DejaWhere Privacy Policy
Version: 0.2 (draft) Last updated: 2026-09-25 Effective date: [TO FILL — not before launch]
The short version
- DejaWhere rebuilds your life timeline from traces you already have (photo metadata, calendar, Google Timeline export, social-network data exports, optional live location) and lets you and someone you know discover where your paths crossed before you met.
- Your photos never leave your phone. We read only the time and location stored inside them, on your device. The only exception is a photo you explicitly choose to share on a specific Finding or put in a printed book.
- Only "visits" are uploaded: a place, a time window, and how confident we are. Not the photos, not the calendar text, not the raw location trail. For a normal (non-sensitive) visit, our server also works out a city, country and, where public map data covers it, a street address — from the coordinates you already uploaded, never a new upload. This is never done for your Home, Work or private places, and the address is visible only to you.
- Recognizing what a moment was about stays on your phone. If you turn it on, DejaWhere can notice generic things like "food", "beach" or "a birthday" in your own moments' photos, and let you note who was there. The photos, the labels and your notes never leave your phone.
- Everything about where you have been is encrypted with a key that belongs only to you. When you delete your account we destroy that key, which makes the data unreadable.
- Nothing is shared without explicit, mutual approval. Another person can only ever see the shared "Us" timeline, never your personal timeline. Your private places are never compared or revealed to anyone. Your Home and Work are never labeled as such to anyone: they can be part of a comparison, but the other person only ever sees their neighbourhood and city (their street and city, if you are both each other's Close Friends), never a house number or the exact spot (Section 5). Comparing with a group of 3–6 people works the same way: everyone must join, and what a group member outside a given pair can see is deliberately limited (Section 3.11).
- We never sell your location data. Ads in the free tier are contextual and not based on who you are or where you have been.
- Your phone number is private. We use a one-way hash of it so friends who already have you in their contacts can find you. It is never shown to anyone except people you and they have both marked as Close Friends.
- Your data is hosted in the European Union (Frankfurt, Germany).
The rest of this policy explains all of this in detail.
1. Who we are
DejaWhere is operated by [TO FILL — legal entity name, company number, registered address] ("DejaWhere", "we", "us"). The founder is Doron Mazor.
We are the data controller for the personal data described in this policy. That means we decide why and how your data is used, and we are responsible for it under the law.
Privacy contact: privacy@dejawhere.app [confirm domain] Data protection officer / privacy contact person: [TO FILL — name, or state that none is required] EU representative (if required under GDPR Article 27): [TO FILL]
We launch first in Israel, but DejaWhere is a global, English-first product. This policy is written to meet the EU General Data Protection Regulation (GDPR) and Israel's Privacy Protection Law, 5741-1981, as amended by Amendment 13. Where a local law gives you more rights than this policy describes, that law applies.
2. Who DejaWhere is for (age)
DejaWhere is not intended for anyone under 16 [confirm age with lawyer — 16 aligns with the GDPR default; some countries set 13–15, and Israeli law may require a different threshold]. We do not knowingly collect data from children under that age. If you believe a child has created an account, please contact us at privacy@dejawhere.app and we will delete it.
3. What data we collect, and where it comes from
We describe this by source, because that is how you experience it in the app. For each source we say what stays on your device and what reaches our servers.
3.1 Your account
| Data | Where it comes from | Where it is stored |
|---|---|---|
| Name, email address, profile photo | Sign in with Google (see 3.2) | Our servers, via Clerk (our sign-in provider) |
| Sign in with Apple identifier | Sign in with Apple, added before the iOS release [confirm at launch] | Same |
| Username (optional) | You choose it | Our servers |
| Mobile phone number (required) | You enter it; we verify it with a one-time code sent through WhatsApp | See 3.3 |
| Device and app information (device type, OS version, app version, push notification token, language, time zone) | Your device | Our servers |
3.2 Sign in with Google (and Google Calendar)
You sign in with your Google account. We use Clerk as our sign-in provider. Google gives us your name, email address and profile photo.
