Privacy Policy
Effective and last updated: 20 August 2026 · Version: 1.1
This Privacy Policy explains how Liudmyla Chaban ("we", "us" or "our") collects and uses personal data when you use the Meets mobile application, its public legal and account-deletion pages, and related services (together, "Meets"). Meets is an adult social-events service intended for users in Ukraine and the European Union.
1. Who is responsible for your data
Controller / owner of the personal-data database: Liudmyla Chaban
Registered address: 67 Pylypa Orlyka Street, Kropyvnytskyi, Kirovohrad Oblast, 25014, Ukraine
Country: Ukraine
Privacy and rights requests: meets01app@gmail.com
2. Data we collect and where it comes from
- Account and age confirmation: email address, password hash, name, account creation time, email-verification status and preferred language. To enforce the 18+ requirement, we process the date of birth you enter, determine whether you meet the threshold, and retain only the result, confirmation method and time—not the exact date of birth. If the entered date shows that you are under 18, we retain the resulting access restriction while the account exists. We do not store your plain-text password.
- Profile: profile photo, city, biography, interests, ideal-meetup description and meetup-style tags, spoken languages and optional Instagram username that you provide.
- Third-party sign-in: provider user identifier and, when the provider supplies them, email address, name, username or profile photo from Apple, Google or Telegram. For Apple, we exchange the short-lived authorization code and store the resulting refresh token encrypted so that we can revoke Apple authorization when the Meets account is deleted.
- Content and social activity: events and their descriptions, categories, dates, photos, locations and addresses; venue banners; event participation; social connections; blocks; reports and supporting details; moderation status and authorised-administrator actions.
- Location: if you grant device permission and request the feature, current coordinates are used to centre the map or help select a place. We do not continuously track you or build a location-history profile. A location or address you deliberately attach to an event or banner is stored as part of that content.
- Telegram features: Telegram identifiers, usernames, chat and membership identifiers, connection and invitation status, and limited message previews from a connected event chat. Meets stores preview text or a media placeholder, not the underlying Telegram media file.
- Notifications and device information: Expo/APNs/FCM push token, platform, app version, notification preferences, delivery attempts and provider receipts. A push token is an app/device identifier used for delivery.
- Purchases: product, transaction, original transaction or purchase-token identifiers, subscription status, entitlement, store environment, renewal/expiry information and billing events received from Apple or Google. Apple and Google process the payment method; Meets does not receive or store the full card or bank-account number.
- Security, diagnostics and support: IP address and request metadata that may be processed by our API, rate-limiting and hosting infrastructure; authentication and security events; error information; account-deletion requests; and correspondence you send to support.
Information comes directly from you, from your use of Meets, from other users who interact with or report content, from the sign-in or store provider you choose, and from connected Telegram features.
3. Advertising and data we do not intentionally collect
Meets does not retain your exact date of birth after the age-threshold check and does not request a telephone number, gender, telephone contact list or address book. We do not provide in-app voice/video calls or direct private messaging; connected Telegram chat previews are described above. We do not perform Face ID authentication, facial recognition, face-template creation or other biometric analysis of uploaded photos. Device-level Face ID used by Apple to approve an Apple sign-in is controlled by Apple and is not received by Meets.
Paid business banners: Meets displays advertising and promotional banners supplied by venues and other business users. A business may pay for a business subscription or another offered plan that permits it to publish a banner. These are direct placements managed by Meets, not advertisements delivered through an external advertising network. Banner visibility may be contextual—for example, based on the categories or filters you select and, when you choose to use location features, proximity to your current location. We do not provide the business with your identity, email address, precise current coordinates, push token or advertising identifier merely because you viewed its banner.
We do not access IDFA or GAID for advertising, integrate a third-party advertising network, create a cross-service behavioural advertising profile, combine Meets activity with activity from other companies' apps or websites for advertising, or use a dedicated advertising, analytics or crash-reporting SDK. We do not sell personal data or send promotional email or push marketing. Service messages such as verification, security, participation and event reminders are not advertising.
