Privacy Policy

Last updated: January 1, 2026 · Version 2.0

This Privacy Policy explains what personal data we process when you use HelloFriendo, why we process it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR). We try to keep this document plain-English; defined legal terms follow GDPR usage.

1. Who we are

The data controller for personal data processed via HelloFriendo is HelloFriendo, Inc.. Our full legal and registration details, including registered address, are listed in our imprint.

We have not formally appointed a Data Protection Officer because we are not required to under GDPR Art. 37. You can still reach our privacy team for any data-protection question at [email protected].

2. What data we collect

We only collect data that we genuinely need to operate HelloFriendo. The categories below cover everything we process.

Account data

When you create an account, we collect and store:

  • Email address (used for login, account recovery, and service notices)
  • Username and any aliases you choose for rooms
  • Password (stored only as a salted bcrypt hash — we never see your password in plain text)
  • Birth date (used to verify that you are at least 16; we store the date, not your daily age)
  • Timestamp and version of the Terms and Privacy Policy you accepted at sign-up

Profile data

Things you choose to add to your profile so other members can connect with you:

  • Values-quiz answers and the resulting archetype
  • Interests, languages you speak, and what you are looking for
  • Optional IRL location at city level plus a search radius — we do not store precise GPS coordinates
  • Avatar image and any decorative profile fields
  • Contact links (e.g. social handles, messaging IDs) which are only revealed to others on mutual consent

Room activity

When you participate in chat rooms we process:

  • Messages you send, including any media attachments
  • Warmth scores and signals derived from your interactions
  • Reveal decisions, mutual-reveal events, and whether a contact link was exchanged
  • Reports, blocks, and moderation actions tied to your account

Device and technical data

Automatically collected when you use the service:

  • IP address (used for security, rate limiting, and rough region detection)
  • User agent, browser, OS, and device type
  • Server logs of requests you make, including timestamps and endpoints
  • Push notification tokens — only if you explicitly opt in to push notifications

Billing data

Payments are handled by external providers (Stripe, Lemon Squeezy, or PayPal where enabled). We never see your full card number. We do store:

  • Subscription, customer, and invoice IDs returned by the payment provider
  • Plan, status, renewal date, and billing email
  • Invoice metadata required for accounting and tax records

Cookies and local storage

We use a small number of cookies and browser storage items. See the dedicated Cookies and local storage section below for the full list and how to manage them.

3. Why we process it (legal bases under GDPR Art. 6)

Every piece of data we process is tied to a specific purpose and a specific legal basis under Article 6(1) GDPR:

  • Account and service delivery — providing the app, your account, rooms, and reveals. Legal basis: performance of a contract (Art. 6(1)(b)).
  • Matching, anti-abuse, fraud prevention, and security — keeping members safe and rooms healthy, including limited automated decisions to flag suspicious behaviour. Legal basis: legitimate interests (Art. 6(1)(f)).
  • Marketing emails and optional analytics — newsletters and product updates, and any non-essential cookies. Legal basis: consent (Art. 6(1)(a)), which you can withdraw at any time without affecting the lawfulness of prior processing.
  • Billing, accounting, and tax — issuing and retaining invoices and similar records. Legal basis: legal obligation (Art. 6(1)(c)).

4. Sub-processors

We rely on a small set of vetted sub-processors that process personal data on our behalf under data processing agreements (DPAs):

  • Railway (US / EU regions) — application hosting, databases, and background workers.
  • Cloudflare R2 (EU / global edge) — object storage for avatars, attachments, and other media.
  • Stripe (US / Ireland) — payment processing where Stripe is enabled.
  • Lemon Squeezy / Paddle (US / EU, where enabled) — merchant-of-record payment processing as an alternative to Stripe.
  • PayPal (Luxembourg / US, where enabled) — payment processing for PayPal checkouts.
  • AWS SES (eu-central-1) — sending transactional emails such as verification, password reset, and notifications.
  • Sentry (currently not configured) — error and performance monitoring; will only be added with this Privacy Policy updated accordingly.

This list may change as we add or replace providers. If we plan to add a new sub-processor that processes personal data, we will update this page and notify registered users at least 30 days in advance so you can object.

