← Legal

Privacy Policy

Your private vault entries and matched conversations are end-to-end encrypted on your device before they ever reach our servers, so not even we can read them. Below is the full picture, in plain English, structured the way GDPR requires, and checked against the practices of the major social apps, minus everything they do that we refuse to.

Last updated 10 September 2026

1. What we collect

Registration: your email address, and your password, which is stored only as a one-way hash, so nobody, including us and our provider, can read it.

Sign in with Google: if you choose Google sign-in, Google shares your name, email address and Google account ID with us to create and secure your account. We receive nothing else from Google: not your contacts, not your files, not your history. You can revoke this access any time in your Google account settings.

Your profile: nickname, date of birth, gender, language, hobbies, the things you struggle with, and your answers to the matching questions.

Your daily reflections, your mood check-ins and the messages you send inside matches.

Photos and voice notes: anyone can attach them to their own journal entries, and anyone can send them in a conversation with a match. See Section 5 for who can see them and Section 9 for how they're protected.

Approximate location, only if you grant location permission. Your device's coordinates are rounded to about a kilometre before anything is stored, so we hold a rough area and never a precise point, used to show distance and nearby people. You can refuse or withdraw this at any time in your device settings, and the app still works: distance features simply turn off.

Device and technical data needed to keep the service running and secure: your IP address, browser and device type, and sign-in timestamps.

Push notifications: if you enable them, your device gives us a push subscription token so we can deliver your daily prompt nudge. Disabling notifications deletes this link.

Anti-abuse records: a one-way salted hash of your email and sign-up attempt counters, used only to detect spam and disposable-address abuse. These cannot be reversed to reveal anything about you.

Membership status, and your acceptance of these documents: which version you agreed to and when.

2. Sensitive information you choose to share

I Feel You asks you to write about how you feel. Your reflections, your answers and the struggles you list may reveal things the law treats as special-category data, for example information about your mental health or wellbeing.

You are never required to disclose any of this. You choose what to write, every day, and you can edit or delete it. Private vault entries are end-to-end encrypted and never shown to anyone.

By choosing to write and publish a daily reflection, you give us explicit consent to process that content for the single purpose of showing it to the people the app is designed to show it to. We never use it for advertising, profiling or anything else, and you can withdraw this consent at any time by deleting the entry or your account.

3. What we never collect

No face scans, no biometric verification, no ID documents, ever. Camera, photo library and microphone access are only ever requested when you choose to attach a photo or record a voice note, whether in a journal entry or a conversation.

No contact list, no address book.

No card details: those go straight to our payment processor and never touch our database.

No advertising identifiers, no cross-app tracking, no data broker feeds.

4. Why we hold it, and on what legal basis

To create your account, match you and carry your messages. Legal basis: performance of our contract with you.

To process sensitive content you choose to publish. Legal basis: your explicit consent, given each time you post.

To keep the app safe: preventing abuse, spam, fake accounts, and enforcing blocks and strikes. Legal basis: our legitimate interest in a safe service and the safety of other users.

To take payment for membership and keep the accounting records that follow. Legal basis: contract, and legal obligation.

To use your location and to send you reminders. Legal basis: your consent, which you can withdraw at any time in your device settings.

We do not build advertising profiles, and we do not target you with ads.

5. Who can see your writing

Your daily reflection is visible only to people you are actively matched with, and only on the day you wrote it. After that it lives only in your own private archive. Entries you mark as private vault are never shown to anyone.

Any photo or voice note follows the same rule as what it's attached to: private vault media is never shown to anyone; media on an entry you share with matches, or sent directly in a conversation, is visible only to that match.

Your matching answers are visible to people browsing Explore, under your nickname. Your real name is never shown unless you and your match both choose to unlock it.

If you unmatch, both sides lose access to the conversation and the shared history immediately.

Other apps in this category analyse message content for topics and trends. We don't: your conversations are end-to-end encrypted, so there is nothing for us to analyse.

6. Moderation and safety

Because chats are end-to-end encrypted, we cannot read them, so moderation relies on members reporting. Blocking someone with a rule-breaking reason files a report with us, together with any detail you choose to add.

A report about a serious risk, such as a threat or a child's safety, reaches us straight away and is reviewed by a person, not left to a count. Other reports accumulate: enough of them against one account leads first to a warning, then to removal.

Public-facing text (nicknames, reflections, matching answers) passes through an automated word filter that censors clearly problematic words in several languages before anything is shown to others.

Strike and block records are kept while an account exists, so a ban can't be escaped by deleting and re-registering.

