πŸ”’
πŸ›‘οΈ
πŸ“‹
βš–οΈ

Privacy Policy

Your Privacy is Our Priority

We believe in complete transparency about how we collect, use, and protect your personal information. Your trust is everything to us.

πŸ”
End-to-End
Encryption
🌍
GDPR
Compliant
πŸ—‘οΈ
30 Days
Auto-Delete
πŸ‘€
No Real
Names Required
πŸ“… Last Updated: December 15, 2024

Table of Contents

Quick Summary

  • β€’ We collect minimal data
  • β€’ No real names required
  • β€’ Messages auto-delete
  • β€’ You control your data
  • β€’ GDPR & CCPA compliant

1. Overview

Welcome to HEY YO! ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our chat platform and related services (collectively, the "Service"). We are committed to protecting your privacy and being transparent about our data practices.

πŸ”’ Our Privacy Commitment

We believe privacy is a fundamental right. We collect only the minimum data necessary to provide our service, use end-to-end encryption for all messages, and give you complete control over your information.

Key Principles

  • Minimal Data Collection: We collect only what's necessary for the service to function
  • User Control: You decide what information to share and can delete it anytime
  • Transparency: We clearly explain what we do with your data
  • Security First: All communications are encrypted and secured
  • No Selling: We never sell your personal information to third parties

By using HEY YO!, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our Service.

2. Information We Collect

We collect information you provide directly to us, information we obtain automatically when you use our Service, and information from third parties in limited circumstances.

Information You Provide

βœ… What We Collect

  • β€’ Username (chosen by you)
  • β€’ Age (for safety and legal compliance)
  • β€’ Messages you send (encrypted)
  • β€’ Profile information (optional)
  • β€’ Interests and preferences (optional)
  • β€’ Support communications
  • β€’ Report and safety data

❌ What We DON'T Collect

  • β€’ Real names or legal names
  • β€’ Email addresses (optional only)
  • β€’ Phone numbers
  • β€’ Physical addresses
  • β€’ Government ID numbers
  • β€’ Financial information
  • β€’ Biometric data

Information We Collect Automatically

When you use our Service, we automatically collect certain information about your device and usage patterns:

  • Device Information: Device type, operating system, browser type and version
  • Usage Data: Features used, time spent, interaction patterns (anonymized)
  • Technical Data: IP address (hashed for privacy), connection timestamps
  • Performance Data: Error logs, crash reports, performance metrics

πŸ“ Location Information

We do NOT collect precise location data. We may derive general location (country/region) from IP addresses for legal compliance and service optimization, but this is not linked to your identity.

Information from Third Parties

We may receive limited information from third parties only in these specific circumstances:

  • Social Media Integration: If you choose to connect social accounts (profile picture, username)
  • Payment Processors: Transaction data for premium subscriptions (no financial details stored)
  • Analytics Services: Aggregated, anonymized usage statistics
  • Safety Partners: Information about known threats or harmful content

3. How We Use Information

We use the information we collect for specific, legitimate purposes that directly benefit your experience on HEY YO!. We never use your data for purposes you haven't consented to.

πŸ’¬

Service Delivery

  • β€’ Enable real-time messaging
  • β€’ Match you with compatible users
  • β€’ Maintain chat history during sessions
  • β€’ Provide customer support
πŸ›‘οΈ

Safety & Security

  • β€’ Detect and prevent abuse
  • β€’ Investigate safety reports
  • β€’ Enforce community guidelines
  • β€’ Protect against fraud and spam
βš™οΈ

Service Improvement

  • β€’ Analyze usage patterns (anonymized)
  • β€’ Develop new features
  • β€’ Fix bugs and improve performance
  • β€’ Optimize user experience
βš–οΈ

Legal Compliance

  • β€’ Comply with applicable laws
  • β€’ Respond to legal requests
  • β€’ Protect our legal rights
  • β€’ Age verification for safety

🎯 Purpose Limitation

We only use your information for the specific purposes listed above. We will never use your data for unrelated purposes without your explicit consent. If we want to use your information for a new purpose, we'll ask for your permission first.

Legal Basis for Processing (GDPR)

For users in the European Union, we process your personal data based on the following legal grounds:

  • Contractual Necessity: Processing necessary to provide our chat service
  • Legitimate Interests: Safety, security, and service improvement (balanced against your rights)
  • Legal Obligation: Compliance with applicable laws and regulations
  • Consent: For optional features like marketing communications (you can withdraw anytime)

4. Information Sharing and Disclosure

🚫 We Never Sell Your Data

HEY YO! has never sold personal information and never will. We do not sell, rent, or trade your personal information to third parties for their marketing purposes.

