Privacy Policy
Heartvault — Privacy Policy
Version: 1.9 Effective date: 2026-08-04 Contact: [email protected]
A note on tone: Heartvault is run by one person (Shagy) for ~200 people maximum. It is not a corporation, has no business model, and is not VC-funded. We've written this in plain language because that's what we'd want to read. Specifics are accurate; jargon is kept where it has to be.
What's live vs. what's planned
In the spirit of saying only what's true: most of the protections described below are built and live; a few are planned but not built yet. We label the not-yet-live ones inline as "Planned" so you're never told a feature protects you before it actually does.
- Live today: account sign-up with a date-of-birth age check; a recorded acceptance of this policy, the Transparency Statement, and the international-transfer consent at sign-up (§10); private-by-default visibility; on-box reverse-geocoding and routing (your location coordinates are resolved on our own server, not sent out); SSE-only notifications (no third-party push company); at-rest message encryption with a logged, audited moderation-access path; the vault: content you author is kept until a person deletes it (§7); immediate hard-delete when you delete something; machine exhaust (analytics, queues) auto-purged on short windows (§7).
- Handled manually today: the formal data rights in §8 — account deletion, data export, correction, restriction, right-to-know — work by contacting the operator, who handles them by hand. Self-service delete/export tools are Planned (no committed date).
- Planned (not built): self-service account-deletion and data-export tools (§8); the in-app minor-account label (§5.5); end-to-end encryption (§5.6/§6).
If you're reading a published copy, anything marked "Planned" was not live as of the version date at the top. Ask us (section 12) for the current status anytime.
1. Who we are
Heartvault is operated by Shagy, an individual person, in the United States. The service runs at heartvault.net. Email is handled at heartbeatcreations.com; yellowduck.uk is a legacy name. There is no corporation behind Heartvault. It is — and is meant to stay — a small invite-only network for a family and a tight circle of close friends.
If you need to reach us about anything in this policy, see section 12.
2. What we collect
2.1 From you, when you sign up and use Heartvault
- Account info: username, password (stored using industry-standard one-way protection — never in a readable form), display name, profile picture (optional), the invite code that brought you here, and a self-reported date of birth (used to apply age-appropriate defaults — see section 9).
- Connections: your friend graph, household membership, blacklist entries if any.
- Content you create: profile bio, journey entries, photos you upload, messages you send, grocery list items, recipes you save, calendar events, chore claims.
- Location data (opt-in): with your explicit per-feature consent, Heartvault collects your location to render your personal journey map, indicate your presence to your household, and enable location-based features. You control whether each location feature is on, and you can turn each off at any time.
- Check-ins: when you check in (a "heartbeat"), the location at that moment and any optional tag / photo / note are recorded.
- Messages: the content of 1:1 messages and group chats is stored on the server (see section 6 for direction on encryption).
2.2 Automatically, as you use the site
- Device + browser info: IP address (see section 2.4), browser type, screen size, basic device characteristics — typical web-server log information.
- Login session: a secure cookie to keep you logged in.
- Analytics events: clicks, page views, errors. Used to find bugs and inform improvements. Stored for 90 days then automatically purged.
2.3 From the Heartvault Android companion app (optional)
If you install the Heartvault Android app and pair it with your account, the app may send:
- Live location (for household presence) while you have it on.
- Geofence triggers (e.g., "arrived at home").
Live tracking and geofencing are device-side controls — you choose whether each is on, and you can turn each off independently at any time.
2.4 Via third parties on your behalf
- Address lookups (typing an address): when you type an address — for example, to save a place by name — Heartvault's server sends that typed address text (not your coordinates) to a public geocoding service (Nominatim, operated by the OpenStreetMap Foundation) to look up where it is. This lookup happens server-side: Nominatim sees a request from our server — your own IP address and your location are never sent to Nominatim. The request is rate-limited and the result is cached. This is the one outward flow that carries something you entered — the address text you typed, and nothing else identifying.
- Turning a check-in coordinate into a place name — done on our own server. When you check in and Heartvault shows a readable place name, that lookup (reverse-geocoding) happens entirely on Heartvault's own server. Your check-in coordinate is not sent to any outside service for this.
- Routing: when the map draws a road route between two points, the request goes to our self-hosted routing engine. It is fail-closed by default — your coordinates do not leave our server.
- Cloudflare: all HTTP traffic between your browser and Heartvault flows through Cloudflare's network (see section 5.2). Cloudflare therefore processes your IP address, the URLs you visit on Heartvault, your HTTP headers, and the timing of your requests, as a data controller in its own right.
