Privacy Policy
1. Summary
CheekyBell is a couples communication app. We treat intimate data with the highest care. This policy explains what we collect, why, where it lives, how long we keep it, and how to exercise your rights.
We follow these core principles:
- Privacy by default. Analytics and crash reporting are off until you opt in.
- No ads in the current production build. AdMob is disabled. We will update this policy and request any applicable consent before enabling ads.
- Data minimization. We collect only what is required to operate the features you use.
- You stay in control. Export and deletion tools are first-class features, not legal afterthoughts.
2. Legal bases
Legal bases under GDPR Art. 6(1):
| Processing | Basis |
|---|---|
| Account, pairing, and in-app communication | Contract (Art. 6(1)(b)) |
| Push-token registration and enabled partner-notification delivery | Contract (Art. 6(1)(b)) |
| Optional rendezvous place and foreground location | Contract (Art. 6(1)(b)); requested only when you invoke the feature |
| Support requests, replies, and service communication | Contract (Art. 6(1)(b)); legitimate interest for signed-out requester support |
| Crash reports (after consent) | Consent (Art. 6(1)(a)) |
| Analytics events (after consent) | Consent (Art. 6(1)(a)) |
| Fraud / abuse prevention, rate limiting | Legitimate interest (Art. 6(1)(f)) |
| Security audit logs | Legitimate interest + legal obligation |
For users in the United States, the same disclosures double as our CCPA/CPRA notice. We do not "sell" or "share" personal information as those terms are defined under California law.
3. What we collect
In short, we collect:
- Identity: email, display name, and hashed identifier for partner discovery. A phone number is optional profile/pairing data, not a phone-sign-in method.
- Profile (optional): avatar, gender, relationship type, age range, fertility goal.
- Pairing & social graph: partnerships, blocks, invite codes, referral codes, and deferred deep links.
- Recommendation shares: when you choose a share action, the time, your internal account identifier, and your referral code are recorded to operate referral attribution. This means a share action was selected, not that a message was delivered. The system share framework may transiently return the selected action so the app can distinguish selection from dismissal; CheekyBell discards it and does not store or transmit the target app. We do not receive your recipients, message content, contacts, or link clicks.
- Communication: chat messages between paired users, bell ring events, message reactions, replies.
- Bell customization: text, images, materials, presets, history.
- Optional features: fertility cycle entries, Belle chat history, position match votes, name match votes, gift / flower events, and rendezvous proposals including the selected place and coordinates.
- Device: FCM/APNs push token, where registered, plus device platform, app version, locale, country (from system).
- Support: category, subject, description, case replies and, for the signed-out public form, a contact email. Signed-in app users may separately opt in to attach a previewed allowlist of app/build version, OS family/version, device model, locale, connectivity and an optional correlation ID.
- Operational: rate-limit counters, security audit log, optional crash reports, optional product analytics.
If you use Rendezvous, the place and its coordinates are stored with the proposal and shared with the invited partner. CheekyBell requests foreground device location only after you tap Current location; it never requests background location, and you can enter a place instead. We do not collect microphone recordings or read your contacts list. Pairing links are handed to the system share sheet without giving CheekyBell access to your recipients. Camera and photo access are requested only at the point of use for a user-selected chat/profile image or QR-code scan. Advertising identifiers are not used while ads are disabled.
4. How we use the data
- Operate the bell, chat, fertility, position/name matchers, virtual flowers, and rendezvous features, including showing and sharing a user-selected meeting place.
- Register push tokens and deliver enabled partner notifications through FCM (Android) or APNs (iOS). Delivery depends on device, network, platform permission, and battery restrictions and is not guaranteed.
- Detect abuse (rate limiting, IP blocking, security audit log).
- Receive, triage and reply to support cases, and publish bilingual service incidents. Support diagnostics are off by default and exclude intimate content.
- Carry a pairing or recommendation code through a first Android Play Store install and attribute a new account when the recipient completes sign-up.
- If you opt in: aggregate, de-identified analytics for product improvement and crash diagnostics.
We do not use your intimate content (chat, bell config, fertility entries, AI chats) to train any ML model.