We may share your information only in the limited circumstances described below. We require all third parties to respect the security of your personal data and treat it in accordance with applicable law.

When We May Share Information

πŸ”§ Service Providers

We work with trusted third-party companies to help us provide our service:

  • β€’ Cloud hosting providers (encrypted data storage)
  • β€’ Analytics services (anonymized usage data only)
  • β€’ Customer support tools (support conversations only)
  • β€’ Payment processors (transaction data only, no financial details stored)

All service providers are contractually bound to protect your data and use it only for specified purposes.

βš–οΈ Legal Requirements

We may disclose information when required by law or to protect safety:

  • β€’ Valid legal process (subpoenas, court orders)
  • β€’ Law enforcement requests (with proper legal authority)
  • β€’ Emergency situations involving imminent harm
  • β€’ Protection of our legal rights and property

We review all legal requests carefully and provide only the minimum information required by law.

πŸ›‘οΈ Safety and Security

To protect our community, we may share limited information:

  • β€’ With safety organizations to combat abuse
  • β€’ Threat intelligence to prevent harmful content
  • β€’ Aggregated safety statistics (no personal identifiers)

🏒 Business Transfers

In the unlikely event of a business transaction:

  • β€’ Merger, acquisition, or sale of assets
  • β€’ Bankruptcy or similar proceedings

You would be notified of any such transaction, and your rights under this Privacy Policy would be preserved.

Information We Don't Share

  • ❌ Marketing Companies: We never share your data for third-party marketing
  • ❌ Data Brokers: We don't sell or provide data to information brokers
  • ❌ Advertisers: We don't share personal information with advertising networks
  • ❌ Social Media: We don't automatically share your activity on social platforms
  • ❌ Governments: We don't provide bulk access to any government (except as legally required)

5. Data Security

Protecting your information is our top priority. We implement multiple layers of security to safeguard your data against unauthorized access, alteration, disclosure, or destruction.

πŸ” Encryption

  • β€’ End-to-End Encryption: All messages encrypted before leaving your device
  • β€’ TLS 1.3: Secure data transmission
  • β€’ AES-256: Military-grade data encryption at rest
  • β€’ Key Management: Secure encryption key handling

🏰 Infrastructure Security

  • β€’ Secure Data Centers: SOC 2 Type II certified facilities
  • β€’ Network Security: Firewalls, intrusion detection, DDoS protection
  • β€’ Access Controls: Multi-factor authentication for all staff
  • β€’ Regular Audits: Third-party security assessments

πŸ‘₯ Access Management

  • β€’ Principle of Least Privilege: Minimal necessary access only
  • β€’ Role-Based Access: Permissions based on job function
  • β€’ Access Logging: All data access is monitored and logged
  • β€’ Regular Reviews: Quarterly access permission audits

πŸ” Monitoring & Response

  • β€’ 24/7 Monitoring: Continuous security monitoring
  • β€’ Incident Response: Rapid response to security events
  • β€’ Vulnerability Management: Regular security updates and patches
  • β€’ Breach Notification: Immediate notification if data is compromised

πŸ† Security Certifications

HEY YO! maintains the following security certifications and compliance standards:

  • β€’ SOC 2 Type II Compliance
  • β€’ ISO 27001 Information Security Management
  • β€’ GDPR Data Protection Compliance
  • β€’ CCPA Consumer Privacy Compliance
  • β€’ Regular penetration testing by certified security firms

What You Can Do

Security is a shared responsibility. Here's how you can help protect your account:

  • Use Strong Passwords: If you create an account, use a unique, strong password
  • Keep Software Updated: Use the latest version of your browser or app
  • Be Cautious: Don't share personal information in chats
  • Report Issues: Contact us immediately if you notice suspicious activity
  • Log Out: Log out when using shared or public devices

6. Your Privacy Rights

You have significant control over your personal information. Depending on your location, you may have additional rights under laws like GDPR (EU), CCPA (California), or PIPEDA (Canada).

πŸ‘οΈ Right to Access

You can request a copy of all personal information we have about you.

✏️ Right to Rectification

You can correct any inaccurate or incomplete information.

πŸ—‘οΈ Right to Erasure

You can request deletion of your personal information ("right to be forgotten").

πŸ“¦ Right to Portability

You can export your data in a machine-readable format.

⏸️ Right to Restrict Processing

You can limit how we process your information in certain circumstances.

🚫 Right to Object

You can object to certain types of processing, including marketing.

