Privacy Policy
Last updated: 11 October 2026
In short
HearMe is only for people aged 18 and over. These are the main things we collect. The sections below say how each item is used and how long it is kept.
- Country, worked out from your IP address by Cloudflare. We never use GPS or your precise location
- IP address, used for safety and to work out your country, and kept in our web server logs for up to 90 days, and longer in a few places listed in Section 8. Our app's own logs also record it with suspected abuse, such as a failed bot check, and are deleted after 14 days
- Nickname, and the avatar and profile details you choose to add
- Email address: optional, only if you create an account or sign in with Google
- Session and user IDs, which keep you signed in and link your data to your session or account
- "I am": the gender you give before your first chat, used for matching and never shown to the people you talk to
- Purchase history: only if you buy Premium
- Chat messages you send in text chats, direct messages and rooms, and reactions in the General room (and old poll votes, kept but not shown)
- Photos: optional, only a profile picture or banner you upload
- Reports, blocks and friends
- Call-quality diagnostics: whether a voice call connected and could be heard. Never the audio
- App install ID or browser device ID: a random ID the Android app or your browser makes, used to apply bans, including under-18 bans, to that phone or browser
- Report voice clips (website only): up to the last 60 seconds of the other person's audio, sent only when you report during a call, deleted within 7 days, except a clip on a report a moderator confirms as child safety or under 18, which is kept as evidence for one year from the confirmation
We don't sell your data. We share it only with the service providers in Section 7. All data is encrypted in transit (HTTPS/TLS, and encrypted WebRTC for voice calls). You can delete your account and its data at any time: see Delete account.
1. Age Requirement
HearMe is strictly for users aged 18 and over. We do not knowingly allow anyone under 18 to use the Service.
We use automated systems to detect signals that a user may be under 18. If you confirm a birth year under 18, we delete your account straight away (if a Premium subscription can't be cancelled at that moment, we sign the account out and remove its 18+ confirmation instead). If our checks show that someone is under 18, we ban their account and device permanently. If a report shows it, a moderator bans the account and its device. Neither ban can be appealed. Safety records are kept as Section 4 describes.
If you believe a minor is using HearMe, report them in-app or email support@hearme.chat.
2. Information We Collect
Automatically
- IP address, and the country derived from it (via Cloudflare). The last IP address we see for your session is also saved on your account record. For 24 hours we also keep the IP address your app or browser last connected from, so a child-safety ban can block it (deleted when you delete your account)
- Session ID and device identifier
- Browser and basic device information
- Pages visited, and time and duration of visits
- What you do on HearMe, counted by our own servers: for example that you started a search, found a match or opened Premium, and call-quality measurements (whether the audio connected and could be heard, audio level numbers, the type of connection, your browser family and platform). Never the audio itself. These are stored with your session ID and your country (Section 6)
Information you give us
- Email address (if you create an account, or sign in with Google)
- If you sign in with Google: a keyed one-way code (hash) of your Google account ID
- Username, your picture (a photo you upload, or one of our emoji pictures), a profile banner if you add one, and profile details you choose to add: a display name and the interests you list, and, if you have an account, a short bio, up to three languages, what you're looking for (friends, just talk or language practice) and a song you're listening to, with a short note
- Chat preferences: interests, gender filter, country/region filter
- Your gender, as you declare it before your first chat. The checkbox screen offers Male, Female or Other; the birth-year screen and Settings offer Man, Woman or Prefer not to say. "Other" and "Prefer not to say" are kept as "not specified", and a gender that is not specified is never used for matching. The answer is used for matching, and counted (with your session ID, never your name) in our private usage statistics, for example how many searches come from each answer. It is never shown to the people you talk to, on your profile, or in any public count. It is kept on your device and, if you have an account, on your account. You can change it in Settings a limited number of times in any 24 hours.
- Your age: before your first chat we ask you to confirm you are 18 or older. Most people see the checkbox screen, which has no birth year: you tick a box to confirm you are 18 or older, and another to agree to the Terms and Privacy Policy. The birth-year screen is shown instead if you are in the EEA, the UK or Switzerland, or we can't tell your country, and you have not turned analytics on; if this device is blocked after someone confirmed a year under 18; or if the checkbox screen can't be loaded. It asks for your birth year. We keep only whether you are 18 or over, never the year. If you confirm a year under 18, we block starting chats on that device for 7 days.
