Privacy Policy
How HearYes handles invitation information, responses, support requests, and technical data.
Política de privacidad
Cómo HearYes trata la información de invitaciones, respuestas, soporte y datos técnicos.
Политика конфиденциальности
Как HearYes обрабатывает данные приглашений, ответы, обращения в поддержку и техническую информацию.
Last updated: 4 October 2026.
Data controller: BONDARENKO BORYS · NIF/NIE Y9723504S · Calle Huelva 7, 06C, 29640 Fuengirola, Málaga, Spain · borman2@ukr.net.
HearYes is operated by BONDARENKO BORYS. For privacy questions, contact borman2@ukr.net.
1. What HearYes is
HearYes helps a sender create a private invitation for a specific person they already know. A recipient can open the invitation through a private link and answer without creating a HearYes account.
2. Information we process
- Sender and recipient first names entered by the sender.
- Invitation content: date idea, date/time, place, vibe, personal message, generated reveal text, and related summary data.
- Recipient response: Yes, Maybe, or Not this time, plus response time.
- Language selected for the invitation.
- Abuse reports and support messages you choose to send.
- Technical and security information reasonably necessary to operate, protect, diagnose, and prevent abuse of the service. For creation rate limits, HearYes stores one-way keyed hashes derived from the app installation identifier and source IP; raw values are not stored in the rate-limit table.
- If paid sending is enabled: purchase/subscription-free transaction status from the app store or payment provider. HearYes does not need your full payment card number.
3. Where the data comes from
Most data is provided by the sender when creating an invitation or by the recipient when responding or reporting. Some technical information is generated automatically when the service is used.
4. Why we use it
- To create, deliver, display, and manage the invitation requested by the sender.
- To save and return the recipient's response to the sender.
- To prevent fraud, abuse, harassment, and technical misuse.
- To provide support and investigate reports.
- To operate paid features when enabled and meet legal/accounting obligations.
Depending on the context and applicable law, these purposes may rely on performance of a requested service, legitimate interests in operating and securing HearYes, consent where required, and compliance with legal obligations.
5. Private invitation links
HearYes uses long, hard-to-guess public tokens for invitation URLs. The link is still a bearer link: anyone who obtains it may be able to open the invitation. Senders should share it only with the intended recipient and recipients should avoid forwarding it.
6. Service providers
HearYes currently uses infrastructure providers including Netlify for web hosting/server functions and Supabase for database infrastructure. These providers process data on our behalf according to their own service terms and privacy/security commitments. If store billing is enabled, Google Play and/or Apple may process purchase information under their own policies.
7. Retention
Invitation data is kept only for as long as reasonably needed to provide the invitation experience, preserve the response for the sender, resolve reports, protect the service, and meet legal obligations. Anti-abuse creation events are automatically kept only for the rolling security window used by the service (currently up to 30 days). Other invitation data follows the retention rules described here and can be deleted on request as described below.
8. Deletion and your rights
Senders and recipients can request access, correction, deletion, restriction, or other rights available under applicable data-protection law. Because recipients do not need an account, we may ask for enough information to identify the relevant invitation and verify the request. See Data deletion.
9. Children
HearYes is not designed for children. Users must meet the minimum age required by applicable law and the relevant app store to use the service lawfully.
10. Security
We use access controls, server-side credentials, hashed sender-owner secrets, restricted database permissions, private-token links, and other reasonable safeguards. No online service can guarantee absolute security.
11. International processing
Our service providers may process data in more than one country. Where applicable, transfers are handled under the safeguards and contractual mechanisms provided by those services and required by law.
12. Changes
We may update this policy when HearYes changes. The current version will remain available at this page with its update date.
13. Contact
Email: borman2@ukr.net
Última actualización: 4 de octubre de 2026.
Responsable del tratamiento: BONDARENKO BORYS · NIF/NIE Y9723504S · Calle Huelva 7, 06C, 29640 Fuengirola, Málaga, Spain · borman2@ukr.net.
