Privacy Policy

Your circle is private.

This policy explains how CEGE Enterprises LLC handles information for the Say You're Real mobile app, the SYR beta, sayyourereal.com, and public request forms.

Legal version: 2026-08-16 · Effective and last updated August 16, 2026

The short version: SYR shows private photo content only to connections within your circle. The current beta does not sell personal information, share it for cross-context behavioral advertising, run third-party or targeted ads, track users for advertising, use personal information for decisions with legal or similarly significant effects, or use it to train general-purpose AI.

1. Scope and operator

CEGE Enterprises LLC operates Say You're Real ("SYR"). This policy covers information processed through the mobile app, authentication and app infrastructure, the public website, and support, privacy, safety, eligibility, and deletion requests. It does not control independent websites you choose to visit, including external safety resources.

2. Information we process

Depending on how you use SYR, we may process:

  • Account and profile data: email, authentication identifiers and state, username, display name, profile details, preferences, avatar and profile media, account status, and legal-policy acceptances.
  • Photos and user-generated activity: camera-created or selected media, profile backgrounds, captions, comments, replies, photo-linked message text or media, authorship, thread participation, view or seen records, viewer lists, timestamps, and the records needed to show content under current visibility rules.
  • Private social and discovery data: connection requests and accepted connections, friend-of-friend suggestions, persistent QR invite identifiers and redemption state, temporary Nearby discovery and pairing-session data, blocks, declines, removal state, and discovery choices. Nearby may use device radios and platform permissions but is not designed to retain precise location.
  • Safety, support, and rights-request data: reports, targets, reasons, details, moderation context, support requests, deletion records, privacy choices, status history, and information needed to verify an account-specific request. A copyright notice, counter-notice, or other intellectual-property request also includes the submitted work description, material locator, contact email, telephone, mailing address, typed electronic signature where required, and required statement outcomes.
  • Phone verification data: a voluntarily submitted phone number, verification state, request and attempt timestamps, delivery or error state where received, and limited consent or opt-out records.
  • Notifications and technical data: push token, notification preferences, notification category and delivery state, read/open or tap-routing state, app version and build, platform, device and permission state, security events, error or reliability records, and limited hosting or network data needed to operate and protect the service.

3. Eligibility and age assurance

SYR applies the state rules described on Eligibility. It may use a complete birth date briefly to determine the correct age group, but it does not save the full date to a profile, regular app records, routine logs, or analytics.

On supported devices, SYR may receive age-range information from Apple Declared Age Range or Google Play Age Signals. Texas users must complete the official route for the store where the app was installed. SYR does not use platform age information for advertising, recommendations, or profiling.

For Ohio users ages 13–15 and Mississippi users ages 13–17, Epic Games Kids Web Services (“KWS”) verifies that the adult taking part in the parent flow is an adult. SYR separately asks the adult to approve the request, confirm the required relationship, and explicitly accept the current Terms; the minor user must separately assent. KWS does not determine the minor user's age or prove the family relationship. Parent consent is not offered nationwide. Ohio also requires SYR to send a written confirmation. It counts as sent when the configured email service accepts it for delivery, which is not the same as proof it reached the inbox.

For adults in Mississippi and Tennessee, SYR briefly decrypts and reads Persona's protected response, records only whether the 18-or-older check passed along with the limited reference and timing needed to apply the result, and then discards the full response. Persona controls the verification method and any evidence it collects under its current service. SYR does not retain identity evidence such as a document, selfie, name, full birth date, or exact age.

SYR keeps only the state, age group, result, type of check, consent or platform status, limited references, policy and legal-release versions, clickwrap evidence, and dates needed to apply the rule. It does not keep provider response bodies, raw store data, identity documents, selfies, biometric templates, precise location, or a parent email as part of the eligibility record. A parent email is used only long enough to complete the KWS or confirmation step and is not kept in SYR account, support, analytics, or backup records. The companies involved may perform limited processing under their own terms.

If required information is missing, unclear, expired, or withdrawn, ordinary access stays restricted until the person completes a valid check. Support cannot manually replace a required provider or platform result.

4. Optional phone contacts and matching

Phone verification and contact discovery are optional. SYR reads contacts only after you allow contact access and explicitly start matching. For that one user-started scan, SYR checks every usable phone number you authorized without stopping after a fixed number. Contact names and full address-book records stay on your device. SYR temporarily sends normalized phone values over an encrypted connection in small batches of no more than 100 and compares protected versions on the server. Only one scan can run at a time for an account. Those protected values are still personal data. SYR does not retain an uploaded address book or unmatched-number list, and it never invites or messages unmatched contacts automatically.

We do not sell, rent, or provide mobile phone numbers, SMS opt-in data, or messaging consent information to third parties or affiliates for their marketing or promotional purposes. Verification messages are user-requested transactional codes, not recurring or marketing messages. See SMS Verification.

5. How we use information

SYR limits processing to disclosed service, safety, security, support, legal, and user-requested purposes and seeks to collect and retain only information reasonably necessary and proportionate for those purposes. We do not repurpose user data for unrelated marketing, advertising, or engagement profiling.