⚑ How to Exercise Your Rights

Exercising your privacy rights is easy and free:

  • β€’ In-App: Use privacy controls in your account settings
  • β€’ Email: Contact privacy@heyyo.in with your request
  • β€’ Live Chat: Use our support chat for immediate assistance
  • β€’ Response Time: We respond to all requests within 30 days (usually much faster)

California Privacy Rights (CCPA)

If you're a California resident, you have additional rights under the California Consumer Privacy Act:

  • Right to Know: What personal information we collect and how we use it
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt out of the sale of personal information (we don't sell data)
  • Right to Non-Discrimination: We won't discriminate against you for exercising your rights

European Privacy Rights (GDPR)

If you're in the European Union, you have rights under the General Data Protection Regulation, including all the rights listed above plus:

  • Right to Lodge a Complaint: You can complain to your local data protection authority
  • Right to Withdraw Consent: Withdraw consent for processing based on consent
  • Automated Decision-Making: Right not to be subject to automated decision-making

7. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience, provide security, and analyze how our service is used. You have control over most cookies and can manage your preferences.

Types of Cookies We Use

πŸ”§ Essential Cookies

Required

Necessary for the service to function properly. Cannot be disabled.

  • β€’ Authentication and session management
  • β€’ Security and fraud prevention
  • β€’ Load balancing and performance
  • β€’ User preferences and settings

πŸ“Š Analytics Cookies

Optional

Help us understand how users interact with our service (anonymized data only).

  • β€’ Page views and feature usage
  • β€’ Performance metrics
  • β€’ Error tracking and debugging
  • β€’ A/B testing for improvements

βš™οΈ Functional Cookies

Optional

Enable enhanced functionality and personalization.

  • β€’ Language and region preferences
  • β€’ Theme and display settings
  • β€’ Chat history and bookmarks
  • β€’ Accessibility preferences

πŸͺ Cookie Management

You can control cookies through:

  • β€’ Browser Settings: Most browsers allow you to block or delete cookies
  • β€’ Privacy Settings: Use our in-app cookie preferences
  • β€’ Opt-Out Tools: Industry opt-out tools for analytics cookies

Third-Party Cookies

We may use third-party services that set their own cookies. These include:

  • Google Analytics: Website usage analytics (anonymized)
  • Cloudflare: Security and performance optimization
  • Support Tools: Customer service chat widgets

Note: Disabling certain cookies may affect the functionality of our service. Essential cookies cannot be disabled as they are necessary for security and basic functionality.

8. International Data Transfers

HEY YO! is a global service with users worldwide. This section explains how we handle international data transfers while maintaining strong privacy protections.

πŸ‡ΊπŸ‡Έ

United States

Primary data centers with SOC 2 compliance

πŸ‡ͺπŸ‡Ί

European Union

GDPR-compliant data processing

🌏

Asia Pacific

Regional data centers for performance

Transfer Safeguards

When we transfer your data internationally, we ensure it receives the same level of protection through:

  • Standard Contractual Clauses (SCCs): EU-approved contract terms for data protection
  • Adequacy Decisions: Transfers to countries with adequate privacy laws
  • Binding Corporate Rules: Internal policies ensuring consistent protection
  • Encryption in Transit: All data encrypted during international transfers
  • Data Minimization: Only necessary data is transferred

🌍 Data Localization

Where legally required, we store data locally within specific regions. For example, EU user data is primarily processed within the EU, with transfers outside only when necessary and with appropriate safeguards.

Your Control Over International Transfers

You have options regarding international data transfers:

  • Opt-Out: You can request that your data not be transferred to specific countries
  • Local Processing: Request processing only within your region (may limit functionality)
  • Transfer Notifications: We'll notify you of any new transfer arrangements

9. Children's Privacy

πŸ”ž Age Requirement

HEY YO! requires users to be at least 13 years old. We do not knowingly collect personal information from children under 13. If you're under 18, please get parental permission before using our service.

We take children's privacy seriously and have implemented special protections for users under 18, in compliance with COPPA (Children's Online Privacy Protection Act) and similar laws worldwide.

Special Protections for Minors

πŸ›‘οΈ Enhanced Safety

  • β€’ Stricter content filtering and moderation
  • β€’ Limited contact with adult users
  • β€’ Enhanced reporting and blocking tools
  • β€’ Proactive monitoring for inappropriate behavior

πŸ”’ Privacy Controls

  • β€’ Minimal data collection for minors
  • β€’ No behavioral advertising to users under 18
  • β€’ Parental access to account information
  • β€’ Easy account deletion process

Parental Rights and Controls

If your child uses HEY YO!, you have the following rights:

  • Access: Review what information we have collected from your child
  • Deletion: Request deletion of your child's personal information
  • Consent Withdrawal: Withdraw consent and delete the account
  • No Further Collection: Prevent further collection of your child's information

πŸ‘¨β€πŸ‘©β€πŸ‘§β€πŸ‘¦ For Parents

To exercise parental rights or if you believe your child under 13 has provided information to us:

  • β€’ Email: parents@heyyo.in
  • β€’ Phone: +1 (555) 123-KIDS
  • β€’ Include: Child's username, your relationship, and verification of identity

Age Verification

We use several methods to verify user age and prevent underage access:

  • Self-Declaration: Users must confirm their age during registration
  • Behavioral Analysis: AI systems detect potentially underage behavior patterns
  • Community Reporting: Users can report suspected underage accounts
  • Manual Review: Suspicious accounts are manually reviewed by trained staff

10. Data Retention

We keep your information only as long as necessary to provide our service, comply with legal obligations, and protect our legitimate interests. We believe in data minimization and automatic deletion.

