Privacy Policy
This policy describes how Elevated Life Connections, LLC, a subsidiary of Elevated Life Network, LLC, the operator of Hey, It’s You! (again), handles information. The service is for adults aged 18 and over. Questions and privacy requests can be submitted through our contact form.
Information we collect
At sign-up we ask for your birth date to confirm you are 18 or older (counted by today’s date in Hawaii); if you are not, nothing is stored. The birth date you give pre-fills your profile and is not kept separately once your profile is saved. We store your email, password hash, first and last name, birth date, phone number, verification status, any requested email or phone change until it is verified, authenticator configuration (optional for members), staff recovery-code hashes, session information, and trusted devices (a hash of a random device token, a coarse browser and operating-system label, when it was added and last used). We also store connections, messages, your per-conversation read position for unread badges, sharing choices, connection decisions, account-status requests, consent records, support requests, and staff security records. We store one current profile photo plus retained original copies of previous accepted uploads, upload times, safety-review results, meetup records, each member’s private notes and ratings, account-change and connection-event history, and moderation flags (including flagged message text). Each account receives a unique profile ID, visible to connections and searchable by authorized staff; it is not a login credential. Issued ID numbers remain reserved without their account link after account deletion. Government ID images are collected only through the restricted upload page after staff requests a flagged-account review. When you verify your ID (required before messaging and sharing), Stripe checks your ID and selfie as described in “ID verification and biometric data” below; we receive only the result, never your ID images, selfie or biometric data. Do not send an ID through chat, the support form, or profile-photo upload. Delivery and hosting providers process technical information needed to operate their services. We use IP-based request limits to reduce abuse. We record observed IP addresses with new staff audit and member activity events and record registration, password-login attempts, two-factor completion or failure, and sign-out for personal and staff accounts. Login history includes account identifiers, account email where matched, event outcome, and server time. Passwords, verification codes, and session tokens are not included. Failed login records include the entered email/username even when no account matches; unmatched attempts have no profile ID. IP addresses may represent a VPN or shared network and do not establish a person’s identity or precise location.
How we use it
We use information to create and secure accounts, check the stated age requirement, verify access to contact details, connect members, deliver messages, apply sharing choices, provide support, prevent abuse, and address documented legal obligations. Email or phone verification confirms access to that contact method; it is not an identity or background check.
What others can see
You can add an optional preferred name (up to 40 characters, not verified, changeable at any time). Until you share your contact info with someone, people with your connection link and your connections see only your preferred name (your first name if you set none), marked “Nickname” when it differs from your legal first name; your legal first and last name are never sent to them. After you share your contact info with a connection, that person sees your legal first and last name, with your preferred name in parentheses when it differs, and your contact card lists your preferred name as a nickname. Other members see your age, calculated by us from your birth date; your birth date itself is never shown or sent to them. Unless ID verification is required, ages and profile names are self-reported and not ID-verified. Your full birthday and email stay private. Your connections can see your safety-approved profile photo and email/phone verification status; your ID documents are never shown. You can save a connection before verification, but both people must complete verification before exchanging messages or contact details. Until a connection has finished verification and has a membership, they see only a small, heavily blurred version of your photo that our server makes from it; your photo itself is sent only to connections who have.
Your connection code changes every 30 seconds and works for one scan. A scan reserves the connection for the person who scanned it for 30 minutes; if they sign in or create an account in that time, we keep the reservation on their account for up to 30 days and send you their connection request once they have a profile photo. The request shows you their preferred name, their photo (unless it’s been reported or is under review) and when they scanned; you have 24 hours to accept or deny it, and they aren’t told which. We keep who scanned, when, and the outcome, and delete it with the rest of the connection records.
Choosing “I’m ready to share my info” shares your last name and verified phone number with that specific connection. The recipient can Call, Text, or Save their info as a contact card containing your name and phone number. Sharing is one way and sharing back is optional. Emails and social accounts are not shared. Turning sharing off blocks future access in the app, but cannot erase contacts, screenshots, or information already saved outside it. Editing your name, phone, or birth date clears your existing sharing choices.
