Effective Date: October 8, 2026

Privacy Policy

HeyLetsConnect.com is dedicated to protecting the privacy of technical builders and creators. This policy outlines exactly what information we collect, why we collect it, and the rigorous boundaries protecting your data.

1. Core Privacy Invariants

We founded HeyLetsConnect on three straightforward privacy commitments:

  • Zero selling of data: We do not sell, rent, monetize, or trade your personal information to third-party data brokers, marketers, or advertisers.
  • No unsolicited discovery: Direct contact coordinates (such as your email address) are never made public and are shared with another builder only after both parties have explicitly accepted an introduction.
  • Minimal tracking: We do not embed surveillance trackers, social media behavioral pixels, or advertising cookie networks.

2. Information We Collect

We collect information to provide, personalize, and operate the mutual matching platform:

A. Information You Provide Voluntarily

  • Account Identity: When authenticating via X (OAuth 2.0 PKCE) or selecting a local profile, we receive your public X handle, numeric user ID, display name, and avatar image URL.
  • Builder Profile Details: You may choose to supply your email address (used strictly for mutual match intro notifications), personal website URL, GitHub username, current timezone, and preferred collaboration hours.
  • Active Requests & Blockers: Problem statements, skills required, assistance offered, tags, and estimated sync commitment durations (e.g., 30-minute sync).
  • Match Proposals: Responses indicating whether you accept or decline an intro proposal.

B. Technical & Edge Diagnostics

  • Edge Telemetry: Anonymized request counts and response timings collected via Cloudflare edge routing to mitigate DDoS attacks and maintain platform uptime.
  • DNS & Agent Lookups: Standard DNS query information processed through Cloudflare 1.1.1.1 DoH infrastructure for DNS-AID service records.

3. Cookies and Local Session Storage

We use strictly functional, essential cookies required to operate authentication and protect against attacks:

  • hlc_session: A secure, HTTP-only cookie containing an encrypted session identifier that maintains your signed-in state.
  • hlc_oauth_verifier & hlc_oauth_state: Temporary, short-lived (10-minute) cookies used exclusively during the OAuth 2.0 PKCE flow to defend against Cross-Site Request Forgery (CSRF). They are immediately discarded upon authentication.

We do not use tracking cookies, targeting cookies, or third-party behavioral analytics cookies.

4. How We Use Your Information

We use the collected information solely for these specific operational purposes:

  • To render your public builder vanity profile (e.g., heyletsconnect.com/@username) and showcase your active needs.
  • To run the open-source synergy matching algorithm that pairs complementary engineering blockers and offerings.
  • To coordinate mutual email intros between two builders who have both explicitly confirmed interest in connecting.
  • To power automated discovery catalogs for AI agents via DNS-AID and WebMCP (RFC 8288 / RFC 9727).
  • To prevent platform abuse, spam, and fraudulent account behavior.

5. How We Share Information

We share your data only in the following transparent situations:

Public Display: Your X username, display name, avatar, bio, offering, looking-for statement, and published requests are visible to anyone visiting your public profile or browsing open requests on the homepage.

Mutual Match Introductions: Your verified email address is shared only with a specific matched builder after both of you have actively clicked "Accept Intro".

Infrastructure Providers: We rely on trusted technical providers who process data strictly under our instructions and confidentiality standards:

  • Cloudflare: Serverless edge compute (Cloudflare Workers), encrypted SQLite data storage (Cloudflare D1), and edge caching.
  • Resend: Transactional email service used solely to deliver mutual match introductions.
  • Unavatar.io: Free public image proxy that caches and serves avatar thumbnails.

Legal Requirements: We may disclose data if legally required to do so in response to a lawful court order, subpoena, or government investigation.

6. Data Security and Safeguards

We take information security seriously and implement robust technical protections:

  • HTTPS Everywhere: All traffic is encrypted in transit using TLS 1.3 with HTTP Strict Transport Security (HSTS) and preload enabled.
  • DNSSEC Validation: Global cryptographic DNS signing prevents DNS spoofing and cache poisoning.
  • Strict Content Security Policy: Comprehensive CSP headers block unauthorized scripts, cross-site injections, and unauthorized framing.
  • Secure Session Management: Authentication credentials and tokens are stored in HTTP-only, secure, SameSite cookies.
  • SQL Injection Defense: All database operations utilize typed, parameterized queries via Drizzle ORM on pure SQLite D1.

7. Your Rights and Data Control

Regardless of where you reside, HeyLetsConnect affords you comprehensive control over your personal data:

  • Access and Update: You can inspect and update your profile, availability, and active blockers at any time from the Publish Need dashboard.
  • Request Withdrawal: You can mark your active requests inactive or withdraw proposals whenever your schedule changes.
  • Right to Deletion: You have the right to request full erasure of your profile and data history. Simply contact us at privacy@heyletsconnect.com, and we will purge your records within 30 days.
  • Data Portability: You may request a machine-readable export of your profile and submitted requests.

8. International Data Processing

HeyLetsConnect is distributed across Cloudflare's global edge network. Your information may be processed in edge data centers located in various jurisdictions around the world. We ensure appropriate technical and organizational measures to safeguard your data regardless of processing location.

9. Children's Privacy

HeyLetsConnect is intended solely for adult professionals and builders. We do not knowingly solicit or collect personal information from children under 18 years of age (or under 16 in the EEA). If you believe a child has provided us with personal information, please notify us immediately so we can remove it.

10. Contact Us

For any questions, concerns, or data rights requests concerning this Privacy Policy, please contact our privacy team: