Transparency Statement
Heartvault — Transparency Statement
Version: 1.4 Effective date: 2026-08-04
This page exists because we think you deserve to know what's actually going on under the hood of Heartvault — not just a privacy policy that satisfies a legal checkbox.
What Heartvault is
Heartvault is a small, invite-only website for a family — and a small circle of close friends — to stay connected and run a household together. It is not a startup. It is not VC-funded. There is no business plan. It runs as a private project for ~200 people maximum, indefinitely.
The original brief was: "a website my grandmother is proud of, that will never be used by more than ~200 people, that helps maintain connection through friends and family and assists in household planning." We try to keep that posture.
What we believe about privacy
Privacy is the first design constraint here, not the last. A few principles that drive the architecture:
- No discoverability. You cannot find someone on Heartvault without their friend code. No search, no directory, no "people you may know." People must know each other offline first.
- No public signup. Heartvault grows by invitation. Each user came from someone who invited them, and that lineage is part of how moderation works.
- No social-media feed. No likes, no followers, no algorithmic ranking. The mechanics that turn social platforms into attention-mining systems are deliberately absent.
- Per-person, opt-in location. Background location is opt-in, controlled per person. The location only activates while you have engaged Heartvault.
- No third-party profile linking. If a non-friend happens to see one of your check-ins (e.g., they were tagged in the same one), they cannot click through to a profile they aren't friends with.
- Your data isn't a product. Heartvault has no business model that would benefit from monetizing your data — and never will.
Who can see what
Heartvault operates on a three-tier circle. More trust means more access, not the other way around:
| Tier | Who | Sees |
|---|---|---|
| Household | The immediate people under one roof | Live presence, household map, shared grocery/chores/calendar, chore-allowance system |
| Family / friends | Wider invited circle | Default journey visibility (after friend acceptance) |
| Blocked | Users you have blacklisted | Less or nothing |
You can move people between tiers. Defaults are private.
Third parties in the loop
Here's the full list of outside services involved, and exactly what each one sees.
- Cloudflare — the path between your browser and Heartvault's server runs through Cloudflare's network. Cloudflare sees your IP and HTTP requests as they pass through. Their privacy policy: https://www.cloudflare.com/privacypolicy/.
- OpenStreetMap's Nominatim — when you type an address to save a place, our server sends that typed address text (not your coordinates) to Nominatim to look up where it is. This is server-side: Nominatim sees a request from our server — never your IP address and never your location. The request is rate-limited and cached. Turning a check-in coordinate into a place name happens on our own server and isn't sent out. Their usage policy: https://operations.osmfoundation.org/policies/nominatim/.
- Google Drive (encrypted backup only) — a disaster-recovery backup is stored on Google Drive, encrypted on our side first, so Google holds only ciphertext it cannot read. This doesn't touch your live traffic; it's an offline safety copy.
Nothing is shared with advertisers, data brokers, or analytics aggregators. There is no business reason to do so.
The superadmin
We disclose this because the alternative is misleading: Heartvault has a "superadmin" role for site administration. Today, Shagy (the operator) is the only superadmin. The superadmin can technically read most data on the server. This is true of every self-hosted system's operator. In practice:
- The superadmin's view is set up as a one-way mirror — sees everyone, seen by no one. This is intentional, so the operator can debug and moderate without affecting trust dynamics.
- Superadmin access is used for site administration, not for personal interest.
- Direction: message content is moving toward end-to-end encryption — readable only by the conversation participants, not even by the operator. Implementation is incremental; the current state still has server-readable message content.
- If additional site-manager admins are ever added, they will be named here before they receive any access.
Where the data lives
- The database is hosted and operated in the United States, encrypted at rest.
- It's a vault: content you author — messages, photos, trips, memories, recipes — is kept until you delete it; nothing you made on purpose expires automatically. Machine exhaust (analytics, queues, transient codes) ages out on short windows. Details: Privacy Policy §7.
- Backups are retained for disaster recovery; off-machine resilience is on the roadmap.
- The companion Android app is distributed from Heartvault's website.
Things still in flux (we'll tell you when they change)
- Off-machine disaster recovery for the database.
- End-to-end encryption for messages.
- Two-way Google Calendar sync for household events.
- Additional site-manager admins (if any).
- A public-facing source-code release (no decision yet).
This statement will be updated when the architecture changes meaningfully.
Related documents
- Privacy Policy — the substantive policy with the legal specifics: /legal/privacy
- Terms of Use — the rules of the road: /legal/terms
How to reach us
See the contact section in the Privacy Policy.