Privacy policy
Last updated: August 2026
1. Who is responsible for your data
The controller of your personal data under the EU General Data Protection Regulation (GDPR) is:
- KMM Technologies
- Legal form: Sole proprietorship (eenmanszaak)
- Owner: Klaus M. Müller
- Prins Willem-Alexanderlaan 9207312 GD ApeldoornNetherlands
- Chamber of Commerce no.: 97917311
- VAT number: NL005295669B02
- Email: info@meetmomme.nl
We have not appointed a data protection officer. We do not carry out the kind of large-scale or systematic monitoring that makes one mandatory under Article 37. Send any privacy question to info@meetmomme.nl.
2. What we collect
- Account data — name, email address and, where available, a profile picture. Depending on how you sign in, these come from Google, Facebook (Meta) or Apple; alternatively you give only an email address, to which we send a one-time sign-in link.
- Profile data — first name, date of birth, town, postcode, the profile photos you upload, a short bio, information about children (age stage), mother phase, family situation and preferences. Your town and postcode are converted once into coordinates so we can work out the distance to other mothers. We do not use GPS and we do not track your location.
- Verification photo (optional)— if you choose the “verified” badge, you take a selfie holding a given gesture. Only our moderators see it, it is never shown on your profile, and it is deleted immediately after review.
- Usage — swipe decisions (interested / not now) and chat messages.
- Technical data — a cookie remembering that you have seen the cookie notice, a device token for push notifications (in the app only, and only if you allow them), IP addresses (briefly, for security and abuse prevention) and technical error reports (logs, without chat content).
- Subscription data — whether you have an active MomMe Circle subscription. We receive no payment details; Apple or Google handles payment.
3. Why we use it, and on what legal basis
- Running your account and connecting you with other mothers, including showing your profile to other users — necessary to perform our contract with you, Article 6(1)(b).
- Push notifications (a new match, a new message) — performance of the contract, Article 6(1)(b). Sending them also needs your device permission, which you can withdraw in your phone settings at any time.
- Occasional reminder emails when there is something new for you (an unanswered message, say) — our legitimate interest in a service that is actually useful, Article 6(1)(f). You can object at any time, in your profile or via the unsubscribe link in the email.
- Keeping the platform safe — screening uploaded photos for unacceptable content, rate limiting, abuse and fraud prevention — legitimate interest, Article 6(1)(f).
- Fixing and improving the service — legitimate interest, Article 6(1)(f).
We never sell your data and we do not use it for advertising. We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects within the meaning of Article 22.
4. Who processes data for us
- Google LLC — Sign-in via Google OAuth (US).
- Apple Inc. — Sign in with Apple (US). Apple may create a private relay address so your email is not shared. See apple.com/legal/privacy.
- Meta Platforms Ireland Ltd. — Sign-in via Facebook OAuth (Ireland/US).
- Self-managed mail server (Plesk / Postfix) — Sign-in, welcome and moderation emails. The server runs on VPS infrastructure from STRATO AG (Germany), which supplies only the underlying infrastructure.
- Neon Inc. — Database provider (US). All profile data, matches and messages are stored in the EU (Frankfurt).
- Vercel Inc. — Hosting for the web application (US).
- Cloudflare Inc. — Profile photo storage via Cloudflare R2 (US). Photos are stored in the EU and are not publicly accessible — only signed-in MomMe users can see them, through a secured, time-limited link.
- Bird B.V. (Pusher) — Real-time delivery of chat messages. Messages pass through Bird's servers but are not stored there.
- Vercel Inc. (Web Analytics) — Anonymous page views and performance. No cookies are set and no IP addresses are stored, so this involves no access to information stored on your device.
- Google LLC (Cloud Vision API) — Uploaded photos are checked once, automatically, for unacceptable content. Legitimate interest in platform safety, Article 6(1)(f). Google does not retain the images after processing.
- RevenueCat, Inc. — Manages the MomMe Circle subscription (US). Receives an encrypted user ID, your name and email, device identifiers and purchase events. Deleted along with your account. Payment details are not shared.
- Apple Inc. / Google LLC (payment) — Processes subscription payment through your App Store or Google Play account (US). MomMe receives no payment details; we see only whether your subscription is active.
- Functional Software, Inc. (Sentry) — Error monitoring (US). Receives technical details (error type, an internal user ID). Chat messages and profile content are not sent.
- 650 Industries, Inc. (Expo) — Delivery of push notifications and app updates (US).
- Upstash, Inc. — Caching and rate limiting. IP addresses and internal user IDs are processed briefly; no profiles or messages are stored.
- OpenStreetMap Foundation (Nominatim) — Converts town and postcode into coordinates (UK). Only the town and postcode are sent — no name, email or other account data.
We have, or are putting in place, a processing agreement with each of the above.
5. Sending data outside the EEA
Some of the providers above are in the United States. Where personal data leaves the European Economic Area, we rely on the European Commission's standard contractual clauses, Article 46(2)(c) GDPR. You can ask us for a copy of the safeguards that apply to any particular transfer.
6. How long we keep it
We keep your data for as long as you have an active account. If you delete your account, the following go immediately and permanently:
- your profile photos and any verification photo not yet reviewed (reviewed ones are already deleted straight after review);
- all profile data, matches and chat messages;
- your account, all linked sessions and push device tokens;
- your subscription record at RevenueCat.
Deleting your account is final and cannot be undone.
One exception: where we have deleted an account for breaking the terms of use, we keep a cryptographic hash of the email address to stop it being used to register again. The address itself cannot be recovered from it. Legitimate interest in platform safety, Article 6(1)(f).
7. Your rights
Under the GDPR you have the right to:
- access the data we hold about you (Article 15);
- rectification of data that is wrong (Article 16);
- erasure (Article 17) — you can delete your account and everything attached to it yourself, in the app (Profile → Delete account);
- restriction of processing (Article 18);
- portability — a copy of your data in a common format (Article 20);
- object to certain processing (Article 21 — see the separate notice below).
Write to info@meetmomme.nl. We reply within one month.
8. Your right to object (Article 21)
You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data that is based on our legitimate interests (Article 6(1)(f)). If you do, we will stop processing the data in question unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or the processing is for establishing, exercising or defending legal claims.
An email to info@meetmomme.nl is enough. You can also turn reminder emails off directly, in your profile or via the unsubscribe link in any such email.
9. Complaining to a regulator
You have the right to complain to a data protection authority.
MomMe is established in the Netherlands, so the Dutch Autoriteit Persoonsgegevens is our lead authority under the one-stop-shop (Article 56). You may always complain to the authority in the country where you live instead — in Ireland, the Data Protection Commission.
10. Cookies
MomMe sets one strictly necessary cookie:
- Notice cookie — remembers that you have seen the cookie notice (valid one year).
We set no tracking or advertising cookies. Because the cookie is strictly necessary to provide a service you have explicitly requested, it does not require consent under Article 5(3) of the ePrivacy Directive as implemented in the country where you live.
11. Security, and reporting a vulnerability
We keep MomMe technically secure: encrypted connections (HTTPS), private photo storage (not publicly reachable, signed-in users only) and passwordless sign-in via magic links or OAuth.
Found a security problem or a vulnerability? Please tell us directly at security@meetmomme.nl rather than sharing it publicly. We reply as fast as we can and are grateful for responsible disclosure. See also our security.txt.
12. Changes
We may update this policy. We will tell you about significant changes by email or a notice in the app.