2.5 What we deliberately do NOT collect
- We do not ask for, store, or process payment card information. There are no payments on Heartvault.
- We do not store anything that meets the US legal definition of "protected health information" (medical records, prescriptions, etc.).
- We do not collect true background GPS — location pings only while you have actively engaged Heartvault.
- We do not maintain a public directory or search. You cannot find a Heartvault user without their friend code.
- We do not buy or receive data from data brokers, advertising networks, or social-graph enrichment services.
3. Why we collect it
- To make Heartvault work — show your friends, render your journey, deliver your messages, sync the grocery list, surface household presence.
- To help your household coordinate — shared calendars, chore boards, meal planning.
- To keep your account safe — login rate limits, suspicious-activity detection, password reset, abuse detection.
- To diagnose problems — error logs and analytics that help us find and fix bugs.
- To honor your privacy choices — track per-person opt-ins for location, friend-graph visibility, blacklists.
We use the legitimate-interest basis (GDPR Article 6(1)(f)) for the minimal data necessary to provide the service you've signed up for. For optional features (location, the companion app), we rely on your consent (GDPR Article 6(1)(a)), which you can withdraw at any time.
4. Who can see what (visibility within Heartvault)
Heartvault operates on a three-tier circle. More trust means more access — not the other way around.
| Tier | Who | Default access |
|---|---|---|
| Household | The immediate people under one roof | Live presence, household map, shared grocery / chores / calendar, chore-allowance system |
| Family / friends | Wider invited circle, after a friend request is accepted | Journey visibility (friends-only by default), profile, tagged check-ins |
| Blocked | Users you have blacklisted | Less or nothing |
Defaults are private. You opt in to wider visibility, not the other way around. Specifically:
- Your profile bio: visible to your accepted friends.
- Your journey/map: friends-only by default; you may restrict to household-only.
- Your messages: only to participants in the conversation.
- Your check-ins: depends on the tag — household-only check-ins only show in your household; friend-visible check-ins show in your friend circle.
- Your grocery list: only your household.
- Your friends list: visible to you; mutual visibility is per-friend.
If you change a visibility setting, future entries pick up the new default. Already-shared content does not retroactively change visibility unless you delete or re-tag it.
5. Who else gets access (third parties and the operator)
5.1 The superadmin
Heartvault has a "superadmin" role for site administration. Today, Shagy is the only superadmin. The superadmin can technically read most data on the server — this is true of any self-hosted application's operator, and we disclose it because saying otherwise would be misleading.
In practice:
- The superadmin is set up as a one-way mirror: sees everyone, but is filtered out of every other user's friend list, check-in tag listings, and profile-by-friend-code lookups. This is intentional, so the operator can debug and moderate without affecting trust dynamics.
- Superadmin access is for site administration (debugging, abuse handling, moderation, responding to deletion requests), not for personal interest.
- Message content: the routine administrative view does not return message bodies — it shows metadata only (who messaged whom, when). Message bodies are accessible only through the logged moderation path described in §5.6. Direction: we are moving toward end-to-end encryption, after which message content will not be readable by the server at all. Metadata will remain readable for safety and abuse-handling. The §5.6 path is current state; end-to-end is direction.
- If additional "site manager" admins are ever added, they will be named on this page before they receive any access.
5.2 Service providers in the loop
- Cloudflare, Inc. — Heartvault's traffic is delivered via Cloudflare's network. Cloudflare therefore sees every HTTP request: the URL, your IP address, basic browser information, and the timing of your visit. Cloudflare uses this both as a service to us (delivering the site, blocking attacks) and for its own purposes as an independent data controller (improving its network and security products). Cloudflare's Privacy Policy: https://www.cloudflare.com/privacypolicy/.
- OpenStreetMap Foundation (Nominatim) — when you type an address to save a place, Heartvault's server sends that typed address text (not your coordinates) to OSMF's public geocoder, server-side — Nominatim sees a request from our server, never your IP address or your location. The request is rate-limited and the result cached. Turning a check-in coordinate into a place name (reverse-geocoding) is done on Heartvault's own server and is not sent here. Nominatim's usage policy: https://operations.osmfoundation.org/policies/nominatim/.
- Google (Google Drive) — encrypted off-site backup. Heartvault keeps a disaster-recovery backup on Google Drive. The backup is encrypted on our side before it ever leaves, so Google stores only opaque ciphertext it cannot read — the decryption key never leaves the operator's control. Used solely for backups; Google receives no readable personal data. Google's Privacy Policy: https://policies.google.com/privacy.
5.3 What we do NOT do
- We do not sell your data to anyone. There is no business model that would make this possible — Heartvault has no business model.
