here for hello← Back

Privacy Policy

Effective 2026-09-02

Our approach

HERE FOR HELLO LLC, an Oregon limited liability company, controls the personal data described in this policy when you use the Here for Hello service. Here for Hello is built around a simple promise: the platform helps you find people near you who want to meet in person, then gets out of the way. We collect only what we need to make that work. We do not sell or license personal data or aggregate product-usage data, and we do not share personal data for cross-context behavioral advertising. Read the same commitments in plain language in our Privacy Promise.

1. What we collect

  • An anonymous account identifier generated when you choose to join the Service. No email, name, or password is required to create an account.
  • Approximate location — after a separate explanation and your affirmative choice, the app requests one current location snapshot and reduces it to a roughly 100-meter grid. The live service uses that coarse point for up to 15 minutes to decide which profiles are nearby. It does not continuously follow your movement, and a heartbeat cannot extend the sharing window. Other users receive no coordinate, distance, direction, route, or person-level map position. Tapping Stop sharing, or reaching the end of the window, clears the point from the live profile. An expired copy may remain in encrypted, access-controlled infrastructure backups until those backups age out; backups are not used for discovery.
  • City estimate before sharing — we use the network address of your connection to estimate a city with a database hosted by us. The estimate can be wrong, especially with a VPN. This does not request device location or make you visible. We do not save the estimate or network address in your profile. Before sharing, the map shows geography only, not live activity counts, people, or person-level positions.
  • Profile content you provide — display name, short biography, and one profile photo. You may leave any of these blank and remove them at any time.
  • Activity signals — the time you were last active, and the record that you sent a “hello” to another user (and vice versa).
  • Plans you create or join — a verified host may publish a title, activity, start and end time, short description, public place name, and an exact meeting point selected on the map. These details, the host’s display name and ID-checked status, and a total attendee count are visible to signed-in people nearby. We keep a private record of who joined so each person can manage their own response; we do not publish an attendee roster.
  • An authentication cookie required to keep your anonymous session signed in. We do not use third-party advertising cookies.
  • A consent receipt containing your account identifier, the versions of the age notice, Terms, and Privacy Policy you accepted, the button used, and a server timestamp. It contains no birth date, IP address, or location.
  • Optional identity-check information — if you choose the paid Stripe Identity check, Stripe collects and processes identity document images, facial images, document information, fraud signals, and information about the device connecting to its service. Stripe stores submitted images, extracted information, and verification results in its systems, including as a processor on our behalf. Authorized Here for Hello Stripe-account administrators can access some captured images, extracted information, and results through Stripe; Stripe does not provide us the biometric identifiers used for the face comparison. Our product database stores only the result, completion time, payment state, and opaque Stripe session references. We do not download or copy the ID or selfie into our product database or photo storage. The public mark reports only that the ID-and-selfie match completed; it is not a background check or safety guarantee. Verification is optional for nearby discovery, greetings, and joining a Plan, and declining it does not limit those free features. Hosting a Plan requires an active ID-checked status. Stripe presents its own notice and consent choices before capturing identity information; do not continue with that optional flow if you do not consent to Stripe's described processing.
  • Minimal operational events — the event name, plus an hourly server-time bucket. These events contain no account identifier, network-address hash, page path, country, device, browser, or operating system. We do not use canvas, audio, font, plugin, battery, or hardware fingerprinting.
  • Information you send through Contact or the Request center — the contact and request details you choose to provide, the case deadline and status, and your account identifier when signed in. The legal queue does not store your IP address or a network-address hash.

2. What we do with it

  • Show you to other opted-in users on the map.
  • Show other opted-in users to you.
  • Deliver the “hello” greeting and inform both parties when it is mutual.
  • Publish time-bounded Plans nearby and manage private attendance responses.
  • Protect the Service from abuse — including bot detection, content moderation, and investigating reports.
  • Understand reliability and the basic connection funnel through privacy-minimal first-party events and aggregated counts.

3. Aggregate data

We use delayed, thresholded, de-identified counts internally to operate and improve the Service. We do not sell or license those reports or any individual user data, identifiers, profile content, contact requests, relationship records, sensitive traits, or location data.

4. Who we share it with

We share data only with the service providers we need to operate:

  • Supabase — database, authentication, and storage hosting.
  • DigitalOcean — application hosting and content delivery.
  • Cloudflare — domain, traffic delivery, and bot protection when enabled.
  • Google or Apple — when you choose the corresponding account sign-in. Separately, uploaded profile photos are sent to Google Cloud Vision SafeSearch for automated safety screening before publication, whether or not you use Google sign-in. The scanner sends the image for classification; it does not send your approximate location or account profile as part of that request.
  • Stripe — payment processing and, only when you choose it, the optional government-ID and selfie check. Here for Hello and Stripe each act as independent controllers for some personal data, while Stripe also processes verification data on our behalf. Stripe uses information to provide, secure, analyze, and improve its payment, fraud, and identity services. Stripe may use service providers and, where legally required, disclose information to governmental authorities. Processing can involve a transfer to the United States. Learn more in the Stripe Privacy Policy.