On the same Google consent screen we also ask for read-only access to your Google Calendar. You can untick this and connect it later, or never. If you allow it:
- Calendar events are fetched directly by your device or browser from Google. They do not pass through our servers.
- The app uses event titles, times and locations only to attach a label (for example "Imagine Dragons concert") and a category to a visit you already made according to your other sources. Calendar entries alone never create a visit.
- Only the resulting label and category are saved with the visit on our servers. The full event text, attendees, descriptions and other calendar content are never uploaded.
Google API Services User Data Policy — Limited Use disclosure. DejaWhere's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain words: we use your Google Calendar data only to label your own timeline inside DejaWhere. We do not use it for advertising, we do not sell it, and no human reads it except with your permission, for security purposes, to comply with the law, or in aggregated and anonymised form.
3.3 Your phone number
Every account must have a verified mobile phone number. This is how friends who already have your number in their contacts can find you.
- We send the verification code only through WhatsApp, using Meta's WhatsApp Business Platform. Meta receives your phone number in order to deliver the message (see Section 7).
- We store your number in two forms: a keyed one-way hash (used for matching), and an encrypted copy (used to show it to Close Friends and for support). We do not store it in plain text.
- Finding friends from contacts: if you allow contact access, the app converts each phone number in your address book into a one-way hash on your device and sends only the hashes to us. We compare them against the hashes of DejaWhere users. The raw numbers, names and other contact details are never uploaded. You are only discoverable by people whose contacts already include your number.
- Who can see your number: nobody, except people you have marked as a Close Friend and who have also marked you as a Close Friend. Regular Connections never see it. Contact matching reveals no numbers to anyone.
- One phone number belongs to one account.
3.4 Your photo library (metadata only)
If you allow photo access, the app reads only the capture time and GPS coordinates stored in each photo's metadata, on your device. This includes iCloud Photos where they are available on the device.
- The photos themselves are never uploaded. Not thumbnails, not previews, not the image content.
- On a Finding card, the app can show you your own photos from that moment. These are loaded from your phone and are visible only to you.
- Exception — a photo you choose to share. You can pick one photo per Finding and share it with the other person in that Connection ("Share my photo from this moment"). That photo is uploaded, stored encrypted, shown only in that Connection's "Us" timeline, and can be removed by you at any time. It is deleted when you remove it, when the Connection ends, or when you delete your account. You can also choose photos for a printed book (see 3.9).
3.5 Your calendars
The device calendar (and Google Calendar, described in 3.2) is read on your device to attach labels to visits. Only labels and categories are saved with visits. Calendar text is never uploaded on its own.
3.6 Google Timeline export
Google Timeline (Location History) has no API, so you export it yourself from the Google Maps app and give the file to DejaWhere. The file is processed on your device or in your browser. The raw file is never uploaded. From it we derive visits and simplified journey paths (see 3.10).
3.7 Facebook, Instagram and Snapchat data exports
You can import the "Download your data" files that Facebook, Instagram and Snapchat let you request. The app reads photo dates, original GPS where present, check-ins, tagged locations, events and Snapchat Memories locations. The files are processed on your device or in your browser and are never uploaded raw. Posts, messages, friends lists and other content in those files are ignored.
3.8 Live location (optional)
You can turn on live location so DejaWhere keeps building your timeline going forward. We use your operating system's visit detection (places where you stop for a while), not continuous GPS tracking. Raw location data stays on your device. Only the resulting visits are uploaded. You can turn this off at any time in your device settings or in the app's Privacy Center.
3.9 Printed products
If you order a printed book or poster:
- The photos you explicitly select for the print are uploaded, encrypted, and deleted no later than 30 days after delivery. For a couple's book, each person approves only their own photos.
- We collect your shipping name, address and contact details and pass them to our print and shipping partner (Gelato) to produce and deliver the order.
- Payment is handled by Stripe. We do not see or store your full card number.
