1. Data controller
- The controller of personal data of users of the BeMyF app is IC SOFTWORKS SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ with its registered office in Krakow, at ul. Adama Vetulaniego 5A / 148, 31-226 Krakow, entered in the register of entrepreneurs of the National Court Register under KRS number 0001238658, NIP: 9452331059, REGON: 544882763.
- The controller can be contacted by e-mail at: kontakt@icsoftworks.pl.
- This Privacy Policy explains what data we process, why we process it, how long we store it and what rights users have.
2. Scope
- This Privacy Policy applies to the BeMyF app, user accounts, community features, chat, photos, coins, reports, blocks and other features available in the app.
- BeMyF is an app intended only for adults who are at least 18 years old.
- Minors may not use the app.
3. What data we may process
Depending on how the app is used, we may process the following categories of data:
- Account data:
- e-mail address,
- user identifier,
- first name,
- last name,
- username,
- information about adulthood confirmation,
- account status,
- e-mail verification status,
- information whether the account is a Creator/F'ka account.
- Profile data:
- profile picture,
- profile description,
- short description,
- social media provided by the user or Creator,
- Creator photo gallery,
- access price set in coins.
- Communication data:
- text messages,
- photos sent in chat,
- information about conversation participants,
- message sending time,
- message read status,
- history of access to Creator profiles and chats.
- Coin and payment data:
- coin balance,
- coin purchase history,
- history of coin use in the app,
- information about purchased packages,
- transaction identifiers,
- information necessary to verify purchases through Apple App Store or Google Play,
- information about voluntary support for Creators,
- identifier of the user sending support,
- Creator identifier,
- number of coins used,
- event time,
- information necessary to settle the Creator program.
- Data concerning access to Creator profiles:
- user identifier,
- Creator identifier,
- access status,
- start date,
- end date,
- number of months of access,
- number of coins used for access or extension.
- Report and moderation data:
- reporting user,
- reported user,
- reported message or conversation,
- report reason,
- report description,
- report status,
- moderation actions,
- information about blocks.
- Technical and safety data:
- push notification token,
- device and platform information,
- technical logs,
- data necessary for Firebase, App Check and notifications to work,
- information about errors and technical events, if processed.
- Account deletion data:
- deletion request date,
- account e-mail address,
- information needed to confirm the user's identity,
- request status.
4. Passwords and login
- Login and authentication in the app are handled by Firebase Authentication.
- The Controller does not store the user's password in plain text.
- The user is responsible for keeping their password and access to the device used with the app confidential.
5. Purposes of data processing
We process user data for the following purposes:
- creating and maintaining the account,
- enabling login,
- verifying the e-mail address,
- confirming adulthood,
- displaying the user's or Creator's profile,
- enabling communication between users,
- handling photos, galleries and messages,
- handling coins and in-app purchases,
- verifying transactions made through Apple App Store or Google Play,
- handling access to Creator profiles,
- handling voluntary support for Creators, recording coin use and calculating Creators' revenue share in accordance with the Creator program rules,
- sending push notifications,
- handling reports, blocks and moderation,
- counteracting abuse, scams, spam and safety violations,
- enforcing the Terms and Community Standards,
- fulfilling account and data deletion requests,
- contacting the user,
- performing legal obligations,
- pursuing claims or defending against claims,
- ensuring stability, security and operation of the app.
6. Legal bases for processing
Depending on the purpose of processing, data may be processed on the basis of:
- performance of a contract or taking steps before entering into a contract,
- legal obligations imposed on the Controller,
- the Controller's legitimate interest, such as safety, moderation, prevention of abuse, pursuing claims and ensuring operation of the app,
- the user's consent, if required in a given case, for example for certain notifications or system permissions.
7. Push notifications
- The app may send push notifications, for example about new messages or events in the app.
- Push notifications may require the user's system consent.
- The user may disable notifications in the device settings.
- An FCM token linked to the user's device may be used to handle notifications.
8. Private messages and reports
- Private messages are part of the app's communication feature.
- The Controller does not treat messages as public.
- Messages may, however, be technically processed, stored, delivered to recipients and analyzed in the event of a report of a violation, safety threat, suspected scam, abuse, violation of law, violation of the Terms or Community Standards.
- If a user reports a message, the Controller may process the content of the reported message, the context of the report and data of users connected with the matter.
9. Photos and media
- Users may send photos in chat, and Creators may add profile pictures and galleries.
- Photos are processed to operate app features, display profiles, support communication and moderation.
- The user should publish only photos to which they have rights and which do not violate privacy, law or app rules.
- Photos violating the Terms, Community Standards or law may be removed.
10. Coins and payment data
- Coin purchases are handled by Apple App Store or Google Play.
- The Controller may process information necessary to confirm a purchase, add coins to the account, prevent abuse and handle complaints.
