Heartbeat helps you remember the people who matter and the moments worth celebrating. To do that, we store a small amount of personal information about you and the people you add. This page explains what we collect, why, who else sees it, and how you can take it back.
1. What we collect
About you
- Email address and password (your password is hashed — we never see the plaintext)
- Display name
- Groups you join and connections you accept
- Pulse actions you take (e.g. "sent a message")
About the people you add
- Their name and your chosen relationship label (friend, family, colleague, etc.)
- Celebration dates (birthdays, anniversaries) you record
- Notes you write about them
- Seeds (private letters / messages) you write to or about them
We do not collect: your contacts, your location, your phone number, payment information (Heartbeat is free during alpha), or any analytics about your in-app behaviour.
2. How we use it
- To show you upcoming celebrations for the people in your circle
- To share your own celebrations with people you've connected with directly or through groups you've joined
- To send transactional email — currently only the account-deletion confirmation link
We do not sell, rent, or share your data with advertisers. We do not train any AI models on your data.
3. Who processes your data on our behalf
The companies below are our sub-processors. They handle parts of the technical infrastructure:
- Supabase (United States) — database, authentication, file storage
- Vercel (United States, global CDN) — application hosting
- Resend (United States) — transactional email delivery
Each of these vendors has their own privacy policies and security certifications. We choose sub-processors that meet a reasonable bar for security and data protection.
4. About the people you add
Heartbeat is a contact-management product, which means part of what you store is about other people. We take this seriously.
- You are responsible for ensuring it's appropriate to store the names, birthdays, and notes you record about other people.
- If someone you've added to Heartbeat asks you to remove their data, you can delete them from your circle at any time on their edit page — this removes their record from our systems.
- If you connect with someone who is also a Heartbeat user, you each see the celebrations the other has opted to share. Neither of you can see the other's private notes or seeds.
5. Your rights
- Access — You can export everything we hold about you as JSON from your profile page.
- Correction — You can edit any person, event, or note directly in the app.
- Deletion — You can delete your account from your profile page. This is irreversible: it permanently removes your account, all the people you've added, your events, seeds, and pulse history.
- Portability — The export above is a machine-readable JSON file.
6. Retention
We keep your data until you delete your account. There is no grace period or soft-delete: when you confirm deletion, the data is gone.
We may retain anonymised, aggregated metrics (e.g. total number of accounts) but these contain no information that identifies you.
7. Security
- All traffic to Heartbeat is encrypted with HTTPS
- Data at rest is encrypted by our database provider
- Passwords are hashed using industry-standard algorithms — we cannot see your password
- Row-level security is enforced at the database layer: one user cannot read another user's private data even through application bugs
8. Children
Heartbeat is not directed at children under 13. We do not knowingly collect data from anyone under that age. If you believe a child has signed up, contact us and we will remove the account.
9. Changes to this policy
If we make material changes we will email registered users at least 14 days before the change takes effect, and update the "last updated" date above.
10. Contact
Questions or requests about your data: privacy@heartbeat-app.com