- The checkbox screen's confirmation record: when you pass the checkbox screen we save one record of it: that you confirmed you are 18 or older and agreed to the Terms and Privacy Policy, which version of the Terms that was (its date), which version of the screen it was, the gender you picked (male, female or other), the time, your random screen ID (the
hm_gatecookie, Section 6) and, if you have a session, your session ID. It has no birth date and no IP address. The birth-year screen writes no such record, only the yes-or-no 18+ answer. Section 8 says how long we keep these records. - Payment details — handled entirely by our payment processor. We never see or store your full card number. We do keep a record of each Premium purchase (Section 8).
- Browser push notifications, if you turn them on: your browser's push subscription (its address at the browser's push service and its encryption keys), the topics you chose (for example "Ring me" or the voice hour), your session or account ID, and when you last tapped a notification. A web message notification shows only "New message from <name>" (and a friend's call "<name> wants to talk"), never the message text
- Ban appeals: your text, linked to the ban and to your session or account
Generated by your use of the Service
- XP, level, friends list, and the rooms you have joined (today, whether you are a member of the General room)
- Direct messages, and what you post in the General room: messages, GIFs and stickers, replies (which show a short quote of the message you answer), @mentions and reactions. Old polls and votes, from before polls were removed in October 2026, are kept but not shown. You can edit a text message for 2 minutes after sending it; the edit replaces the text and we keep no earlier version. A message someone has reported can't be edited. A message you delete is deleted at once, with its reactions and any poll votes
- Chat records: which two sessions were matched, when, for how long, and whether it was text or voice. No message content
- Stranger Jury cases, votes and comments. For a case you ask about we keep the title, the story and the two sides you wrote, the category, the country you posted it from, and the votes, reasons and comments people add. Votes and comments don't store a country. We keep no name or contact detail from you: your case, votes and comments are tied only to pseudonymous keys, a hash of the random device ID in the
hm_udcookie (Section 6), of your session, or of your account if you are logged in, and a keyed hash of your IP address (we don't store the address itself), used only to limit abuse. Your private link is stored only as a hash. If you ask about a case, we also keep the comments you hid from your own view and the people you blocked from commenting on your cases (their pseudonymous keys, not a name). - Stranger Jury notifications, if you turn them on: your browser's push subscription, linked to the case it is for
- Reports you submit, or that are submitted about you
- Safety and moderation records (see Section 4)
3. How We Use Your Data
- To match you with other users and run text chat, voice calls, rooms and direct messages
- To create and manage your account, and provide Premium features you purchase
- To keep the platform safe — detect abuse, minors, fraud, and illegal activity
- To show your Stranger Jury case to people who confirm they are 18 or over, count their votes, and tell you when the verdict is in
- To act on reports and enforce our Terms of Service
- To understand usage and improve the Service
- To comply with the law and respond to lawful requests
We do not sell your personal data.
Legal bases (for users in the EU/EEA, UK, and similar jurisdictions): performance of a contract (running the Service you asked for), legitimate interests (safety, abuse prevention, improvement), legal obligation (safety and law-enforcement duties), and consent (analytics cookies and marketing emails, where applicable).
4. Safety, Moderation, and Automated Scanning
You should understand exactly what this means in practice.
Automated checks. Messages sent on HearMe pass automated checks by software. Today these detect:
- Users who state or indicate that they are under 18
- In one-to-one chats, direct messages, rooms and posts: content our rules don't allow, such as slurs, threats, encouragement of self-harm and sexual content involving minors; outside direct messages, also contact details and links
- In one-to-one chats, a message that suggests someone may be in distress: we show the writer support lines, and the other person a short note with support lines that doesn't quote the message. We keep a record that this happened in that chat (the chat's ID, and whether it went to the writer or the other person), never the message
- Spam patterns, through rate limits and a bot challenge
Profile pictures and banners you upload are checked by an automated image filter on our own server.
Consequences. If your message is flagged, it may be blocked from delivery, and you may receive a warning, have your chat ended, or have your account suspended or permanently banned. A ban also blocks each phone or browser the banned account is used on, until 30 days after it was last used there (never longer than the ban). If we can recognise the phone or browser the account last used before the ban, it stays blocked for as long as the ban lasts. An under-18 ban blocks the phone or browser it was detected on for as long as the ban lasts. For a ban a moderator makes for child safety or for being under 18, the IP address the account used in the last 24 hours is blocked for 72 hours, if there is one. For any other ban, a moderator may block the internet connection (IP address) for up to 30 days. The automatic under-18 ban never blocks an IP address. Other people using the same device or connection may be affected and can write to us. A ban on an account can be appealed once, within 30 days of when it began (except child-safety and under-18 bans). A block on a device or connection can't be appealed.
