The answers you submit
The free matching flow processes the style and shopping answers you submit: design direction, shape, metal, wear, setting priorities, diamond preference, budget, spending priority, features to avoid, and an optional note.
In the browser, those answers are sent to the RingMatcher server when you request a Ringprint. In the native app, a questions-only Ringprint is created on the device; answers are sent only when you attach photos for optional analysis. In either remote flow, they are used to create the result and check that the recommendation respects the choices you made.
Optional image handling
Photos are optional and face photos are never required. Selected images are previewed and resized in your browser or re-encoded by the native app. Up to three resized images and their labels may be sent through the RingMatcher server to OpenRouter and a configured model provider for that request. If image analysis is unavailable, your answers alone create the result.
RingMatcher does not intentionally save uploaded image files to an account or image database. Zero-data-retention and data-collection-denial settings are requested from OpenRouter, but OpenRouter, any routed model provider, and their infrastructure, terms, and legal obligations still apply. Do not upload an image you are not comfortable transmitting for analysis.
Native app data, purchases, and recovery
A questions-only Ringprint in the native app is created on the device, so those answers do not leave the device for matching. If you add up to three photos, the app re-encodes them and sends the device-resized images, their context labels, the questionnaire answers, the content locale, and a random installation identifier through RingMatcher for that request. Cookies are omitted. RingMatcher then sends the answers and images to OpenRouter, the configured AI gateway, with zero-data-retention and data-collection-denial settings requested. RingMatcher does not intentionally persist the match request body or uploaded image files, and saved Ringprints never contain a photo file or image payload. OpenRouter, any routed model provider, and their infrastructure, terms, and legal obligations still apply.
The app stores saved Ringprints in AsyncStorage, including the questionnaire answers, optional note, generated result, locale, source, timestamps, and image-analysis counts. Paid-plan snapshots, generated guidance, setup inputs, and tool activity are also stored in AsyncStorage; source snapshots omit the free-form Ringprint note. These records are app-local but are not encrypted by AsyncStorage. Photo files are excluded. A random installation UUID and purchase capabilities—including draft and access tokens, obfuscated purchase-binding identifiers, and a Google Play purchase token after billing—are stored separately with device-only SecureStore settings.
On Android, RingMatcher disables app backup and excludes its app files, databases, preferences, and device-to-device transfer domains from backup rules. This is intended to keep local Ringprints, plans, and purchase capabilities off Android backup and migration services. Other operating-system, device-administration, forensic, or user-initiated copying behavior is outside RingMatcher's control.
If you choose Report this result, the app sends RingMatcher the result identifier, visible result title, summary and rationale, the selected report reason, an optional note, the content locale, and the random installation identifier in a request header. The service uses the installation identifier and network address to enforce an hourly report limit. It writes the report content, reason, optional note, locale, a generated report identifier, and the receipt time to structured deployment logs so the report can be reviewed. Those report logs do not intentionally include the raw installation identifier or network address; their retention follows the deployment logging configuration. Reporting is optional and does not affect saved Ringprints or paid access.
Starting a Google Play checkout sends RingMatcher the selected pack, random installation UUID, local Ringprint identifier, and a SHA-256 digest of the Ringprint—not the questionnaire answers, uploaded photos, or generated plan. The server persists a digest of the installation identifier, the Ringprint identifier and digest, generated draft/access identifiers, product and pack identifiers, obfuscated Google Play binding identifiers, capability hashes, and timestamps. Claiming a purchase sends the raw Google Play purchase token to RingMatcher so it can be verified with Google Play. The server persists a digest of that token, and may persist an order-ID digest and purchase-completion timestamp; it does not write the raw purchase or order token to its purchase-state file.
The protected Google Play app-review path sends the reviewer access code and random installation UUID to RingMatcher. The server compares a one-way code digest, enforces network and installation limits, and persists only the code digest, installation digest, synthetic draft/claim/access identifiers, pack and product identifiers, and timestamps—not the plaintext review code. It returns signed, expiring plan capabilities to device-only SecureStore. This review path does not open billing or create a charge.
An unclaimed purchase draft expires after 7 days. After a successful claim, its draft and replay-claim record become eligible for pruning when that same 7-day draft capability expires. Paid access expires after 30 days for Shortlist or Complete Plan and after 90 days for Together Plan. Expired eligible rows are pruned atomically during later purchase-state maintenance, such as a subsequent draft creation or purchase grant; there is no background deletion timer. Unexpired drafts and access records are not evicted to make room for newer records.
