HelloMe is a presence-sharing app for a small, mutually-confirmed circle of people
you actually know. You sign in with your phone number, share a simple availability
status (free / text / busy) with people who have accepted you into their circle, and
reach them through your phone's own apps (call, SMS, FaceTime, WhatsApp). There are
no ads, no advertising SDKs, no behavioural or product analytics, and no cross-app or
cross-site tracking in HelloMe. The one exception to that shape of processing is crash
and error diagnostics, which exist so we can find and fix bugs — what they contain, and
what we strip out of them first, is in Section 3.
This policy explains exactly what HelloMe collects, why, who processes it on our
behalf, how long it is kept, and how you can delete everything yourself from inside the
app.
If you have any question about this policy or your data, contact
privacy@hellome.us.
HelloMe ("we", "us") provides the HelloMe mobile app. We are the data controller for the
personal data described below. Contact: privacy@hellome.us.
2
What we collect, and why
We collect only what the app needs to function. We do not sell your data and we do
not use it for advertising or tracking.
Why we need it — legal basis: performance of our service to you
Phone number
What it isYour mobile number, verified by SMS one-time-passcode (OTP).
Why we need itIt is your identity and login on HelloMe, and it is how your contacts find whether you are on HelloMe. We never share your number with other users through the app.
Display name
What it isThe name you choose to show.
Why we need itSo people in your circle recognize you.
Profile photo (avatar)
What it isAn image you optionally upload.
Why we need itShown to people in your circle (and to someone who has sent you a request, so you can decide whether to accept). Optional — you can use HelloMe without one.
Presence status
What it isOne of free, text, or busy, plus the time it last changed.
Why we need itThe core purpose of the app: letting your accepted circle see if you're reachable.
Push notification token
What it isAn Expo push token tied to your device, plus the platform (ios/android).
Why we need itSo we can notify you of friend requests, acceptances, and when someone you've allowed becomes free. Stored only after you grant notification permission; removed on sign-out.
Reach-out preferences
What it isOptional preferred call/message channel.
Why we need itSo "reach out" opens the right app (e.g. WhatsApp vs. SMS).
Contacts matching
What it isIf you grant contacts permission, your device sends your contacts' phone numbers (normalized) over an encrypted connection so we can check which are already on HelloMe. The numbers are matched and immediately discarded — your address book is never stored on our servers (we keep only a short-lived one-way hash of each number, ≤24h, to rate-limit the feature — see Section 8).
Why we need itTo let you find people you already know who are on HelloMe. Optional — it only runs if you grant permission. See Section 8.
We do not collect your precise or coarse location, your browsing history, your
message content, your call logs, your health/financial data, or any advertising
identifier.
Camera and photo library
If you set a profile photo, the app asks permission to use your photo library or camera
(iOS prompts: "HelloMe uses your photos to set your profile picture." /
"HelloMe uses the camera to take your profile picture."). The image is used only as
your avatar. We do not scan your library or access photos you don't choose.
3
How your data is shared (processors / sub-processors)
We use a small number of service providers ("processors") to run the app. They process
data only on our instructions, to provide their service to us:
Supabase (Postgres database, Auth, Storage, Realtime)
What it handlesStores your profile, circle relationships, presence, device push tokens, and your avatar image. Authenticates your phone-OTP session. Delivers presence updates in real time.
NotesPrimary backend. Access is constrained by row-level security (see Section 6).
SMS OTP provider (e.g. Twilio)
What it handlesSends the one-time passcode used to verify your phone number at sign-in.
NotesReceives your phone number to deliver the SMS.
Expo push notification service
What it handlesRelays push notifications to your device using the push token.
NotesReceives the push token and message payload.
Sentry (crash & error diagnostics)
What it handlesCrash reports and stack traces, your device model, OS version and app version, a sampled share of performance traces, and scrubbed breadcrumbs — the trail of navigation, network and console events leading up to an error.