Safety records. When our systems flag content, or when a user reports you, we create a safety record. This can include the message content, the matched text, your user or session ID, your IP address, and a timestamp. We delete these records 12 months after they are made, or when a ban they support ends if that is later — and later still if legally required or if needed for an ongoing investigation — so we can enforce bans, catch repeat offenders, and respond to lawful requests. This deletion runs automatically every day. The exception is a report a moderator confirms as child safety or under 18: we keep that report, a frozen copy of the messages shown with it, and its audio clip (if it has not already been deleted) as evidence for one year from the confirmation, or longer if a moderator extends it for the authorities, even after you delete your account. Reports marked Under 18 are shown to moderators first.
Human review. Flagged content and reports may be reviewed by our moderation team.
Abuse prevention. We use Cloudflare Turnstile to prevent abuse. It runs every time you post a Stranger Jury case or comment, and when you ring someone from their invite link (hearme.chat/u/…) (a check you normally don't see, which sends Cloudflare a one-time token and your IP address), and otherwise only when we see unusually rapid activity, such as many new chats or messages in a short time. It may process your IP address and browser details to do so. See Cloudflare's Privacy Policy at https://www.cloudflare.com/privacypolicy/.
Voice calls. Audio is transmitted peer-to-peer using WebRTC, and relayed through our servers only when a direct connection isn't possible. We do not record or store your calls. Every one-to-one call is private. The only exception is a report: if the person you are talking to is on the website, they can send us the last 60 seconds of audio held in their browser, which a person on our team reviews and which we delete within 7 days, except a clip on a report a moderator confirms as child safety or under 18, which is kept as evidence for one year from the confirmation. The Android app holds no audio. Reported audio is not transcribed automatically. There is no video on HearMe.
Stranger Jury. Everything you write for a case or a comment is checked by automated filters when you send it: for contact details (phone numbers, email addresses, social media handles, links), names, sexual content, signs that someone is under 18, threats and hate, and signs that someone may harm themselves. Contact details are blocked. If something in a case looks like a person's name, we ask you to confirm it isn't a real person's name before it is posted, and those cases are flagged for review; in a comment, anything that looks like a name is blocked. A person looks at flagged items. If a case or comment looks like someone may hurt themselves, it is not posted and not stored: we show support lines instead. For cases we keep only an event with the reason, the country and your session ID, no text. People can report a case or a comment; when several different people report one, or the person who asked and one other person report a comment on their case, it is hidden until a moderator reviews it, and a moderator can remove it or stop the writer using Jury (the same bans as elsewhere, up to 30 days for a device, session or connection, and linked to your account if you have one).
General room. Messages in the General room pass the same automated checks as chats when you send them, and are blocked if they break our rules. Only people with an account can send GIFs and stickers. Other people see your nickname and picture, never your session ID; each message carries a random public ID for your profile, so tapping your name opens your profile card (see "Your profile" below). When two different people, on different connections, report a message, it is hidden from everyone until a moderator reviews it. Our moderators, who are HearMe's own admins, can see every message from the last 7 days, including hidden ones, which session wrote each one, and the reports on it, including who made them. They can delete, hide or restore a message, mute someone in the room for 10 minutes or 24 hours, pin a message, turn on slow mode, or ban an account; each action is logged with the moderator and the time. So that a mute also reaches the device and connection someone posts from, we keep, for 8 days, your session, your device ID and a keyed code of the connection you last posted from (never the IP address itself). For each reported message we keep for 8 days who reported it and a keyed code of their connection, and, until 30 days pass without reports hiding a message, which people's reports hid whose messages, so moderators can spot people reporting someone together. We don't keep who was online or typing. When you join the General room we keep a record that your session is a member of it, when you joined and when you last opened or posted in the room (at most once an hour) and your role in the room (today always "member"), nothing else, so the room lets you back in (on any device where you're signed in to your account; a guest's session stays in one browser) until you leave it, and so the member count only counts people who opened or posted in the room in the last 30 days. If you joined as a guest and then sign up or log in on the same browser or phone, your membership moves to your account (the guest's record is removed), so you are counted once. It doesn't move if the device is blocked as under 18, if the guest or the account is banned, or if the account hasn't confirmed it is 18 or over. When you sign up or log in, a short-lived note on our server (about 10 minutes) tells the guest's other open tabs to switch to your account. The record is removed when you choose Leave room, when you are banned from HearMe (at the latest the next time you try to join), when we block a person under 18, or when the account is deleted (a guest account after 30 days without use). Other people see only how many members the room has, and only from three, never who they are; our moderators can see who the members are.
