Legal
Privacy Policy
Last updated: September 25, 2026
This policy explains how your personal data is processed when you use the Hemdem website, web app and mobile apps (together, the "Service"). Users in Türkiye should also read the KVKK Disclosure Notice.
1. Data controller
The data controller is [business details required] ([business details required]). For any privacy question: [business details required].
2. Data we collect
• Account data: email address and password (the password is stored hashed by our authentication provider); anonymous accounts provide no email. • Profile data: name or nickname, date of birth, gender, gender you're interested in, country, content language, bio, profile photos, social links. • Verification data: the selfie you submit for profile verification. • Content: your test answers, tests you create, posts, comments, likes, 24-hour statuses and trails (text/photo), your messages and photos sent in chat. • Location: if you allow it, your approximate location (coordinates rounded to about 1 km) and the location of a trail when you leave one. • Usage data: last seen time, Discover decisions (like/pass), profile views, coin and point activity, support requests. • Device data: your device's push notification token, basic technical logs (IP address, browser/device info) and, to the extent you allow, an advertising identifier for showing ads.
3. Why we process data
To create and manage your account; calculate compatibility from test results; provide Discover, matching and messaging; send notifications; run the distance filter and the Trails map; process coins, Premium and purchases; show ads; keep the Service safe, prevent fake accounts and abuse, review reports; and meet our legal obligations.
4. Legal bases
Performance of a contract (providing the Service), legitimate interests (security, fraud and abuse prevention, improving the Service), legal obligations, and consent (optional processing such as location, push notifications and personalized ads). You can withdraw consent at any time in your device/browser settings or in the app.
5. What others can see
Your profile (name/nickname, age, gender, country, bio, photos, badges), posts, statuses, trails and the tests you create are visible to other users. Your exact location is never shown; distance appears only as approximate kilometers. Messages are visible only to the people in the chat.
6. Service providers and transfers
We never sell your data. To run the Service we work with: Supabase (database, file storage and authentication — servers in Singapore), Vercel (web hosting), Expo, Google Firebase Cloud Messaging and Apple Push Notification Service (push notifications), Google AdSense/AdMob (ads), OpenStreetMap and Esri (map imagery; your IP address reaches them when you open the map), Google Play and the Apple App Store (in-app purchases — your card details never reach us). Some providers are located outside your country, so your data is transferred internationally with appropriate safeguards. We may also share data with authorities when legally required.
7. Advertising
Google AdSense ads may be shown on the web and Google AdMob ads in the mobile app. These providers may use cookies or advertising identifiers to show and measure ads. You can turn off personalized ads in your browser/device settings and in Google Ad Settings. Premium members don't see in-app interstitial ads.
8. Retention
We keep your data while your account is open. Chat messages are deleted automatically after 10 days; statuses and trails are taken down after 24 hours. When you delete your account, your profile and all related data (tests, messages, posts, matches) are permanently deleted and purged from technical backups within 30 days. Logging out of an anonymous account deletes the account and its data. Records we must keep by law are kept only as long as required.
9. Security
Database access happens only server-side over authorized connections; no database key is ever sent to the browser or the app. Connections are encrypted with HTTPS. No system is 100% secure, but we take reasonable technical and organizational measures to protect your data.
10. Age limit
The Service is only for people aged 18 and over. We delete accounts and data of anyone we determine to be under 18. See our Child Safety Standards page for our approach to child safety.
11. Your rights
You have the right to access, correct, delete, restrict or object to the processing of your data and to request a copy of it (KVKK Art. 11 and, where applicable, the GDPR). You can edit your profile in the app, delete your account in the app, or contact us at [business details required] or via the Contact page. We respond within 30 days. You may also lodge a complaint with your local data protection authority.
12. Changes
We may update this policy. We will announce significant changes in the app or by email; the date at the top of this page shows the latest update.