YOUR INFORMATION, EXPLAINED
Privacy & retention
InterestMatch helps people find friends through shared hobbies and activities. This page explains the information used by the app and the choices available to you.
Updated 22 September 2026 · اقرأ بالعربية
What you share with members
Signed-in members can see your display name, bio, hobbies, languages, group preferences, organization or community, posts and photos. Your residence country and approximate city appear in profiles and location searches only if you enable sharing. Birthplace is separate, optional and appears only when both people consent and share the same country. It never affects match ranking.
Country and city suggestions are searched on this server using a local copy of GeoNames data, licensed under CC BY 4.0. The data has been filtered and compacted and may be incomplete. You can enter a city yourself. The picker does not request your device location or send your search to a geocoding provider.
In Discover activities, Use my location requests your browser's permission only when tapped. Coordinates are rounded to three decimal places before being sent to this server to sort venues by approximate straight-line distance. They are not saved to your profile or database. Choose a country or city to browse without device location. Opening Map loads visible map tiles from OpenStreetMap, which receives your IP address, this site's origin and the map area requested. Only locations explicitly set for published businesses become venue pins; city centers are approximate reference points.
Activity titles, hobbies, dates, UAE times and approximate areas are visible to eligible signed-in members. Exact meeting notes are sent only to the organizer and accepted members. Blocking, account suspension and content moderation can further restrict visibility.
Activity invitation links
Anyone holding an activity invitation link can see its organiser's display name and public plan details. Guest names are unverified, and only the organiser sees names and replies. Private meeting details require the organiser's approval and are shown only to that approved guest. A group-sourced invitation does not reveal the private group's members, conversations or calendar. Do not put a home address in the public place field.
Your browser stores a random guest key for this invitation in the current session so you can change or clear your answer. Clearing erases your name and choice; an anonymous version record remains until the plan is removed. Closing the session or using another device can lose access to your answer. Replacing or revoking the invitation link ends access through the old link, but cannot recall details already seen. No guest contact information, account or download is required.
Dated links close at the end of the chosen UAE day; undated links close after 30 days. Plans and replies are removed within 30 days after closure by scheduled cleanup, which may be delayed while this PC is off. Deleting the organiser's account removes their invitations and replies. Account exports omit other guests' names and all invitation secrets. Private backups follow the retention described below. There are no email or push reminders; keep the link to check changes.
Public posts: your choice
New posts made through this website default to Public. You can choose Members only before publishing. Existing posts keep their chosen audience. Choose Public when posting, or use Edit or Audience on your own post, to let anyone see your display name, caption, hobby, photo and like count without an account. Your profile details and email are not included. Public posts can be viewed by people who are signed out, including someone you blocked. Switching back to Members only stops further guest access, but cannot recall copies someone already saved or shared.
What stays private
Gender is optional and self-declared, not verified. If you provide it, signed-in members can see it and use it in people/post-author searches. Every post starts with Everyone as its gender audience. Women-only or men-only posts require a signed-in viewer with the matching profile selection; the author can always see their own post. These restrictions cover the post and photo, including shared photo URLs. Guests cannot see restricted posts. Audience controls cannot recall copies someone already saved.
Place-group chat is visible to eligible members who join, including people who join later. Leaving ends your group access but does not delete earlier messages. You can delete your own messages. Blocking and moderation restrict what each member can see.
Appearing in a place’s people list is optional and starts off for existing memberships and every new join or rejoin. If you opt in, eligible current and later group members can see your name and hobbies there and open the parts of your member profile they are already allowed to view. Hiding, leaving, account deletion, suspension or group archiving removes you from subsequent directory results. Blocks hide the two accounts from each other. Hiding or leaving does not erase earlier chat or its authorship; account deletion follows the rules below. Previously viewed or saved copies cannot be recalled.
Group counts describe membership, not people physically at the venue. InterestMatch does not request GPS, track presence or calculate nearby distances. Opening a venue’s Maps link sends Google Maps a search using public venue details, without private profile information or meeting notes.
Feedback, bug reports, suggestions and the operator's replies are visible only to the author and the operator. The form sends the text and category you choose, not automatic screenshots or copies of your private conversations. Place suggestions are reviewed by the operator; approved place information becomes visible to signed-in members.
Your email, account export, password credentials, sessions and recovery codes are not part of another member's public profile. Reports and contact requests go to the community operator, not to other members. A report against you is not included in your account export.
Matching uses profile interests, shared approximate area, organization, languages and group preferences. It does not use birthplace, nationality, religion, private messages or moderation records. A score is an explanation of shared fields, not a compatibility probability or identity check.
