Privacy Policy
Last updated: August 29, 2026
1. Information We Collect
When you create an account, we collect your email address and any profile information you choose to provide. When you use Matteca, we collect the data you voluntarily log including tracker entries, goals, journal notes, and finance entries.
We also collect basic usage data such as login timestamps, device type, and browser type to improve the service. We do not collect data from your device beyond what you explicitly enter into Matteca.
You can submit a feature request without an account. When you do, we store the text you type and a random identifier saved in your browser (used only to stop the same browser starring a request more than once). We do not link a feature request to your name, email address, or IP address.
2. How We Use Your Information
Your information is used to:
- Provide and maintain the Matteca service
- Calculate your daily scores, streaks, and analytics
- Process your subscription payments through our payment provider
- Send you important service-related communications
- Improve and develop new features
3. Third-Party Integrations
If you connect third-party work tools (Jira, Asana, or Notion), we access only your work activity: task completions, status changes, and time logged. These integrations are read-only. We do not access your files, messages, or any data beyond work activity events.
You can disconnect any integration at any time, and we will delete the associated access tokens and synced events.
4. Data Storage and Security
Your data is stored securely on Supabase (powered by PostgreSQL) with row-level security policies ensuring you can only access your own data. All data is transmitted over HTTPS. We do not sell, rent, or share your personal data with third parties for marketing purposes.
5. Payments
When you buy a subscription, your payment is processed by Paddle.com Market Limited ("Paddle"), which acts as the Merchant of Record and authorised reseller for the purchase. Paddle collects and processes the information needed to complete and manage your transaction, such as your name, email address, billing address, and payment details. Paddle handles this data as an independent controller under its own privacy notice.
Matteca does not store your full payment card details. We receive only limited transaction data from Paddle (such as your subscription status and the email used) so we can manage your account access. See our Refund Policy for how refunds are handled.
6. Data Retention and Deletion
Your data is retained as long as your account is active. You can delete your account and all associated data yourself at any time, from Settings in the web app or the Profile tab in the iOS app. Deletion is immediate and permanent: your login, every tracker entry, and every uploaded image are removed, and there is no undo and no backup to restore from. If you cannot reach the app, email support@matteca.com and we will process the request within 30 days.
7. Cookies and Analytics
We use essential cookies for authentication and session management. These are always active because the service cannot function without them.
We also use PostHog (PostHog Inc.), a third-party product analytics processor, to help us understand how Matteca is used and to fix bugs. Data sent to PostHog is processed and stored in the United States. Through PostHog we may collect:
- Usage and interaction events (pages visited, buttons clicked, features used)
- Device and browser information, and an approximate location derived from your IP address
- Session recordings (a visual replay of how you interact with the app), captured for a sample of sessions. Everything you type into a form field is masked automatically. On top of that, sensitive figures shown on screen - weight, calorie/macro numbers, food log details, finance amounts (income, spend, recurring income), and sleep times/hours - are blacked out, along with free-text personal areas such as your journal/notepad entries and profile details (name, email). None of this is ever legible on the replay
- Error, crash, and diagnostic reports, used to identify and fix bugs
This analytics tracking uses cookies and local storage and only runs if you accept it in our cookie consent banner. You can decline it there, and you can change your choice at any time by clearing your site data and revisiting the banner. We do not sell this data, and it is retained only as long as needed for the purposes described above. A small number of internal team accounts are excluded from this tracking entirely.
Our landing page displays a Product Hunt launch badge. The badge image is loaded directly from Product Hunt (api.producthunt.com, operated by Product Hunt Inc. in the United States), so every visit to the landing page makes a request to their servers before you have made any cookie choice. That request carries your IP address, your browser's user agent, and the address of the page you are on. We do not receive that information, and we do not use the badge to identify or track you; Product Hunt handles it under its own privacy policy. The badge sets no cookie on our site. The same is true of the web font the landing page loads from Google Fonts (fonts.googleapis.com): it is a request to Google that carries your IP address, user agent and referring page, and nothing more.
