hour4hour is a services-only time bank. This policy explains exactly what we collect about you, why we collect it, and how you can delete it. We do not sell your data, and we do not run advertising trackers.
What we collect
We collect only what's needed to run the app and connect you with other members:
| Data | Why we collect it |
|---|---|
| Account email | Sign-in via passwordless magic link (Supabase Auth). We never store a password. |
| Display name, bio, city | Shown on your profile so other members know who they're trading with. |
| Approximate location | Used to show nearby listings within a search radius. We do not store or display your exact address. |
| Listings, proposals, and messages | The content you write to offer, request, negotiate, and coordinate exchanges. |
| Credit ledger entries | An append-only record of hours earned and spent, so balances stay accurate and auditable. |
| Device push token | Used through Apple's Push Notification service (APNs) to notify you of new proposals, messages, and confirmations. |
| ID verification document (optional, in-person only) | Uploaded to private storage and reviewed by a hour4hour operator before you can meet another member in person. Your ID image is never shown to other members and is deleted on request. |
What we don't do
- We do not run advertising trackers or third-party ad networks in the app.
- We do not sell your personal data to anyone, for any reason.
- We do not display your ID document to other members — it's reviewed by an operator only, for verification purposes.
- We do not have a way to convert credits to cash, so there's no financial account data tied to your credit balance.
Finding people you know
hour4hour can optionally show you which of your phone contacts are already members. When you run this search, your device turns each phone number and email in your contacts into a one-way SHA-256 hash — never the raw number, email, or name — and only those hashes are sent to our server for comparison; they are not stored afterward. A hash can only match a member who separately opted in by turning on “Let contacts find me,” which stores a hash of your own number and email so others can find you the same way. Matching is opt-in on both sides: running the search is your choice, and being found requires the other member’s own toggle. You can turn “Let contacts find me” off at any time from the Find People screen, which immediately stops your hashes from being used in future matches; deleting your account, described above, removes any stored hashes along with the rest of your profile.
Where your data lives
hour4hour is built on Supabase, hosted in a United States data region. Supabase acts as our data processor for authentication, database storage, and file storage (including ID verification documents). Push notifications are delivered through Apple's Push Notification service (APNs).
How long we keep it
Your profile and ledger data is kept as long as your account is active. The credit ledger is append-only by design — individual entries aren't deleted, since they form the historical record of completed exchanges — but it is not shared with anyone outside of your own account view and operator support.
This is not tax advice. You may need to report the value of services you receive.
Deleting your account and data
You can request full account deletion at any time by emailing yiana00@gmail.com. We'll remove your profile information, uploaded ID document, and personal contact details. Ledger entries tied to completed exchanges with other members may be retained in de-identified form to keep other members' records accurate.
Children's privacy
hour4hour is intended for members 18 and older. We do not knowingly collect information from anyone under 18.
Changes to this policy
If this policy changes in a meaningful way, we'll update the effective date above and, where appropriate, notify you in the app.
Contact us
Questions about this policy or your data? Email yiana00@gmail.com.