3.10 What actually reaches our servers: "visits" and what is derived from them
Everything above is fused on your device into a list of visits. A visit is:
- a place (a map location and its precision radius, and where possible a matching public place from the Overture Maps dataset),
- for a normal (non-sensitive) visit only: a city, a country and, where our map data covers it, a street address — see Section 3.11,
- a time window (start, end, and how uncertain each is),
- a confidence score,
- an optional label and category (for example from your calendar),
- a summary of the evidence (for example "3 photos, 1 calendar event") — never the photo content or the calendar text,
- a sensitivity flag (normal, home, work, private) that you can change.
Visits, simplified journeys between visits (walk, drive, transit, flight), and derived summaries (how many days of each year we have data for, which places you visit regularly, home and work detection) are stored on our servers, encrypted with your personal data key (see Section 6).
Raw signals (every individual photo location, every calendar event, every Timeline point) stay in an encrypted database on your device only. You can clear them at any time in the Privacy Center.
3.11 City, country and street address
For a visit you have not marked Home, Work or private, our server works out roughly where it was — a city, a country and, where our map data has that level of detail, a street (and house number, where known). This never uses anything new: it looks up the coordinates of a visit you already uploaded against public map data (OpenStreetMap and Overture Maps — see "Attributions"). Nothing about your photos, calendar or raw location trail is used or sent for this.
- Never stored for Home, Work or private places. Those visits get no city, country or address on your timeline, the same as they get no place name. The one exception is in memory, during a comparison you both approved: for a Home or Work visit (never a private one) our server looks up its neighbourhood, city and nearest street name, only to show the other person the area at their precision level (Section 5), and keeps nothing of it apart from the Finding itself.
- Visible only to you. Your resolved addresses are shown to you in My Life and are stripped out of anything another person can see — the shared "Us" timeline, a Finding, a share card, a printed book. Only the place, time and distance rules in Section 5 apply to what others see; a street address is never part of that.
- Where no house-number address is close enough (this is common in some countries, including Israel, where that part of the public map data is sparse), we show the nearest named street instead ("Near Herzl St") rather than nothing.
3.12 Connections, comparisons and Findings
When you connect with someone and you both approve a comparison, our servers compare your two visit lists and produce Findings: Crossings (same place, same time), Echoes (same place, different times), Neighbors (you lived near each other at the same period, shown only as a neighbourhood name — a street name for mutual Close Friends — and only if you both opt in), and Together (crossings after the date you met). Your Home and Work can be part of Crossings too, but only as one Finding per area and year, rounded to the month, and never labeled Home or Work for the other person (Section 5).
We store: the Connection (who, when, how you connected — nearby, QR, link or contact — and its status), your private tag for the person (partner, friend, family, colleague, other — visible only to you), your consent record for each comparison (what scope you accepted and when), and the Findings themselves, encrypted.
Group comparisons. You can also compare with a group of 3 to 6 people at once (built from your existing Connections). The same rules apply, extended for more than two people:
- Everyone must join. The comparison only runs once every invited member has explicitly joined; declining means nothing of yours is used.
- A privacy switch per person. Each member chooses whether people they didn't personally cross paths with can also see where they crossed paths with someone else in the group (place and year only — never the exact time, the spot, or anything if you leave it off).
- What a group member can see about a pair they were not part of is deliberately limited: at most the place name (if both people share it), the general area and the year — never coordinates, an exact time, a distance, or the evidence behind it — and only when both people in that pair turned the switch on and the viewer is connected to both of them.
- Leaving a group deletes that group's Findings for everyone in it, the same principle as leaving a pairwise Connection.
- Home, work and private places are never matched in a group comparison either, and, like pairwise Crossings, nothing from today is ever matched.
3.13 Chat
Chat between Connections is provided by Stream (see Section 7). Messages are encrypted in transit and at rest, but chat is not end-to-end encrypted: Stream and, when necessary for support, safety or legal reasons, authorised DejaWhere staff can access message content. Chat history is deleted when a Connection ends or is blocked.
3.14 Usage analytics and errors
We collect product analytics (which screens you use, which features you try, how long imports take) through PostHog, hosted in the EU. Analytics events never contain location data. We collect crash and error reports through Sentry so we can fix bugs. These reports may contain your user ID, device information and the technical state of the app at the time of the error.
