WhoAgain?Home

Privacy Policy

Effective date: June 12, 2026

This Privacy Policy explains how Silv LLC, a Florida limited liability company ("Silv," "WhoAgain," "we," or "us"), collects, uses, discloses, and protects personal data in connection with the WhoAgain web application and related services (the "Service"). It is part of, and incorporated into, our Terms of Service.

A note about information you record about other people. A core function of WhoAgain is letting you record information about other individuals (for example, a person you met, their car, where you met, notes, and social handles). When you do this, you decide what to record and why, and you act as the party responsible for that information (for example, the "controller"), while we process it on your behalf and at your direction (for example, as a "processor" or "service provider"). See Section 6. You are responsible for having any rights, consents, and lawful bases the law requires before you record information about another person.

1. Who We Are and How to Contact Us

Data controller / business (for data we control):Silv LLC (operator of WhoAgain). For privacy questions, requests, or complaints, contact us by email at legal@whoagain.app.

We have not appointed a Data Protection Officer, as one is not required for a service of this size; you can reach our privacy contact at legal@whoagain.app for any privacy matter. We have not appointed an EU/EEA representative under Article 27 GDPR or a UK representative; the Service does not target the EU/EEA or the UK at launch, and we will appoint such a representative only if and when the Service actively targets those regions.

2. Scope and Our Role (Controller vs. Processor)

This Policy applies to personal data we process through the Service, including the personal CRM (B2C) side available worldwide and the Events platform (B2B) side (organizer features available only in Florida, USA at launch). Our role depends on the data:

  • We are the controller / business for personal data we collect to provide and operate the Service to you — your account and identity data, authentication data, payment-related metadata, your public profile, usage and device data, communications with us, and (for organizers and attendees) event-account data we use for our own operational purposes.
  • We are a processor / service provider for the personal data you record about other people in your private records, and for personal data an organizer collects from attendees through the Service. In those cases, you (or the organizer) are the controller, and we process the data on your behalf and at your direction. See Section 6.

3. Categories of Personal Data We Collect

We collect the following categories, depending on how you use the Service:

  • Account and identity data — name or display name, email, password (stored hashed/secured by our authentication provider), settings, and profile information.
  • Authentication data — credentials and identifiers used to sign you in, including via email/password, Google sign-in (limited profile information from Google, such as name, email, and account identifier), and, for attendees, a phone number verified by SMS one-time passcode, plus related metadata such as sign-in timestamps and tokens.
  • Your private records about other people ("Your Content") — names, photographs, notes, tags, and custom attributes you record about other individuals, which may include a person's car, where you met them, social handles, and free-text notes. This may include personal data about people who are not users of the Service. See Section 6, including our caution against recording sensitive or "special category" data.
  • Public profile and social links — if you create an opt-in public profile / "social links" card (at /u/{handle}), the handle, name, photo, links, and other information you choose to publish, which are publicly accessible.
  • Event and attendee data (B2B) — for organizers: event details, ticket types, pricing, segments, messages, and roster data; for attendees: the phone number used to join, RSVP and headcount responses, check-in status and timestamps, ticket reservations (including where one account reserves multiple tickets), and event communications.
  • Payment data (via Stripe) — we do not collect or store full payment-card numbers. We receive limited payment metadata from Stripe (e.g., transaction/customer identifier, payment status, amount and currency, last four digits and card brand, and billing details for receipts, refunds, fraud prevention, and accounting), and, for organizers, connected-account identifiers and payout status. Your payment data is also processed by Stripe under its own policy.
  • SMS and messaging metadata — phone numbers, message content for messages sent through the Service, delivery status, timestamps, opt-in/opt-out status (including STOP/HELP), and related metadata. SMS delivery is performed by AWS SNS.
  • Usage, telemetry, and analytics data — how you interact with the Service, such as features used, pages viewed, actions taken (for example, an "app open" event), and aggregate performance metrics.
  • Device and log data — IP address, browser type, operating system and device type, language, approximate location inferred from IP, request times, and error/crash logs.
  • Cookies and similar technologies — used to operate the Service, remember preferences (for example, your light/dark theme), keep you signed in, and, where permitted, measure usage. See Section 14.
  • Embeddings and derived data — to provide search and AI features, we generate vector embeddings and other derived representations of Your Content (planned via the Google Gemini API).
  • Communications and support data — information you provide when you contact us, including the content of your messages and your contact details.

We do not intentionally collect government identifiers, precise geolocation, or "special category"/"sensitive" personal data for our own purposes. If you record such data about other people, you do so as the controller and at your own risk (Section 6).

