Privacy Policy for Matcha Shift

Last Updated: February 14, 2026

Introduction

This Privacy Policy explains how Jolt Co. ("us", "we", or "our") collects, uses, and discloses your information in connection with your use of the Matcha Shift mobile application (the "Service"). We are committed to transparency and providing you with meaningful control over your data.

1. Information We Collect

We collect information to provide and improve our Service. The types of information depend on how you use the Service and the choices you make.

  • Account Information: When you create an account, we collect your email address and name. To comply with U.S. law, we also require your Date of Birth to verify you are over the age of 13, personalize content, and create age groups for marketing campaigns.
  • Optional Profile Information: During registration, you may voluntarily provide your Gender. Providing this information is completely optional and is used to help us personalize content and target marketing campaigns.
  • Age and Gender Groups: We calculate your age group from your date of birth (e.g., "23-27") and use your gender to create demographic groups. These groups are used for content personalization and marketing purposes, but your exact date of birth is never shared.
  • Subscription Information: When you subscribe, our third-party payment processor collects your payment information. We do not store your full payment card details.
  • Consumer Health Data (as defined by applicable law): This includes data you provide, such as self-reported wellness data (e.g., mood, stress levels), and data we generate from your use of the Service, such as meditation session data (e.g., length, frequency, content selected).
  • Usage and Technical Data: We automatically collect data like your IP address, device type, operating system, and how you interact with our Service (e.g., features used, time spent).

2. How We Use Your Information & Your Choices

We use your information for specific purposes and give you clear choices over how your data is used. The use of our Service requires processing essential data as described in our Terms of Service. For all other purposes, we rely on your explicit consent, which you can grant or deny through the choices presented to you.

You can review and change your choices at any time in your account's Privacy Settings.

PurposeData UsedIs Consent Required?What Happens if You Decline?
Provide Core Service & Verify AgeAccount Info, Date of Birth, Subscription Info, Meditation HistoryNo (Required for Legal Compliance & Terms of Service)You cannot create an account or use the app's basic functions.
Age- and Gender-Based PersonalizationAge Group (13-17, 18-22, 23-27, 28-32, 33-37, 38-42, 43-47, 48-52, 53-57, 58-62, 63-67, 68+), Gender GroupYes (Optional)We cannot provide age- and gender-appropriate content recommendations or target marketing campaigns to you.
Personalize Your ExperienceConsumer Health Data, Gender (optional), Usage DataYes (Optional)We cannot provide personalized insights or recommendations.
Send Promotional CommunicationsAccount Information, Usage DataYes (Optional)You will not receive emails or push notifications about new features or offers.
Deliver Personalized AdvertisingUsage Data, Age Group, Gender Group, Inferred InterestsYes (Optional)We cannot share data with ad partners to show you relevant ads or to find new users.

3. Disclosure of Your Information

We do not sell your Personal Data or Consumer Health Data in the traditional sense. However, some laws, like the California Consumer Privacy Act (CCPA), define "selling" or "sharing" broadly. As described below, we only disclose your data to third parties for specific purposes and, where required, with your consent.

We may disclose your information to the following categories of third parties:

  • Service Providers: Companies that perform services on our behalf, such as Supabase for database hosting and backend infrastructure, and payment processors for handling subscriptions. These providers are contractually bound to protect your data and use it only for the services we request.
  • Analytics Providers: To help us understand and improve the Service. All data shared for analytics is aggregated or de-identified where possible.
  • Advertising Agencies (Service Providers): We may engage third-party advertising agencies to manage and optimize our marketing campaigns. These agencies receive your age group (e.g., "23-27") and gender group to help us reach potential new users. They are contractually bound to protect your data and use it only for the services we request.
  • Advertising Partners: With your explicit consent for "Age- and Gender-Based Personalization" and "Personalized Advertising," we may share your age group (e.g., "23-27"), gender group, and usage data with partners like Meta, Google, X, Pinterest, and Apple. This is to show you more relevant ads on their platforms and to help us reach potential new users. You have the right to opt-out of this sharing at any time by changing your Privacy Settings.

We may also disclose your information if required by law or to protect the rights, property, or safety of Jolt Co., our users, or others.

