Last updated August 5, 2026
This policy explains what HelpU collects when you use the app, why, who else touches it, and what you can do about it. It describes the app as it actually works today — not a template.
These documents are currently available in English only. Greek and the other languages HelpU supports will follow once the translations have been reviewed; until then the English text is the one that applies.
Who is responsible
HelpU is an early-stage project based in Larnaca, Cyprus. It is not yet an incorporated company, so the person responsible for your data — the controller, in the language of the GDPR — is the individual who runs the project. You can reach them at saleemmatar6@gmail.com, and that is the address for every request in this policy.
If HelpU is later incorporated, the company will take over as controller and this policy will be updated to name it. Nothing about what is collected changes because of that.
What we collect
Only what the app needs to arrange and record a job:
•
Account details — your first and last name, and your email address or phone number, depending on how you sign in.
•
A profile photo, if you choose to add one. It is a picture of your own face, and inside the app it is shown to nobody but you. It is stored at a public link: anyone who has that link can open the picture, and the link goes on working until the file itself is taken down.
•
Addresses — street, unit, area, city and postcode for each address you save, plus any access notes you add. Access notes often contain a gate or door code, which is the single most sensitive thing in the app; it is treated accordingly.
•
Bookings — what you booked, when, with whom, the price breakdown, and any note you attach to the job.
•
Messages — the messages you send to a provider through the app, and theirs to you.
•
Reviews — your rating, the tags you pick, and any note you write.
•
Preferences — your chosen language and appearance (light, dark or system).
•
Payment identifiers — the card brand, the last four digits and the expiry, so you can recognise a saved card. Nothing more.
•
If you sign up as a provider — your business or display name, service area, bio, business photo, VAT number if you give one, your services, your team members, and any links to your own website or social accounts that you add.
•
If you sign up as a provider, up to twelve photographs of your work and the captions you write for them. These are meant to be seen: they are shown on your public profile to anyone browsing the app. Each one is stored at a public link too, so anyone who has that link can open the photograph whether or not they use HelpU.
•
If you sign up as a provider, the documents we ask you to upload so your listing can be checked, and what kind each one is. There is a section on those below, because they are the most sensitive thing in the app.
•
If you are a provider and you switch live sharing on while you are travelling to a job, your position at that moment, for as long as that job says you are on the way. One point, overwritten, never a trail.
•
Tips, if you leave one: the amount, the booking it belongs to, and whether the payment went through.
HelpU does not collect your location in the background, does not read your contacts, and does not track you across other apps or websites. The live sharing described below is foreground only and stops the moment the job does; the app asks for no background location permission of any kind, on either platform.
Your card details never reach HelpU
Payments run through Stripe. When you enter a card, it goes from your device to Stripe directly, inside their own payment sheet. HelpU never sees, receives or stores your card number, expiry-plus-CVC pair, or any authentication data. What comes back to us is a token plus the brand, the last four digits and the expiry month and year, which is what the app shows you on the payment methods screen.
Why we are allowed to hold it
•
To perform the contract you entered into — arranging, pricing, delivering and paying for a booking. This covers your account, your addresses, your bookings, your messages and your payments.
•
To comply with legal obligations — bookings are financial records and Cypriot bookkeeping and tax rules require them to be kept.
•
For our legitimate interests — keeping the marketplace safe, preventing fraud and abuse, and being able to investigate a dispute between a customer and a provider. We do not use these interests to profile you or to market to you.
•
With your consent, where the app asks for it — for example before it uses a device permission.
•
Verification documents are held for our legitimate interest in a marketplace that is safe to let into your home, and so that we can identify the businesses trading through the platform. A provider cannot be approved to take bookings until theirs have been reviewed, so this is also part of performing the contract with them.
•
A provider's position while they are on the way is shared on their consent, given for that journey and withdrawn by switching it off. It is used for one purpose, which is letting the customer see them approaching.
•
A tip is part of the contract for that booking, and once it is paid it is a financial record we are required to keep.
Who else processes it
Two companies, both acting on our instructions as processors, and no one else:
•
Supabase — hosts the database and the authentication service. The project runs in an EU region, so your account, addresses, bookings, messages and reviews are stored in the European Union.
•
Stripe — processes payments. Stripe is an independent controller for the payment data it collects directly from you, under its own privacy policy, and may process it outside the EEA under the European Commission’s standard contractual clauses.
There are no analytics SDKs in this app, no advertising SDKs, no crash-reporting service that carries your personal data, and no third-party trackers. Your data is not sold, rented or shared for anyone else’s marketing, ever.
What a provider can see, and when
This is enforced in the database, not just in the app, so it holds no matter what a provider’s device does.
