Privacy Policy
Last updated: August 28, 2026
ООО «Почти» (Russia) · Nearily Inc. (United States)
1. Who We Are and What This Policy Covers
Nearily is a coffee loyalty and subscription platform. This policy covers the Nearily iOS and Android apps, the web app (app.nearily.com), the nearily.com website, the partner panel, and Neo — our support assistant — both inside the app and as a Telegram bot. If you talk to Neo on Telegram, this policy applies to those conversations even if you have no Nearily account.
For users in the Russian Federation, the personal-data operator is ООО «Почти» (INN 7801750230, St. Petersburg, Russia). For all other users, the data controller is Nearily Inc. (Delaware, United States). Both companies apply this policy together.
2. Information We Collect
Information you provide: phone number (for signing in), display name, username, bio, profile photo, language, cafe reviews, droplets (short public notes), messages you send to Neo, and anything you include in a support request.
Collected automatically: device model and OS version, app version, crash reports, push notification token, usage events linked to your account ID (stamps earned, cafes visited, rewards redeemed, screens used, subscription events), and the IP address and technical metadata of requests in our server logs.
Contacts (optional, off by default): if you turn on friend finding, phone numbers from your address book are hashed (SHA-256) on your device and only the hashes are matched on our servers to find friends already on Nearily. Raw address-book data does not leave your device, and the hashes are used for nothing else.
What we do NOT collect: payment card numbers (payments are processed by payment providers and the app stores — card details never reach our servers), biometric data, browsing history, or data from other apps on your device.
3. Location
Nearby cafes: with your permission we use your approximate location to show partner cafes around you.
Cafe presence: when you collect a stamp, the app can show other signed-in users that you are at that cafe — cafe name only, never coordinates. This is on by default and expires on its own within hours; you can turn it off in the app’s privacy settings.
Live location (Club): if you start a live-location share, the app sends your exact coordinates roughly every ten seconds while the share is active, visible to the audience you chose (everyone, friends, or followers). You can stop at any time, and shares expire on their own. Presence and live locations are transient: they expire quickly and are not written to long-term storage.
Background permission: iOS may ask for "Always" location access so an active share keeps working while the app is in the background. It is used only for that.
4. How We Use Your Information
We use your information for the following purposes:
(a) providing the Service — stamps, rewards, cashback, subscriptions, social features;
(b) signing you in — via SMS, verification call, or a Telegram code;
(c) showing nearby partner cafes when you allow location access;
(d) sending notifications about your account activity;
(e) product analytics and crash diagnosis — usage events are linked to your account ID and used to fix and improve the Service, not to advertise to you;
(f) supporting you, through Neo and our team;
(g) telling you about Service changes when necessary.
We do not sell personal data, we show no third-party advertising, and we make no automated decisions with legal effect about you.
5. Who Receives Your Data
We share data only with the providers the Service runs on, each receiving only what its role needs:
(a) Cloud infrastructure provider — authentication, the operational database copy, file storage, cloud functions, push notifications, crash reporting and app analytics.
(b) Yandex.Cloud LLC (ООО «Яндекс.Облако», Russia) — our primary personal-data database (YDB) and object storage for images and Neo chat archives.
(c) SMS.ru (Russia) — sign-in texts and verification calls; receives your phone number.
(d) Telegram Messenger Inc. — if you choose "code via Telegram", your phone number is sent to Telegram’s Gateway API to deliver the code; Neo’s Telegram side and our Club group run on the Telegram Bot API.
(e) YooKassa (ООО НКО «ЮМани», Russia) — payments in Russia: amount, product, and your account ID.
(f) International payment provider — payments outside Russia: your account ID and email address if provided.
(g) Apple and Google — purchases made through the App Store or Google Play are processed by the store.
(h) iiko (Russia) — at partner cafes using iiko tills, the phone number you give at the till identifies your loyalty account.
(i) Text-processing providers — Neo’s replies are generated by AI models; the text of your conversation is processed to produce each reply.
