and freedoms.
- Consent — for optional marketing communications if offered in the future, and for device permissions such as push notifications where the operating system or applicable law requires consent. You may withdraw consent where processing relies on consent, without affecting the lawfulness of processing before withdrawal. Browser and device settings also let you control many optional permissions.
- Compliance with legal obligations — when we must retain or disclose information to meet applicable law.
- Protection of vital interests — only in rare circumstances where processing is necessary to protect someone’s life or safety.
8. User content and ownership
- You retain ownership of the information and files you submit to Matricula.
- You grant Matricula only the limited rights technically necessary to host, process, transmit, display, back up, and otherwise operate the service.
- Matricula does not claim ownership of your user content.
- Matricula does not sell user content.
- Matricula does not use private user content to train public or third-party artificial-intelligence models unless you have been separately informed and have provided any consent required by law.
When you use Matricula’s AI assistance features, relevant questions and filtered account context may be sent to our AI service provider (currently Anthropic) so the feature can generate responses or proposals. Access controls still apply: the assistant is intended to receive only context you are authorised to see, and proposed changes require your confirmation before they are applied. Medical file bodies and similar raw file payloads are not designed to be sent to the AI provider; Matricula typically works with metadata and references.
9. Information about other people and children
Because Matricula may contain information about family members and children:
- Account holders must have the legal right or appropriate authority to add information about another person.
- Parents or legal guardians are responsible for information entered about minors.
- Matricula is intended for adults managing household information. It is not intended for children to create independent Matricula accounts.
- Users should avoid entering information that is unnecessary for the intended purpose.
11. International data transfers
Application data is primarily hosted in the European Union. In particular, Matricula’s managed database is operated in the EU, and the application programming interface is hosted in Western Europe.
Some service providers may process information outside the European Economic Area, including providers based in the United States or that operate globally (for example authentication, AI, payments, email, push notifications, maps, analytics, and content delivery). Where required, Matricula relies on legally recognised safeguards such as adequacy decisions or Standard Contractual Clauses.
We do not claim that all data remains exclusively in the EU in every processing scenario, because certain features necessarily involve subprocessors outside the EEA.
12. Data retention
- Account and user content is retained while the account remains active.
- You can request deletion of your account and related content as described below.
- Backups and operational recovery systems may retain deleted data for a limited recovery period.
- Certain security, billing, transactional, or legal records may be retained where reasonably necessary.
- Data is deleted or anonymised when it is no longer required for the purposes described in this policy.
Day-to-day records may be tombstoned or hard-deleted depending on the operation. Account deletion hard-deletes the login after Sign in with Apple token revocation (when stored) and authentication-provider user deletion. Last-administrator Family deletion removes the live Family dataset after explicit confirmation. Exact backup retention windows depend on our hosting providers’ operational practices.
13. Account and data deletion
You may:
- Access and correct much of your information directly in the Matricula application.
- Delete individual records you control within the product, subject to family sharing and role permissions.
- Delete your account from Settings → Delete Account on Web, iOS, and Android. The product first shows the impact for each Family you administer.
Delete Account has three outcomes:
- Account only — when another Family Administrator or Owner remains. Your login, devices, assistant threads owned by that login, and login email are removed. The shared Family graph remains for remaining administrators. Medical records are family-scoped owner-only rows; the product default is to keep them while the Family remains (they become inaccessible after unlink). This is pending legal review of special-category data.
- Transfer required — when you are the last Family Administrator but an eligible Contributor login exists. The account is not deleted until you transfer administration (Make Admin).
- Account and Family — when you are the last Family Administrator and no eligible Contributor successor exists. After explicit confirmation the Family becomes immediately inaccessible and the live dataset is permanently removed shortly afterwards. Paddle billing is cancelled when a provider subscription exists.
Delete Account is not a full GDPR Article 17 erasure of every mention of you inside a still-administered Family. For erasure or anonymisation of data concerning you that remains in a shared Family, email [email protected]. Fulfilment may require balancing remaining family users’ rights (including minors in the graph).
Documents in Matricula are references, not hosted files. We do not delete third-party storage you control. Sign in with Apple users may also stop using Matricula with their Apple ID in Apple ID settings if a legacy login predates stored refresh-token revocation.
Deleted data is removed from live systems promptly. Backup copies of the production database expire according to the hosting provider’s backup rotation for the subscribed plan (Supabase backups). Restored backups are not used to re-create a deleted Family in production except for documented disaster recovery, after which purge would be re-applied. We do not retain deleted Family datasets indefinitely.
Operational exceptions (duration subject to counsel): security logs, deletion audit rows (proposed 12 months), billing webhook idempotency records, Paddle’s own records, and data needed for legal claims.
A dedicated public data-export or privacy-choices page may be added in the future. Until then, please email us to request access, correction, export assistance, or deletion that you cannot complete in the product.
14. GDPR and other privacy rights
Depending on your jurisdiction and circumstances, you may have rights to:
- Access personal data we hold about you
- Correct inaccurate personal data
- Request deletion
- Restrict certain processing
- Object to certain processing
- Receive a portable copy of data you provided
- Withdraw consent where processing relies on consent
- Lodge a complaint with your relevant data-protection authority
These rights are not absolute. Legal exceptions may apply, and we may need to verify your identity before fulfilling a request. We will respond within the timeframes required by applicable law.
Delete Account in Settings is not the same as a GDPR Article 17 erasure request. Use the contact address below to request erasure or anonymisation of data concerning you that remains in a Family still administered by others. Fulfilment may require balancing remaining family users’ rights.
15. Security
Matricula uses reasonable technical and organisational safeguards appropriate to the nature of the data, including:
- Encryption in transit via HTTPS for production services
- Access controls and authenticated API access using signed tokens
- Managed database hosting with encryption at rest as provided by our database provider
- Device-side secure storage for session tokens on supported mobile platforms
- Backups and operational recovery practices of our hosts
No method of transmission or storage is completely secure. We work to protect your information, but we cannot guarantee absolute security.
17. Notifications and device permissions
Matricula may request device permissions only for corresponding features. Currently, this includes:
- Push notifications — to deliver reminders and related alerts when you enable them. On Android, notification permission may be requested after sign-in. You can change this in operating-system settings or disable reminder preferences in the product where available.
Denying optional permissions limits only the related functionality. Matricula does not currently require camera, photo-library, or contacts access for core use.
18. Third-party links and integrations
Matricula may link to or open external services, such as map applications, payment checkout pages hosted by Paddle, authentication provider pages, or document locations referenced by URLs you store. Once you leave Matricula, those services are governed by their own privacy practices. This policy does not control how third parties handle information they collect.
19. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page.
For material changes, we will provide reasonable notice through the website, the application, email, or another appropriate channel.
20. Contact
If you have questions about this Privacy Policy, or if you wish to exercise privacy rights, request support with account or data deletion, or ask about how Matricula handles personal data, contact us at:
The Matricula service provider / data controller is identified in our Legal Notice. Please include enough detail for us to identify your account and request. We may ask for additional information to verify your identity before acting on privacy requests.
Prefer product details over legal text? See the privacy overview on the home page. Also read our Terms of Service and Legal Notice.