Privacy policy
Last updated: 27 April 2026
Who we are
justmeornah is operated from the United Kingdom by an independent operator. The data controller for this service can be contacted at privacy@justmeornah.com.
What data we process
- Reporter data: the email address you sign up with (verified by magic link), your Discord username, Discord user id, and Discord-account email — all obtained when you click "Verify your Discord" and grant the OAuth consent prompt. The Discord email is never revealed to other reporters; we keep it solely so we can flag mismatched identities (a fraud signal).
- Target data: the Discord handle of the person you report. We do not collect emails, real names, photos, or other identifiers for these third parties — only the handle as a string.
- Service data: session cookies (essential, set by Better Auth), submission timestamps, and Stripe payment metadata when you unlock a match (we do not see card details — Stripe handles those).
- Analytics: we use Plausible, which is cookieless and does not collect personal data.
Lawful basis
For your own data, we rely on contract (to provide the service you sign up for) and your explicit consent (specifically: revealing your Discord handle to other reporters who pay to unlock — you check a box at submission time).
For the Discord handles of third parties you submit, we rely on legitimate interest under UK GDPR Article 6(1)(f) — the interest of helping users avoid deception in early-stage online relationships. We've performed a Legitimate Interests Assessment (LIA); a summary is available on request from privacy@justmeornah.com. Third parties retain the rights described below regardless of basis.
Retention
Submissions are kept indefinitely. The product is explicitly designed to detect overlapping relationships across long time windows (the historical-overlap match) — a relationship from years ago can match against a new report today, and that's the point. Limiting retention would defeat the purpose of the service.
Submissions are removed in three ways:
- You revoke the submission from your dashboard (immediate, permanent — the row is hard-deleted and excluded from all future matching).
- You delete your account. Send a request to privacy@justmeornah.com — we delete your account and cascade-delete every submission you made within 30 days.
- The person you reported requests erasure via the data-request form (or by emailing us). We action within 30 days under UK GDPR Article 17.
We also send you an annual reminder email asking if your relationship is still going, so you can mark it ended (kept for matching, but flagged as a past relationship) or revoke it. Stripe payment records are retained for 7 years to comply with HMRC tax record-keeping rules.
We have performed a Legitimate Interests Assessment (LIA) documenting why indefinite retention is necessary and proportionate for the stated purpose. A summary is available on request from privacy@justmeornah.com.
Your rights (and the rights of anyone you've reported)
Under UK GDPR you (or someone whose Discord handle has been submitted here) have the right to:
- Access the data we hold relating to a Discord handle
- Request erasure (the “right to be forgotten”)
- Object to processing
- Lodge a complaint with the ICO at ico.org.uk
To exercise these rights, use our data request form or email privacy@justmeornah.com. We action erasure requests within 30 days.
Visibility
We do not publish, list, or expose any submission publicly. Match data is only visible to the reporters involved. Your Discord handle is only revealed to a specific other reporter when both of you have submitted the same target handle and one of you has paid £2.99 to unlock — and only because you explicitly consented to this at submission time.
Sub-processors
- Amazon Web Services — hosting and database (eu-west-2, London)
- Resend — transactional email
- Stripe Payments UK Ltd — payment processing for unlocks
- Plausible Analytics — cookieless aggregate analytics
Cookies
We set a single essential session cookie (named better-auth.session_token) so that signed-in users stay signed in. We do not use marketing or analytics cookies, so no consent banner is required under PECR.
Changes to this policy
If we change this policy materially we'll email all signed-up users before the changes take effect.