Privacy Policy
Effective: 21 July 2026
This policy explains how Who Need Help processes personal data when people use the voluntary-help service, including Google sign-in. Who Need Help is not an advertising network and does not sell personal data.
Data we process
- Account and profile: email address, password hash if a password is added, display name, biography, locale, privacy and messaging preferences, optional thank-you URL, linked social profiles, confirmation status, and the time at which the registration rules were accepted.
- Help and activity content: requests, categories, descriptions, pickup instructions, selected locations and visibility, activity plans, matching and handover status, messages, participation decisions, reviews, category proposals, and votes.
- Trust and support: blocks, reports, moderation signals and decisions, support requests, account-deletion or data-export requests, and legal content-removal notices. These records may include the content, contact details, timestamps, and reviewer actions needed to handle the case.
- Location and tracking: a request or activity location that the user selects, plus exact location, accuracy, and capture time only when a participant actively starts live sharing. Tracking sessions retain summary evidence such as distance, sample count, movement, and proximity timestamps.
- Security and operation: session cookies, short-lived login and OAuth state, hashed rate-limit identifiers, request timestamps, and application or proxy logs needed to operate, diagnose, and protect the service.
Google sign-in data
Google sign-in requests the basic email and profile scopes.
The service uses the Google account's stable identifier, verified email address, email
verification result, and name to register, sign in, link the account, and seed the
display name. It stores the stable Google identifier and normalized email with the local
account. The application consumes provider tokens only while completing the sign-in
exchange and does not persist Google access tokens or ID tokens.
Google user data is not used for advertising, profiling outside Who Need Help, or sale. It is shared only with infrastructure processors when necessary to operate and secure the service, or when disclosure is legally required.
Why data is used
Data is used to authenticate accounts, publish and match requests, coordinate help or activities, deliver private chat and transactional email, apply the user's visibility choices, verify handovers, calculate reputation, prevent abuse, moderate content, respond to support and legal notices, maintain backups, and keep the service reliable.
Visibility and recipients
Other users see profile, request, activity, reputation, and location information only through the product rules and visibility settings. Exact match locations and private chats are limited to the relevant participants. Approved activity participants can see the activity's exact location and group chat. Public social links are visible as marked verified or unverified.
Hosting, database, backup, transactional-email, and map-tile providers process the minimum data needed to provide their component of the service. External social-profile and thank-you links are controlled by their own operators and policies.
Retention and deletion
The current exact tracking point is deleted when sharing stops, the match ends, or either participant blocks the other. Derived movement and proximity evidence may remain to protect reputation integrity and investigate abuse. Login tokens and rate-limit buckets expire or are pruned according to their operational windows.
Other account, content, communication, moderation, support, and legal records are kept while needed to provide the service, resolve disputes, prevent fraud, meet legal duties, or preserve the integrity of completed-help records. Backup copies may remain until the relevant backup expires. A deletion request does not erase records that must still be retained for those purposes.
Your controls
Account settings control profile, location visibility, direct messages, and connected Google sign-in. Live tracking is optional and can be stopped. You may submit a privacy or data-export request or an account-deletion request. Use the content-removal form for a specific item of illegal, infringing, or privacy-violating content.
Security, adults, and changes
The service uses access controls, hashed credentials and handover codes, encrypted HTTPS transport, restricted visibility, and audit records. No internet service can guarantee absolute security. Who Need Help is intended only for adults aged 18 or older.
This page will be updated when data practices materially change. The effective date above identifies the current version.
Contact
Contact the Who Need Help operator through the public support form. Select “Privacy request”, “Data export”, or “Account deletion” so the request reaches the appropriate queue.