3.15 Nearby connection (Bluetooth)
When you use "Connect nearby", your phone advertises a fixed DejaWhere Bluetooth signal, and a nearby phone doing the same connects to it privately (not a public broadcast) to read a short-lived random token. The token carries no identity, rotates every few minutes, and this only works in the foreground, while both people have the app open on the "Connect nearby" screen. Our server matches the two tokens to create the Connection. On Android, this uses the Bluetooth permissions introduced for this purpose (scan, advertise, connect), requested with the neverForLocation flag where supported, since we never need your location for this feature.
3.16 On-device photo understanding
If you turn this on (it is off by default), DejaWhere can recognize generic things in your own moments' photos — for example "food", "beach", "a birthday" or "the park" — using Google's ML Kit image-labeling software, which runs entirely on your phone.
- The photo and the result never leave your phone. Only a short list of allowed labels (like "food" or "beach") is kept, on your device, alongside the moment. We never store or upload the photo, and we never run any face detection or face recognition — we do not identify people in your photos, only generic scenes and objects. A small set of labels about appearance or body parts is dropped before it is even stored, and it never runs on private visits' photos.
- "Who was there?" — a note about which of your Connections, or which group ("family", "the kids", etc.), were with you for a moment — is something you type or pick yourself, or that we infer only from a
togetherFinding with someone you have tagged. This, too, stays on your phone; it is never uploaded, searched or shown to anyone else. - Google receives anonymous usage metrics about the ML Kit software itself (for example, that the labeling ran, and how long it took) — not your photos, and not the labels we produce from them. This is disclosed because Google is already one of our processors (Section 7); ML Kit is not a new company receiving your data, but it is a new kind of processing on your device.
- You can turn this off, and clear everything it has stored, at any time in the Privacy Center. Turning it off deletes the labels immediately.
- Available on Android today; not yet on iOS.
3.17 Inviting friends on WhatsApp
You can invite people from your contacts who are not yet on DejaWhere. This reuses the same one-way contact hashing described in Section 3.3 — nothing new is uploaded to find out who is already on DejaWhere and who isn't. The invite itself is sent by you, through WhatsApp's own share sheet on your phone; we do not send it on your behalf and we do not see who you sent it to.
Your invite can optionally show how many years of timeline you have rebuilt (for example, "8 years of memories"), rounded to the nearest year and never shown for less than two years. This is off unless you turn on "Show how many years" for your invites, and it never reveals where you have been — only a number.
3.18 Video music, On This Day photo notifications, trips and the world map
These features work entirely with data you already have on your device and in your account; none of them upload anything new:
- Music for your videos. When you make a share video, you can add a short bundled music track or a track from your own phone. This mixing happens on your device; the track you pick is never uploaded, and neither is the finished video unless you explicitly share it.
- On This Day photo notifications. A notification can show one of your own photos from a past year on this day. The photo is read from your device only when the notification fires, shown in the notification, and never leaves your phone.
- Trips and the world map. These are views of your existing timeline — grouping your visits into trips, and showing the countries and cities you've been to on a map — built from visits (and, for the world map, the city/country data in Section 3.11) you already have. No new data is collected to show them.
3.19 Data we do NOT collect
- Photo or video content (except a photo you explicitly share or print).
- Faces, face recognition or any identification of who is in a photo.
- Calendar event text, attendees or descriptions.
- Raw GPS trails or continuous tracking.
- Your contacts' names, numbers or details (only one-way hashes).
- Precise location in analytics.
- Advertising identifiers for cross-app tracking. We do not show the iOS App Tracking Transparency prompt because we do not track you across apps.
