Skip to main content

MeForYou

Privacy Policy

Last updated: 24 September 2026

Who handles your information

MeForYou is operated by FOP Sergii Petrovych Udovychenko, an individual entrepreneur registered in Ukraine. Contact: serhiyudovychenko@gmail.com. See our contact page for safe ways to describe a problem.

This policy covers creating and receiving surprises or remembrances and contacting us. Visitors can use a private link without an account, but the service still processes information as described below.

Accounts and Google sign-in

We use your email and account identifier to sign you in and associate surprises with your account. Google sign-in provides basic account information, which may include your name, email, profile picture and provider identifier. Supabase, our authentication provider, stores account and sign-in information. We use this for authentication and account management. MeForYou does not request access to your Gmail messages or Google Drive files.

You can remove MeForYou’s access in your Google account settings. This does not delete information already stored by MeForYou; contact us to request account deletion.

Moments, remembrances and visitor activity

We store labels such as a recipient or remembered person’s name, the selected destination and coordinates, availability times, meeting instructions, stories, messages and uploaded media submitted by creators. A Remembrance is the creator’s contribution; it is not presented as communication from the remembered person. Only share personal information and media you have permission to share.

We store activity such as link opening, approximate proximity milestones, arrival, unlocking, reactions and starting a return surprise. Creators can see relevant status information. A private link or generated QR acts as an access key: anyone who obtains it may use the visitor experience and unlock content if the conditions are met. It is not an identity or family-relationship check.

Location and maps

When you choose to use your location, your browser asks for permission. A creator’s selected destination is saved with the moment. For visitors, a location-check or unlock control sends a fresh reading, reported accuracy and timestamp to our server to check distance and availability. A creator can instead allow a moment to open without a location check.

The visitor database does not store raw GPS samples or route history. It stores derived activity and session information. Creators do not receive your exact live coordinates from these checks. We do not continuously track your location in the background. You can deny or withdraw browser location permission, but location-gated unlocking will then be unavailable.

Place searches send search text to OpenStreetMap’s Nominatim service through our server. Map tiles load from OpenStreetMap in your browser, exposing connection information such as your IP address and requested map area to that provider. See the OpenStreetMap Foundation privacy policy.

Browser storage, saved drafts, diagnostics and analytics

Authentication uses cookies. A recipient session cookie recognises an unlocked session and helps limit repeated actions. While a signed-in creator is composing a moment, we keep a local copy in the current browser tab and save the draft to the creator’s account so it can be resumed on another device. A saved draft can include names, locations, schedules, messages and references to uploaded media. Creators can delete drafts from My moments; deleting a draft also requests removal of its unattached uploads. Clearing browser storage can remove only the local copy or end a session; it does not delete an account draft.

Vercel hosts the site and provides web analytics on non-recipient pages. Our application excludes private recipient routes from Vercel Analytics. Hosting and authentication providers may process IP addresses, browser information, request metadata and operational logs to deliver and protect the service.

When optional PostHog analytics is enabled, it sends allowlisted page categories and action names, sign-in method, surprise type, timing type, photo presence and broad error categories, browser and major version, operating system, device type, primary browser language, window-size category, app release and allowlisted referral/UTM categories only after you allow it in Privacy settings. You can decline or turn it off using the preferences at the bottom of any page without losing access. We store your choice in local storage and a consent cookie, and use a random identifier and the first consented referral/allowlisted UTM categories in session storage to connect actions within the current tab across reloads. It expires after 30 minutes of inactivity or 24 hours, and is cleared when you withdraw consent. Closing the tab normally clears session storage, although browser session restoration or tab duplication may preserve it. After consent, a short-lived, one-use sign-in completion cookie contains only the provider category and is consumed without sending analytics if consent is absent. After consent, our hosting provider Vercel supplies approximate country and city inferred from the network IP address. These can be inaccurate, particularly with VPNs or mobile networks; they are not GPS or the surprise destination. A same-origin request obtains only these coarse fields, held in memory for this tab session (refetched after a reload); our application does not store them in its database or include raw IP addresses in analytics payloads. They may be unavailable. Attribution begins on the first measured page after consent, survives reloads in the same tab, and is removed when consent is withdrawn or the session expires. A missing referrer is labelled direct or unknown, not proof of a direct visit. We do not send PostHog private links, content, names, emails, coordinates or account identifiers, and do not record sessions or automatically collect clicks. Your browser’s Do Not Track or Global Privacy Control signal disables this collection. Withdrawal stops new events, not information already sent. Our PostHog project is hosted in the US. PostHog can still receive your network IP address and ordinary connection headers; we enable discarding client IP data in the project. Optional action analytics relies on your consent. Sentry error monitoring, when configured, removes sensitive request and user context. These safeguards do not mean all infrastructure logs are anonymous.