4. How We Use Personal Data

  • Provide and operate the Service — create and manage your account; authenticate you; store and display your private records; generate embeddings and provide search (including semantic/AI search); create and manage public profiles; enable event creation, joining, RSVPs, headcounts, check-ins, ticketing, and messaging.
  • Process payments — facilitate ticket purchases and Subscriptions, payouts to organizers (via Stripe Connect), receipts, refunds, and our platform fee, through Stripe.
  • Communications — send transactional and service messages (including SMS one-time passcodes, RSVP/check-in confirmations, event updates, organizer broadcasts, and account/security notices), respond to inquiries, and, where permitted, send marketing you can opt out of.
  • Personalize and improve — understand usage, debug and fix problems, develop features, and improve performance and reliability.
  • Safety, security, and fraud prevention — protect the Service, users, and the public; detect and respond to fraud, abuse, and security incidents; enforce our agreements.
  • Legal and compliance — comply with law and lawful requests; establish, exercise, or defend legal claims; maintain financial and tax records.
  • Business operations — accounting, audits, and (subject to Section 7) business transfers.
  • On behalf of controllers — where we act as a processor/service provider, we use the data only to provide the Service as instructed by you or the organizer.

AI/ML use. We use Your Content to generate embeddings and provide search and AI-assisted features. We do not use the content of your private records to train generally-available AI models for third parties, and we endeavor to use providers and configurations that do not use customer data submitted via their APIs to train the providers' general models. AI features are probabilistic and may be inaccurate; do not rely on them as a sole source of truth.

5. Legal Bases for Processing (GDPR/UK GDPR)

Where the GDPR or UK GDPR applies, we process personal data under Article 6(1) on these bases:

  • Performance of a contract (Art. 6(1)(b)) — to provide the Service, manage your account, process transactions, and respond to requests.
  • Legitimate interests (Art. 6(1)(f)) — to operate, secure, and improve the Service, prevent fraud and abuse, understand usage, communicate with you, and protect our rights, where not overridden by your rights. You may object (Section 12).
  • Consent (Art. 6(1)(a)) — where we ask for it (for example, certain marketing, non-essential cookies/analytics). You may withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)) — to comply with laws (for example, tax and accounting).
  • Vital/public interest (Art. 6(1)(d)/(e)) — in rare cases, as permitted by law.

Where we act as a processor for data you or an organizer control, the controller is responsible for the legal basis, and we process on the controller's documented instructions. Special category data (Art. 9) requires an additional condition (such as explicit consent); we ask that you do not record such data, and if you do, you are responsible for ensuring a valid condition exists.

6. Information You Record About Other People

WhoAgain is designed to help you remember people you meet, which means you may record personal data about other individuals, including non-users.

Your responsibilities as the controller. When you record information about another person: you are the controller of that information and decide what to record and why, and we act as your processor/service provider, handling it on your behalf solely to provide the Service; you must have all rights, consents, and lawful bases required by law to record, store, process, and share that information and to instruct us to process it; and you must comply with applicable law, including providing any required privacy notice to, and honoring any rights of, the individuals concerned.

Caution against sensitive / "special category" data. Please do not record information that is sensitive or constitutes "special category" data under applicable law (for example, data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic or biometric data, or data concerning health, sex life, or sexual orientation), or government identifiers, financial-account numbers, or precise geolocation, unless you have a valid legal basis and any heightened consent the law requires. We do not request such data and recommend you do not store it. You record such data at your own risk and remain solely responsible for it.

Requests from individuals you have recorded. If an individual whose data you have recorded contacts us to exercise rights (for example, access, correction, or deletion), because we act as the processor and do not control the purposes, we will generally refer the individual to you and/or notify you, and you must respond and act as required by law. We may also take steps we consider appropriate or legally required, including providing the individual with information identifying you as the controller, and assisting you in responding. Aside from providing the Service (hosting, storing, indexing, generating embeddings, securing, and backing up the data) and complying with law, we do not use the personal data in your private records for our own independent purposes.

7. How We Share Personal Data; Subprocessors

We share personal data only as described below. We do not sell personal data (Section 8).

