Trust & Safety

Built around consent.

An app that maps where two people have been carries real responsibility. Here is how Have We Met? is designed to keep the sensitive parts in your hands — and how to use it wisely.

The design principles

Two yeses, always

Nothing in Have We Met? happens to a person who didn't opt in. A session exists only when one person creates it and the other joins with a private code. Both people run their own scan on their own phone. There is no way to compare against someone who hasn't chosen to compare with you.

Metadata first, photos never by default

The matching engine sees coordinates and timestamps — not pictures. Your photos stay on your device through the entire scan. Revealing a photo is a separate, deliberate act: a review screen shows you exactly which photos would be revealed, you de-select anything you want kept private, and only then does anything transmit.

Reveals are reversible

Revealed a photo and thought better of it? Revoke it. It disappears from your partner's view and is deleted from our servers. (Honesty note: no app can un-see what a person has already looked at — reveal at the pace you're comfortable with.)

No feed, no strangers, no discovery

There are no public profiles, no browsing, no matchmaking pool. The only person who ever sees your results is the one person you paired with. Have We Met? is a private conversation between two timelines.

What sharing a moment shares

Moment cards you export from the app show the moment's place, dates, distances, your first names if you added them, and — only when both of you have revealed them — the photos on that moment. What leaves the app is always visible on the card in front of you before you share it.

Using it wisely

If something goes wrong

Your story is yours. We just draw the map.