· 3 min read
What a relationship app knows about you besides content
Even an app that cannot read your words knows a great deal. Metadata is the part nobody reads the policy for, and it is often the revealing part.

Content is what you wrote. Metadata is everything else: when, from where, how often, with whom, on what device, for how long.
People assume content is the sensitive part. In practice metadata is frequently more revealing, because it is structured, easy to analyse at scale, and rarely protected with the same care.
What metadata says without reading a word
Consider what is knowable about a couple from timing alone.
Two accounts that always used the app within minutes of each other, and then stopped for eleven days, and then one of them was active at three in the morning several nights running.
Nobody read anything. The shape of a difficult fortnight is fully legible.
Add location, which many apps collect by default, and you know which one left the house. Add device information and you know when someone got a new phone, which correlates with a great deal.
You can describe the arc of a relationship quite accurately without ever seeing a single sentence that was written in it.
The categories worth knowing about
Identifiers. Your account, your device, and advertising identifiers that let activity be joined up across different apps by third parties.
Usage. Sessions, timestamps, features touched, how long you stayed. Almost universally collected.
Diagnostics. Crash reports, which sometimes contain more than intended.
Location. Precise or coarse. Often collected when there is no product reason for it.
Contacts. Some apps request the address book, which exposes information about people who never installed anything.
Purchases. What you bought and when, which comes from the store rather than the app.
Third parties are usually where it goes
Most apps do not build their own analytics, crash reporting, advertising attribution or push infrastructure. They use services.
Each of those services receives some subset of the above, and each has its own policy, its own retention period and its own jurisdiction. This is the part that almost never appears clearly in a privacy policy, because it is a list of vendors rather than a sentence.
The practical consequence is that "we do not sell your data" can be entirely true while several companies you have never heard of hold records of when you used the app and from where.
How to read the actual answer
On the App Store and Google Play, look at the data safety disclosure rather than the marketing page. It is standardised and it is declared under penalty of removal, which makes it more reliable than prose.
Pay attention to the distinction between data linked to you and data not linked to you. Linked is the category that matters.
And look at what is collected for advertising or marketing, which is listed separately.
What Duoheart collects
We are a subscription product with no advertising, so there is no advertising identifier, no attribution network and no reason to collect location.
What we hold is what is required to run the service: an account, a pairing between two accounts, subscription status, and basic diagnostics. Content is encrypted on the devices with a key we never receive, so timing and volume are visible to us in the sense that any server sees that a request happened, and the content is not.
We do not think this makes us unusual in intent. Plenty of companies want to collect less. It is easier when the business model does not require more.
The question to ask
Not "is my content private" but "what is knowable about me from everything except my content."
For most apps the honest answer is: a great deal. For any app, it is worth knowing which.
Questions people ask
- What is metadata and why does it matter?
- Everything about an interaction except its content: timing, frequency, location, device. It is structured and easy to analyse, and it often reveals more than the content itself.
- Where do I find what an app actually collects?
- The data safety disclosure on Google Play and the privacy labels on the App Store are standardised and more reliable than marketing copy.
- Does end to end encryption protect metadata?
- No. It protects content. Timing, frequency and connection information remain visible to the operator regardless.


