HeyFrom.me

Privacy

Your page is only as public as you make it. Closer and Inner content is never sent to anyone you have not granted access to — it is filtered on the server, not hidden in the browser.

Last updated: 18 August 2026

1. Who we are (data controller)

HeyFrom.me is operated by FPP Consulting Ltd, a company registered in England and Wales, which is the data controller for personal data processed through this service.

FPP Consulting Ltd
103 Blundell Avenue
Cleethorpes
England, DN35 7RH
United Kingdom

Privacy contact: privacy@heyfrom.me

2. What data we process

  • Account data: email address, authentication identifiers (including Google sign-in identifiers when you use it), sign-in timestamps.
  • Profile content: your link name, what you are open to, answers, tags, photos, optional date of birth (only your age can be shown, and only if you turn that on), and the visibility level you choose for each item.
  • Interactions: heys you send and receive, connections, chat messages, notifications and your notification preferences.
  • Technical and usage data: IP address and device/browser information processed for security and abuse prevention, plus simple counts such as page views and heys sent.

We do not ask for special-category data. Anything you volunteer in free-text fields is published according to the visibility level you select, so please share only what you are comfortable sharing.

3. Why we process it and on what legal basis

  • To provide the service (account, profile, heys, chat) — performance of a contract, Art. 6(1)(b) GDPR.
  • Security, abuse prevention and service improvement — legitimate interests, Art. 6(1)(f) GDPR.
  • Transactional emails you can switch off in Settings — contract and legitimate interests; optional analytics cookies — consent, Art. 6(1)(a) GDPR.
  • Legal obligations (for example responding to lawful requests) — Art. 6(1)(c) GDPR.

4. Who can see your data

Other people see only what your visibility settings allow: Everyone, Closer, or Inner. Hidden content is filtered on the server and is never delivered to a browser that is not entitled to it. We never sell personal data and we do not run advertising.

We use a small number of processors acting on our instructions under Art. 28 GDPR: hosting and application infrastructure, database, authentication and file storage, email delivery for transactional messages, and AI providers used solely to translate the interface (never your personal content).

5. International transfers

Some processors operate outside the UK/EEA. Where that happens, transfers are protected by the UK International Data Transfer Addendum and/or the European Commission's Standard Contractual Clauses, together with technical measures such as encryption in transit and at rest.

6. How long we keep it

Account and profile data are kept while your account exists. Heys expire after 72 hours and are removed or anonymised afterwards; chat messages remain until you or the other person deletes the connection. After account deletion we remove or irreversibly anonymise your data within 30 days, except records we must keep for legal or security reasons (kept no longer than necessary, normally up to 12 months).

7. Your rights

Under the UK GDPR and the EU GDPR you have the right to access, rectification, erasure, restriction, data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you can withdraw it at any time without affecting processing already carried out.

You can exercise most rights directly in Settings (edit or hide your page, pause heys, delete your account) or by writing to privacy@heyfrom.me. We answer within one month. You may also complain to the UK Information Commissioner's Office (ico.org.uk) or to your local EU supervisory authority.

8. Cookies and local storage

We use strictly necessary storage only until you consent to anything more: your sign-in session, your language choice, and the record of your cookie choice. These are required for the service to work and do not need consent.

Optional analytics storage — simple, aggregated counts that tell us whether the product works — is used only if you accept it. We set no advertising or cross-site tracking cookies.

9. Security and children

Data is encrypted in transit and at rest, access rules are enforced at the database level by row-level security, and administrative access is restricted and logged. No service can promise absolute security, but we work to keep the exposure of your data to the minimum the feature needs.

The service is for adults: you must be 18 or older to create an account.

10. Changes

If we change this notice materially, we will show the new date here and, where required, ask for your consent again.