4. Data Security and Breach Notification

We implement commercially reasonable security measures, including encryption (such as TLS and AES-256), to protect your information. However, no security measure is perfect or impenetrable. We cannot guarantee the absolute security of your information.

In the event of a data breach involving your health information that requires notification under applicable laws, such as the FTC's Health Breach Notification Rule, we will provide notice to the affected individuals and the FTC as required.

5. Your Privacy Rights

Depending on your state of residence (e.g., California, Washington), you may have specific rights regarding your personal information, including the right to:

  • Access the specific pieces of personal information we have collected about you.
  • Correct inaccuracies in your personal information.
  • Delete your personal information.
  • Opt-out of the "sale" or "sharing" of your personal information (which you can exercise by disabling "Age- and Gender-Based Personalization" or "Personalized Advertising" in your settings).

You can exercise these rights through your account settings or by contacting us directly at the email below.

6. International Data Transfer

Your information may be transferred to, and processed in, countries other than your own, including the United States (where our service providers are located) and Japan (where our team is based). We take steps to ensure that your data is treated securely and in accordance with this Privacy Policy.

7. Children's Privacy

Our Service is not directed to individuals under the age of 13. To ensure compliance with the Children's Online Privacy Protection Act (COPPA), we require all users to provide their date of birth during registration to verify they are 13 years of age or older. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete such information and terminate the child's account.

8. Data Retention

We retain your personal data only for as long as necessary to provide you with our Service and for legitimate and essential business purposes, such as maintaining the performance of the Service, making data-driven business decisions about new features, and complying with our legal obligations.

For detailed information about data retention after account deletion, please see Section 12 below.

9. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. For material changes, we will provide a more prominent notice, such as through an in-app notification, before the change becomes effective.

10. Data Collection Consent Details

When you create your Matcha Shift account, you agree to this Privacy Policy, which includes your consent to the data collection practices described below. You can manage your data collection preferences at any time by visiting your account's Privacy Settings after logging in.

10.1 Age- and Gender-Based Personalization

  • What we do: We use your age group (e.g., "23-27") and gender group to provide age- and gender-appropriate content recommendations and to target marketing campaigns. Your age group and gender group may be shared with: - Our internal marketing team - Third-party advertising agencies (as service providers) to help manage and optimize our marketing campaigns - Advertising platforms (Meta, Google, X, Pinterest, Apple) to show you relevant ads and reach potential new users
  • Data collected: Date of birth (used to calculate age group), gender, age group, gender group.
  • Age groups used: 13-17, 18-22, 23-27, 28-32, 33-37, 38-42, 43-47, 48-52, 53-57, 58-62, 63-67, 68+
  • Purpose: To provide age- and gender-appropriate recommendations, personalize advertising, improve the service, and help us reach potential new users through targeted marketing campaigns.
  • Third parties: Your age group and gender group may be shared with: - Internal marketing team - Third-party advertising agencies (as service providers) - Meta Platforms, Inc., Google LLC, X Corp., Pinterest, Inc., and Apple Inc.
  • Important: Your exact date of birth is never shared with third parties. We always use age groups (e.g., "23-27") to protect your privacy.
  • Your control: You can disable age- and gender-based personalization at any time in your Privacy Settings. If you disable this feature, we will not use your age group or gender group for personalization or share them with advertising partners or agencies.

10.2 Personalize My Experience

  • What we do: We analyze your wellness data (meditation history, mood, stress levels) and optional profile information (like gender and age group) to suggest personalized sessions and insights tailored to your needs.
  • Data collected: Meditation session history, self-reported mood and stress levels, session preferences, usage patterns, and optional profile information.
  • Purpose: To provide personalized recommendations and insights that enhance your experience with Matcha Shift.
  • Third parties: No data is shared with third parties for this purpose.
  • Your control: You can disable this feature at any time in your Privacy Settings.

10.3 Receive Promotional Communications

  • What we do: We'll send you emails and push notifications about new features, special offers, and updates.
  • Data collected: Email address, push notification preferences, and engagement data.
  • Purpose: To keep you informed about important updates, new features, and special offers.
  • Third parties: No data is shared with third parties for this purpose.
  • Your control: You can disable promotional communications at any time in your Privacy Settings.

