Privacy & Cookie Policy

Privacy Policy Overview

This policy explains how Brustna Hjärtan collects, uses, and protects your personal information when you use our mobile app and associated web pages. We are committed to safeguarding your privacy and being transparent about how your data is handled.

Information We Collect

We collect information you provide when creating and using your account: email address, phone number (optional), display name, and username. Your profile may include birth date, gender, biography, spoken languages, and a profile image. We also store your interest categories and interest levels, as well as your responses to prompts like 'who am I' and 'why am I here'. Activity data includes chat messages, shared images, emoji reactions, saved and pinned messages, and status updates. We also store push notification device tokens and timestamps for your consent choices.

How We Use Your Information

Your information is used to power the matching algorithm, which considers your interest categories, spoken languages, and interest levels to connect you with compatible users. We use your data to deliver messages and push notifications, and to enable content moderation through admin review of user reports. We do not sell your personal data to third parties.

Data Storage & Security

Your data is stored via Supabase with row-level security (RLS) policies that restrict access at the database level. All connections are encrypted in transit. Profile images are stored in a public storage bucket, while chat images are stored in a private bucket accessible only to chat participants.

Third-Party Services

We use Supabase for our database, authentication, file storage, and server-side functions. Push notifications are delivered through the Expo Push Notification Service. We do not use third-party analytics, advertising, or behavioral tracking services.

Push Notifications

Push notifications are delivered via the Expo Push Notification Service and are entirely opt-in — you choose whether to enable them. Notifications may be triggered by new messages, new matches, and other activity. Your device token is stored securely and used solely for delivering notifications to your device.

Your Rights

You can request access to your personal data at any time. You may delete your account, which enters a 30-day grace period during which your data is preserved — after this period, your account is permanently removed and your messages are anonymized. You can pause your account to temporarily hide your profile from matching without losing your data. You can block other users at any time. For users in the EU, you have additional rights under GDPR including data portability and the right to object to data processing.

Cookies

The primary experience is through our mobile app, which does not use cookies. Our web pages use standard session cookies for authentication and preferences only. We do not use third-party tracking cookies.

Contact

For any privacy-related questions or requests, please reach out to us using the contact form on our website. We will respond to your inquiry as promptly as possible.