4. Why we use your data, and our legal basis
Under the GDPR we need a legal basis for each use. Israeli law requires that we use data only for the purpose you gave it to us for, with your informed consent where required. Here is how they map.
| What we do | Why | Legal basis (GDPR) |
|---|---|---|
| Create and secure your account, verify your phone number | To run the service you asked for | Performance of a contract (Art. 6(1)(b)) |
| Build your personal timeline, map, Wrapped and On This Day from the sources you connect | This is the core service | Performance of a contract; your consent for each source (photos, calendar, live location, file imports), which you can withdraw per source (Art. 6(1)(a)) |
| Read your Google Calendar labels | To label your visits | Your consent, given on the Google consent screen (Art. 6(1)(a)) |
| Match your contacts by hash, including to invite people by WhatsApp | So friends can find you, and so you can invite the ones who aren't on DejaWhere yet | Your consent to contact access (Art. 6(1)(a)); legitimate interest in letting existing users discover you [confirm with lawyer — see open questions] |
| Work out a city, country and street address for a normal visit | To label your own timeline and show it on the world map | Performance of a contract; the same consent as the source that produced the visit (Art. 6(1)(a)/(b)); never for Home, Work or private places |
| Recognize generic things (like "food" or "beach") in your own moments' photos, on your phone | To title and let you search your own moments | Your consent, off by default (Art. 6(1)(a)); processing happens on your device |
| Run a comparison and show Findings, including a group comparison | The "Cross Paths" feature you and the others requested | Performance of a contract; explicit consent of every participant, or every group member who joined, for each comparison (Art. 6(1)(a)) |
| Provide chat | Part of the service | Performance of a contract |
| Process payments, subscriptions and print orders | To fulfil your purchase | Performance of a contract; legal obligation to keep accounting records |
| Send push notifications about comparisons, invites and messages | To tell you when something you asked for is ready | Performance of a contract; you can turn them off |
| Send occasional product emails | To tell you about DejaWhere | Consent, with an unsubscribe link in every email [confirm opt-in vs opt-out under Israeli spam law, Section 30A of the Communications Law] |
| Analytics and crash reports | To improve and fix the app | Legitimate interest (Art. 6(1)(f)); no location data included [confirm whether consent is required for analytics cookies/SDKs in target markets] |
| Show contextual ads in the free tier | To fund the free tier | Legitimate interest; ads are non-personalised |
| Detect implausible or fake timelines, rate-limit abuse, handle reports | To keep DejaWhere safe for everyone | Legitimate interest (Art. 6(1)(f)) |
| Staff access for support, safety and legal purposes | To help you and to comply with law | Legitimate interest; legal obligation (Art. 6(1)(c)) |
| Keep audit logs of all access | Security and accountability | Legitimate interest; legal obligation |
Location data and inferences. Your location history can reveal sensitive things about you (for example, visits to a place of worship, a clinic, or a political event). We treat all location data as sensitive, encrypt it with your personal key, never sell it, never use it for advertising, and never use it for any purpose other than the ones listed above. [Lawyer: confirm whether any of this qualifies as "special category" data under GDPR Art. 9 or "sensitive information" under the Israeli PPL, and whether explicit consent wording is needed.]
Automated decisions. DejaWhere makes automated inferences (where you were, where you live and work, whether two people crossed paths). None of these produce legal or similarly significant effects on you. You can correct or hide any visit, and mark any place as home, work or private.
5. Sharing, what other people can see, and the rules that never change
These rules are built into the product and this policy:
- Nothing is shared without explicit, mutual approval. A comparison runs only when both people approve it and its scope (all time, a date range, or trips only). A group comparison runs only once every invited member has explicitly joined.
- Only the intersection. The other person sees the shared "Us" timeline: the Findings, the place, the time rounded to 15–30 minutes, and a rough distance. They never see your personal timeline, your other visits, or your evidence (each person sees only their own evidence). In a group, someone who wasn't part of a particular pair's crossing sees, at most, the place and the year, and only if both people in that pair chose to allow it.
- Home and Work are never labeled, and private places are never compared. A place you marked private is excluded from matching altogether, whatever else it is. Your Home and Work can be matched, but toward the other person they look like any other area: a connection sees the neighbourhood and city (for example "Florentin, Tel Aviv"), or only the city when no neighbourhood is known; someone you and they both marked as a Close Friend (the same rule that shows phone numbers) sees the street and city (for example "Herzl St, Tel Aviv"). Never a house number, never the words "home" or "work", and any map point is only the neighbourhood's or city's centre, or a point rounded to about 300 m for a street. Such a Finding is one per area and year, rounded to the month, with no distance or time together, so it never shows a daily pattern. Neighbors Findings follow the same rule and appear only if both of you opt in. Home and Work are never matched in a group comparison, a trips-only or an events-only comparison, and a photo can never be shared on such a Finding.