Direct messages
Private text messages are available between accepted connections. Removing a connection, blocking or suspension prevents further access until the relationship is eligible again. These conversations are stored on the operator’s PC and are not end-to-end encrypted. Routine moderation does not include access to your whole conversation: if you report a message, that selected message and your report details are copied into the operator’s report inbox.
You can delete your own message text; the conversation retains a “Message deleted” marker and identifiers to prevent a retry from restoring it. A previously submitted report may retain its selected-message evidence. Deleting either participant’s account removes their shared live conversation and its message reports. Your account export includes your own sent messages, not copies of the other person’s messages. Backups follow the retention rules below.
Where information is stored
When enabled, Message the creator lets visitors chat privately with the selected creator account without registering. A separate private browser cookie provides access for up to 30 days from creation; clearing it removes access to that chat. Messages expire after 30 days. Delete this chat removes its live messages; anti-spam records with hashed network/browser identifiers and delivery IDs remain for up to 24 hours. This chat is stored on the operator's PC, is not end-to-end encrypted, and follows the backup policy below. A guest chat is tied to this browser rather than a member account.
The community operator stores application data and private backups on their PC. The operator can access data to run and moderate the community. Meeting notes are protected by access controls; they are not encrypted from the operator. Use the public HTTPS address when it is available to protect information in transit.
The app does not require a paid matching or photo-processing service. Public HTTPS may pass through the configured tunnel provider. When configured, Google, Discord or GitHub can appear as optional sign-in choices. If you choose one, that provider handles authentication. The app uses your provider account identifier, verified email and a suggested display name to create or link your account. Your account email and linked sign-in details stay private. Provider access and refresh tokens are not saved in the community database or sent to your browser. These sign-in methods do not verify your age or real-world identity.
Photos and browser storage
New post photos are limited to 256 KiB and 1,200 pixels per side, with one photo per post. Members may upload five post photos in a rolling 24 hours and keep up to 20 post photos or 5 MiB. Text posts remain available when a photo allowance is full. Video and animated uploads are unavailable; the browser can convert a selected animated PNG or WebP into a still photo. Existing photos are preserved.
The supplied browser uploader compresses photos and removes original image metadata before sending them. Direct post-photo API uploads are checked for format and size but may retain metadata. Avoid posting private information, including precise home locations, documents or someone else's contact details.
A private session cookie keeps you signed in. The app stores only your language preference in browser local storage. Form drafts remain in the current page until discarded, closed or replaced; they are not saved as an offline account copy. No private content is stored in an offline service worker cache.
To reopen an activity, group or plan, or preview an invitation after provider sign-in, this tab may temporarily store its identifiers, target view or invitation code, the provider and a 15-minute expiry. No messages, plan text, ledger, answers or account details are stored. The app clears this when you return or cancel. Joining and attendance still require separate choices.
Team picker keeps the names you enter or select and its results in this tab's memory. Selecting friends or a group loads names you already have permission to see; adding them to the picker does not invite or notify them. It does not upload them or save them across a reload. Copy results only when you want to keep or share them. Adding a joined activity to your calendar creates a file containing its activity name, public meeting location and schedule; it does not read your calendar. A downloaded copy does not update automatically, and deleting or changing the activity cannot remove copies you kept elsewhere.
Access, export and deletion
Use Profile to edit your information and sharing choices. Account & recovery lets you download your data, generate ten single-use recovery codes, or permanently delete your account after confirming authentication.
Your own profile shows your sign-in email only to you. Change password requires your current password. For an account without a password, sign in with a linked provider within the last five minutes before adding one. A successful change signs out other sessions and invalidates old recovery codes; generate and save a fresh set afterward.
InterestMatch does not send email-verification or password-reset messages. Save recovery codes privately outside this device before you lose access. Each code works once; a new set replaces every older code. An already-linked sign-in provider can provide another way into your account when available. Matching email addresses never automatically merge accounts: first sign in to your existing account, then link another provider from Profile. Without a saved code or usable linked sign-in, there is no email reset fallback.
Deletion removes your live profile, sign-in identities, sessions, recovery codes, posts, photos, owned activities, relationships, requests and blocks. Reports involving your account, related moderation records and your messages to the operator are also removed from the live database. Other members' unrelated records remain.
Optional activity details on a post—including the venue or area, time, duration, group size, confirmed signup count and cost—follow that post's audience. Use a public meeting place rather than a private home address. Joining requires an account. Only the host sees the participant list and requests; other readers see counts, not names. A signup is not a location check-in. Deleting the post removes its activity and signup records.
