Privacy at here
Last updated 18 August 2026.
here helps people meet in real life and make genuine friends. That only works if it feels safe, and if you can trust us with your information. This page explains, in plain language, what we collect, why, and what we never do.
The short version
- We collect the minimum we need to match you with people and keep the group safe.
- Your ID check is handled by a specialist provider. We never see or store your ID document or your selfie.
- We do not sell your data. Not to anyone, not ever.
- You can delete your account yourself, at any time, from your profile. Your profile, your photo and your notifications go. A few things stay, and we say further down exactly which and why: a one-way fingerprint of your ID document, anything you reported or anybody reported about you, and the email address you sign in with, so that coming back is possible if you change your mind.
What we collect
Before you have an account, if you join the waiting list. Right now this is the only thing the public site does, so for most people reading this it is the only part that applies:
- Your email address, and the city you asked about. If your city is not one we are opening in, we keep the note you left about which one you want, because that is how we decide where to go next.
- How you arrived: which advert or link brought you, and which page you landed on. It is stored against your address rather than in a cookie, and we use it for one thing, which is knowing which adverts are worth paying for. It is never sold and never shared for anybody else’s advertising.
- Whether we have emailed you, whether it arrived, and whether you unsubscribed. We keep that so you are not sent the same thing twice and are not sent anything after you have said stop.
You can ask us to remove all of it at any time, at hello@joinhere.app, and every email we send you has an unsubscribe link. Joining the list does not create an account and none of it is shown to anybody.
When you sign up and set up your profile:
- Your email address, so you can sign in. We email you a six-digit code, so there is no password to store.
- Your first name, age range, gender, the city you are in, the languages you speak, and optionally your nationality and a few interests.
- A photo of you. You can add an account without one, but you cannot be matched with anyone until you have: it is how the person you are meeting recognises you, and being recognisable is not optional when the whole thing ends with two strangers finding each other in public. You can change it any time, and it is deleted when you delete your account.
- If you are a woman, whether you have asked to be introduced only to other women. It is off unless you turn it on.
- When you mark yourself as available: the place, what you are up for, your group preference, and when it expires. This is deleted or expires on its own, and is never shown to other members.
- The matches we propose, whether you accepted, whether you met, and the feedback you give afterwards.
- Basic usage analytics: which screens get used and which steps people finish, so we can see where the app is confusing. We record the events we have chosen, not everything you touch, and we do not track you across other sites. You can switch it off entirely, for this browser, under Analytics on your profile, and nothing else stops working.
- If you turn on notifications, a push subscription for your browser. You can turn it off at any time, in here or in your browser settings.
- If you report somebody or block them, that we did so and what you wrote. Safety records outlive an account on purpose: deleting yours does not erase what happened at a meeting.
We deliberately ask for a first name only, and an age range rather than a birth date. We do read your date of birth from the ID check, once, to confirm you are over 18, and it is not kept. That is explained below.
About location. When you say you are open, we ask your device for your approximate location so we can find someone nearby and pick a meeting point that suits you both. We only ask at that moment, never while you are simply browsing or signing up.
While your availability is active we hold that approximate position. When it ends, we delete it. There is no directory of where members are, no background tracking, and no trail of where you have been: the only position we hold is the current one, and only while it is current. The map on a confirmed meet shows two dots, yours and theirs, and neither is stored as history.
This one is not optional. We used to let you pick an area from a list instead, and we stopped: choosing a name off a list says where you claim to be, not where you are, and the person who walks out to meet you is the one who pays if those differ. So if you will not share your location, you can still have an account and a profile, but you cannot be matched.
Before you have both agreed to meet, your position is never shown to anybody. Not while you are waiting, not on a proposal. The only thing another member sees at that stage is a number: how many people are open in the city.
Once you have both said yes, and only then, you can see each other on the way to the meeting point. This is the part worth reading carefully, because it is the one time your actual position is shared with another person.
- It starts only when you leave. Your first reading after agreeing is kept as a starting point and is never shown to anyone; nothing is shared until you are more than about a hundred metres from it. If you stay where you are, nobody sees anything, which is deliberate: the place you were sitting when you said yes is usually your home.
- After that, and until you arrive, the other person sees a moving dot on a map, and an estimate of how many minutes away you are. You see the same of them. Neither of you is given an address, and there is no history: the dot is only ever where you are now.
- It stops the moment the meet ends, is cancelled, or expires. At that point your starting point, your last position and the estimate are all deleted from our database automatically, in the same instant. Nothing about that walk is kept.
- To work out the minutes, the coordinates are sent to a routing service. This now happens on its own when a meet is confirmed, rather than only when you ask for it, because an estimate that arrives after you have set off is not much use. What is sent is two sets of coordinates and nothing else: no name, no account, nothing that says it is you.
The map itself is drawn by a mapping provider, which means it receives your device’s network address and the area of the map you are looking at. Both it and the routing service are listed below with everyone else who handles anything.
Once a meet is confirmed you can also send each other short messages, to sort out finding each other. Those are kept for thirty days and then deleted.