HearYes es operado por BONDARENKO BORYS. Para cuestiones de privacidad: borman2@ukr.net.
1. Qué es HearYes
HearYes ayuda a una persona a crear una invitación privada para alguien concreto que ya conoce. La persona destinataria puede abrirla mediante un enlace privado y responder sin crear una cuenta.
2. Información que tratamos
- Nombres del remitente y destinatario introducidos por el remitente.
- Contenido de la invitación: idea, fecha/hora, lugar, tono, mensaje personal, texto del reveal y datos de resumen relacionados.
- Respuesta del destinatario: Sí, Quizá o Esta vez no, junto con la hora de respuesta.
- Idioma de la invitación.
- Reportes de abuso y mensajes de soporte que decidas enviar.
- Información técnica y de seguridad razonablemente necesaria para operar, proteger, diagnosticar y prevenir abusos. Para limitar la creación masiva, HearYes guarda hashes unidireccionales derivados del identificador de instalación y de la IP de origen; los valores brutos no se guardan en la tabla de límites.
- Si se habilitan pagos: estado de la compra proporcionado por la tienda o proveedor de pago. HearYes no necesita el número completo de tu tarjeta.
3. De dónde proceden los datos
La mayor parte procede del remitente al crear la invitación o del destinatario al responder/reportar. Algunos datos técnicos se generan automáticamente al usar el servicio.
4. Para qué los usamos
- Crear, entregar, mostrar y gestionar la invitación solicitada.
- Guardar y devolver la respuesta al remitente.
- Prevenir fraude, abuso, acoso y uso técnico indebido.
- Prestar soporte e investigar reportes.
- Operar funciones de pago cuando existan y cumplir obligaciones legales/contables.
Según el contexto y la ley aplicable, el tratamiento puede basarse en la prestación del servicio solicitado, intereses legítimos para operar y proteger HearYes, consentimiento cuando sea necesario y obligaciones legales.
5. Enlaces privados
HearYes utiliza tokens públicos largos y difíciles de adivinar. Aun así, el enlace funciona como una llave: cualquiera que lo obtenga podría abrir la invitación. Compártelo solo con la persona prevista y evita reenviarlo.
6. Proveedores
HearYes usa actualmente Netlify para hosting/funciones web y Supabase para infraestructura de base de datos. Si se habilita facturación en tiendas, Google Play y/o Apple pueden tratar datos de compra bajo sus propias políticas.
7. Conservación
Conservamos la información solo durante el tiempo razonablemente necesario para prestar la experiencia, mantener la respuesta, resolver reportes, proteger el servicio y cumplir obligaciones legales. Los eventos técnicos usados para limitar abusos se conservan solo durante la ventana de seguridad necesaria (actualmente hasta 30 días). Los demás datos de invitación siguen las reglas de conservación descritas aquí y pueden eliminarse a solicitud.
8. Eliminación y derechos
Remitentes y destinatarios pueden solicitar acceso, rectificación, eliminación, limitación u otros derechos reconocidos por la ley aplicable. Como el destinatario no necesita cuenta, podemos pedir información suficiente para localizar la invitación y verificar la solicitud. Consulta Eliminar datos.
9. Menores
HearYes no está diseñado para niños. El usuario debe cumplir la edad mínima exigida por la ley aplicable y por la tienda correspondiente.
10. Seguridad
Aplicamos controles de acceso, credenciales solo de servidor, secretos del propietario almacenados mediante hash, permisos restringidos de base de datos y enlaces con tokens privados. Ningún servicio online puede garantizar seguridad absoluta.
11. Tratamiento internacional
Nuestros proveedores pueden procesar datos en más de un país. Cuando corresponda, las transferencias se gestionan mediante las garantías y mecanismos contractuales exigidos por la ley.
12. Cambios
Podemos actualizar esta política cuando cambie HearYes. La versión vigente estará siempre disponible aquí.
13. Contacto
Email: borman2@ukr.net
Обновлено: 4 октября 2026 года.
