Privacy Policy
English version (informational) · 2026
1. Data controller and data collected
AuPair Connect is the controller of the data described in this policy. We collect the following categories of data: identification and account data (e-mail address, login identifiers), profile and matching data, content you publish, messages and associated metadata, verification data (identity documents, proof of address, referee contact details), purchase and subscription data, technical and security data, and aggregated or pseudonymised audience-measurement data.
We apply the principles of minimisation and purpose limitation: only data necessary to operate the service and to perform the requested verifications is collected. No special category of data within the meaning of Article 9 GDPR (religious beliefs, ethnic origin, health, sexual orientation, etc.) is collected or used for matching.
2. Purposes of processing
Your data is used to: provide and secure the Platform and the application; enable account creation, authentication, matching and messaging between members; carry out trust verifications and certification; manage purchases and access to paid features; send you the notifications you have accepted; prevent fraud and abuse; respond to your requests; and measure and improve the quality of the service.
3. Cookies and trackers
See our Cookie Policy for details of the trackers used and the related consents.
4. Hosting and sub-processors
AuPair Connect uses a cloud hosting provider acting as a data sub-processor to host and secure your data and to manage account authentication, storage and hosting of the website and application. These services process your data under our instructions, within the framework defined by our processing agreement, in accordance with the GDPR.
When you write to us at a public contact address (hello@, help@ or partners@), your message may be processed using automated customer-support request-management assistance tools. These tools only assist us: no reply is sent without systematic human review and approval, no automated decision is taken about you, and they receive only the text of your message, stripped of your contact details, links, attachments and any data relating to a child. This processing is governed by our contractual commitments and the technical measures described in our processing register.
5. Video calls
Video calls between members rely on a real-time communication provider acting as a data sub-processor. During a call, the audio and video streams are transmitted in transit through its infrastructure to establish and route the communication. These streams are neither recorded nor retained by AuPair Connect after the call ends. The provider only receives the technical data required to set up the link (channel identifier, temporary access tokens, media streams).
6. Purchases, subscriptions and app stores
Purchases and subscriptions are handled through the Apple App Store and Google Play app stores, which process the payment and never pass us your banking details. To manage access to paid features, we use an entitlement-management provider acting as a data sub-processor, which receives a purchase identifier and the purchase / subscription history associated with your account (product purchased, status, validity dates, any trial). This information is used solely to activate and maintain your entitlements. Subscriptions are firm commitments with no automatic renewal; see our Terms / EULA.
7. Push notifications
To alert you about new messages and incoming calls, we register a push notification token unique to your device, provided by the operating system’s notification service (Apple / Google). This token is stored server-side, linked to your account, and passed to the relevant provider solely to deliver the notifications you have accepted. You can disable notifications at any time in your system settings; the corresponding token is then no longer used.
8. End-to-end encrypted messaging
The content of your private conversations is protected by end-to-end encryption: only the correspondents hold the keys needed to decrypt the messages, and AuPair Connect has no clear-text access to them. Private keys are kept exclusively in your device’s secure storage, never on our servers. We nonetheless keep the metadata strictly necessary to operate the service (participant identifiers, timestamps, sent and read status) as well as any content you choose to publish outside private messaging (profile, photos).
9. Automatic translation of your profile
To allow other members to read your profile in their own language, the narrative sections you write may be transmitted to an automated translation service. The resulting translations are kept in secure cached storage on our servers to keep transfers to a minimum, and are erased when the corresponding profile is deleted. Only actually written sections that are missing in the reader’s language are processed; no identity documents are involved.
10. Subtitling and translation of your pitch videos
To make your pitch videos accessible in all languages, the voice track may be processed by automated transcription and translation services (subtitle generation). The audio is processed ephemerally: the extracted file is hosted temporarily and automatically erased at the end of the operation, and intermediate transcription data is deleted once consumed. Your voice is used only to subtitle your own video and never for any other purpose.
11. Automatic reading of your proof of address
When you submit a proof of address as part of the certification programme, the document is analysed by an automated text-recognition (OCR) service for the verification of the proof of address, in order to extract the issuer, address and date and compare them with the declared address. The document is processed confidentially, in a restricted-access storage space, for the retention periods described in the “Trust verifications” section below.
12. App stability and audience measurement
To ensure the stability of and improve the application, we use crash-reporting tools (error type, technical stack trace, device model, OS version) and audience-measurement tools producing aggregated and pseudonymised usage events. A pseudonymous user identifier may be associated with these measurements to link an incident to an account without exposing your identity. These data are never used for automated decisions about you and are not used for advertising purposes.
13. Retention periods
Data is retained only for as long as necessary for the purposes described above. Cached translations are erased when the corresponding profile is deleted. Periods specific to trust verifications are set out in section 15.
14. Your rights (GDPR)
In accordance with the GDPR, you have a right of access, rectification, erasure, restriction, objection and portability of your data. To exercise these rights, contact us at hello@aupairconnect.app. The account deletion procedure in the app and by e-mail is described on the Account deletion page. You may also lodge a complaint with the competent supervisory authority.
15. Trust verifications (criminal record, address, references)
As part of the voluntary trust certification programme, we may process the documents and contact details you send us. Their retention is strictly limited to what is necessary for the requested verification:
- Criminal record check: the document is retained only for as long as necessary for review by our team (human review), then deleted immediately after the decision, whether positive or negative. Only the decision (date and result) is retained, never the document itself. Any review without a decision after 60 days is automatically closed and the corresponding document is deleted.
- Proof of address: after validation, the document is retained for the lifetime of the account in order to maintain the profile’s certification. It is deleted immediately upon rejection and together with all your data if you delete your account.
- References: your referee’s contact details (name and e-mail address) are used only to send the confirmation request. They are never shared with other members or reused for other purposes. The referee, a non-user third party, is informed of the purpose of the request; the confirmation link is single-use and expires after 30 days.
16. Security and final provisions
We implement appropriate technical and organisational measures to protect your data against unauthorised access, alteration or disclosure (encryption in transit and at rest, access segregation, logging). The verifications comply with the principles of data minimisation and storage limitation (Art. 5 GDPR). Documents relating to a specific category (criminal record) are subject to particularly restrictive processing: access limited to authorised review, immediate destruction after the decision, minimal retention with no copy or archiving. Data is never retained beyond what is necessary for the purposes described.