- Never today. Same-day visits are never matched, so nobody can learn where you are right now.
- Regular places are vague. If you are both regulars at the same café, we say so without listing individual times.
- Snapshots only. A comparison is a snapshot at the moment of approval. "Check again" needs fresh approval from both of you (or, for a group, from everyone in it again). There are no automatic re-runs.
- You control it. You can hide any visit from matching, exclude sensitive places, end or block a Connection at any time. Ending or blocking a Connection deletes its Findings and its chat. Leaving a group deletes that group's Findings for everyone in it.
- No public anything. There is no public feed, no followers, no public profile of where you have been.
- Your street address is always owner-only. Even inside a shared "Us" timeline or a group, nobody but you ever sees the street address of one of your visits.
6. How we protect your data
- Hosting in the EU. Our servers and database run on Amazon Web Services in the eu-central-1 (Frankfurt, Germany) region. [At the time of this draft, DejaWhere runs only in development on the founder's computer; confirm this section reflects the production setup at launch.]
- Encryption in transit and at rest. All traffic uses TLS. Databases and file storage are encrypted at rest.
- Field-level encryption with a key that is yours. Every piece of location data (visits, journeys, Findings, place summaries) is additionally encrypted with a per-user data key, which is itself protected by a hardware-backed master key (AWS KMS). Even someone with a copy of our database cannot read your timeline without your key.
- Crypto-shredding on deletion. When you delete your account, we destroy your data key. From that moment your location data is unreadable, even in backups. Backups are kept for up to 14 days; deletion is complete once they expire.
- Encrypted on your device too. Raw signals live in an encrypted on-device database.
- Access controls. The API is the only component that can reach the database; every request is scoped to the signed-in user; any access to another person's data is checked against your Connections and consents.
- Staff access and logging. See Section 9.
- Security testing. Dependency scanning on every code change and an external penetration test before launch [confirm at launch].
No system is perfectly secure. If a breach affects your data, we will notify you and the relevant authorities as required by law (see Section 12).
7. Who we share data with (our processors)
We do not sell your data to anyone, and we never sell location data. We share data only with service providers who work on our behalf under contract ("processors"), and only what each one needs. Each provider is bound by a data processing agreement. [Every entry below is marked "(confirm at launch)": verify the provider, the data shared, the hosting region and the DPA before publishing.]
| Provider | What they do for us | What they receive | Location |
|---|---|---|---|
| Clerk (confirm at launch) | Sign-in and account management | Name, email, profile photo, Google/Apple identifiers, verified phone number, session data | [TO FILL — confirm region and DPA] |
| Google (confirm at launch) | Sign in with Google; Google Calendar (fetched by your device); Google Play billing (Android); ML Kit on-device photo recognition (Android, opt-in) | Sign-in: your Google account identity. Calendar: nothing from us — your device talks to Google directly. Play: purchase data. ML Kit: anonymous usage metrics about the software only — never a photo or a label, which stay on your phone | USA / global; EU–US Data Privacy Framework and SCCs |
| Apple (confirm at launch) | Sign in with Apple; App Store billing (iOS) | Sign-in identity; purchase data | USA / global |
| Meta — WhatsApp Business Platform (confirm at launch) | Delivers the phone verification code | Your phone number and the code message | USA / global; SCCs |
| Amazon Web Services (confirm at launch) | Hosting, database, file storage, key management, email delivery (SES) | All server-side data, encrypted | EU, Frankfurt (eu-central-1) |
| Stream (confirm at launch) | Chat | Your user ID, display name, photo and messages | EU region |
| Stripe (confirm at launch) | Payment for printed products | Payment details, email, billing address | USA / global; SCCs |
| Gelato (confirm at launch) (fallback: Prodigi) | Printing and shipping | Name, shipping address, contact details, the print file (including the photos you chose) | Global network of print partners — the print may be produced in the country nearest you |
| RevenueCat (confirm at launch) | Subscription management for App Store and Google Play | App user ID, purchase and subscription status | USA; SCCs |
