Match Up

Legal

Privacy Policy

Match Up is a training app, not an advertising business. This policy explains exactly what the app collects, why it needs it, where it lives, and how to get it back or delete it.

Last updated · August 4, 2026

The short version

  • Match Up collects the account you sign up with, the tennis profile you fill in, and the training you log. Nothing else about you.
  • There are no ads, no advertising identifiers, and no third-party marketing or analytics trackers.
  • Your data is never sold, rented or shared for marketing.
  • Data is stored in a Supabase (PostgreSQL) database in the United States, protected by row-level security so your account can only ever read and write its own rows.
  • You can ask for a copy of your data, or have it permanently deleted, by emailing jonathanmahrtguyou@gmail.com.

01

Who this policy covers

This policy applies to the Match Up iOS app (currently distributed as a TestFlight beta) and this website. The app is built and operated by Jonathan Mahrt Guyou, the sole developer and the data controller for the information described here.

You can reach the developer at any time at jonathanmahrtguyou@gmail.com.

02

What the app collects

Everything below is information you enter yourself in the app, with the single exception of crash diagnostics. Match Up does not read your location, contacts, photos, calendar, microphone, HealthKit data, or any wearable or fitness tracker.

Account information

Your email address and a password, handled by Supabase Auth. The password is stored only as a salted cryptographic hash — it is never visible to the developer and cannot be recovered, only reset. An account is required to use the app, so that your training history is private to you and backed up.

Your tennis profile

The details you choose to enter on your profile: name (whatever you type — it does not have to be your legal name), height, weight, playing level, playing style, dominant hand, and your current training phase (for example pre-season or in-season). All of these are optional and can be edited or cleared at any time in the app.

Logged workout data

The training you record: which workout and program week, sets, reps and load — weight in pounds, height or distance in inches, time in seconds, resistance-band colour, or bodyweight — plus the exercises performed and the start and completion timestamps of each session. This is the core of the app: it is what produces your personal records, training volume, consistency and streaks.

Daily energy check-ins

A 1–5 energy rating and the date you gave it. This is combined with your recent training load to calculate your readiness score. It is a self-reported number, not a health measurement, and it is never shared with anyone.

Tournaments and streaks

Tournaments you add — name, date and duration — which the app uses to build periodization phases around your competition. Also your current and longest weekly streak and which weeks you used a streak freeze.

Crash and error diagnostics

If the app crashes or hits an error, a diagnostic report is sent to Sentry so the bug can be fixed. These reports contain technical information — the error and its stack trace, device model, operating system version and app version — together with a small sample of performance traces. Match Up does not attach your account identity, email or training data to these reports.

03

What the app does not collect

  • No advertising, no advertising identifiers (IDFA), and no ad networks.
  • No third-party marketing, attribution or behavioural analytics trackers.
  • No location data, contacts, photos, calendars or microphone access.
  • No HealthKit, Apple Watch, WHOOP or other wearable or health platform data.
  • No payment or financial information — the beta does not take payments.
  • Your data is never sold, rented, or shared with data brokers, and it is not used to train machine-learning models.

04

Why each piece of data is collected

  • Account information — to authenticate you, keep your training history attached to you and no one else, and let you sign in on a new device.
  • Tennis profile — to personalise the app and give context to your training. It is not used for any purpose outside the app.
  • Workout logs — to run the program, show your progress, personal records, training volume and consistency, and to advance you through the four-week block.
  • Energy check-ins — to calculate your readiness score alongside your recent training load.
  • Tournaments — to place Peak, Taper, Competition and Recovery phases around your competition dates.
  • Crash diagnostics — solely to find and fix bugs and keep the app stable.

The legal basis for processing this data is the performance of a contract — you asked the app to deliver and track your training, and it cannot do that without this information — and, for crash diagnostics, a legitimate interest in keeping the app working.

05

Where your data is stored

Your account and training data are stored in a Supabase project — a managed PostgreSQL database — hosted in the United States. Match Up's data lives in its own dedicated database schema.

  • Row-level security is enforced at the database level. Every row is bound to the account that created it, so one account can never read or modify another account's data.
  • Data is encrypted in transit over HTTPS/TLS and encrypted at rest by Supabase.
  • Passwords are stored only as salted hashes by Supabase Auth and are never accessible to the developer.
  • A copy of your current training data is also cached on your own device so the app works offline. That local copy is erased when you sign out.

If you are in the European Economic Area or the United Kingdom, be aware that using the app means your data is transferred to and processed in the United States.

06

Service providers

Match Up uses a small number of third parties to operate. They process data only to provide their service, and none of them are permitted to use it for their own marketing.

  • Supabase — database and authentication. Stores your account, profile, workout logs, energy check-ins, tournaments and streaks. United States.
  • Sentry — crash and error diagnostics. Receives technical error reports only. United States.
  • Apple — distributes the beta through TestFlight. Apple receives the email address you use for TestFlight and standard install and crash information under Apple's own privacy policy.
  • Vercel — hosts this website. Standard server request logs only; the website sets no tracking cookies and has no analytics.

One note on external links: the “watch demo” button next to an exercise opens a YouTube search for that exercise name in your browser. Nothing about your account or your training is sent with it, but once you leave the app you are on YouTube's service and Google's privacy policy applies.

07

How long data is kept

  • Your account, profile and training history are kept for as long as your account exists — training history is only useful if it is long-running.
  • When you request deletion, your account and all associated data are permanently deleted within 30 days.
  • Crash diagnostics in Sentry are retained on Sentry's standard retention schedule (approximately 90 days) and then discarded automatically.
  • The offline cache on your device is deleted as soon as you sign out, and when you delete the app.

08

Your rights and how to use them

Whatever jurisdiction you are in, the following are available to you on request. Depending on where you live — for example under the GDPR in Europe or the CCPA in California — some of these may also be legal rights.

  • Access — ask for a copy of everything stored about you.
  • Portability — receive that copy in a machine-readable format.
  • Correction — most of your data (profile, tournaments, logged sets) can be edited directly in the app; for anything else, email and it will be corrected.
  • Deletion — have your account and all associated data permanently erased.
  • Objection and restriction — ask that processing be limited, or object to it.

To exercise any of these, email jonathanmahrtguyou@gmail.com from the address on your account. Requests are answered within 30 days, free of charge. There is no requirement to give a reason, and using these rights will never degrade your access to the app.

09

Security

Access to your data is protected by authenticated sessions and database row-level security, all traffic runs over TLS, and passwords are salted and hashed by Supabase Auth. Access to the production database is limited to the developer.

No system is perfectly secure, and no honest policy will claim otherwise. If you believe your account has been compromised, or you have found a security issue in the app, please email jonathanmahrtguyou@gmail.com and it will be treated as a priority.

10

Children

Match Up is not directed at children under 13, and information is not knowingly collected from them. If you are under the age of digital consent where you live, please use the app only with a parent or guardian's permission. If you believe a child has provided information through the app, email jonathanmahrtguyou@gmail.com and the account will be deleted.

11

Changes to this policy

If this policy changes in a way that materially affects how your data is handled, the updated policy will be posted on this page with a new “last updated” date, and beta testers will be notified by email before the change takes effect. This version was last updated on August 4, 2026.

12

Contact

Questions, requests or complaints about privacy go to the same place as everything else: jonathanmahrtguyou@gmail.com. It is a one-person project, so the reply will come from the person who wrote the code.

For help using the app, see the support page.