  • Authenticate accounts, enforce eligibility and policy acceptance, and provide app features.
  • Store and display profiles, photos, comments, messages, views, and connections under product visibility rules.
  • Provide optional verification, contact discovery, notifications, recovery, and account security.
  • Process blocks, safety reports, support, privacy choices, and account deletion.
  • When enabled, check submitted content for safety and send limited cases to restricted human review under the Safety Rules.
  • Detect abuse, protect users and the service, debug failures, maintain reliability, and comply with law.

6. Visibility and sharing

Your photos, messages, and activity are shown only where your account, connections, conversations, and settings allow. Private by default limits exposure inside SYR, but it cannot prevent a recipient from taking a screenshot or using another device.

Our configured providers include Supabase for authentication, database, and storage; Cloudflare for website delivery, security checks, and restricted ingress; Apple and Google for sign-in, age-signal, push, and app-distribution services; Epic Games Kids Web Services for adult verification in the adopted parent flows; Persona for supported adult age assurance; Resend for required transactional parent email; and Twilio for user-requested SMS verification. A named provider is used only for the applicable feature and only when that integration is enabled. Providers may process information to provide contracted services or meet legal obligations under their terms. We may also disclose limited information when reasonably necessary to comply with law, respond to valid process, protect a person, investigate abuse, enforce terms, or defend rights.

When automated content review is enabled, SYR may send submitted text and a reduced-size copy of an image to OpenAI's moderation service. This can include profiles, captions, comments, replies, photos, backgrounds, avatars, and private photo-chat content. A private message remains private from other users except its participants, but it may still be checked for safety and reviewed by a small group of authorized people when needed. A check may allow content, send it for review, or block it before it is posted or sent.

The safety service may use content only to provide the contracted safety service or meet legal and security obligations—not for SYR advertising, recommendations, unrelated marketing, or engagement profiling. Its processing and retention follow its terms and SYR's account settings. Automated checks and human reviewers can make mistakes and cannot find every violation. A flag alone is not proof of wrongdoing, and reporting and blocking remain available even when a check allows content.

Safety handling may include a legally required report or preservation to the National Center for Missing & Exploited Children (NCMEC) or its CyberTipline, law enforcement, or another lawful recipient. A person seeking help with non-consensual intimate imagery may also choose independent services described on Take It Down Help. SYR does not send intimate media from a public web form because those forms do not accept files.

SYR does not sell personal data or share it for cross-context behavioral advertising. The current beta does not include third-party or targeted advertising, third-party tracking for ad targeting, or profiling in furtherance of decisions that produce legal or similarly significant effects.

7. Public website and request forms

You can read the public site without signing in. The first support, privacy, eligibility, or general safety form asks only for the topic, a short description, and any state or category needed to route it; it does not ask for your email or SYR username. The intimate-image removal form is a narrow exception: a complete request needs a working contact email, typed signature and signature-intent statement, content locator, depicted person's name, reporter capacity, and required authority and good-faith statements. An authorized representative selects only a simple representative category and attests to authority. SYR does not ask for an ID, birth date, home address, phone number, notarization, image upload, or separate perjury statement in this form. The account-deletion form needs an account email or username, and copyright notices need the contact and statement information required to review them. Public forms do not accept files. Never send a password, verification code, identity document, full birth date, or intimate media.

After a successful submission, you receive a private status key. For support, privacy, or eligibility matters, the status page may let you verify an email address with a short-lived code and send a private reply. General safety and intimate-image requests do not offer that general reply channel; the intimate-image contact and signature fields are encrypted for restricted handling and are not shown on the public status page. The deletion process uses the account information supplied with the request and does not reveal whether an account was found.

Online forms use a security check and limits designed to prevent abuse. They may briefly process limited network information and compare a protected version. Both are personal data. Ordinary cases do not keep a network-based submitter identifier, and account-deletion requests do not keep the comparison. Security-check and hosting providers may process technical data under their terms. If an online form is unavailable, the page keeps an email option visible.

8. Retention and deletion

We retain information while needed to provide the beta, maintain security and integrity, resolve support or safety matters, meet legal obligations, or establish and defend rights. These are maximums or lifecycle boundaries, not a promise to keep every record for the entire period:

