Privacy Policy
Last updated: 15 July 2026
This Privacy Policy explains what personal data Hazemere collects, why, and what rights you have over it. Hazemere is currently operated by an independent individual, who acts as the data controller; you can reach the operator — including to request the operator's identity — at contact@hazemere.com. Hazemere serves a global, primarily English-speaking audience, and this Policy grants the rights required under the EU General Data Protection Regulation (GDPR), the UK GDPR, and comparable data-protection laws.
Hazemere is a cinematic travel-world web app. Most of it — worlds, routes, locations — is public, static content that needs no account. Personal data is involved only when you sign in, save worlds, publish a tour in the creator studio, or message another member.
1. What data we collect
- Account data — your email address (always), and, if you sign in with Google, your name and profile picture as provided by Google. We do not receive or store your Google password.
- Memory data — the worlds you save (♡) and the worlds you mark as lived-in, tied to your account.
- Creator content — if you become a creator: the handle, display name and bio you enter, plus the tours you build and the photos you upload.
- Social data — who you follow and who follows you, the worlds you like, and the witness notes you leave on worlds.
- Message data — the content of the private 1-to-1 messages you exchange with members you mutually follow, plus who sent what to whom and when, and whether a message has been read. Messages are stored in readable form (not end-to-end encrypted) — see "Security" below.
- Safety data — reports you submit, the members you block, and records of moderation actions.
- Device data — if you turn on notifications in our mobile app, the push token that identifies your device (handled by Google Firebase Cloud Messaging) so we can send you notifications; it is removed when you sign out of that device.
- Technical data — aggregate, non-identifying analytics (page views, outbound clicks) collected without cookies; server logs (including IP address) kept for a short period for security; and the strictly-necessary session cookie that keeps you signed in.
2. Why we process it
- To authenticate you and keep you signed in (email magic link or Google).
- To provide the account and memory features — saving worlds and remembering the ones you've lived in.
- To let creators build, preview, submit and publish tours, and to moderate that content.
- To provide the social layer — follows, likes, witness notes, notifications and private messages — and to keep it safe.
- To understand, in aggregate, how the product is used, so we can improve it.
3. Legal basis
Under the GDPR/UK GDPR (and equivalent laws) we rely on: performance of a contract — to provide the features you sign up for; your consent — given when you choose to sign in and submit content; and our legitimate interests — keeping the service and its members secure, moderating content, and understanding in aggregate how the product is used. Where we rely on consent, you may withdraw it at any time by deleting your account or writing to us; withdrawal does not affect processing already carried out.
4. Cookies and analytics
We use only a strictly-necessary session cookie to keep you signed in, and — with your consent — Google Analytics 4 to understand in aggregate how the product is used. Google Analytics sets analytics cookies and processes usage data (including a truncated IP and an identifier) on Google's infrastructure, which may involve a transfer to the United States under standard contractual clauses. We run no advertising cookies.
- Session cookie — keeps you signed in; strictly necessary (no consent needed).
- Google Analytics — aggregate usage stats; loads only after you accept the consent banner, and stays off (no analytics cookie) if you decline.
When you first visit we ask for your choice in a consent banner; declining keeps analytics disabled. You can also delete or block cookies in your browser settings — blocking the session cookie will sign you out, and clearing site data lets you make the consent choice again.
5. Who we share data with
We do not sell your personal data. We use a small set of processors to run the service: Supabase (database and file storage, hosted in Singapore), Google (OAuth sign-in, Google Analytics 4 for consent-based usage analytics, and — for mobile push notifications — Firebase Cloud Messaging), Vercel (application hosting), Cloudflare (image CDN and inbound email routing), and Resend (account emails). These providers may process data on servers outside your country; where personal data is transferred internationally, we rely on the providers' appropriate safeguards (such as standard contractual clauses). We also disclose data where required by law, and to protect the safety of members.
6. Storage and retention
We keep account and memory data while your account exists. Published creator content stays available while published. Server logs (including IP) are kept for up to 30 days. When you delete your account, or ask us to delete your data, we remove it within a reasonable period, except where the law requires us to keep certain records. Our internal retention schedule is available on request.
We keep the private messages you exchange while your account exists; when you or the other participant deletes an account, the messages tied to it are deleted with it. We do not keep messages indefinitely, and we may retain the minimum needed to handle an open safety report or to meet a legal obligation.
7. Your rights
You can ask us to access, correct, export (data portability) or delete your personal data, and to restrict or object to its processing; where processing is based on consent, you can withdraw it. To exercise any of these, write to the operator at the address below and we will respond within the time the law allows (generally one month under the GDPR). You also have the right to lodge a complaint with your local data-protection authority (in the EU/EEA, your national supervisory authority; in the UK, the ICO).
These rights cover your private messages: you can ask for a copy of your messages (export) or ask us to delete them. Because a message has two parties, deleting your account removes your copy, but the other participant may keep their copy of what you sent them.
8. Security
Access to personal data is protected by authentication and database row-level security, so each user can reach only their own records. Staff may access data only where necessary to operate and moderate the service; such access is restricted to what is necessary, and moderation actions (such as removing content) are recorded. No method of transmission or storage is perfectly secure, but we take reasonable measures to protect your data, and we will notify affected users and the relevant authority of a personal-data breach where the law requires (within 72 hours under the GDPR).
Because private messages are stored in readable form rather than end-to-end encrypted, authorised staff can technically access them where strictly necessary to operate or moderate the service or to comply with the law; such access is restricted to what is strictly necessary, and moderation actions are recorded. We do not read private messages for advertising, and we review them only reactively — in response to a report — never by proactively scanning them.
9. Children
Hazemere is not directed to children. You must be at least 16 (or the minimum age of digital consent in your country; at least 13 where local law sets a lower floor, such as the United States). We may set a higher minimum age for social or messaging features. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes
We may update this Policy as the product evolves (for example, when payments are introduced). We will change the date at the top and, for material changes, give notice in the app.
Privacy and data-protection requests (access, deletion, etc.): contact@hazemere.com.