4. Why we use data and our legal bases
- Contract: to register and authenticate you; maintain your profile; publish and display the content you choose to share, including paid business banners; provide events, participation, social connections, blocking, Telegram integrations and requested notifications; verify subscriptions and deliver paid features; support you; and process account deletion.
- Consent: to access optional current location and send notifications through device permissions, and for another optional use where we specifically ask for consent. You can withdraw permission in device settings or disconnect the optional integration. Withdrawal does not affect earlier lawful processing.
- Legitimate interests: to secure Meets, prevent fraud and spam, enforce age and safety rules, investigate reports, moderate content and paid promotions, provide contextual business placements without cross-service tracking, protect users and legal rights, maintain service reliability and diagnose failures. These interests are balanced against your rights; you may object as described below.
- Legal obligations and claims: to keep required billing or accounting records, respond to binding legal requests, and establish, exercise or defend legal claims.
- Vital interests: in exceptional cases, to use or disclose information reasonably necessary to address a credible and immediate threat to someone's life or safety.
Some account and authentication data is necessary to create an account. If you do not provide data needed for a feature, we cannot provide that feature. Profile details, device permissions, Telegram connection and publication of content are optional.
5. What other users can see
Meets is a social-events service. Depending on what you add or do, other users may see your name, profile photo, city, biography, interests, languages, Instagram username, events, event photos, venue/banner information, event location, participation and social connection information. Business banners are promotional content and may be labelled or visually presented as banners. Event and banner content may also be available through public deep links. Reports, reporter identity, private support correspondence, authentication data, push tokens and purchase identifiers are not intended to be public. Do not upload another person's image, location or personal information without permission, and avoid placing sensitive data in public fields.
6. Service providers and disclosures
We share only what is necessary for the relevant feature with these categories of recipients:
- Infrastructure: Railway in Amsterdam, Netherlands, for backend hosting; Neon on AWS eu-central-1 in Frankfurt, Germany, for PostgreSQL database hosting; and Amazon S3 in AWS eu-central-1 in Frankfurt, Germany, for image files.
- Communications: Expo and the relevant Apple Push Notification service or Firebase Cloud Messaging for push delivery, and Brevo for transactional email.
- Identity, platform and payments: Apple, Google and Telegram when you choose their sign-in, platform, purchase, bot or chat features.
- Maps and places: Google Places/Maps services, CARTO map tiles, and OpenStreetMap-based Nominatim and Overpass services when you view a map, search for a place or request address lookup. A provider may receive the query, approximate or submitted coordinates, IP address and standard request metadata.
- Other users or the public: for profile, participation and user content that the feature is designed to share.
- Safety and legal recipients: a person at risk, courts, regulators, the Ukrainian Parliament Commissioner for Human Rights, EU supervisory authorities, law enforcement, professional advisers or other recipients where disclosure is legally required or reasonably necessary to protect people, investigate abuse, defend rights or enforce our terms.
A business whose banner you see provides the promotional content, but Meets does not disclose your account or contact data to that business merely to display the banner. If you independently contact or visit the business, its own privacy notice applies to the information it collects.
Providers process data under their applicable service and data-processing terms and may also act as independent controllers for their own platform activity. Their privacy notices govern that independent processing.
7. Where data is processed and international transfers
Primary application data is hosted in the European Union: the API in Amsterdam and the database and image storage in Frankfurt. The controller is established in Ukraine and may access data from Ukraine to operate and support Meets. Apple, Google, Expo, Brevo, Telegram and mapping providers may process data in other countries where they or their subprocessors operate.
Where the GDPR's international-transfer rules apply, we rely on an available lawful mechanism appropriate to the provider and transfer, such as the European Commission's Standard Contractual Clauses, an adequacy decision, or another permitted safeguard, together with supplementary technical and organisational measures where appropriate. You may ask us for information about the mechanism relevant to your data.
8. How long we keep data
- Account, profile and content: while the account is active, then deleted through the account-deletion process, subject to the exceptions below.
- Deleted S3 media: the current object is queued for deletion. Because S3 versioning is enabled, non-current object versions are permanently removed by lifecycle rules after 30 days. Incomplete multipart uploads are cleared after seven days.
