Effective August 22, 2026
Who we are and what this Policy covers
This Privacy Policy explains how Brave LLC, a Delaware limited liability company (“Brave,” “HYPE,” “we,” “us,” or “our”), collects, uses, discloses, and retains information through the HYPE mobile application, usehype.app, link.usehype.app, and related services (collectively, the “Service”). HYPE is independently operated and is not sponsored, administered, or controlled by McNair or another school authority.
The Service is directed to users in the United States who are at least 13. If you are a minor, use HYPE only with parent or legal-guardian permission where required. If you do not agree with this Policy, do not use HYPE.
Information you provide
- Account and authentication information, including your phone number, one-time verification status, authentication identifiers, sessions, and account status.
- Profile and school information, including age, grade, first and last name, gender, username, optional profile photo, selected or verified school, onboarding progress, and school-membership status.
- Social and product activity, including friend selections, requests, acceptances, removals, hides, blocks, poll batches, candidate presentations, answers, skips, HYPE sent and received, Inbox reads, Activity state, Coins, rewards, Boost requests and fulfillment, cooldowns, and invitations.
- Content and communications, including profile content, deletion reason selected from HYPE’s options, feedback, support requests, screenshots or attachments you choose to send, and communications with Brave.
Do not send support information you do not want us to process. If you provide information about another person, you represent that you are authorized to do so.
Location and regional school verification
During signup, HYPE requests one fresh device location, which may be precise when Precise Location is enabled in iOS, to determine whether you are within the server-configured region for an available school. Latitude, longitude, accuracy, capture time, and calculated distance are processed only for that request and are not stored or sent to Mixpanel. HYPE retains only the permission state and a short-lived regional result, matched school, verification time, and expiration needed to finish signup.
After membership is verified, HYPE removes the short-lived verification marker. Returning users can generally use HYPE away from school, and HYPE does not continuously track or retain location history. You may manage Location in iOS Settings, but disabling access before required verification may prevent signup or school access.
Contacts and invitations
If you allow Contacts access, HYPE reads contact information on your device to help identify possible friends, invitation recipients, and poll choices while your school has fewer than four eligible members. HYPE does not upload raw contact phone numbers, email addresses, or photos. In Add Friends, names, birthdays, and photos remain on the device while HYPE may send one-way cryptographic digests of normalized phone numbers or email addresses for privacy-reduced matching. During onboarding, HYPE may also upload contact labels and readable birthdays together with one-way identifier digests to rank or prefill possible matches. A digest reduces exposure but is still treated as personal information and is not guaranteed to be irreversible against all possible inputs.
For a Contact-backed poll, HYPE sends an ordered phone digest and display label for each proposed choice. The server verifies that each digest belongs to the account’s current contact import and stores the label with the poll-option record so the poll can be resumed and its result can be presented. The separate pending-HYPE record stores the digest but not the label, birthday, raw phone number, or ranking. If the matching phone joins and verifies the same school within 90 days, each unexpired pending selection becomes an individual HYPE event; otherwise the pending selection is permanently deleted after 90 days. Poll-option records are retained under the poll, HYPE, safety, integrity, and account-deletion rules described below.
HYPE does not automatically message contacts. You choose a recipient and use Apple Messages or another user-controlled sharing destination. HYPE stores invitation records, opaque tokens, delivery-state information available to the app, inviter and school context, and recipient identifier digests rather than raw recipient phone numbers or email addresses. The receiving application, carrier, and recipient may separately process the invitation.
You can revoke Contacts permission in iOS Settings. Previously uploaded matching records may remain until refreshed, no longer reasonably needed, or your account is deleted, subject to the retention section below.
Information collected automatically
- Device and application information, such as device model, operating-system version, app version, build number, environment, permission states, notification authorization, app state, network state, and session identifiers.
- Usage and analytics information, such as screens and features used, timestamps, entry source, onboarding progress, friend and eligible-classmate counts, poll and candidate identifiers, selections and skips, response time, HYPE and Inbox interactions, invitation and share destinations, Coins and Boost states, cooldowns, notification events, blocks, errors, latency, retry results, and retention activity.
- Technical and security information that our infrastructure or providers may receive automatically, including IP address, request timestamps, user-agent or device information, authentication events, logs, crash or diagnostic information, and suspected abuse or fraud signals.