•
While a booking is waiting to be accepted, a provider sees your first name, your area and your city. That is enough to decide whether to take the job.
•
Your phone number, your full street address, your access notes and whatever you typed into the booking’s own notes box are released only once the job is live — accepted and running — and stay available for 24 hours after it ends, so a provider can follow up on the day.
•
After that window, the provider loses access to all of it.
•
Your review is visible with your first name, as reviews are on any marketplace.
Provider verification documents
Every provider has to be checked before their listing can go live, and that means uploading documents. These are scans of identity papers and criminal record certificates, so they are the most sensitive files this app holds and they get their own section.
•
What is collected: the file itself, what kind of document it is, and when you uploaded it. Depending on the work you do that can be an identity document, a police clearance certificate, a child protection certificate, a beautician or carer registration, or proof of insurance.
•
Why: because someone is deciding whether to let a stranger into their home, and a checked document is the only part of that decision we can actually stand behind. It is also the gate on approval. A provider cannot be set live until their documents have been reviewed.
•
Where the files sit: a private storage bucket in the same EU hosted project as the rest of the database, under a path tied to your provider account. The bucket is not public, and there is no public link to any file in it.
•
Who can see them: you, and the person at HelpU who reviews them. No customer ever sees a document. No other provider can. The database will not let a provider read anyone else's file, and it will not let any provider approve, reject or annotate a document at all, including their own.
•
What a customer sees instead: one yes or no. The HelpU Checked badge means the review was done and passed. It carries no document, no reference number, no issuing authority and no date.
•
If a document is rejected the reviewer leaves a short reason and you can read it, so rejected is never a dead end. That note is visible to you and to HelpU, and to nobody else.
•
If you delete your account the document records go with it, and the file paths are handed to the operator so the files themselves are removed from storage. There is no bookkeeping reason to keep evidence for an approval that has just been withdrawn.
•
Your export includes the details of each document you uploaded, but not the scans. Those are sent by a person if you ask for them, because a policy should not be able to hand out an automatic link to a passport scan.
Live location while a pro is on the way
When a provider marks a job as on the way, they can share their position so you can watch them approach instead of guessing. It exists for that one status and nothing else, and the limits below are enforced in the database rather than by the app remembering to behave.
•
It is the provider's choice and it is off unless they turn it on. Sharing needs both the switch and the location permission on their phone.
•
Turning it off really stops it. The app releases the GPS rather than continuing to watch and quietly skipping the upload, and the last point that was stored is removed at the same time, so the map you are watching loses the dot rather than freezing it.
•
It is foreground only. Nothing is shared while their app is in the background or closed.
•
It is one point, not a trail. A single row per booking holds a latitude, a longitude and the time it was written, and every update overwrites the last. A new position goes up roughly every fifteen seconds while sharing is on.
•
It is deleted the moment the booking stops saying on the way. That deletion happens in the same database transaction as the status change, not in a nightly cleanup, so there is no window in which it lingers. There is no history table and there is not going to be one.
•
Only the customer on that booking, and the provider whose phone is sharing it, can read the position, and only that provider can write it. No one else can see where anybody is.
•
The dot on your map is only ever a real reported position, and only a recent one. Nothing is smoothed, interpolated, or slid along a road it was not reported on, and no arrival time is calculated from a distance nobody measured. If about a minute passes with no new position, the dot is removed instead of being left where it was, because a pro whose phone has gone quiet is not somewhere, they are unknown.
•
Your own location is a separate thing and is not part of this. It is used on your device to centre the map while you place a pin on an address, and the only thing that leaves your phone is the pin you save, which goes to the pro who takes your job.
Tips
After a completed job you can add a tip. HelpU takes nothing from it, not a percentage and not a fee. There is nowhere in the database to record a commission on a tip, which is the strongest way we know to say it.
•
What is recorded: the amount, which booking it was for, who paid, who it was for, whether the payment succeeded, and, if the money is ever sent back, how much was refunded and whether a chargeback is open. A tip carries no message and no note, so there is no free text in it at all.
•
The card is handled by Stripe exactly as any other payment, and the card number never reaches HelpU.
•
One tip per booking. A failed attempt is retried on the same record rather than creating a second one, so a single gesture cannot become two charges.
•
The provider sees a total for the tips they received in the last 30 days on their Earnings screen, and nothing more: there is no per-tip line for either of you, no notification, and nothing about the tip on your booking afterwards. The record is kept, and both of you can ask for it.
•
A tip is money that moved, so it is kept as a financial record in the same way a booking is, and it survives account deletion. There is no name, address or note in it to scrub, and removing it would destroy the record rather than protect you.
