1who is responsible
plain-language summary: HERE and more, operated from prague. one address for anything about your data.
The controller of your personal data is the operator of HERE and more, operated from Prague, Czech Republic (“HERE and more”, “we”, “us”). This policy covers hereandmore.com, the HERE and more desktop and mobile applications, igni, the JEM identity, and the connected surfaces we operate.
For anything concerning your data, write to lnk@gradientrising.com.
2what we hold
plain-language summary: your entry, what you bring into your room, and thin technical traces. payment cards never touch us.
- entry and identity — the name or identifier you choose, your email address, your passkey public keys, and the device metadata that comes with them. Where a specific feature requires identity verification, verification data (such as a document and a selfie) is processed by our verification processor for that purpose only.
- what you bring — messages, files, voice notes, images, and everything you place in your room or share with people and apps inside the service.
- technical traces — IP address, device and browser type, timestamps, and security and diagnostic logs.
- payment — handled by payment processors; we receive confirmations and billing status, never full card numbers.
3why we hold it
plain-language summary: to run the service you asked for, to keep it safe, to meet legal duties — and for anything else, only with your consent.
We process personal data on these legal bases:
- contract — to provide the service you entered: your room, your people, your apps, igni, downloads, memberships.
- legitimate interests — to secure the service, prevent abuse and fraud, diagnose failures, and improve how it works. We weigh these interests against your rights, and you may object at any time.
- legal obligation — to keep what tax, accounting, or other law makes us keep, and to answer lawful orders.
- consent — for anything optional you switch on. Consent can be withdrawn at any time, without affecting what happened before.
We do not sell personal data, and we do not build or trade advertising profiles.
4igni and machine processing
plain-language summary: igni reads what you address to it so it can answer and act. machine helpers work for us under contract — nobody trains ad models on your life.
To respond and act, igni processes the content you address to it and the context you have chosen to give it. Where parts of this processing run on vetted model providers, they act as our processors, bound by contract to process your data only on our instructions and only to provide the service. We do not permit your personal data to be used for third-party advertising.
Machine-generated content is produced automatically and can be wrong; the terms of service describe your responsibility when acting on it.
5your keys and your face
plain-language summary: your face never leaves your device. we only ever see the lock click open.
Entry to the service uses passkeys (WebAuthn). Your biometrics — face, fingerprint — are verified inside your own device and are never transmitted to us or stored by us. What we receive is cryptographic: a public key, and signed confirmations that your device unlocked it. There are no passwords in the service for anyone to steal.
6who we share with
plain-language summary: the machines that run the service, the people you choose, and the law when it genuinely demands.
- processors — infrastructure hosting, email delivery, identity verification, and payment processing, each under a data processing agreement and only as needed for their task.
- people and apps you choose — what you share into a room, with a person, or with an app is visible to those you shared it with.
- authorities — when a law, court order, or enforceable request genuinely requires it, no wider than required.
- a successor — if the service changes hands or form, your data may move with it under the same protections, and you will be told.
7where it lives
plain-language summary: on servers in the european union.
Primary infrastructure runs in the European Union (Hetzner, Germany and Finland). Where a processor operates outside the European Economic Area, transfers rest on recognised safeguards — an adequacy decision or standard contractual clauses — and we keep those transfers as narrow as the task allows.
8how long we keep it
plain-language summary: for the life of your entry, plus a short backup horizon. then it goes.
We keep your data for as long as your entry is open, plus the short horizon of rotating backups. Security and diagnostic logs are kept briefly and then deleted or anonymised. When your entry closes, we delete or anonymise your personal data within 30 days plus the backup cycle, except what the law makes us keep — and that, only for as long as it makes us.
9how we protect it
plain-language summary: keys instead of passwords, encryption in transit, tight access. honest limit: no system is invulnerable.
Protection is built into the shape of the service: passkeys instead of passwords, encryption in transit, isolation between systems, access limited to what each part needs, and regular backups. We work to protect your data seriously and continuously — and we say honestly that no system is invulnerable, and we cannot promise absolute security.
10your rights
plain-language summary: see it, correct it, take it, erase it, object to it — and complain to the authority if we fail you.
Under the GDPR and Czech law you have the right to:
- access your personal data, and receive a copy;
- rectify what is inaccurate;
- erase what we no longer need to hold;
- restrict processing while a question is resolved;
- object to processing based on legitimate interests;
- portability — take the data you provided in a machine-readable form;
- withdraw consent at any time, for anything based on consent.
Write to lnk@gradientrising.com and we will answer within one month. You also have the right to complain to a supervisory authority — in the Czech Republic, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz), or the authority of the country where you live.
11cookies
plain-language summary: only the cookies that keep you in. no trackers, no ads — which is why there is no cookie banner.
The service sets only strictly necessary cookies: session and security cookies that keep your entry open and safe. There are no advertising cookies, no cross-site trackers, and no third-party analytics riding along. Because nothing beyond the essential is set, no cookie consent is asked for — there is nothing to consent to.
12children
plain-language summary: the service is not for children under 15.
The service is not directed to children under 15 years of age, and we do not knowingly hold their data. If we learn that an entry belongs to a child below the required age, we will close it and delete the data. If you believe a child is using the service, tell us.
13changes
plain-language summary: this page carries the current date. material changes get a heads-up.
We may update this policy as the service evolves. The effective date at the top always shows the current version. For material changes we will give notice within the service, or by other reasonable means, before they take effect.
14contact
plain-language summary: one address. a person reads it.
For anything in this policy — questions, requests, rights, worries — write to lnk@gradientrising.com. Postal contact details are available on request.