| Google AdMob (confirm at launch) | Non-personalised, contextual ads in the free tier | Only what the SDK requires to serve non-personalised ads (for example device type, app, coarse context). No location history, no personal profile | USA / global |
| PostHog (confirm at launch) | Product analytics | Usage events; never location | EU |
| Sentry (confirm at launch) | Error and crash reporting | Error reports with user ID and device information | [TO FILL — confirm EU data residency option] |
| Expo (EAS / Expo Notifications) (confirm at launch) | Push notification delivery via Apple and Google | Push token, notification content | USA |
| Protomaps / Overture Maps / OpenStreetMap (confirm at launch) | Map tiles, place names, city/country boundaries and street addresses (see Section 3.11 and "Attributions") | No personal data is sent to or received from these sources. Tiles are served from our own storage; the places, locality, country and street/address datasets are downloaded once and loaded into our own database, then matched against the coordinates you already uploaded | n/a |
| Vercel (confirm at launch) | Hosting of the web app, marketing site and admin portal | Web requests (IP address, browser) | [TO FILL — confirm region] |
Other people on DejaWhere. We share Findings and the Us timeline with the other participant of a comparison, as described in Section 5. People who have your number in their contacts can see that you are on DejaWhere.
Legal and safety. We may disclose data if required by law, a court order or a lawful request from a public authority, or when necessary to protect someone's safety or to enforce our Terms. We will challenge requests we believe are unlawful or overbroad, and we will tell you unless we are legally prevented from doing so. [Lawyer: confirm this commitment is workable under Israeli and EU law.]
Business transfers. If DejaWhere is acquired or merges with another company, your data may be transferred as part of that transaction. The new owner will be bound by this policy, and we will notify you before your data becomes subject to a different policy. [Lawyer: confirm wording.]
8. International transfers
Your data is stored in the EU. Some of our providers (listed above) operate in the United States or globally. Where data leaves the European Economic Area, the United Kingdom or Israel, we rely on the European Commission's Standard Contractual Clauses, the EU–US Data Privacy Framework where the provider is certified, or an adequacy decision. Israel benefits from an EU adequacy decision. [Lawyer: confirm the transfer mechanism for each provider, and the Israeli PPL transfer regulations (Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001) for transfers out of Israel.]
9. Staff access to your data
We want to be honest about this: authorised DejaWhere staff may access your data for support, safety and legal purposes. For example, to help you with a problem you reported, to investigate a report of abuse, to check a timeline that our integrity system flagged as implausible, or to comply with a legal obligation.
- Every such access requires the staff member to record a reason, and every access is written to an append-only audit log.
- Staff sign in through a separate system with mandatory multi-factor authentication, and access is limited by role. Only the most privileged role can open a full timeline.
- We do not notify you individually when staff access your data. We may add a "who accessed my data" history in the app in the future.
- Staff never access your data for curiosity, marketing or any purpose not listed above. Doing so is grounds for immediate dismissal.
10. How long we keep your data
| Data | Kept until |
|---|---|
| Account data, visits, journeys, Findings, Connections | You delete your account (or the specific item) |
| Raw signals on your device | You clear them in the Privacy Center, or you uninstall the app |
| Findings and chat of a Connection | The Connection ends or is blocked, then deleted promptly |
| A photo you shared on a Finding | You remove it, the Connection ends, or you delete your account |
| Print photos | Up to 30 days after delivery of the order |
| Order and payment records | As long as tax and accounting law requires (typically 7 years in Israel [confirm]) |
| Comparison consent records and audit logs | [TO FILL — proposed: as long as the account exists plus a limited period, for accountability; lawyer to confirm] |
| Analytics and error reports | [TO FILL — proposed: 12 months, then aggregated or deleted] |
| Backups | Up to 14 days, after which deleted data is gone for good |
| Inactive accounts | [TO FILL — proposed: after a long period of inactivity we email you and then delete; lawyer to confirm period] |
After you delete your account we may keep a minimal record (for example a hash of your phone number, or your email) only as long as needed to prevent abuse, honour a block, or meet a legal obligation. [Lawyer: confirm what may be kept and for how long.]
