Private by default.
Purpose-limited by design.
This notice describes the current AuPairPilot build. Legal bases, retention periods, and final wording require privacy-counsel approval before public launch. The monitored privacy contact is support@aupairpilot.de.
1. What AuPairPilot collects
AuPairPilot stores account and onboarding data, eligibility answers and policy versions, profile and matching information, identity-review evidence, phone numbers submitted for manual verification, messages, safety reports, moderation events, and security records such as hashed login and rate-limit tokens. The host-family profile does not request children’s names or ages; applicants should not include them in free-text answers.
2. Why the data is used
The data supports account access, eligibility checks, privacy-scoped matching, identity and safety review, mutual-match messaging, abuse prevention, and required operational audits. The final legal basis for each purpose remains subject to counsel confirmation.
3. Who can see it
Profiles are not discoverable at account creation. Approved users see only limited discovery fields before a mutual match. Exact addresses and raw identity documents are never part of the discovery response. Authorized reviewers may access identity evidence, and each administrative view is logged.
4. Service providers
The current architecture uses Cloudflare for application hosting, structured data, and private object storage, and Resend for transactional account email, including sign-in, verification decisions, mutual matches, and new-message alerts. Notification emails do not include private message content. Production provider agreements and international-transfer review must be completed before launch.
5. Retention and your rights
Retention holds prevent deletion when a safety case requires preservation. Otherwise, counsel-approved periods will control deletion of rejected identity evidence and moderation records. To request access, correction, objection, restriction, portability, or deletion, email support@aupairpilot.de. The final request-handling process remains subject to privacy-counsel approval before launch.