Your profile. What it shows. If you have an account, your profile card shows your nickname, your emoji or the photo you uploaded (as a still picture), and the month you joined. If you add them, it also shows a short bio (up to 60 characters; a longer bio, or one our filters don't allow, is saved but not shown), your interests, up to three languages, what you're looking for (friends, just talk, or language practice) and "Listening to": a song from Apple's catalogue with an optional note of up to 100 characters, shown for 24 hours. Your profile card never shows your age, gender, country, email address or session ID. A guest's card shows only a nickname, an emoji and the word "Guest". Your detailed profile page, which only you, your friends and someone you have chatted with can open, also shows your @username, "Member since", your bio and interests (the same filtered text as the card), your Premium or staff badge, your frame, name colour, banner, title, chat-bubble style and profile effects if you set them, how many friends you have and some of their names and pictures, and your badges and achievements; on your detailed profile page your uploaded picture plays if it is animated. Someone you've blocked, or who has blocked you, can't open it. Your full profile page is at your @handle (for example hearme.chat/@yourhandle). It shows what your card shows, as a still picture: your nickname, your emoji or photo, your @handle, the month you joined, and your bio, interests, languages, what you're looking for and your song if you added them.
Who can see it. People on HearMe can open your card from a chat or call with you, their chat and call history, a direct message, a friend request or notification, a message you posted in the General room, a friends list, or a link to your full profile page (who can open that page is described below). Your friends also see on your card whether you are online right now; nobody else does. In the General room, people see your photo next to your messages if you have an account and uploaded one (otherwise your emoji). Someone you've blocked, or who has blocked you, can't open your card. Any logged-in person who has confirmed they are 18 or over can open your full profile page at your @handle, unless you choose "Friends only" in Edit profile: then only you and your friends can. Guests can't open full profiles; they are asked to sign up. A person you've blocked, or who has blocked you, can't open it either, and neither can a banned account. Your @handle is shown to the people who are allowed to open your full profile (on your card and on the page itself); a card opened from a one-to-one chat with a stranger doesn't show it. On Who's online, people see your nickname, your picture (your photo if you have an account and uploaded one, otherwise your emoji), your country flag, a Premium badge unless you've hidden it, a staff badge, whether you're in a chat or call, whether you're up for text, voice or either, and whether you take Say hi. The card they open from there shows only your nickname, your picture, whether you have an account and whether you're friends or have a friend request open, and lets them say hi, add you as a friend, report or block you. A guest's photo is never shown. Someone who sees your photo on Who's online or in the General room may have it kept in their browser for up to 5 minutes. To let you open someone from Who's online, we keep, for 30 minutes, which people your list showed you.
Your public ID. Your profile has a random public ID, never your session ID. It is not sent in chats or calls with strangers. It goes with your General room messages and appears in friends lists, friend requests and direct-message lists, so people can open your card. We keep it until your account is deleted.
Your @handle. If you have an account, you get an @handle the first time it is needed: two ordinary English words and four digits, like calmriver4821, not made from your nickname, and it stays the same if you change your nickname. You can pick your own in Edit profile (letters, numbers and underscores, 3 to 20 characters; names that read as HearMe or its staff are refused), once every 30 days. People who know your handle can open your full profile if your setting allows it. When you change it, the old one is kept for nobody for 30 days (you included), then it can be taken, and nothing forwards from it. When you delete your account, your @handle is normally kept for nobody for 30 days, then it can be taken. We keep it until your account is deleted. Guests have no @handle.
How to change or remove it. On your profile page, tap Edit profile to change your bio, emoji, photo (Remove photo), your @handle, who can open your full profile, languages, "Looking for" and song (Remove song). Your interests are edited in "Your profile in a chat" on your profile page. A song also disappears by itself after 24 hours, and we delete it within a day after that. When you delete your account, we delete your profile.
Checks and reports. We check bios, interests and songs (title, artist and note) with our text filters. One that suggests you are under 18 is kept as a safety record (see above). A new photo is shown to other people only after an automatic image check passes. If the check can't run, the photo waits on our server where other people can't see it, and they keep seeing your previous picture (or your emoji if you had none) until a later check passes; a photo that fails the check is deleted. A banner or a profile effect you upload goes through the same check, and if it can't run the upload is refused, so you can try again later. When someone reports you, from a chat, a call, a direct message, a General room message or your profile, a copy of your profile as saved goes with the report, including a bio or note the card hides: bio, interests, languages, what you're looking for, which emoji you use and whether you have a picture, and your song (title and artist, Apple's track ID, its note, when it was set and when it was due to expire, even if it has since expired). A copy in a report follows the report (Section 8).