Identity verification
You can sign up and set up a profile without verifying. Before you can be matched to meet anyone in person, we ask you to confirm you are a real person, using a government ID and a quick selfie. This is the single biggest thing that makes meeting a stranger safe, and it keeps here free of fake and throwaway accounts.
This check is carried out by Didit, a specialist identity-verification provider, on their own secure systems. Your ID document and your selfie are sent to Didit, not to us. We never see your face scan and we never keep your document.
When a check passes, we read two things from the result and then let them go. Your date of birth, to confirm you are 18 or over, and your document number, which we turn into a one-way fingerprint. Neither the date nor the number is stored. The fingerprint cannot be turned back into a document number; it exists so that one person cannot quietly run several accounts, and so that somebody removed for hurting people cannot walk back in with a new email address.
Didit handles that data as an independent provider under their own privacy policy. We use them for one thing only: to confirm you are a real person, over 18, holding a real document, whose face matches it. We do not use identity verification for advertising, profiling, or anything beyond keeping the platform safe.
Who we share data with
We do not sell your data and we do not share it for advertising. We rely on a small number of trusted providers to run the service, each handling only what it needs to:
- Didit, for identity verification.
- Supabase, for our database and accounts, hosted in the EU.
- Cloudflare, which serves the app to your device.
- PostHog (EU), for privacy-friendly product analytics.
- Resend, to send you sign-in and welcome emails.
- OpenRouteService, to turn coordinates into a number of minutes on the way to a confirmed meet. Two sets of coordinates and nothing else: no name, no account, nothing that says it is you. We do not keep the position, and all that is stored afterwards is the number of minutes, which the person waiting for you sees. Nothing is sent before a meet is confirmed.
- MapTiler, which draws the map on the meet screen. It receives your device’s network address and which part of the map is being shown, which is a rough indication of where you are. It is never told who you are.
- Cloudflare Turnstile, which checks that the waiting list form is being filled in by a person and not a script. It runs in your browser and receives your device’s network address and some technical signals about the browser itself. It is not told your email address, it does not use cookies to follow you around, and it is not analytics: the only thing it hands back to us is yes or no.
- Google Maps, only if you tap “Get directions”, which hands you over to Google with the meeting point as the destination. From that point you are using Google under their own terms.
We pick providers that publish a data protection agreement for business customers, and each of them gets only the part of the service named beside it. None of them has our permission to use your data for anything of their own, and we do not sell or hand anything to anyone who is not on this list. We keep a written record of what each provider receives and which terms cover it. If you want to know what applies to a particular one, ask and we will tell you.
What other members can see
Nobody can browse members on here. There is no directory, no list of nearby people, and no way to search for someone. While you are waiting, others see only a number: how many people are open at that place.
When we propose a meet, each of you sees the other’s first name and photo, an age range, the country they said they are from if they filled that in, and what you have in common: shared languages, shared interests, and what each of you said you were up for, which is one of a short fixed list and never anything you typed. You see that before you decide, because agreeing to meet a stranger without knowing who they are is not a decision anybody should be asked to make.
Nationality is optional. You can leave it blank when you sign up and clear it later in your profile, and if it is blank there is nothing to send.
This is still not browsing. We have already chosen, there is no directory, no gallery and no search, you see one proposal at a time, and passing needs no reason and is never explained to the other person.
If either of you passes, or nobody answers in time, the proposal disappears and so does everything it showed you. Somebody who passed cannot look the other person up afterwards.
No one ever sees your email, your exact age, your ID, or any contact details. Your position is shared only in the one case described above: with the person you have already agreed to meet, once you set off, until you arrive.
How long we keep it
We keep your profile while your account is active. Availability expires by itself, and the approximate location attached to it is deleted the moment it does. If you delete your account, we remove your profile, your photo, your interests and your push subscriptions, and we stop emailing you. The address you sign in with is kept, because it is the only way an account can be brought back for somebody who changes their mind. Anything held by Didit for your identity check is kept and deleted under their own retention rules.
The ID fingerprint outlives deletion too, and we would rather say so plainly. The one-way fingerprint from your ID check is kept, for every account that has passed the check, not only for people who were removed. It is not your document number and cannot be turned back into one, and it carries no name, no date and nothing that points at you. It stays because it answers two questions after an account is gone, and both of them matter to the person on the other side of a meet: whether this document already belongs to somebody here, so that one person cannot quietly run several accounts, and whether it belongs to somebody we removed for hurting a member, so that they cannot come back on the same passport with a new email address. There is no end date on it today. Everything else attached to that check, including the reference held by the provider, is cleared at the same moment.
What that means in practice, in both directions: if you delete your account and later change your mind, sign in with the same email address and it comes back, though the profile details you cleared are gone for good. Signing up again with a different address and the same document does not give you a second account, because the fingerprint recognises the document and the check is refused.
Notifications
If you turn them on, we use standard web notifications to tell you when we have found someone, when a meet is confirmed, and when one is cancelled. These are about availability you started yourself, and we only ask for permission after you tap to enable them.
There is a second kind: a nudge when somebody nearby says they are free, so you can say you are too. This one is on by default, because with a small number of members it is the only way two people who are both free on the same evening ever find out about each other. You see it as a ticked box when you turn notifications on, you can untick it there, and you can turn it off at any time in your profile. It never names anyone, it never says how many, and it goes out at most once a day. The push message itself carries no content: your device fetches what to show, so the push service never sees it.
Your choices
- Edit or remove your profile details any time, right in the app.
- Delete your account yourself, from your profile. It takes two taps and nobody has to approve it.
- Ask us for a copy of your data.
For a copy of your data, email us and a real person will take care of it, within 30 days and usually the same week. We will ask you to send the request from the address on the account: posting somebody’s profile, their meets and their messages to whoever asks for them would be its own kind of leak. The copy leaves out two things on purpose, and both are somebody else’s: the identity of anybody you reported, and the fingerprint of your document, which we could only include by undoing the thing that makes it safe to keep.
Why we are allowed to do this
Most of what we hold, we hold because you asked us to introduce you to somebody, and we cannot do that without it. That is the contract between us: your name, your photo, your languages, where you are when you say you are free. Without any one of them there is no meet.
- To provide the service, which covers your profile, your availability, the matches we propose and the meeting points we pick.
- Because the law requires it, for the age check. We are not allowed to introduce children to strangers, so confirming you are over 18 is not optional and not something you can decline and still take part.
- Because we have a real interest in keeping people safe, which covers identity verification, reports, blocks, and the one-way fingerprint that stops somebody removed for hurting people from coming straight back. We think anybody meeting a stranger would want us to do this, and that is the test.
- Because you said yes, for notifications, and for the waiting list. You can take either back at any time, in the app or in your browser for notifications, and by unsubscribing or writing to us for the list. Nothing else stops working.
How long, exactly
- Your position while you are open: deleted the moment your availability ends. There is no history.
- Positions during a meet: deleted the instant the meet ends, is cancelled, or expires.
- Messages between two people meeting: 30 days.
- Your profile and photo: for as long as you have an account, and deleted when you delete it.
- Reports and blocks: kept after an account is deleted, because deleting your account should not erase what happened to somebody else at a meeting.
- The one-way fingerprint from your ID check: kept for every verified account, with no end date, for the two reasons given above. It is not your document number and cannot be turned back into one.
- Your email on the waiting list: until you ask us to remove it, or until we stop running.
Where your data goes
Your account, your profile, your photo and everything else in our database sit in the European Union, and so do our analytics. The rest follows the provider, so here is who is where:
- Switzerland.The map on the meet screen is drawn by MapTiler, a Swiss company. It gets your device’s network address and which part of the map you are looking at, never your name.
- Cloudflare serves this site and runs the bot check on the waiting list form, from whichever of its data centres is nearest to you.
- Germany. The walking estimate is calculated by OpenRouteService, run by a research institute in Heidelberg. Two sets of coordinates go there and nothing else.
- The United States.Resend sends our emails, so it gets your address and what we wrote. Cloudflare serves the app, so it sees your device’s network address and what you asked for. Supabase (our database) and PostHog (our analytics) are American companies even though the servers holding our data are in the EU, which means their people can reach it when they are supporting us. Google is in this line too, but only if you choose it: signing in with your Google account, or tapping “Get directions” and being handed over to Google Maps.
- Didit, for the ID check. Your document and your selfie go to them and not to us, on their systems, under their own privacy policy, which you see before you start the check and which says where they hold it. We are told the outcome.
Switzerland and the EU treat each other’s protection as equivalent, so the Swiss and German parts of that list stay inside the rules you already have. The American ones do not, on their own, which is why we rely on the data protection terms those companies publish: the standard contractual clauses the European Commission wrote for exactly this situation, and for some of them a certification under the Swiss-US Data Privacy Framework as well. Ask us which applies to a particular provider and we will tell you.
What is stored on your device
We keep you signed in, which needs a cookie. We remember that your browser has already given us your location once, so we stop explaining why we are asking. And our analytics keep an identifier so that ten screens in one visit are counted as one visit. We do not use advertising cookies and nothing here follows you to other websites.
Your rights
You can ask us for a copy of everything we hold about you, ask us to correct it, ask us to delete it, and object to us holding it. Most of it you can do yourself in the app, immediately and without asking anybody: edit your profile, change your photo, turn notifications off, or delete your account in two taps.
For anything else, email us and a person will deal with it. If you are not happy with how we handle it, you can complain to the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, and if you live in the EU you can complain to the authority in your own country instead.
If this page changes
We will change it when the product changes, and the date at the top will move. If a change actually affects what we do with your data, rather than tidying a sentence, we will tell you in the app rather than hoping you re-read this.
Who we are
here is operated from Basel, Switzerland. Whoever operates it decides what happens to the information on this page and is responsible for it.
Email hello@joinhere.app, and a person reads it. The full name and postal address of the operator are available on request, by email.
here is for making platonic friends. It is not a dating service, and identity verification exists only to keep everyone safe.