Privacy Policy
What we keep, why we keep it, who can see it, and how it goes away when you ask.
Last updated September 27, 2026
What Lovvy is
Lovvy is a private movie diary for couples and individuals. You log the films you watch, rate them, write notes and build a shared history. Your data is stored securely and is never shared with advertisers or sold to third parties.
What we store
We store your account email, display name and profile details; diary membership and invitation details; logged films and series, ratings, notes, tags and photos; watchlists, preferences and activity used for statistics. If you enable push notifications, we store your device push token. When billing is enabled, we also store subscription status and provider identifiers. Service providers may process operational logs and request metadata.
What we use it for
We use this information to authenticate your account, sync your diary, display shared content, generate statistics and recaps, and deliver in-app updates and push notifications when device permission is enabled. You can manage push permission in your device settings. We do not sell, rent or share your personal data for marketing.
Apple sign-in and your calendar
If you use Sign in with Apple, we keep the refresh credential needed only to revoke that Apple authorization if you delete your Lovvy account. It is kept in protected server storage and is not available to other Lovvy users or app clients. If you choose Add to Calendar, Lovvy writes or removes the movie-night event in the calendar you select on your device; Lovvy does not copy your calendar into its service.
Where it lives and how it is protected
Supabase provides authentication, database and private file storage. Access rules restrict personal and shared diary records to authorized accounts. Network connections use HTTPS. Hosting location, provider logs and backup retention depend on the deployed service configuration; contact us for details.
Sharing a diary
Your diary partner can see shared films, watchlists and statistics. Personal ratings, notes, tags and diary photos remain private until the entry is revealed to your partner. Leaving removes your personal entries and stops future access, while shared records belonging to the diary can remain with the other member. Copies already seen or shared outside Lovvy cannot be recalled.
Photos and camera
You can choose profile pictures and diary photos from your photo library. Profile pictures are visible to your active diary partner; diary photos follow the entry sharing rules. JPEG, PNG and WebP uploads remove private metadata. HEIC/HEIF images can retain embedded metadata such as location or device information. Review or remove that metadata before choosing a photo if you do not want to share it.
Third-party services
Supabase provides authentication, database and file storage. If you sign in with Google, Google confirms your identity and shares your name, email address and profile picture with us. Resend delivers the emails that carry your sign-in code and receives your email address to do so. TMDB supplies film and series metadata and posters: searches are sent through our backend, while loading posters can disclose network metadata such as your IP address to the image service. Expo delivers push notifications and receives device tokens and delivery metadata. When billing is enabled, RevenueCat synchronizes subscription status with Apple or Google; we do not receive your card details.
Your rights
In-app diary export is not currently available. You can request a copy of your data by emailing us and delete your account from Settings. Account deletion removes your account and personal diary entries. A shared diary and the surviving partner's records are preserved; a diary with no remaining partner is deleted. If you are in the EU or UK you also have the right to object to processing and to lodge a complaint with your local authority.
Data retention
Personal records are removed from the active database when account deletion succeeds. Photo-file removal runs separately through background cleanup. Shared records can remain with the surviving diary member; sender-specific notification copies are cleared during departure cleanup. Previously delivered notifications or exported copies cannot be recalled. Backups, service logs and payment-provider records have separate retention processes. Contact us about those records or a deletion request; this app does not guarantee a fixed removal deadline for every provider or backup.
Children
Lovvy is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it promptly.
Changes to this agreement
We may update these terms and this policy from time to time. Significant changes will be announced by email or with an in-app notice. Continuing to use Lovvy after a change takes effect means you accept the updated agreement.
Contact
Questions, requests or complaints go to privacy@lovvy.app. We aim to reply within five business days.
This website only
The waitlist on lovvy.app
If you join the waitlist on this website, we keep your email address, the language of the page you used, which form on the site you used and the date you signed up. We use it for one thing: to email you when Lovvy is available on the App Store. We do not sell it or share it for marketing. It is stored with Upstash, the database provider connected to our hosting on Vercel. To stop abuse of the form, we count sign-up attempts per network address for one hour using a one-way hash, and never store the address itself. To be removed from the list, write to privacy@lovvy.app.
This page and the Terms of Use are one agreement, the one shown in the app under Privacy & Terms.
Questions go to privacy@lovvy.app.