5. International transfers

Some of our sub-processors (notably Stripe and AWS) may transfer or replicate personal data to countries outside the European Economic Area, including the United States. Where this happens, transfers are protected by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, additional safeguards such as encryption in transit and at rest. You can request a copy of the relevant safeguards by emailing [email protected].

6. How long we keep it

We keep personal data only as long as we need it for the purposes set out in this policy, or for as long as the law requires us to. In practice that means:

  • Active accounts: kept for as long as your account exists.
  • Room messages: kept for up to 90 days after a room closes, or until you delete your account — whichever comes first.
  • Security and audit logs: kept for 12 months, then deleted or further anonymised.
  • Marketing email consent: kept until you withdraw it; the record that you previously consented is retained as evidence of compliance.
  • Billing records: kept for the period required by tax and accounting law in our jurisdiction (typically 7–10 years).
  • Deleted accounts: we anonymise or delete personal data within 30 days of an account-deletion request, except where we are required to retain it (for example, for fraud prevention or tax obligations).

7. Your rights

Under GDPR Articles 15 to 22, you have the following rights regarding your personal data:

  • Right of access (Art. 15) — get a copy of the personal data we hold about you.
  • Right to rectification (Art. 16) — correct inaccurate or incomplete data.
  • Right to erasure (Art. 17) — the so-called right to be forgotten.
  • Right to restriction (Art. 18) — ask us to pause processing while a dispute is resolved.
  • Right to data portability (Art. 20) — receive your data in a machine-readable format.
  • Right to object (Art. 21) — object to processing based on legitimate interests, including profiling.
  • Right to withdraw consent (Art. 7(3)) — at any time, with no effect on past processing.
  • Right to complain — lodge a complaint with your local EU/EEA data protection authority.

8. How to exercise your rights

The fastest way to exercise most of these rights is through your account: in Settings → Privacy you can export your data or request account deletion. You can also email [email protected] from the address tied to your account and we will respond within one month, as required by GDPR Art. 12(3).

9. Cookies and local storage

We try to keep cookies to the minimum required to run a safe, working service. Categories we use, or reserve for future use:

  • Essential — session cookies, CSRF tokens, and the record of your cookie-consent choice. These cannot be disabled because the service would not work without them. Legal basis: legitimate interest / strict necessity (no consent required).
  • Analytics — currently none. This category is reserved; if we add privacy-friendly analytics later, they will only run after you give consent.
  • Marketing — currently none. This category is reserved; we do not run advertising cookies today.

You can review and change your choices at any time via Manage cookie preferences.

10. Children

HelloFriendo is intended for people aged 16 or older, in line with GDPR Art. 8 as implemented in most EU member states. We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe that your child has created an account, please contact us at [email protected] and we will delete the account and associated data.

11. Anonymity and reveal

HelloFriendo is built around staged, mutual reveal. A few product facts you should know:

  • Your username and any room aliases are not publicly linked to your legal identity.
  • Your contact links are private by default and only shared with another member after both sides agree to a mutual reveal.
  • Reveals are irreversible from our side: once a contact link has been shared with another member, we cannot retract it from their device.
  • We cannot recover messages that you or another member have deleted, and we cannot reconstruct rooms after their retention window has passed.

12. Security

We take reasonable technical and organisational measures to protect your data, including:

  • Passwords stored as salted bcrypt hashes — never in plain text.
  • TLS-encrypted transport for all traffic between your device and our servers.
  • Encryption at rest for databases and object storage at the infrastructure level.
  • Audit logs of sensitive operations, retained for 12 months.
  • Principle of least privilege for staff access to production systems.
  • You can help by using a strong, unique password and enabling any additional security features we offer.

13. Changes to this policy

We may update this Privacy Policy from time to time as our product or applicable law changes. The current version and last-updated date are shown at the top of this page. For material changes that affect your rights, we will notify registered users by email and, where appropriate, ask for renewed consent.

14. Contact

If you have questions about this Privacy Policy or how we handle your data, contact HelloFriendo, Inc. at [email protected]. Full legal and registration details are in our imprint.