PRIVACY

Privacy policy

Effective September 10, 2026

Here is a dating app that shows you to other people only while you're physically at a participating venue. That design decides most of what follows: we collect little, we keep it briefly, and the most sensitive thing we touch — your precise location — is checked and thrown away, never stored.

Here is operated independently from Toronto, Canada. Our privacy officer is the person in charge of protecting your personal information; questions and privacy requests go to privacy@ihere.ca.

The short version

What we collect, and why

Phone number

You sign in with your phone number, verified by a text-message code. It's your account identifier. We don't use it for marketing, we don't share it with other users, and it's deleted with your account. One exception, for safety: if an account is banned, we keep its phone number so the same person can't come straight back.

Date of birth

Collected once at signup to confirm you're 18 or older, and locked afterwards — it can't be edited. Other users see your age, never your date of birth.

Profile

Your first name, 2–4 photos, and who you're looking to meet. Photos are compressed and stripped of metadata (EXIF, including any embedded location) on your device before upload; every photo is scanned by automated moderation when you upload it, and your display name is checked by an automated text classifier when you set it (see "Automated moderation and holds" below).

Precise location

Used to find venues near you and to confirm you are inside one. The app sends your approximate position to our servers when it looks up which venues are near you, and, while you're checked in, your precise position about every twenty seconds to confirm you're still inside the venue's boundary; a fix that isn't accurate enough is rejected rather than guessed at.

While you are checked in, that confirmation continues with the screen off. Without it, locking your phone for a few minutes would drop you out of the venue — taking your pending likes and your open chats with it — while you were still standing in the room. It is limited in three ways, and each is enforced rather than promised: it runs only between checking in and checking out, it never asks for or uses "Always" location access, and iOS displays its own location indicator for the entire time it is active. If you have not opened the app for an hour it stops by itself, and you leave the venue the ordinary way. When you are not checked in, the app uses no location in the background at all. Each fix is used for that one check and then discarded — none is ever stored, so there is no location history to show, share, or lose. Other users never see your position, your distance, or your coordinates — only that you're at the same venue they are. You can turn location off at any time in your device settings — without it Here can't check you in, and that's all that changes.

Being at a venue

While you're checked in, we hold a presence record: which venue, when you arrived, when the app last confirmed you're still there, and the profile basics that put you in the room — including your gender, who you're looking to meet, your verification status, and any moderation restriction on the account. It's deactivated when you leave or stop responding, and deleted about a week later. Other users never read this record; it's what builds the deck.

Likes and passes

Each like or pass you throw is kept as a record: it's what stops the deck re-dealing someone you've already answered, and what turns a mutual like into a match. What it does expires with the venue's night; the record itself is deleted with your account.

Messages

Chats exist between matched people at the same venue. Each message deletes itself about 30 days after it was sent — reported or not. Notifications never include what was written.

Did you meet?

After a night with a match, the app may ask whether you met in person. Your answer is kept briefly (about 30 days) and folded into anonymous totals that tell us whether Here works. The person you matched with never sees it.

Reports and blocks

If you report or block someone — or someone reports or blocks you — we keep a record. The report itself (who reported whom, the category, any note) is kept for about 90 days. The pairing record — the thing that keeps two people from ever being shown to each other again — is permanent, and stays after either account is deleted, because it's what keeps a removed person from coming back to the people who reported them. None of it is ever visible to other users.

Push token and crash reports

If you allow notifications, we store a push token (issued via Expo) to send exactly two kinds of notification: a new match, and a reply in a live chat. Neither carries a word of what was written; the reply notification names the sender the way the app does — a first name travels to the push services (Expo, Apple, Google) and nothing else does. The app also reports crash telemetry (Firebase Crashlytics) so we can fix what breaks; crash reports include technical details like your device model, operating system, and IP address.

Product events

Here keeps a short record of plain actions, so we can find out where the app is failing people: that a check-in was refused and why, that a screen was opened, how you answered a permission prompt, that a code was sent, that a deck was shown and how much of it, that you liked or passed, that a chat ended and how.

Each entry holds the action, your account ID, sometimes the venue, and sometimes a small number — how many people were in the room, how far outside a venue a refused check-in was, how long a screen was open. Nothing else. Never any content: no messages, no names, no photographs, no search text. Never your coordinates — a refused check-in records the distance, never the place. Never an advertising identifier, and never a device or installation ID.

It goes to our own servers and nowhere else. There is no analytics SDK and no advertising SDK in the app, no analytics company or advertising network receives any of this, and we never touch an advertising identifier — which is also why what we can see is limited to the short list above.

It is deleted with your account, and it expires on its own after about ninety days. We keep a copy for counting, on our own servers, that expires on the same ninety-day clock; deleting your account stops any more being written, and clears the record itself, but that counting copy runs out its own clock rather than disappearing the same day.

Technical identifiers

To run your account we also hold technical identifiers: a random account ID created at signup, and installation identifiers that Firebase and Expo assign your copy of the app, used for sign-in, push delivery, crash reporting, and attestation. Sign-in records include when you signed in and the address the request came from. All of it is deleted with your account; crash reports expire on their own schedule, about 90 days.

Device integrity

Requests the app makes to our servers carry an attestation from Apple (App Attest) or Google (Play Integrity), via Firebase App Check, proving they come from a genuine copy of Here. That shares integrity signals about your device with Apple or Google; it doesn't tell them who you are.

