Privacy Policy
In brief. We collect only the data without which SeeU cannot function: your phone number for signing in, your profile data, and the material you publish and send. To find people nearby, your phone broadcasts a one-time code rather than your location. We do not sell data, show advertising or use advertising identifiers. You can delete your account in the app at any time.
1. General provisions
1.1. This policy sets out how the personal data of users of the SeeU mobile app and the seeu.kz website (together, the “Service”) is processed.
1.2. The personal data operator is the owner of the Service (“we”, “us”). Details of the operator are published on the Legal information page.
1.3. We process data in accordance with the Law of the Republic of Kazakhstan No. 94-V “On Personal Data and Their Protection” of 21 May 2013 and other laws of the Republic of Kazakhstan. If you use the Service from another country, the laws of that country may also apply to the processing, and we take them into account.
1.4. This policy forms part of the Terms of Use. By registering, you give your consent to the collection and processing of personal data on the terms set out in it.
2. Data we collect
Data you provide
- Phone number: used for signing in and protecting your account.
- Profile: name, username, profile photo (optional) and bio.
- Posts: photos, videos, stories, live broadcasts, comments, likes and follows.
- Messages: the text messages, voice messages, photos, videos, files, stickers and GIFs you send.
- Card: the photo, the text and, if you have chosen one, the track that people nearby hear when they open your card.
- Audio: tracks and other material you publish.
- Rooms and meetups: the rooms and meetups you create and your messages in them.
- Enquiries: reports, messages to the support team and any material attached to them.
Data generated through your use of the Service
- Connections: your follows, the private messaging access you have granted and the users you have blocked.
- Card events: information about who viewed your card or sent you warmth and when, and whose cards you viewed.
- Scanner: the one-time codes issued to your phone and the times at which they were issued.
- Calls: information about who called whom and when, and the duration of each call. Calls are not recorded.
- Technical data: IP address, device model, operating system and app versions, request times, session identifiers, notification token and crash reports.
Device data processed only with your permission
Each permission is requested when it is first needed and can be turned off in your phone’s settings. Without it, the other features of the Service continue to work.
- Bluetooth: required for the scanner to find people nearby and show them your card.
- Camera and microphone: used for taking photos and videos, voice messages, calls and live broadcasts.
- Photos and videos on your device: required to select a file for publication or to save what you have recorded.
- Music on your device: allows you to add your own audio files to the player.
- Contacts: allow you to find people you know who already use SeeU. Numbers are compared as secure hashes; your address book never leaves the device in readable form.
- Location: used only while the app is in use, to determine the nearest city for meetups and for the city tag in stories. The city is determined on your phone; your coordinates are not sent to us. The scanner does not use location.
- Notifications: allow us to inform you of new messages, calls and events.
Camera effects
Effects and masks are processed on the phone itself. To apply them, the app detects faces and human silhouettes in the frame using the device’s built-in tools (Google ML Kit works without a network connection). This data does not leave your phone, is not sent to us and is not stored. We do not create biometric templates or identify the people who appear in images.
Data we do not collect
- passport details, individual identification numbers (IIN) or biometric data;
- advertising identifiers (IDFA, Advertising ID);
- your location history or precise coordinates;
- the contents of your address book in readable form.
3. Purposes of processing
- Operating the Service: creating your account, displaying your profile and posts, delivering messages, connecting calls, finding people nearby and saving your settings.
- Protecting users: preventing spam, fraud, account takeovers and abuse, enforcing blocks and limiting the frequency of requests.
- Reviewing reports and applying the Community Guidelines.
- Responding to enquiries sent to the support team.
- Improving the Service: identifying errors and bottlenecks on the basis of technical data and de-identified statistics.
- Complying with the law: responding to lawful requests from government authorities and retaining data for the required periods.
We do not use data for advertising purposes and do not build advertising profiles. Automated checks may flag material for a moderator, but decisions to restrict an account are made by a person.
4. Legal grounds for processing
We process data on the basis of the consent you give at registration and to the extent necessary to perform the Terms of Use. Certain data is processed because the law requires it, for example when responding to a court request. Device data (contacts, location and other data) is processed only after you have granted the relevant permission in the system.
5. Cards and the scanner
5.1. While visibility is on, your phone broadcasts a one-time code over Bluetooth. The code is issued by our server, is valid for a few minutes and is renewed regularly. It contains no name, phone number or profile link. A phone that receives the code obtains from our server only your card: its photo, its text and the track you have chosen.
5.2. If visibility is on, your phone may continue to broadcast the code even when the app is in the background. You can turn visibility off in the settings at any time: broadcasting then stops, and previously issued codes no longer point to your card.
5.3. Every view of a card and every instance of warmth is recorded; these records are used to compile the counters and the list of viewers. The owner of a card can see this list only within a set period: 12 hours for views and 24 hours for warmth. The records themselves are kept for as long as both accounts exist.
