Privacy Policy

What HereMe does with your information

HereMe replaces the paper visitor book. This policy says what we collect, why we may, who else sees it, how long it is kept, and what you can make us do about it. It is written to be read by the person it is about.

Who we are, and two roles

HereMe is operated by iTsitso Space LTD, a company incorporated in the Republic of Kenya. In this policy "we", "us" and "HereMe" mean that company, and "the Act" means Kenya's Data Protection Act, 2019 (No. 24 of 2019).

This one policy covers:

  • HereMe, the app for Android and iOS (space.itsitso.hereme);
  • HereMe Gate, the Android app organisations run on the tablets and phones at their entrances (space.itsitso.hereme.gate);
  • the web console at console.hereme.me, the lost-phone page at account.hereme.me, and this website, hereme.me.

We hold your information in one of two roles, and the difference matters:

  • We are the controller of your account, your profile, your vault, your messages and the rest of what HereMe keeps for you. We decide how that is used, and we answer for it.
  • A host is the controller of the visit records it receives. When you check in at a school, an office, an estate or a home that uses HereMe, the host receives only what you chose to share, and that copy is the host's visitor book. For it, we are the host's processor: we keep it on the host's instructions, for the period the host set (at most 7 days on HereMe), and we use it for nothing else.

How to reach us

  • privacy@hereme.me — anything about your personal data: a copy of it, a correction, deletion, an objection, a complaint, or a breach you think has happened.
  • support@hereme.me — your account, or something that is not working.
  • legal@hereme.me — legal notices, and our company particulars.
  • security@hereme.me — a security weakness you have found.

For a visit record a host holds, write to the host first; if you write to us, we pass your request to the host and help it answer (see Your rights).

Our company number and a postal address for service are not printed here yet; we would rather leave them off than print something that turns out to be wrong. Ask legal@hereme.me and we will give them to you, free of charge and by return.

Your data, your choice

Five promises sit under everything else on this page. Each is how HereMe is built, not only how we intend to behave.

  • Your data is yours. Your profile, your ID and passport details and the documents you keep in HereMe belong to you. HereMe keeps them encrypted, and iTsitso staff have no way to open them.
  • You share only when you are at peace with it. Nothing leaves your account unless you choose it — item by item, for a person or host you name, for a purpose they must state. Your ID, passport and documents need your fresh confirmation every time.
  • You can see what you shared. Every sharing from your vault, and every time a host opened a document you shared, is listed in your vault's sharing history.
  • What you share becomes the host's copy. A host keeps what you shared for the period it showed you before you agreed — at most 7 days on HereMe. Deleting your data in HereMe does not delete a host's copy, but we pass your request to the host.
  • We never sell your data, we show no advertising, and we never use what you share with hosts for anything else.

The information we hold

Everything HereMe holds about a person falls into a row below. If a kind of information is not in this table, HereMe has no place to keep it.