Law enforcement and child safety. We will preserve and disclose data to law enforcement or child-protection authorities where we are legally required to, or where we believe in good faith it is necessary to prevent serious harm — including any case involving child sexual exploitation or abuse. We have zero tolerance for this content.
5. What We Store, and What We Don't
| Type | Stored? |
|---|---|
| Random 1-on-1 text chat | Kept for up to 24 hours after the chat's first message, so moderators can see context if someone reports (the last 30 messages of a chat you were in). Longer when flagged by our safety systems or included in a report |
| Random 1-on-1 voice calls | Not recorded by us. If the other person is on the website, their browser keeps the last 60 seconds in memory during the call and sends it to us only if they report you; we delete it within 7 days, except a clip on a report a moderator confirms as child safety or under 18, which is kept as evidence for one year from the confirmation. The Android app records nothing: a report from it sends only when the call started and ended |
| Direct messages with friends | Stored, so you can see your history, until you or the other person deletes their account. Longer when they are part of a report: a report keeps a copy |
| General room messages and reactions (old polls and votes: kept, not shown) | Stored. When the General room is open, anyone on HearMe can read the last 7 days of the room, even before joining; after 7 days a message is no longer shown to anyone. The rooms list shows anyone who opens it, without a session, the room's newest message from the last 30 minutes (the sender's nickname and the text); we ask search engines not to quote it. We don't delete room messages on a schedule yet, so a message stays on our servers until you delete it, a moderator deletes it, or you delete your account (a guest account is deleted after 30 days without use). Reactions, and an old poll's votes, go with the message they are on. An old poll isn't shown, so you can't delete it yourself: a moderator can, and deleting your account removes it |
| Reported chats | Stored as part of the report, so moderators can see context: what the reporter wrote, the last 30 messages of the chat or direct-message conversation, the reported person's profile (bio, interests, languages, what they're looking for, emoji, whether they have a picture, and their song with its note and when it was set), and for a voice call when it started and ended. A report made elsewhere (a ring or a profile card) keeps a copy of what was reported. A report about a General room message keeps a copy of that message as it was when it was reported (for a GIF or sticker, its link), and a copy of the reported person's profile as for other reports, so a moderator can review it after the message is gone |
| Stranger Jury cases, votes and comments | Stored, and visible to anyone who confirms they are 18 or over while the case is live or has a verdict. A shared case page is not indexed by search engines. Your case title and the verdict also appear on a share picture that anyone with the link can see. Your private link lets you delete it any time |
| Chat records (who was matched with whom, when and for how long; no content) | Stored until the account is deleted, then removed within 24 hours (Section 8) |
| Safety-flagged messages | Stored until we delete them, which happens automatically after 12 months, or later while a ban or appeal they support is in effect (Section 4). A report a moderator confirms as child safety or under 18 is kept one year from the confirmation |
6. Cookies and Local Storage
Essential cookies handle your session and keep you signed in. These are required for the Service to work. The hm_general cookie only says whether the General room is open, and the hm_pv2 cookie only whether the new profiles are on; neither holds anything about you.
Analytics. We measure page views, and what you do on HearMe (for example starting a search, finding a match or opening Premium), with Google Analytics 4. In the EEA, the UK and Switzerland, or when we can't tell your country, it runs only if you accept cookies in the banner; everywhere else it runs by default, and you can turn it off at any time in "Cookie settings" at the bottom of every page on the website.
Advertising. We may show ads from Google (Google AdSense) on our articles and guides: the blog and our guide, comparison and country pages. We never show ads in chats, voice calls, rooms, messages or profiles, and Premium members see no ads. Google and its partners may use cookies and similar identifiers to show ads, measure them and, if you allow it, personalise them based on your visits to HearMe and other sites. In the EEA, the UK and Switzerland, or when we can't tell your country, we ask for your consent first and use advertising cookies only if you accept; everywhere else they are on by default. Anyone can switch off personalised ads at any time in "Cookie settings" at the bottom of every page on the website, or in Google's My Ad Center. Without that consent Google may still show non-personalised ads, chosen from the page you are reading rather than from your activity, and it never affects your access to HearMe. To learn more, see How Google uses information from sites or apps that use its services.
