Privacy Policy
Lova holds things people don't usually write down — how you felt today, what you wrote about your relationship, what you're struggling with. So this page is written to be read, not to be skimmed past. It says what we store, who else can touch it, and — most importantly — what your partner can and cannot see.
1. Who we are
Lova is built and run by one person: Aliaksandr Kokh, an individual developer based in Belarus. There is no company behind it. That means the "data controller" — the party legally answerable for your data — is a private individual, not an organisation.
Contact:
- privacy@withlova.com — anything about your data, your rights, deletion, export
- safety@withlova.com — anything about safety, crisis handling, misuse
2. What Lova collects
Your account
- email address
- password (stored as a hash, never in readable form)
- your name
- gender
- age
- interface language
What you chose in onboarding
- what you want from the relationship right now — picked from a fixed list
- your love language, and the answers you gave to work it out
- the time of day you want to hear from Lova, and whether notification previews are hidden
About your couple
This lives in a shared couple record, not in your personal record:
- your partner's name, as you typed it
- the date your relationship started
- marital status, and a wedding date if you gave one
- whether you have children, and the age of the youngest
Your day
- mood — chosen from a fixed list of five values, not free text
- whether you marked today's suggestion as applied
- whether you liked the suggestion or not
The intake questionnaire
- four free-text answers about you and about your relationship
AI content
- the text of the suggestions generated for you
- the text of the weekly letters
Safety
The fact that the crisis classifier fired: the category, the confidence score, a postpartum flag, when it happened, and which part of the app it happened in.
The text that triggered it is never stored. Not in the database, not in logs, not anywhere. Only the outcome is kept.
Technical
- your time zone, and whether notifications are switched on
- when you last opened the app
- device type, OS version and app version — these are attached automatically to crash reports and analytics events, and we don't store them ourselves
- your device's push token stays with OneSignal, not with us. What we give them is your Lova account id, because a notification needs an address
Subscription
- status, start and end dates, plan
3. What Lova does not collect
We do not collect, and the app does not ask for:
- your location
- your photo library
- your microphone
- advertising identifiers (IDFA)
- your browsing activity outside the app
Three permissions iOS may ask you for, and what each is actually for:
- Camera — only to scan your partner's invite code. Nothing is photographed, saved, or uploaded; the camera reads a QR code and closes.
- Contacts — only when you tap "save these numbers" on the crisis-resources screen, so the helplines are in your phone when you need them. Lova writes contacts and never reads your address book. (iOS grants read and write together here; the app simply doesn't have a code path that reads.)
- Face ID — an optional lock on your own questionnaire answers. The check happens on your device, and we never receive anything biometric.
And beyond that:
- No ads. There is no advertising in Lova.
- No selling data. We do not sell your data and do not pass it to data brokers.
- No cross-app tracking. Our App Privacy Manifest declares
NSPrivacyTracking = false, and Lova never shows the tracking permission dialog. - No payment details. Purchases go through Apple. Lova never sees your card number.
4. Why we're allowed to process this
| What | Legal basis |
|---|---|
| Running your account, storing your profile, couple data, moods and suggestions (Supabase) | Performance of our contract with you |
| Sending your data to a language model to generate suggestions and run the crisis classifier (Anthropic) | Performance of our contract plus your explicit consent, given on a dedicated screen during onboarding |
| Push notifications (OneSignal) | Your consent, given through the iOS system dialog |
| Crash reports (Sentry) | Our legitimate interest in keeping the app from breaking |
| Product analytics (Mixpanel) | Our legitimate interest in understanding which parts of the app work. Events carry no free text and nothing about safety, and none of it is used for advertising |
| Subscription management (RevenueCat, Apple In-App Purchase) | Performance of our contract, and our legal obligation to keep records of purchases |
You can withdraw consent where consent is the basis. Withdrawing consent for the AI processing means Lova can no longer generate suggestions for you, which is the entire product. Where the basis is our legitimate interest, you can object — write to privacy@withlova.com and we'll stop.
5. Who else touches your data
These are the only third parties in the current build.
Supabase — database, authentication, server functions.
Region: Seoul (ap-northeast-2). Holds essentially everything
listed in section 2.
Anthropic (Claude API) — generates the daily suggestions and runs the crisis classifier. Location: United States. What is sent to the model: your name, your mood, your goal, your love language, your couple context, your questionnaire answers, and your previous suggestions. Anthropic does not train its models on data sent through the API.
OneSignal — push notifications. Location: United States. Holds your device token, your Lova account id, and the text of the notifications sent to you.
Mixpanel — product analytics. Region: US. What goes there: the fact that an event happened, plus properties drawn from fixed lists, linked to your Lova account id. What never goes there: suggestion text, questionnaire answers, names — and never crisis events, crisis categories, or safety flags of any kind. This isn't a promise about our discipline: the analytics interface has no field a free-text value would fit into, and no method for crisis at all.
Sentry — crash reports. Sent without personal data
attached (sendDefaultPii is off).
RevenueCat — subscription management. Receives your Lova account id and Apple's purchase receipt. Never card details.
Apple In-App Purchase — payment.
Not in Lova: Firebase, Google Analytics, Facebook SDK, Sign in with Apple, Google Sign-In, and any advertising network. None of these are in the build.