WhatWhyHow longWho sees it
Your account: e-mail address (and phone number, if your sign-in has one), how you sign in (Google, Apple or e-mail and password), your HereMe IDSigning you in and keeping the account safeWhile you have the accountYou; our staff, for support
Your public card: display name and profile photoBeing recognised when someone scans your code or types your HereMe IDUntil you change themAnyone who has your code or HereMe ID; fellow members of your organisations
A visit — the host's copy: what you chose to share at check-in, the host, the gate, the times, and the guard who actedThe host's visitor bookThe host's retention period: at most 7 days after the visit on HereMe (ID items no longer), then deleted. A host that needs its book longer keeps its own export, under its own policyThe host's authorised members
A visit — your copy, and your confirmationYour own historyOn your phone, in HereMe's encrypted store, until you sign out or HereMe is erased from the phone. HereMe's server copy: 7 days after the visitYou
Your public hall: a visit you choose to show (the place and the day, never the time)Showing where you have beenUntil you remove it or delete your account. It is something you publish, so the 7-day rule does not remove itPeople connected with you — never someone you blocked or who blocked you
Your standing at a host: a host you visited may record that it trusts you (let in at once) or refuses you entry, with a reason its member writes and who set itThat host's gate deciding who may come inUntil the host clears it (the change stays in the host's audit trail)That host only — its members who check visitors in see the standing; only its owners and admins see the reason. Never another host: there is no shared list. You see only that a host trusts you; a refusal shows only as the gate's "please speak to the desk". The host's gate devices keep the HereMe IDs it trusts or refuses, so that they work offline
A visit with another person: what you chose to share with them (name, e-mail, phone — never ID documents) and the connection it makesRemembering who you met; messaging between people who have metWhat you shared: 7 days from the visit, then deleted. An offer not confirmed within 5 minutes, or answered "Not me", is deleted with what it carried. The connection, with the name the other person's pass showed: while you have the accountThe other person. Before they confirm, they see only your name and HereMe ID and which items you offer, not their values; afterwards, what you shared, with every open logged and shown to you. They never see your profile
Messages to someone you have met. End-to-end encrypted: HereMe cannot read them. HereMe keeps only that a message was sent, by whom, in which conversation and whenTalking to people you have metOn HereMe: 7 days after sending (the record without text, and the encrypted copies until each of your devices collects them), then deleted. On your phone: until you "Delete for me", sign out, or HereMe is erased from the phone. In your Google Drive, only if you turn backups on (see Backups)You and the other person. A message you report is handed to us by your phone, with its text, for review
Organisations and invitations: the organisation's name and kind, each member's role, and an invitee's e-mail address or phone number, typed by whoever invites themRunning an organisation's consoleMembership: until you leave or are removed. An invitation: until answered, withdrawn or 7 days pass; the record stays in the organisation's audit trailFellow members see your display name and HereMe ID — never your e-mail or phone; owners and admins see invitations
Console browsers your phone signed in: browser and system (e.g. "Chrome on Windows"), the city and country the sign-in was opened from, as our network saw it (never the IP address), whether it is a shared computer, which of your phones approved it and when, last use, and any extra lock you chose (a PIN, kept only as a one-way hash)Signing the console in from your phone; letting you see and sign out your console browsersWhile the browser stays signed in (30 days unused, or 12 hours on a shared computer), then deleted 30 days after it ends. The audit trail keeps the sign-in's browser, system and country — not the cityYou, on your phone and in the console
Devices and push tokens; each phone's erase check (a one-way hash of a secret only that phone holds) and whether you asked to erase HereMe from itSign-in, notifications, and telling a lost phone to erase HereMeUntil sign-out, or 60 days unused; the erase check until the next sign-in on that deviceYou
Notifications: your inbox (what you were told and when you read it; for a message, the sender's name — never its text), your notification choices, and a record of each push sentTelling you about check-in, checkout, "confirm you visited", "were you with…", the thank-you, messages, invitations and security events7 days, then deleted from HereMeYou
Blocks and reports: the people you blocked; reports you made, with what you saw when you made themYour safety, and reviewing abuseBlocks: until you unblock or delete your account. Reports: kept for review and as evidence, also after your account is deletedYou (your blocks — a blocked person is never told); our staff (reports)
Your vault: contact cards (name, organisation, job title, phone, e-mail, address, website), national IDs, passports, other IDs, documents, items with fields you define, and files — photos, PDFs and audio recordings, up to 10 MB eachSharing when you choose, one item per requestUntil you delete them, or your accountOnly you. Never iTsitso staff
Shared copies from your vault: for each thing a host asks for, the one item you pick — name, phone, e-mail, an ID number, or an ID photo. ID items and photos each need a fresh sign-in. An ID photo is watermarked on your phone ("Shared with {host} · {date} · for {purpose} · via HereMe") before it leaves, and sealed with the host's keyThe host's stated purposeThe host's retention for sensitive items: 1–7 days, never longer than the rest of its record. A photo whose visit never reached HereMe is deleted within a dayThat host's members who hold its sensitive-data permission — never iTsitso staff. Your sharing history lists what you shared, with whom, for what, and each time the host opened it
Passes and their device keys; at a gate with no connection, what you choose to share travels inside your code, sealed so that only the host can open itChecking in at gates, also offlineA pass lasts at most 7 days. Your phone keeps its own copy of an offline visit (the host, the gate, the time and the names of what you shared, never the values) until HereMe has it; the gate device keeps its records, encrypted, until they uploadYou; the host
Event tickets: your HereMe ID tied to a ticket an organisation issued (its own ticket and attendee references, the ticket type and status), and the ticket's check-in (time, gate, device, guard)Letting a ticketed event check you in at its HereMe gateDeleted once the host's visit retention has passed after the event endsThe organisation's owners, admins and managers, and the organisation's own ticketing system (status, time, gate name and device label only). Your name reaches the host only through the check-in itself
Your profile photoYour public cardUntil you replace or remove it — then deleted at once. Photos are re-encoded before anyone sees them, which removes location and camera details; the original stays private and goes with the photoAs your public card
Consent records: which version of these documents you accepted, when, and your confirmation that you are 18 or olderProving what you agreed toWhile you have the account, and for the legal period afterYou; our staff
Security and audit logsSecurity, and investigating abuse24 months; any IP address in them for 90 daysOur staff
A deletion request: when and where you asked, the date it runs, and its stepsCarrying out the deletion, and proving it was doneKept with the account's tombstoneOur staff
What you write to us by e-mailAnswering youWhile we deal with it, and afterwards as the record of our answerOur staff

