Your words belong to you

Privacy

This notice describes the actual data flows of the app, website, and subscription processing.

Last updated 23 August 2026

Controller

The controller responsible for Love, Spoken is:

Katarzyna Ludwig
2209 Skyler Dr
Mount Pleasant, SC 29466-9394
United States
support@lovespoken.app

Send privacy requests to support@lovespoken.app. Further provider details appear in the legal notice.

Data we process

  • Account: stable Apple and Supabase user identifiers, plus name and email when Apple provides them.
  • Couple connection: display names, invitation, pair membership, language, time zone, rhythm, and selected topics, including the separate ordinary categories “Closeness & Connection” and “Intimacy & Sexuality”.
  • Personal content: audio recordings, written answers, confirmed transcripts, private AI drafts, approvals, memories, and weekly letters.
  • Device and operation: push token, app version, device/installation identifier, job status, product events, and necessary security and error categories.
  • Subscription: app account token, product, transaction identifiers, environment, purchase/expiry/revocation dates, and renewal, retry, and grace-period status. Love, Spoken does not receive full payment details.
  • Support and safety requests: sender, message, technical details, and private content only when you include it yourself in the request.

We do not sell personal data, use advertising trackers, or perform cross-app tracking.

Purposes and legal bases

Account, private two-person connection, answers, playback, timeline, letters, and subscription access are processed to perform our agreement with you. Optional AI processing takes place only with explicit consent that you can withdraw at any time.

Security, abuse prevention, safety requests, fraud prevention, and reliable operation rely on our legitimate interests and, where required, legal duties. We process support data to answer your request. Mandatory statutory retention obligations remain unaffected.

Supabase

Supabase is the operational backend for authentication, the PostgreSQL database, private object storage, server-side functions, and real-time updates. The project is hosted in the Frankfurt region.

Audio is stored in a private bucket. The app receives short-lived signed playback URLs. Row Level Security and server-side authorization restrict access to the relevant account and current couple connection.

On-device storage and background synchronisation

When local synchronisation is enabled for your account, the app keeps an on-device SwiftData copy of couple state, the 30-day question plan, answers, free moments, letters, chapters, settings, and sync status, separated by account, couple connection, and relationship epoch. A local outbox records changes that have not yet been confirmed. Personal text content and outbox payloads are encrypted with AES-GCM using a separate, non-synchronising device key for each account. The key is stored in the iOS Keychain and bound to that device.

Local app-support and audio files use iOS Data Protection and are excluded from iCloud backups. Audio is downloaded when needed or kept locally until a later upload; the encrypted LRU audio cache is limited to 300 MB. Recordings that have not yet been sent are not removed automatically from this cache.

This allows local content to appear immediately. When connectivity is available, the app synchronises with Supabase in the background, particularly when the network returns, the app becomes active, or a push wakes it. Supabase remains authoritative for couple membership, relationship epoch, blocking, mutual reveal, Premium status, and final delivery.

OpenRouter and optional AI

Before personal audio or text is optionally sent to OpenRouter for the first time, the app identifies the purpose and recipient and asks for your explicit, withdrawable consent. No AI request starts without this consent. Consent granted before the recipient changed must be granted again.

  • If you choose a transcript, the selected audio recording is sent.
  • If you request considerate wording, the original text, language, and a length limit are sent.
  • If you ask the app to create a weekly letter, only confirmed source text, language, week context, and required display names are sent.

You can also share a voice note without a transcript; for that step it is not sent to OpenRouter. Account and couple identifiers are not transmitted.

OpenRouter brokers the request to a model provider available for the selected model. Love, Spoken restricts the models by feature and requires endpoints that OpenRouter marks as Zero Data Retention and that deny data collection for every request. Response caching is not requested by Love, Spoken for personal content. Under OpenRouter's published ZDR rules, OpenRouter does not retain the content of these requests while prompt logging is not enabled, and the selected underlying endpoints may not retain it or use it for training. Technical usage data such as model, token or audio duration, cost, status, and time may be processed without the personal content for billing and operation.

Love, Spoken currently uses OpenAI text models through OpenRouter; transcription may be processed by the Whisper providers available there. The specific available providers may change, but remain restricted by the privacy filters above. The resulting transcript or private rewording or letter draft is stored in Supabase so that you can review it.

Vercel and StoreKit servers

Vercel delivers this website and runs the server-side Apple subscription processing in Frankfurt. It verifies Apple's signed JWS data from StoreKit transactions and App Store Server Notifications V2, links it to the Love, Spoken account through the app account token, synchronises state with Supabase, and regularly reconciles known subscriptions.

This flow processes purchase and account-linkage data, but not audio recordings, answers, transcripts, or letters. For delivery, security, and function operation, Vercel may log technically necessary connection data such as IP address, time, URL, status, and browser information.

