Back to home
01 / Legal

Privacy Policy

Effective May 1, 2026

We built HeyArab as a small, careful place for the Arab diaspora to meet. We take the privacy of that space seriously. This policy explains, in plain English, what information we collect when you use HeyArab, why we collect it, who we share it with, and what you can do about it.

If anything below is unclear, email us at support@heyarab.app and we'll do our best to make it clearer.

01

Who we are

HeyArab (the "service", "we", "us", "our") is a culture-first dating service for the Arab diaspora. The service is offered through our mobile app, our website (heyarab.app), and the supporting back-end. The data controller is HeyArab. Full company details and registered address are listed at the end of this document.

02

What this policy covers

This policy covers personal information we collect through the HeyArab mobile app, the heyarab.app website, and any communication you have with us by email or other channels. It does not cover websites or services that link to HeyArab but that we don’t operate (for example, news articles or social media platforms that mention us).

03

Information we collect

We try to collect as little as possible while still running the service well. The categories below cover everything we currently collect.

Account information

  • Phone number (used as your primary identifier and for SMS one-time codes during sign-in).
  • Email address, if you choose to add one.
  • Display name.
  • Authentication tokens issued by AWS Cognito.

Profile information you provide

  • Date of birth (used to confirm you are 18 or older and to display your age).
  • Gender, religion and denomination, dialect, country of origin, current city, education level, relationship intent, and stance on children.
  • Photos you upload to your profile.
  • Voice intros you record (audio clips up to 30 seconds, attached to one of our prompts).
  • Prompt answers and any free-text fields you complete.
  • Filter preferences (age range, distance, religion, etc.) used by the discovery algorithm.

Photo verification (optional)

If you choose to verify your photos, we collect a short video selfie. We send it to AWS Rekognition, which checks that the face is a real person (“liveness”) and that it matches the photos on your profile. We store the verification result and a single reference image for moderator review; we don't sell or share the underlying biometric template.

Usage information

  • Likes, passes, matches, and messages.
  • Screens you visit and the order you visit them in (used to improve the onboarding flow and surface bugs).
  • Reports and blocks you submit.
  • Time you last opened the app, used to power the "last active" indicator and to retire long-inactive accounts.

Device information

  • Device type, operating system, app version, and language.
  • Push notification token (issued by Apple, Google, or OneSignal).
  • IP address, used for rate-limiting and to flag obviously coordinated abuse.

Location information

You tell us where you're based by searching for your city during onboarding. You can also tap “Use my location” to let the app read your device's location once, in the foreground, so we can find the nearest city for you. Either way, we resolve your location to a city and store that city along with its coordinates, which we use to show approximate distance to other members. We never access your location in the background and we don't continuously track your movements. If you'd rather not share device location at all, just type your city instead.

Subscription information

If you join HeyArab Club, our subscription tier, RevenueCat manages the subscription state on our behalf. RevenueCat receives a pseudonymous user ID and the subscription product you chose. Apple App Store and Google Play handle the payment itself. We never see your card number.

Diagnostic information

When the app crashes or hits an unexpected error, we send a stripped-down stack trace to Sentry to help us fix it. We try to scrub personal information out of those reports; if you'd rather not send them at all, you can disable error reporting in Settings.

04

How we use your information

We use the information above to:

  • Run the matching service and show you potential matches.
  • Deliver and store messages between you and your matches.
  • Verify photos when you ask us to.
  • Investigate reports, block harmful behavior, and keep the community safe.
  • Bill and manage HeyArab Club subscriptions.
  • Send you service notifications (new match, new message, account changes).
  • Improve the product. Understand which screens cause confusion, which features get used, where we lose people during onboarding.
  • Detect and prevent fraud, abuse, and security threats.
  • Comply with legal obligations.

We do not use your data to train machine-learning models for advertising. We do not run ads on HeyArab.

06

Who we share information with

We don't sell your personal information. We share information only with the service providers that make HeyArab work, listed below, and only what each of them needs to do their job.

  • Amazon Web Services (United States, EU): hosting, database, file storage, content delivery, authentication (Cognito), photo verification (Rekognition), and AI moderation features (Bedrock).
  • RevenueCat (United States): subscription management for HeyArab Club.
  • Apple Inc. and Google LLC: payment processing for in-app purchases on iOS and Android. They handle the actual transaction; we receive only the receipt.
  • Google LLC (United States): Google Maps Platform, used for city search and geocoding during onboarding. This is separate from Google Play, which processes Android in-app purchases. Google receives the location text you search for; we do not send Google your account identity.
  • Cloudflare, Inc. (United States): Turnstile, a bot- and abuse-prevention check run when someone submits a vouch. Cloudflare receives the submitter’s IP address and browser signals.
  • OneSignal (United States): push notification delivery.
  • PostHog (European Union for EEA users; United States for everyone else): product analytics.
  • Sentry (United States): crash reporting and error monitoring.
  • AWS Simple Notification Service (United States): SMS one-time codes for sign-in.

