TemanCerita Privacy Policy
In effect from 21 September 2026. Applies to the temanceritaa.com website and the TemanCerita app on Android and iOS.
This page is written so you can understand it without a lawyer. If anything is still confusing, send your question to admin@temanceritaa.com and we'll answer it.
Data we collect
If you create a customer account
- The name you choose to enter
- Your email address
- Your WhatsApp number
- Your password, stored as a one-way hash. We can't read it, not even ourselves
- Your order history and the ratings you give
If you sign up as a talent
Everything above, plus the age, gender, city, hobbies, bio, profile photo, rates, and schedule you enter yourself. Your profile photo and those details are shown publicly, because they make up your profile page.
If you choose identity verification, we keep a photo of your ID card. That's explained separately below.
What's collected automatically
- IP address and device type, used to prevent forced login attempts and mass sign-ups
- Your last login time and the device used, so you can tell if someone logs in without permission
- Your device's notification token, if you allow notifications in the app
- Visit statistics through Google Analytics on the site
- Visit markers from the Meta Pixel on the site, used to measure the ads we run on Instagram and Facebook. What's sent to Meta is the page you open and a device marker. If your email and phone number are sent too, they're always hashed with SHA-256 first, so Meta never receives your actual address
What we never collect
- Your conversations with talents. They happen on WhatsApp, not on our system, so we have no access to them at all
- Your exact location. Your city is entered by you, not taken from GPS
- Your contacts, photo gallery, microphone, or camera. The app doesn't ask for those permissions
- Customers' card numbers or bank details. Payments are handled outside our system
What the data is used for
- Running your account and processing orders
- Connecting you with talents on WhatsApp
- Sending verification codes and password reset codes
- Sending notifications about orders and balance withdrawals
- Calculating levels, discounts, and revenue sharing
- Handling reports of abuse and rule violations
We don't sell data to anyone. We also don't show third-party ads inside the app.
ID card photos for talents
Identity verification is optional, not required. Talents can stay active without uploading one.
If you upload one:
- The file is stored in a locked folder outside the public area of the server. There's no address anyone outside can open, even if they guess the file name
- Only admins can view it, and every time it's opened we record who opened it and when
- The ID number is never copied into the database. Only the image file and its review status are stored
- You can ask for it to be deleted at any time. The verified badge will be removed as well
How long it's kept
- Active accounts: for as long as the account is in use
- Order history: five years, for bookkeeping and resolving disputes
- ID card photos: until you ask for them to be deleted, or until the account is deleted
- Security logs and login attempts: 90 days
- Accounts rejected during screening: personal data is archived, and the only thing kept permanently is a random fingerprint of the email and phone number. That fingerprint can't be turned back into the original email or number. Its only purpose is to stop someone who was rejected from signing up again and again with the same details
Your rights
You have the right to ask for:
- A copy of all the data we have about you
- Correction of wrong data
- Deletion of your account and its data
- Deletion of your ID card photo only, without deleting your account
Send your request to admin@temanceritaa.com from your registered email address. We'll process it within 14 working days.
One exception you should know about: paid order history can't be deleted before five years have passed, because it's a financial record. What can be deleted is the personal data attached to it.
Security
- Every connection uses HTTPS
- Passwords are stored with bcrypt, never in their original form
- App tokens are stored as SHA-256 fingerprints, not as they are, so a database leak doesn't automatically mean an account leak
- On phones, tokens are stored in the Android Keystore, not in an ordinary file
- Changing your password automatically logs out every other device
No system is immune. If there's a breach that affects your data, we'll tell you by email within 72 hours of finding out.
Minors
TemanCerita is only for people aged 17 and over. We don't accept sign-ups from anyone younger. If we find an account belonging to a minor, we delete it along with its data. If you're a parent and find your child registered, email us and we'll delete it without needing a long explanation.
Third-party services
- Expo Push, to send notifications. Only the device token, title, and notification text are sent there
- Meta (Instagram and Facebook), to measure ad results. We send the type of event (opening the site, booking, contacting CS) with a device marker. Your conversations are never sent there. You can turn this tracking off in the ad settings of your own Meta account, or with an ad blocker in your browser
- Google Analytics, for site visit statistics. Not used in the app
- WhatsApp, where conversations happen. Your chats there fall under WhatsApp's privacy policy, not this one
- Hostinger, where our server and database are hosted
Changes to this policy
If there are important changes, we'll let you know by email and in-app notification at least 14 days before they take effect.
Contact us
Email: admin@temanceritaa.com
Instagram: @temanceritaa.co
WhatsApp customer service: open a chat