- The Controller does not store the user's full payment card data.
- Payment data may be processed by Apple or Google in accordance with their own rules.
- Coins are a digital unit used only in the BeMyF app.
- When the voluntary support feature is used, the Creator may receive information in the app about the name or username of the supporter and the number of coins used for support. The Creator does not receive payment card data or access to the user's payment account.
11. External services and technology providers
To operate the app, we may use external services, in particular:
- Firebase Authentication — user login and accounts,
- Cloud Firestore — app database,
- Firebase Storage — storage of photos and attachments,
- Firebase Cloud Messaging — push notifications,
- Firebase App Check — app protection,
- Firebase Cloud Functions — backend logic,
- Apple App Store — handling purchases on iOS,
- Google Play — handling purchases on Android,
- providers of BeMyF website hosting,
- e-mail providers used to contact users.
If in the future the app starts using additional tools such as analytics, crash reporting, advertisements or advertising SDKs, the Privacy Policy should be updated.
12. Who we may share data with
Data may be shared with:
- technical service providers necessary for the app to operate,
- app store operators for payment handling,
- entities providing hosting, mail, infrastructure or security services,
- persons authorized by the Controller,
- public authorities, if required by law,
- entities supporting the Controller in pursuing claims or defending against claims.
13. Transfers of data outside the European Economic Area
- Some technology services used by the app may involve processing data outside the European Economic Area.
- In such cases, the Controller applies appropriate safeguards required by data protection law, in particular mechanisms offered by service providers, standard contractual clauses or other legally permitted bases for data transfer.
14. Data retention period
- Account data is stored for the duration of the account's existence.
- Data concerning transactions, payments, complaints, settlements or legal obligations may be stored for the period required by law or the period needed to pursue claims and defend against claims.
- Messages, photos and other User Content are stored for the period needed for the app to operate, unless they are deleted earlier or there is a basis for further storage.
- Reports, blocks, violations and moderation data may be stored for the period needed to ensure safety, prevent abuse and defend against claims.
- After account deletion, data is deleted or anonymized unless law or justified safety, accounting or legal purposes require further storage.
15. Account and data deletion
- The user may request deletion of the account and data.
- The request may be submitted through the feature available in the app or by contacting the Controller at: kontakt@icsoftworks.pl.
- The Controller may require confirmation of the user's identity, for example by sending a message from the e-mail address linked to the account.
- We fulfill account deletion requests without undue delay, usually within up to 30 days, unless law or special circumstances require a longer period.
- Some data may be retained in anonymized or restricted form if necessary for legal, accounting, safety, abuse prevention or claims-related reasons.
16. User rights
The user has rights resulting from personal data protection law, in particular:
- the right of access to data,
- the right to rectification of data,
- the right to deletion of data,
- the right to restriction of processing,
- the right to data portability,
- the right to object to processing,
- the right to withdraw consent if processing is based on consent,
- the right to lodge a complaint with the competent supervisory authority.
In Poland, the supervisory authority is the President of the Personal Data Protection Office.
17. Data security
- The Controller applies organizational and technical measures intended to protect user data against unauthorized access, loss, change or disclosure.
- Access to data is limited to people and services that need it to perform specific purposes.
- The user should also take care of the security of their account, password and device.
18. Data of minors
- The BeMyF app is intended only for adults.
- We do not knowingly collect data of people under 18 years of age.
- If we have a justified suspicion that an account belongs to a minor, we may verify, limit, block or delete it.
- Reports concerning the potential involvement of minors are treated as a priority.
19. No advertising or advertising analytics
- As of the publication date of this version of the Privacy Policy, the app does not use advertisements or external advertising SDKs.
- If advertisements, advertising analytics, tracking tools or similar technologies are added in the future, the Privacy Policy will be updated.
20. No external artificial intelligence services
As of the effective date of this version of the Privacy Policy, the BeMyF app does not use external artificial intelligence services to process messages, photos, profile data or other users' personal data.
The onboarding conversation with Oliwka visible in the app is a static, previously prepared tutorial. Replies are stored in the app and are not generated by an external AI model.
Messages, photos, profile data or other users' personal data are not sent to an AI service provider.
If BeMyF starts using external AI services in the future, users will receive the required information, the Privacy Policy will be updated, and consent will be obtained to the extent required by law and platform rules.
21. Changes to the Privacy Policy
- The Privacy Policy may be updated, in particular in the event of changes to app features, technology providers, law or Apple App Store and Google Play requirements.
- The user may be informed about material changes in the app or electronically.
- The current version of the Privacy Policy is available in the app and in the BeMyF Help Center.
22. Contact
For matters concerning privacy, personal data, account deletion or safety, the Controller may be contacted at: kontakt@icsoftworks.pl.