Legal · Privacy

Privacy Policy

Version 1.7 · Effective 2026-08-24 · Last updated 2026-08-24

1. Summary

CheekyBell is a couples communication app. We treat intimate data with the highest care. This policy explains what we collect, why, where it lives, how long we keep it, and how to exercise your rights.

We follow these core principles:

  • Privacy by default. Analytics and crash reporting are off until you opt in.
  • No ads in the current production build. AdMob is disabled. We will update this policy and request any applicable consent before enabling ads.
  • Data minimization. We collect only what is required to operate the features you use.
  • You stay in control. Export and deletion tools are first-class features, not legal afterthoughts.

2. Legal bases

Legal bases under GDPR Art. 6(1):

ProcessingBasis
Account, pairing, and in-app communicationContract (Art. 6(1)(b))
Push-token registration and enabled partner-notification deliveryContract (Art. 6(1)(b))
Optional rendezvous place and foreground locationContract (Art. 6(1)(b)); requested only when you invoke the feature
Support requests, replies, and service communicationContract (Art. 6(1)(b)); legitimate interest for signed-out requester support
Crash reports (after consent)Consent (Art. 6(1)(a))
Analytics events (after consent)Consent (Art. 6(1)(a))
Fraud / abuse prevention, rate limitingLegitimate interest (Art. 6(1)(f))
Security audit logsLegitimate interest + legal obligation

For users in the United States, the same disclosures double as our CCPA/CPRA notice. We do not "sell" or "share" personal information as those terms are defined under California law.

3. What we collect

In short, we collect:

  • Identity: email, display name, and hashed identifier for partner discovery. A phone number is optional profile/pairing data, not a phone-sign-in method.
  • Profile (optional): avatar, gender, relationship type, age range, fertility goal.
  • Pairing & social graph: partnerships, blocks, invite codes, referral codes, and deferred deep links.
  • Recommendation shares: when you choose a share action, the time, your internal account identifier, and your referral code are recorded to operate referral attribution. This means a share action was selected, not that a message was delivered. The system share framework may transiently return the selected action so the app can distinguish selection from dismissal; CheekyBell discards it and does not store or transmit the target app. We do not receive your recipients, message content, contacts, or link clicks.
  • Communication: chat messages between paired users, bell ring events, message reactions, replies.
  • Bell customization: text, images, materials, presets, history.
  • Optional features: fertility cycle entries, Belle chat history, position match votes, name match votes, gift / flower events, and rendezvous proposals including the selected place and coordinates.
  • Device: FCM/APNs push token, where registered, plus device platform, app version, locale, country (from system).
  • Support: category, subject, description, case replies and, for the signed-out public form, a contact email. Signed-in app users may separately opt in to attach a previewed allowlist of app/build version, OS family/version, device model, locale, connectivity and an optional correlation ID.
  • Operational: rate-limit counters, security audit log, optional crash reports, optional product analytics.

If you use Rendezvous, the place and its coordinates are stored with the proposal and shared with the invited partner. CheekyBell requests foreground device location only after you tap Current location; it never requests background location, and you can enter a place instead. We do not collect microphone recordings or read your contacts list. Pairing links are handed to the system share sheet without giving CheekyBell access to your recipients. Camera and photo access are requested only at the point of use for a user-selected chat/profile image or QR-code scan. Advertising identifiers are not used while ads are disabled.

4. How we use the data

  • Operate the bell, chat, fertility, position/name matchers, virtual flowers, and rendezvous features, including showing and sharing a user-selected meeting place.
  • Register push tokens and deliver enabled partner notifications through FCM (Android) or APNs (iOS). Delivery depends on device, network, platform permission, and battery restrictions and is not guaranteed.
  • Detect abuse (rate limiting, IP blocking, security audit log).
  • Receive, triage and reply to support cases, and publish bilingual service incidents. Support diagnostics are off by default and exclude intimate content.
  • Carry a pairing or recommendation code through a first Android Play Store install and attribute a new account when the recipient completes sign-up.
  • If you opt in: aggregate, de-identified analytics for product improvement and crash diagnostics.

We do not use your intimate content (chat, bell config, fertility entries, AI chats) to train any ML model.