We may also disclose information when we believe in good faith that disclosure is necessary to comply with a lawful request, protect someone's safety, enforce our Terms of Service, or in connection with a corporate transaction (merger, acquisition, sale of assets). If a corporate transaction would change how your information is handled, we'll let you know first.

07

International transfers

HeyArab is operated from the United States, and most of our infrastructure runs in AWS regions in the U.S. (us-east-1) and the European Union (eu-west-1 for analytics that come from the EEA). When we transfer personal information from the EEA, the UK, or Switzerland to the United States, we rely on the European Commission's Standard Contractual Clauses, supplemented by AWS's transfer-impact safeguards. You can ask us for a copy of the relevant safeguards by emailing support@heyarab.app.

08

How long we keep your information

  • Active accounts: we keep your information while your account is active.
  • Deleted accounts: when you delete your account, we soft-delete immediately and remove the data permanently after 30 days, except where we have to keep some of it (see below).
  • Reports and moderation records: up to 5 years after they’re closed, so we can investigate repeat offenders and meet trust-and-safety obligations.
  • Audit logs of staff actions: at least 1 year, in a tamper-evident store.
  • Diagnostic information: 90 days.
  • Backups: rotated on a 35-day cycle, then permanently destroyed.
09

Your rights

No matter where you live, you can:

  • See what we hold about you.
  • Correct anything that’s wrong.
  • Delete your account (Settings → Delete account, or email support@heyarab.app).
  • Export your data in a structured, machine-readable format.

If you live in the EEA, the UK, or Switzerland (GDPR)

  • Access, correction, deletion, restriction, and objection rights.
  • Right to data portability.
  • Right not to be subject to a decision based solely on automated processing that significantly affects you (HeyArab does not currently make any such decisions).
  • Right to withdraw consent for any consent-based processing.
  • Right to lodge a complaint with your local data-protection authority. We’d appreciate the chance to address your concern first, so email support@heyarab.app.

If you live in California (CCPA / CPRA)

  • Right to know what categories of personal information we’ve collected and how we use them.
  • Right to delete personal information we hold about you.
  • Right to correct inaccurate personal information.
  • Right to opt out of "sale" or "sharing" of your personal information. We do neither, but the right exists.
  • Right to limit the use of sensitive personal information (race or religion you choose to share, biometric verification data) to what’s strictly necessary to provide the service.
  • Right not to be discriminated against for exercising these rights.

Other U.S. states (Virginia, Colorado, Connecticut, Utah, Texas, and others) give you broadly similar rights. If you live in one of those states and want to exercise them, the same email address works: support@heyarab.app.

How to exercise your rights

Email support@heyarab.app from the address associated with your account, or use the in-app Settings menu. We’ll respond within the time required by your local law (30 days under GDPR; 45 days under CCPA, with a possible 45-day extension). If we need to verify your identity first, so that no one else can impersonate you, we’ll tell you what we need.

10

Children

HeyArab is strictly for adults. You must be 18 or older to use the service. If we discover an underage account, we'll terminate it immediately and delete the associated data. If you believe a child is using HeyArab, email us at support@heyarab.app and we’ll act fast.

11

How we protect your information

  • All data in transit is encrypted with TLS 1.2 or higher.
  • Photos, voice intros, and database backups are encrypted at rest using AWS-managed keys.
  • Access to production systems is limited to a small team, requires single-sign-on with multi-factor authentication, and is logged.
  • We run automated security checks on our dependencies and apply security patches on a regular cadence.

No system is perfectly secure. If you become aware of a vulnerability, please email support@heyarab.app and we'll respond promptly.

12

Cookies and similar technologies

Our website uses a small number of first-party cookies to remember your language preference and to keep you signed in. We do not run third-party advertising or tracking cookies. The mobile app does not use cookies.

13

Changes to this policy

We'll update this policy as the service evolves or the law changes. Material changes are flagged at the top of the policy with a new effective date, and we’ll send you a notice through the app or by email at least 14 days before they take effect. Continued use after the change means you accept the updated policy.

14

How to contact us

For privacy questions, requests, or concerns: support@heyarab.app.

For trust-and-safety issues: support@heyarab.app.

For everything else: support@heyarab.app.

Questions? support@heyarab.app