We do not sell personal data. The current product has no targeted-ad system, public attendee list, people-nearby radar, continuous location tracking, movement history, or public phone-number surface.
Who runs Nearmigo
Nearmigo is operated by Mohit Karnawat, an individual operating the Nearmigo service. For a privacy question, request, or complaint — including before you sign in, or after you have deleted your account — write to nearmigo.com/contact. Once signed in, Help & feedback in You reaches the same people.
Information the service processes
- Account: your phone number, one-time-code and session records, account identifiers, and security/rate-limit records. Your phone number identifies the account and is not shown to other people. For return-account safety, Nearmigo may keep a protected, non-public key derived from the number so blocks and safety standing can still work after an account is deleted or returns. The raw number is not stored in that key, and the key is never used for ask discovery or matching.
- Profile and content: the name, optional photo and story you add; asks, responses, chats, drafts, city/place labels, events, blocks, hides, notification choices, and account settings; and private Support threads and optional Support images.
- Safety: reports, moderation results and categories, the explanation a reporter supplies, and the exact content needed to review a report. A conversation report preserves both people’s messages from the beginning of that conversation through the moment the report is filed; later messages are not included. Nearmigo does not accept reporter-uploaded screenshots or other report images.
- Service operation: standard request/device metadata processed by our hosting, authentication and security providers. Nearmigo operational logs are designed not to contain ask text, place queries, provider IDs, tokens, or raw coordinates.
- Optional device notifications: if you turn them on, a private browser Push endpoint, public encryption key, and authentication secret used for that subscription.
Phone sign-in security
Nearmigo uses phone one-time codes for sign-in. When the anti-abuse check is enabled, Cloudflare Turnstile may process browser, device, and network signals to decide whether a code request appears human. The short-lived Turnstile response is sent with that code request to Supabase Auth for verification. Nearmigo does not put the response in browser storage, a URL, or an application log, and a fresh response is required for each initial or repeated code request.
Cloudflare handles that check under the Cloudflare Privacy Policy.
Drafts saved on this device
To survive a refresh or an uncertain connection, unfinished ask and private-Search drafts may stay in account-keyed storage on this device for up to 48 hours. An unfinished chat message and its exact retry key stay only in this browser tab’s session storage. Draft words are not sent to another person or an AI provider until you deliberately submit the relevant action. Signing out or deleting the account clears this account’s saved recovery data from the current device; closing the tab also clears the chat draft.
AI reading, moderation, and matching
The service currently uses Anthropic for structured reading, OpenAI for independent safety moderation, and Voyage AI for embeddings and relevance reranking. New shared city/place/event labels and uploaded photos also receive safety moderation. Approved public text may be converted to server-side embeddings used to nominate relevant asks. Search text remains private to its owner; identity, photos, phone numbers, exact location, reports, and moderation evidence are excluded from matching embeddings. Providers may change as the service changes; this notice will be updated when that materially affects how information is handled.
Ordinary private-chat words are not sent to an AI provider or human reviewer simply because they are sent. The service computes a private one-way repetition fingerprint that can open a human-review pattern signal without including those words. If someone makes a report, the exact reported message may be checked for safety. The complete held conversation and the reporter’s own explanation are available only to authorized human safety reviewers; they are not sent to an AI provider as one conversation and are not automatic evidence against either person. A whole-conversation report sends no chat message to AI.
AI can be wrong. Safety gates fail closed when required providers are unavailable, and people can block, hide, decline, or report regardless of an automated result.
Optional place and location features
Typed place search
If Google Places is configured, text you type after the local catalog is checked can be sent to Google Autocomplete. Suggestions and Google display/address/type content stay transient. If you confirm a result, Nearmigo stores the full Google Place ID and a label you wrote and confirmed separately—not a copied Google display label.
Use location once
Location is requested only after you tap the one-shot control and your browser grants permission. One foreground latitude/longitude fix goes to the server and, when configured, the location provider only long enough to name nearby canonical places. Nearmigo does not return it to the UI, put it in a URL or token, store it in product tables, log it, subscribe to movement, or call watchPosition. Denying permission leaves local search and manual entry available.