Map archives are served from Here for Hello's dedicated DigitalOcean storage. Your browser requests map data from that storage without account cookies or referrers. City and ZIP-area searches use a local reference index rather than sending your query to a geocoding service. Our hosting and traffic delivery providers receive network requests, and archive byte ranges can reveal which map area is viewed. Map sources and attribution are identified on the map. Geographic coverage and available detail depend on the published archive regions.

Each processor handles data under its own privacy and security terms. We configure access for the service being provided and review the applicable processor terms and settings before launch.

5. Visibility & your control

You control whether you appear on the map at all. The visibility toggle in your profile takes effect immediately. When visibility is off, no other user can see you or send you a greeting. During a visible session, nearby people receive a rotating encounter identifier rather than your account identifier. A new identifier is created when a new visible session begins.

A Plan’s meeting point is separate from your visibility point. When a verified host publishes a Plan, the chosen public meeting point remains visible with that invitation until the Plan ends or is canceled. It does not update as the host moves and is not used to build movement history.

6. Retention & deletion

We retain profile and relationship data while your account is active. Approximate location is cleared from the live profile when sharing stops and automatically when the 15-minute session expires. An expired copy may remain in encrypted, access-controlled infrastructure backups until the applicable backup expires; it is not returned to the app or used for discovery. Location-free operational counters are retained only as long as reasonably needed for reliability and measurement. Contact requests are set to expire after 90 days unless they must be preserved for an active request, dispute, safety incident, or legal obligation. You may ask us to delete your account and associated data through our Contact page. Aggregate data that cannot reasonably be linked back to you may remain. We may preserve limited records when required by law. You can request account deletion from your profile. We withdraw your profile from discovery and freeze hosted Plans while a manual preservation and erasure review is pending. Already issued photo links may remain usable for up to five minutes. The request screen provides a reference and a review date within seven days; that is a review commitment, not a claim that erasure is complete. We retain the account and associated data pending that decision and must address any justified retention scope and timeline, not retain everything indefinitely. The Contact page remains available for updates, access, correction, portability, and other privacy requests. Where applicable and permitted after preservation review, erasure includes requesting irreversible redaction of a Stripe Identity session and its related verification reports, events, and request logs. A request to Stripe is not confirmation of completed redaction. Stripe says its redaction process may take up to four days. Stripe says biometric identifiers used for verification, fraud, and security are removed within one year, and that it typically retains other submitted identity information for three years unless it is deleted sooner or law permits or requires longer retention. Those periods concern information held in Stripe's systems; Here for Hello does not store the ID or selfie in its own database. For personal data Stripe controls independently, including requests to withdraw consent for Stripe's future use of biometric information, contact Stripe Support.

Active and recently ended Plans, including their selected meeting point and private attendance records, are scheduled for deletion 30 days after the Plan ends, unless a report, safety incident, dispute, or legal obligation requires limited preservation. A restricted hold identifies the matter, records, reason, decision owner, and review date. When the hold is released, the ordinary 30-day deletion rule resumes; a hold does not authorize unrelated or indefinite retention.

7. Children

The Service is intended for users 18 and older. We do not knowingly collect information from anyone under 18. If we learn that we have collected information from a minor, we will delete it promptly.

8. Your rights

Depending on where you live, you may have the right to access, correct, port, or delete personal information we hold about you, and to object to, restrict, or obtain information about certain processing. Because we do not sell personal information or use it for targeted advertising, there is no sale or targeted-advertising opt-out to enable. We will not discriminate against you for exercising a right under applicable law.

Submit a request through the Request center below. Where applicable law permits, an authorized agent may submit for you; we may ask for proof of the agent's authority and may verify the request directly with you. If we deny a privacy request, submit a new Request center case and choose “Appeal a privacy-request decision.” We will explain the result and provide any further complaint path required by applicable law.

9. Security

All traffic to and from the Service is encrypted in transit. Access to user data is restricted at the database layer by row-level security: a signed-in user can read only profiles that are affirmatively visible, their own profile, and relationship records they are a party to, including the other person's display name. Users can modify only their own profile. No system is perfectly secure; we cannot guarantee absolute security of any information transmitted to or stored by us.

10. International users

The Service is operated from the United States. By using it, you consent to the transfer of your information to the United States for processing.

11. A change of ownership

A merger, acquisition, financing, reorganization, bankruptcy, or sale of assets does not erase the promises that applied when we collected your information. A successor must continue to apply those promises to existing information. Before previously collected information can be used or disclosed in a materially broader way, we or the successor must give you a clear explanation and obtain your affirmative consent. If that consent is not obtained, the information remains subject to the original promises or must be deleted, except where limited retention is required by law.

12. Changes to this policy

We may update this policy from time to time. Changes will be posted on this page with a new effective date. A material revision will also be presented through a renewed “Agree and continue” action before you can enter the Service. We will not apply a material expansion in the collection, use, sale, licensing, or disclosure of previously collected personal information without a clear notice and your affirmative consent.

13. Contact

Submit privacy questions, deletion requests, access requests, appeals, and other rights inquiries through our Request center, or mail HERE FOR HELLO LLC, 3601 S River Pkwy Unit 311, Portland, OR 97239, USA.