- Push-notification information, including Apple Push Notification service device tokens, environment, token status, notification jobs, delivery acceptance or failure status, badge counts, and notification-open routing.
Mixpanel analytics may use stable HYPE user and school identifiers and approved profile segments such as age or age bucket, grade, gender, profile-photo state, and permission states. HYPE’s analytics contract excludes raw phone numbers, OTP codes, contact names or digests, exact coordinates, profile-photo URLs, notification text, invitation secrets, and anonymous-sender identities.
How we use information
- Create, authenticate, secure, restore, deactivate, and delete accounts.
- Verify regional school eligibility and maintain a school-contained pilot.
- Create profiles; find classmates and friends; support invitations; and operate public Profile links and HYPEcodes.
- Issue polls, record answers and skips, create and deliver HYPE, manage Inbox and Activity, enforce cooldowns, and operate Coins and Boosts.
- Send service, friend, HYPE, safety, and product notifications when permitted.
- Apply blocks, enforce rules, investigate misuse, prevent fraud, protect students and the Service, and comply with legal obligations.
- Provide support, respond to requests, debug failures, maintain reliability, and communicate about material service or policy changes.
- Measure activation, engagement, fairness, safety, invitations, retention, reliability, and pilot performance; conduct research and product experiments; and improve, develop, and market HYPE.
- Create aggregated or deidentified information and use it for any lawful purpose, provided we do not attempt to reidentify it except to test our deidentification protections or as permitted by law.
What other users may see
Eligible same-school users may see profile information needed to identify classmates, such as your name, username, grade, gender, profile photo, school context, friendship state, and limited mutual-friend information. Poll candidates see only what the interface displays; poll recipients do not receive the sender’s identity from HYPE but may see a broad gender signal and grade. Brave retains the underlying sender and recipient association on the server.
Accepted friends may see qualifying, delayed Activity about HYPE another accepted friend received, excluding HYPE the viewer personally sent or received. Activity is newest-first, non-tappable, delayed by approximately 15–45 minutes, and visible for up to seven days, subject to blocking and eligibility rules.
A stable, unlisted shared Profile link may display only your first name, username, and avatar to anyone who has the link, without requiring login or same-school membership. The page is configured not to be indexed, but recipients can copy or forward it, and search engines or third parties may not always honor technical instructions. Adding a profile as a friend still requires an authenticated, eligible same-school account.
How we disclose information
- Service providers and processors that support cloud hosting, databases, storage, authentication, SMS verification, analytics, website hosting, push notifications, customer support, security, and communications. Current or expected providers include Supabase, Twilio, Mixpanel, Vercel, Apple, and related infrastructure vendors.
- Snapchat, Instagram/Meta, Apple Messages, the iOS share system, or another destination when you intentionally initiate a share or handoff. Those services receive the content or link you choose to transfer and process it under their own policies.
- Professional advisers, auditors, insurers, financing sources, and corporate counterparties subject to appropriate obligations.
- Government authorities, schools, parents or guardians, law enforcement, courts, or other parties when we believe disclosure is reasonably necessary to comply with law or legal process; enforce our terms; investigate fraud, abuse, or safety concerns; protect rights, property, or safety; or respond to an emergency.
- An acquirer, investor, lender, affiliate, successor, or other party in connection with an actual or proposed financing, reorganization, merger, acquisition, bankruptcy, sale, or transfer of all or part of Brave or its assets.
- Other parties at your direction, with your consent, or as otherwise described when information is collected.
We do not sell personal information for money, use it for third-party cross-context behavioral advertising, or track you across unrelated companies’ apps and websites for advertising. We may disclose information to processors and use analytics for HYPE’s own operational, research, safety, and product purposes. If our practices change, we will update this Policy and provide choices required by law.
Anonymity limits
“Anonymous” in HYPE means that the recipient is not shown the sender’s account identity through the ordinary product interface. It does not mean the event is anonymous to Brave, our infrastructure, or every person who may infer context. We retain event associations to deliver HYPE, enforce blocks, investigate misuse, analyze the pilot, protect users, and comply with law. We may disclose information when permitted by this Policy or required by law, and we do not guarantee that another user cannot infer a sender from timing, grade, gender, poll context, or information outside HYPE.