- We do not share with advertisers. There are no ads on Heartvault.
- We do not share with data brokers, social-graph enrichment services, or analytics aggregators.
- We will not voluntarily turn over user data to law enforcement absent a legally valid request (such as a subpoena or warrant). If we receive a valid request, we will review it carefully and respond as required by applicable law. Given the narrow, invite-only nature of Heartvault, this is very unlikely to come up.
5.4 Push notifications (only if you opt in)
Push notifications are off by default. If you turn them on, you'll get a brief alert that names who messaged you — for example, "New message from [name]" — when a new direct message arrives. The alert names the sender, but never contains the message text or a preview.
How it works — a live connection to Heartvault's own server, nothing more. While you have Heartvault open, your browser holds an open connection to Heartvault's server (a standard web technique called Server-Sent Events), and the server sends the alert down that connection. There is no separate push program and no third-party push company — no Google Firebase, no Apple Push, and no self-hosted push daemon. As with all of Heartvault's traffic, the signal travels over Cloudflare (§5.2), which carries only the sender's name and the generic alert — never your message content. Because delivery rides your live connection, no device push-token is stored with any third-party service. You can turn notifications off at any time. (If we ever add an option to show message content or a preview in notifications — or ever route notifications through an outside push provider — we will update this policy and ask before enabling it.)
5.5 When other members are minors
Accounts that indicate a minor (under 18) will be labeled in the interface so other members know they are messaging a young person (this in-interface label is Planned — see the status box at the top; until it ships, treat it as forthcoming). Heartvault does not monitor the content of personal messages; we rely on members to behave appropriately. If we become aware of apparent child sexual abuse material, federal law (18 U.S.C. §2258A) requires us to report it to the National Center for Missing & Exploited Children (NCMEC).
5.6 What we do with your message content
Heartvault encrypts message bodies (and any attached location) at rest on the server using strong, industry-standard encryption (AES-256-GCM) under a key bound to the server's operating environment. This is not end-to-end encryption. The household server is a trusted server: it holds the keys to your messages, decrypts them in memory when it needs to (see below), and re-encrypts them when it stores them again. We tell you this directly because end-to-end has a specific, stronger meaning — and Heartvault does not meet that bar today.
The server reads message content for two purposes only:
- Delivering messages to the person you sent them to (it can't render a message it can't read).
- Automated translation — when two members speak different languages, Heartvault translates messages using open-source software running on the same server, over a loopback connection that never touches the public internet. The translation processing reads your message content; nothing leaves the server — no outside translation API is ever called.
No routine human access. The operator's administrative view of Heartvault does not show message contents during normal operation; it shows only metadata (who messaged whom, when). The only path by which a human can read your messages is a moderation-access endpoint restricted to the superadmin, requiring a stated reason, and every access is recorded — actor, target, conversation, reason, client IP, timestamp — in an append-only audit log that is never deleted. The endpoint refuses to serve content if the audit row cannot be written, so no human read can happen without leaving a permanent record.
Standing principle: we don't routinely read your messages; a logged moderation-access path exists for safety, and every access is recorded. The direction we are moving in long-term is end-to-end encryption — where translation happens on the recipient's device and the server can't read content at all — but that's a future change. Until it ships, the above is the honest picture.
6. Security
Heartvault takes reasonable, industry-standard security measures to protect your data — in transit, at rest, and at access time. We don't publish the specifics of our defenses, both because that practice is more useful to attackers than to users, and because the truer measure of a security posture is responsible handling of issues when they arise.
Material security incidents: if Heartvault experiences a security incident that materially affects your data, we will notify affected users within a reasonable period (consistent with applicable breach-notification law) and describe what happened, what was affected, and what to do.
Direction: end-to-end encryption for personal message content is on the development roadmap. Until it ships, message content is protected by the measures above but is readable to the operator if abuse-handling requires.
If you have a specific security concern (e.g., evaluating Heartvault for a child's account, or comparing against another service), contact us — see section 12.
7. How long we keep your data — the vault
Heartvault is a family vault: things you put in on purpose stay until a person deletes them. Things the machine produced along the way age out automatically. Concretely:
- Content you author — kept until you delete it (or ask the operator to). Messages and chat photos, journey entries, deliberately-recorded trips, memories, recipes and their photos, calendar events, list items, and person-directed heart-pings have no automatic expiration. (Earlier versions of this policy described an automatic 7-day message purge; that purge has been retired — your messages are part of the vault now, kept until deleted like everything else you author.)
