Legal · Privacy

Privacy Policy

Version 1.0 · Effective 2026-05-26 · Last updated 2026-06-17

1. Summary

CheekyBell is a couples communication app. We treat intimate data with the highest care. This policy explains what we collect, why, where it lives, how long we keep it, and how to exercise your rights.

We follow these core principles:

  • Privacy by default. Analytics and crash reporting are off until you opt in.
  • Ad-free with Premium. The free tier shows banner ads via Google AdMob, served only after your consent; Premium removes them entirely. We never sell or rent your personal data.
  • Data minimization. We collect only what is required to operate the features you use.
  • You stay in control. Export and deletion tools are first-class features, not legal afterthoughts.

2. Who we are and the legal basis

The data controller is CheekyBell. For questions, GDPR/CCPA requests, or complaints: support@cheekybell.com.

Legal bases under GDPR Art. 6(1):

ProcessingBasis
Account creation, authentication, partner pairingContract (Art. 6(1)(b))
Push notification delivery to your partnerContract (Art. 6(1)(b))
Subscription billing & receipt verificationContract (Art. 6(1)(b))
Crash reports (after consent)Consent (Art. 6(1)(a))
Analytics events (after consent)Consent (Art. 6(1)(a))
Fraud / abuse prevention, rate limitingLegitimate interest (Art. 6(1)(f))
Security audit logsLegitimate interest + legal obligation

For users in the United States, the same disclosures double as our CCPA/CPRA notice. We do not "sell" or "share" personal information as those terms are defined under California law.

3. What we collect

In short, we collect:

  • Identity: email or phone, display name, hashed identifier for partner discovery.
  • Profile (optional): avatar, gender, relationship type, age range, fertility goal.
  • Pairing & social graph: partnerships, blocks, invite codes, deferred deep links.
  • Communication: chat messages between paired users, bell ring events, message reactions, replies.
  • Bell customization: text, images, materials, presets, history.
  • Optional features: fertility cycle entries, AI chat history with Belle, position match votes, name match votes, gift / flower events, rendezvous proposals.
  • Device: FCM/APNs push token, device platform, app version, locale, country (from system).
  • Operational: rate-limit counters, security audit log, optional crash reports, optional product analytics.

We do not collect: precise GPS location, contacts list, photo library beyond a single chosen image, microphone, camera (unless you explicitly grant it for an avatar), advertising identifiers (IDFA / AAID).

4. How we use the data

  • Operate the bell, chat, fertility, AI companion, position/name matchers, virtual flowers, and rendezvous features.
  • Deliver push notifications to the right partner via FCM v1 (Android) and APNs (iOS).
  • Verify in-app purchases and unlock entitlements (Premium, bell customization).
  • Detect abuse (rate limiting, IP blocking, security audit log).
  • If you opt in: aggregate, de-identified analytics for product improvement and crash diagnostics.

We do not use your intimate content (chat, bell config, fertility entries, AI chats) to train any ML model.

5. Where the data lives

ServicePurposeRegion
Supabase PostgresPrimary databaseEU (eu-west-1)
Supabase StorageAvatars, chat images, bell brandingEU (eu-west-1)
Supabase Edge FunctionsServer-side webhook + receipt verificationEU
Firebase Cloud MessagingAndroid push deliveryGoogle global
Apple Push Notification ServiceiOS push deliveryApple global
Firebase Analytics (opt-in)Product analyticsGoogle global
Firebase Crashlytics (opt-in)Crash reportingGoogle global
Google AdMob (free tier only)Banner adsGoogle global
Google Generative AI (Gemini)Belle AI chatGoogle global

For EU/EEA users, transfers to Google/Apple are covered by Standard Contractual Clauses and the EU-US Data Privacy Framework where applicable.

6. Sharing & third parties

We share personal data only with:

  1. Sub-processors listed above, strictly to operate the service.
  2. Your partner, who can see whatever you choose to share inside the partnership.
  3. Authorities, when legally compelled. We disclose minimum required and notify you unless prohibited.

We never sell or rent data to advertisers or data brokers. Free-tier ad delivery uses Google AdMob ad request context, and personalized ads are gated on consent.

7. Retention

DataRetention
Account profileUntil you delete the account
Chat messagesUp to per-partnership chat-history limit + user-controlled delete
Bell ring events24 hours after delivery (auto-expired)
Bell configuration historyLast 50 versions per user
Fertility cyclesUntil you delete or close the account
AI chat (Belle) summariesUntil you delete or close the account
Push tokensUntil app is uninstalled or token rotates
Security audit log90 days (rolling)
Rate-limit counters24 hours
Crash reports (if opted in)90 days
Analytics events (if opted in)14 months (default Firebase retention)

8. Your rights

  • Access — export all your data via Settings → Privacy → Export My Data.
  • Rectify — edit your profile, bell, fertility data, etc. directly in the app.
  • Delete — delete the account from Settings → Account → Delete Account, or use the public deletion request page if you cannot access the app.
  • Withdraw consent — toggle Analytics / Crash Reporting off in Settings → Privacy any time.
  • Object / restrict — contact support@cheekybell.com.
  • Portability — the export file is JSON, machine-readable.
  • Lodge a complaint — with your local supervisory authority.

We respond within 30 days.

9. Security

  • Transport: TLS 1.2+ everywhere, HSTS enforced. Mobile clients pin Supabase/Firebase certificate roots.
  • At rest: Postgres encrypted at rest by Supabase. Sensitive secrets in Supabase Vault.
  • Authentication: Supabase Auth with token rotation, optional biometric local lock, password 12-char minimum with complexity rules.
  • Authorization: Row-Level Security on every public table.
  • Audit: All admin actions and security-sensitive events written to audit_log.

10. Children

CheekyBell is for adults aged 18 or older. We do not knowingly collect data from anyone under 18. If we learn we have, we delete the data and the account.

11. Changes to this policy

We will notify you in-app and via email before material changes take effect. The effective date at the top of this document is updated whenever we publish a new version.

12. Contact

Email: support@cheekybell.com


This policy is intentionally written in plain language. If anything is unclear, ask us — privacy is a feature, not a checkbox.