Privacy Policy
Effective September 18, 2026
Have We Met? exists to show two people the moments their paths nearly crossed. Doing that requires touching some of the most personal data a phone holds — where you have been, and when. This policy explains exactly what we collect, what we don't, and the choices you keep at every step. The short version: matching uses your photos' location and time metadata, your photos themselves stay on your phone unless you deliberately reveal them, and everything you contribute can be deleted.
1. Who we are
Have We Met LLC ("we", "us") operates the Have We Met? iOS application and this website. We are the data controller for the personal data described in this policy.
Have We Met LLC
4653 Carmel Rd, STE 308 #AA152
San Diego, CA 92130
United States
Contact: privacy@havewemetapp.com
2. What we collect
Data you provide
- Photo metadata. When you run a scan, the app reads the location coordinates and timestamps attached to photos in your library and uploads that metadata to our servers so it can be compared with your partner's. We do not upload the images themselves during a scan.
- Revealed photos. If — and only if — you choose to reveal photos to your paired partner, compressed copies of those specific photos, with their location and camera metadata removed, are uploaded so your partner can view them.
- Session details. The session code that pairs you, the optional month/year you say you met, and the optional first name you enter (8 characters or fewer).
- Messages to us. Anything you send to support, including your email address if you write to us.
Data collected automatically
- Crash reports. If the app crashes or hits an error, a report goes to our crash-reporting provider: the error and its stack trace, the app and iOS version, the device model, and the sequence of screens that led up to it. Session codes and internal identifiers are removed before a report leaves your phone. Crash reports never contain photos, coordinates, or names.
- Usage analytics. We record which steps of the app were reached and which controls on the results screen were used, with counts and durations — for example, how many photos a scan covered, how long it took, and how many moments were found — plus the app version and a random identifier created when the app is installed. These events never contain photos, coordinates, place names, first names, or session codes. The identifier is not linked to your identity and is not used to follow you across other apps or websites.
- Performance timings. How long a scan, an upload, or a comparison took, sent to our own servers so we can keep the app fast.
- Server logs. Like any internet service, our servers see the IP address and basic details of each request. We use them to limit abusive traffic and to secure the service, and keep them no longer than 30 days.
What we do not collect
- No advertising identifiers, no cross-app tracking, no data brokers.
- No contact list, no continuous or background location — the only location data we see is what your chosen photos already carry.
- No content analysis of your images. Matching is arithmetic on coordinates and clocks, not computer vision on pictures.
3. Your photos, specifically
Photo access uses Apple's photo library permission, which you can limit or revoke at any time in iOS Settings. Within the app:
- Scanning reads metadata only. Your images are not transmitted, stored, or analyzed by us during a scan.
- Before any photo reaches your partner, you pass through a review screen where you select exactly which photos to reveal, one by one. Nothing is revealed by default — revealing is always an action you take.
- Photos you reveal may appear on moment cards your partner shares (this is disclosed again in the app at the moment of reveal).
- You can revoke a revealed photo afterward, which removes it from your partner's view and from our servers. Revocation cannot un-see what a person has already seen.
4. How we use your data
- To find your moments — comparing the two libraries' metadata to compute crossings, categories, and distances. This is the product.
- To show revealed photos to the one partner you chose.
- To operate and improve the service — fixing crashes, keeping it fast, and understanding which parts of the app are used so we know what to build next.
- To respond to you when you contact support.
We do not use your data for advertising, we do not sell it, and we do not train machine-learning models on your photos or locations.
5. What your paired partner sees
Pairing is user-initiated: a session exists only when one of you creates it and the other joins with the code. Within a session, your partner sees:
- The matched moments — the places, dates, times, and distances where your two libraries crossed. This necessarily discloses to your partner that you were at those matched places at those times.
- Your first name, only if you entered one.
- The met date, if either of you set one (only the session creator can set it).
- Your revealed photos, only after you review and reveal them.
Your partner does not see your unmatched photos, your unmatched locations, or anything about parts of your library that didn't cross theirs. Pair with people you trust: matched locations are shared with your partner by design, and the app cannot control what a partner does with information they've seen. See Trust & Safety for guidance.