10.4 Allow Personalized Advertising

  • What we do: We share your usage data to show you relevant ads and help us reach users who might benefit from Matcha Shift. Your usage data may be shared with: - Our internal marketing team - Third-party advertising agencies (as service providers) - Advertising platforms (Meta, Google, X, Pinterest, Apple)
  • Data collected: Usage data, inferred interests based on your interaction with the Service, and engagement patterns.
  • Purpose: To show you relevant advertisements on third-party platforms and to help us identify and reach potential new users.
  • Third parties: Our internal marketing team - Third-party advertising agencies (as service providers) - Meta Platforms, Inc., Google LLC, X Corp., Pinterest, Inc., and Apple Inc.
  • Your control: You can disable personalized advertising at any time in your Privacy Settings. If you disable this feature, we will not share your usage data with advertising partners or agencies.

11. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Jolt Co. IW Bldg. 1F, 2-10-31 Kanda-Jinbocho, Chiyoda-ku, Tokyo, Japan Email: matchashift@gmail.com

12. Account Deletion and Data Retention

12.1 How to Delete Your Account

You can request to delete your account at any time through the app's settings. Upon deletion request, your account will be deactivated immediately, and you will no longer be able to access the Service.

12.2 Two-Stage Deletion Process

We follow a two-stage process to balance your privacy rights with legitimate business needs:

Stage 1: Account Deactivation (30 Days)

When you request account deletion: - Your account is immediately deactivated and you lose access to the Service. - Your personal information is isolated and not used for any marketing or service purposes. - You have 30 days to contact us if you wish to recover your account.

Stage 2: Permanent Anonymization (After 30 Days)

After 30 days of inactivity following your deletion request: - All personally identifiable information (name, email address, date of birth, gender, etc.) is permanently deleted from our systems. - Your account cannot be recovered after this point.

12.3 Data Retained After Account Deletion

After permanent anonymization, we retain two categories of data for specific, legitimate purposes:

A. Anonymized Audit Log (Permanent Retention)

We retain fully anonymized data that cannot be used to re-identify you. This data is used for: - Internal analytics: Understanding user behavior patterns and service usage trends - Security and fraud prevention: Detecting and preventing unauthorized access - Service improvement: Making data-driven decisions about features and functionality - Marketing optimization: Optimizing marketing campaigns and audience targeting based on anonymized demographic data

Data retained in anonymized form: - Your age group at deletion (e.g., "23-27") - Your gender at deletion - Your subscription status at deletion (active, trial, expired, etc.) - Your cumulative meditation statistics at deletion (total sessions, total minutes, rank) - Your account creation and deletion dates

Important: This data is completely anonymized and cannot be linked back to your identity. It is retained indefinitely for statistical analysis, service improvement, and marketing optimization.

B. Legal Compliance Record (4-Year Retention)

To comply with U.S. marketing laws (such as the CAN-SPAM Act) and defend against potential legal claims, we retain a separate compliance record containing: - A hashed version of your email address (using SHA-256 encryption) - The date and time you provided marketing consent - The IP address from which you provided consent - The version of our Privacy Policy you agreed to

Important: This data is used exclusively for legal compliance and is never used for marketing purposes. It is automatically deleted after 4 years.

12.4 Data Deleted Upon Account Deletion

The following data is completely deleted and not retained in any form: - Your name - Your email address - Your date of birth (exact date) - Your meditation records and session history - Your mood and stress level data - Your favorite sessions - Your device tokens - Your profile picture - Your coupon redemption history - All other personal and health-related information

12.5 Legal Compliance and Litigation

Notwithstanding any other provision in this Privacy Policy, we may retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements. Specifically, if you have deleted your account, we may use the internal account identifier retained in our Legal Compliance Record and Anonymized Audit Log to identify your data in the event of a legal claim or dispute. This process is strictly controlled and is used only for the purpose of producing legally required evidence. The process involves using a hash of your email address to locate your internal account identifier, which is then used to retrieve your anonymized data. This allows us to respond to legal requests without retaining your personally identifiable information for longer than necessary.

12.6 Data Portability

Upon request, we will provide you with a copy of your personal data in a machine-readable format.