Русский · English
Privacy Policy
You&Me · Revision 1 · Last updated: August 25, 2026
You&Me is a private space for two people: shared plans, documents, wishes and loyalty cards. This policy explains what the app stores, where it is kept, who can see it, and how you can remove it.
The app is developed and operated by Dmitry Keller (the "developer", "we"). For any question about this policy or about your data, write to kellerdimka@gmail.com.
- We do not sell your data and we never show ads.
- There are no analytics, crash-reporting or advertising SDKs in the app.
- Your content is visible only to you and to the one partner you choose to link with.
- You can delete your account and your data from inside the app at any time.
1. What we collect
Account information
Signing in is possible only through Sign in with Apple. From it we receive a user identifier and an email address — which will be Apple's private relay address if you chose to hide your real one. We store an account identifier generated by Firebase Authentication. There are no passwords: we never see or store one.
Your profile
A display name and a date of birth, if you enter them. The date of birth is used only to show the birthday inside your shared space and to remind your partner in advance.
Content you create
Everything you put into the app is stored so that it syncs between your devices and your partner's:
- wishes, including product links, prices and images you attach;
- plans, trips, tasks and polls;
- shared calendar events and important dates;
- time capsules — letters that stay sealed until a date you set;
- loyalty cards, including card numbers and barcodes;
- files you upload or scan, and their contents.
The app does not ask you to upload identity documents, banking details or other confidential material, and does not recommend doing so. What you put into your shared space is your decision; access to uploaded files is restricted to the members of your space by server-side rules.
Device permissions
- Camera — to scan pages and to read the barcodes of loyalty cards. Captured images are saved into your own space; nothing is sent anywhere else.
- Calendar — to import events from your device calendar and to export shared events back into it. This happens on your device and only when you ask for it.
- Face ID / Touch ID — to lock the section with your files. Biometric matching is performed entirely by iOS; the app receives only a yes-or-no answer and never gains access to your biometric data.
- Photo library — pictures you pick are passed to the app by the system picker. The app is not granted access to the rest of your library.
Links you paste
When you add a product link to a wish, the app opens that page in the background to read its title, price and picture. That request goes directly from your device to the website you pasted, and it is subject to that website's own privacy practices. We do not log the links you open, beyond storing the wish itself in your space.
What we do not collect
The app contains no analytics, no crash-reporting, no advertising and no third-party tracking SDKs. It does not use the Advertising Identifier (IDFA) and does not ask for tracking permission. It does not send push notifications, and it does not collect your location.
2. Where the data is stored
Data is stored using Google Firebase — Firebase Authentication, Cloud Firestore and Cloud Storage — running on Google's cloud infrastructure. Google processes this data on our behalf as an infrastructure provider; see the Firebase Privacy and Security policy.
The Google servers running the project are located outside the Russian Federation. What that means for users in Russia is explained in section 10.
Copies of your files are also kept in the app's private folder on your device, so that you can open them without an internet connection. That folder is not accessible to other apps and is included in your device's protection.
3. Who can see your data
Your content is readable only by the members of your space: you, and the one partner you link with using an invitation code. This is enforced on the server by security rules that check membership on every read and write — it is not merely hidden in the interface.
To be straightforward with you: as the operator of the Firebase project, the developer holds technical administrative access to the database. It is used only where strictly necessary — to investigate a fault or to comply with a legal obligation — and never to browse user content out of curiosity.
We do not share your data with any other third party. We do not sell it, rent it, or use it for advertising.
4. Legal basis and purpose
We process your data solely to provide the features you use: keeping your content in sync between your devices and your partner's, and keeping it available offline. Where the GDPR applies, the legal basis is the performance of a contract with you (Art. 6(1)(b)) — the service you asked for cannot exist without storing what you put into it. For users in Russia the legal basis is your consent — see section 10.
5. Retention and deletion
Your data is kept for as long as your account exists. You can delete your account from inside the app: Us → Couple settings → Delete account. See the account deletion page for the details of what is removed.
In short: if you are alone in your space, everything is erased. If you are linked with a partner, your profile and your membership are removed while the shared archive stays with your partner, because it belongs to both of you. In both cases, the local copies of files on your device are erased.
Deleted data is removed from the live database immediately. Residual copies may persist in the infrastructure provider's backups for a limited period before being overwritten.
6. Your rights
You may request access to your data, ask for it to be corrected, or ask for it to be erased. The fastest route to erasure is the in-app deletion described above. For anything else, write to kellerdimka@gmail.com and we will respond as soon as we can. If you are in the EEA or the UK, you also have the right to lodge a complaint with your local data protection authority.
7. Children
You&Me is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, write to us and we will remove it.
8. Changes to this policy
If this policy changes, the new version will be published on this page with an updated revision number and date at the top. Material changes will also be announced inside the app, and you will be asked to confirm your consent again.
9. Contact
Dmitry Keller
kellerdimka@gmail.com
10. Processing of personal data under Russian law (152-FZ)
This section applies to users in the Russian Federation and is written in the terms of Federal Law No. 152-FZ of 27 July 2006 "On Personal Data". The authoritative version of this section, together with the consent text, is the Russian one.
Operator
Dmitry Keller (Келлер Дмитрий Алексеевич)
Tax number (ИНН) 661401740383
Address: ул. Крауля, д. 77, г. Екатеринбург, Россия
Email: kellerdimka@gmail.com
Personal data processed
- Apple ID identifier and email address (possibly Apple's private relay address), and the account identifier issued by Firebase Authentication;
- the display name you set and your date of birth, if you entered it;
- the content you create: wishes, plans, trips, tasks, polls, calendar events, important dates, time capsules and loyalty cards;
- the files you upload and their contents.
The app processes no biometric data and no special categories of personal data. Face ID matching is performed by iOS; the app receives only the result.
Purposes
- providing the features you use: storing your records and syncing them between your devices and those of the partner you linked with;
- keeping your records available offline;
- answering your support requests.
Operations performed
Collection, recording, systematisation, accumulation, storage, updating, retrieval, use, transfer (granting access to the partner you linked with, and cross-border transfer), blocking, deletion and destruction. Processing is both automated and non-automated.
Legal basis
Your consent (Art. 6(1)(1) of 152-FZ), given when you sign in to the app, and performance of the contract to which you are a party (Art. 6(1)(5)). The consent text is on a separate page.
Cross-border transfer
Data is stored and processed on Google servers (Google LLC, Google Ireland Limited) outside the Russian Federation. By using the app you consent to this cross-border transfer; it is stated explicitly in the consent text.
Retention and withdrawal of consent
Data is processed for as long as your account exists, or until you withdraw your consent. You can withdraw it by deleting your account in the app (Us → Couple settings → Delete account) or by writing to kellerdimka@gmail.com. Withdrawal stops the processing and deletes your data as described in section 5.