If you star a feature request, we save a random identifier in your browser's local storage so your stars are remembered on that device. It is anonymous and is not linked to your identity.
If a save fails — usually because you went offline — we keep what you typed in your browser's storage so you don't lose it, and we keep the change itself so we can send it when you're back online. Both stay on your device, are never sent to us except as the save you were already making, and are cleared as soon as the save succeeds or you discard it. We don't keep passwords, card details, or anything you type into a payment field this way.
8. Bug Reports
If you report a bug, using the bug icon in the top bar, the link on onboarding, or the right-click menu, we receive your description plus diagnostic context: your device and browser, the page you were viewing, the time, and the last few error messages the app logged. A screenshot is included only if you add one yourself, and you choose the area it captures. If you have accepted analytics cookies, the report may also include a link to your PostHog session recording so we can see exactly what happened. This information is used only to investigate and fix the bug you reported, is visible only to the Matteca team, and is retained only as long as needed to resolve it.
9. AI Access (connecting your own AI)
Matteca lets you connect your own AI account - such as Claude or ChatGPT - so that AI can read and change your Matteca data on your behalf. This is entirely optional and is off unless you set it up yourself.
If you connect an AI, your Matteca data is sent to that AI provider. When your AI reads or changes something in Matteca, the data involved leaves our systems and is transmitted to the company that operates that AI (for example Anthropic for Claude, or OpenAI for ChatGPT). Once it reaches them, it is governed by their privacy policy and terms, not ours. We do not control how they use, store, train on, or retain it. You should read the privacy policy of any AI you connect before connecting it.
You choose how much access to give. You can grant read-only access, or allow the AI to make changes, and you can narrow that to specific areas of the app. Some things are never available to a connected AI, regardless of what you allow: your password, your email address, your subscription and billing, deleting your account, submitting bug reports or feedback, connecting or disconnecting other apps, and uploading files.
To let you see and undo what your AI does, we keep an activity log for 30 days. Each entry records which connection acted, what it did, and a copy of the affected data as it was immediately beforehand so the change can be reversed. That copy can include the same personal information as the record it relates to - for example food, weight, sleep, finance or journal entries. It is stored with the same protections as the rest of your data, is visible only to you, and is deleted automatically after 30 days.
You can revoke any connected AI at any time from Settings, which immediately ends its access. Revoking does not retrieve data that was already sent to that AI provider.
10. AI Memory
If you connect an AI, it can save notes about you so it remembers useful context next time - your goals, your habits, what you are working toward, or anything else it judges worth keeping. This is what we call AI Memory. It is off unless you turn it on, and you can turn it off at any time.
What gets saved is decided by the AI, not by us. It records what it thinks is relevant, which can include personal details you mentioned in conversation rather than only things you tracked in Matteca. You can see everything that has been saved, edit any of it, and delete individual notes or all of them, from Settings. Memories are kept until you delete them - they do not expire on their own.
Memories are shared between every AI you connect. A note saved by one AI can be read by another you connect later. They are also sent to whichever AI reads them, which means they leave our systems and reach that provider, exactly as described in section 9.
Memories are encrypted at rest, so a stolen copy of our database would not reveal them. Nothing in Matteca shows your memories to us, and we do not read them. To be straightforward with you about the limit of that: because Matteca has to decrypt a memory in order to hand it to your AI, this is not a system where it would be technically impossible for us to access them. We are telling you what we do and do not do, not claiming a guarantee we cannot make.
Separately, if you use Matteca's own built-in AI assistant (currently switched off and not available), it can summarise your saved memories into a short profile to give itself context. Producing that summary sends the memories to OpenRouter, which routes them to a third-party model provider (DeepSeek by default). This only happens if you have turned AI Memory on, are on a paid plan, and use the built-in assistant. It does not happen when you connect your own AI through AI Access.
11. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes by posting a notice on the service. Continued use of Matteca after changes constitutes acceptance of the updated policy.
12. Contact
Matteca is operated by Muhammad Ali Raza, a sole proprietor. If you have questions about this privacy policy, contact us at support@matteca.com.