Privacy Policy
HelloMates: Solo Travel App, operated by Yiriba LLC. Last updated: 2026-10-09.
The short version. HelloMates needs to know who you are, roughly where you are while you use it, and what you say in chat, because that is what the app does. We do not sell your data, we show no ads, and the app uses no advertising SDK; the iOS and Android apps send their usage events and session recordings to PostHog, our product analytics provider: a session recording is a replay of what was on your screen while you used the app, without masking, so it includes what you type and the images shown, photos included (the one thing never recorded is the sign-in code you type or that a sign-in link carries); PostHog also records the names of the screens you open, your taps, app crashes, and the approximate city and country from your IP address (GeoIP); the hellomates.app website uses Vercel Web Analytics, which sets no cookies, and Google Analytics, which sets first-party cookies (named _ga) to count visits; both record page views, referrer, country, device type, browser and operating system. Your "here tonight" status expires after 24 hours and Moments fade after 7 days. Your Arm it location fixes are kept for 30 days. You can delete your account, and everything with it, from Settings.
- Who is responsible
- What we collect
- Why we use it
- Location
- Arm it and your contacts
- Home and HelloMates Family
- Who processes your data for us
- How long we keep it
- Deleting your account
- International transfers
- Your rights
- Children
- Security
- Changes
- Contact
1. Who is responsible
Yiriba LLC, Pearland, TX, United States ("Yiriba", "we", "us") is the controller of the personal data described here. This policy covers the HelloMates iOS app, the HelloMates Android app, the website at hellomates.app and the services behind them (together, "HelloMates"). It applies to travellers, to people in the Home role, and to the contacts a traveller adds for Arm it.
2. What we collect
| Data | Where it comes from |
|---|---|
| Account. Your email address or phone number, or the identifier Apple or Google gives us when you sign in with them (Apple may give us a relay address instead of your real one); your first name or the name you go by; your profile photo; your preferred language. | You, at sign-in and in your profile. The profile photo is checked for a human face by an automated service (see section 7); the check answers "yes" or "no" and creates no face template or biometric identifier. |
| Women's lane selfie check. Two pictures of your face taken in the app when you choose to take the check (one looking at the phone, one with your head turned as the screen asked), the automated check's answer (whether the pictures show the same live person, whether the person presents as a woman, a confidence and a one-line reason), the decision, and any note a person on our team added. | You, only when you start the check; the camera is asked for on that screen. The pictures are sent to the automated check (section 7) and, when it is not sure, shown to a person on our team. The check creates no face template or biometric identifier, and the pictures are never shown to other users. Retention is in section 8. |
| Onboarding answers. Your destination city, where you are staying (hostel, hotel, landing, home), what you want from the trip, who worries about you at home, how long the trip is and how committed you are to going out. | You, in the onboarding screens. They shape what the app shows you first. |
| Location. Your position while the app is in use, when you have allowed it; the city you chose; and, for Arm it, low-power background fixes (the phone's significant-change and visit updates) while a timer is armed or "Share location for Arm it" is on in Settings, so that the message your contacts get if you miss a check-in carries your last position. | Your device, with your permission. Section 4 explains the detail. |
| Presence and landings. Your "here tonight" status and lane, the hostel or street you joined, and any arrival date, city or flight number you enter. | You. A flight number is sent to a flight-data provider to get the landing time; nothing else about you goes with it. |
| Chat and Moments. Messages in city, hostel, street, room and direct chats; photos and posts in Moments; room titles, places, times and cost-split entries; likes, replies, "showed up" ticks and reports. | You and the people you talk to. |
| Arm it. Your check-in hour, the contacts you add (name, phone number or email, and optionally their city), your prepared message and note, and the delivery log for each message we send on your behalf. | You type contacts in; HelloMates does not read your address book. |
| Home links. The invite you create, who accepted it, and the check-in status shared with them. | You and the person you invite. |
| Purchases. The store's transaction and subscription records for Plus, Trip Pass, Lifetime and HelloMates Family: product, dates, environment, renewal and refund status, and the store's transaction identifiers. On iPhone that store is Apple; on Android it is Google Play. We never receive your card number. | Your device (a signed receipt or purchase token) and the store's servers (server notifications). |
| Device. Your push notification token, and the version of the app and of iOS or Android. | Your device, so that we can send check-in reminders, chat and Home notifications. |
| Usage events. Which onboarding screen you reached, in-app events (for example "status set", "room joined") with their details, the names of the screens you open, your taps, app crashes and their technical details, push notifications received and opened, and answers to in-app surveys, each with a timestamp. | The app, sent to our own servers. The iOS and Android apps also send the same events to PostHog, our product analytics provider (section 7). The app uses no advertising SDK. |
| Session recordings. A replay of your screen activity while you use the app: the screens you open, where you tap and scroll, and the app's network requests (their address, timing and status, not their content). Nothing is masked: a recording shows the screen as you saw it, including what you type, the images shown (your photos and other people's), names, plan titles and messages. | The iOS and Android apps, sent to PostHog (section 7), to see where people get stuck and fix it. Not used for advertising. |
| Support. Messages and screenshots you send us from Settings, and our replies. | You. |
| Server logs. IP address, request path and time, kept briefly for security and debugging. | Your device, when it talks to our servers. |
3. Why we use it
- To run HelloMates (performance of our contract with you): sign you in, show who is here tonight, put you in the right chats, deliver messages and notifications, run rooms and the cost split, run Arm it, run Home, and grant what you paid for.
