Draft — pending legal review. This policy has not been reviewed by counsel and is not yet in effect. Placeholders are marked 【TODO: like this】.

Privacy policy

Here · Effective date: 【TODO: date, on counsel sign-off】

Here is a dating app that shows you to other people only while you're physically at a participating venue. That design decides most of what follows: we collect little, we keep it briefly, and the most sensitive thing we touch — your precise location — is used once and thrown away.

Here is operated by 【TODO: legal entity name】, based in Canada. Questions and privacy requests go to our privacy officer at privacy@ihere.ca.

What we collect, and why

Phone number

You sign in with your phone number, verified by a text-message code. It's your account identifier. We don't use it for marketing and we don't share it with other users.

Date of birth

Collected once at signup to enforce the 18+ requirement, and locked afterwards — it can't be edited. Other users see your age, never your date of birth.

Profile

Your name, 2–4 photos, and who you're looking to meet. Photos are compressed and stripped of metadata (EXIF, including any embedded location) on your device before upload, and every photo is scanned by automated moderation before anyone else can see it (see "Automated moderation" below).

Precise location

Used only while the app is open — never in the background. Your position is sent to our servers to confirm you're inside a participating venue (within a 40-metre ceiling of its centre). Other users never see your position, your distance, or your coordinates — only that you're at the same venue they are. The raw fix is discarded after that check; we don't keep a location history.

Messages

Chats exist between matched people at the same venue. Transcripts are deleted automatically about 30 days after a conversation ends. If a conversation is reported, the reported content is preserved separately as evidence for about 90 days.

Reports and blocks

If you report or block someone — or someone reports or blocks you — we keep a record. These records are retained even after an account is deleted, because they're what keeps a removed person from coming back to the people who reported them. They're never visible to other users.

Push token and crash data

If you allow notifications, we store a push token (issued via Expo) to send you exactly one kind of notification: a new match. The app also reports crash telemetry (Firebase Crashlytics) so we can fix what breaks.

Identity verification — only if offered, only if you choose it

Some versions of the app may offer optional identity verification through Persona, using a short video selfie. This feature may not be present in the first release; if it isn't in your app, none of this data is collected. Where it is offered: verification is voluntary and gates nothing — an unverified profile is not penalized. You give explicit consent at capture. The raw video is deleted by the vendor immediately after the check; we retain only the result and one reference frame, for about 12 months or until you delete your account, whichever comes first.

Automated moderation

Every profile photo is scanned before going live, using Google Cloud Vision and matching against known child sexual abuse material (CSAM). Confirmed CSAM is reported to the authorities — see our child safety standards. In-app reports are reviewed by people.

How long we keep things

DataKept
Raw location fixNot stored — discarded after the venue check
Chat transcripts~30 days after the conversation ends
Reported-content evidence~90 days
Raw verification video (if offered)Deleted by the vendor after the check
Verification result + one frame (if offered)~12 months, or until account deletion
Profile, photos, matches, presenceUntil you delete your account (completed within 30 days)
Reports and blocksRetained after account deletion, for safety

Who we share with

We don't sell your personal information, and there are no ads. We use a small set of sub-processors to run the service:

Sub-processorWhat for
Google Firebase (Google LLC)Sign-in, database, file storage, server functions, crash reporting
Google Cloud VisionAutomated photo moderation before photos go live
PersonaOptional identity verification — only if offered, and only if you choose to verify
ExpoDelivering the one push notification we send (a new match)

We may also disclose information where the law requires it — for example, a valid order from law enforcement, or the mandatory reporting described in our child safety standards.

Where your data lives

Our databases and file storage run in Google's Canadian cloud region (Montréal). Some processing by sub-processors — photo moderation and identity verification — may occur outside Canada.

Your rights

Under Canada's federal privacy law (PIPEDA) and, in Québec, Law 25, you can ask us what personal information we hold about you, ask us to correct it, and ask us to delete it. Deletion is built into the app — here's how — and works by email too.

To make a request, write to our privacy officer at privacy@ihere.ca. We'll verify it's you (usually by the phone number on the account) and respond within 30 days. If you're not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada, or in Québec, the Commission d'accès à l'information.

Children

Here is for adults. You must be 18 or older to create an account; date of birth is checked at signup and can't be changed afterwards. Accounts we suspect belong to minors are removed. See our child safety standards.

Changes

If this policy changes in a way that matters, we'll say so in the app before the change takes effect, in plain words.