Оператор данных: BONDARENKO BORYS · NIF/NIE Y9723504S · Calle Huelva 7, 06C, 29640 Fuengirola, Málaga, Spain · borman2@ukr.net.
Оператор HearYes: BONDARENKO BORYS. По вопросам конфиденциальности: borman2@ukr.net.
1. Что такое HearYes
HearYes помогает отправителю создать приватное приглашение конкретному человеку, которого он уже знает. Получатель открывает приглашение по приватной ссылке и может ответить без создания аккаунта.
2. Какие данные мы обрабатываем
- Имена отправителя и получателя, введённые отправителем.
- Содержание приглашения: идея, дата/время, место, настроение, личное сообщение, текст reveal и связанные данные.
- Ответ получателя: Да, Может быть или Не в этот раз, а также время ответа.
- Выбранный язык приглашения.
- Жалобы на злоупотребления и сообщения в поддержку, которые вы сами отправляете.
- Техническая и защитная информация, разумно необходимая для работы, диагностики, безопасности и предотвращения злоупотреблений. Для ограничения массового создания HearYes хранит односторонние хеши, полученные из идентификатора установки приложения и исходного IP; исходные значения в таблице лимитов не сохраняются.
- Если включается платная отправка: статус покупки от магазина/платёжного провайдера. HearYes не требуется полный номер банковской карты.
3. Откуда берутся данные
Большая часть данных вводится отправителем при создании приглашения или получателем при ответе/жалобе. Часть технической информации создаётся автоматически при использовании сервиса.
4. Зачем мы их используем
- Создать, доставить, показать и обслужить приглашение.
- Сохранить ответ получателя и вернуть его отправителю.
- Предотвращать мошенничество, давление, преследование и технические злоупотребления.
- Оказывать поддержку и разбирать жалобы.
- Обслуживать платные функции после их включения и выполнять юридические/бухгалтерские обязанности.
В зависимости от ситуации и применимого законодательства основаниями могут быть оказание запрошенной услуги, законный интерес в работе и защите HearYes, согласие там, где оно требуется, и выполнение юридических обязанностей.
5. Приватные ссылки
HearYes использует длинные трудноугадываемые токены. Но ссылка всё равно работает как ключ: любой человек, который её получил, потенциально может открыть приглашение. Не публикуйте её открыто и не пересылайте без необходимости.
6. Поставщики инфраструктуры
Сейчас HearYes использует Netlify для сайта/серверных функций и Supabase для базы данных. При включении оплаты Google Play и/или Apple могут обрабатывать сведения о покупке в соответствии со своими политиками.
7. Срок хранения
Данные хранятся только столько, сколько разумно необходимо для работы приглашения, сохранения ответа, рассмотрения жалоб, защиты сервиса и выполнения правовых обязанностей. Технические события, используемые для ограничения злоупотреблений, автоматически хранятся только в пределах защитного окна (сейчас до 30 дней). Остальные данные приглашений хранятся по правилам этой политики и могут быть удалены по запросу.
8. Удаление и права
Отправитель и получатель могут запросить доступ, исправление, удаление, ограничение обработки и другие права, доступные по применимому законодательству. Поскольку получателю не нужен аккаунт, мы можем запросить достаточно информации, чтобы найти приглашение и проверить запрос. См. Удаление данных.
9. Дети
HearYes не предназначен для детей. Пользователь должен соответствовать минимальному возрасту, который требует применимое законодательство и соответствующий магазин приложений.
10. Безопасность
Мы используем разграничение доступа, серверные секреты, хеширование owner-secret отправителя, ограниченные права базы данных и приватные токены ссылок. Ни один онлайн-сервис не может гарантировать абсолютную безопасность.
11. Международная обработка
Инфраструктурные поставщики могут обрабатывать данные в разных странах. Там, где это требуется, применяются предусмотренные законом договорные и иные механизмы защиты.
12. Изменения
Политика может обновляться вместе с HearYes. Актуальная версия и дата обновления всегда будут доступны на этой странице.
13. Контакты
Email: borman2@ukr.net