  • Service providers / subprocessors — trusted third parties that provide the Service on our behalf under contracts requiring them to protect personal data and use it only to provide their services. Our key subprocessors are listed in Section 20 and include Google Firebase / Google Cloud, the Google Gemini API (planned), Amazon Web Services (AWS SNS), and Stripe.
  • Payments — payment and payout data is shared with Stripe (and, for organizers, processed through their Stripe connected accounts via Stripe Connect). Stripe acts as a separate controller for certain payment data.
  • Between users, as you direct — for example, your public profile is visible to anyone with the link; when someone scans your QR card, they may save a contact record about you; and organizers can see attendee/roster data, RSVPs, check-ins, and messages for their events, while attendees receive organizer communications.
  • Legal and safety — to comply with law, enforce our Terms, prevent fraud or security issues, or protect the rights, property, or safety of WhoAgain, our users, or the public.
  • Business transfers — in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to this Policy or a successor policy.
  • With your consent, or as you otherwise direct.
  • Aggregated/de-identified data — which cannot reasonably identify you and which we will not attempt to re-identify except as permitted by law.

8. We Do Not Sell Your Personal Data

WhoAgain does not sell your personal data, and does not "share" it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA and similar U.S. state laws. We have not sold or shared personal data (including the personal data of individuals you record, and including minors) in the preceding 12 months. We do not knowingly sell or share the personal data of consumers under 16 years of age.

9. International Data Transfers

WhoAgain is operated from the United States, and our subprocessors (including Google Firebase/Google Cloud, the Google Gemini API, AWS SNS, and Stripe) host and process data in the United States and may process it in other countries where they operate. If you access the Service from outside the United States, your personal data will be transferred to, stored in, and processed in the United States and potentially other countries.

Safeguards for EEA/UK/Switzerland transfers. Where we transfer personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards as required by law, such as the European Commission's Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum/IDTA for UK transfers), or other lawful mechanisms. You may request more information at legal@whoagain.app.

10. Data Retention

We retain personal data for as long as necessary to fulfill the purposes in this Policy, unless a longer or shorter period is required or permitted by law, considering the data's sensitivity, the purposes, the risk of harm, and legal, accounting, tax, and reporting requirements. General guidelines:

  • Account and profile data — while your account is active, and a reasonable period afterward to comply with law, resolve disputes, and enforce agreements.
  • Your private records (Your Content) — while you keep them in the Service; deleted records are removed from active systems and purged from backups within a reasonable period, subject to legal holds.
  • Event and attendee data — for the duration of the event relationship and a reasonable period afterward; organizers determine retention for data they control, subject to our defaults.
  • Payment/transaction records — as required for accounting, tax, audit, and anti-fraud purposes (often several years). Full card numbers are not retained by us.
  • SMS/messaging metadata — as needed to provide messaging, demonstrate consent and opt-outs (including STOP/HELP records), and comply with law.
  • Logs, telemetry, and analytics — for a limited period for security, debugging, and analytics, then deleted or aggregated/de-identified.

Self-service deletion. You can delete your account and associated data at any time from Settings → Privacy & data → Delete account (Section 12.4). When you do, we delete the data described there from our active systems promptly (typically immediately), cancel any active Subscription, and purge residual backup copies within a reasonable period — except for the limited records we are permitted or required to retain, such as tax, accounting, and fraud-prevention records, and information others have already copied.

11. Security

We implement technical and organizational measures designed to protect personal data, including reliance on reputable infrastructure providers (Google Cloud/Firebase, AWS, Stripe), access controls and authentication, per-user access rules at the database and storage layers, encryption in transit and (where provided by our infrastructure) at rest, and use of a PCI-DSS-compliant payment processor (Stripe) so we do not handle full card numbers. No method is perfectly secure, and we cannot guarantee absolute security; you are responsible for keeping your credentials and devices secure. If we become aware of a personal-data breach that affects you, we will notify you and the relevant authorities as required by law.

12. Your Privacy Rights

Depending on where you live and applicable law, you may have some or all of the rights below. The fastest way to exercise the core rights is with the self-service controls in the app (Section 12.4), which let you download a copy of your data and permanently delete your account; you may also contact legal@whoagain.app. We will respond within the timeframe required by law, may need to verify your identity, and (where you act as a controller, e.g., regarding data about others) may direct certain requests to you. You will not be discriminated against for exercising your rights.

12.1 Rights under the GDPR / UK GDPR (EEA, UK, and similar)

  • Access — confirmation of whether we process your personal data and a copy of it.
  • Rectification — correction of inaccurate or incomplete data.
  • Erasure ("right to be forgotten") — deletion in certain circumstances.
  • Restriction — restricting processing in certain circumstances.
  • Data portability — receiving certain data in a portable format and, where feasible, having it transmitted to another controller.
  • Object — objecting to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — where processing is based on consent, at any time (without affecting prior processing).
  • Lodge a complaint with your local supervisory authority (Section 19).