11. Your rights and how to use them
You can do most of this yourself in the app's Privacy Center; for anything else, email privacy@dejawhere.app [confirm domain]. We will respond within one month (GDPR), or sooner where Israeli law requires it [confirm PPL response deadlines]. We may need to verify your identity first.
- Access and export. See what we hold about you and download a copy of your timeline and account data in a machine-readable format.
- Correction. Edit any visit, place, label or profile detail. Your edits are never overwritten by the app.
- Deletion. Delete individual visits, Connections, shared photos, or your whole account. Account deletion destroys your encryption key (see Section 6) and is complete once backups expire within 14 days.
- Withdraw consent, per source. Turn off photo access, calendar, live location or contact matching at any time in the app or your device settings. This does not affect what was lawfully done before, and we will tell you if it limits a feature.
- Object. You may object to processing based on our legitimate interests, including analytics.
- Restrict. Ask us to pause processing while we handle a dispute.
- Portability. Receive your data in a common format or, where feasible, have it sent to another service.
- Not to be subject to purely automated decisions with legal or similar effects. We do not make such decisions.
- Complain. You can complain to a supervisory authority at any time:
- Israel: the Privacy Protection Authority (הרשות להגנת הפרטיות), [TO FILL — address and contact details].
- EU / EEA: the supervisory authority in the country where you live or work, or where you believe the problem occurred. [TO FILL — if we appoint an EU lead supervisory authority or representative, name it here.]
- We would appreciate the chance to resolve your concern first, but you are not required to contact us before complaining.
Rights of the other person. Because DejaWhere is about two people's data, some of your rights meet theirs: for example, if you delete your account, Findings you shared with someone disappear from their Us timeline as well; and we cannot give you the other person's underlying visits, because they are not your data.
12. Data breaches
If a security incident affects your personal data in a way that is likely to put you at risk, we will notify the relevant authority (within 72 hours under the GDPR, and as required by the Israeli Privacy Protection Regulations (Data Security), 5777-2017) and notify you directly without undue delay, explaining what happened and what you can do. [Lawyer: confirm the Israeli notification obligations that apply to a database of DejaWhere's classification under the Data Security Regulations, and whether database registration is required.]
13. Cookies and similar technologies (web)
Our website and web app use:
- Strictly necessary cookies and local storage to keep you signed in and remember your settings.
- Analytics (PostHog) to understand how the site is used. [Lawyer: confirm whether a consent banner is required for PostHog in the EU/UK and in Israel, and adjust.]
We do not use advertising cookies or third-party tracking on the website. The mobile apps do not use cookies but use equivalent SDKs described in Section 7.
14. Changes to this policy
We may update this policy as DejaWhere grows. If the change is significant (for example a new purpose, a new kind of data, or a new category of recipient), we will tell you in the app or by email before it takes effect and, where the law requires it, ask for your consent again. The date at the top tells you when it was last changed, and we keep previous versions available on request.
15. Contact
DejaWhere — [TO FILL — legal entity, address] Email: privacy@dejawhere.app [confirm domain] Data protection contact: [TO FILL] EU representative: [TO FILL if required]
16. Attributions
DejaWhere's maps, places, and the city, country and street address information described in Section 3.11 are built in part from public map data:
- © OpenStreetMap contributors, available under the Open Data Commons Open Database License (ODbL). We use it, among other things, to fill in street addresses in places Overture Maps does not yet cover well. See openstreetmap.org/copyright.
- Overture Maps Foundation, whose datasets (places, divisions, addresses and transportation) are released under the Community Data License Agreement – Permissive, Version 2.0 (CDLA-Permissive-2.0). See overturemaps.org.
This data describes the world, not you: no personal data is ever sent to OpenStreetMap or Overture Maps, and nothing they provide identifies you or anyone else. We host a copy of the relevant map tiles and datasets ourselves rather than querying these projects live.