Last updated: 26 Aug 2026

Privacy Policy

Your love story, encrypted — not even we can read it.

Heartbeat is a private, couples-only app. This policy explains what we collect, how we protect it, and how you stay in control.

1. End-to-end encryption

Every message, photo, video, and voice note is encrypted on your device with X25519 key exchange and AES-256-GCM before it leaves. Our servers store only unreadable .enc blobs. We cannot decrypt, read, or sell your content — even if compelled.

Safety numbers let you verify your partner in person. Your 12-word recovery phrase keeps your keys yours; without it, not even we can restore your history.

2. What we collect

We do not collect: message content, photo/video content, voice note content, location (unless you share a moment with location), contacts, or advertising IDs. We show no ads and use no trackers.

3. On-device security

Biometric App Lock (Face ID / fingerprint, fallback to device PIN) protects the app when you background it. Auto-lock triggers after 2 minutes in the background. Encrypted media storage and row-level database security scope every row strictly to your couple.

4. How we share data

We don't. Heartbeat has no public profiles, no discovery, no social graph, and no data brokers. Push notifications are relayed via Apple/Google push services but carry no readable content — only “new heartbeat” signals. WebRTC calls are peer-to-peer; no middleman sees or records them.

5. Your controls

6. Retention

Encrypted blobs are retained only until delivered and then pruned. If you delete your account, they are purged. No backups retain readable content.

7. International

App languages: English, Spanish, French. Data is hosted in encrypted form; keys never leave your devices. If you are in the EU/EEA or Saudi Arabia, you have rights to access, correct, export, or delete your data — contact us to exercise them.

8. Changes & contact

We’ll post updates here and bump the date above. Questions: privacy@heartbeat.living · Support