Privacy Policy
1. Overview
Hemma ("we", "us") builds a daily photo ritual for iPhone. This policy explains what we collect when you use the app, why we collect it, and the choices you have. We aim to collect as little as possible and to keep what we do collect safe.
2. Information we collect
We collect the photos you choose to submit, the captions and place names you type alongside them, your votes, and basic account details: your display name, username, the email address Sign in with Apple gives us (which may be a private relay address), and an optional Instagram handle. We also store a notification token for your device, and whether you have added the Hemma widget — the widget needs a silent daily nudge to change its picture, so the token is registered whether or not you allow alerts. We do not collect your location — photos are stripped of camera metadata, including GPS coordinates, and the app never asks for location access. We run no analytics or advertising code of any kind.
3. How we use it
Your submissions and votes power the daily matchups and the winning widget. Account details let others recognise your entries. Technical data helps us fix problems and improve performance. Photos are also screened automatically before they appear, which involves a third party — see Automated content moderation below. We do not sell your personal information.
4. What others can see
Photos you submit are shown to other Hemma users for voting and may appear as the day’s widget. Your display name and any linked handle are shown alongside your entries. Do not submit anything you would not want shared publicly.
5. Reporting and blocking
You can report any photo or profile from the ⋯ menu beside it, and you can block another member from the same place. Blocking works both ways and is never disclosed: their photos stop reaching your voting board and their profile closes to you, and yours does the same to them. Neither of you is told. One exception, stated here because the app states it too: the daily featured photo belongs to a whole region and is served to everyone alike, so it stays on your screen — with the blocked member’s name removed. You can undo any block under Settings → Blocked accounts.
6. Automated content moderation
Every photo you submit is checked automatically before it can appear anywhere in the app. We first remove the file’s metadata — including any GPS coordinates your camera recorded — and then send a downsized copy of the image to Anthropic, whose Claude model rates it for content that would not belong in an all-ages public feed. Nothing else goes with it: no caption, no place name, no display name, no account identifier. Photos the model flags are held back from the app and reviewed by a person before any decision is made. Under Anthropic’s API terms, images sent this way are not used to train their models.
7. Service providers
We run Hemma on a small number of infrastructure providers rather than our own hardware: DigitalOcean (servers, photo storage, image delivery), Neon (database), Cloudflare (traffic routing), Apple (Sign in with Apple and push notifications), Sentry (crash and error reports), and Anthropic (the automated moderation described above). Each processes data only on our instructions and for no purpose of their own. Their infrastructure is in the United States, so if you use Hemma from the EU or UK your data is transferred there under the standard contractual clauses those providers offer.
8. Data retention & your rights
You can view your archive, delete individual photos, and request deletion of your account and associated data at any time. We keep data only as long as needed to run the service or meet legal obligations. Where the GDPR applies, you have rights of access, rectification, erasure, and portability.
9. Contact
Questions about this policy or your data? Reach us at [email protected], or see our Support & Contact page.