Our own usage counts. Separately from Google Analytics, our servers count how HearMe is used so we can fix what doesn't work: that a visit happened, the name of the site that sent you (for example "google.com", never the full link) or a campaign tag, which features were used (a search, a match, a reminder), a message posted in the General room (whether it was text, a GIF or a sticker, never its words; before polls were removed in October 2026, also a poll and a poll vote), your country (from Cloudflare, never from you), the gender answer you gave when you searched (counted as man, woman or not specified, for our private statistics only), whether a search asked to meet only men or only women and whether that filter was applied, call-quality measurements, and how long searches and calls took. These counts are tied to a random ID kept in your browser's local storage and to your session, never to your IP address, name, email or what you say. They are not shared with anyone and are not used for advertising. If you're in the EEA, the UK or Switzerland, or we can't tell your country, the counts your browser sends (visits and page steps) are kept without that ID or your session until you turn analytics on (Accept in the banner, or Cookie settings). Nothing is stored in your browser for them, and any ID saved earlier is removed. The counts our servers make themselves (searches, matches, calls and call quality) are always stored with your session ID.
Age-check cookies. hearme_age_verified (essential, 30 days) remembers that you passed the 18+ check: a yes, and nothing else. Both screens set it. hearme_u18 (essential, 7 days) is set only if you confirm a birth year under 18 on the birth-year screen, and blocks starting chats on that device. hm_gate (a random ID, 180 days) decides which of the two screens you see, so you keep seeing the same one. It is saved on the checkbox screen's record (Section 2). We set it when the checkbox screen is about to show. If you're in the EEA, the UK or Switzerland, or we can't tell your country, we don't set it until you turn analytics on, and you get the birth-year screen. It is not used for advertising.
Stranger Jury. Jury uses one essential cookie, hm_ud: a random device ID, kept for 1 year. We store only a hash of it, to count one vote per person, apply limits and link your reports. It is not used for advertising or analytics. If you ask about a case, your browser also keeps the private owner code for it in local storage (hm_jury_own) so you can come back to your verdict. It goes to us only when you ask for your own case.
Local storage remembers your preferences (sound, theme), the random usage-count ID above, a random device ID used to apply bans to this browser, how long an under-18 block on this device lasts, and for the General room: the time you last read the room, whether you left the room rules open or closed (so they open the way you left them; the first time, they open expanded), whether this browser is one of the 1 in 10 that don't see the General room preview while waiting for a match (a random draw kept in this browser; our usage counts of a search or a room visit say which of the two groups it is in, so we can tell whether the preview helps. If you're in the EEA, the UK or Switzerland, or we can't tell your country, we don't make it until you turn analytics on, and you always get the preview), when to show the GIF button again after GIFs were busy (at most 10 minutes), and, if you send a GIF or sticker, the random GIF ID described in Section 7.
You can clear cookies and local storage at any time to reset your session.
7. Third-Party Services
Each has its own privacy practices:
- Cloudflare — CDN, security (including Turnstile abuse checks), country detection
- Google Analytics — usage statistics on the website: only after you accept in the EEA, the UK and Switzerland (and where we can't tell your country), on by default elsewhere and can be switched off in Cookie settings
- Google STUN servers — during a voice call your browser asks them for your public address so a direct connection can be tried; they see your IP address, never your audio
- KLIPY — GIFs and stickers in the General room. When you open the GIF picker, your browser contacts KLIPY to load GIFs. A GIF or sticker someone posts in the room is also loaded from KLIPY by the browser of everyone who sees it (with reduced motion on, only once you tap to play it). KLIPY sees your IP address and browser like any website your browser loads from, that the request came from hearme.chat, the words you search for and the categories you tap. Searches ask for KLIPY's strictest content setting. We don't send KLIPY your name or account, and our servers send KLIPY nothing. So that the picker can show your recent GIFs and stickers, the first time you send one your browser makes a random ID that stays on this device; it is sent to KLIPY with each GIF or sticker you send (with the words you searched for, if any) and when you open Recent. We never link it to your account or keep it on our servers. In the EEA, the UK and Switzerland (or where we can't tell your country), unless you have allowed analytics cookies, no such ID is made or sent and the picker has no Recent tab. A GIF you send is stored as a link to KLIPY's image, as part of your message. In the Android app, the app (not a browser) contacts KLIPY directly. It makes and sends no such ID or device ID: KLIPY sees your IP address, the words you search for, the categories you tap and which GIF or sticker you send.
- Apple (iTunes Search) — the song on your profile. When you search for a song, your browser asks Apple's iTunes service directly; Apple sees your IP address and browser, that the request came from hearme.chat, and the words you search for. In the Android app, the app (not a browser) asks Apple directly, only after you tap Add a song and type at least two characters, and sends no cookies or sign-in. Apple sees your IP address, the app's user agent and the words you search for, and nothing is linked to your account. A song's picture loads from Apple's servers in the search results and when anyone views the profile card, and its 30-second preview only when someone plays it. Our servers send Apple nothing; we store the song's title, artist, Apple's track ID and links (picture, preview, page), your note, and when it was set and when it expires. Apple and Apple Music are trademarks of Apple Inc., registered in the U.S. and other countries.