(j) Transactional email provider; email routing and network infrastructure provider.
(k) Partner cafes — the cafe you visit sees your name and your stamp, reward and cashback state at that cafe. Cafes cannot browse your activity at other cafes, and we do not give them your phone number (at iiko tills you provide it to the till yourself).
If your profile is set to public, your username, name, avatar and public stats are visible to other users, including via profile links on the web. You can restrict this in the app’s profile settings.
We disclose information when required by law, court order, or a competent authority.
6. Where Your Data Is Stored
Your personal data is recorded in the Russian Federation: identity data (account ID, name, username, phone, email, profile photo path, language, role, signup date) and your loyalty records (stamps, rewards, cashback, follows, droplets, reviews) are written to our database in Yandex Cloud — YDB «nearily-pd», region ru-central1, operated by Yandex.Cloud LLC.
Operational copies of the same data live in a cloud database (multi-region — see section 7), which the apps read and write in real time.
Images are stored in two places at once: cloud object storage (section 7) and Yandex Object Storage in Russia. Conversations with Neo are stored only in Russia; to generate each reply, the conversation text is processed by the text-processing providers named in section 5.
Transient data — live locations and cafe presence — is processed in the cloud database (section 7) and expires by design; it is not kept in long-term storage. Payment records are held by the payment providers, with transaction references in our databases.
Part of our server code executes in our cloud provider’s European region (Belgium). That is where code runs, not where data is kept.
7. Cross-Border Transfers
Your data is processed in both Russia and the United States, and by the providers listed in section 5 in their countries. We transfer to each recipient only what its purpose requires. For users in Russia: your personal data is recorded in a database located in the Russian Federation, and transfers abroad are made for the purposes described in this policy.
You can object to a transfer or withdraw consent by contacting us (section 14). Parts of the Service cannot operate without their providers, so objecting to a transfer may mean that those parts stop working for you.
8. Retention and Deletion
We keep your personal data while your account is active. You can delete your account in the app (Settings → Delete account, confirmed by SMS) or by contacting us. Deletion removes your profile, loyalty records, droplets, reviews, follows, notifications, Neo chat history and profile images from both the US and the Russian systems. We complete deletion within 30 days.
What we must keep longer: payment and transaction records where accounting and tax law requires it; support correspondence for as long as needed to resolve the matter and defend legal claims; records needed to prevent fraud. Server logs are kept for a limited period (typically 30 days). Aggregated statistics that no longer identify you may be kept.
9. Your Rights
You have the right to:
(a) Access your personal data — ask what we hold about you.
(b) Correct inaccurate data — edit your profile in the app, or ask us.
(c) Delete your account and data — in the app or by request.
(d) Export your data in a portable format — on request.
(e) Withdraw consent including location access, at any time in device or app settings.
(f) Object to specific processing.
Write to hello@nearily.com. We respond within the periods required by applicable law, and never later than 30 days. Users in Russia may also complain to Roskomnadzor; users elsewhere, to their local data-protection authority.
10. Age
Nearily is for people aged 16 and over. We do not knowingly create accounts for anyone younger; if we learn that a user is under 16, we delete the account and its data.
11. Security
All traffic is encrypted in transit (TLS). Database access is restricted by security rules and server-side checks; sign-in codes are stored only as hashes; production access is limited to the people who operate the Service. No storage is perfectly secure — if a breach affects you, we will notify you promptly.
12. Cookies and Analytics
The mobile apps do not use cookies. The website uses essential cookies, and — only with your consent given in the cookie banner — web analytics services including Яндекс.Метрика (with session replay) to understand how the site is used. Details are in the Cookie Policy at nearily.com/cookies.
13. Changes to This Policy
When this policy changes in a way that matters, we tell you in the app or by notification before the change takes effect. The current version always lives at nearily.com/privacy.
14. Contact
hello@nearily.com — for privacy matters in Russia: ООО «Почти», St. Petersburg; otherwise: Nearily Inc., Delaware, United States.