We use your information to run Hello!, keep your circles private, and protect the service. We don’t sell personal information, run advertising, or track you across other companies’ apps and websites.
Who is responsible
This policy covers the Hello! iPhone and Mac apps, widgets, API, and littlehello.app. The operator and controller of your personal information is Madhu G B (sole proprietor), based in India. Contact: support@littlehello.app.
What we collect and why
- Account details: your email address, optional display name, an account identifier, and account creation time. We use these to send requested sign-in codes, identify you, and maintain your account.
- Circles: circle names, ownership, invitations, membership identifiers, and join or leave times. These let us share content with the right people and enforce circle limits.
- Content you share: voice recordings of up to sixty seconds, their duration and sharing time, and optional emoji moods. We store and deliver them to your chosen circle. Draft recordings stay on your device until you share them.
- Listening progress: playback position and the first completed listen. This lets you resume and applies the replay expiry. We do not show your listening progress or read receipts to other people.
- Security and operation: hashed session tokens, protected sign-in code checks, rate-limit counters, request metadata, and diagnostic events. Requests expose an IP address and technical information to our hosting provider; application rate limits use protected pseudonymous keys rather than storing plain IP addresses as rate-limit identifiers.
- Support: the email address and information you choose to send when asking for help or reporting a concern.
We do not access your address book, precise location, camera, or photo library. We do not transcribe recordings or use them to train AI models. Please avoid recording other people or sharing their personal information without appropriate permission.
Who can access your moments
Your display name and current mood are visible to members of your circle. A recording is available to you and the eligible members who belonged to that circle when it was shared. New members do not receive earlier recordings. Circle owners can manage invitations and members. Your email address is not included in the circle’s member listing.
We use Cloudflare for hosting, the database, private audio storage, security, and sign-in email delivery. These services process information on our behalf. Your email provider also processes the sign-in emails it receives. The website currently loads fonts from Google Fonts, which receives the connection information needed to deliver them. See Cloudflare’s privacy information and Google Fonts privacy information.
Information may be processed in countries other than yours through these providers. Where applicable law requires safeguards for international transfers, those safeguards must apply. We may disclose information when legally required, to protect people or the service, or in connection with a transfer of the service, subject to applicable law.
How long things stay
- Voice availability: up to seven days from sharing. Each recipient’s first completed listen starts a replay window of up to twenty-four hours, capped by that original seven-day limit. Deleting a recording or revoking the sender’s membership prevents new authorised downloads.
- Audio removal: expired or inaccessible audio is removed by background cleanup, normally targeted within twenty-four hours. Failures or a backlog can delay physical removal. A storage lifecycle rule provides an eight-day expiry backstop; provider deletion is asynchronous.
- Moods: hidden after twenty-four hours; expired values are removed by background cleanup. We do not keep a separate mood history.
- Accounts and circles: account information remains until account deletion. Membership history may remain while the account and circle exist. Invitations expire after seven days.
- Security records: sign-in codes expire after ten minutes; sessions after thirty days. Rate-limit windows are at most twenty-four hours. Expired records are normally removed by the hourly cleanup.
- Minimal recording records: identifiers and retry-prevention metadata can remain while the original membership is active, even after audio removal. Once that membership is inactive or removed, purged records become eligible for cleanup after thirty days from sharing.
- Diagnostics and backups: Cloudflare Workers logs and traces have provider retention of up to seven days. Database recovery copies may retain earlier database state for up to thirty days. We do not create separate application audio backups.
- Support correspondence: retained as needed to address your request, resolve disputes, and meet legal obligations.
Disappearing means access expires in Hello!; it cannot prevent someone from making an external copy. Already buffered audio can remain playable until playback stops or its known expiry is reached. Deletion is not instant physical erasure from every system or backup.
On your device and in widgets
Sign-in credentials are held in the system Keychain. Drafts and listening progress are stored locally and excluded from device backups. Drafts remain until shared, discarded, or removed by account deletion on that device; signing out alone does not discard them. Audio downloaded for playback is held in memory.
Widgets share a sign-in credential with the app and cache circle names, people, moods, and voice availability, but not audio recordings. Widget visibility and refresh timing are controlled by your device. Anyone able to see your home screen or desktop may see widget content; remove a widget if you don’t want it visible there.
Your choices and rights
You can edit your name, clear a mood, delete your own recordings, leave circles, remove widgets, or turn off microphone access in system settings. Microphone permission is requested for recording; listening does not require it.
To delete your account, open Settings → Account → Delete account. If you own circles, first transfer ownership or close them. Deletion removes your account and memberships, revokes sign-ins, and makes your recordings unavailable for new downloads. The device completing deletion clears its drafts, listening progress, and widget data. Other devices discover the revoked session on their next request; local drafts on those devices are not remotely erased.
You may also contact support@littlehello.app to request access, correction, a copy, deletion, restriction, or objection, where applicable. We may verify your identity. Where processing is based on consent, you may withdraw it without affecting earlier lawful processing. You can complain to your local data protection authority.
Where a legal basis is required, we rely on providing the service you request for core account and sharing functions, legitimate interests for proportionate security and support, consent where required, and compliance with legal obligations.
Age requirements
Hello! is intended for people aged 18 or older. If you believe someone below the minimum age has supplied personal information, please contact us so we can investigate and take appropriate action.
Security and changes
We use encrypted network connections, private storage, and membership checks. Hello! does not currently provide end-to-end encryption: the service can process recordings to store and deliver them. No system can guarantee complete security.
We will update the date on this page when the policy changes and provide additional notice of material changes where required. We will obtain consent where required for new uses of information.