Legal

Privacy

Last updated September 9, 2026

Heartbeat helps people send personal dating invites. This page explains what we collect and why — soft-launch draft, not legal advice.

Who this covers

Creators who sign in to build invites, and recipients who open a /d/ link without creating an account.

What we store

Creator account email and profile basics; invite content you publish (photos, bio, quiz, places, times); confirmations (answers + chosen slot); sparse analytics events (opens, steps); optional abuse reports (reason + hashed fingerprint, not raw IP).

Recipients

Recipients do not need an account. We do not ask for their email or phone on the invite funnel. Confirmation emails go to the creator only.

Retention

Live and closed invites remain until the creator deletes them or requests account deletion. Place preview caches and library items follow the same creator account lifecycle.

Processors

We use Supabase (auth/database/storage), Stripe (billing), Resend (confirm emails), and Vercel (hosting). Each processes data needed to run Heartbeat.

Contact

Privacy questions or deletion requests: use the contact email published on your Heartbeat deployment (or your operator inbox).