- To keep people safe (our legitimate interest, and yours): automated moderation of the words and photos people post (names, bios, profile photos, messages, room titles, Moments and chat photos), which can refuse content or hold it for review, the face check on profile photos, report handling, blocks, suspensions and appeals, and detection of automated or abusive accounts.
- To open the women's lane (your consent, and nothing else): the two pictures of the selfie check, and the answer the automated check gives about them. The check runs only when you start it, and only after the screen has told you what the pictures are for, who sees them and how long they are kept. It is optional: every other feature of HelloMates, free and paid, works without it. You can withdraw at any time by turning the women's lane off under Me, which closes the lane for you; a passed check's pictures are already deleted, and deleting your account deletes the decision record. Withdrawing does not undo processing that already happened.
- To translate (your request): text you ask to have translated is sent to a translation service and the result is cached for 30 days so the same text is not translated twice.
- To bill correctly (contract and legal obligation): verify purchases with Apple, attribute revenue to the partner whose code you used, and keep the records tax law requires.
- To improve HelloMates (legitimate interest): understand where people stop during onboarding and which features are used, in aggregate.
- To answer you (contract): support threads and appeals.
- To comply with the law and to establish, exercise or defend legal claims.
We do not sell personal data, do not share it for cross-context behavioural advertising, do not show ads, do not build profiles about you for third parties, and do not use your content to train artificial intelligence models.
4. Location
- HelloMates asks for location while the app is in use for the chats and the tonight list. When you first arm a check-in it explains why and then asks for "always" access, for one purpose: while a timer is armed, or while "Share location for Arm it" is on in Settings (on by default, off with one tap), the app receives the phone's low-power background location updates (significant changes and visits, never continuous tracking) and sends each fix to our servers, so that the message your contacts get if you miss a check-in carries where you last were. With "while in use" only, we get fixes only while the app is open, and the Arm it screen says so. Turning the setting off takes one last fix, keeps that spot, and stops the updates.
- Your position is used to put you in the right city, street or hostel chat, to show you as "here tonight" at city level, and to fill in the last known location for Arm it. Other users see your city, whether you are in the same hostel or street, and, only after you check in, an approximate pin on the Tonight map for up to 24 hours. You check in yourself, each time, by choosing a status or tapping "Check in here"; the app never checks you in on its own, and nothing moves your pin until you check in again. The first time you check in, the app asks whether to show you on the map, and you can say no; your answer is "Show me on the map" in Settings and you can change it any time. The pin is a point our servers place a few hundred metres from where you checked in, stable for the day so that reading the list repeatedly cannot average it back, and the distance shown next to you is measured to that same point. The exact spot is never sent to anyone else's phone. You see your own pin at your real position, and only you do. With the setting off they see you at city level only, with no pin and no distance. You can send someone your exact position deliberately with "Share my exact location" on their profile, which sends them one message with a map link to where you are at that moment and nothing after it. The Arm it setting is separate.
- You can use HelloMates, including every paid feature, without granting location. Without it the tonight list works at city level, from the city you chose.
- For Arm it, location fixes are kept for 30 days, then deleted (a fix within 50 metres and 10 minutes of the previous one is not stored). The latest fix goes only to the contacts you chose, with the time it was taken, and to a Home user only during the window described in section 6.
5. Arm it and your contacts
When you add a contact for Arm it, you give us that person's name and phone number or email address. We use them for exactly one thing: to deliver the message you prepared if you miss a check-in. Contacts do not receive reminders or "checked in" notices; those go to you and, if you have one, to your Home contact inside the app. We do not add contacts to any list, do not message them for any other reason, do not show them to other users, and do not use their details to build a profile. Please tell your contacts that you have added them. A contact who does not want these messages can reply STOP to the text, use the "stop these messages" link in the email, or write to hello@hellomates.app. We keep that number or address on a stop list so that no HelloMates user can add it again, and we tell the traveller that the contact could not be reached. Contact details are stored encrypted at rest by our database provider, and you can edit or delete them at any time in the app.
