privacy policy
What stays between you, stays between you.
Effective: August 27, 2026.
The short version
- Notes about your moments are end-to-end encrypted on your devices. Our servers store ciphertext only.
- We do not sell, share, or train any model on your private data.
- Feedback stays private unless you separately opt in to sharing a normalized signal for couple recommendations.
- Comments are community content: they are moderated and visible only to signed-in members entitled to the underlying content.
- No advertising trackers. Analytics are aggregate and pseudonymous.
- You can export your data or delete your account at any time.
What we collect
- Account identifiers — Apple/Google subject ID or a hashed email.
- Device metadata — platform, encrypted push token, public key for E2E key exchange.
- Moment metadata — timestamp, initiator, location chip, rating, style tags.
- Notes — stored as ciphertext only. We cannot read them.
- Content activity — whether you opened, saved, or completed a Date or Therapist item.
- Structured feedback — your private rating of a Spark, Date, or Therapist item.
- Community comments — the comment text and public identity option you choose, plus moderation status and timestamps.
What we do not collect
- Your email address (stored only as a salted hash for sign-in dedup).
- Your phone’s location, contacts, microphone, or camera.
- Plaintext notes, photos, or voice memos.
How we use it
To run the app: sync between you and your partner, send the gentle reminders you opt into, produce observations and recommendations, and operate the moderated community comments feature. Notes and comment text are never used as personalization signals.
Feedback and personalization
Raw Spark, Date, and Therapist feedback belongs to the person who submitted it and is private by default. Each category has its own default-off consent control. If you opt in, Luvally creates a normalized preference signal for your couple’s recommendations instead of sharing your original response. Turning a consent off removes that category’s projection. Your partner cannot see the underlying feedback.
Community comments
Comments are reviewed before publication. Once approved, a comment is visible only to authenticated members who can access the related content. The public comment shows the identity option you chose; moderators can see the underlying author account for safety and enforcement. Editing an approved comment removes it from public view until it is reviewed again. Comments are never used to personalize recommendations.
Deletion and retention
You can delete your comments at any time. Permanently deleting your account removes your comments and associated personal interaction data. We may retain a minimized, body-free moderation record containing identifiers, status changes, and timestamps for operational auditing; it does not retain the comment text, display name, email, or other author-identifying information.
Subprocessors
- Cloudflare — hosting, database, object storage
- Anthropic — generating the weekly observation from aggregate stats
- Stripe — payments (only if you subscribe to Premium)
- Resend — transactional email (invites, magic-link codes)
- Expo — push notifications (content-hidden)
Contact
Questions about privacy? Write to [email protected].