Where we act as a processor for data you or an organizer control, please direct rights requests to the relevant controller; we will assist the controller as required.

12.2 Rights under the California CCPA/CPRA (California residents)

  • Know / Access — the categories and specific pieces of personal information we collected, the sources, the purposes, and the categories of third parties with whom we disclose it.
  • Delete — deletion of personal information we collected from you.
  • Correct — correction of inaccurate personal information.
  • Opt out of sale/sharing — we do not sell or share personal information (Section 8), so there is nothing to opt out of; we honor opt-out preference signals (such as Global Privacy Control) where applicable.
  • Limit use of sensitive personal information — we do not use sensitive personal information for purposes that would trigger this right.
  • Non-discrimination — you will not be discriminated against for exercising your rights.

Submit a request via legal@whoagain.app. You may use an authorized agent, subject to verification. California "Shine the Light": we do not disclose personal information to third parties for their own direct-marketing purposes.

12.3 Other U.S. state rights

Residents of other U.S. states with comprehensive privacy laws (for example, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others) may have rights similar to those above, including to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and certain profiling. We do not sell personal data or use it for targeted advertising. To exercise these rights, contact legal@whoagain.app; where a state provides an appeal process for denied requests, you may appeal by contacting us, and if denied, contact your state attorney general.

12.4 Self-service controls in the app (data export & account deletion)

You don't have to wait for us to act manually — WhoAgain provides self-service privacy controls in Settings → Privacy & data:

  • Download my data (access & portability). Generates a machine-readable JSON export of the personal data associated with your account — your account and profile information, your private records about other people ("Your Content"), your public profile/card, the events you organize and their guest lists, the events you've joined, the messages you've sent, and your subscription status. To protect our systems and other people, it excludes internal or derived operational data that isn't meaningfully your personal data — for example, machine-learning embeddings, internal payment-processor identifiers (we show your plan, status, and renewal date, not Stripe customer or subscription identifiers), and raw security/analytics logs.
  • Delete account (erasure / right to delete). Lets you permanently and immediately delete your account and the associated personal data yourself. After you re-authenticate and type a confirmation, we delete your account and profile, your private records and uploaded photos, your public profile/card, and your event memberships; cancel any active paid Subscription; and — because an organizer controls their own events — delete the events you created along with their guest lists, check-ins, and messages. The confirmation screen names upcoming events that will be removed before you proceed. This action cannot be undone.

What deletion does not remove. Consistent with Section 10, a limited set of data may survive deletion where the law permits or requires it: records we must keep for legal, tax, accounting, or fraud-prevention purposes (for example, transaction records retained by us or by Stripe); information other people have already copied or saved (for example, public-profile information another user saved as their own contact record, which they — not we — control); and residual copies in routine backups, which are isolated and purged within a reasonable period. Deleting your account does not, by itself, entitle you to a refund (see the Terms of Service).

13. SMS, Phone Numbers, and Opt-Out

We process phone numbers and SMS metadata to provide event join verification (one-time passcodes), organizer broadcasts, RSVPs, check-ins, and other transactional and event-related messages. SMS delivery is performed by AWS SNS.

  • Consent — by providing your phone number, you consent to receive transactional and event-related texts as described in the Terms of Service. Message frequency varies, and message and data rates may apply.
  • Opt out / help — reply STOP to opt out of non-essential messages (you may receive a final confirmation) and HELP for help, or contact support@whoagain.app. After opting out, certain features (such as SMS-based event join) may not function.
  • We do not sell phone numbers — phone numbers and SMS opt-in data are not sold or shared, and SMS consent is not used for unrelated marketing without separate consent where required.
  • Organizer messages — where an organizer sends messages, the organizer is the controller and is responsible for compliance (including the TCPA and carrier rules); we process the data on the organizer's behalf to deliver the messages.

14. Cookies, Analytics, and Similar Technologies

We and our service providers use cookies, local storage, and similar technologies to operate and improve the Service:

  • Strictly necessary — required to provide the Service (for example, authentication/session, security, load balancing); these cannot be switched off.
  • Preferences — remember your settings (for example, your light/dark theme stored locally on your device).
  • Analytics/performance — where used, help us understand usage and improve the Service; where required by law, we request consent for non-essential cookies/analytics and provide controls.

You can control cookies through your browser settings, though some features may not work without them. Where we offer a cookie banner or preference center, you can manage non-essential cookies there. We honor recognized opt-out preference signals (such as Global Privacy Control) where applicable, and do not use cookies for cross-context behavioral advertising. Our analytics may be provided through our infrastructure providers (for example, Firebase/Google) as described in Section 20.