5.4. Your card is not linked to your profile. We do not disclose to other users which account a card belongs to.
6. Sharing of data
With other users
Other users can see your posts within the audience you have chosen, your profile (name, username, photo and bio) and your card, if they are nearby and using the scanner. The owner of a card can see that you viewed it. The people you correspond with can see your messages.
With providers necessary for the operation of the Service
These providers process data on our behalf, solely for the stated purposes, and are obliged to protect it.
| Provider | Purpose | Data |
|---|---|---|
| Cloudflare, Inc. | Storage and delivery of media files (Cloudflare R2) | The photos, videos, audio and files you upload |
| WhatsApp (Meta Platforms) | Phone number confirmation at sign-in: you send us a message from your own WhatsApp | The phone number the message was sent from and the code it contains |
| Apple Inc. | Delivery of notifications to iPhone (APNs) | Device token and notification text |
| Google LLC | Delivery of notifications to Android (Firebase Cloud Messaging) | Device token and notification text |
| Server infrastructure provider | Hosting of the Service’s servers and database | Data stored on our servers |
The GIFs in the Service are taken from the GIPHY library and stored on our servers; consequently, no requests are sent to GIPHY when you search for or send a GIF.
With government authorities
Data is disclosed only in response to a lawful request and to the extent provided for by law. The procedure is set out in Government requests.
With a successor
If the Service passes to another organisation as a result of reorganisation or sale, the data passes with it. The new owner will be obliged to comply with this policy or to obtain your consent to new terms.
We do not sell personal data and do not share it with advertising networks or data brokers.
7. Cross-border transfer of data
Some of the providers listed in section 6 are located outside the Republic of Kazakhstan. The transfer of data to such providers constitutes a cross-border transfer: we transfer only the information necessary for a specific task, and only to providers that ensure the protection of data. By giving your consent at registration, you also agree to such transfers.
8. Place and periods of data storage
8.1. The Service’s database containing personal data is hosted on servers located in the Republic of Kazakhstan. Media files are stored in Cloudflare R2.
8.2. We keep data for no longer than is necessary for the purposes specified in section 3:
| Data | Retention period |
|---|---|
| Account, profile, connections, settings | For as long as the account exists |
| Posts, comments, Audio material | Until you delete them or the account is deleted |
| Messages | Until they are deleted or the account is deleted; the message cache on your phone is kept for up to 7 days |
| Records of card views and warmth | For as long as both accounts exist; shown in the card owner’s list for 12 and 24 hours respectively |
| One-time scanner codes | A few minutes |
| Sign-in session: the code and the sender's number | 2 minutes until confirmation; the record is deleted within an hour |
| Server logs | Up to 30 days |
| Backups | Up to 30 days after the data is deleted from live systems |
| Reports and decisions on them | Up to 3 years, in order to take repeat violations into account and to respond to claims |
8.3. Where the law requires data to be kept for longer, it is kept for the period prescribed by law and solely for that purpose.
9. Data protection measures
- Data is transmitted between the app and our servers only over encrypted connections (TLS).
- Sign-in keys are kept in the device’s secure storage.
- Staff access to data is granted only to those who need it for their work; signing in to the administration system requires a second factor.
- Media files are provided through links with a limited period of validity.
No system can guarantee absolute protection. In the event of a breach that may affect your rights, we will notify you and the competent authority in the manner and within the time limits established by law.
10. Rights of the data subject
You have the right:
- to know what data about you we process and to obtain a copy of it;
- to correct inaccurate data; most information can be edited directly in your profile;
- to request the deletion or blocking of data if its processing is unlawful or no longer necessary;
- to withdraw your consent to processing, in which case your account will be deleted, since the Service cannot function without data;
- to turn off device permissions (Bluetooth, contacts, location and others);
- to appeal against our actions to the personal data protection authority or to a court.
Rights are exercised in the app: Settings (Настройки) → My data (Мои данные). There you may request a copy of your data, its correction or deletion and withdraw your consent, and follow the progress of your request. If you cannot sign in, write to privacy@seeu.kz, stating the phone number linked to your account. We may ask you to confirm that the account belongs to you and respond within the time limits set by law. You may also delete your account yourself by following the procedure set out in Delete your account and data.
11. Minors
The Service is intended for persons aged 16 and over. Users aged 16 and 17 use it with the consent of a legal guardian. If we learn that an account belongs to a person under 16, we will delete the account together with its data. The detailed conditions are set out in Age and child safety.
12. The seeu.kz website
The website does not use cookies, visitor analytics or third-party scripts. Like any web server, the website’s server records technical information about requests (IP address, time, page address and browser type) and keeps it for up to 30 days for protection against attacks. Further details are provided in Cookies and on-device data.
13. Changes to this policy
We may update this policy when the Service or the law changes. We give advance notice of material changes in the app before they take effect. The date of the current version is shown at the top of this document.
14. Contact information
For matters concerning the processing of personal data, please write to privacy@seeu.kz. Contact details for other enquiries are provided on the Contact page.