If you use Here in a web browser instead of the app, the same check is done by Google reCAPTCHA, which scores whether the request looks like a person rather than a script. reCAPTCHA also verifies the sign-in request before we text you a code. That shares signals about your browser and how it behaves on the page with Google under Google's privacy policy; it doesn't tell Google who you are.

Using Here in a browser

The browser version is the same product on the same account, with two things a browser cannot do: it can't keep confirming you're in the venue while the screen is off (so you drop off after the usual short grace, and come back when you reopen the page), and it can't send notifications. Crash reports aren't collected from the browser version.

Identity verification — only if offered, only if you choose it

Some versions of the app may offer optional identity verification through Persona, using a short video selfie. This feature is not in the current release; if it isn't in your app, none of this data is collected. Where it is offered: verification is voluntary and gates nothing — an unverified profile isn't penalized, and there is no "unverified" badge. You give explicit consent at capture, and you can decline without losing anything. The raw video is deleted by the vendor immediately after the check, pass or fail. We keep the result and a single reference frame; both are deleted when you delete your account, and no later than about 12 months after the check.

Automated moderation and holds

Every profile photo is scanned when it's uploaded, using Google Cloud Vision, and display names are checked with Google's automated language moderation. A photo the scan flags — or a scan that fails outright — hides the account until the flag is resolved — by our team, or by a clean follow-up scan; we err on the side of the room. Reports work the same way: a serious report, or reports from several different people, can hide or limit an account automatically while a human reviews it. The holds are automatic; the decisions that matter are made by people, and every enforcement action is logged. If your account is held and you think we've got it wrong, write to support@ihere.ca — a person will look. Anything involving children is handled under our child safety standards, including reporting to authorities where the law requires it.

How long we keep things

DataKept
Raw location fixNot stored — discarded after the venue check
Venue check-in recordDeactivated when you leave or the night ends; deleted about 7 days later
Chat messagesAbout 30 days after each message is sent
Report recordsAbout 90 days
Blocks, and the pairing record from a reportPermanent — kept for safety, including after account deletion
Push tokenUntil you sign out or delete your account
Deletion request record (email path)About a year — the record that the deletion happened
Crash reportsAbout 90 days, held by Firebase Crashlytics
Verification result (only if offered)Until you delete your account, and no later than about 12 months after the check; the raw video is deleted by the vendor right after the check
Profile, photos, date of birth, phone number, sign-in dataUntil you delete your account (deletion completes within 30 days)
Enforcement records (holds, bans — and a banned account's phone number)Kept after account deletion, so a removed person can't come straight back

Who we share with

We don't sell your personal information, and there are no ads. We use a small set of service providers to run the service:

ProviderWhat for
Google Firebase (Google LLC)Sign-in, database, file storage, server functions, crash reporting, app attestation
Google Cloud Vision and Cloud Natural LanguageAutomated photo moderation at upload; automated checking of display names
ExpoDelivering push notifications and app updates
Apple / Google PlayDevice integrity attestation (App Attest / Play Integrity)
PersonaOptional identity verification — only if offered, and only if you choose to verify
Microsoft 365 (Microsoft Corporation)Our support, privacy and safety mailboxes — what you write to us, and our replies

Each of these providers protects your data to the same standard this policy describes, and may use it only to provide its service to us — never for its own advertising or profiling.

We may also disclose information where the law requires it — for example, a valid order from law enforcement, or the mandatory reporting described in our child safety standards.

Where your data lives

Our databases, file storage, and servers run in Google's Canadian cloud region (Montréal). Some processing happens on our providers' infrastructure outside Canada, mostly in the United States: sign-in verification, photo moderation, crash reporting, push delivery, and identity verification where offered. While your information is outside Canada — or outside Québec — it is subject to the laws of the jurisdiction it's processed in, and may be accessible to that jurisdiction's authorities under a lawful order.

How we protect it

Everything between the app and our servers travels encrypted (TLS), and everything stored is encrypted at rest in Google's cloud. Requests from the app must carry a device attestation — our user-facing API rejects calls without a valid one. Inside Here, nobody browses messages: an operator can open a conversation only through a report that names it, and every such access is logged. Photos are stripped of metadata before they ever leave your phone. No system is perfect — if a breach ever creates a real risk of serious harm to you, we will tell you, and the Privacy Commissioner, as the law requires.

Your rights and choices

Under Canada's federal privacy law (PIPEDA) and, in Québec, Law 25, you can ask us:

You can also withdraw consent without deleting anything: turn location off in your device settings (Here can't check you in, and that's all that changes); turn notifications off the same way; and if identity verification is offered, simply don't take it — nothing in Here requires it. Withdrawing consent entirely means closing your account, which you can do yourself, in the app.

To make a request, write to our privacy officer at privacy@ihere.ca. We'll verify it's you (usually by the phone number on the account) and respond within 30 days. If you're not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada or, in Québec, the Commission d'accès à l'information.

Children

Here is for adults. You must be 18 or older to create an account; date of birth is collected at signup and can't be changed afterwards. Accounts we find are under 18 are removed. See our child safety standards.

Changes

If this policy changes in a way that matters, we'll post the new version here, in plain words, before it takes effect. The current version always lives at this address.