Dearest Heart
How it worksPrivacyWritingShop

Last updated 16 August 2026

Privacy Policy

Dearest Heart is an app for exactly two people. This policy is written to be accurate rather than short: it says what we hold, what we are technically unable to read, who else touches it, how long it lives and what you can make us do about it.

One thing is worth reading before the rest. The contents of your messages, letters, captions, voice notes and photos are end-to-end encrypted. The key is generated on your two devices and never transmitted to us. For that content we are not in a position to decide anything about it, disclose it, or restore it — which is a stronger guarantee than any promise in this document, and also a limit on what we can do for you.

Contents
  1. 1. Who is responsible
  2. 2. What we cannot read, and why that is verifiable
  3. 3. What we collect, why, and on what legal basis
  4. 4. What we do not collect
  5. 5. Who processes it for us
  6. 6. International transfers
  7. 7. How long it is kept
  8. 8. Your rights, and how to use them
  9. 9. Security
  10. 10. Children
  11. 11. Cookies and this website
  12. 12. Changes

1. Who is responsible

Lyvme (“we”, “us”) is the data controller for Dearest Heart and for dearestheart.app. Written enquiries, including requests under any of the rights below, go to privacy@dearestheart.app.

Registered address and company number: to be completed before release. If you are in the EEA or the UK and are not satisfied with our answer, you may complain to your own supervisory authority; in Turkey, to the Kişisel Verileri Koruma Kurumu (KVKK).

2. What we cannot read, and why that is verifiable

When two people pair, each device generates an X25519 key pair and publishes only the public half. Each side derives the same shared secret from its own private half and the other’s public half; that secret is never transmitted. It is stored in the device’s secure keychain, and a per-month key is derived from it (HKDF-SHA256) to encrypt each item with AES-GCM.

The consequences are not marketing:

  • We cannot produce the plaintext of your messages, letters, captions, voice notes or photos — not on request, not under a court order, and not to an attacker who obtains our database.
  • We cannot restore that content. If both members of a pair lose their devices and neither kept the recovery key, it is permanently unrecoverable.
  • Push notifications are sent as ciphertext. Your device decrypts and composes the text locally, in the moment before the banner is drawn.

The client is the only place plaintext exists. Where this policy talks about “content”, it means these encrypted items; everything else is listed plainly below.

3. What we collect, why, and on what legal basis

DataWhyLegal basis (GDPR Art. 6)
Email address; password (hashed, by Firebase Authentication — we never see it)To have an account at all, and to reset itContract (6(1)(b))
Display name, city, time zone, chosen languageShown to your partner; the city drives “their weather” and the distanceContract (6(1)(b))
Pairing: which two accounts form a couple, when, and single-use invite codesThe app is meaningless without itContract (6(1)(b))
Encrypted content: messages, letters, photos, voice notes, captionsTo deliver them to the other personContract (6(1)(b))
Content metadata: sender, timestamp, size, read receipts, the date a sealed letter opensOrdering, delivery, and enforcing the seal in the security rulesContract (6(1)(b))
Shared records: expenses and amounts, occasions, bucket list, countries visited, a song a day, flight details you scan from your own boarding passThe features you chose to useContract (6(1)(b))
Cycle data — health data under GDPR Art. 9Only if you use that feature. Stored where only your own account can read it; a narrowed copy is published for your partner only to the extent you chooseExplicit consent (9(2)(a)), which you withdraw by hiding it or deleting the entry
Calendar free/busy blocksOnly if you connect a calendar, to find hours you are both free and awake. Event titles only if you choose to share themConsent (6(1)(a))
Device push token, device public key, platformTo deliver notifications and to establish encryptionContract (6(1)(b))
Subscription status, store platform, purchase receiptTo unlock paid features for both of you and to verify a purchaseContract (6(1)(b))
Crash diagnostics (Firebase Crashlytics): device model, OS version, stack traceTo fix what crashedLegitimate interests (6(1)(f)) — keeping the app working
Reports you submit: who reported whom, when, the reason chosenSafety, and a legal obligation to act on abuse reportsLegitimate interests and legal obligation (6(1)(f), 6(1)(c))

Where the basis is consent, you may withdraw it at any time without affecting what was lawful before; where it is legitimate interests, you may object under Article 21.