5. Where the data lives

ServicePurposeRegion
Supabase PostgresPrimary databaseUnited States (AWS us-east-1)
Supabase StorageAvatars, chat images, bell brandingUnited States (AWS us-east-1)
Supabase Edge FunctionsServer-side app operationsUnited States (AWS us-east-1)
Google OAuthOptional Google sign-inGoogle global
ResendTransactional email deliveryResend delivery infrastructure
Cloudflare TurnstileBot and abuse prevention during authentication and signed-out public support requestsCloudflare global
Firebase Cloud Messaging / APNsPush-token registration and delivery of enabled partner notificationsGoogle / Apple global
Firebase Analytics (opt-in)Product analyticsGoogle global
Firebase Crashlytics (opt-in)Crash reportingGoogle global
Google AdMobNot active in the current production buildNot applicable while disabled
AI inference providerProcesses Belle AI requests only when invoked, through the server-side proxyProvider infrastructure

For EU/EEA users, transfers to Google/Apple are covered by Standard Contractual Clauses and the EU-US Data Privacy Framework where applicable.

Authentication and signed-out public support requests use Cloudflare Turnstile to help distinguish people from automated abuse. Depending on risk, the short security check may be visible. For Cloudflare's handling of the limited browser and device signals used for that check, see the Cloudflare Turnstile Privacy Addendum.

6. Sharing & third parties

We share personal data only with:

  1. Sub-processors listed above, strictly to operate the service.
  2. Your partner, who can see whatever you choose to share inside the partnership, including a rendezvous place and its coordinates.
  3. Authorities, when legally compelled. We disclose minimum required and notify you unless prohibited.

We never sell or rent data to advertisers or data brokers. No advertising SDK requests are made while ads are disabled in the current production build.

7. Retention

DataRetention
Account profileUntil you delete the account
Chat messagesUp to per-partnership chat-history limit + user-controlled delete
Bell ring events24 hours after delivery (auto-expired)
Bell configuration historyLast 50 versions per user
Fertility cyclesUntil you delete or close the account
AI chat (Belle) summariesUntil you delete or close the account
Push tokensUntil app is uninstalled or token rotates
Security audit log90 days (rolling)
Rate-limit counters24 hours; public support identifiers are HMAC-pseudonymized before storage
Support cases and repliesWhile active, then 180 days after closure; the closed case and its replies are purged together
Recommendation share eventUntil account deletion
Crash reports (if opted in)90 days
Analytics events (if opted in)14 months (default Firebase retention)
Rendezvous places and coordinatesUntil the rendezvous/partnership or account is deleted; a saved home location remains until replaced or account deletion

8. Your rights

  • Access — export all your data via Settings → Account → Export My Data.
  • Rectify — edit your profile, bell, fertility data, etc. directly in the app.
  • Delete — delete the account from Settings → Account → Delete Account, or use the public deletion request page if you cannot access the app.
  • Withdraw consent — toggle Analytics / Crash Reporting off in Settings → Privacy any time.
  • Object / restrict — contact support@cheekybell.com.
  • Portability — the export file is JSON, machine-readable.
  • Lodge a complaint — with your local supervisory authority.

We respond within 30 days.

9. Security

  • Transport: TLS 1.2+ everywhere, HSTS enforced, and standard platform certificate validation is used. We do not represent certificate pinning as a deployed production control until its production pins are independently verified.
  • At rest: Postgres encrypted at rest by Supabase. Sensitive secrets in Supabase Vault.
  • Authentication: Supabase Auth with token rotation, optional biometric local lock, password 12-char minimum with complexity rules.
  • Authorization: Row-Level Security on every public table.
  • Audit: All admin actions and security-sensitive events written to audit_log.

10. Children

CheekyBell is for adults aged 18 or older. We do not knowingly collect data from anyone under 18. If we learn we have, we delete the data and the account.

11. Changes to this policy

We will notify you in-app and via email before material changes take effect. The effective date at the top of this document is updated whenever we publish a new version.

12. Data controller and contact

Email: support@cheekybell.com
Postal: BASIC SOFT Számítástechnikai Fejlesztő és Szolgáltató Betéti Társaság, 2111 Szada, Margita utca 87., Hungary


This policy is intentionally written in plain language. If anything is unclear, ask us — privacy is a feature, not a checkbox.