The short version
Duoheart is built so that we, the people who run it, cannot read your messages, your daily answers, or your call audio and video. They are encrypted on your device before they ever leave it, using a key only you and your partner hold. We store ciphertext, not your conversation.
What we collect
We collect the minimum needed to run the service:
- Your email address, used to sign you in with a one-time code.
- Your public encryption key, so your partner’s device can securely share your couple’s conversation key with you.
- Encrypted message and answer content - we store the ciphertext only, we do not hold the key to decrypt it.
- Basic account and subscription metadata (creation date, language, subscription status) needed to operate the app.
What we never see
The content of your messages, your daily question answers, your photos and videos sent in chat, and your call audio or video. All of this is end-to-end encrypted with a key derived on your devices - Duoheart’s servers never possess it.
Third-party services
We use Supabase for authentication, database, and realtime infrastructure, and standard payment processors for subscriptions. These providers process encrypted data or billing information - never your decrypted conversation.
Your rights
You can request a copy of your account data or request deletion of your account and all associated data at any time by contacting privacy@duoheart.app. Deleting your account permanently deletes your encrypted data - we cannot recover it afterward, by design.
Changes
If we make material changes to this policy, we’ll notify you in the app before they take effect.
Contact
Questions about this policy: privacy@duoheart.app