Retention, deactivation, and deletion
We retain personal information for as long as reasonably necessary to provide and improve HYPE, maintain account and transaction integrity, administer the pilot, protect safety and security, resolve disputes, enforce agreements, comply with law, and support the purposes described in this Policy. Retention depends on the information’s nature, sensitivity, operational need, legal requirements, and risk. Some visible features use shorter windows—for example, Activity rows are available for up to seven days—even though underlying authorized operational records may be retained longer.
Requesting deletion immediately deactivates normal account access and notification delivery. You may recover the account during the next 24 hours. If you do not recover it, HYPE schedules permanent deletion of the Auth user, profile photo, profile, membership, poll, HYPE, friend, contact, invitation, location, Coin, Boost, notification, and other dependent account records. Technical processing or retries may take additional time.
We may retain information where reasonably necessary in provider backups or logs; to detect or prevent fraud, abuse, or security incidents; to comply with legal, tax, accounting, insurance, or regulatory obligations; to establish, exercise, or defend legal claims; to maintain transaction integrity; or where deletion is technically infeasible or prohibited. We may retain deidentified or aggregate information, including an aggregate deletion-reason count that does not include a user ID, phone number, free text, or event timestamp. Third parties that received information at your direction process it under their own retention policies.
Your controls and choices
- Review and update available profile fields through Edit Profile or contact support for help.
- Control Contacts, Location, Photos, Camera, and Notifications through iOS Settings. Disabling a permission may limit related features.
- Hide suggestions, remove friends, reset the hide list, and block an anonymous sender using available in-app controls.
- Log out to clear the local session without deleting the account.
- Request account deletion through Profile, Edit Profile, Manage Account, Delete Account, then recover within 24 hours if you change your mind.
- Contact support@usehype.app to request privacy assistance or exercise applicable legal rights.
We may need to verify your identity and authority before fulfilling a request. We may deny or limit requests where permitted by law, including to protect another person, preserve security or fraud-prevention records, maintain legal claims, or comply with an exception. Authorized agents may be required to provide proof of authority, and we may still verify directly with the account holder.
U.S. state privacy rights
Depending on where you live and whether applicable law covers Brave’s processing, you may have rights to confirm processing; access, correct, delete, or obtain a portable copy of personal information; opt out of sale, targeted advertising, or certain profiling; limit certain sensitive-data processing; withdraw consent; and appeal a denied request. HYPE does not currently sell personal information, conduct third-party targeted advertising, or use personal information for decisions producing legal or similarly significant effects.
Submit a request or appeal to support@usehype.app with the subject “Privacy Request” or “Privacy Appeal.” Describe the right you wish to exercise and the HYPE account involved without emailing an OTP or password. We will not discriminate against you for exercising a valid privacy right. These rights are not absolute and may not apply to all information or users.
Children and teens
HYPE is not intended for children under 13, and we do not knowingly allow them to create accounts. If you believe a child under 13 provided personal information, contact support@usehype.app with enough information for us to investigate. We may delete or restrict the account and associated information after appropriate verification.
Users under the age of legal majority must have parent or legal-guardian permission where required. Parents and guardians should discuss account security, invitations, public Profile links, Contacts, Location, notifications, social sharing, blocking, and responsible use with their teenagers. A parent or guardian may contact us about a minor’s account, but we may verify identity, relationship, and authority before disclosing or changing information.
Security
We use administrative, technical, and organizational safeguards designed to protect information, including authenticated access, server-side authorization, school isolation, row-level security, restricted service credentials, and limited analytics fields. No system, transmission, device, storage provider, or security control is completely secure. We cannot guarantee that information will never be accessed, altered, lost, or disclosed. Protect your phone and verification codes and notify support@usehype.app if you suspect unauthorized access.
International use
HYPE’s initial service is offered in the United States and information is processed in the United States and other locations where our providers operate. We do not represent that HYPE is appropriate or legally available elsewhere. If you access HYPE from another jurisdiction, you are responsible for compliance with local law and understand that information may be transferred to jurisdictions with different data-protection rules.
Changes to this Policy
We may update this Policy as HYPE, our providers, or legal requirements change. We will post the updated version and effective date and provide additional notice when required. Continued use after the effective date means the updated Policy applies to subsequent processing, subject to rights that cannot legally be waived.
Contact
Send privacy questions, requests, or appeals to support@usehype.app or Brave LLC, 20 River Court, Jersey City, NJ 07310.