- Google OAuth — optional sign-in with Google
- Our payment processor (currently Freemius) — Premium subscription billing on the website (we do not store full card details)
- Resend — sends the emails we send you, such as verification codes, password-reset links and a welcome email, so it receives your email address and the message
- Zoho Mail — receives the email you send to our support address and your replies to our emails, so it sees your address and your message
- Browser push services — run by your browser's maker (for example Google, Apple or Mozilla); they deliver the web notifications you turn on
- Backblaze B2 — stores our encrypted backups (Section 11); we encrypt them before they leave our server, so the provider cannot read them
8. Data Retention
- Random 1-on-1 text chat (the last 30 messages of a chat you were in): deleted 24 hours after the chat's first message, so moderators can see context if someone reports in that time. Deleting your account does not remove it sooner
- Messages in the General room (text, links to GIFs and stickers; old polls are kept but not shown), with their reactions and votes: shown in the room for 7 days. We don't delete them on a schedule yet, so they stay until you delete them, a moderator deletes them, or you delete your account (an old poll isn't shown, so only a moderator or your account's deletion removes it). Reports about room messages and the log of moderators' room actions follow the safety-record and moderator-log lines below
- Your General room membership (that your session joined the room, when, and when you last opened or posted in it; a guest's moves to the account when they sign up or log in, unless the device is blocked as under 18, either side is banned, or the account hasn't confirmed 18+): until you leave the room, are banned from HearMe (at the latest the next time you try to join), are blocked as under 18, or delete your account; a guest account's goes with it after 30 days without use
- The song on your profile: shown for 24 hours, then deleted within a day. Your other profile details: until you change them or delete your account
- Chat records (which two sessions were matched, when, for how long, text or voice; no content): until the account is deleted, then removed within 24 hours
- Reported voice clips (last 60 seconds): deleted within 7 days, except a clip on a report a moderator confirms as child safety or under 18, which is kept as evidence for one year from the confirmation
- Stranger Jury cases, with their votes, comments and reports: until you delete the case with your private link or, if you're logged in, from My cases on your profile, or until we remove it
- The keyed IP hash kept with a Jury case, vote, comment or report: cleared 30 days after it is made (the case, vote or comment itself stays as described above)
- People you blocked from commenting on your Jury cases: we delete these 12 months after you block them (they are also deleted when you delete your account); comments you hid from your own view go with the case
- Stranger Jury notification links: until you turn them off, your push subscription ends, or the case is deleted
- Server logs (our web server): your IP address and the page address, 90 days. The private link's code is never in a page address. Our voice relay server can log the IP address of any device that connects to it while setting up or during a call, for up to 15 days. Our app's own logs also record the IP address with suspected abuse, such as a failed bot check, and are deleted after 14 days (logs written before 10 October 2026 are deleted by 25 October 2026)
- Browser push subscriptions: until you turn notifications off, the push service tells us the subscription has ended, or you delete your account. "Ring me" and voice-hour opt-ins also end after 30 days without a tap on a notification
- Usage counts and other event records (Section 6): we plan to delete them 13 months after they are made, but nothing deletes them on a schedule yet, so for now they stay. Counts kept with your session ID are also deleted when you delete your account
- Your session cookie: it expires 30 days after it was last set; the data linked to your session follows the guest account and account lines below
- The log of our moderators' actions (for example that an account was banned or unbanned): 12 months, also after the account is deleted
- After you delete your account: a short record that the session was deleted, for 31 days, or for as long as a ban on it lasts, so a deleted account can't be used to escape a ban; and the name you went by, for 24 hours
- When you delete your account, your General room membership, messages, reactions and votes are deleted; replies other people wrote to you no longer quote you, and messages that @mentioned you no longer point to your account (the words others wrote stay as they wrote them). Logging out, or deleting your account on the website, also removes the random GIF ID from that device; KLIPY's list of GIFs sent under the old ID stays with KLIPY, linked to nothing of ours.
