Privacy Policy
Last updated: April 3, 2026
Mato is published by Sycamore SAS, a company registered in Paris, France. We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable French law.
1. Data collected
- WhatsApp phone number — to identify your account and send you messages.
- First name — to personalize bot responses and task attribution.
- Message content — text, voice notes and images sent to Mato, to create and manage your to-do list.
- Email address — only if you create a web account or make a payment via Stripe.
- Payment data — processed directly by Stripe. We never store your card numbers.
2. Use of data
- Operating the Mato service (message processing, list management, sending confirmations).
- Transcribing and analyzing your messages via AI (Google Gemini) to understand your requests.
- Managing your subscription and sending receipts (via Stripe).
- Sending a monthly activity summary (Family plan subscribers only).
- We never use your data for advertising or commercial profiling.
3. Data sharing
- Meta (WhatsApp Cloud API) — message routing. Policy: whatsapp.com/legal/privacy-policy
- Google (Gemini AI) — natural language processing and voice transcription. Your messages are sent to the Gemini API for analysis. Google does not use them to train models when the paid API is used.
- Supabase — database hosting, located in Europe (AWS eu-west). Policy: supabase.com/privacy
- Cloudflare — website and webhook hosting. Policy: cloudflare.com/privacypolicy
- Stripe — payment processing. Policy: stripe.com/privacy
- n8n Cloud — workflow orchestration. Policy: n8n.io/legal/privacy
- We never sell your data to third parties.
4. Hosting and location
All data is hosted in Europe (European Union). The Supabase database is located in the AWS eu-west region. Static files are distributed via Cloudflare's global network with a European origin.
5. Data retention
- Active tasks — retained as long as the family account is active.
- Completed tasks — retained indefinitely in the database (for monthly reports and history). Hidden from the web interface after 7 to 14 days depending on the category.
- Raw messages — retained in an audit log for debugging purposes. Deleted after 90 days.
- Deleted account — all personal data is deleted within 30 days of the request.
6. Your rights (GDPR)
- Access — obtain a copy of your personal data.
- Rectification — correct inaccurate data.
- Deletion — request deletion of your account and data.
- Portability — receive your data in a structured, readable format.
- Objection — object to the processing of your data.
- Restriction — request restriction of processing.
To exercise these rights, send an email to hello@mato.do or a WhatsApp message to Mato with the word "data".
7. Security
- WhatsApp communications are end-to-end encrypted by Meta.
- Database access is protected by service keys and row-level security policies (RLS).
- Web access tokens are random 128-bit identifiers, mathematically impossible to guess.
- Payments are processed by Stripe (PCI DSS Level 1 certified).
8. Cookies
Mato does not use tracking or advertising cookies. A session cookie may be used if you create a web account, solely to maintain your login.
9. Changes
We may update this policy. In case of significant changes, we will notify you via WhatsApp or email. The last update date is shown at the top of this page.
10. Contact
- Email: hello@mato.do
- WhatsApp: send "data" to Mato
- Publisher: Sycamore SAS, Paris, France