Post comments and replies
Comments follow the post's current audience. Anyone can read comments on a visible Public post shared with Everyone; writing requires an account. Your display name and eligible profile picture appear with your comment. Changing the post audience changes who can read its comments. Blocking and moderation also affect access. Avoid including private contact details in public comments.
Deleting a comment removes its text, but an anonymous top-level marker may remain to keep other people's replies together. Identifiers, retry records and timestamps can remain to prevent duplicate writes and enforce limits. Account deletion removes your comment text and identity; anonymous markers may remain for other people's replies. Deleting the post removes its comments and replies.
A report shares the selected comment text and report details with the operator. That selected evidence may remain after the comment is edited or deleted, but related account or post deletion removes it. Your account export includes your own comment records, not other people's replies or private parent content. Comment drafts and pending retries stay only in the current tab's memory. The private backup policy below applies to comments too.
Shared cost groups
A cost-group owner can select accepted friends to invite inside the app. Before joining, an invited friend sees only the group name, currency, owner and member count. Pending friends cannot be assigned expenses. The recipient chooses Join or Decline; no code or external message is needed. Invitations expire after seven days. A response marker used for safe retries remains until seven days after expiry, then bounded cleanup removes it. Blocking, suspension, account deletion or owner transfer invalidates affected invitations.
Share lets a cost-group or friend-group owner reopen the current invitation link, copy it or display a QR generated on this device. The server keeps a private key in its database and backups so it can recover new links for the authorized owner. Account exports exclude the key and invitation codes. Existing links stay valid until replaced or invalidated by group access changes. A private group-plan link grants no access: recipients must already belong to that group.
Tools includes private cost groups. Joining with an invitation code shares your display name and the group's expense, split and recorded repayment history with its members, including people who join later. Share codes only with people you trust. Group records do not include your sign-in email. The app calculates balances; it does not collect, send or verify payments.
Members can correct entries they recorded. Leaving requires your recorded balance to be zero and ends group access, but preserves shared calculations. Account deletion is always available: it removes your account link and displayed identity from cost records while keeping numerical shares and recorded repayments so other members' balances do not change. Deleting an account does not settle a balance. Your account export includes the cost records made available under your current access.
Group members can see recent expense changes and deleted expenses, including their saved titles and notes. An eligible author can restore a deleted expense after reviewing its balance effects. Change history starts when this feature is installed and keeps up to 50 recent changes per group, subject to the server's 50,000-change limit; older changes may be removed. Account deletion clears your authored titles and notes from both expenses and retained change history. Shared numerical records remain.
A friend-group owner who also owns a cost group can connect them. Eligible current and later friends can preview the cost group’s name, currency and member count, then choose to join and see its existing shared history and member names, including people outside the friend group. Joining is never automatic. Leaving or deleting a friend group, or disconnecting its costs, does not remove cost membership, erase expenses or settle balances. Replacing the cost invitation or transferring cost ownership stops new joins through the old connection; current cost members keep their ordinary authorized access.
Previous date polls
The earlier date-poll tool remains under Previous date polls. These polls are private to people who explicitly join by invitation. Members, including people who join later, can see your display name and the times you select. A preview reveals only the organizer name, title, time zone, voting deadline and current member count; it does not reveal proposed times or answers. Poll membership is separate from cost groups and activities. The organizer chooses a time; your answer is not an attendance booking.
You can clear your answers or leave. Removing a member deletes their membership and answers. Blocking ends one person's participation in shared polls: if the organizer is involved, the other person is removed; otherwise the person making the block leaves. Unblocking does not restore membership or answers. Account deletion removes polls you organize entirely and removes your membership, answers and retry records elsewhere. Your account export contains your own answers and authorized poll context, not other members' answers.
Voting and joining close at the displayed deadline. Selecting a time freezes answers and closes invitations. Cancellation removes answers immediately. After the chosen time ends, or the latest option ends if no time was chosen, answers become unavailable immediately and are removed during bounded cleanup. Cancelled and expired summaries remain for up to seven days after cancellation or the effective event end; after that they are unavailable and all poll records are purged during cleanup. The app does not import or read private calendars. Poll drafts stay in the current tab's memory and clear when your session changes. The private backup policy below also applies to polls.
Friend groups and weekly availability
Groups are private to people who explicitly join. An owner can invite accepted friends or share an invitation link; receiving an invitation does not add you automatically. Your name and any weekly Free or Busy times you choose are visible to eligible group members, including people who join later. Unanswered times mean Not shared. Common time compares the saved calendars and shows windows when every current member has explicitly marked Free. Busy and unshared times prevent a confirmed overlap. All times use UAE time. This does not read your calendar, reveal your location or indicate live presence.