Google processes provider requests under the Google Privacy Policy. A contracted or self-hosted OpenStreetMap-based provider may be used instead; public OSMF Nominatim is disabled in this deployment.
Optional device notifications
Notifications are off until you choose to turn them on. Nearmigo stores the browser subscription as private capability material and routes an encrypted, generic knock through the push provider used by your browser or operating system (for example Apple, Google, Microsoft, or Mozilla). The push payload contains no person, ask, response, message, matching, place, search, or identifier content. The signed-in app opens its private Activity or conversation to learn what changed.
Turning notifications off attempts to remove both this browser’s subscription and its exact server record. Deleting the account removes every server-side subscription owned by it. A browser push provider may keep its own security or delivery logs on its schedule; Nearmigo does not use Push for continuous location or activity tracking.
Private Support
Signed-in Support is private to you and authorized service operators. You may optionally attach up to three images to a request. The upload path removes embedded image metadata and enforces file, byte, pixel, and safety limits before private storage; neither the browser nor an operator receives a raw storage path or public URL. Operators access an image only through a bounded, reauthorized byte proxy. Support images are not public, are not used for matching, and are not the reporter-uploaded evidence prohibited in the reporting flow.
Who receives information
We use service providers only to operate the product, including:
- Supabase for authentication, database, storage, realtime, and Edge hosting;
- an SMS delivery provider for phone one-time codes;
- Cloudflare Turnstile for phone sign-in abuse checks when enabled;
- configured AI providers for reading, moderation, and embeddings;
- Google Places or an explicitly configured map provider when you use those features; and
- your browser or operating system’s push provider when you opt in to device notifications.
We may also preserve or disclose limited information when reasonably necessary to investigate abuse, protect people, comply with valid legal process, or defend legal rights. This is not a promise to retain every report or disclose it automatically.
Retention and deletion
Different records have different product lifetimes. Expiring contexts and lookup proofs are short-lived; completed queue receipts are pruned; and words from a stopped private Search are redacted after the configured retention window (currently 30 days). Content you deliberately publish or send can remain while it is needed for discovery, a conversation, safety review, or service integrity. When a response is accepted, the exact ask and context that person responded to become private conversation context for both participants. That snapshot and the retained response/message can remain in the counterpart’s thread even if the ask is later edited or closed.
You can delete your account from Account settings. Deletion first disables the account and atomically scrubs the live profile and session authority, then resumable, bounded cleanup pages remove owned product records and private storage before the final authentication row is removed. This keeps deletion immediate for privacy without making one large cascade a condition of signing out the account. Support threads and optional Support images remain private while a request is active. A resolved or closed request is retained for up to 90 days for continuity and abuse handling, then its words and image authority enter exact bounded cleanup. Account deletion starts that same cleanup immediately; private object authority is retained only until storage absence is verified, so a failed or late storage action cannot strand bytes without a cleanup receipt. A person you chatted with keeps the conversation text, including any accepted ask/context snapshot and retained response, in a closed, half-deleted thread. Your identity, profile and ability to send are removed, and the counterpart sees a neutral unavailable state without your identity or the reason. Removed messages show a tombstone instead of keeping a second stale copy. The conversation bridge exposes no ask, response, message, member, Place, or matching-evidence identifier. If a conversation was reported, its exact report-time prefix can remain privately held for the open review and, under the current policy, for 90 days after the final decision. Later chat messages are outside that hold. Account deletion, participant-side removal, or a later edit does not rewrite the held safety record; access is limited to authorized reviewers and every transcript page they open is logged. Backups and provider security logs may expire on their own controlled schedules.
Your choices
- Do not grant location permission; typed and manual paths remain.
- Edit profile and notification choices, leave a place context, or close an ask.
- Block, hide, decline, report, or sign out other devices.
- Delete the account from Account settings.
- Use Help & feedback in You for access, correction, deletion, or privacy questions.
Adults, security, and changes
Nearmigo is intended for adults and requires adult confirmation. We use access controls, row-level database rules, private storage, scoped server functions, rate limits, and moderation, but no internet service can promise absolute security. We may update this notice as the product or its providers change; a material update will receive a new effective date and an appropriate in-product notice.