Meetups and connection controls
Connected, verified members can record a meetup’s scheduled time and place for both participants to see. Notes and thumbs-up/down ratings are hidden from the other participant. They are not confidential from the service: authorized staff with legal-export permission may access the selected member’s notes and ratings for a documented legal purpose, with an authenticated staff session and an audit record. Normal chat review and chat exports do not include private notes. Pausing contact stops new messages from being delivered to the person who paused. The other person may continue sending; messages sent during the pause remain visible only to their sender, are retained for authorized staff review, and are not delivered later when contact resumes. No email notifications are sent for those messages. Removing a connection ends both participants’ access to its conversation, photos, contact details, and meetup log. Removing a connection cannot be undone from the old connection. To reconnect in person, generate a fresh short-lived QR code, have the other person scan it, and confirm their request. This restores the most recent retained connection, including its messages, meetups, and each person’s private notes. Contact sharing is off for both participants until they choose to share again. Removing a connection does not erase retained records or information previously saved outside the app; account deletion and legal-hold rules continue to apply.
Connection requests
Scanning a QR code sends an approval request after the scanner has completed their profile and uploaded a profile picture. The QR owner sees the requester’s first name in an in-app popup and may accept or decline. Requests expire after ten minutes. No connection or access to messages and shared contact details is granted before approval. Live request notifications require the app to be open.
Connection locations
If you opt in when requesting a connection and grant device location access, we temporarily keep the proposed pin with your request and save it to a new connection only upon acceptance. Temporary pin data is cleared after the request is handled, or after expiry when the owner next checks requests. If you opt in when connecting and grant device location access, we save that device’s coordinates, accuracy, and device-reported connection time alongside the server timestamp. Each person can save one pin from their own device, visible only to the two participants. A pin added later records its actual capture time and does not recreate where you were earlier. Older connections may only have a server-recorded time. Blue identifies your pin and green identifies the other person’s pin. This does not prove that both people were present and is not live tracking. Connecting works without location access. Opening a dashboard map sends the pin coordinates and technical request information to OpenStreetMap so it can display the map. Existing connections without a saved location show no pin. Location records follow the connection’s deletion and legal-hold rules.
Nearby count
The nearby counter starts automatically when you open the dashboard and uses your device location only after you grant browser or device location permission. It sends your current coordinates to our server while the dashboard is open. We keep only your latest coordinates for this feature, count other verified users who have granted location permission within a quarter mile, and return only the total—not their names, locations, distances, or directions. Location readings are approximate. Readings stop counting after five minutes without an update; expired rows are removed during subsequent nearby requests. You can revoke location permission in your browser or device settings to stop future updates. Your last reading stops counting after five minutes without an update. This is separate from saved connection map pins and does not track your background location.
Message notifications
Message email notifications are enabled by default and can be turned off in Account settings without disabling security emails. When delivery is active, we send a generic alert for a new unread message to your verified account email. Alerts do not contain the message, sender name, or profile photo. Our email provider processes your address and delivery details. Pending alerts may be retried for up to 23 hours and delivery-job records are removed after seven days. Turning off alerts, reading the message, pausing the conversation or removing the connection can suppress pending alerts.
We save a separate mobile push preference for future iOS and Android support. Push delivery is not active on the website yet, and saving the preference does not grant device notification permission. We also save that you have dismissed the communication reminder for each connection so it does not repeatedly interrupt your conversation.
Communication safety
Our communication rules require polite, respectful, non-explicit conversations. Use Report profile if someone violates these rules or makes you uncomfortable. Reporting and safety review use the records and restricted staff access described below; reporting does not notify the other member or automatically pause or remove your connection. Reports alone do not restrict the reported member, except that a nudity or sexual-content report hides the reported photo pending review, and reports of harassment or explicit content from at least two different members within 14 days automatically suspend the profile pending staff review (see the Terms).
Photo retention and safety review
You have one current profile picture at a time. Replacing it does not erase the previous upload: we retain original copies of all accepted profile photo uploads in restricted history for account integrity, safety review, and documented legal preservation. Historical pictures are not shown to your connections. They remain while the account is retained and are queued for deletion when the account is purged, unless preservation rules apply. Failed or rejected upload requests that were never accepted are not guaranteed to be retained. The 15-year staff audit rule does not mean that all profile photos are kept for 15 years.