- Machine exhaust — ages out automatically: silent background location pings (short-lived), analytics events (90 days), the notification queue (90 days), internal metrics snapshots (a bounded window), one-time codes (pairing/reset — minutes to hours), abandoned minor-pairing invitations, and cached community-event listings (source-defined). Orphaned media files are swept; photos attached to live content are keepsakes and are never swept.
- Account data — kept as long as your account exists.
- The moderation-access audit log (§5.6) — append-only, kept indefinitely. That log is the accountability record of every human access to message content; keeping it forever is the point.
- Backups — rotating disaster-recovery snapshots, rotated out typically within 30 days.
When you delete something, deletion is immediate. Heartvault hard-deletes it right away — there is no recoverable "soft-delete" copy kept in active systems, and no grace window. After deletion, the only remaining copies are in disaster-recovery backups, which rotate out within about 30 days. (An earlier draft planned a 14-day soft-delete recovery window; that plan is withdrawn — it was never built, and it is not currently planned. Deletion is immediate and final.)
Total maximum retention after deletion: about 30 days (backup rotation only).
Expedited erasure on request: because deletion is already immediate, the main thing left to accelerate is backup purging — if you require faster removal (for example, under GDPR Article 17 "right to erasure" or a comparable state law), contact us (section 12) and we will accelerate backup-purge timelines as far as backup mechanics allow.
8. Your choices and rights
You can, at any time:
- Edit your profile (display name, bio, picture) from your profile page.
- Delete your content — remove journey points, messages, list items, recipes, calendar events.
- Control your visibility — set journey visibility to household-only, hide specific check-ins, change profile defaults.
- Disable location — turn it off; existing journey points are yours to delete or keep.
- Blacklist specific users — they will see less or nothing of you.
- Leave Heartvault — request account deletion by contacting us (section 12); the operator deletes your account promptly (deletion is immediate and final — §7).
How these rights are fulfilled — honestly. The self-service controls just above (edit, delete your own content, visibility, disable location) are live now. The formal data-subject rights — account deletion, data export, correction, restriction, right-to-know — are fulfilled manually: you contact the operator (section 12) and Shagy handles it by hand, promptly. For a network this small that is a valid method, and it is the honest current state: there is no in-product self-service account-deletion or data-export tool today.
Planned (no committed date): two self-service tools — a one-action account deletion (which will also remove your messages from shared conversations — by design) and a data export (a machine-readable JSON bundle). Until they ship, every formal right below is exercised by contacting us, and we will not describe these tools as existing.
8.1 If you are an EU, UK, or Swiss resident (GDPR / UK GDPR)
You have additional rights:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — have your data deleted (this is the same as the leave-Heartvault flow above; section 7 explains the deletion timeline).
- Restriction — limit how we process your data while a question is open.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — for features you opted into (location, the app).
- Complain — lodge a complaint with your national data-protection authority.
Contact us (section 12) to exercise any of these. We will respond within 30 days.
8.2 If you are a California resident (CCPA / CPRA)
You have the rights to:
- Know what categories of personal information we collect and share.
- Delete your personal information.
- Correct inaccurate personal information.
- Opt out of sale or sharing — we don't sell or share for cross-context advertising, but the right exists regardless.
- Limit use of sensitive personal information — we don't use it for non-essential purposes.
Contact us (section 12) to exercise any of these.
8.3 Other US state laws
Residents of states with similar comprehensive privacy laws (Colorado, Virginia, Connecticut, Utah, etc.) have substantially similar rights. We honor those rights via the same contact path.
9. Children's privacy
Heartvault may include children under 13 as part of a household in the future. Right now, under-13 sign-ups are declined: if the date of birth given at signup indicates an age under 13, the account is not created and no data about that person is stored. The parental-consent approach described below is built but currently switched off — it stays off, pending legal counsel, until Heartvault is ready to enroll children. When it is turned on, the following approach applies, to comply with the US Children's Online Privacy Protection Act (COPPA):
- Date-of-birth check at signup. Every Heartvault account self-reports a date of birth at signup. Accounts indicating under-13 require the parental-invite flow below; accounts 13–17 carry minor-account defaults; accounts 18+ are adult accounts. This DOB check is self-reported (not identity-verified), but it is combined with Heartvault's invite-only nature, which means an adult member is always the proximate point of accountability for a minor's presence.
- Children are invited by their parent or legal guardian through that parent's verified Heartvault account. Verifiable parental consent is collected through the parent's existing account credentials, account history, and explicit confirmation at the invite step. We consider this a stronger consent signal than email verification, because the parent is already a vetted Heartvault member via the invite-only chain.
