Privacy Policy

Effective September 18, 2026

  1. Who we are
  2. What we collect
  3. Your photos, specifically
  4. How we use your data
  5. What your paired partner sees
  6. Legal bases (GDPR)
  7. Third parties
  8. Retention and deletion
  9. Your rights
  10. California residents
  11. Security
  12. International transfers
  13. Children
  14. Cookies and this website
  15. Changes to this policy
  16. Contact us

Have We Met? exists to show two people the moments their paths nearly crossed. Doing that requires touching some of the most personal data a phone holds — where you have been, and when. This policy explains exactly what we collect, what we don't, and the choices you keep at every step. The short version: matching uses your photos' location and time metadata, your photos themselves stay on your phone unless you deliberately reveal them, and everything you contribute can be deleted.

1. Who we are

Have We Met LLC ("we", "us") operates the Have We Met? iOS application and this website. We are the data controller for the personal data described in this policy.

Have We Met LLC
4653 Carmel Rd, STE 308 #AA152
San Diego, CA 92130
United States

Contact: privacy@havewemetapp.com

2. What we collect

Data you provide

Data collected automatically

What we do not collect

3. Your photos, specifically

Photo access uses Apple's photo library permission, which you can limit or revoke at any time in iOS Settings. Within the app:

4. How we use your data

We do not use your data for advertising, we do not sell it, and we do not train machine-learning models on your photos or locations.

5. What your paired partner sees

Pairing is user-initiated: a session exists only when one of you creates it and the other joins with the code. Within a session, your partner sees:

Your partner does not see your unmatched photos, your unmatched locations, or anything about parts of your library that didn't cross theirs. Pair with people you trust: matched locations are shared with your partner by design, and the app cannot control what a partner does with information they've seen. See Trust & Safety for guidance.

7. Third parties

We use a small number of service providers to run the service, each bound to protect your data to at least the standard of this policy, as required by our agreements with them and by Apple's guidelines:

These providers process data only on our behalf and only for the purposes above. We do not sell your data, and we do not share it with advertisers, data brokers, or any parent or subsidiary entity. We may disclose data if legally compelled, and we will tell you unless the law forbids it.

8. Retention and deletion

Deleting a session removes its data for both participants, since a session's results are inherently shared. Results you have already seen stay on your own phone until you start a new session or close the app.

9. Your rights

Depending on where you live, you have the right to access, correct, export, restrict, object to the processing of, and delete your personal data. To exercise any of these, email privacy@havewemetapp.com from the device or address connected to your request. We respond within 30 days. If you are in the EU/EEA or UK, you may also lodge a complaint with your supervisory authority.

10. California residents

Under the CCPA/CPRA: we collect the categories described in Section 2 (identifiers you provide, geolocation contained in photo metadata, photos you reveal, and the crash, usage, and log data described there); we use them for the purposes in Section 4; and we do not sell or share your personal information as those terms are defined in California law, and have not in the preceding 12 months. You have the rights to know, delete, correct, and to not be discriminated against for exercising them. Submit requests to privacy@havewemetapp.com.

11. Security

Data is encrypted in transit (TLS) and at rest. Session access requires the session code held by the two participants. Revealed photos are stored as compressed copies scoped to their session. No system is perfectly secure; if a breach affects your data we will notify you as required by law.

12. International transfers

Our servers are located in the United States. If you use the app from elsewhere, your data is transferred to and processed in the US. Where GDPR applies, transfers rely on standard contractual clauses with our providers.

13. Children

Have We Met? is not directed at children and is not for use by anyone under 16. We do not knowingly collect data from children; if you believe a child has used the app, contact us and we will delete the data.

14. Cookies and this website

This website is static and sets no cookies, no analytics, and no trackers. Font files are served by Google Fonts, which receives the standard technical request data involved in serving a file.

15. Changes to this policy

If we change this policy in a way that matters, we will update the effective date above and note the change in the app before it takes effect. Continued use after a change means the new policy applies.

16. Contact us

Questions, concerns, or requests: privacy@havewemetapp.com. General support: support@havewemetapp.com or the Support page.