6. Data leaving your country
Your data is stored in South Korea (Supabase) and processed in the United States (Anthropic, OneSignal, Mixpanel, Sentry, RevenueCat). If you are in the EU, the UK, or another region with data transfer rules, this means your data leaves that region.
For these transfers we rely on the data processing agreements each of these providers offers as part of their terms, which incorporate the European Commission's Standard Contractual Clauses. If you want to see which agreement applies to a particular provider, write to privacy@withlova.com.
7. Privacy inside a couple
This is the part that matters most, so it gets the most space.
Lova is used by two people who share one AI context. Sharing a context is not the same as sharing your answers. The whole design rests on that distinction.
7.1 Your questionnaire answers are yours alone
The four free-text answers you write about yourself and your relationship are never shown to your partner. Not directly, not in summary, not quoted, not paraphrased — and not inside the text of the suggestions your partner receives. There is no view, screen, or export in Lova that surfaces one partner's answers to the other.
7.2 What your partner actually sees
- your name
- your mood for today
- your moods across the current week, in the weekly letter — the five values themselves, with nothing written under them
- the shared suggestions for the couple, and whether one of you has marked today's as done
- the counter of days you've been together
- that your subscription is active — because in a Couple plan one payment opens the app for both, and the other person has to know the app works
That's the complete list.
7.3 Crisis events are invisible
Crisis classifier events and safety flags are not visible to your partner at all, and they are not displayed anywhere in the interface — including your own.
The reason is blunt: a phone can end up in the other person's hands. A screen that says "we detected a crisis signal" is a risk to the person it's supposed to protect. So there isn't one.
7.4 Hidden previews
You can turn on hide previews. With it on, push notifications arrive with no content — one neutral line, no buttons, nothing about what the suggestion says or how you're doing.
Use it if your phone is visible to other people.
7.5 If the couple breaks up
The shared couple context is deleted. Each person's own personal data stays with them, in their own account. Ending a relationship in Lova does not hand either person the other's data, and does not delete either person's account.
8. Safety signals
Lova runs a classifier that looks for signs of crisis, including postpartum-related signals.
What is kept: the category, the confidence score, the postpartum flag, the time, and which part of the app it happened in.
What is not kept: the raw text. Ever. It is not written to the database, and the classifier's input is not retained.
Where it does not go: not to Mixpanel, not to your partner, not into the interface.
Questions about this: safety@withlova.com.
9. The AI part
Lova is not therapy, not couples counselling, not medical care, and not a crisis service. If you're in danger or in crisis, contact local emergency or crisis services.
The suggestions are generated by a language model. They can be wrong, off-base, or simply not right for your situation. Treat them as a prompt to talk to each other, not as professional advice.
Everything AI-generated is marked as such in the interface.
Before the first call to the model, Lova shows a dedicated screen asking for your explicit consent to send your data for processing. Nothing is sent to the model before you agree.
More on how this works, and what Lova will never advise, on the safety page.
10. Notifications
Push notifications go through OneSignal and are sent only if you allow them in the iOS system dialog. You can turn them off in iOS Settings at any time.
See hidden previews if you want notifications without visible content.
11. Age: adults only
Lova is for adults, 18 and over.
We ask your age during onboarding, and the app does not let anyone under 18 through. We do not knowingly collect data from children. If you believe a minor is using Lova, write to privacy@withlova.com and we'll delete the account.
12. Deleting your account, and how long we keep things
You can delete your account from inside the app. It is irreversible.
Deletion cascades and removes:
- your profile
- your questionnaire answers
- your moods
- your suggestions
- crisis events and safety flags
- your subscription record
- your membership in the couple
Your partner keeps their own Lova and their own data. Deleting your account does not delete theirs. One thing that stays with them: the weekly letters written for the two of you, because they were addressed to both. Your personal answers are not in them and are gone with everything else. If nobody is left in the couple, the shared record is deleted too.
Retention
While your account is active, we keep the data described in section 2 so the app can work.
- Safety flags expire by themselves 30 days after they're set — that limit is in the database, not in a routine somebody has to remember to run.
- Deleted data can survive for a short while in our provider's encrypted database backups — no longer than 30 days — before those backups are overwritten.
- Crash reports in Sentry are kept for 90 days under that provider's standard retention.
- Analytics events in Mixpanel are kept while the project is active; ask us and we'll delete yours.
13. Your rights
You have the right to:
- access — get a copy of what we hold about you
- correction — fix anything wrong
- deletion — have your data erased
- objection — object to processing
- portability — receive your data in a portable form
How to use them: write to privacy@withlova.com. We respond within 30 days.
One honest note: data export is currently done by hand. There's no self-service export button yet. Ask by email and we'll put it together for you.
If you're in the EU, the UK, or another region with a data protection authority, you can also complain to the supervisory authority where you live. We'd rather you wrote to us first, but that's your right and it doesn't depend on us.
14. Changes to this policy
If we change this policy, we'll update the effective date at the top. For changes that affect what we collect or who we share it with, you'll get an in-app notice and an email before the change takes effect.
15. Contact
- privacy@withlova.com — data, rights, deletion, export
- safety@withlova.com — safety and crisis handling
Controller: Aliaksandr Kokh, individual developer, Belarus.