- Children's accounts collect and display less by default than adult accounts:
- Location feature is off by default and requires the parent to enable it for the child.
- Friend connections to non-household users require parent approval.
- Profile visibility defaults to household-only.
- The child cannot invite others.
- Parents can review, edit, and delete their child's data at any time through a Family safety tab on the parent's profile.
- No targeted advertising, behavioral profiling, or third-party analytics specific to children, ever. (We don't do these for anyone — see section 5.3 — but the COPPA explicit commitment is made here.)
- No public discoverability of any account, child or adult — see section 2.5.
If you are a parent and want to review the data we hold about your child, change consent, or delete the child's account, contact us (section 12).
10. International users
Heartvault is operated from the United States. Everything you put into Heartvault — your messages, photos, location, profile — is stored and processed on a server located in the United States. Cloudflare, the service provider through which your traffic flows, processes data in the United States and the European Economic Area and participates in the EU-US Data Privacy Framework and its UK and Swiss extensions (see https://www.cloudflare.com/privacypolicy/).
If you live outside the United States, using Heartvault means your personal data leaves your country and travels to the United States, where it is protected by the safeguards described in this policy (encryption, no sale, no ads, no data brokers, logged access) — but where the laws that protect it are United States laws, which may differ from your country's.
We ask for this consent explicitly, not silently — and we record it. When you create your account, the onboarding agreements include a separate, recorded acceptance of this international transfer — shown in your language and logged alongside your other agreements (the record captures the document version, the exact text you saw, your chosen language, and the time you accepted). Some countries — for example El Salvador, under Decreto 144 — legally require an express, individualized transfer consent, and this recorded acceptance is how we meet that bar. You can withdraw at any time by requesting deletion of your account (§8). The canonical consent texts below are the exact wording that step uses.
Cláusula de consentimiento (es): "Heartvault opera desde los Estados Unidos. Tus datos personales — mensajes, fotos, ubicación y perfil — se almacenan y procesan en un servidor ubicado en los Estados Unidos. Si vives fuera de los Estados Unidos, al usar Heartvault tus datos se transfieren a los Estados Unidos, donde se protegen con las salvaguardas descritas en nuestra Política de Privacidad (cifrado, sin venta de datos, sin publicidad, sin intermediarios de datos, acceso registrado), bajo las leyes de los Estados Unidos. Acepto de forma expresa esta transferencia internacional de mis datos personales. Puedes retirar tu consentimiento eliminando tu cuenta en cualquier momento."
Consent clause (en): "Heartvault operates from the United States. Your personal data — messages, photos, location, and profile — is stored and processed on a server located in the United States. If you live outside the United States, using Heartvault transfers your data to the United States, protected by the safeguards in our Privacy Policy, under United States law. I expressly accept this international transfer of my personal data. You can withdraw consent by requesting deletion of your account at any time."
11. Changes to this policy
If we change this policy in a material way, we will post the updated version and highlight what changed.
Your original acceptance of this policy is recorded at sign-up (§10). Planned (not built yet): an in-app step that shows you a material change on your next login and asks you to acknowledge it before continuing, recorded the same way. Until that ships, we notify you of material changes by posting the updated version with changes highlighted, rather than by a forced next-login acknowledgment.
Minor wording fixes (typos, clarifications) will be applied without an explicit acknowledgment step but will appear in the version history below.
Version history:
- v1.9 — 2026-08-04 — Retention rewritten as "the vault" (§7): content you author is kept until a person deletes it; the automatic 7-day message purge is retired; the previously-planned 14-day soft-delete window is withdrawn (deletion stays immediate and final). §8 updated to reflect that the formal data rights are fulfilled manually via the contact path (self-service tools remain planned). §10: the recorded onboarding acceptance is live.
- v1.8 — 2026-06-16 — Present-reality corrections (on-box reverse-geocoding, SSE-only notifications, fail-closed routing, on-box translation); live-vs-planned status box added.
- v1.7 — 2026-06-11 — International transfer consent upgraded to an express, recorded acceptance, with canonical Spanish and English clause texts.
- v1.6 — 2026-06-08 — Message-content encryption disclosure (§5.6) added; administrative view no longer returns message bodies (§5.1).
- v1.5 — 2026-06-04 — Minors disclosure (§5.5) added.
- v1.0–v1.4 — 2026-05-29 → 2026-06-02 — Initial drafting and early revisions.
12. Contact
For privacy questions, deletion requests, parental review requests, complaints, or anything in between:
- Email: [email protected]
- In-app: the bug-report form on every page, marked "Privacy question"
- Postal mail: available on request via email
Responses come from the operator (Shagy) personally.