Privacy Policy
Draft for legal review. Written to match how the Herelo app actually handles data. Have a lawyer check it against the Digital Personal Data Protection Act 2023, the IT Rules 2021 and the UK GDPR before launch, and fill in the bracketed details.
Who we are
Herelo is operated by [COMPANY LEGAL NAME], [REGISTERED ADDRESS], India ("Herelo", "we"). We decide why and how your personal data is used, which makes us the Data Fiduciary under India's Digital Personal Data Protection Act 2023.
The short version
- Herelo is for adults. You must be 18 or older.
- Other people never see your exact location, a map of where you've been, or where you live.
- Location features are off until you turn them on, and you can turn each one off at any time.
- We don't sell your data and we don't show third-party ads.
What we collect and why
| Data | Why | How long we keep it |
|---|---|---|
| Phone number | Sign-in with a one-time code; one account per number | Until you delete your account |
| Profile: name, birth date, gender, who you want to see, what you're looking for, photos, prompts, work, city, languages | Showing your profile to people you may match with; the 18+ check (others see your age, never your birth date) | Until you delete your account or remove the item |
| Verification selfie and the pose you were asked for | Confirming you're the person in your photos before you can check in at venues. Never shown on your profile. | 90 days after the decision, then deleted [CONFIRM] |
| Venue check-ins | Showing you to people at the same venue for up to 2 hours. Your coordinates are used once to confirm you're within 150 m and are not stored; only the venue is. | 30 days |
| Crossed-paths areas (only if you turn it on) | Finding people who passed the same ~220 m area in the same half hour. Areas where you're often found at night are treated as your home and never produce a match. | 14 days |
| Travel plans | Showing you in the destination city from 14 days (30 with Passport) before you arrive | Until you delete the trip or your account |
| Likes, matches and messages | Running the service; safety tips on messages that look like scams | Until you or your match unmatch, block, or delete the account |
| Reports, blocks and moderation decisions | Keeping people safe and handling complaints | Up to 3 years, longer if required by law [CONFIRM] |
| Device push token | Sending the notifications you've chosen | Until you sign out, or 270 days unused |
| Purchase records | Giving you what you paid for (Plus, Passport, Spotlight); tax and accounting | 8 years, as Indian tax law requires [CONFIRM] |
| Waitlist email, city, gender and what you're looking for (both optional), referral code | Telling you when Herelo opens in your city; inviting people in an order that keeps the community balanced | Until launch plus 12 months, or until you unsubscribe |
Automated safety checks
To keep Herelo safe, photos are automatically checked for nudity, violence, hate symbols and people who appear to be under 18; verification selfies are compared with your profile photos; and messages and profile text are checked for hate speech, threats and severe harassment. Some decisions are made automatically, such as removing a photo or hiding an abusive message. Borderline cases go to a trained person. You can ask for any automated decision to be reviewed by a person by writing to [safety@herelo.app].
Who we share data with
Other Herelo users see your profile card, never your phone number, birth date, exact location or verification selfie. We use these service providers, under contracts that limit them to providing their service to us:
- Supabase: database, file storage and sign-in, hosted in Mumbai, India.
- Amazon Web Services: photo and selfie checks in Mumbai, India; message toxicity checks in the United States.
- Google Firebase: delivering push notifications.
- An SMS provider [Twilio / MessageBird]: sending sign-in codes.
- Apple, Google, RevenueCat and Razorpay: processing payments. We never see your full card details.
We share data with authorities only when Indian law requires it, or to protect someone from serious harm.
Transfers outside India
Most data stays in India. Message text checked for abuse and push notifications pass through servers in other countries, including the United States, and travel-mode users are matched with people in their destination country. These transfers follow the DPDP Act and any countries it restricts.
Your rights
You can, at any time:
- see and correct your profile in the app;
- withdraw consent for any location feature by switching it off;
- ask for a summary of the personal data we hold about you and who we've shared it with;
- delete your account in Settings (or see how to delete your account), which erases your profile, photos, matches and messages straight away, except records we must keep by law;
- nominate someone to exercise these rights if you die or can't act yourself;
- complain to our Grievance Officer, and if you're not satisfied, to the Data Protection Board of India.
UK users also have the rights in the UK GDPR, including objecting to processing and complaining to the Information Commissioner's Office.
Grievance Officer
[NAME], Grievance Officer
[grievance@herelo.app] · [ADDRESS]
We acknowledge complaints within 24 hours and resolve them within 15 days.
Changes
If we change this policy in a way that affects you, we'll tell you in the app before it takes effect.