Privacy Policy

Last updated 14 September 2026

uThere? works on nicknames, so other uTheres never see who you are. This page says what we hold, why, how long, and what you can ask us to do about it. If you are in the EU or UK, the GDPR rights below are yours.

Who is responsible

The controller of your personal data is Daniele Saita, still on Saturn, but will move to Earth soon. Privacy questions go to privacy@uthere.app, and our data protection contact is Daniele Saita.

What we collect

  • Your account: nickname, email address, a hashed password (never the password itself), or the identifier your Google or Apple sign-in gives us.
  • What you post: wall sprays, chat messages, voice clips and the automatic transcripts of them, reactions, and the rooms you open or walk into.
  • Your settings: the voice disguise you prefer, your country for crisis lines (only if you choose one), mute and snooze choices, and whether you are on the listeners list.
  • Technical data: session token, timestamps, and basic logs needed to keep the service up and to stop abuse.

We do not track your location and we do not run advertising profiles on you.

Why we hold it, and our lawful basis

  • To run the app — showing your posts to the uTheres you shared them with, delivering chats and voice rooms: performance of our contract with you (Art. 6(1)(b)).
  • To keep uTheres safe — moderation, reports, blocking, rate limits: legitimate interests (Art. 6(1)(f)), and legal obligation where one applies.
  • To answer you — support and appeals: contract and legitimate interests.
  • Optional extras — AI recaps or parodies of a voice room: your consent, which is asked for in the room and can be withdrawn.

Voice clips, transcripts and special category data

Voice clips are transcribed automatically so uTheres who cannot listen can still read the room. If you talk about your health or your feelings, that may be special category data; we hold it only because you chose to post it in a place built for that (Art. 9(2)(a) consent, and Art. 9(2)(e) where you have plainly made it public on the wall).

Self-harm detection: automated, and private

Text and transcripts are screened for signs of self-harm. If something is flagged, two things happen — and only two. You are shown a gentle message with a crisis line for your country, and one private notice goes to the owner of the room you said it in, or to our moderators when there is no room owner, so someone can reach out quietly. Nothing is marked publicly, no other uThere is told, and no account is suspended by the automated check alone: a person decides anything that follows. That is our safeguard against a decision made purely by a machine (Art. 22).

Who else sees your data

Other uTheres see your nickname and what you post (or nothing but the post, if you posted anonymously). Beyond that we use a small number of processors under contract:

  • Emergent (emergent.sh), for hosting and database infrastructure;
  • OpenAI, for transcription, moderation screening, recaps and text-to-speech of the content you post;
  • Resend, for the emails we send you (password resets and notices);
  • Google and Apple, if you choose their one-tap sign-in.

We do not sell your data. Ever.

Leaving the EU

Some of those providers are outside the EU/EEA, including in the United States. Where that happens we rely on the European Commission's Standard Contractual Clauses, or an adequacy decision where one exists, and we ask for the security measures that go with them. Ask us for a copy of the safeguards at privacy@uthere.app.

How long we keep it

  • Voice room clips: they die with the room.
  • Wall sprays, chat messages and reactions: until you delete them, or until you delete your account.
  • Your account: until you delete it. Deletion removes your nickname, email and posts.
  • Moderation records (what was removed and why, reports, appeals): 12 months, so repeat harm can be spotted and appeals answered.
  • Sessions: 7 days, then they expire on their own.

Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another service. You can withdraw a consent at any time, which does not undo what was done while it was given. Write to privacy@uthere.app and we will answer within one month.

You do not have to ask us for a copy: "Take a copy with you" on your own profile downloads everything you put in as one file, whenever you want.

If you think we have got it wrong, you can complain to your national data protection authority — in the EU that is the one where you live or work.

Security, and children

Passwords are hashed, sessions are short-lived and carried in a cookie your browser cannot read from scripts, and access to moderation tools is limited to the people who need it. uThere? is not for children: you must be at least 16. If we learn an account belongs to someone younger, we delete it.

Cookies

We use one cookie: the session that keeps you signed in. No advertising or analytics cookies, so there is nothing to consent to beyond signing in.

Changes

If this policy changes in a way that matters, we will say so in the app before it takes effect.