6. Home and HelloMates Family
A Home user is linked to you only through an invite you created. They always see whether you have checked in, whether a timer is armed, when the check-in is due and when you last checked in. With HelloMates Family they also see your last known location during an active or fired timer, your flight and landing time, and your last ten timers. Location is never inside a push notification. Removing a Home link stops all of this at once. The Home user's own account data is covered by this policy in the same way as yours.
7. Who processes your data for us
We use the following companies as processors. Each acts on our instructions, under a contract that limits what it may do with the data, and only for the purpose listed.
| Processor | What it does for us | Where the data is processed |
|---|---|---|
| Supabase | Hosts our Postgres database (every account, chat, room, Moment, Arm it and purchase record) and the real-time socket layer that pushes chat messages to your device. | Singapore |
| Google Cloud (Cloud Run, Cloud Scheduler) | Runs our backend servers and the timer that checks Arm it deadlines every minute. | Singapore (asia-southeast1) |
| Google Cloud Storage | Stores Moments photos and profile photos. | Singapore (asia-southeast1) |
| OpenAI | Translates text you ask to have translated; screens text and photos for abuse (names, bios, messages, room titles, Moments, profile photos and photos sent in chats) so that content can be refused or held for human review; answers whether a profile photo shows a human face; judges the two pictures of the women's lane selfie check (same live person, presents as a woman, a confidence and a reason). Sent through the API under terms that exclude training on the data. | United States |
| Twilio | Sends SMS sign-in codes and the SMS leg of your Arm it message to the contacts you chose. | United States |
| Resend | Sends email sign-in codes, the email leg of your Arm it message, and support emails. | United States |
| Apple | On iPhone: Sign in with Apple; in-app purchases, subscription status, refunds and server notifications; push notifications (APNs) to your device. | United States and Apple's global network |
| Sign in with Google (we receive your Google account identifier, email and name when you choose it). On Android: Google Play in-app purchases, subscription status, refunds and server notifications; Firebase Cloud Messaging push notifications to your device. | United States and Google's global network | |
| Vercel | Hosts the hellomates.app website and the invite links; receives the IP address, browser type and page requested of visitors to the site, kept in its logs for a short period. It also runs Vercel Web Analytics on the site, which is cookieless and records page views, referrer, country, device type, browser and operating system. | United States and Vercel's global network |
| Google Analytics | Measures visits to the hellomates.app website (not the apps). Sets first-party cookies (named _ga) and records page views, referrer, approximate location, device type, browser and operating system. Google Analytics does not log or store IP addresses. Not used in the iOS or Android app. | United States and Google's global network |
| PostHog | Product analytics for the iOS and Android apps: the usage events in section 2 (which screen you reached and in-app events such as "status set"), the app version and build, an install identifier and, once you sign in, your account identifier. Like any server it receives your device's IP address, from which it records an approximate city and country (GeoIP). Also screen names, taps, crash reports, push notification receipts and opens, survey answers, and session recordings of the app's screens (section 2), recorded without masking, so a recording can include what you type, the images shown, names and messages, but never a sign-in code. Not used for advertising. | United States |
| AeroDataBox (via RapidAPI) | Returns the live arrival time and airport for a flight number you enter. Only the flight number and date are sent; no account data. | European Union and United States |
Beyond these processors we share personal data only: with other users, as the app is designed to (your name, photo, city, status, level, and what you post or send); with the contacts you chose for Arm it; with a Home user you invited; with a partner whose invite code you used, in aggregate (counts and revenue, never your identity or messages); with authorities or others where the law requires it or where it is necessary to protect someone's safety; and with a buyer if Yiriba is sold or merged, under this policy. We do not sell personal data.
8. How long we keep it
| Data | Kept for |
|---|---|
| "Here tonight" presence | Expires 24 hours after you set it; replaced when you set a new one. |
| Women's lane selfie check pictures | Deleted the moment a check passes. Kept until a person decides when the automated check was not sure. Kept 30 days after a decline, for the appeal, then deleted. The decision record (the answer, the outcome, who decided, any note; never a picture) stays for the life of the account. |
| Moments | Fade from the feed 7 days after posting and are purged from storage on the same schedule. |
| Chat messages | For as long as the chat exists, so that the people in it can read their history. Room and direct chats close when the room is over or when either side leaves. Held messages that are not released are deleted with the report. |
| Arm it location | 30 days per fix, including the spot kept when you turn "Share location for Arm it" off; older fixes are deleted automatically. |
| Arm it contacts and prepared message | Until you edit or delete them, or delete your account. |
| Arm it delivery log | 30 days, with contact details masked in our dashboard, so that we can show you what was sent and retry failures. |
| Landings | Until the landing has passed and been replaced by a new one. |
| Translation cache | 30 days. |
| Sign-in codes | Minutes; deleted once used or expired. |
| Reports, suspension notices and appeals | For the life of the account and for up to 2 years after a ban, so that a banned person cannot simply return. |
| Purchase records | For the period tax and accounting law requires, typically 7 years, in a form that identifies the transaction rather than you once the account is gone. |
| Usage events and server logs | Usage events 12 months in identifiable form, then aggregated; server logs 30 days. |
| Session recordings | At most 90 days at PostHog, then deleted. |
| Support threads | 2 years after the last message. |
9. Deleting your account
Open Me, then Settings, then Delete account. Deletion is immediate and removes your profile, name, photo, sign-in identifiers, the pictures and records of any women's lane selfie check, onboarding answers, presence, landing, the rooms you host and your membership of other rooms, Arm it timers, contacts and prepared message, Home links, direct threads, Moments and likes, translation usage, reputation events, device tokens and entitlements. Messages you sent in shared chats keep their text but are attributed to "deleted", not to you, because the other people in the conversation keep their history. Purchase records stay for the period in section 8, and a suspension record may stay to enforce a ban. Your subscription is not cancelled by deleting the account; cancel it in the store you bought it from (on Android, the Google Play Store app under Payments and subscriptions; on iPhone, Settings, then your name, then Subscriptions). The steps are also set out at hellomates.app/delete-account.html.