Messages are screened for potentially inappropriate content. Flagged attempts may be held before delivery, retained for review, returned to the sender with a warning, and displayed in the authorized staff safety queue. Uploaded photos are approved by default unless automated screening flags them. Reports of nudity, sexual content, fake profiles, or impersonation immediately hide the reported photo from connections and alert staff for explicit-content or authenticity review. Authorized staff may approve or reject it. Approval is a photo review, not proof of identity. We use limited message rules and staff photo review unless an automated provider is configured. When configured, OpenAI’s moderation service may process message text and uploaded photos for screening. Screening can miss content or flag acceptable content, and does not guarantee safety. Contact support to request review of a moderation decision.
Staff access and scoped exports
Staff permissions separately control profile and photo previews, documented-reason chat review, moderation, account recovery, verification, and legal exports. Recovery may revoke sessions, force a password change, or require new two-factor enrollment. Staff sign in through Microsoft (Microsoft Entra ID, our organization’s work accounts): Microsoft checks the staff member’s password and multi-factor authentication and tells us who signed in (a Microsoft account identifier, sign-in name, display name and email) and that the staff role and multi-factor policy applied. We store that identifier, sign-in name and display name with the staff account and record each sign-in in the staff audit log. A new staff sign-in has no permissions until the Owner grants them. The @heyitsyouagain.com and @blunetgroup.com domains are reserved for staff and cannot create personal accounts; a company email alone does not grant access.
Authorized staff can produce separate exports for chat logs, profile photo history, connection/reconnection/removal/pause events, account changes, meetup history, the selected member’s private notes and ratings, and staff access/action audit events. Each export requires a selected account, date range, documented legal basis or case reference, permission, and an authenticated staff session. Exports and staff access are logged. Photo exports include retained original files; chat exports include both sides of the selected member’s conversations but exclude private notes. Meetup history filters by scheduled date; notes filter by their last-saved date and contain only that member’s current saved version. Overwritten note versions are not retained. Other histories use their recorded upload or event time. Date boundaries use UTC. Records from before history recording began may be unavailable.
Export tools do not themselves authorize disclosure. Any release to authorities or others must be reviewed for a valid legal basis and limited to the appropriate scope. Retained records, legal holds, and downloaded exports are not public. A downloaded export is a separate copy that cannot be recalled by deleting the active account; its authorized custodian must handle its security, permitted use, and retention under the applicable legal basis.
Service providers and disclosures
Our hosting, database, email, and verification providers process information needed to deliver the service. Twilio Verify sends and checks verification codes by text message, voice call or email: it processes your phone number (text and call codes) and your email address (email codes, including password-reset codes). All email from us, including those codes, is delivered by Twilio SendGrid. Stripe (Stripe Identity) performs ID verification when it is required (see below), and Stripe processes membership payments (see Payments and membership). Microsoft Entra ID handles staff sign-in (it does not process member accounts). We do not sell personal information or share mobile numbers or SMS opt-in records with third parties for their marketing. SMS consent information is used only for verification delivery, related operational support, and necessary legal compliance. Disclosure to authorities requires review of a valid legal basis; merely requesting deletion does not result in disclosure.
Payments and membership
Stripe is our payment processor. When you start a membership, you enter your payment details in Stripe’s fields on our membership page (or Apple Pay or Google Pay); they go directly to Stripe and never reach our servers. We never receive or store card numbers, security codes or bank details. Stripe handles them under its own privacy policy (stripe.com/privacy). We create a Stripe customer for you with your email address and your first and last name, and keep your email in sync with Stripe when you change it.
We keep only: your Stripe customer ID, subscription IDs and invoice IDs; each subscription’s status (active, paused, past due, canceled), period, intro-price and cancellation dates; paid invoice amounts and dates; refunds (amount, status, reason and who issued them); when a payment failed; when you agreed to automatic renewal and the version of that wording; when you first used the introductory price and when your first month at that price ends; and, for your receipts in the app, each payment’s receipt number, description, amount, date and payment method (the card brand and last four digits only). We also keep your time zone as your browser reports it on the membership page, so dates in membership emails and the intro month’s reminder match yours. We send your membership emails and receipts ourselves; Stripe doesn’t email you. When our team adds free months, a discount or credit, we keep what was added, until when, who added it and why; and whether you were already shown the one-time offer to stay (in the ledger below, so it isn’t shown again). Staff can see these records and open your customer record in Stripe’s dashboard; refunds are issued through Stripe, and our app never makes payouts or transfers.