Purposes and service providers

We process information to deliver requested features, authenticate creators, store and reveal surprises or remembrances, prevent abuse, diagnose failures and answer support requests. Where applicable law requires a legal basis, providing the service relies on performing our agreement with you; security and support rely on legitimate interests subject to your rights; and compliance with binding legal duties relies on those duties. Where consent is required for optional processing, it must be obtained before that processing.

Providers include Supabase for authentication, database and file storage; Vercel for hosting and web analytics; Google when you choose Google sign-in; OpenStreetMap for maps and search; and PostHog or Sentry when enabled. We may disclose information where required by law or necessary to investigate misuse. We do not sell private surprise or remembrance content.

Providers may process information outside your country. Applicable protections and transfer requirements depend on your location and provider arrangements. Contact us with questions about providers or safeguards relevant to your information.

Retention and deletion

New Free surprises and remembrances allow visitor access for 72 hours from creation. When that period ends, the private link is paused and a 30-day owner recovery period begins. The creator can still review, revoke or delete the moment during recovery. Eligible moments can be extended with a one-time purchase for the duration shown before checkout. This is not a promise of permanent or lifetime storage. Earlier surprises created before this policy was activated may retain their previous access terms.

Delete moment immediately removes it from the creator’s list and revokes its link and generated QR destination. Its private content and uploaded files are queued for permanent removal, normally within 24 hours. Revocation alone does not delete content, create a replacement link or recall copies someone has already saved. An unlock timing deadline and the Free keeping period are separate controls.

Visitor sessions expire after 24 hours. Expired session records are cleaned up when that moment is accessed again. When a Free moment reaches the end of its 30-day recovery period, its private text and uploaded media are queued for permanent removal. Active account drafts protect their attached uploads from routine orphan cleanup. Deleting a draft requests removal of those unattached uploads; uploads no longer attached to a current draft are normally removed after 24 hours.

Email us to request deletion of your account, a privacy review of a remembrance, or removal of remaining metadata. We will assess the request, verify ownership or authority where needed and explain any information retained for security or legal reasons. Backups and provider logs may remain until their retention cycles end.

Your choices and rights

Depending on applicable law, you may have rights to access, correct, delete or receive a copy of your personal data, restrict or object to processing, withdraw consent, or complain to a competent data-protection authority. Contact us to exercise a right or raise a concern. We may need proportionate information to verify your request. Do not send passwords, sign-in links or private moment links in your initial email.

Creators can edit, revoke and remove moments in My moments. Visitors can stop using a link, decline location permission, choose not to react and report content from the reveal page. MeForYou is not end-to-end encrypted: authorised service infrastructure processes content to deliver the experience.

Changes

We will update this page when practices change and provide appropriate notice of material changes. Our Terms of Use explain safe use of the service.

Additional analytics context

With analytics consent, event properties may also include the surprise purpose, location mode, broad unlock-radius and media categories, and a bounded recipient entry method such as direct link, generated QR, pasted link, camera scan or QR image. They may also include the session entry page, event order and broad session age, plus color scheme, reduced-motion and display-mode preferences and broad connection and local-time categories. These are bounded categories rather than private content, exact times, URLs or coordinates.

Private by design

No account needed to receive. Keep your link private and share only with who you choose.

Location-based surprise

Leave a message, photo or media at a real place. They arrive and unlock what you left.

Create a remembrance

Leave a calm, private memory connected to a place that mattered.

MeForYou

Leave something meaningful, somewhere that matters.

Private messages, photos and memories at real places — for the people who matter most.

Create your first memory

Choose a place, leave a message and give someone a moment they’ll always remember.

Get started

© 2026 MeForYou. All rights reserved.

🇺🇦 Built in Ukraine, creating meaningful moments worldwide.