You can clear your availability or leave. Removal deletes your group availability. Removing a member also invalidates existing invitation links. Blocking removes the non-owner when an owner is involved; otherwise the person making the block leaves their shared groups. Unblocking restores nothing. Suspending or deleting an owner deletes their groups; other members' suspension or deletion removes their membership and availability. Your export includes your own availability, not other members' answers. Group invitations can use the same 15-minute sign-in continuation described above.
Conversations in friend groups
Only eligible, joined members can open a friend-group chat. Current members, including people who join later, can see the retained messages and their authors’ current names and usernames. Text messages expire 30 days after first sending; editing does not extend that deadline. Expired messages become unavailable immediately and are removed during bounded cleanup, which can be delayed while the PC is off. These conversations are stored on this PC and are not end-to-end encrypted.
You can edit or delete your own messages. The group owner can remove a message but cannot rewrite it. Deletion clears the text and leaves an empty marker until expiry. A report shares only the selected message version, your reason and your added details with operators. An operator can remove that reported message without opening the conversation. The selected reported copy can survive an edit or manual deletion until the source message expires or is removed by membership, group or account cleanup.
Leaving or removal deletes your messages and the chat reports you submitted. This also applies to membership ended by blocking, suspension or account deletion; rejoining restores nothing. Deleting or suspending the owner removes the group and its conversation. Your account export includes your own retained messages and submitted report details, not other members’ messages. Retry fingerprints contain no message text and expire at the end of the UTC day after their request day, giving 24–48 hours for safe retries. Drafts and pending requests stay only in this tab’s memory and clear on account or session changes. The private backup policy below applies.
Activity proposals in friend groups
Any current member can propose an activity. Current members, including people who join later, can see the proposal and each respondent's current name, username and choice: joining, interested, interested but busy, or not interested. These answers are not anonymous. You can change or clear your own answer. The author can edit a proposal; a real change clears all answers so everyone can choose again. The author or group owner can delete it.
Proposals and their answers expire 30 days after creation; edits do not extend this. Expired content becomes unavailable immediately and is removed during bounded cleanup, which may be delayed while the PC is off. Leaving, removal, blocking or suspension that ends your membership deletes your authored proposals and your answers elsewhere. Account deletion does the same; deleting or suspending the owner deletes the group and its proposals. Rejoining restores nothing.
Your export includes only retained, currently authorized proposals you authored or answered, with your own current answer and no other members' answers. Retry fingerprints contain no proposal text or cached responses and remain until the group or actor account is deleted. Drafts and pending retries stay only in this tab's memory and clear on account or session changes. Responding does not join a dated plan, change shared availability, cast a poll vote or affect costs. The private backup policy below applies.
Dated plans in friend groups
The group owner can arrange dated outings. Current members, including people who join later, can see retained plan details and current named Going or Not going answers. Weekly availability and poll votes never count as attendance. A real change to the plan details clears previous answers so everyone can confirm again. A cost note is descriptive; publishing, answering or cancelling a plan never changes cost-group membership, expenses or balances.
Leaving or removal deletes your answers; rejoining restores none. The same applies when blocking, suspension or account deletion removes your membership. Suspending or deleting the owner deletes the group and all its plans. At the end of an outing or on cancellation, all answers become unavailable immediately. Cancellation deletes answers immediately; bounded cleanup removes ended answers. Plan text remains for 30 days after the end or cancellation unless the owner deletes it sooner. After that deadline it is unavailable, and bounded cleanup removes it from the live database. Cleanup can be delayed while the host computer is off.
Your export includes only currently authorized plans you own or have explicitly answered, and only your own current answer. Past and cancelled exports include only plans you own, without attendance answers or counts. Retry fingerprints contain no plan text and remain until the friend group or your account is deleted. Drafts and pending retries stay in this tab’s memory and clear on account or session changes. A calendar download includes the plan title, public venue and time, without reading your calendar. It is a snapshot that does not update automatically; later changes or deletion cannot recall copies you keep elsewhere. The private backup policy below also applies.
Preparation lists in a plan
Current group members, including people who join later, can see the plan’s Bring / do list, its authors and volunteers. Members volunteer only for themselves; volunteering or marking an item done never changes attendance, calendars or costs. The author may edit an unclaimed or self-claimed item. The group owner may release a volunteer or remove an item, but cannot assign work to someone else or mark their task done. Real edits to the plan details keep the item text and clear volunteers and completion so members can choose again.