Offer and refund ledger. To prevent repeated introductory prices, repeated offers to stay and abuse of automatic refunds, we keep a separate ledger of keyed hashes (HMAC-SHA256 with a dedicated secret key) of the account ID, the Stripe customer ID, the normalized email address, the normalized phone number and the payment card’s fingerprint (a Stripe identifier for the card, not the card number) that were used for the introductory price or a paid membership, with the dates of first introductory offer, last payment, last automatic refund and when the offer to stay was shown. The ledger contains no readable personal data, is used only to decide whether the introductory price or an automatic refund can be offered, survives account deletion and purge, and each entry is deleted 3 years after it was last used.
Voluntary contributions (“Support us”). If you make a one-time contribution, you pay in Stripe’s fields on our Support us page; card details go directly to Stripe. If you’re signed in, we use your Stripe customer; if not, you give Stripe an email address for the receipt, and we don’t keep it. We keep only: the Stripe checkout and payment IDs, the amount and currency, the date, whether it was refunded and when, and your account ID if you were signed in, and, when you were, a receipt in the app (amount, date, receipt number and the card brand and last four digits). We send one thank-you email with the receipt to your account’s email address or the address you gave for the receipt, and no other email about it; Stripe doesn’t email you. Contributions are not connected to your membership. Staff with billing permission can see your contributions and refund them; the Owner sees only total amounts. We also keep when you last chose “Hide for now” on the dashboard’s Support us card.
Suspension, deletion, and retention
Pausing your account hides it while preserving its data until reactivation or a deletion request. Requesting deletion hides the account immediately and starts a 60-day retention period. During that period you can sign in, confirm a new device if needed, and explicitly cancel deletion. After the deadline, cancellation is disabled and cleanup deletes the account and associated profile, authentication records, consent records, connections, conversations, meetup records, private notes and ratings, moderation flags, and member history. Original profile photo files are queued for storage cleanup; deletion may complete after the database purge and retry after a storage failure. Any ID verification sessions still held at Stripe are queued for redaction at Stripe. Requesting deletion (and the purge) cancels a paid membership at Stripe right away, with a full refund inside the 5-day refund window (see the Terms); Stripe keeps its own payment records as the law requires, and the offer and refund ledger stays as described above.
Signing up again within 60 days. If you sign up with the email address or phone number of an account scheduled for deletion, nothing about that account is shown or confirmed until you verify that email or phone with a code. Then the scheduled deletion is canceled and the account is reactivated as a new sign-up: you set a new password, accept the current policies, verify your email, phone and ID again and complete your profile again (your new sign-up details replace the old ones); two-step verification, trusted devices and sessions are cleared. The account keeps its ID, Stripe customer, membership and purchase history, introductory-price status, staff notes and its audit and safety history (reports, suspensions, ID reviews and legal holds); a suspended account stays suspended. Your previous connections, messages, meetups, notes and photos are deleted and not restored. If your email and phone match two different scheduled accounts, the most recently deleted one is reactivated and the other is linked to it for introductory-price and purchase history. We record that the account was reactivated and which identifier matched (email or phone), not the values.
Staff support notes record the reason for access, work performed, outcome, author, and time in the restricted audit trail and follow its 15-year retention rule. Corrections are appended rather than overwriting prior notes. A documented legal hold can delay deletion of relevant account or connected-conversation records. New holds have a specified duration and expiry; expiry is processed on service activity before retention cleanup. Existing holds without a recorded expiry remain active until reviewed. Access remains restricted while retained. Security/login audit logs for personal and staff accounts, and staff access and action logs, are retained for 15 years from each event, including account identifiers, account email, affected record identifiers, observed IP address when available, action, outcome, and timestamp. Authorized staff with audit permission can review login history for a documented reason and an authenticated staff session; date-filtered login exports also require legal-export permission. Earlier events may lack IP addresses; these cannot be reconstructed. These audit records survive deletion of staff or member accounts. Government ID images, selfies used for verification, and biometric templates are not included in this 15-year audit retention rule. Hosting or delivery-provider copies and backups follow those providers’ retention processes and are not guaranteed to disappear at the same instant as the active database. Information already copied outside this service cannot be removed by us.