Apple, sign-in, push, and subscriptions

Sign in with Apple is used for authentication. StoreKit handles purchase, introductory offer, renewal, cancellation, restoration, and refund. Apple sends Love, Spoken signed transaction status; Love, Spoken does not receive full card or bank details.

Notifications use Apple Push Notification Service (APNs). Push messages are neutral and do not include audio, transcripts, answers, or letter excerpts. Push tokens are used only after system permission and are removed server-side on sign-out or account deletion when the server can be reached.

Support through iCloud Mail

support@lovespoken.app is operated through Apple iCloud Mail. When you email us, the participating mail providers process sender and recipient address, time, subject, message, attachments, and technical headers. Send private couple content only when it is necessary for your request.

Product analytics without content

Love, Spoken records its own operational and product events in Supabase to understand delivery, errors, and core flow usage. These include a stable internal account ID, event type, time, and only predefined categories such as result, input mode, plan, language, build, and a bounded attempt level. Couple, answer, letter, job, and transaction IDs and free text are not stored as analytics dimensions. Answer text, audio, transcript, and letter content are not stored as analytics content.

The website uses no advertising or analytics cookies. No external advertising or product analytics SDK is integrated.

What your partner sees

Raw transcripts, private AI drafts, and unsent weekly letters remain private. For mutual-reveal questions, your partner sees your answer only after both of you have answered. A letter is shared only after you expressly send it.

Separation ends the couple connection. New sharing and couple notifications stop. Each person's own content remains associated with its author; access to a former partner's content ends under the deletion and separation rules.

Blocking, separation, and local cleanup

When local synchronisation is enabled, blocking or separation takes effect locally at once. Partner content and data from an inactive relationship epoch are removed from the local view; pending deliveries to the former partner are rejected. The next authoritative Supabase sync confirms the relationship state and removes the related local partner data.

Your own history may remain where the ordinary rules allow it. After blocking or separation, your own unsent recording remains only as a private local audio draft: server references and the former delivery are removed, so it cannot later be sent to the former partner. You can listen to or delete the draft yourself. On sign-out, the app deletes the account-specific local data, outbox, audio files, and associated device key; if cleanup cannot finish technically, it continues on the next launch.

“Intimacy & Sexuality” and “Closeness & Connection” topics

The adult-oriented, non-graphic “Intimacy & Sexuality” category remains distinct from emotional closeness and connection. Both categories can be selected or deselected in the same compact topic picker as other topics. The app collects no adult confirmation and no separate intimacy-consent decision; mutual activation is not required.

Topic selection affects only unopened future questions. Answers already shared voluntarily remain subject to the ordinary sharing and deletion rules.

Support and safety requests

An in-app report about received content stores the reporter, reported user, content type and internal content ID, reason, time, status, and your optional note. The reported text or audio file is not copied into the report queue. If you email support@lovespoken.app, we additionally process sender details, email metadata, and files or excerpts you add yourself. We use these details to answer the request, review abuse, and protect the service.

Retention and backup

Account and relationship content generally remains until you remove it through a deletion feature or delete your account. Short-lived playback links expire after a few minutes. Love, Spoken requires the Zero Data Retention and no-data-collection filters described above for personal AI requests and does not request response caching. Support, security, and transaction data is deleted or anonymised once no longer needed for the request, operation, abuse prevention, refund, or statutory evidence.

No separate external backup archive for personal audio or relationship data is currently connected as an additional provider. We therefore do not promise an additional recovery copy outside the operational system. Before such a backup provider is activated, we will update this notice and the deletion process.

Consent and your rights

Go to Personal settings → Privacy & AI to withdraw AI/transcription consent. This stops new OpenRouter requests. A request already sent cannot technically be recalled. You can also delete your transcripts and dependent private AI drafts there.

You can request access, correction, portability, restriction, objection, and deletion. The in-app ZIP export contains profile and content records for your own account together with your own raw audio files that are still available when the export is created. Your partner’s audio and partner content that has not been released to you are not included. Start full account deletion inside the app; see Delete account. You may also lodge a complaint with a competent data protection authority.

Recipients and international transfers

Recipients are limited to the providers needed for a particular flow: Supabase, OpenRouter and the model provider selected under the privacy filters described above, Vercel, and Apple, including iCloud Mail, StoreKit, and APNs. Depending on the service, data may be processed outside the EEA. Such transfers are subject to the mechanisms in the applicable processor or provider agreement, especially adequacy decisions or standard contractual clauses where they apply to the recipient.

Changes

If data flows, providers, or purposes change materially, we will update this page and notify you in the app when fresh consent or another user choice is required.