I'M HERE

Privacy Policy

I'M HERE · Version 1.0 · Effective:

This app helps people who are in the same place at the same time meet briefly. Location is the most sensitive data we handle, which is why we keep it for the shortest time. Below is what we collect, why, and how long we keep it — without overstating any of it.

1. Who is responsible

The controller of your personal data is Mert Dolu, based in the United Kingdom. You can reach us at info@useimhere.com about anything in this policy.

The app is distributed in the United Kingdom only and is for people aged 18 and over.

2. The short version

3. What we collect

DataWhat it isWhy
AccountYour email address, a random identifier we assign you, account status, language and time zoneSo your account exists and you can sign in
ProfileDisplay name, the text you write about yourself, your photo, interests, languages you speakSo others can decide who they want to meet
Private profileDate of birth, gender, occupation, and your visibility choices for eachThe 18+ check, and letting you choose what is shown
LocationYour coordinates, measurement accuracy, an area code, and a technical flag for spoofed locationFinding people near you. See section 4
SessionWhen you said you were here, when it ends, its stated purposeRunning the 30-minute window
InteractionsRequests sent and received, connections made, your continue decision, your blocksCore functionality
MessagesThe text of your messagesThe chat. Message text is never written to any log
Contact sharingThe phone number, Instagram, email or other detail you choose to shareSo you can continue off the app. You can withdraw it
ReportsWho you reported, the category, and your noteSafety. No user can read these files
Technical recordsOperation receipts, abuse counters, invitation code recordsPreventing duplicate operations and abuse

Two things we keep elsewhere, two we do not keep

Your email address lives only in the sign-in system, not in the app database, and is never shown to another user.

We do not store your IP address. We generate an irreversible fingerprint of it for abuse counters. The raw address is never written to any record.

Hidden photo data is stripped. Uploaded images are re-processed and embedded capture information — including the coordinates where the photo was taken — is not retained.

We do not want special category data. We do not ask about your health, religious or political views, ethnicity or sexual orientation, and we ask you not to put them in your profile.

4. Location

Location is the most sensitive data here. Three things matter.

Nobody sees where you are

Your coordinates stay on the server. No user can see your point, their distance from you, or your direction. Others are only told you are nearby. The coloured density you see on the map reflects how busy an area is, not individual people.

Location is deleted in three stages

StageWhat happensWhen
1Your coordinates are recordedWhen you say you are here
2Coordinates and area code are erasedAs the session ends; within 24 hours at the latest
3The remaining record, with no coordinates in it, is deleted entirelyAfter 7 days

If you end the session yourself or delete your account, this erasure is brought forward. It can never be postponed.

The map provider never receives your location

Map imagery is served by OpenFreeMap. Your location, identity and account data are not sent to that provider. There is no advertising or tracking software in the map component.

5. Why we process your data, and on what basis

PurposeLawful basis (UK GDPR)
Creating your account, matching you with people nearby, running the chatPerformance of a contract — Article 6(1)(b)
Reviewing reports, enforcing blocks, preventing spoofed location and abuseLegitimate interests — Article 6(1)(f): user safety
Enforcing the 18+ limitLegitimate interests — Article 6(1)(f): protecting children
Keeping aggregate, non-identifying usage statisticsLegitimate interests — Article 6(1)(f): improving the service
Responding to lawful requestsLegal obligation — Article 6(1)(c)

You can withdraw your device's location permission at any time in your phone's settings. The core function of the app will not work without it.

6. How long we keep things

DataRetention
Precise location (coordinates)End of session; 24 hours at most
Session record without coordinates7 days
Messages, continue decisions, shared contact details30 days after the chat stops being writable
Ended meeting requests30 days
Pair cooldown records30 days
Notification queue7 days
Notification replay protection24 hours
Report files90 days after the file is closed
Operation receipts and abuse counters24 hours
Server logs14 days
Backups30 days
Aggregate statistics (non-identifying)90 days
Empty trace of a closed connectionIndefinite
Your profile and accountUntil you delete it

About that last row: when a chat is cleared, the connection record itself is not deleted but is emptied. All that remains is the fact that a connection existed and closed; no identity fields and no content remain. It is never displayed anywhere in the app and exists to stop the same connection being reopened by mistake.

7. What happens when you delete your account

Plainly

When you delete your account, your messages remain in the chat on the phone of the person you spoke to. Your name, photo and profile are deleted and they can no longer reach you — but the text of what you wrote is part of their own chat history, so it is not deleted.

Those messages do not stay forever either. Messages are deleted 30 days after a chat stops being writable. A chat stops being writable in three ways: it closes, it becomes read-only after both of you decide to continue, or the message allowance runs out. The clock starts at whichever happens first. No chat keeps messages indefinitely. You are warned in the app a week before messages are deleted. You are not shown an exact date or a countdown — only which stage the chat is at. We tell you something has been deleted only once it actually has been.

We do not tell you that the other side's copies were deleted, and we make no such promise.

The moment you request deletion, your access ends, any open session closes, your location is queued for erasure and pending requests lapse. We then delete, in order: your sign-in record and email address, your profile and date of birth, your photo file, your location records, your requests, your continue decisions, the contact details you shared, and your operation receipts.

Your identity in report files

If there is an open report involving you, your identity fields in that file are not deleted but replaced with a pseudonym, so an open safety review can continue even if the reported person deletes their account.

We will also tell you the limit of that: this pseudonym is not anonymisation. Someone with access to the database could reverse it. It protects against an outside party and against someone using the admin screens; it does not protect against someone with access to the system itself.

8. Who we share data with

We do not sell your data. We do not share it with ad networks, data brokers or marketers. There are two providers we need to run the service:

ProviderForWhat is sent
Google FirebaseSign-in, database, photo storage, server functions and later notificationsThe data described in this policy. Your email address only in the sign-in system
OpenFreeMapMap imageryOnly requests for the map area shown on screen. Your location, identity and account data are not sent

We chose not to use another map provider because its tracking could not be switched off.

Beyond this, we share data only where we are legally required to, in response to a valid legal request.

9. Where your data is held

Your data is held on servers in the United Kingdom, in the London region. The database, the file storage and the server functions that process your data are all located there — your data is not only stored in the UK, it is processed there.

Our provider, Google, may access this data from outside the United Kingdom in the course of maintenance and support. Where that happens, the transfer relies on the safeguards required by the UK GDPR.

10. Your rights

UK data protection law gives you the right to:

Write to info@useimhere.com. We respond within one month.

If you are unhappy with our response you can complain to the UK regulator, the Information Commissioner's Office, at ico.org.uk/make-a-complaint. We would prefer you came to us first, but you do not have to.

11. Security

The app cannot reach the database directly; every operation goes through checked server functions, and the database rules refuse direct access outright. Photos are held in private storage and opened only through time-limited addresses. Invitation codes are never stored in plain form.

No system is perfect. If a breach affects your personal data, we will make the notifications the law requires.

12. 18+ only

This app is for people aged 18 and over. The age check runs on the server; a claim made by the app is not accepted. If we learn an account belongs to someone under 18 we close it and delete the data.

13. Changes to this policy

When we update this policy we change the version number and date on this page. For significant changes we will tell you in the app.

14. Contact

For anything: info@useimhere.com

Privacy Policy · Version 1.0 · Draft · I'M HERE