6. Legal bases (GDPR)
- Consent — reading your photo library's location metadata, and each reveal of a photo. You can withdraw consent by revoking photos, ending a session, or revoking photo permission in iOS.
- Performance of a contract — running the comparison and showing results within a session you initiated or joined.
- Legitimate interests — crash reports, usage analytics that are not tied to your identity, and server logs, to keep the service reliable, secure, and improving.
7. Third parties
We use a small number of service providers to run the service, each bound to protect your data to at least the standard of this policy, as required by our agreements with them and by Apple's guidelines:
- Cloud hosting and storage — Railway (application servers) and Supabase (database and file storage), which hold session data, uploaded metadata, and revealed photos.
- Place names — to label a matched moment with a place ("Sorrento, Italy"), the coordinates of that matched moment are sent to a reverse-geocoding provider, BigDataCloud. Only matched moments are sent, never the rest of your library, and nothing that identifies you goes with them.
- Crash reporting — Sentry receives the crash reports described in Section 2.
- Product analytics — PostHog receives the usage events described in Section 2.
- Map imagery — moment maps are rendered using Google Maps; map tiles are requested with the matched coordinates needed to draw them, subject to Google's privacy policy.
These providers process data only on our behalf and only for the purposes above. We do not sell your data, and we do not share it with advertisers, data brokers, or any parent or subsidiary entity. We may disclose data if legally compelled, and we will tell you unless the law forbids it.
8. Retention and deletion
- Sessions are short-lived. A session expires 24 hours after it is created. There is nothing to cancel and no account to close.
- Scan records. The location and time records from your scan are deleted within 24 hours of the session expiring, except the handful that describe a matched moment, which are deleted together with the moment 7 days later.
- Matched moments and revealed photos are deleted 7 days after the session expires. The week of grace is so a partner who reopens the app can still see what they were sent.
- Session records — the session code, the optional first names, and the optional met date, with no photos or locations — are deleted 30 days after the session expires. We keep them that long to answer support questions.
- Revoked photos are deleted from our servers when revoked.
- Deletion requests — you can request deletion of everything tied to your sessions at any time; see Delete your data. We complete deletion requests within 30 days.
- Crash reports are kept no longer than 90 days, usage analytics no longer than 12 months, and server logs no longer than 30 days.
Deleting a session removes its data for both participants, since a session's results are inherently shared. Results you have already seen stay on your own phone until you start a new session or close the app.
9. Your rights
Depending on where you live, you have the right to access, correct, export, restrict, object to the processing of, and delete your personal data. To exercise any of these, email privacy@havewemetapp.com from the device or address connected to your request. We respond within 30 days. If you are in the EU/EEA or UK, you may also lodge a complaint with your supervisory authority.
10. California residents
Under the CCPA/CPRA: we collect the categories described in Section 2 (identifiers you provide, geolocation contained in photo metadata, photos you reveal, and the crash, usage, and log data described there); we use them for the purposes in Section 4; and we do not sell or share your personal information as those terms are defined in California law, and have not in the preceding 12 months. You have the rights to know, delete, correct, and to not be discriminated against for exercising them. Submit requests to privacy@havewemetapp.com.
11. Security
Data is encrypted in transit (TLS) and at rest. Session access requires the session code held by the two participants. Revealed photos are stored as compressed copies scoped to their session. No system is perfectly secure; if a breach affects your data we will notify you as required by law.
12. International transfers
Our servers are located in the United States. If you use the app from elsewhere, your data is transferred to and processed in the US. Where GDPR applies, transfers rely on standard contractual clauses with our providers.
13. Children
Have We Met? is not directed at children and is not for use by anyone under 16. We do not knowingly collect data from children; if you believe a child has used the app, contact us and we will delete the data.
14. Cookies and this website
This website is static and sets no cookies, no analytics, and no trackers. Font files are served by Google Fonts, which receives the standard technical request data involved in serving a file.
15. Changes to this policy
If we change this policy in a way that matters, we will update the effective date above and note the change in the app before it takes effect. Continued use after a change means the new policy applies.
16. Contact us
Questions, concerns, or requests: privacy@havewemetapp.com. General support: support@havewemetapp.com or the Support page.