Hey Circl.

Privacy Policy

Nexrage Studios · Last updated October 9, 2026

Hey Circl (“Hey Circl”, “we”) helps groups decide what to watch, eat, do, play and listen to. This policy explains what we collect when you use the iOS app, the iMessage extension, the widget and heycircl.com, why we collect it, who we share it with, and the choices you have.

This is the privacy policy linked from Google’s consent screen when you sign in with Google or connect YouTube. It lives at https://www.heycircl.com/privacy. The terms of use are at heycircl.com/terms.

What we collect

DataWhyLinked to you
Name, email, and profile photo from Sign in with Apple or Sign in with GoogleCreate your account and show your name to your circles. Apple may give us a private relay email instead of your real one.Yes
Sign-in tokens (access token, refresh token, and Apple or Google identity token)Keep you signed inYes
Profile: interests, streaming services, dietary preferences, allergies, budget, taste notesPersonalize recommendationsYes
Circles, votes, picks, reactions, and decision historyRun rounds, learn what a circle likes, and show activity to membersYes
Location you allow: coordinates with a city or area label, and on iOS the areas you visit often and evenings that are already busyFind restaurants and activities nearby, and time recommendations. You can skip this.Yes
Push notification tokenNotify you about rounds, votes and picks (opt-in)Yes
Subscription status. On the web: Stripe customer id, subscription id, plan, and status. On iOS: Apple transaction identifiers, plan, and expiry.Unlock Circl Pro. Stripe and Apple handle payment. We do not store card numbers.Yes
Connected-account tokens and the interests imported from a source you connectRead that source and refresh it. See Connected sources.Yes
Business details for partners (name, website, contact email)Run sponsored-pick campaigns bought on heycircl.comYes
Diagnostics (request logs, crash reports)Keep the service runningNo

We do not use advertising identifiers, do not track you across other companies’ apps or websites, and do not sell your data.

Account sign-in

You can sign in with Apple, and with Google. Sign in with Google and connecting YouTube use the same Google app. Signing in asks Google for your name, email address, and profile photo. Connecting YouTube is a separate consent, described below. We store the tokens those providers issue so the session can continue.

Connected sources

Connecting a source is optional. We store an access token and, when the provider issues one, a refresh token, plus the provider id and username, so we can import interests and sync later. Disconnecting a source deletes that connection and its tokens. Interests already imported stay on your profile until you remove them or delete your account.

YouTube

YouTube uses the youtube.readonly scope only. We read your channel id and channel name, subscriptions (up to 500), liked videos (up to 300), and playlists you created (up to 25 playlists, 30 items each). System lists such as Watch Later, uploads, and the Liked videos playlist itself are not walked as playlists; likes are read separately, up to the cap above.

Each item is classified with the YouTube category id when we have one, then topic details, then a whole-word keyword match on the title and description. We do not request watch history, watch time, or search history.

A later sync can remove YouTube-sourced subscriptions, likes, or playlist items that disappeared, but only for a list that finished loading. A failed fetch does not wipe that list. Interests from other sources, and interests you added yourself, are left in place. Disconnecting YouTube deletes the connection and keeps interests already imported.

Other sources you can connect

  • Spotify. We ask for user-top-read and user-library-read. We store your Spotify id and display name and import top artists and top tracks.
  • Twitch. We ask for user:read:follows. We store your Twitch id and display name and import followed channels (up to 200).
  • Discord. We ask for identify and connections. We store your Discord id and username and the accounts you have linked there (type, id, and name). A linked Steam account can be used to import that Steam library. Other linked accounts may be suggested as connects.
  • Reddit. We ask for identity, mysubreddits, and history. We store your Reddit username, subscribed subreddits, and recently upvoted posts when that history is available.
  • Steam. There is no Steam sign-in. You give a profile URL or id, or we read a Steam id already linked on Discord. We look up the public profile name and owned games, including playtime, with our own Steam API key.

On iOS you can also allow Apple Music, Health, Calendar, Photos, or location. The app reads those on the device and sends titles (and, for location, area labels and coordinates, plus evenings that are already busy). We do not store an OAuth token for those sources, and we do not receive the raw photo, workout, or calendar event.

How recommendations work

To generate picks we send the interests and recent decisions of the members of a circle, the chosen category, and the circle’s city to an AI model provider (OpenAI). We send first names so explanations can say who a pick suits, never emails or account identifiers. Catalog data comes from TMDB (movies and shows), Google Places (restaurants and venues), Spotify (music) and RAWG (games); these providers receive only the search terms needed to look items up.

Public circles

If you create a public circle, its name, handle, description, photo, member count, host name and recent picks are visible to anyone with the link and in Discover. Followers can see the circle’s activity feed; hosts can see aggregate audience insights (never individual voting records). Private circles are only visible to their members.

Sponsored picks

Rounds in public circles may include one sponsored candidate. Hosts on Creator Pro can turn these off for their circle, or leave them on and receive a share per placement. A sponsored candidate is always labeled “Sponsored”, is chosen from a partner’s campaign by category and city only, and no member data is shared with the partner. Partners only see aggregate impressions and taps.

Who we share data with

  • Apple: Sign in with Apple, in-app subscriptions and round packs, push notifications.
  • Google: Sign in with Google, YouTube when you connect it, and Google Places for venue search.
  • OpenAI: recommendation generation (data is not used to train their models under our API terms).
  • TMDB, Spotify, RAWG: catalog lookups. Spotify, Twitch, Discord, Reddit, and Steam also receive the calls needed to import a source you connected.
  • Stripe: Circl Pro subscriptions bought on the web, and sponsored-pick campaigns bought by businesses. Stripe processes the card. We store the customer and subscription ids, not the card number.
  • Vercel and Neon: hosting and database infrastructure in the United States.

We share data with these providers only as needed to provide the service, and never for their own marketing.

Retention and deletion

We keep your data while your account exists. You can delete your account from Settings › Delete account. That deletes your user record and the data stored with it, including your profile, interests, memberships, votes, connected accounts and their tokens, and the subscription records we hold. Circles where you are the only member are deleted. A group decision can remain, with you no longer listed as the person who confirmed it. Anonymous, aggregated statistics (for example “picked by 12 circles this month”) are not linked to you and may be retained.

Your choices

  • Edit your name, photo and interests in the Profile tab.
  • Disconnect a source from You. That removes the connection and keeps imported interests.
  • Turn notifications on or off in Settings, or in iOS Settings › Notifications.
  • Manage or cancel a web subscription from Settings › Subscription (Stripe). Manage or cancel an App Store subscription in iOS Settings › Apple Account › Subscriptions.
  • Leave any circle from the circle’s options menu.
  • Email us to access or correct your data.

Children

Hey Circl is not directed at children under 13 and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.

Changes

We will post any changes here and update the date above. Material changes will also be announced in the app.

Contact

Nexrage Studios · fraz@nexrage.com