7. Who processes it for us

Supabase, which hosts our database, authentication and file storage on our behalf.

Google, if you choose to sign in with your Google account.

Stripe, which handles membership payments and holds the card details we never see.

Your device's push notification service (operated by Apple, Google or Mozilla depending on your browser) to deliver reminder nudges you opted into.

Authorities, only where we're legally required to disclose.

We never sell your data. We never rent it. We never hand it to advertisers or data brokers. There is no corporate family to share it with.

8. Where your data goes

Our providers may process data outside the European Economic Area. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard offered by that provider.

9. How it's protected

Chat messages and journal entries you save to your private vault are end-to-end encrypted on your device, and this extends to any photo or voice note sent in a conversation or saved to your vault. The keys live on your devices and behind your recovery phrase, so we cannot read that content. If you lose the phrase, nobody can recover it.

A photo or voice note attached to a journal entry you share with matches is not yet end-to-end encrypted the same way; treat it like the rest of that shared entry.

Everything else is encrypted in transit and at rest by our hosting provider. Passwords are hashed, never stored in readable form. We do not additionally encrypt fields such as your email or nickname: treat them as data we can technically read if we must, for support or safety.

Access is enforced at the database level with row-level rules, so one person's reflections cannot be read by someone who isn't matched with them, not even by mistake in the app.

No system is perfect. If a breach is likely to put your rights at risk, we will notify you and the supervisory authority within the deadlines the GDPR sets.

10. How long we keep it

Account data (profile, reflections, matches, messages) is kept for as long as your account exists.

When you delete your account, all of it is erased immediately and permanently: not archived, not soft-deleted. There is no hidden retention window. A paused account keeps its data until you delete it.

Safety records, such as blocks and strikes against an account, are kept while that account exists, so bans can't be shed by a quick reset.

Anti-abuse email hashes and sign-up counters are kept for up to 12 months after your last sign-up attempt, then deleted.

Billing and accounting records: 7 years, as Belgian accounting law requires.

Anonymous deletion feedback, if you leave any, is kept with nothing linking it back to you.

11. Your rights in the EEA and UK

Access and portability: download everything we hold on you as a JSON file, any time, from Settings. No request, no waiting.

Rectification: correct your profile and answers yourself in the app.

Erasure: delete your account from Settings and it is gone, including everything you wrote.

Restriction and objection: you can object to processing based on our legitimate interests, and ask us to restrict processing while a dispute is open.

Withdrawing consent: turn off location or notifications in your device settings at any time. This doesn't affect anything done before you withdrew.

For anything you can't do yourself, write to hello@ifeelyou.dev. We answer within one month.

Complaint: if you're in the EU/EEA you can complain to your local data protection authority. In Belgium that's the Gegevensbeschermingsautoriteit / Autorité de protection des données (dataprotectionauthority.be). In the UK, the ICO.

12. Your rights in US states (California and others)

If you live in California or another US state with a privacy law, you have the right to know what personal information we hold, to access it, correct it and delete it. The tools in Settings (download my data, edit profile, delete account) let you exercise all of these directly.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of. We also do not use or disclose sensitive personal information for any purpose other than providing the service.

Exercising your rights never changes your experience: we do not discriminate against anyone for using them.

13. Automated decisions

The order people appear in Explore is decided by an algorithm using language, distance, shared struggles and hobbies, and whether they already said 'I feel you' to you. It only affects ordering. There is no automated decision that produces a legal or similarly significant effect on you, and no profiling for advertising.

14. Cookies and tracking

We use only what is needed to keep you signed in and to keep the service running. No third-party advertising trackers, no cross-site tracking, no analytics cookies.

15. Children

The app is for adults, 18 and over. Age is checked at sign-up and enforced in the database. If we find an account belonging to a minor, we delete it.

16. Requests from law enforcement

If a court order or binding legal request compels us to disclose data, we review it carefully and disclose only what the law strictly requires. Because chats and private vault entries are end-to-end encrypted, we cannot hand over their contents: we don't have the keys.

Where the law allows, we will tell you a request was made about your data.

17. Who operates I Feel You

I Feel You is operated by an individual based in Belgium, who acts as the data controller under the EU General Data Protection Regulation (GDPR) and can be reached at hello@ifeelyou.dev for anything privacy-related. A postal address is available on request.

18. Changes and contact

If this policy changes materially, we'll ask you to review and accept it in the app, and record which version you agreed to.

Data questions or requests: hello@ifeelyou.dev.