HereMe does not take payments yet. When paid plans for organisations open, payments will be received in Kenya by M-Pesa, and this table will gain a row for them first (see Who else sees it).

What we do not collect

Plainly
  • Your location. HereMe does not ask for location permission and does not track where you are. A check-in records the host and the gate, never GPS. Two things come close, and we name them: the city and country a console sign-in was opened from, and IP addresses in security logs for 90 days.
  • The text of your messages. It is sealed on your phone before it leaves; HereMe has no way to read it.
  • Your fingerprint or face. If you turn on the app lock, your phone checks it; nothing about it — not the setting, not the result — reaches us.
  • Your contacts, photos or files, beyond the ones you choose to add.
  • Camera images. The camera reads codes on your phone; we neither store nor send what it sees.
  • Advertising or analytics. No advertising SDK, no analytics SDK, no tracking pixel; this website loads nothing from anyone else.
  • Card, bank or PIN details.

We do not buy personal data, scrape it, or build profiles from anything outside HereMe. There is no directory and no search: nobody can look you up.

Where the information comes from

  • From you — what you type, add to your vault, choose to share, or write to someone.
  • From Google or Apple, if you sign in that way — your name and e-mail address on that account, and an identifier that links it to your HereMe account.
  • From your device — its push token, platform, app and system versions, model, language and time zone.
  • From a host — your standing there, if it sets one, and the guard and gate that recorded your visit.
  • From an organisation's ticketing system — that your HereMe ID holds one of its tickets.
  • From someone who invites you to an organisation — the e-mail address or phone number they typed.
  • From our network — the approximate place (city and country) a console sign-in was opened from.

Why we are allowed to use it

The Act lets us process personal data only for a reason it recognises (s.30). Here is the one we rely on for each thing we do.

What we doThe basis
Run your account, sign you in, keep your devices and console browsers, send notifications at the critical pointsContract — to give you the service you signed up for
Pass what you choose to a host or a person, item by itemYour consent, given each time you share; for ID items and documents, given afresh every time
Keep a host's visitor book for the hostWe act for the host, as its processor. The host relies on its own lawful basis for keeping a visitor book
Carry your messages, and keep your vault, passes and public hallContract
Keep security and audit logs, review reports, enforce blocks and the Terms, record where a console sign-in came fromOur legitimate interest in keeping HereMe and the people on it safe
Keep consent records and answer lawful requestsLegal obligation

If we ever want to use your information for a purpose that is not compatible with the one it was collected for, we will ask you first. We do not send marketing, and we make no decision about you by computer alone that has a legal or similarly significant effect: a host's decision to trust or refuse a visitor is made by a person at that host, and its gate only applies it.

Hosts, and the people you share with

At a gate, HereMe shows you the host, what it asks for, why, and how long it keeps it — before you agree. You choose what to share. A host can mark an item as required; if you do not share it, the host decides whether to let you in, and many hosts will offer you a manual way in.

  • A host keeps its copy for at most 7 days on HereMe. HereMe then deletes it. Every week we remind the host's owners and admins to export what they need; an export is the host's own copy, kept under its own policy and lawful basis, and we keep no copy of it.
  • Sensitive items — ID numbers, passport details, document photos — are seen only by the host's members who hold its sensitive-data permission, and are deleted before the rest of the record.
  • Gates work offline. A gate with no connection still checks your pass; what you share travels sealed inside your code. A change — a revoked pass, a refusal — reaches an offline gate when it next connects.
  • Deleting your account or a vault item does not delete a host's copy. We forward your request to each host holding one, and the host decides as controller. Your vault shows the host's answer.

