Privacy Policy
Last updated: May 15, 2026
Controller and contact
ToldYeah! is operated by Arash Parsania, Munich, Germany. For privacy questions, account requests, or deletion requests, contact us at support@toldyeah.com.
What ToldYeah! is
ToldYeah! lets users create hidden predictions, send prediction requests, open predictions at the chosen time or earlier with credits, receive notifications, and settle prediction outcomes with other users.
Data we collect
We process account data such as email address and authentication identifiers, profile data such as username, avatar, language, rank and trust score, app content such as predictions, requests, subjects, messages, invite links, outcomes and votes, friend and counterparty relationships, notification records and push tokens, purchase and credit activity, and support requests, abuse reports, technical data such as device, app and security logs needed to operate the service.
Payment data
Credit packs are processed through Apple App Store, Google Play and RevenueCat. ToldYeah! stores credit balances, purchase events and product identifiers, but we do not receive or store full payment card details.
How we use data
We use data to provide accounts, predictions, requests, reveal timing, invite links, notifications, credits, purchases, profile features, support, abuse prevention, security, debugging, legal compliance and service reliability.
Legal basis
Where GDPR applies, we process data to perform our contract with you, based on our legitimate interests in operating and securing ToldYeah!, based on consent where required such as optional push notifications, and to comply with legal obligations.
Who can see content
Prediction and request content is shown according to the app rules. The sender, recipient, accepted invite user, or public-link viewer may see the relevant content when the product flow allows it. Public broadcast links can be opened by multiple people while the link is valid.
Public link moderation
Public broadcast links are less private than one-to-one predictions because they are designed for sharing. If a public link is reported or appears to create abuse, illegal content or safety risks, we may review the public-link record and remove it. Removed public links show only a neutral removal notice.
Administrator and support access
We design operational dashboards to use aggregate and account-level information where possible. Private prediction and request content is not intended to be routinely reviewed by administrators. Limited access to records may be used only where needed to operate the service, investigate abuse, fix technical issues, comply with legal obligations, protect users, or respond to a support request.
Support requests
When you send a support request, we process the message, selected category, priority and related account information to investigate and respond to that request. Do not include more personal information than needed to explain the issue.
Service providers
We use service providers to run the app, including Supabase for authentication, database and storage, Vercel for web hosting, Expo and native platform services for app delivery and push infrastructure, Apple and Google for app distribution and payments, RevenueCat for purchase handling, and Brevo or similar email providers for transactional emails. These providers process data only as needed to provide their services.
Push notifications
If you allow push notifications, we store a device push token and use it to send app alerts such as new predictions, requests, unlock reminders, outcome prompts and purchase or credit-related messages. You can disable push notifications in your device settings.
Retention and deletion
We keep data as long as needed to operate ToldYeah!, maintain credits and purchases, comply with legal obligations, resolve disputes, prevent abuse and maintain security. You can request account deletion in the app where available or by contacting us.
International processing
Our providers may process data in countries outside your country of residence. Where required, we rely on appropriate safeguards such as contractual protections offered by the relevant providers.
Children
ToldYeah! is not intended for children under 13. If we learn that a child has provided personal data without appropriate permission, we will take reasonable steps to delete it.
Your rights
Depending on your location, you may have rights to access, correct, delete, restrict or object to processing of your personal data, and to withdraw consent where processing is based on consent. Contact us at support@toldyeah.com to exercise these rights.
Changes
We may update this Privacy Policy when the product, providers or legal requirements change. The updated version will be posted on this page.