iUniMatch
Home Profile Find Matches Messages Forum Saved
Login Register Continue as guest
Menu
Home Profile Find Matches Messages Forum Saved Login Register Continue as guest

Privacy

Privacy Policy

Last updated: 5 September 2026

iUniMatch is operated by an individual. The operator is the data controller. Contact support@iunimatch.com with any privacy question or request.

Information we collect

  • Account details such as name, username, email address, password hash, account type, and login information.
  • Profile and education details you provide, including country, graduation year, education system, subjects, grades, interests, university preferences, and profile image.
  • Content and interactions, including posts, comments, forum contributions, follows, likes, saved items, reports, uploaded images, and private messages.
  • Institution-verification and university-information requests.
  • Technical and security information such as IP-derived information, request times, browser information, session identifiers, and security events.
  • Registration-security results and limited browser or network signals processed by Cloudflare Turnstile to distinguish people from automated abuse.
  • Optional analytics described below, only after you accept analytics cookies.

Please do not submit sensitive information that is unnecessary for using the service. Passwords are stored as hashes, not plain text. iUniMatch does not request precise GPS location.

Why and how we use information

  • Providing the service (contract): creating accounts, authenticating users, displaying profiles and content, delivering messages, saving choices, and providing requested features.
  • Recommendations (contract): comparing information and preferences supplied by users with university and programme information.
  • Safety and operation (legitimate interests): moderating content, investigating reports, preventing fraud and abuse, securing accounts, debugging, and maintaining reliability.
  • Analytics (consent): measuring and improving the service only after optional analytics consent.
  • Compliance (legal obligation): meeting applicable legal duties and establishing, exercising, or defending legal claims.

Cookies and optional analytics

Essential first-party cookies keep users signed in, protect forms, maintain session security, and remember requested features. They are necessary for the service and are not used for advertising.

PostHog EU remains disabled unless you select “Accept analytics.” If accepted, it may collect page visits, navigation, clicks, form-submission events, performance, errors, approximate session length, heatmaps, privacy-masked session replay, device/browser details, and approximate location inferred from network information.

Analytics is configured to mask page text and all form inputs, remove URL query strings, avoid person profiles, and avoid intentionally collecting passwords, email addresses, private messages, uploaded files, form contents, or precise location. Rejecting analytics does not restrict the service. The preference cookie lasts up to six months. Use “Privacy choices” in the footer to withdraw or change your choice at any time.

Cloudflare Turnstile is used only on the account-registration form as a strictly necessary security measure. It processes the limited technical signals needed to detect automated abuse and does not receive the contents entered in the registration fields. It is not controlled by the optional analytics preference.

Cookie and browser-storage list

Name Provider and purpose Duration Consent
iunimatch_session iUniMatch — authentication, guest state, form protection, and security. Browser session for guests; up to 12 hours after the latest request for signed-in users. Not required; strictly necessary.
iunimatch_analytics_consent iUniMatch — remembers whether optional analytics was accepted or rejected. Up to 6 months. Not required; stores the user's privacy choice.
ph_iunimatch_analytics PostHog EU — maintains an anonymous analytics identity and session information for usage analytics and privacy-masked replay. Up to 6 months. Required before this cookie is created.
__cf_bm (conditional) Cloudflare — distinguishes legitimate traffic from automated traffic when Bot Fight Mode or bot protection is active. Expires after 30 minutes of inactivity. Not required; security cookie.
cf_clearance (conditional) Cloudflare — remembers that a visitor passed a security challenge. Normally 30 minutes; the configured challenge period may change this. Not required; security cookie.

After analytics consent, PostHog may also use browser session storage for temporary session state. If analytics consent is withdrawn, PostHog's analytics cookie is cleared and an opt-out choice may remain in browser local storage. Browser developer tools show the cookies and storage currently present on a particular device. Cloudflare may introduce other strictly necessary short-lived cookies only when a security or availability feature requiring them is triggered.

Who receives information

Information is available as needed to the operator, users with whom you choose to interact, and providers acting on iUniMatch's behalf. Current providers include Render (hosting), Cloudflare (DNS, security, and content delivery), Namecheap Private Email (email), and PostHog EU (consent-based analytics). Information may also be disclosed when legally required or necessary to protect users or legal rights. iUniMatch does not sell personal data.

International transfers

The application is hosted in the European Union and PostHog is configured for EU hosting. Global providers may process limited information outside the European Economic Area. Where required, transfers rely on an adequacy decision, standard contractual clauses, or another lawful safeguard. Contact us for more information about applicable safeguards.

How long we keep information

  • Account, profile, message, and content data is generally kept while the account or content remains active, then deleted or anonymised when no longer needed, subject to legal and security requirements.
  • Inactive guest accounts are automatically deleted after 30 days.
  • Expired registration and administrator-verification challenges are automatically deleted after they expire. Old rate-limit records are deleted after 30 days.
  • Security audit records are automatically deleted after 365 days.
  • Completed or rejected privacy requests are kept for three years to document their handling, then automatically deleted. Their contact details and request text are removed immediately if the related account is deleted.
  • Closed moderation cases, appeals, and protected evidence are kept for three years to document safety and legal decisions, then automatically deleted unless preservation is legally required.
  • Pending requests and moderation records are kept while needed to review and document their outcome.
  • Optional analytics follows the configured PostHog project retention period and is deleted or aggregated when no longer needed.
  • The analytics-consent preference remains on the device for up to six months unless changed or deleted sooner.

Your rights

Under the GDPR and other applicable data-protection laws, you may have rights to access, correct, erase, or obtain a copy of your data; restrict or object to processing; and withdraw consent without affecting earlier lawful processing. Applicable national law may provide additional rights.

Signed-in users can download a machine-readable JSON copy or permanently delete their account from the privacy-request page after confirming their password. To exercise another right or request help, email support@iunimatch.com from the address associated with the account. Reasonable proof of identity may be requested. You may lodge a complaint with the data-protection supervisory authority that is competent under applicable law. The European Data Protection Board's authority list can help you find the relevant authority in the European Economic Area.

If you are signed in, you can also submit and track a privacy request directly through iUniMatch.

Matching and recommendations

iUniMatch may automatically compare academic information and preferences you provide with university or programme information. Suggestions are informational, not admission decisions, and do not produce legal or similarly significant effects. Universities make their own decisions.

Age requirement

iUniMatch is for people aged 16 or older. If we learn that personal data was collected from someone under 16, we will take reasonable steps to delete it. Contact us if you believe this has occurred.

Security and policy changes

We use reasonable technical and organisational safeguards, but no online service can guarantee absolute security. This policy may be updated when the service or legal requirements change. Material changes will be shown through a new “Last updated” date and, when appropriate, another notice.

Privacy Terms Report illegal content Moderation transparency Contact support