Privacy Policy
Last updated: May 16, 2026
Effective date: May 16, 2026
1. Introduction
Youneedto ("we", "us", "the App") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, how we protect it, and what rights you have over it.
Youneedto is a private recommendation-sharing app — not an advertising platform. We do not sell your data. We do not run ads. We collect only what we need to run the Service.
If you have questions, contact us at hello@youneedto.app.
2. Data We Collect
2.1 Account Data
When you create an account we collect:
- Email address — used for authentication, notifications, and account recovery
- Display name — shown to club members
- Username — your unique public handle
- Password — stored as a secure bcrypt hash, never in plain text
- Profile avatar — optional image you upload
If you sign in via Google or Apple OAuth, we receive your email address and name from those providers. We do not receive or store OAuth tokens beyond what is required for authentication.
2.2 Content You Create
We store:
- Recommendations you post (titles, notes, links, status)
- Comments you write
- Clubs you create or join
- Invite tokens you generate
- Notification preferences you set
2.3 Usage Data
We collect limited technical data to operate and improve the Service:
- IP address (used for rate limiting — not stored long-term)
- Browser type and OS (for error reporting via Sentry)
- Pages visited and actions taken within the app (via Umami — anonymized, no cookies, no cross-site tracking)
2.4 Communications
If you contact us by email, we retain that correspondence to respond to your inquiry.
3. Data We Do NOT Collect
- We do not track you across other websites
- We do not build advertising profiles
- We do not collect payment information (donations are handled by GitHub Sponsors or Ko-fi — see their respective privacy policies)
- We do not record audio or video
- We do not access your device contacts, camera, or microphone
4. How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Provide the Service (clubs, recommendations, feed) | Account data, content | Contract |
| Send transactional emails (verification, notifications) | Email address | Contract |
| Send weekly digest (if enabled) | Email address, notification data | Consent |
| Detect and prevent abuse | IP address, usage data | Legitimate interest |
| Fix bugs and improve the Service | Error logs (Sentry) | Legitimate interest |
| Anonymized analytics | Aggregated usage data (Umami) | Legitimate interest |
We never use your data for advertising or sell it to third parties.
5. Data Sharing
We share your data only with the services required to operate Youneedto:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database and authentication | All stored data |
| Vercel | Hosting and edge functions | Request data |
| Resend | Transactional email delivery | Email address, name |
| Upstash | Rate limiting | IP address (ephemeral) |
| Sentry | Error tracking | Error logs, device info |
| Umami | Anonymous analytics | Anonymized page views |
| TMDB | Movie and series metadata + streaming availability | Search queries, content identifiers |
| Google Books | Book metadata | Search queries |
All services are bound by their own privacy policies and data processing agreements. We do not share your data with anyone else.
6. Data Retention
| Data | Retention Period |
|---|---|
| Account data | Until you delete your account |
| Recommendations | Indefinitely (anonymized if you delete your account) |
| Comments | Indefinitely (anonymized if you delete your account) |
| Notifications | 90 days |
| Error logs (Sentry) | 30 days |
| Rate limit data (Upstash) | Minutes to hours (ephemeral) |
| Email logs (Resend) | 30 days |
7. Account Deletion and Data Export
7.1 Deletion
You may delete your account at any time from Settings → Account → Delete Account.
Upon requesting deletion:
- A 24-hour grace period begins — you may cancel during this window
- After the grace period, your account data is permanently deleted
- Your recommendations and comments remain but are attributed to "Deleted user"
- You will receive a goodbye email with a summary of your activity
7.2 Data Export
You may request an export of your personal data at any time by emailing hello@youneedto.app with the subject line "Data Export Request". We will send you a CSV file within 30 days containing your account data, recommendations, and comments.
8. Your Rights
Depending on your location, you may have the following rights:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data (you can update most data directly in the app)
- Erasure — request deletion of your data (account deletion handles this)
- Portability — receive your data in a machine-readable format (data export)
- Objection — object to processing based on legitimate interest
- Restriction — request that we restrict processing of your data
To exercise any of these rights, contact us at hello@youneedto.app. We will respond within 30 days.
9. Cookies and Storage
Youneedto uses:
- Session storage — to maintain your authentication session (Supabase Auth)
- Local storage — to remember UI preferences (theme, language)
We do not use advertising cookies or third-party tracking cookies. Our analytics (Umami) are cookie-free.
10. Children's Privacy
Youneedto is not directed at children under 13. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under 13 without parental consent, we will delete it promptly.
If you believe we have collected data from a child under 13, contact us at hello@youneedto.app.
11. Security
We take the security of your data seriously:
- Passwords are hashed using bcrypt — never stored in plain text
- All data is transmitted over HTTPS
- Database access is protected by Row Level Security (RLS) — users can only access data they are permitted to see
- Profile images and club covers are stored in private Supabase Storage buckets — accessible only via signed URLs
- We conduct security reviews on every code change via automated tooling
No system is 100% secure. If you discover a security vulnerability, please report it responsibly to hello@youneedto.app before disclosing it publicly.
12. International Data Transfers
Youneedto is hosted on infrastructure primarily located in the United States (Supabase, Vercel, Upstash). If you are accessing the Service from outside the United States — including from Mexico or the European Union — your data may be transferred to and processed in the United States.
By using the Service, you acknowledge this transfer. We take steps to ensure your data is handled in accordance with this Privacy Policy regardless of where it is processed.
13. Open Source and Transparency
Youneedto's source code is published under the MIT license at github.com/youneedto. This means anyone can inspect how we handle data at the code level. We believe transparency builds trust.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or an in-app notification at least 14 days before the changes take effect.
The "Last updated" date at the top of this document reflects the most recent revision.
15. Contact
Email: hello@youneedto.app
GitHub: github.com/youneedto
For data protection inquiries specifically, use the subject line "Privacy Request" so we can route your message correctly.
Youneedto is a donation-supported open source project. We have no investors, no advertisers, and no incentive to misuse your data. Your trust is the foundation of this project.