When you visit another person, each of you holds what the other chose to share, for 7 days; it is deleted after that. Every time they open it, you can see so.

Messages, end to end

You can message only people you have met through a HereMe visit, and nobody you blocked or who blocked you.

Every message is end-to-end encrypted: HereMe cannot read it. It is locked on your phone for the other person's devices (and your own other devices) before it leaves, and HereMe has no way to receive its text. When a message arrives, HereMe's push only tells your phone that something new is waiting: it contains no text and not even the sender's name. Your phone then collects the encrypted message, opens it, and shows the notification itself — by default with the sender's name and the first words, or, if you choose in Settings, with the name only or with nothing but "You have a new message". A locked screen shows only "HereMe". That preview is made on your phone; HereMe, Google and Apple never see it. On iPhones, message notifications will arrive once push notifications are available there.

The limits, so you know them
  • HereMe still sees that a message was sent: by whom, to whom, when, and how large its encrypted copies are. We need that to deliver, order, count and delete messages.
  • Reporting a message hands its text to us. Your phone sends the text it shows, so that our staff can review the report. The report screen says so before you send it.
  • HereMe does not yet offer a way to compare security codes ("safety numbers") with the other person.
  • "Delete for everyone" works only while HereMe still holds the message (7 days), and cannot reach a copy the other person already backed up. "Delete for me" removes it from your phone only.
  • Your phone collects new messages when you open HereMe and, on Android, when a message's push arrives. A phone that collects nothing for 7 days misses what was sent in that time.
  • The encryption covers messages. Your vault and your visits are protected as this page describes, but they are not end-to-end encrypted.

Backups to your own Google Drive

Your messages and your record of visits live on your phone. If you lose the phone, they are lost — unless you turn on backups (off until you do).

  • A backup goes to the hidden HereMe folder of your own Google Drive. HereMe asks Google only for access to that folder, and your phone talks to Google directly: HereMe's servers never see the file, its key or your Google account.
  • It holds your conversations, messages and your record of visits. It does not hold your vault (HereMe keeps that for you), what others shared with you for a limited time, or any key.
  • It is locked with a 64-character key or a password that only you hold. If you lose it, nobody can open the backup — not even HereMe.
  • The last two backups are kept until you delete them in Google Drive. Deleting a message for everyone, or deleting your account, does not reach a backup you already made.
  • It uses your Google storage. You can remove HereMe's access at any time in your Google Account (Security → third-party access).

For a backup, Google acts as your own storage provider under your agreement with Google, not as ours.

Who else sees your information

Besides the hosts and people you choose to share with, these are the only companies that receive personal data from HereMe. Each works for us under its data-processing terms, unless the table says otherwise.

WhoWhat they getWhat forWhere
Google — Firebase Authentication, App Check and Play IntegrityYour sign-in details (e-mail, name, the Google or Apple identifier), and checks that a request comes from the real appProving who you are; keeping fake apps outOutside Kenya
Google — Firebase Cloud Messaging (and Apple's push service on iPhone)Your device's push token, and each push: for a message, only a signal with no name and no text; for other events, the push's title and bodyDelivering notifications. Delivery is not guaranteed or instantOutside Kenya
Google — ML Kit, on AndroidNothing from HereMe: it reads codes on the phoneScanning HereMe codesOn your phone
Apple — Sign in with Apple, App AttestThat you are signing in to HereMe, and the identifier and e-mail Apple returnsSigning in on iPhone; checking the app is genuineOutside Kenya
SupabaseEverything in the table above that HereMe's servers hold — encrypted where this page says soHereMe's databaseUnited Kingdom (London)
CloudflareEvery request to HereMe passes through it; it runs HereMe's servers and stores files such as profile photos and encrypted ID photos; it receives e-mail sent to our addressesNetwork, hosting, file storage and our inbound e-mailCloudflare's global network
ResendAn e-mail address and the e-mail we send it — for example the weekly visitor-book backup reminder to an organisation's owners and adminsSending HereMe's e-mailOutside Kenya
An organisation's ticketing systemThe check-in state of the tickets that system created: status, time, gate name and device labelThe organisation's own event. It works for the organisation, not for usChosen by the organisation
Google Drive — yoursYour encrypted backup, if you turn backups onYour own backup (see Backups). Google acts for you, not for usYour Google account

When paid plans open, Safaricom (M-Pesa) will receive and report organisations' payments to iTsitso's Paybill in Kenya. We will add it here before the first payment is taken.