The 60-day account workflow does not waive your statutory privacy rights. Where applicable law requires earlier action or permits only narrower retention, that law controls. Use the contact form to request review, correction, access, portability, earlier deletion, or appeal. We may need to verify your identity and will explain any applicable limitation.
ID verification and biometric data
ID verification is required for all personal accounts. It is the third step after email and phone: messaging and contact sharing unlock only after it. Before you start, we show a notice and ask for your explicit consent, and record that consent with its version and time. Our processor Stripe, Inc. (Stripe Identity) then asks for a photo of your government-issued photo ID (driver’s license, passport or national ID card) and a live selfie, checks that the ID is genuine and compares your selfie with the ID photo. That comparison uses biometric identifiers and biometric information (a scan of face geometry). Stripe processes it on our behalf for this check only, under its privacy policy.
Stripe returns the name and date of birth read from your ID; we compare them with your profile (first given name and last family name, ignoring case, accents, hyphens and middle names; date of birth exactly; and 18 or older) and keep only the result: verified or not, which fields didn’t match (name, date of birth or age), the dates, the number of attempts and Stripe’s session reference. We never receive or store your ID images, selfie, document number, address, face data or the values read from your ID. After a verified name and date of birth are recorded, they are locked; corrections go through support. You can try up to 3 times a day and 5 times in total; after that our team may ask you to upload your ID for a manual review as described below.
Retention and destruction: as soon as a check has a final result (verified, not matching, or canceled), we ask Stripe to redact that session, which deletes the ID images, selfie and biometric data from Stripe’s records, except where a documented legal hold requires us to keep them until the hold ends. Sessions of deleted accounts are redacted too. Stripe may retain limited records as its own policy and the law require. In every case biometric data is permanently destroyed once the purpose of the check is satisfied and no later than 3 years after your last interaction with us. We do not sell, lease, trade or otherwise profit from biometric data, and we disclose it only to Stripe as our processor, with your consent, or when required by law, a valid warrant or subpoena. We protect it with the same or greater care as other confidential information.
Illinois residents: this section is our written policy and retention schedule under the Biometric Information Privacy Act, and the consent step is our written release. Texas and Washington residents: we collect biometric identifiers only with your notice and consent, for identity verification only, and destroy them within the time described above (Texas: within a year after the purpose expires; Washington: we do not use them for any other purpose or sell them). You can decline; without ID verification, messaging and contact sharing stay locked while it is required, and you can still ask support about a manual review. Contact us to ask about or withdraw consent for future checks.
Profile pictures and flagged-account ID review
A profile picture remains required. Replacing a picture does not trigger a selfie check; ID verification (above) compares your selfie with your ID, not with your profile picture. Pictures remain subject to content safety review. Both participants must verify email and phone and complete any required account recovery before communicating. When memberships are paid, the first phone and ID checks happen after you start your membership, so we don’t send your number to Twilio or start an ID check with Stripe before then. Twilio Verify is used to verify a phone number when you first verify it and whenever you change it (a code by text message or voice call, as you choose), a new email address (a code by email), and — only if you turn on two-step verification — a new device the first time it signs in (a code by text, call or email to a phone number or email address already verified on your account). Two-step verification is optional for members and off by default; with it off, you sign in with your password and we email you whenever a new device signs in. Devices stay trusted until you remove them in Account settings; a password reset removes all trusted devices. Passkeys. If you add a passkey, your device checks your fingerprint, face, PIN or screen lock itself: no biometric data (fingerprints or face images) ever reaches us. We keep only what signs you in: the passkey’s credential ID and public key, its signature counter (to detect a copied passkey), how your device can reach it (transports), whether it syncs between your devices, the name you gave it, and when it was added and last used; plus a single-use sign-in challenge for 5 minutes. We email you when a passkey is added or removed. You can remove passkeys in Account settings; a password reset or a staff-issued temporary password removes them too. Passkeys are for member accounts only. After a password reset you verify your phone number again (the reset code already confirmed your email); after a staff-issued temporary password you verify both your email address and your phone number again. Otherwise verification is asked again only when you change your email or phone number or when staff remove a verification — never for ordinary sign-ins, new devices or being signed out for inactivity. Once your email, phone number, first name, last name or birth date is verified, you can no longer edit it yourself: editing your profile sends one change request with every verified detail you changed (the current and new values) and a reason, stored encrypted. Our support team reviews it, and after approval you verify every new detail within 5 days — a code to the new email or number, and a new ID check for your name or birth date (your ID must match). Nothing changes until all of them are verified; if you don’t finish in time, the request expires and your current details stay. Until then other members and the contact card you share see only your current verified details; the requested values are visible only to you and our support team. Requests, decisions and their reasons are kept with your account history and audited. While an approved change waits for verification, you can use only My Profile and Account settings; messages sent to you are kept and shown afterwards, and we notify your previous email address when an email change completes. An authenticator app is optional for members. Staff sign in with Microsoft and its multi-factor authentication at every sign-in; only the Owner keeps an emergency password and authenticator sign-in, and every use of it is reported to our security contacts. Email/phone badges confirm contact-method control, not legal identity or age.