4. What we do not collect

  • Your location. The city your partner sees is the one you typed. The app requests no location permission.
  • Your contacts or photo library. Only the photos you actively send leave your device.
  • Advertising identifiers. There is no advertising in Dearest Heart, no tracking SDK, no data broker, and nothing is sold or shared for cross-context behavioural advertising in the sense of the CCPA/CPRA.
  • Anything about people who are not users. We do not upload address books or build shadow profiles.

5. Who processes it for us

These are our processors. Each is bound by a data processing agreement and none of them is permitted to use your data for their own purposes.

ProcessorWhat it doesWhere
Google (Firebase Authentication, Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, Realtime Database, Crashlytics)Hosts the service and delivers notificationseurope-west3, Frankfurt, Germany
Apple / Google PlayTake the payment. We receive the fact and status of a subscription, never your card detailsPer their own terms
AeroDataBoxLive flight status. Sent a flight number and date only — never your identityEU
Google Calendar APIOnly if you connect it, and only free/busy timesGoogle
VercelServes dearestheart.app — this website, not the appEU region

Public metadata endpoints of music services are queried for a song’s title and artwork when you paste a link. No account, no sign-in and no identifier of yours is involved.

6. International transfers

Your data is stored in the European Union. Some processors are US-headquartered and may access data from outside the EEA for support and operations; those transfers rely on the European Commission’s Standard Contractual Clauses together with the EU–US Data Privacy Framework where the recipient is certified. For transfers out of Turkey we rely on your explicit consent or the undertakings permitted under Article 9 KVKK. A copy of the relevant safeguards is available on request.

7. How long it is kept

DataKept
Account and profileUntil you delete the account
Encrypted content and shared recordsUntil deleted by either of you, or until the account is deleted
Invite codes24 hours, then dead whether used or not
Push tokensUntil the device unregisters, signs out, or the token is rejected as dead
Crash reports90 days
Reports of abuseUp to 2 years, so a pattern can be recognised
BackupsPurged on a rolling basis within 30 days of deletion

8. Your rights, and how to use them

Under the GDPR and UK GDPR you have the rights of access (Art. 15), rectification (16), erasure (17), restriction (18), portability (20) and objection (21), and the right not to be subject to automated decision-making (22) — of which there is none here. Under KVKK Article 11 you have the equivalent rights. Under the CCPA/CPRA you have the rights to know, delete, correct and opt out; we do not sell or share personal information, so there is nothing to opt out of.

Two of these need no request at all:

  • Erasure — Settings → Safety → Delete account, inside the app. Immediate and permanent.
  • Objection to a partner’s access — unpair or block, which ends the pair, removes the key and cached content from your device, and stops that person reaching you.

For anything else write to privacy@dearestheart.app. We answer within 30 days (KVKK: 30 days; CCPA: 45). We will ask you to confirm you control the account’s email address, and nothing more — identity checks that collect a passport scan to protect a display name are their own privacy problem.

What we cannot do: hand over the plaintext of encrypted content, because we do not have it. An access request returns everything listed in section 3, and the ciphertext.

9. Security

  • Content is end-to-end encrypted (X25519 → HKDF-SHA256 → AES-GCM), with keys derived per calendar month so that a key recovered from an old device opens only the months it was present for.
  • Keys are held in the platform keychain, protected by the device passcode and available only after first unlock.
  • Every read and write is checked by server-side security rules, which are tested against an emulator on each change; a pair is exactly two accounts and its membership is immutable.
  • All traffic is TLS. Data at rest is encrypted by the platform, and content is additionally encrypted by you.
  • Optional device lock (Face ID, Touch ID or your passcode) in front of the app itself.
  • Should a breach occur that is likely to risk your rights, we notify the supervisory authority within 72 hours and you without undue delay.

10. Children

Dearest Heart is not directed at children. You must be at least 13, and at least 16 in the EEA unless a parent or guardian consents. We do not knowingly create accounts for children; if we learn of one, we delete it. Contact us at privacy@dearestheart.app if you believe a child has an account.

11. Cookies and this website

The app uses no cookies. This website uses none that are not strictly necessary unless you allow them; what there is, and how to change your mind, is set out in the Cookie Policy.

12. Changes

If this policy changes in a way that affects what we collect or why, we will say so in the app and on this page before the change takes effect, and — where the law requires it — ask for your consent again. The date at the top is the date of the current version.

WritingShopPrivacyTermsLicenceCookies
© Dearest Heart