MATCH
Match Privacy Policy
Last updated: 19 September 2026
This Privacy Policy covers Match, Achefor’s soulmate-initial reading at achefor.com/match. On the site, Match is presented as SoulCypher. For the Achefor directory waitlist and the rest of the website, see the Achefor Privacy Policy.
What information you enter
To generate a Match result you submit:
- Name (required). The form asks “What’s your name?” and accepts a name up to 80 characters. This can be a first name or a fuller name. It is used to generate the reading.
- Date of birth (required). Used to generate the reading.
- Birth time (optional). If you add it, it adds more detail to the reading.
- Birth location (optional). If you add it, it adds more detail to the reading.
The calculator form does not ask for an email address, payment details, or a password.
Why the information is required
Name and date of birth are required because the Match engine uses them to produce the result. Birth time and birth location are optional. Leaving them blank still generates a full reading.
How the Match result is generated
The calculation is automated. The same name and birth details currently always produce the same result. Match uses numerology and astrology-inspired rules plus a SHA-256 fingerprint so the same inputs map to the same reading id. It is not a lookup of a real person, and no human reviews your case before the result is shown.
Achefor does not send your Match inputs to an AI service to generate the reading.
Whether the information is stored
Date of birth, birth time, and birth location are not stored. They are used in memory to generate the result, then discarded. The application rejects storing those fields on saved records.
Name is stored after you tap Reveal, even if you never enter an email. Achefor keeps a display form of the name with the reading fingerprint, strongest initial, public share id, and timestamps so the operator can see Reveals and so you can later attach an email to that reading.
Whether the result is stored
Yes. After Reveal, Match stores:
- An operator Reveal row — name, fingerprint, strongest initial, public share id, and timestamps. Email is empty until you keep the reading or pay to unlock it.
- A public share card — a random
/match/r/…link with the generated initials, example names, archetype, vibe scores, traits, meeting scene, and fingerprint. It does not include your name, email, or birth details. Anyone with the link can open it. Share images are generated from that card.
If you later keep a reading by email, or unlock it at checkout, Match also stores a magic-link account: email, name, the generated reading (not birth details), activity such as saved, opened, or paid, and timestamps. That account has no password.
When Achefor sends or queues a reading email, a local copy of that message is written to a mail outbox. The copy includes the email address, name, reading text, and private link.
Email is collected only if you choose to keep a reading (when checkout is off) or if you unlock through Stripe Checkout (when checkout is on). Stripe collects the checkout email. Achefor then stores that address on your Match account and can email the reading.
Keeping or unlocking a Match reading does not add your email to the Achefor directory waitlist. The waitlist is a separate form on the homepage.
Whether information is sent to third parties
- Hostinger hosts the app and the stored files.
- Stripe processes paid unlocks. Stripe receives the payment, the email you enter in Checkout, and metadata Achefor sends: the reading fingerprint and display name. Card details are handled by Stripe, not stored in Achefor’s files.
- Zoho Mail sends reading and magic-link emails when SMTP is configured. If SMTP is not configured, messages stay in the local mail outbox only.
- WhatsApp, Instagram, or Facebook receive a public card URL or image only if you choose to share from your device. Match does not upload your birth details to those apps.
- Google Analytics receives ordinary usage data on the live site, as described under cookies and analytics.
Achefor does not sell Match member lists and does not send Match inputs to an AI service.
Cookies and analytics
On the live site at achefor.com, Match pages load Google Analytics (gtag.js, measurement ID G-EM5MX14628), the same tag as the rest of achefor.com. Google may set cookies such as _ga to measure visits. The preview site at dev.achefor.com does not load Google Analytics.
achefor_memberis set only after you keep or unlock a reading. It is HttpOnly, limited to the /match path, SameSite=Lax, and lasts about 30 days. It holds a signed session so you can reopen readings. It is not used for advertising. Visitors who only generate a reading and leave do not get this cookie.- A short-lived signed reading ticket is posted in the unlock or keep form. It is not a cookie. It holds the generated reading and display name, not birth details, and expires in about two hours.
- A service worker may cache static files on your device so the app loads faster. It is told not to cache admin, checkout, webhook, paid, or email routes.
Admin uses a separate cookie. That cookie is not set for ordinary Match visitors.
IP address and technical information
The Match application does not write IP address, browser user-agent, or device IDs into its stored files. The hosting provider or a reverse proxy may log requests. This policy does not describe those host logs because they are not written by the Match application.
Data retention
Reveal rows, share cards, share images, member accounts, and mail-outbox copies are not deleted automatically. They remain until Achefor removes them.
How to request deletion
There is no in-product delete button. To ask Achefor to delete an email, name, reading, or share card, email privacy@achefor.com. Include the email address you used, and the reading fingerprint if you have it. Birth details cannot be deleted from storage because they are not stored.
Security
What Match actually does:
- Birth fields are blocked from stored records.
- Member and admin cookies are HttpOnly and SameSite=Lax. They are marked Secure in production.
- Reading tickets, magic links, and cookies are HMAC-signed.
- Stripe webhooks are checked with Stripe’s signing secret.
- The live site is served over HTTPS.
Stored JSON files and mail-outbox copies are not encrypted at rest by the application. Achefor does not claim a security certification.
Privacy rights
You can ask Achefor what Match data it holds about you, ask for a correction to a name or email, or ask for deletion. Email privacy@achefor.com.
Minimum age
Match is for people aged 18 or over. The calculator accepts a date of birth from 1900 through yesterday and does not currently verify that you are 18. Do not use Match if you are under 18.
How to contact Achefor about privacy
Email privacy@achefor.com.
Changes to this Privacy Policy
If this policy changes, Achefor will update this page and the date at the top.