Privacy Policy

Last updated: May 16, 2026

Effective date: May 16, 2026

1. Introduction

Youneedto ("we", "us", "the App") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, how we protect it, and what rights you have over it.

Youneedto is a private recommendation-sharing app — not an advertising platform. We do not sell your data. We do not run ads. We collect only what we need to run the Service.

If you have questions, contact us at hello@youneedto.app.

2. Data We Collect

2.1 Account Data

When you create an account we collect:

  • Email address — used for authentication, notifications, and account recovery
  • Display name — shown to club members
  • Username — your unique public handle
  • Password — stored as a secure bcrypt hash, never in plain text
  • Profile avatar — optional image you upload

If you sign in via Google or Apple OAuth, we receive your email address and name from those providers. We do not receive or store OAuth tokens beyond what is required for authentication.

2.2 Content You Create

We store:

  • Recommendations you post (titles, notes, links, status)
  • Comments you write
  • Clubs you create or join
  • Invite tokens you generate
  • Notification preferences you set

2.3 Usage Data

We collect limited technical data to operate and improve the Service:

  • IP address (used for rate limiting — not stored long-term)
  • Browser type and OS (for error reporting via Sentry)
  • Pages visited and actions taken within the app (via Umami — anonymized, no cookies, no cross-site tracking)

2.4 Communications

If you contact us by email, we retain that correspondence to respond to your inquiry.

3. Data We Do NOT Collect

  • We do not track you across other websites
  • We do not build advertising profiles
  • We do not collect payment information (donations are handled by GitHub Sponsors or Ko-fi — see their respective privacy policies)
  • We do not record audio or video
  • We do not access your device contacts, camera, or microphone

4. How We Use Your Data

PurposeData UsedLegal Basis
Provide the Service (clubs, recommendations, feed)Account data, contentContract
Send transactional emails (verification, notifications)Email addressContract
Send weekly digest (if enabled)Email address, notification dataConsent
Detect and prevent abuseIP address, usage dataLegitimate interest
Fix bugs and improve the ServiceError logs (Sentry)Legitimate interest
Anonymized analyticsAggregated usage data (Umami)Legitimate interest

We never use your data for advertising or sell it to third parties.

5. Data Sharing

We share your data only with the services required to operate Youneedto:

ServicePurposeData Shared
SupabaseDatabase and authenticationAll stored data
VercelHosting and edge functionsRequest data
ResendTransactional email deliveryEmail address, name
UpstashRate limitingIP address (ephemeral)
SentryError trackingError logs, device info
UmamiAnonymous analyticsAnonymized page views
TMDBMovie and series metadata + streaming availabilitySearch queries, content identifiers
Google BooksBook metadataSearch queries

All services are bound by their own privacy policies and data processing agreements. We do not share your data with anyone else.

6. Data Retention

DataRetention Period
Account dataUntil you delete your account
RecommendationsIndefinitely (anonymized if you delete your account)
CommentsIndefinitely (anonymized if you delete your account)
Notifications90 days
Error logs (Sentry)30 days
Rate limit data (Upstash)Minutes to hours (ephemeral)
Email logs (Resend)30 days

7. Account Deletion and Data Export

7.1 Deletion

You may delete your account at any time from Settings → Account → Delete Account.

Upon requesting deletion:

  • A 24-hour grace period begins — you may cancel during this window
  • After the grace period, your account data is permanently deleted
  • Your recommendations and comments remain but are attributed to "Deleted user"
  • You will receive a goodbye email with a summary of your activity

7.2 Data Export

You may request an export of your personal data at any time by emailing hello@youneedto.app with the subject line "Data Export Request". We will send you a CSV file within 30 days containing your account data, recommendations, and comments.

8. Your Rights

Depending on your location, you may have the following rights:

  • Access — request a copy of your personal data
  • Rectification — correct inaccurate data (you can update most data directly in the app)
  • Erasure — request deletion of your data (account deletion handles this)
  • Portability — receive your data in a machine-readable format (data export)
  • Objection — object to processing based on legitimate interest
  • Restriction — request that we restrict processing of your data

To exercise any of these rights, contact us at hello@youneedto.app. We will respond within 30 days.

9. Cookies and Storage

Youneedto uses:

  • Session storage — to maintain your authentication session (Supabase Auth)
  • Local storage — to remember UI preferences (theme, language)

We do not use advertising cookies or third-party tracking cookies. Our analytics (Umami) are cookie-free.

10. Children's Privacy

Youneedto is not directed at children under 13. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under 13 without parental consent, we will delete it promptly.

If you believe we have collected data from a child under 13, contact us at hello@youneedto.app.

11. Security

We take the security of your data seriously:

  • Passwords are hashed using bcrypt — never stored in plain text
  • All data is transmitted over HTTPS
  • Database access is protected by Row Level Security (RLS) — users can only access data they are permitted to see
  • Profile images and club covers are stored in private Supabase Storage buckets — accessible only via signed URLs
  • We conduct security reviews on every code change via automated tooling

No system is 100% secure. If you discover a security vulnerability, please report it responsibly to hello@youneedto.app before disclosing it publicly.

12. International Data Transfers

Youneedto is hosted on infrastructure primarily located in the United States (Supabase, Vercel, Upstash). If you are accessing the Service from outside the United States — including from Mexico or the European Union — your data may be transferred to and processed in the United States.

By using the Service, you acknowledge this transfer. We take steps to ensure your data is handled in accordance with this Privacy Policy regardless of where it is processed.

13. Open Source and Transparency

Youneedto's source code is published under the MIT license at github.com/youneedto. This means anyone can inspect how we handle data at the code level. We believe transparency builds trust.

14. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or an in-app notification at least 14 days before the changes take effect.

The "Last updated" date at the top of this document reflects the most recent revision.

15. Contact

Email: hello@youneedto.app
GitHub: github.com/youneedto

For data protection inquiries specifically, use the subject line "Privacy Request" so we can route your message correctly.

Youneedto is a donation-supported open source project. We have no investors, no advertisers, and no incentive to misuse your data. Your trust is the foundation of this project.