Privacy Policy
This Privacy Policy explains how Heartstead collects, uses, stores, and protects your information when you use the Service. It is written to reflect the features currently available in the application. It is general information, not legal advice.
1) Who we are
Heartstead is the controller for the personal data processed through this Service. If you need help with a privacy request, please Get in touch.
2) Information we collect
- Account and profile data: email, phone, name, gender, age, location, relationship preference, marital status, education, occupation, languages, motivations, bio, values, and interests.
- Photos and media: user-uploaded images, moderation status, and visibility settings such as private, approved-only, public-to-matches, and public.
- Usage and security telemetry: IP address, device and browser details, page visits, profile opens, timestamps, and abuse-prevention logs.
- Relationship actions: interests, matches, photo access requests, and messages when messaging is available through an accepted interest, an active match, or granted photo access.
- Verification: contact verification and optional identity-verification materials if you choose to submit them.
- When you contact Heartstead, we collect the name, email address, subject, category, message and language you submit. We also store our support replies and their delivery status so we can handle and document your request.
- For a legitimate expected invitation, partnership discussion or operational follow-up, an authorized administrator may send one individual Heartstead email. We store the recipient name and address, message, purpose, internal reason, fixed sender identity, preview evidence and delivery status. This tool does not support subscriptions or bulk mailing.
3) How we use your information
- Provide and personalize profile, browse, matching, messaging, and photo-access features.
- Operate safety features such as moderation, verification review, fraud prevention, rate limiting, and abuse investigation.
- Enforce privacy controls such as profile visibility, photo visibility, and access-request decisions.
- Send service communications such as verification messages, interests, message notifications, and policy updates.
- Comply with law and enforce our Terms of Service.
- With analytics consent, measure how public pages are used and publish aggregate country-level statistics for all available recorded activity. These count recorded actions, which may repeat; they are not unique people, profiles, members, registrations, matches, or people online.
4) Legal bases (GDPR / UK GDPR)
- Contract: to operate the Service you ask us to provide.
- Legitimate interests: security, fraud prevention, product improvement, and moderation.
- Consent: for optional actions you choose, including public-page analytics and generation of aggregate country-level statistics for all available recorded activity, identity verification submissions, or requests involving private photo access.
- Legal obligation: when we must comply with applicable law or lawful requests.
5) Photos, privacy, and moderation
- Visibility controls: photos may be private, approved-only, public-to-matches, or public depending on account settings and moderation state.
- Access approval: some photo access is unlocked only after a user grants access or another permitted connection path allows it.
- Moderation: photos are reviewed through internal admin workflows and human moderation. If automated moderation is added later, this policy will be updated.
6) Cookies and similar technologies
Essential cookies are required for sign-in, security, and core features. Optional analytics run only after you consent and may be used to build the aggregate country-level statistics for all available recorded activity described above.
- Essential cookies: always active.
- Analytics cookies: optional and off until you allow them.
- Use “Manage cookie choices” in the footer to withdraw analytics consent. Choosing essential cookies stops future analytics collection. When we can link prior analytics actions to your signed-in account or this browser, we exclude them from future aggregate activity statistics during consent-withdrawal processing.
7) Sharing and processors
We do not sell your personal information. We share data only with service providers needed to run the Service, such as:
- Authentication: Users.Life sign-in services.
- Notifications: email and service-notification providers used for transactional messages.
- Storage and database providers: infrastructure used to store application data and approved photos.
- Internal moderation and admin tooling: used to review verification and policy issues.
8) International transfers
If data is transferred internationally, we use appropriate safeguards required by applicable law.
9) Data retention
- After account deactivation, we retain limited records only as required for safety, legal, fraud-prevention, and dispute-resolution purposes, then delete or anonymize them according to our retention schedule.
- Messages, interests, and access requests: retained while accounts remain active and then deleted or anonymized according to operational policy.
- Security telemetry and moderation logs: retained only as long as needed for security, audit, or abuse-prevention purposes.
- Verification selfie and identity-document media is kept while review is pending; the 30-day finalized-media deletion clock has not started at that stage. For approved, rejected, or superseded inactive submissions, the media is scheduled for deletion after the configured retention period, currently 30 days from the review date or last update. Outcome and audit records may remain where needed for safety, fraud prevention, disputes, or legal obligations. Retention settings and operational timing may change.
- Contact submissions, reply drafts, replies and related delivery records are retained according to the support, operational, legal, safety, fraud-prevention and dispute-resolution needs that apply to the request. Those needs determine the retention duration. You may ask us to access, correct or delete this information through the contact form; legal or safety obligations may limit deletion.
- One-off administrative outreach records and associated delivery logs are retained for 730 days, then deleted by our retention process. You may object to further outreach or request access, correction or deletion through our contact form; legal, safety or fraud-prevention duties may limit deletion.
10) Your rights
You can download a copy of your current profile data or deactivate your account from the Account tab.
- Download your current profile data as JSON.
- Deactivate your account and hide your profile immediately.
For access, correction, deletion, or other privacy requests that need support, contact our privacy team. Contact privacy support.
11) Children
Heartstead is for adults 18 and older only. If you believe a child has provided us personal data, contact us so we can investigate and remove it.
12) Security
- We use encryption in transit, access controls, audit logging, and other technical and organizational safeguards appropriate to the Service.
- Only authorized personnel should access moderation or verification data.
13) Changes to this Policy
We may update this Privacy Policy from time to time. If the changes are material, we will post an updated effective date and use reasonable efforts to notify active users.
14) Contact
Questions or requests? Get in touch