- Closed reports and associated report, block and content-moderation audit records are normally retained for 24 months from closure or creation, as applicable, for safety, repeat-abuse prevention and dispute resolution, and are then deleted. Open investigations may be retained until they are closed. Active user-to-user blocks remain while needed for the feature and are removed when either associated account is deleted.
- After account deletion, we retain pseudonymised Apple or Google purchase identifiers, subscription status and associated billing-event records for five years for accounting, fraud prevention, refund handling and dispute resolution. These records are then deleted unless a longer period is required for a legal claim, audit or binding legal obligation. We do not receive or store full payment-card details.
- Push delivery receipts are retained for up to 30 days, notification-delivery history for up to 90 days, and a push token is removed when invalid, on sign-out or account deletion, or after 12 months without re-registration.
- Telegram message previews are limited to the most recent 50 messages per connected event chat and are retained for no more than 90 days. Meets stores preview text or a media placeholder, not the underlying Telegram media file. Expired Telegram connection and invitation records are deleted during scheduled cleanup.
- Refresh tokens and temporary email-verification, password-reset, social-verification, sign-in and account-deletion tokens are deleted after they expire or are revoked during scheduled cleanup.
- Security, fraud-prevention, support and dispute records are kept only as long as reasonably necessary for the relevant incident, legal claim or binding obligation.
- Provider backups may retain a residual copy until the provider's normal backup-rotation cycle completes. Deleted information restored solely for disaster recovery will not be returned to ordinary active use and will be deleted again.
9. Account deletion
You can permanently delete your account in Meets settings or initiate deletion at our public account-deletion page. Deactivation alone is not used as a substitute. The process deletes the account and associated active data, queues managed media for deletion, detaches the limited pseudonymised billing records described above, and removes push tokens. If Sign in with Apple is connected, the encrypted refresh token is held in a separate queue only until Apple confirms revocation; failed revocation requests are retried and the token is deleted after success. Deleting Meets does not cancel an Apple or Google store subscription, which must be managed in the relevant store.
10. Your rights and choices
Subject to applicable conditions and exceptions, users in Ukraine and the EU may ask to know whether and why we process their data; obtain access and a copy; correct inaccurate data; erase data; restrict processing; receive portable data they provided; object to processing based on legitimate interests; withdraw consent; and complain to a regulator or court. EU users may object at any time to direct marketing, although Meets currently does not conduct direct marketing.
You can edit profile data in the app, remove content, revoke location and notification permissions in device settings, disconnect Telegram, block users and delete the account. There is not currently an automated data-export button; request a portable copy by emailing meets01app@gmail.com.
We may request information reasonably necessary to verify identity. We normally respond within one month under the GDPR and within the periods required by Ukrainian law; the GDPR period may be extended by up to two further months for a complex or numerous request, with notice. Requests are normally free, but applicable law permits limits for manifestly unfounded or excessive requests.
EU users may complain to the supervisory authority in the Member State of their habitual residence, workplace or the alleged infringement; contacts are available from the European Data Protection Board. In Ukraine, you may contact the Ukrainian Parliament Commissioner for Human Rights or a court.
11. Security
We use HTTPS transport encryption, password hashing, access controls, authenticated sessions, restricted infrastructure credentials, encryption of stored Apple refresh tokens, provider storage-security controls, deletion queues and limited administrative access. No service can guarantee absolute security. Contact meets01app@gmail.com immediately if you believe your account or data is at risk.
12. Adults only
Meets is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us so we can investigate and delete it where appropriate.
13. Automated decisions
The 18+ access rule is applied automatically to the date of birth you provide: an under-18 result prevents registration or use. The exact date is not retained. Contact support if you believe the restriction is incorrect. Meets does not otherwise use solely automated decision-making, including profiling, that produces legal or similarly significant effects. Technical safeguards such as rate limits may automatically reject suspicious requests, while report and account moderation can be reviewed by an authorised administrator.
14. Changes to this Policy
We may update this Policy when Meets, our providers, the law or our processing changes. We will publish the new version and effective date and, where required, provide notice or request acknowledgement before a material change takes effect.
15. Contact
Questions, objections and rights requests: meets01app@gmail.com. Please do not send passwords, access tokens, full payment details or unnecessary sensitive information.