Legal
Privacy
Last updated September 9, 2026
Heartbeat helps people send personal dating invites. This page explains what we collect and why — soft-launch draft, not legal advice.
Who this covers
Creators who sign in to build invites, and recipients who open a /d/ link without creating an account.
What we store
Creator account email and profile basics; invite content you publish (photos, bio, quiz, places, times); confirmations (answers + chosen slot); sparse analytics events (opens, steps); optional abuse reports (reason + hashed fingerprint, not raw IP).
Recipients
Recipients do not need an account. We do not ask for their email or phone on the invite funnel. Confirmation emails go to the creator only.
Retention
Live and closed invites remain until the creator deletes them or requests account deletion. Place preview caches and library items follow the same creator account lifecycle.
Processors
We use Supabase (auth/database/storage), Stripe (billing), Resend (confirm emails), and Vercel (hosting). Each processes data needed to run Heartbeat.
Contact
Privacy questions or deletion requests: use the contact email published on your Heartbeat deployment (or your operator inbox).