Our own staff

HereMe's staff console is separate from everything above, reachable only by named iTsitso staff, with a second sign-in factor, a 30-minute idle logout and a 12-hour cap. Staff cannot open your vault — there is no path to it — and cannot read your messages. They do not browse visit records: a host's records are shown to staff only under a support grant that host issues. Every staff action, and every sensitive read, is recorded with its reason.

When the law requires it

We disclose personal data only under lawful process — a court order, or a lawful request from the Data Commissioner or another authority — and only what is required. A request for a host's visit records is sent to the host, unless the law compels otherwise; we tell the host unless the law forbids it. We record what we gave.

If HereMe is ever sold, merged or reorganised, its records may pass to the new owner, who would be bound by this policy until it lawfully publishes another. We would tell you.

We do not sell personal data. We never have, and this policy does not permit it.

Sending information outside Kenya

HereMe's database is in the United Kingdom, because our database provider has no region in Africa. Sign-in, notifications and e-mail run on Google's, Apple's and Resend's services outside Kenya, and Cloudflare carries every request on its global network. So your information leaves Kenya.

The Act allows that only with appropriate safeguards or your consent (ss.48–50). Each provider is bound by its data-processing terms to act only on our instructions and to keep the data secure. Most transfers are also necessary to give you the service you asked for. What does not leave your control: the text of your messages is encrypted end to end, your vault is encrypted before it is stored, and a backup is locked with a key only you hold.

Once data is held in another country, Kenyan law is harder to enforce over it, and that country's authorities may have powers of access Kenya's do not. That is the honest risk.

Deleting your account and your data

You can delete your HereMe account at any time, for any reason, free of charge. There are three ways:

To ask, you sign in again just before (your password, or your Google or Apple account). Asking signs you out everywhere at once. The deletion runs 14 days later; until then you can sign in and keep your account. If you are the only owner of an organisation that has other members, hand it over first.

What goes

Your account and sign-in, profile and photo, vault, devices and push registrations, notifications and their choices, invitations waiting for you, your place in organisations (an organisation left with nobody in it is closed and its name removed), HereMe's copy of your visits, your public hall, your connections and your messages on HereMe.

What stays, and why

  • A record of what you agreed to, for the legal period; the audit trail, which holds no personal data; and a tombstone that stops your HereMe ID from ever being given to someone else.
  • Reports you made, kept as evidence.
  • Hosts' copies of what you shared — kept on HereMe for at most 7 days after each visit, and in any export a host made, under the host's own policy. We forward your deletion request to each host that holds a copy.
  • Copies outside HereMe: messages already on other people's phones, and any backup in your own Google Drive.
  • Our database provider's backups, until they age out on its schedule.

You can also delete any vault item on its own, at any time, without deleting your account.

If you lose your phone

At account.hereme.me, sign in and choose "Sign out everywhere and erase HereMe from my devices". Every device is signed out at once, and each phone and tablet erases what HereMe keeps on it — your pass and its keys, the encrypted local database, items not yet sent, the app lock setting and the app's caches — when it next hears from HereMe.

The limit

A phone that is switched off, or never connects again, cannot be erased. Until it connects, what HereMe kept on it stays protected only by the phone's own lock and HereMe's encryption on the phone. On iPhone, erasing happens at the app's next start. The erase reaches only HereMe — not other apps, and not your photos or files. A HereMe Gate device is revoked by its organisation instead.