- Guest accounts: a guest session ends after 30 days of inactivity. We delete the guest account then too, automatically, along with the data linked to it. A guest account whose Premium is still running is kept until that ends, and deleted once it has ended and the guest has been inactive for 30 days
- Account data, including the last IP address we saw for your account: until you delete your account
- Safety and moderation records: until we delete them. We do that automatically after 12 months, or when a ban they support ends if that is later, or later still where legally required or needed for an ongoing investigation. A report a moderator confirms as child safety or under 18, with a frozen copy of the messages shown with it, is kept one year from the confirmation (or longer if a moderator extends it for the authorities), even after you delete your account
- Age-confirmation records of the checkbox screen (Section 2): we delete them automatically after 12 months. The ones linked to your session are deleted at once when you delete your account; a record with only the screen ID can't be linked to you, so it stays until that 12-month deletion
- Ban records: kept for as long as the ban is in effect. A record of the connection (IP address) stops blocking after at most 30 days (72 hours for a child-safety or under-18 ban), but we do not delete it on a schedule yet
- Ban appeals: kept until the ban ends or is lifted, or for 12 months after the appeal, whichever is later, and while any other ban on you is in effect. We delete them then, automatically
- When an account is banned, we make a keyed one-way code (hash) of its verified email address and of its Google account. The email code ignores anything after a "+" in the address, and dots in a Gmail address, so those forms count as the same address. These codes are kept for as long as the ban lasts, including after the account is deleted, so the ban can't be dodged by signing up again. The address itself is not kept. When a timed ban ends the code stops blocking anyone, and we then delete it automatically.
- Billing records: when you buy Premium we keep a record of the purchase. For payments on the website that is the payment processor's full notice to us: it includes the email address you paid with and whatever else the processor sends (such as your name or country), the plan, the amount and the processor's IDs. It is no longer tied to your account record, but the email address still identifies you. These records stay when you delete your account so we can handle refunds and disputes. We keep them for as long as tax and accounting law requires; we have no automatic deletion for them yet, so for now they stay. Our payment processor, Freemius, also keeps its own records
9. Your Rights
Depending on where you live, you may have the right to access, correct, delete, object to or restrict our processing of your data, withdraw consent, request data portability, and complain to your local data protection authority.
You can delete a Stranger Jury case yourself at any time: open your private link (it looks like hearme.chat/r#…) and tap Delete or, if you're logged in, use My cases on your profile. The case and everything on it, its votes, comments and reports, are deleted right away, everywhere on HearMe. The share picture of the case may stay cached for up to 5 minutes; copies people made, link previews that messaging apps already fetched and push notifications already delivered can't be recalled. Keep the link private: anyone who has it can see your case and delete it. If you delete your account, your cases and everything on them are deleted with it, and so are the votes, comments and reports you made and your Jury notification links. An upvote a guest on the website gave someone's comment is kept as an anonymous count.
You can delete your account yourself, from Settings on the website or from You → Delete account in the Android app. If your account has a password, the app asks you for it. If you can't, email us from the address on your account: we reply to that address to confirm the request, then delete the account the same way, within 30 days of confirming. Deleting an account, yourself or through us, does not delete a child-safety report held as evidence, or the ban records of a banned account (they stay, so a ban still holds). The Delete account page lists what is deleted and what we keep.
To exercise any of these, email support@hearme.chat. We'll respond within the time required by applicable law, and may need to verify your identity first.
Please note: deleting your account, yourself or through us, doesn't delete safety records, ban records or data we're legally required to keep, and doesn't lift a ban.
10. International Data Transfers
HearMe is available globally. Your data may be transferred to and processed in countries other than your own, including by the third-party providers listed in Section 7. Where required, we rely on appropriate safeguards for those transfers. Our own servers are run by a hosting provider, with servers located in India; Cloudflare, Resend, Google, KLIPY, Apple and the backup provider in Section 7 process data elsewhere too.
11. Security and Data Breaches
We use HTTPS/TLS encryption, access controls, and encrypted backups. Database backups are made daily and weekly. Our encrypted backups are deleted automatically: daily ones within about a month and weekly ones after about 8 weeks, so something you deleted can remain in a backup until then. Backups include held child-safety evidence, including audio clips, and are encrypted. No system is completely secure, and we can't guarantee absolute security.
If we become aware of a breach that poses a risk to you, we will notify affected users and the relevant authorities as required by law.
12. Children's Privacy
HearMe is not for anyone under 18. We do not knowingly collect personal data from anyone under 18.
If you are under 18, do not use this Service and do not send us any personal information.
If you are a parent or guardian and believe a child under 18 has given us personal information, report the account or email support@hearme.chat, and we will ban the account and its device.
13. Changes to This Policy
We may update this policy. The "Last updated" date will change, and material changes will be announced on the Service. Continuing to use HearMe after a change means you accept the updated policy.