5. Where the data lives
| Service | Purpose | Region |
|---|---|---|
| Supabase Postgres | Primary database | United States (AWS us-east-1) |
| Supabase Storage | Avatars, chat images, bell branding | United States (AWS us-east-1) |
| Supabase Edge Functions | Server-side app operations | United States (AWS us-east-1) |
| Google OAuth | Optional Google sign-in | Google global |
| Resend | Transactional email delivery | Resend delivery infrastructure |
| Cloudflare Turnstile | Bot and abuse prevention during authentication and signed-out public support requests | Cloudflare global |
| Firebase Cloud Messaging / APNs | Push-token registration and delivery of enabled partner notifications | Google / Apple global |
| Firebase Analytics (opt-in) | Product analytics | Google global |
| Firebase Crashlytics (opt-in) | Crash reporting | Google global |
| Google AdMob | Not active in the current production build | Not applicable while disabled |
| AI inference provider | Processes Belle AI requests only when invoked, through the server-side proxy | Provider infrastructure |
For EU/EEA users, transfers to Google/Apple are covered by Standard Contractual Clauses and the EU-US Data Privacy Framework where applicable.
Authentication and signed-out public support requests use Cloudflare Turnstile to help distinguish people from automated abuse. Depending on risk, the short security check may be visible. For Cloudflare's handling of the limited browser and device signals used for that check, see the Cloudflare Turnstile Privacy Addendum.
6. Sharing & third parties
We share personal data only with:
- Sub-processors listed above, strictly to operate the service.
- Your partner, who can see whatever you choose to share inside the partnership, including a rendezvous place and its coordinates.
- Authorities, when legally compelled. We disclose minimum required and notify you unless prohibited.
We never sell or rent data to advertisers or data brokers. No advertising SDK requests are made while ads are disabled in the current production build.
7. Retention
| Data | Retention |
|---|---|
| Account profile | Until you delete the account |
| Chat messages | Up to per-partnership chat-history limit + user-controlled delete |
| Bell ring events | 24 hours after delivery (auto-expired) |
| Bell configuration history | Last 50 versions per user |
| Fertility cycles | Until you delete or close the account |
| AI chat (Belle) summaries | Until you delete or close the account |
| Push tokens | Until app is uninstalled or token rotates |
| Security audit log | 90 days (rolling) |
| Rate-limit counters | 24 hours; public support identifiers are HMAC-pseudonymized before storage |
| Support cases and replies | While active, then 180 days after closure; the closed case and its replies are purged together |
| Recommendation share event | Until account deletion |
| Crash reports (if opted in) | 90 days |
| Analytics events (if opted in) | 14 months (default Firebase retention) |
| Rendezvous places and coordinates | Until the rendezvous/partnership or account is deleted; a saved home location remains until replaced or account deletion |
8. Your rights
- Access — export all your data via Settings → Account → Export My Data.
- Rectify — edit your profile, bell, fertility data, etc. directly in the app.
- Delete — delete the account from Settings → Account → Delete Account, or use the public deletion request page if you cannot access the app.
- Withdraw consent — toggle Analytics / Crash Reporting off in Settings → Privacy any time.
- Object / restrict — contact support@cheekybell.com.
- Portability — the export file is JSON, machine-readable.
- Lodge a complaint — with your local supervisory authority.
We respond within 30 days.
9. Security
- Transport: TLS 1.2+ everywhere, HSTS enforced, and standard platform certificate validation is used. We do not represent certificate pinning as a deployed production control until its production pins are independently verified.
- At rest: Postgres encrypted at rest by Supabase. Sensitive secrets in Supabase Vault.
- Authentication: Supabase Auth with token rotation, optional biometric local lock, password 12-char minimum with complexity rules.
- Authorization: Row-Level Security on every public table.
- Audit: All admin actions and security-sensitive events written to
audit_log.
10. Children
CheekyBell is for adults aged 18 or older. We do not knowingly collect data from anyone under 18. If we learn we have, we delete the data and the account.
11. Changes to this policy
We will notify you in-app and via email before material changes take effect. The effective date at the top of this document is updated whenever we publish a new version.
12. Data controller and contact
Email: support@cheekybell.com
Postal: BASIC SOFT Számítástechnikai Fejlesztő és Szolgáltató Betéti Társaság, 2111 Szada, Margita utca 87., Hungary
This policy is intentionally written in plain language. If anything is unclear, ask us — privacy is a feature, not a checkbox.