Saved Ringprints and completed paid plans remain on the device until you remove them, the bounded local history replaces older Ringprints, app storage is cleared, or the operating system removes the app data. Removing a completed paid plan also asks SecureStore to delete its associated capability. A plan with an unfinished purchase is protected from ordinary removal because the local draft may still be needed for Google Play recovery. RingMatcher has no user account or cross-device plan library: clearing local app data, removing protected credentials, changing devices, or uninstalling can make a consumed one-time purchase or its generated plan impossible to recover. Contact contact@ringmatcher.com for privacy or server-record deletion questions.
Sensitive inferences are outside the purpose
The image-analysis instructions restrict the model to visual design clues such as color, line, proportion, texture, silhouette, accessories, objects, and interiors. They prohibit identifying a person, brand, location, or private detail and prohibit inferring sensitive traits.
Text or instructions visible inside an uploaded image are ignored. A user-supplied ‘not their style’ label is treated as negative evidence; a general style clue is treated as lower-confidence context rather than proof.
Shared links
A Ringprint share link contains the visible recommendation, selected diamond preference, and budget bracket in the URL fragment. It does not contain uploaded image files or the questionnaire answers as separate fields. Text you submit may influence the visible explanation, so review the result before sharing it.
Anyone with the link can read the information encoded in it. The public service does not create an account or a private, access-controlled workspace for the free Ringprint.
When you continue from a Ringprint to the retailer finder, the visible shape, setting, metal, center-stone range, origin, and budget bracket are transferred in a bounded URL fragment. A fragment is not sent with the retailer-page HTTP request or written to server access logs, and RingMatcher removes it from the address bar after importing it. Anyone who receives the unimported link can still read those fields.
Website paid packs and Stripe
Optional paid packs purchased on ringmatcher.com use Stripe for one-time payment processing. When you start website checkout, RingMatcher sends Stripe the receipt email you enter, the selected pack identifier, the server-set amount and currency, and generated request and PaymentIntent identifiers. Stripe’s Payment Element collects and processes the payment details. RingMatcher does not receive or store your full card number, security code, or the contents of Stripe-hosted payment fields.
Stripe metadata contains only generated identifiers, payment and fulfillment status, the pack identifier, and a one-way hash used to bind access to the browser that created the checkout. RingMatcher does not put questionnaire answers, uploaded photos, private notes, or paid report contents in Stripe metadata.
RingMatcher places the PaymentIntent identifier and a generated access capability in per-pack HttpOnly, SameSite cookies with a 100-day maximum age so the server can verify that browser’s payment directly with Stripe. These cookies do not create an account or portable, cross-device access. A pending-checkout record may also remain in that browser’s local storage for up to 30 days so a confirmed payment can be recovered after a refresh without beginning another charge. It contains the pack and PaymentIntent identifiers, receipt email, request identifier, status, timestamp, and whether the checkout replaces an older pack purchase—not card details, questionnaire answers, photos, or report contents.
Stripe’s infrastructure, terms, privacy policy, and legal obligations apply to its processing. On the production website, paid report sessions are stored on a protected server volume and restored across routine restarts and deployments. Shortlist and Complete Plan sessions expire after 30 days; Couple’s Edition sessions expire after 90 days, or earlier when RingMatcher completes a deletion request.
Request limits, first-party measurement, and technical logs
To prevent abuse, the server may use your network address to derive a temporary request-limit key held in server memory. The raw address is not included in your Ringprint, its share link, or an analytics event.
RingMatcher sends small, first-party events for funnel milestones across the landing page, guides, Ringprint creation, sharing and downloads, optional checkout and paid-pack workflows, and the retailer finder. The event contract permits only the event name plus fixed source, channel, pack, status, purchase type, CTA destination, CTA placement, or locale values, booleans, bounded counts or scores, allowlisted guide slugs, and reviewed catalog retailer IDs. It excludes questionnaire answers, budgets, notes, generated direction text, arbitrary URLs or page paths, free-text destinations, payment identifiers, error digests, messages or stacks, personal details, and arbitrary text.
After a guide-to-quiz click, browser session storage may keep only these attribution values—the allowlisted guide slug, locale, and CTA placement—plus technical version and expiry metadata. The attribution is accepted for at most 30 minutes and is consumed once for an attributed Ringprint request. An expired record is ignored and removed on next access; session storage also ends with the browser tab or session. It contains no questionnaire answers, budgets, photos, contact details, or account or user identifier.
Accepted events are written only as structured server deployment logs. RingMatcher does not send them to a third-party analytics service or store them in a dedicated analytics database; retention depends on the deployment’s logging configuration. Events do not include an account or user identifier. Technical AI usage such as model name, token counts, response status, and estimated processing cost may also be logged without questionnaire answers or uploaded photos.
What RingMatcher does not sell
RingMatcher does not sell rings or personal data. If accounts, payment practices or providers, analytics providers, storage, or model providers change, this page should be reviewed before the changed service is offered publicly.
For privacy questions or requests, email contact@ringmatcher.com.