At the plan’s end or cancellation, all checklist text and volunteer information become unavailable immediately. Cancellation or plan deletion removes the list; bounded cleanup removes ended lists and can be delayed while the host is off. Leaving or removal deletes your authored items and releases your volunteered tasks. The same cleanup applies when blocking, suspension or account deletion removes membership; rejoining restores nothing. Deleting the group deletes its lists.
Your export includes only currently authorized item text you authored and items you volunteered for, with only your own completion state. It does not include another person’s volunteer identity or completion. Retry fingerprints contain no item text and expire at the end of the following UTC day; rolling counters remain until their epoch expires. Drafts and pending requests stay in this tab’s memory and clear on account or session changes. Existing private backups follow the policy below.
Polls in friend groups
Group polls use your existing friend-group membership. Current members, including people who join later, can see questions, choices and results. Anonymous polls show vote totals and your own choice without other voters' names. Named polls show each voter's current display name and username beside their choice. The host database links votes to accounts; anonymous results are not secrecy from the host, and small-group totals can sometimes reveal a choice by inference.
You can change or remove your vote while voting is open, and remove it after voting closes. The question, choices and voting mode stay fixed after publication. The creator or group owner can close or delete a poll. Deleting a poll removes it and all its responses.
Leaving or being removed from a friend group deletes your votes and every poll you created there, including its responses. The same cleanup applies to membership removed by blocking, suspension or account deletion. Deleting a friend group deletes all its polls. Your export includes your own vote and currently authorized question/choice context, without other members' votes. Request fingerprints used to prevent duplicate actions remain until the friend group or account is deleted; they contain no question or choice text. Drafts and pending retries stay in the current tab's memory and clear on account or session changes. The private backup policy below also applies.
Profile pictures
A profile picture is optional. Eligible signed-in members can see it. Visitors can also see it while you have at least one visible Public post with Everyone selected. Changing every such post's audience, deleting those posts, or removing your photo ends new public access; saved copies cannot be recalled. Signing out may allow someone to see content available to all visitors.
The browser compresses profile pictures to at most 512 pixels per side and 128 KiB. The server strips metadata and accepts only supported still JPEG, PNG or WebP pictures. You can replace or remove your picture; five successful uploads are allowed per rolling 24 hours, and removal does not reset that allowance. Profile, post and business photos share the PC's image storage budget. Export includes your current picture and retained upload records. Deleting your account removes them.
Business listings
Published business listings, prices, public venue details and gallery photos are visible without an account. Only current operators can create or manage them; drafts and hidden entries are restricted to operators. Each listing can have up to four supported still JPEG, PNG or WebP photos, each at most 256 KiB and 1,200 pixels per side. The server removes image metadata. Hiding or deleting an entry ends new public access to its photos; previously saved copies cannot be recalled.
Map and YouTube or Vimeo links open an external site only when you choose them. No external map, video player or thumbnail loads automatically. Those sites receive your browser request and apply their own privacy policies.
Operator actions have private attribution, retry records and moderation audit records. Deleting an operator account removes its creator/editor attribution and request records; shared listings and their photos remain. Your export contains your attributed listing identifiers, timestamps and retained request metadata, not catalog photos, draft contents or other operators' information. An operator can separately hide or delete a listing.
Retention and backups
A photo-upload allowance record stores your account ID, upload ID, time and byte size without copying the photo. Deleting a photo does not reset the 24-hour allowance. Expired allowance records are removed during a later successful photo upload; account deletion removes your records. Your account export includes your retained upload records.
Deleting a chat message removes its text. Its identifiers, authorship and time remain to prevent a retried send from restoring it; account deletion removes those records. Group drafts are kept only in the current tab and cleared when the session changes.
Account deletion also removes your place memberships, chat messages, chat reports and private product feedback. Approved shared-place entries may remain with their creator attribution removed. Deleting a feedback submission removes its text and reply; a record containing your account ID, submission ID and time may remain to enforce the daily submission limit. Expired limit records are cleaned on a later successful submission, and account deletion removes them. Moderator audit records do not retain earlier copies of feedback reply text.
Unless a shorter retention period is described above, content remains in the live community until it is deleted by its owner, removed through moderation or cleaned up with account deletion. Ordinary sign-out ends that session; it does not delete your account.
Private backup snapshots can contain earlier records. Scheduled backups expire after 14 days during successful supervisor backup cycles; manually retained copies may last longer. Account deletion does not rewrite old backups, and restoring an older backup can restore deleted records. Deletion is not a promise of forensic erasure from disks or database journal files.
Questions and privacy requests
Anyone can use Contact me to reach the creator by email or WhatsApp without an account. Private creator chat appears there when enabled; signed-in members can also submit an account request. Replies are not guaranteed immediately. This is not an emergency service.