How long it is kept
Bookings are kept. What you were charged, for what, and where the job happened is a financial record, and Cyprus requires those records to be retained — so a completed booking, including the price breakdown and the address snapshot taken at the time, survives even after you close your account.
Everything that is about you rather than about the transaction does not survive. See the next section for exactly what happens.
Deleting your account
You can delete your account from inside the app; you do not have to email anyone to do it. Deletion is immediate and cannot be undone. Here is precisely what it does:
•
Your name, email address and phone number are cleared from your profile.
•
Your profile photo is removed from storage, so the picture stops being served at its public link. This is the one item on this list that is not guaranteed. The removal is made from your own device, with your own session, in the moments before the account goes, and it can fail: if it does, the fact that there was a photo is recorded and passed to the operator so the file is taken down by hand. Until that happens the picture is still reachable by anyone holding the link.
•
Every saved address is scrubbed in place — street, unit, area, city, postcode and access notes are wiped. The gate codes go.
•
The notes and access notes stored on your bookings are deleted.
•
Your saved payment methods are deleted, and any active subscription at Stripe is cancelled so you cannot keep being billed for an account you no longer have.
•
Any package you bought is cancelled. Every visit in it that has not happened yet is cancelled with it, at no charge, and every session you paid for and did not use is refunded to the card that paid. Deleting your account ends a standing schedule you prepaid for, so this is the one thing here you may want to finish or cancel yourself first.
•
If you sold packages, they are cancelled too, on the same terms. Your customers lose the visits you can no longer perform, and every session they paid for and did not use is refunded to the card that paid. This is the largest thing deleting a provider account does to other people, so it is worth telling those customers yourself before you do it.
•
Your messages keep their place in the thread but their text is replaced, so the other person’s conversation does not develop holes.
•
Your reviews keep their score — other customers relied on it, and a provider should not lose their rating because you left — but the written note and the tags are deleted.
•
If you were a provider, your listing is unapproved and de-identified, your services are taken offline, and any website or social links on it go with it.
•
If you were a provider, the photographs of your work are removed from storage on the same terms as your profile photo, and their file paths are recorded and passed to the operator so anything that removal did not finish is taken down by hand.
•
If you were a provider, your verification documents are deleted, the reviewer notes on them go too, and the file paths are passed to the operator so the scans themselves are removed from storage. A withdrawn approval has no evidence worth keeping.
•
Any live position row is deleted outright, even if a booking was left sitting in the on the way state, so an erasure never depends on a trigger having fired.
•
A paid Featured placement is stopped immediately and the billing behind it is cancelled, for the same reason as any other subscription: a deleted account has no login left to stop a charge with.
•
Your login is permanently disabled: the password is destroyed, the email and phone are released, every session is ended, and the credential is banned. There is no route back in, including password reset and one-time codes.
We keep one record of the deletion itself — that an account with a given internal identifier was deleted, when, whether it had bookings, whether it had a profile photo, and the storage paths of any work photographs it had. The first part is required to demonstrate we honoured your request. The last two are the working list for the removals described above, and they are cleared once those files are gone. None of it is your name, your address, your messages or your face.
Your rights
Under the GDPR and Cyprus Law 125(I)/2018 you can ask for any of the following, and it is free:
•
Access and portability — write to saleemmatar6@gmail.com and we will send you a machine-readable export of your profile, addresses, bookings, messages, reviews, provider listing, card summaries, any package purchases, and the details of any verification document you uploaded. The document scans themselves are sent by a person rather than by an automatic link, for the reason given above.
•
Rectification — correct anything wrong, mostly from the profile and address screens.
•
Erasure — delete your account, as described above, subject only to the booking records we are legally required to retain.
•
Restriction and objection — tell us to stop a particular use.
•
Withdrawal of consent, where a use was based on consent, without affecting what happened before you withdrew it.
Write to saleemmatar6@gmail.com for anything the app cannot do for you. We answer within one month.
If you are not satisfied
You can complain to the Cypriot supervisory authority: the Office of the Commissioner for Personal Data Protection (Γραφείο Επιτρόπου Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Nicosia, Cyprus — dataprotection.gov.cy. You may also complain to the authority in the EU country where you live or work.
Security
Traffic between the app and our servers is encrypted in transit. Access to data is enforced row by row in the database itself, so your rows are reachable only by you and — for the limited window described above — the provider doing your job. This is a young product and we do not claim it is perfect; if you find a problem, please write to us and we will fix it.
Children
HelpU is for adults. It is not directed at children and accounts may not be created by anyone under 18. If you believe a child has given us data, write to us and we will delete it.
Changes to this policy
If this policy changes in a way that matters, the date at the top changes and the app tells you before the change takes effect. Older versions are available on request.