Privacy Centre
What we hold, who sees it, and how to get it back or deleted
Last updated 28 July 2026
The short version
ByeThings is a marketplace for selling things you no longer want. To do that we need to know who you are, where roughly you are, and what you are selling. That is genuinely all — we do not sell your data, we do not share it with advertisers, and we do not track you across other apps or websites.
Two things are worth reading properly rather than skimming: what happens to the photographs you scan, and how your address is handled. Both are below.
Who is responsible for your data
ByeThings is a trading name of Tomo Interactive Ltd, a company registered in England and Wales under company number 17045564, whose registered office is at 1 Richmond Road, Lytham St. Annes, England, FY8 1PE.
Tomo Interactive Ltd is the data controller for the personal data described here. You can reach us at contact@tomointeractive.com. Our registration with the Information Commissioner's Office is ZC209137.
If you are in the UK or the EU, the UK GDPR and the EU GDPR apply to you and this policy is written to meet them. If you are elsewhere, we apply the same standard rather than a weaker local one.
What we collect, and why
Each of these has a purpose, and we do not collect anything we have no use for.
Your email address and password — so an account exists and only you can open it. Passwords are stored hashed; nobody here can read yours.
Your display name and profile picture, if you set one — so the person you are messaging knows who they are dealing with.
Your general area and postcode — so buyers can see roughly how far away an item is. Other people only ever see the outward code, for example M30.
Your full address and phone number, if you save them — so a parcel has somewhere to go and a collection has somewhere to come to. See "Your address" below.
Photographs of the items you scan, and any notes you write about them.
Your listings, messages and offers.
Whether you have asked for emails about the app, and when you asked — so that consent is a record rather than something we assume from you having an account.
If — and only if — you switch on analytics in Cookie Settings: a record that certain steps happened, such as a scan finishing or a listing being published, tied to your account id. Never your photographs, descriptions, prices, messages or postcode. It is off unless you turn it on, and the Cookie Policy describes it in full.
Technical information needed to keep the service working — your device and app version, and your IP address for rate limiting. The address itself is not kept: it is turned into a one-way code that cannot be read back into an address, used to count how many scans have come from one connection in the last hour, and deleted within a day.
Our legal bases
Under the UK and EU GDPR every use of your data needs a lawful basis. Ours are:
Performance of a contract — running your account, publishing your listings, carrying your messages and processing your scans. Without these the app cannot do what you downloaded it for.
Legitimate interests — keeping the service secure, preventing abuse and fraud, and limiting how fast scans can be requested so the service is not overwhelmed. We have weighed these against your rights and consider them proportionate.
Legal obligation — where we must keep or disclose records by law.
Consent — for anything optional, such as notifications and emails about the app. You can withdraw it at any time without losing access to the rest of the app, and we keep a record of when you gave it so we can show it was asked for rather than assumed.
What happens to a photo you scan
When you scan an item, the photograph is reduced in size on your device and sent to our server, which passes it to a specialist artificial-intelligence provider in the United States. That provider identifies the item and estimates what it is worth, and the result comes back to you.
The photograph is sent on its own. Your name, email address, home address and phone number are not sent with it, so the provider receives a picture of an object rather than a picture belonging to a person.
It is processed to answer that single request and nothing else. Under our contract with the provider, images sent this way are not used to train their models and are not retained for their own purposes.
We keep a technical record that a scan happened — when, from which device, and a one-way fingerprint of the image so the same photo is not charged for twice. That fingerprint cannot be turned back into your photograph.
Photographs on listings you publish are stored so buyers can see them, and are publicly readable by anyone with the link, because that is what publishing a listing means. Photographs you scan but never publish are not shared with anyone.
If you want to know exactly which provider that is, ask us at contact@tomointeractive.com and we will tell you.
Your address, specifically
Your full address and phone number are private, and are held so that they are readable only by your own account. This is enforced by the database itself rather than by each screen remembering to hide them, which means a bug in the app cannot expose them.
They are never shown on a listing, never included in search results, and never visible to another user — until you accept a reservation and choose to share them. That is a decision you make, not something the app does for you.
Buyers see the outward part of your postcode and the general area you typed. Nothing narrower.
Messages between users
Messages are stored so that both people can read the conversation, and are readable only by the two of you. They are not end-to-end encrypted: we can technically access them, and we will do so only where we are required to by law or where it is necessary to investigate a report of abuse, fraud or harm.
When somebody messages you or makes an offer, we email you to say so. That email carries their display name and the first line of what they wrote, so it passes through our email provider — named in the list above. It is sent because you have a listing somebody is asking about, not because you agreed to hear from us, so turning off product emails in your profile does not stop it.
Messages cannot be edited or deleted individually, by you or by the other person. That is deliberate — on a marketplace where two strangers agree terms, a conversation that can be rewritten afterwards protects nobody. Deleting your account removes whole conversations, which is different from editing one.
Emails about the app
There are two kinds of email from us, and they work differently.
The first is the email the service cannot run without: a password reset code, a reply about a report you made, or a notice about your account. Those are sent because you have an account, and they are not something you can turn off while keeping one.