NotesUsed solely to find and fix bugs; events are stored in the United States. Before any event or breadcrumb leaves your device, the app removes phone numbers (both +E.164 and loosely formatted) and auth/push tokens from it, and blanks any field whose name looks like a phone number, token, password, or session. Sentry itself is configured not to attach your IP address or any user identifier. Your phone number is your identity on HelloMe, so this scrubbing is the point.
We do not share your personal data with advertisers, data brokers, or any other
third party for their own purposes.
4
How long we keep it (retention)
- Account data (profile, display name, phone number, avatar, presence, reach-out
preferences) is kept for as long as your account exists. When you delete your account
(Section 5), it is removed.
- Push tokens are removed when you sign out on a device, and when you delete your
account.
- Circle relationships, friend requests, and blocks are removed when you delete your
account (in both directions — rows you created and rows that reference you).
- SMS OTP codes are short-lived and managed by Supabase Auth / the SMS provider.
- Crash diagnostics follow Sentry's retention configuration and contain no advertising
identifiers.
We do not keep backups of an account beyond what is necessary to operate the service
reliably; routine operational backups age out on a rolling basis.
5
Deleting your account (in-app, self-service, permanent)
You can permanently delete your HelloMe account from inside the app — you do not need
to email us.
How: open the app while signed in and use the Delete account action in your
profile/settings. Confirm when prompted.
What happens, technically:
- The app first removes your avatar image(s) from Storage.
- The app calls the server function
delete_account, which:
- deletes your circle edges (both directions),
- deletes your friend requests (sent and received),
- deletes your blocks (both directions),
- deletes your profile row, and
- deletes your authentication identity (auth.users), which cascades your
sessions and tokens.
- You are signed out on the device.
This is irreversible and is scoped strictly to your own account — the function takes
no target parameter and acts only on the signed-in user, so no one can use it to delete
anyone else.
If you ever cannot use the in-app deletion (e.g. you've lost access to the device), email
privacy@hellome.us and we will delete your account on request after verifying your
identity.
6
Security model — privacy is enforced, not just promised
HelloMe is built so that presence is never visible without mutual consent:
- Mutual consent always. Connection is request → accept → presence. A pending request
never reveals your status. You see someone's live status only after you have accepted
a connection with them.
- Row-Level Security (RLS). The database enforces that you can read a profile's status
only if it's your own profile, or there is an accepted circle edge from you to that
person. This is enforced at the database layer — not just in the app UI — and Realtime
presence updates are filtered by the same rule, so a status change is delivered only to
people in that user's circle.
- Minimal disclosure on lookup. Looking someone up by phone number (or, in future,
by contact match) reveals only whether they are on HelloMe and your relationship state —
never their name, photo, phone number, or status until they accept you.
- Blocks are invisible. A blocked relationship is simply omitted from results, so a
block is never revealed to either party.
- Transport security. Connections to our backend use standard HTTPS/TLS. Your login
session token is stored on-device in the platform's protected app storage
(UserDefaults / Keychain-backed app storage via the OS).
No system is perfectly secure, but we design HelloMe to disclose the minimum and to make
the privacy boundary a property of the data layer.
HelloMe is not directed to children. You must be at least 13 years old (or the minimum
digital-consent age in your country, if higher — e.g. 16 in parts of the EU) to use
HelloMe. We do not knowingly collect data from anyone below that age. If you believe a
child has provided us data, contact privacy@hellome.us and we will delete it.
9
International data transfers
Our processors (Supabase, the SMS OTP provider, Expo, and Sentry) may store and process
data on servers located outside your country, including in the United States. Where
required, we rely on appropriate safeguards (such as the processors' standard contractual
clauses) for these transfers. By using HelloMe you understand your data may be processed in
these locations.
Depending on where you live, you may have rights to access, correct, export, or delete your
personal data, and to object to or restrict certain processing. You can edit your profile and
delete your entire account from inside the app at any time (Section 5). For any other
request, contact privacy@hellome.us.
If we make material changes, we will update the Effective date above and, where
appropriate, notify you in the app. Continued use after an update means you accept the
revised policy.