Yieeha

Privacy

Data minimization is part of the product logic, not just legal copy.

Yieeha only asks for data needed for sign-in, verification, security and operation.

For privacy questions, you can reach us directly through the contact address below.

Controller

NET-LINE Online-Dienste GmbH

This entity determines the purposes and means of the processing described here.

Company

NET-LINE Online-Dienste GmbH, Wannenäckerstr. 25, D-74078 Heilbronn

Scope

This notice covers the Yieeha website and the app features released at the relevant time.

Principles

What Yieeha stands for

These principles apply to the website and shape the app interface too.

Minimal data collection

Only information required for sign-in, verification, security and product operation is requested.

No contact sync

There is no address-book access, no contact permission and no silent contact import.

Transparent auth explanations

When email or phone number are used, the purpose is explained briefly, clearly and directly.

Data we process

Accounts, communication, devices and user-initiated calls

The data involved depends on the features you actually use.

Account & sign-in

User ID, email address, optional phone number and linked sign-in methods for sign-in, verification, recovery and account linking.

Sign-in methods

The sign-in methods offered by Yieeha are explained directly in the app. Only information required for sign-in, verification and account linking is processed.

Messages & media

Message text and images, videos or voice messages you choose. Camera and microphone are used only after you start a capture or call.

Calls & linking

Audio/video data during a call plus call offer, call state, QR challenge and producer delegation for setup, delivery, billing safety and revocation.

Coins & call billing

If you use a paid live call, we process the coin balance, displayed price or coins per minute, debited coin cents, transaction and offer identifiers, timestamps, and billing/refund evidence that is required. The current Android Play version does not offer coin or paid-media purchases or external payment links.

Device & push

Installation ID, a pseudonymous device identifier derived from the Android ID, app version, device model, operating-system version and push token for device management, notifications, abuse prevention and troubleshooting.

Safety

Reports, blocks, mutes and limited security/error logs for abuse prevention, investigation and reliability.

Purposes & recipients

Product operation without advertising tracking

We do not sell personal data or use it for third-party advertising or data brokerage.

Product functions

Processing for sign-in and recovery, messaging, media upload, push delivery, QR linking and audio/video calls.

Call billing

Billing data is used to show the price before a live call, perform debits atomically and accountably, prevent duplicate charges, process required refunds, and meet statutory accounting or evidence duties.

Safety & support

Processing to fulfil deletion requests, prevent and investigate abuse and diagnose technical failures.

Google sign-in

When you choose “Continue with Google”, your device or browser and our sign-in service exchange the technically required OAuth/OpenID data with Google Ireland Limited. Mesavo requests only the openid, email and profile scopes, uses them solely for sign-in and account linking, and receives neither your Google password nor access to contacts or other Google services.

Google Identity

Contracted service providers

Data is processed only as needed by contracted providers for hosting/databases, sign-in and delivery, push, media/call transport and security logs. They act under our instructions and safeguards.

International transfers

Some sign-in, push or device-platform providers may process data outside the EEA. Where this occurs, transfers rely on an applicable adequacy decision or appropriate safeguards such as EU Standard Contractual Clauses. Information about specific safeguards and copies is available via privacy@yieeha.app.

Legal disclosure

Disclosure to authorities or others occurs only when legally required or needed to protect rights and safety.

Retention & protection

Only as long as needed for each purpose

Retention depends on the data category, user choice, security needs and legal obligations.

Account & content

Account deletion is processed by data category. Deletable account data, messages and media are deleted or anonymised after verified completion. Categories retained for legal, security or evidentiary reasons remain for their applicable period; backups expire under their related protection and rotation periods.

Billing evidence

Coin and call billing data is handled separately from deletable communication content. It is retained only as long as required for open debits or refunds and statutory accounting, tax, fraud-prevention, or evidence duties, and is then deleted or anonymised under the applicable rule.

Short-lived linking data

Unused QR challenges expire after five minutes. Device/push registrations and producer links remain active only until sign-out, revocation, invalidation or verified processing in the account-deletion workflow.

5 min

Technical logs

Security, delivery and error logs are kept only for each service's limited operational retention period and then deleted or aggregated unless a specific security or legal case requires longer preservation.

Technical protection

Transport protection, role/purpose-bound access, short-lived tokens, revocable device/QR links and protected secrets limit access. App tokens are stored in protected device storage.

Data subject rights

Access, correction, deletion and objection

You can exercise your rights directly through the privacy contact. Account and deletion processes are also available in the app.

Access & copy

You can request information about personal data being processed and obtain a copy.

Correction, restriction & portability

You can have inaccurate data corrected, restrict processing where the legal conditions apply, and receive provided data in a portable format.

Account deletion

The app accepts a confirmed deletion request for processing with HTTP 202 Accepted and provides a receipt status that can be checked without signing in. This is not proof of completion; without complete cross-store and Apple evidence, the status remains manual-review-required. An email request is available without app access.

Objection & withdrawal

You can object to processing based on legitimate interests for reasons relating to your particular situation. Consent can be withdrawn at any time with future effect.

Privacy contact

Requests concerning any of these rights go to privacy@yieeha.app.

Direct

Right to complain

You may lodge a complaint with a data-protection supervisory authority. For the company seat, the Baden-Württemberg State Commissioner for Data Protection and Freedom of Information is available in particular.