The second is occasional news about ByeThings — the app launching on the App Store, a feature worth knowing about. Those are sent only if you have asked for them, by ticking the box when you sign up or by turning it on later in your profile. It is off unless you turn it on, we record when you turned it on, and you can turn it off again at any time in your profile or with the unsubscribe link at the bottom of every one.
We do not send email on behalf of anyone else, and your address is never passed to another company for their own marketing.
Who else sees your data
We use a small number of companies to run the service. Each one only receives what it needs to do its job, and each is bound by a contract that limits what it may do with it.
We do not sell your personal data. We do not share it with advertisers or data brokers. We do not use it to build a profile of you for marketing.
Our database and storage provider (United Kingdom or European Union) — Accounts, listings, messages and photo storage. Receives: Email address, password hash, display name, profile picture, address and phone number, listings, messages and offers.
A specialist AI provider (United States) — Identifying what is in your photo and estimating what it is worth. Receives: The photograph you are scanning and any notes you typed with it. No name, email address, address or phone number is sent with it.
Our email provider (United States) — Sending password reset codes, telling you when somebody messages you or makes an offer, passing on a report you make about a listing, and — only if you have asked for them — occasional emails about the app. Receives: Your email address, the name of anyone who contacts you and the first line of what they wrote, and anything you write in a report.
Google (United States) — Signing in, only if you choose "Continue with Google". Receives: Your email address and name from your Google account.
Apple (United States) — Signing in, only if you choose "Continue with Apple". Receives: Your name and email address from your Apple account. If you use Hide My Email, we only ever receive a relay address and never your real one.
Our subscription provider (United States) — Checking that a subscription or scan pack was really bought, and telling us which account it belongs to. Receives: Your account identifier and what you purchased. No card details: those are handled by Apple or Google and never reach us.
PostHog (European Union) — Product analytics — which steps of the app people reach — and only if you turn it on in Cookie Settings. Receives: Your account identifier, which step happened, whether you are on a phone or the web, and counts such as how many photographs. Never your photographs, descriptions, prices, messages or postcode.
Postcodes.io (United Kingdom) — Turning the first half of a postcode into an approximate location, so the marketplace can show how far away something is. Receives: The first half of a postcode only — for example "SW1A", never "SW1A 1AA". No name, account or device information is sent with it.
Our app delivery provider (United States) — Delivering the app and its updates. Receives: Device and app version information.
Where your data is held
Your account, listings and messages are held in the United Kingdom or the European Union. Photograph scanning and price comparison are carried out in the United States, as set out above.
Where data leaves the UK or the EEA, the transfer is covered by the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, together with the additional safeguards those require. We have assessed each transfer and are satisfied it gives your data essentially equivalent protection.
You can ask us for the identity of any provider named above only by category, and for a copy of the safeguards in place, at contact@tomointeractive.com.
How long we keep things, and how to delete it all
We keep your account and its contents for as long as your account exists.
You can delete it yourself, from Profile. It is immediate rather than a request that goes into a queue: your profile, your listings, your photographs, your conversations and any offers are removed as you confirm it.
Two things to know before you do. It cannot be undone, and we cannot recover any of it. And your conversations go for the other person too — a thread is one record shared between two people, so deleting your half deletes theirs.
Deleted with the account: your email address, name, profile picture, address, phone number, listings, listing photographs, conversations, messages and offers.
Kept afterwards: technical records of scans made — a time, a cost and a one-way fingerprint of an image — with your account no longer attached to them. They contain nothing that identifies you, and they are how we account for what scanning costs.
Kept where the law requires it: records of a completed transaction may be held for up to six years for tax and accounting purposes.
Your rights
You can ask us to do any of the following, free of charge, by writing to contact@tomointeractive.com. We will respond within one month.
Access — get a copy of the personal data we hold about you.
Rectification — have anything inaccurate corrected. Most of it you can already edit yourself in Profile.
Erasure — have your account and data deleted. You do not have to ask: Profile has a Delete my account button that does it immediately.
Portability — receive your data in a machine-readable format, or have it sent to another service.
Restriction and objection — ask us to stop using your data in a particular way, including anything we do on the basis of legitimate interests.
Withdraw consent — for anything you agreed to optionally, at any time.
Complaints
If you think we have handled your data badly, please tell us first at contact@tomointeractive.com — most things are quicker to fix directly.
You also have the right to complain to the Information Commissioner's Office at ico.org.uk, or to the data protection authority in your own country if you are in the EU. Complaining to us first is not a condition of that right.
Children
ByeThings is not for children. You must be at least 18 to hold an account, unless a parent or guardian has agreed to it and supervises your use — see the Terms and Conditions.
We do not knowingly collect personal data from anyone under 18 who is using the app without that permission. If you believe a child has given us their data, write to contact@tomointeractive.com and we will delete it.
Security
All traffic between the app and our servers is encrypted in transit. Your data is protected at the database level by rules that check who is asking before returning a row, so an account can only ever read what belongs to it.
No service can promise it will never be breached. If a breach affects your personal data and is likely to be a risk to you, we will tell you, and the ICO within 72 hours, as the law requires.
Changes
This policy was last updated on 2026-07-28. If we change it in a way that materially affects you, we will tell you in the app before it takes effect rather than quietly replacing the page.