its me← Back

Privacy Policy

Effective 2026-08-04

Our approach

its me is built around a simple promise: the platform helps you find people near you who want to meet in person, then gets out of the way. We collect only what we need to make that work. We never sell or license data that can be tied back to an individual user.

1. What we collect

  • An anonymous account identifier generated when you first open the Service. No email, name, or password is required to create an account.
  • Approximate location — the app requests your current location when you choose to be visible, then snaps it to a roughly 100-meter grid before storage. We store the latest coarse point, not a route or location history. A visible session lasts up to 15 minutes.
  • Profile content you provide — display name, short biography, and up to four photos. You may leave any of these blank and remove them at any time.
  • Activity signals — the time you were last active, and the record that you sent a “hey there” to another user (and vice versa).
  • An authentication cookie required to keep your anonymous session signed in. We do not use third-party advertising cookies.
  • Minimal operational events — the event name, first-party page path, coarse country and device family, timestamp, and a salted network-address hash that rotates daily. We do not use canvas, audio, font, plugin, battery, or hardware fingerprinting.
  • Information you send through Contact — your email, message, request type, account identifier when signed in, and a daily rotating network-address hash used to limit spam.

2. What we do with it

  • Show you to other opted-in users on the map.
  • Show other opted-in users to you.
  • Deliver the “hey there” greeting and inform both parties when it is mutual.
  • Protect the Service from abuse — including bot detection, content moderation, and investigating reports.
  • Understand reliability and the basic connection funnel through privacy-minimal first-party events and aggregated counts.

3. Aggregate data & commercial use

We may use aggregated, de-identified counts to operate and understand the Service. We do not sell or license individual user data, profile content, contact requests, or location data. We will not attempt to re-identify data that has been de-identified.

4. Who we share it with

We share data only with the service providers we need to operate:

  • Supabase — database, authentication, and storage hosting.
  • DigitalOcean — application hosting and content delivery.
  • Cloudflare — domain, traffic delivery, and bot protection when enabled.
  • Google and Stripe — only when you choose Google account linking or optional identity verification.

Each processor handles your data under its own privacy and security terms and is contractually limited to providing the service we engage them for.

5. Visibility & your control

You control whether you appear on the map at all. The visibility toggle in your profile takes effect immediately. When visibility is off, no other user can see you or send you a greeting.

6. Retention & deletion

We retain profile and activity data while your account is active and operational events only as long as reasonably needed for reliability, security, and measurement. Contact requests are set to expire after 90 days unless they must be preserved for an active request, dispute, safety incident, or legal obligation. You may ask us to delete your account and associated data through our Contact page. Aggregate data that cannot reasonably be linked back to you may remain. We may preserve limited records when required by law.

7. Children

The Service is intended for users 18 and older. We do not knowingly collect information from anyone under 18. If we learn that we have collected information from a minor, we will delete it promptly.

8. Your rights

Depending on where you live, you may have the right to access, correct, port, or delete personal information we hold about you, and to object to or restrict certain processing. To exercise these rights, contact us at the address below. We will not discriminate against you for exercising any right under applicable law.

9. Security

All traffic to and from the Service is encrypted in transit. Access to user data is restricted at the database layer by row-level security: a signed-in user can read only profiles that are affirmatively visible and can modify only their own record. No system is perfectly secure; we cannot guarantee absolute security of any information transmitted to or stored by us.

10. International users

The Service is operated from the United States. By using it, you consent to the transfer of your information to the United States for processing.

11. Changes to this policy

We may update this policy from time to time. Material changes will be posted on this page with a new effective date.

12. Contact

Submit privacy questions, deletion requests, access requests, and other rights inquiries through our Contact page.