πŸ’¬ Chat Messages

  • β€’ Active Chats: Stored during conversation
  • β€’ Auto-Delete: Deleted after 30 days of inactivity
  • β€’ User Control: Delete messages anytime
  • β€’ Safety Reports: Reported content kept for investigation

πŸ‘€ Account Information

  • β€’ Active Accounts: Kept while account is active
  • β€’ Inactive Accounts: Deleted after 2 years of inactivity
  • β€’ Deleted Accounts: Immediately removed (30-day grace period)
  • β€’ Backup Systems: Purged within 90 days

πŸ“Š Analytics Data

  • β€’ Usage Statistics: Anonymized and aggregated
  • β€’ Retention Period: 26 months maximum
  • β€’ Personal Identifiers: Removed after 90 days
  • β€’ Research Data: Fully anonymized, no time limit

βš–οΈ Legal & Safety Data

  • β€’ Safety Reports: 7 years or until resolved
  • β€’ Legal Holds: Until legal matter concludes
  • β€’ Compliance Records: As required by law
  • β€’ Audit Logs: 3 years for security purposes

πŸ—“οΈ Retention Schedule Summary

Data Type Retention Period User Control
Chat Messages 30 days Delete anytime
Profile Info While account active Edit/delete anytime
Usage Analytics 26 months (anonymized) Opt-out available
Safety Reports 7 years Contact support

Factors Affecting Retention

We may retain information longer than the standard periods in these circumstances:

  • Legal Requirements: Laws may require longer retention for certain data
  • Safety Investigations: Ongoing safety or abuse investigations
  • Legal Disputes: Litigation or regulatory proceedings
  • User Requests: You can request longer retention for your own records

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We are committed to keeping you informed about any changes.

How We Notify You of Changes

πŸ“§

Email Notification

For significant changes affecting your rights

πŸ””

In-App Notice

Prominent notification when you next use the service

🌐

Website Banner

Notice on our website and help pages

Types of Changes

βœ… Minor Changes

Clarifications, formatting, or non-substantive updates

Notice: Updated policy posted with revision date

⚠️ Moderate Changes

New features, updated practices, or expanded explanations

Notice: In-app notification and email to registered users

🚨 Major Changes

Significant changes to data use, sharing, or your rights

Notice: 30-day advance notice via email, in-app, and website

πŸ“‹ Your Options When We Update

When we make significant changes, you can:

  • β€’ Continue Using: Acceptance of new terms by continued use
  • β€’ Adjust Settings: Update your privacy preferences
  • β€’ Contact Us: Ask questions about the changes
  • β€’ Delete Account: If you don't agree with the changes

Version History

We maintain a history of significant policy changes:

  • December 15, 2024: Current version - Enhanced CCPA compliance, updated cookie policy
  • September 1, 2024: Added children's privacy protections, expanded user rights section
  • June 15, 2024: Initial privacy policy published

12. Contact Us

We're here to help with any questions about this Privacy Policy or how we handle your personal information. Our privacy team is dedicated to protecting your rights and ensuring transparency.

πŸ”’ Privacy Team

πŸ“§ privacy@heyyo.in
πŸ“ž +1 (555) 123-PRIV
⏰ Response within 48 hours

βš–οΈ Data Protection Officer

πŸ“§ dpo@heyyo.in
πŸ“ EU Representative Available
πŸ›‘οΈ GDPR & CCPA Specialist

Company Information

HEY YO! Inc.

123 Innovation Drive, Suite 500
San Francisco, CA 94105
United States

EU Representative

HEY YO! Europe Ltd.
45 Tech Square, Floor 12
London EC2A 4DN
United Kingdom

Business Registration

Delaware Corporation
Registration: DE-123456789
VAT ID: GB123456789

Thank you for trusting HEY YO! with your privacy.
We're committed to protecting your personal information and being transparent about our practices.

Ready to Chat Safely?

Join HEY YO! knowing your privacy is protected by industry-leading security and transparency.

End-to-end encrypted β€’ GDPR compliant β€’ Your data, your control