Privacy Policy
Last updated: 2 October 2026 · Türkçe: KVKK Aydınlatma Metni
Afterhi lets people at the same venue tonight see each other and say hi. This policy explains what we collect, why, who can see it, how long we keep it and what you can do about it.
Afterhi is run by Utku Erem Karaoğlan, who is the data controller under Türkiye’s Personal Data Protection Law No. 6698 (“KVKK”). Contact: hello@afterhi.app.
- No email, phone number or password. Your account is a random key kept on your phone.
- Your photo and profile are shown only to people checked in at the same venue while you’re visible, to people you met in the last 7 days and to people you chat with.
- A hi stays silent: the other person only learns about it if they say hi to you too.
- Notifications never show names or photos.
- No ads, no tracking, and we never sell your data.
- You can delete your profile at any time in Profile.
What we collect
Your account
The first time you open Afterhi, your phone gets a random sign-in key, stored in its keychain. We store only a scrambled (hashed) copy of it.
Your profile
The first name you enter, your intention for the night (Socialising, New business or Dating) and, if you add it, your “Ask me about…” line.
Your photo
The photo you take in the app when you check in, with the time and the venue it was taken at. It’s reused for about 4 hours, so one photo covers a night out.
Your visits
The venue whose code you scanned, when you checked in and when your visibility ended (after 3 hours, or when you leave). For each visit we also count how many hi’s you sent and received, but not to or from whom.
Hi’s, meetings and chats
- Who you said hi to, until it becomes mutual or your visit ends.
- For mutual hi’s: when they happened, how you found each other, whether you confirmed meeting, the conversation cards shown to you, your Keep in touch? answers and your sealed notes.
- Chat messages, and how far each of you has read.
Safety
The people you block, and the reports you make: who you reported, the reason, anything you wrote, and that person’s name and a copy of their photo at that moment.
Notifications
If you allow notifications, the push token Apple (iPhone) or Google (Android) gives your phone.
Technical data
This website, afterhi.app, uses no cookies, analytics or content from other sites; its fonts and images are served from afterhi.app itself.
Your IP address and request details pass through Cloudflare, our hosting provider, to deliver the service and to slow down abuse (for example, too many sign-ups from one address). We don’t store IP addresses or keep request logs.
What we don’t collect
Your location (we only know the venue whose code you scanned), contacts, photo library, microphone, advertising identifiers, email address or phone number. The camera is used only to scan venue codes and take your photo; frames from scanning are not stored.
Why we use it
- To run Afterhi: showing you to people at the same venue, delivering hi’s, meetings, Keep in touch?, chats and notifications.
- To check photos: see “The photo check” below.
- To keep people safe: blocks, reports, abuse limits and removing people who break the Terms.
- To understand the pilot: counts such as how many people checked in or said hi, never who said hi to whom.
- To meet legal obligations, for example a lawful request from a court or authority.
Under KVKK, we rely on the performance of our agreement with you (the Terms) to run the service, on our legitimate interest in keeping Afterhi safe and understanding how it’s used, and on legal obligations where they apply.
The photo check
When you take a photo, it’s sent to an AI model, GLM-4.6V-Flash by Z.ai, which checks that nothing in it is inappropriate and that you’re the main person in it. It doesn’t identify you: it’s not face recognition and not an ID check. We don’t use your photo to train any model.
Who can see what
| Who | What they see |
|---|---|
| People checked in at the same venue, while you’re visible | Your photo, name, intention and “Ask me about…” |
| People you met | The same, for 7 days after you met (People you met) |
| People you keep in touch with | The same, and your messages, for as long as the chat exists |
| Someone you said hi to | Nothing, unless they say hi to you too |
People you block, and people you parted with (Not now, or no chat after Keep in touch?), don’t see you again at any venue.
Service providers
We use these providers to run Afterhi. They process data on our behalf and only for that purpose. All of them are outside Türkiye.
| Provider | What for | Data |
|---|---|---|
| Cloudflare, Inc. (USA, global network) | Servers, database, photo storage | Everything described above |
| Z.ai (Zhipu AI) | The photo check | Your photo, when you take it |
| Apple Inc. (USA) | Delivering notifications to iPhones | Push token and the notification text |
| Google LLC (USA), Firebase Cloud Messaging | Delivering notifications to Android phones | Push token and the notification text |
Because these providers are abroad, your data is transferred outside Türkiye. These transfers are made under Article 9 of KVKK. We disclose data to authorities only when the law requires it.
How long we keep it
| Your photo | Until you take a new one, until 90 days pass without a visit, or until you delete your profile |
| A hi that wasn’t returned | Until it becomes mutual, you take it back, you leave or check in again, and in any case no longer than a day |
| Sealed notes | Deleted unread at 12:00 the day after your visit, unless you both chose to keep in touch |
| Profile, visits and blocks | Until you delete your profile |
| Meetings, notes and chats | Until you or the other person deletes their profile |
| Reports | One year, even if either profile is deleted |
| Push token | Until you delete your profile or Apple tells us it’s no longer valid |
What we keep after you delete your profile
Deleting your profile (Profile → Delete profile) immediately deletes your photo, name, intention, “Ask me about…”, visits, hi’s, meetings, notes, chats (including the other person’s messages to you) and blocks.
We keep reports for one year: the reports you made and the reports made about you, with the reason, any text, the reported person’s name and a copy of their photo. This lets us act if someone who abused others comes back. A report you made doesn’t include your name or photo.
Security
All traffic is encrypted (HTTPS). Photos are only served to the people allowed to see them, as described above. Chats are stored on our servers so they reach the other phone; they aren’t end-to-end encrypted, and we don’t read them unless the law requires us to.
Age
Afterhi is for people aged 18 and over. If we learn that someone under 18 is using it, we delete their profile.
Your rights
You can see and edit your profile in the app, and delete it at any time. Under Article 11 of KVKK you also have the right to learn whether your data is processed and to request information about it; to learn the purpose and whether it’s used accordingly; to know who it’s transferred to in Türkiye or abroad; to have it corrected, deleted or destroyed, and to have those to whom it was transferred notified; to object to an outcome against you that arises solely from automated analysis; and to claim compensation for damage caused by unlawful processing.
Write to hello@afterhi.app. We answer within 30 days, free of charge. You can also complain to the Personal Data Protection Authority (KVKK).
Changes
If we change this policy, we’ll update the date above, and tell you in the app if the change matters to you.