15. Children's Privacy

The Service is not directed to children under 13 (or under the higher minimum age required by your jurisdiction), and we do not knowingly collect personal data directly from children under that age. Purchases require users to be 18 or older. If you believe a child under the applicable minimum age has provided us personal data, contact legal@whoagain.app and we will take appropriate steps to delete it. If you record information about a minor in your private records, you are responsible for ensuring you have any rights and consents required by law (for example, parental consent), and you do so as the controller and at your own risk. We do not knowingly sell or share the personal data of minors.

16. Region-Specific Disclosures

16.1 EEA, UK, and Switzerland (GDPR / UK GDPR)

This supplements the rest of the Policy for individuals in the EEA, UK, and Switzerland. Controller and contact: Section 1. EU/UK representative: none is appointed at launch (see Section 1). Legal bases: Section 5. Your rights: Section 12.1. International transfers and safeguards (SCCs/IDTA): Section 9. You have the right to complain to a supervisory authority (Section 19); UK residents may contact the Information Commissioner's Office (ICO). Where you provide data as a controller (recording data about others), Section 6 applies.

16.2 California (CCPA/CPRA)

This supplements the rest of the Policy for California residents. Categories collected in the past 12 months: identifiers (e.g., name, email, phone, account/online identifiers, IP address); customer records; commercial information (e.g., transactions, tickets/Subscriptions); internet/network activity (e.g., usage, device, log data); geolocation (approximate, from IP); audio/visual (e.g., photos you upload); and other information you provide — collected from you, your use of the Service, and service providers (e.g., sign-in and payment providers). Purposes: Section 4. Disclosures for a business purpose: to the subprocessors in Sections 7 and 20. Sale/Sharing: we do not sell or share personal information and do not use sensitive personal information for purposes requiring a right to limit (Section 8). Your rights and how to exercise them: Section 12.2. Retention: Section 10.

16.3 Other jurisdictions

Where other privacy laws apply to you, we will honor the rights and obligations those laws require, as described in Section 12.3 and elsewhere. Contact legal@whoagain.app with questions.

17. Third-Party Links and Services

The Service may link to or integrate with third-party websites and services (for example, social media links on public profiles, Google sign-in, Stripe checkout, and others). We are not responsible for the privacy practices or content of third parties; when you interact with a third party, that third party's privacy policy governs. We encourage you to review their policies.

18. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will provide notice by reasonable means (for example, posting the updated Policy with a new effective date, email, or in-app notice). Changes are effective as of the date stated, unless a later date is required by law. Your continued use of the Service after the changes take effect constitutes acceptance, except where additional steps (such as consent) are required by law.

19. Contact and Complaints

For privacy questions, requests, or complaints, contact us by email:

Silv LLC (operator of WhoAgain)
Attn: Privacy
Email: legal@whoagain.app

If you are in the EEA, UK, or Switzerland and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local supervisory authority. UK residents may contact the Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to address your concerns first.

20. Subprocessor List

We use the following key subprocessors to provide the Service, under appropriate contractual protections. This list may change; we will update it as our subprocessors change.

SubprocessorService providedCategories of data processedProcessing location
Google LLC — Firebase / Google CloudAuthentication, Firestore database, cloud storage, hosting, and cloud functionsAccount/identity, authentication, Your Content (private records), public-profile data, event/attendee data, usage/telemetry, device/log dataUnited States
Google LLC — Gemini API (planned)Text embeddings for semantic/AI searchText derived from Your Content (to generate embeddings); resulting embeddingsUnited States
Amazon Web Services, Inc. — AWS SNSSMS message deliveryPhone numbers, message content, delivery metadataUnited States
Stripe, Inc.Payment processing and Stripe Connect marketplace payouts (WhoAgain does not store full card numbers)Payment/transaction metadata, billing details, connected-account data; full card data handled by Stripe as a separate controllerUnited States (and other countries where Stripe operates)

Data is hosted in the United States. Subprocessors may use their own sub-processors and may process data in additional countries; appropriate transfer safeguards apply as described in Section 9. For an up-to-date list of subprocessors, contact legal@whoagain.app.


WhoAgain is a product of Silv LLC. This is a template and must be reviewed by qualified legal counsel before use. The canonical version of this Policy is maintained in the project repository at docs/legal/privacy-policy.md.

WhoAgain?
Terms of Service·Privacy Policy
© 2026 Silv LLC · whoagain.app