hearto
Privacy Policy
Last updated: September 5, 2026
1. Information we collect
- Account information: email address, username, password (stored hashed by our authentication provider, Supabase Auth — never in plain text), and, if you use Sign in with Apple, the identifier Apple provides.
- Content: photos, captions, comments, direct messages, and likes you post or send.
- Usage data: follows, likes, reports, and blocks you make, used to operate the following feed and moderation queue.
- Device/technical data: standard mobile network data, plus crash and error diagnostics (e.g. what the app was doing when it crashed) sent to Sentry or equivalent for error monitoring. These reports are not linked to your account or identity.
- Precise location: if you choose to tag a post with your location or use the Nearby feed, we collect your device's precise GPS coordinates at that moment. Denying location access disables only these features — everything else in the app still works.
We do not collect contacts.
2. How we use information
- To operate your account, the following feed, and social features (follows, likes, comments);
- To detect likely AI-generated images before they publish, using a third-party detection API (Sightengine or equivalent);
- To screen photos, captions, comments, and direct messages for content that violates our Community Guidelines (e.g. sexual, violent, or harassing content) before they're posted or sent, using a third-party moderation API (OpenAI's moderation service or equivalent);
- To review reports and enforce our Community Guidelines;
- To communicate with you about your account (e.g. security notices).
3. Third parties we share data with
- Supabase — database, authentication, file storage, and backend functions (supabase.com/privacy).
- Sightengine (or equivalent) — receives the URL of uploaded photos to return an AI-content likelihood score. It does not receive your account information.
- OpenAI (or equivalent) — receives photo URLs, captions, comments, and direct message text to check for content-policy violations before publishing. It does not receive your account information beyond the content itself.
- Apple — if you sign in with Apple, authentication is handled by Apple per their privacy terms.
- Sentry (or equivalent) — receives crash and error diagnostics to help us fix bugs. Not linked to your account or identity.
We do not sell your personal information.
4. Data retention and deletion
You can permanently delete your account at any time from Settings. This removes your profile, posts, comments, follows, likes, and messages (including from conversations with other users), and deletes your uploaded media from storage. Deletion is immediate and cannot be undone.
5. Age requirement
hearto requires users to be at least 16 years old. Because the app hosts unrestricted user-generated content, its App Store age rating is set to 17+.
6. Your rights
Depending on where you live, you may have rights to access, correct, or delete your personal information, and to object to certain processing. Contact us at wli950574@gmail.com to exercise these rights; account deletion is also available directly in the app.
7. Changes to this policy
We'll update the "Last updated" date above when this policy changes and, for material changes, notify you in the app.
8. Contact