Staff may flag an account for a documented identity, age, or account-integrity concern and request a copy of a government-issued photo ID. We use it to manually review document validity and match first name, last name, and birth date against the submitted profile, including the 18+ requirement. Messaging and contact sharing are restricted until approval. The request and upload page appear in your account. Failure or refusal to comply with required ID verification will result in permanent account suspension following staff review. Contact support if you cannot provide the document, dispute the request, or want to appeal a decision.
ID images are stored separately from profile pictures in restricted service storage. Only staff with ID-review permission may view them for a documented reason; access and decisions are audited. They are never displayed to connections, sent to automated photo moderation, or included in profile-photo exports. A copy alone is not a live identity check and cannot guarantee authenticity.
Pending ID images remain until the review is decided or the account is deleted. Reviewed original ID images are queued for deletion 30 days after the decision, unless a documented legal hold applies. Replacement uploads queue the previous copy for removal; replacements are blocked while that document is held. Cleanup occurs on service activity and may retry after storage failures. Account deletion also queues ID originals for removal subject to legal holds. Review status, submitted name/birth-date snapshot, and timestamps follow account retention; staff access and decision audit records follow the separate 15-year rule. Permanent suspension is an access restriction, not automatic account deletion. Suspended members can contact support for privacy/deletion requests or appeals.
Member safety reports
You can report a connected profile for nudity, impersonation, harassment, threats, suspected underage use, scams, or other concerns. Reports include your account identifier, the reported account and connection, category, optional explanation, current photo-history reference, timestamp, and observed IP address. Authorized safety staff can review the report and relevant retained records. Reports are not shown to the reported member. Reporting alone does not pause or remove a connection; you can choose either action afterward. Automatic actions (hiding a reported photo, suspending a profile pending review after reports from two members within 14 days) and staff decisions to restore, confirm, lift or convert them are recorded in the audit trail. A suspended member is notified by email and in the app. Reports survive removing a connection and follow the reported account’s deletion and legal-hold rules. Staff review decisions remain in the separate audit trail. Deleting the reporter’s account removes its live account link.
Security and cookies
We use secure session cookies, password hashing, two-factor authentication, and server-side access controls. Only staff with relevant permissions may access administrative tools. The app does not promise end-to-end encryption or absolute security. Essential session cookies keep you signed in; this release does not intentionally use advertising cookies. Sessions have no fixed lifetime: we record when you were last active (at most once a minute; automatic background checks do not count) and sign you out after a period of inactivity — 30 minutes by default, or 15 minutes, 1, 2 or 4 hours as you choose in Account settings (“Sign me out after being inactive for”); staff accounts are always signed out after 10 minutes. You are warned shortly before, and your trusted devices are not affected. On the website your session also ends when you close your browser, unless you choose “Stay signed in on this device”: then it lasts up to 14 days from when you signed in, without the inactivity sign-out, and ends at once after a security change such as a new password.
Changes and contact
We will update the date above when this policy changes and obtain additional agreement when required. Contact Elevated Life Connections, LLC through Help & contact or support@heyitsyouagain.com for support and privacy requests. Requests are routed through the service’s internal support tools.