  • Ordinary support content is scheduled for deletion or removal no later than 30 days after the matter closes unless a limited legal hold applies. Raw routine logs are scheduled for removal no later than 30 days after collection. Copies held by service providers follow their documented deletion schedules.
  • Contact details and correspondence for ordinary support or privacy matters follow the same close-plus-30-day schedule. Eligibility-correction correspondence may remain for up to 90 days. Short-lived verification codes and sessions expire sooner.
  • Routine safety and moderation case records may remain for 24 months after closure. A serious non-CSAM safety case may remain for five years after closure. A shorter schedule may apply when the record is no longer needed, and a documented case-specific legal hold may control for its valid period.
  • Non-media Take It Down request records, including the restricted contact and signature payload, are scheduled for deletion five years after the case closes unless a documented legal hold applies. The statutory 48-hour clock begins when all required elements of a valid request are received and is not paused or reset by later follow-up.
  • Copyright notices, counter-notices, related contact information, and case correspondence may remain for three years after the matter closes unless a documented legal hold applies.
  • Versioned legal-acceptance evidence and arbitration opt-out receipts are append-only. After an account is deleted, the related clickwrap evidence is eligible for controlled purge after 24 months unless a documented legal hold requires longer retention.
  • Minimal audit, ban, and suppression records may remain for up to 24 months and are reviewed at least once a year.
  • The contents submitted in a CyberTipline report are scheduled for deletion one year after submission unless another documented legal duty or limited hold requires a different period.
  • Active holds cover only identified records, are reviewed at least every 90 days, and end only after a separate authorized review.
  • Encrypted recovery backups are locked for 30 days and targeted to expire after 30 days. A service provider may need its documented processing window to finish deletion; any remaining copy stays protected and out of ordinary use. Deleted data is not restored to ordinary use from a backup.

After ownership is verified, SYR immediately removes the account and ordinary content from normal use. There is no required waiting period. You may cancel only before permanent deletion begins. The normal completion target is seven calendar days, with an outer target of 30 days unless there is an identity dispute, a limited legal or safety hold, a service-provider limitation, or another documented lawful reason. SYR does not call a partly completed request finished. Details are on Account Deletion.

Deleting your photo also removes its comments, replies, and photo-linked private chat. If your comment, reply, or message belongs to a conversation that otherwise remains, SYR removes your words and identity but may leave a blank structural marker so other people's replies still make sense. A private chat that cannot work without the deleted photo or account is removed.

Deletion cannot erase screenshots, gallery saves, offline copies, or records another company controls. Limited audit, safety, fraud-prevention, legal, and backup records may remain for the periods above and are not returned to ordinary product use.

9. Your choices

You can control what you post, connections, blocks, notification choices, optional phone verification and contact discovery, and account deletion. Depending on where you live and subject to lawful exceptions, you may also ask to access or obtain specific pieces of personal data, correct inaccuracies, delete personal data, and receive eligible data in a portable and, to the extent technically feasible, readily usable format. You may appeal a privacy-request decision where applicable. Use Privacy Choices.

Applicable law may also provide rights to opt out of sale or sharing, targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects. SYR currently performs none of those activities. A related form selection opens a case for confirmation or a concern; it does not claim that SYR changed a setting for an activity that does not exist.

SYR recognizes Global Privacy Control where required. Because the beta does not sell or share personal data, run targeted ads, or use covered profiling, the signal does not change a setting today. If those practices change, we will update this notice and honor the signal before using data that way.

We use verification proportionate to the request's risk. Access, portability, correction, or deletion may require stronger proof of account control before data is disclosed or changed; a general practice question, appeal, or opt-out request may require less unless account-specific action is needed. We ask only for minimum evidence through a restricted channel and may deny or limit a request where law permits. Do not upload or email IDs, passwords, verification codes, or a full birth date.

An authorized agent may submit where applicable. We may verify the agent's authority and the requester's identity, or ask the requester to confirm directly, as law permits. A parent or guardian may raise a child-safety or privacy concern and act where legally applicable; we verify the relationship and authority proportionately before disclosing or changing child data. That does not create a parental dashboard, message-access right, or consent shortcut for an ineligible user.

After a successful submission, the page gives an immediate acknowledgment. Once SYR receives a verifiable request, our operational target is a substantive privacy response within 45 calendar days. If reasonably necessary and applicable law permits an extension, we will notify the requester during the initial response period, explain the reason, and may take up to 45 additional calendar days; any shorter legal deadline controls. If we decline or limit a request, we explain the basis and any available appeal process where required. We target a written privacy-appeal decision within 45 calendar days, or sooner where law requires, and provide regulator-contact information after a denied appeal where applicable law requires it.

We do not discriminate for exercising an applicable privacy right or use dark patterns to obstruct a choice. A request may still affect a feature when the requested data is necessary to provide it, and lawful program differences or request limits may apply.

10. Security

We limit access, separate sensitive credentials, reduce what we log, and use other safeguards designed for the beta. App and website connections use encryption in transit when they are available. That does not mean every SYR conversation is end-to-end encrypted, and no online system is perfectly secure. Keep passwords and verification codes private, use supported software, and report suspected account compromise through Support.

11. Children and minor users

Anyone under 13 is ineligible. Higher minimum ages and assurance rules apply in certain states, and U.S. territories are unavailable for the initial beta. SYR does not offer a general parental-consent path for an otherwise ineligible user. If you believe an ineligible minor is using SYR, use the concern path on Eligibility.

12. Changes and contact

We may update this policy as the beta, law, or our practices change. A material change may require a new in-app acceptance or eligibility review before ordinary access continues.

Questions or requests: Privacy Choices, [email protected], or CEGE Enterprises LLC, Attn: Legal, 7027 W Broward Blvd #715, Plantation, FL 33317.