Keeping it safe

What protects your information, as built:

  • Encrypted in transit. Every connection to HereMe uses HTTPS.
  • The database decides who may read what. One host cannot read another's records; one person cannot read another's conversations, whatever a request asks for.
  • Your vault is encrypted at rest under keys only HereMe's private server holds, with an offline copy of the master key under two-person control. Only you, and the hosts you share with, can open items through HereMe. It is not end-to-end encrypted: our server opens items in order to deliver the copies you share. Staff have no path to it.
  • Messages are end-to-end encrypted (see Messages).
  • On your phone, HereMe's database is encrypted with a key held in the phone's hardware-backed keystore, and erased when you sign out. Your pass is bound to a key that cannot leave the phone, and its live code is re-signed every 15 seconds, so an old screenshot of it does not work.
  • An app lock, if you want one, using your phone's own fingerprint, face or screen lock. It guards a phone picked up unlocked; it does not replace your sign-in, and anyone who knows your phone's screen lock can open it.
  • The console is signed in from your phone, which shows you the browser and place asking before you approve. You can sign any console browser out from your phone at once, and add a PIN or an authenticator app to a browser. An organisation's owner decides whether its work in the console needs that phone approval (it does unless the owner turns it off); with it off, a Google or e-mail sign-in also reaches the organisation's work.
  • Sensitive acts need a fresh sign-in: opening ID items, deleting your account, signing out everywhere.

No system is perfectly safe, and we will not claim ours is. Keep your sign-in to yourself, and tell us about any device or console browser you do not recognise.

If something goes wrong

If personal data is reached by someone who should not have it and there is a real risk of harm, we will notify the Data Commissioner within 72 hours of becoming aware, tell you what happened and what to do, and — for a host's records — tell the host without delay (Act s.43).

Cookies and browser storage

  • hereme.me — these pages — sets no cookies and stores nothing in your browser.
  • console.hereme.me keeps your sign-in (in your browser's storage, or only for the tab on a shared computer), a key this browser made and cannot export (so that only this browser can finish a sign-in your phone approved; erased when you sign out), the organisation you last chose, and when you last dismissed the backup reminder.
  • account.hereme.me keeps your sign-in only for the tab.

None of it is advertising or analytics, and none of it follows you to other sites.

Your rights, and our deadlines

These rights are free, and the deadlines are the ones Kenyan law sets.

Your rightWhat it gets youWe answer within
To be toldWhat is collected, why, who receives it and how it is protected — this pageBefore collection
AccessConfirmation that we hold your data, and a copy of it7 days
CorrectionAnything wrong about you put right. Most of it you can correct yourself in the app14 days
DeletionYour data erased (see Deleting your account)14 days
RestrictionYour data kept but not used, while a question about it is settled14 days
ObjectionAn end to a use you disagree with, unless we have an overriding ground14 days
PortabilityYour data in a common electronic format30 days
Withdraw consentAn end to anything that rested on your consent. What was lawfully done before stays doneOn receipt

Write to privacy@hereme.me and say which right you are using; the e-mail address on your account is usually enough for us to find you. We may first confirm it is you — handing your data to someone pretending to be you would itself be a breach. Someone may act for you: a parent or guardian, or a person you authorised (s.27). If we say no, we tell you why, in writing, and that you may complain to the Data Commissioner.

For a host's visit records, the host is the controller: we forward your request to it and help it answer.

Children

HereMe is for people aged 18 or over, and you confirm your age when you sign up. In Kenya a child is anyone under 18, and a child's data needs a parent's or guardian's consent. If you are a parent or guardian and believe a child has an account, write to privacy@hereme.me and we will delete it.

Complaints

You can complain to us, to the regulator, or both. You do not have to come to us first.

To us: privacy@hereme.me. We acknowledge a complaint within 7 days and answer within 30. A request about your own data keeps its own deadline above, whether or not you call it a complaint.

To the Office of the Data Protection Commissioner (Act s.56): complaints portal cie.odpc.go.ke · website www.odpc.go.ke · info@odpc.go.ke · 020 780 1800 · Britam Tower, Hospital Road, Upper Hill, Nairobi · P.O. Box 30920-00100 G.P.O. Nairobi.

To the courts: a person who suffers damage through a breach of the Act — distress included — is entitled to compensation (s.65). Nothing in this policy or our Terms takes that away.

Changes to this policy

When what HereMe does changes, this page changes first, with a new version and date at the top. When a change matters to you, the app asks you to read and accept the new version before you carry on. We will never quietly widen what we collect and call it a clarification. If you want the version that applied on a particular date, ask privacy@hereme.me.

Related: Terms of Service · Delete your account · Lost phone