Privacy Policy
Last updated: May 13, 2026
1. Who we are
Sundain is operated by Leonard Bauer, based in Cologne, Germany. We are the data controller
responsible for your personal data under the EU General Data Protection Regulation (GDPR).
Contact: [email protected]
2. What data we collect
We collect the following categories of personal data:
- Account data: name, email address, and authentication credentials when you create an account.
- Conversation data: the content of your conversations with our AI, used to build your cognitive profile.
- Profile data: interests, skills, needs, and preferences derived from your conversations — only when you opt in to profiling.
- Usage data: app interactions, device information, and log data for service improvement and security.
- Connection data: information about matches and interactions with other users on the platform.
- Attachment data: images and documents (e.g. PDFs) you choose to attach to chat messages. Images may be captured via your device camera or selected from your gallery; the camera and photo-library permissions are only used when you actively initiate an attachment.
- Voice data: audio recordings of your conversations with our AI when you use voice mode. The microphone permission is only used while you are in an active voice session.
3. Why we process your data
We process your data for the following purposes and legal bases:
- Providing the service (contract performance): account management, AI conversations, and user matching.
- Cognitive profiling (consent): building your profile to enable meaningful connections. This is entirely opt-in.
- Service improvement (legitimate interest): analytics, debugging, and improving our AI models. We never use raw conversation content for training.
- Security (legitimate interest): fraud prevention, abuse detection, and platform integrity.
- Legal obligations (legal basis): compliance with applicable laws and regulations.
4. Cognitive profiling — your choice
Profiling is the core of how Sundain connects people, but it is always opt-in.
You choose whether to enable it, and you can disable it at any time. Profiling is free for all
users — it is not a paid feature.
When profiling is enabled, our AI analyzes your conversations to understand your needs, skills,
emotional state, and interests. This information is used to find complementary people — not just
similar ones. No raw conversation content is ever shared with other users or used in the matching
algorithm directly.
5. How we share data
We do not sell your personal data. We share data only in these cases:
- With other users: only the information you explicitly choose to make visible through your granular sharing settings.
- Service providers: hosting (Hetzner, Germany), object storage for chat attachments (Cloudflare R2), AI processing including image understanding for attachments (Anthropic), and essential infrastructure providers, all bound by data processing agreements.
- Legal requirements: when required by law or to protect rights and safety.
6. Where we store data
Your data is stored on servers in Germany (Hetzner). When we use third-party AI providers,
data may be processed outside the EU under appropriate safeguards (Standard Contractual Clauses).
7. How long we keep data
We retain your data for as long as your account is active. Conversation data used for profiling
is processed and then the raw content is not retained beyond what is needed for the service.
When you delete your account, all personal data is erased within 30 days, except where retention
is required by law.
8. Your rights
Under GDPR, you have the right to:
- Access your personal data and receive a copy.
- Rectify inaccurate data.
- Erase your data ("right to be forgotten").
- Restrict processing in certain circumstances.
- Data portability — receive your data in a structured, machine-readable format.
- Object to processing based on legitimate interest.
- Withdraw consent at any time for consent-based processing (like profiling).
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
9. Cookies and tracking
We use only essential cookies required for the service to function. We do not use advertising
trackers or third-party analytics cookies.
10. Children
Sundain is not intended for users under 16 years of age. We do not knowingly collect data from
children. If you believe a child has provided us with personal data, please contact us and we
will delete it.
11. Changes to this policy
We may update this policy from time to time. We will notify you of material changes via email
or in-app notification. Continued use of the service after changes constitutes acceptance.
12. Contact and complaints
For questions or concerns about this policy, contact [email protected].
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is
the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW).