Privacy Policy
Herae is an intimate product — it's where you keep movie nights, voice and video calls, and the little memories you make with the people closest to you. This policy explains, in plain language, exactly what we collect, what we deliberately don't, and why. It is written for how Herae actually works, not from a template.
The short version. Your voice and video calls are peer-to-peer and are never recorded or stored by us. Your saved Moments are private by default. We use our own first-party analytics rather than shipping your behavior to third-party ad or tracking companies. We never sell your data.
1. Who we are
Herae ("Herae", "we", "us") provides a browser extension that lets people watch video together in sync with built-in voice, video, and chat, and a companion website (Herae Moments) where the memories from those sessions live. This policy covers both. If you have questions, contact privacy@herae.app.
2. What we collect
Account information
- Username — chosen by you, lowercase letters, numbers and underscores.
- Email address — used for sign-in, account recovery, and transactional email (verification and password reset).
- Password — if you sign up with a password, we store only a salted bcrypt hash, never the password itself. If you sign in with Google, we never receive or store a password.
- Google sign-in — if you choose "Continue with Google", we receive your verified email address from Google to create or locate your account. We do not receive your Google password.
Content you create
- Moments — the photo collages and short video clips (up to 45 seconds) you choose to save from a session, together with a poster image, an optional caption, the theme you picked, and your chosen privacy level (private, contacts-only, or public).
- Reviews, ratings, session titles, likes and comments you write.
- Profile picture and contacts (the people you connect with by username).
- Session context — for a session you save something from, we store the title, page URL, and thumbnail of what was watched so the memory has context. Only sessions you deliberately save from generate this.
Technical information
- Authentication tokens (a signed JWT) kept in your browser's local storage so you stay logged in.
- Presence — whether you're currently online, so contacts can see availability. This is transient and not logged historically.
- Limited request metadata — IP address and standard request data are processed transiently for security and rate-limiting. We do not build advertising profiles from it.
- Error diagnostics — if something crashes, technical error details may be sent to our error-monitoring provider (Sentry) to help us fix it.
3. What we deliberately do NOT collect
- Your calls. Voice, video, and chat during a session are peer-to-peer (WebRTC), encrypted in transit, and travel directly between participants. We do not record, store, or have access to their contents. When a direct connection can't be established, media may be relayed through a TURN server to keep the call working — but it is still end-to-end encrypted and is never stored.
- Your general browsing. The extension only acts on the tab where you're actively watching together, to keep playback in sync. It is not a history tracker and does not report the pages you visit on your own.
- Third-party ad/tracking cookies. We don't run them. See our Cookie Policy.
- Payment card details. Herae is free to start; we don't process card data on our own servers.
4. How we use your information
- To provide the core service: authenticating you, syncing playback, connecting calls, and storing the Moments you choose to save.
- To send transactional email you'd expect (email verification, password reset).
- To keep the service secure and reliable (rate-limiting, abuse prevention, crash diagnostics).
- To understand product health with first-party analytics: we record a small set of events in our own database — such as account creation, login, sending/accepting a contact invite, capturing a Moment, and posting a review — to measure activation and retention for a beta. This data stays in our database and is not sent to a third-party behavioral analytics vendor.
5. Visibility & sharing between users
You control how each Moment is shared with other Herae users through its privacy level:
- Private (default) — only the people who were in that Moment.
- Contacts — also visible to your accepted contacts.
- Public — visible to any signed-in Herae user and reachable by its link.
Public profiles show your username, picture, and counts of content that is actually visible to the viewer under these rules. If you use the Share feature to post to another platform (Instagram, WhatsApp, etc.), that content leaves Herae and becomes subject to that platform's own terms and privacy policy.
6. Service providers we rely on
We use a small number of trusted third-party providers strictly to run Herae — for example to host the service and store data, deliver verification and password-reset emails, help peer-to-peer calls connect, and monitor errors. These providers process data on our behalf under their own security commitments. We do not sell your personal data to anyone.
7. Data retention
We keep your account and content until you delete them or delete your account. When you delete a Moment, its record and stored media files are removed. When you delete your account, we permanently delete or irreversibly anonymize your data as described in our Account Deletion Policy. One-time email tokens expire automatically (24 hours for verification, 1 hour for password reset) and are single-use.
8. Security
- Passwords and email tokens are stored only as strong, industry-standard one-way hashes — never in plain text.
- Traffic is served over HTTPS, and data is encrypted in transit.
- We apply security headers, a strict cross-origin allowlist, and rate limits on sensitive endpoints.
- You can invalidate every existing login for your account at any time by resetting your password.
No system is perfectly secure, but we design Herae to minimize what could ever be exposed.
9. Your rights & choices
- Access & correction — you can view and edit your profile, Moments, reviews, and comments in the app.
- Deletion — you can permanently delete your account (see the Account Deletion Policy) or request help at privacy@herae.app.
- Content takedown — see our Content Removal Policy and DMCA Policy.
- Depending on where you live (e.g. the EEA/UK or California), you may have additional rights to access, port, or restrict processing of your data. Email us and we'll help.
10. Children
Herae is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect their data. If you believe a child has created an account, contact privacy@herae.app and we'll remove it.
11. International users
Herae is operated using infrastructure that may process and store data in different countries. By using Herae you understand your information may be handled in locations outside your own, always under the protections described here.
12. Changes to this policy
We may update this policy as Herae evolves. When we make material changes, we'll update the "Last updated" date above and, where appropriate, notify you in the app or by email.
13. Contact
Privacy questions: privacy@herae.app · General: support@herae.app · Legal: legal@herae.app. See the Contact page.