Skip to content
HeartTap

Legal

Privacy Policy

Last updated 20 August 2026

This policy explains what HeartTap collects, why, and what happens to it. HeartTap is operated by FlutterKada. If anything here is unclear, email admin@flutterkada.com and we will explain it in plain terms.

The short version

HeartTap is a private app for two people. There is no public feed, no followers and no discovery surface. The photos, videos, drawings and answers you send go to the partner you are linked with, and to nobody else. We do not sell your personal information, and we do not use the content you share to train machine learning models.

What we collect

Information you give us

  • Account details. An email address if you create a full account, along with a display name and optional profile photo. You can use HeartTap as a guest without an email address, and link an email later.
  • Content you share. Photos, videos, drawings, captions, status updates, question answers and daily check-in responses. This is stored so it can be delivered to your partner and shown in your shared timeline.
  • Your partner link. The fact that your account is connected to another account, and when that connection was made.

Information collected automatically

  • Device and app data. Device model, operating system version, app version, language and time zone, plus a device identifier used to deliver notifications.
  • Usage data. Which screens you open and which features you use, so we can see what is working and what is broken.
  • Diagnostics. Crash reports and error logs.

How we use it

  • To deliver your content to your partner and keep both phones in sync.
  • To send notifications and refresh your home screen widget.
  • To operate accounts, sign-in and subscriptions.
  • To diagnose crashes and fix problems.
  • To understand which features are used, in aggregate, so we can improve the app.
  • To detect abuse and to act on reports and blocks.

Service providers we use

We rely on the following third parties. Each one receives only what it needs to do its job, and each has its own privacy policy governing that data.

  • Supabase hosts our database, authentication and file storage. Your content and account data live here.
  • Firebase (Google) provides push notification delivery, crash reporting and analytics.
  • Apple Push Notification service delivers notifications on iOS devices.
  • RevenueCat manages subscription entitlements. Payment card details are handled entirely by Apple and Google, and never reach us or RevenueCat.
  • PostHog provides product analytics so we can see how features are used.
  • AppsFlyer provides install attribution, so we can tell which marketing brought someone to the app.

Payments

Subscriptions are purchased and billed through the App Store or Google Play. We never see or store your card number. We receive confirmation that a subscription is active, its tier and its renewal date.

How long we keep things

Account data is kept while your account exists. Content you share is kept so that you and your partner can see it in your timeline, until you delete it or delete your account. Media attached to status updates is removed automatically after 48 hours as part of routine cleanup. Diagnostic logs are kept for a limited period and then discarded.

Deleting your data

You can delete your account from inside the app under Profile. Deleting your account removes your account record and the content associated with it. Content you sent to your partner that they have saved to their own timeline may remain visible to them. Full instructions, including what to do if you no longer have the app installed, are on our account deletion page.

Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to certain processing, or ask for it in a portable format. Email admin@flutterkada.com to exercise any of these and we will respond within the period the law requires. We will never charge you for making a request or treat you differently for having made one.

Children

HeartTap is not intended for children. You must be at least 13 years old to use it, and older where your country sets a higher age for consent to data processing. If we learn that we hold data from a child below that age, we will delete it.

International transfers

Our providers operate infrastructure in several countries, so your data may be processed outside the country you live in. Where that happens, we rely on the safeguards offered by those providers for such transfers.

Security

Data is encrypted in transit. Access to production systems is restricted. No system is perfectly secure, and we do not claim that content shared through HeartTap is end-to-end encrypted. Content is stored in a form our infrastructure can process in order to deliver it to your partner and render your widget.

Changes to this policy

If we make a material change we will update the date at the top of this page and, where the change is significant, tell you in the app.

Contact

Questions about this policy, or about your data, go to admin@flutterkada.com.