When you delete your account we also keep one safety record of what the account did: the profile details you gave us, the messages you sent, the reports you made and the reports made about you, the people you blocked and who blocked you, the rooms and Moments you posted, and the Arm it contacts you named. We keep it for up to 24 months in a separate store that no part of the app reads, and we use it only to investigate abuse and to answer legal requests, never for marketing or to rebuild a profile. It never includes the women's lane selfie pictures, which are deleted with the account.
10. International transfers
Our servers and database are in Singapore, and some processors are in the United States. Yiriba is a United States company. HelloMates is used by travellers everywhere, so your data will be transferred to, stored in and processed in countries other than the one you live in, including countries whose data protection laws differ from yours. Where the GDPR or UK GDPR applies to you, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) with each processor outside the EEA or the UK, on the processor's own adequacy or certification where one exists, and, for the transfer to Yiriba itself, on the necessity of the transfer to perform our contract with you. You can ask us for a copy of the safeguards at the address in section 15.
11. Your rights
Wherever you live, you can access and correct your profile in the app and delete your account in Settings. You can also write to hello@hellomates.app to exercise any right below; we will answer within 30 days and may ask you to confirm that you control the account.
European Economic Area, United Kingdom and Switzerland
Under the GDPR, the UK GDPR and Swiss law you have the right to access your personal data and receive a copy; to have it corrected or erased; to restrict or object to processing that rests on our legitimate interests; to receive the data you gave us in a portable format; and to withdraw consent where processing rests on consent (the women's lane selfie check, which you withdraw by turning the lane off under Me; location access, which you switch off in your phone's Settings; and the background fixes for Arm it, which you switch off in the app's Settings). Our legal bases are set out in section 3. You may complain to your national supervisory authority; in the UK that is the Information Commissioner's Office. Write to us at the address in section 15 and we will answer.
California and other US states
Under the California Consumer Privacy Act (as amended by the CPRA) and similar laws in other states, you have the right to know what personal information we collect, use and disclose, to delete it, to correct it, to obtain a copy of it, and not to be discriminated against for exercising these rights. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is nothing to opt out of; we honour Global Privacy Control signals as an opt-out of sale or sharing in any case. We do not use or disclose sensitive personal information (precise location, the contents of your messages) for any purpose other than providing the service you asked for and keeping it safe. You can appoint an authorised agent to make a request on your behalf. Section 2 lists the categories we collect, section 3 the purposes, section 7 the recipients and section 8 the retention periods.
Everyone else
The laws of Australia, Singapore, Brazil, Canada, Thailand and many other countries give you similar rights of access, correction and deletion. Write to us and we will apply the strongest of them that fits your situation.
12. Children
HelloMates is for people aged 18 and over. That is our own rule, set in the Terms and enforced by us; it is not the same thing as the age rating a store shows, which each store derives from its own questionnaire and which is lower (Google Play rates the app 12+). We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has an account, write to hello@hellomates.app and we will close it and delete the data.
13. Security
Every connection between the app and our servers uses TLS. Data at rest is encrypted by our database and storage providers. Sessions are signed tokens; sign-in codes expire within minutes and are limited to a few attempts. Access to production data is limited to the people who run HelloMates, through named accounts, and our admin tools mask contact details. No system is perfectly secure; if we learn of a breach that affects you, we will tell you and the relevant authority as the law requires.
14. Changes
When we change this policy we post the new version at hellomates.app/privacy.html with a new "Last updated" date. For material changes we tell you in the app or by email before they take effect. When we add a processor we update section 7 first.
15. Contact
Yiriba LLC
Pearland, TX, United States
Email: hello@hellomates.app