Company
NET-LINE Online-Dienste GmbH, Wannenäckerstr. 25, D-74078 Heilbronn
Privacy
Yieeha only asks for data needed for sign-in, verification, security and operation.
For privacy questions, you can reach us directly through the contact address below.
Controller
This entity determines the purposes and means of the processing described here.
NET-LINE Online-Dienste GmbH, Wannenäckerstr. 25, D-74078 Heilbronn
privacy@yieeha.app
This notice covers the Yieeha website and the app features released at the relevant time.
Legal bases
The applicable legal basis depends on the feature and purpose. Optional information and device permissions remain voluntary.
GDPR Article 6(1)(b) for account, sign-in, messaging, media, linking and explicitly started calls where needed to provide the selected feature.
GDPR Article 6(1)(f) for IT security, abuse prevention, reliable delivery, diagnostics and support. Our interest is secure, stable and accountable messaging; conflicting interests are considered in each case.
GDPR Article 6(1)(c) where statutory retention, disclosure or evidence duties require processing.
GDPR Article 6(1)(a) where we expressly request consent for optional processing. Consent can be withdrawn at any time with future effect.
Without identifiers required for the account, recipient and delivery, the relevant messaging feature cannot be provided. Denied camera, microphone or push permissions only limit the corresponding optional feature.
Principles
These principles apply to the website and shape the app interface too.
Only information required for sign-in, verification, security and product operation is requested.
There is no address-book access, no contact permission and no silent contact import.
When email or phone number are used, the purpose is explained briefly, clearly and directly.
Data we process
The data involved depends on the features you actually use.
User ID, email address, optional phone number and linked sign-in methods for sign-in, verification, recovery and account linking.
The sign-in methods offered by Yieeha are explained directly in the app. Only information required for sign-in, verification and account linking is processed.
Message text and images, videos or voice messages you choose. Camera and microphone are used only after you start a capture or call.
Audio/video data during a call plus call offer, call state, QR challenge and producer delegation for setup, delivery, billing safety and revocation.
If you use a paid live call, we process the coin balance, displayed price or coins per minute, debited coin cents, transaction and offer identifiers, timestamps, and billing/refund evidence that is required. The current Android Play version does not offer coin or paid-media purchases or external payment links.
Installation ID, a pseudonymous device identifier derived from the Android ID, app version, device model, operating-system version and push token for device management, notifications, abuse prevention and troubleshooting.
Reports, blocks, mutes and limited security/error logs for abuse prevention, investigation and reliability.
Purposes & recipients
We do not sell personal data or use it for third-party advertising or data brokerage.
Processing for sign-in and recovery, messaging, media upload, push delivery, QR linking and audio/video calls.
Billing data is used to show the price before a live call, perform debits atomically and accountably, prevent duplicate charges, process required refunds, and meet statutory accounting or evidence duties.
Processing to fulfil deletion requests, prevent and investigate abuse and diagnose technical failures.
When you choose “Continue with Google”, your device or browser and our sign-in service exchange the technically required OAuth/OpenID data with Google Ireland Limited. Mesavo requests only the openid, email and profile scopes, uses them solely for sign-in and account linking, and receives neither your Google password nor access to contacts or other Google services.
Data is processed only as needed by contracted providers for hosting/databases, sign-in and delivery, push, media/call transport and security logs. They act under our instructions and safeguards.
Some sign-in, push or device-platform providers may process data outside the EEA. Where this occurs, transfers rely on an applicable adequacy decision or appropriate safeguards such as EU Standard Contractual Clauses. Information about specific safeguards and copies is available via privacy@yieeha.app.
Disclosure to authorities or others occurs only when legally required or needed to protect rights and safety.
Retention & protection
Retention depends on the data category, user choice, security needs and legal obligations.
Account deletion is processed by data category. Deletable account data, messages and media are deleted or anonymised after verified completion. Categories retained for legal, security or evidentiary reasons remain for their applicable period; backups expire under their related protection and rotation periods.
Coin and call billing data is handled separately from deletable communication content. It is retained only as long as required for open debits or refunds and statutory accounting, tax, fraud-prevention, or evidence duties, and is then deleted or anonymised under the applicable rule.
Unused QR challenges expire after five minutes. Device/push registrations and producer links remain active only until sign-out, revocation, invalidation or verified processing in the account-deletion workflow.
Security, delivery and error logs are kept only for each service's limited operational retention period and then deleted or aggregated unless a specific security or legal case requires longer preservation.
Transport protection, role/purpose-bound access, short-lived tokens, revocable device/QR links and protected secrets limit access. App tokens are stored in protected device storage.
Data subject rights
You can exercise your rights directly through the privacy contact. Account and deletion processes are also available in the app.
You can request information about personal data being processed and obtain a copy.
You can have inaccurate data corrected, restrict processing where the legal conditions apply, and receive provided data in a portable format.
The app accepts a confirmed deletion request for processing with HTTP 202 Accepted and provides a receipt status that can be checked without signing in. This is not proof of completion; without complete cross-store and Apple evidence, the status remains manual-review-required. An email request is available without app access.
You can object to processing based on legitimate interests for reasons relating to your particular situation. Consent can be withdrawn at any time with future effect.
Requests concerning any of these rights go to privacy@yieeha.app.
You may lodge a complaint with a data-protection supervisory authority. For the company seat, the Baden-Württemberg State Commissioner for Data Protection and Freedom of Information is available in particular.