LoveStreaks
Home Privacy Terms Support

LoveStreaks Privacy Policy

Effective date: July 24, 2026
Last updated: July 24, 2026

LoveStreaks is operated by Daitoku Corp. ("LoveStreaks," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the LoveStreaks iOS application, website, support channels, and related backend services (collectively, the "Service").

This Policy does not govern Apple's independent handling of information through the App Store, Sign in with Apple, StoreKit, or Apple device services. Apple's privacy terms apply to Apple's processing.

1. Privacy at a glance

  • We do not sell personal information.
  • We do not share personal information for cross-context behavioural advertising.
  • We do not use third-party advertising SDKs or cross-app tracking.
  • We do not request your contacts, microphone, camera, precise location, HealthKit data, or permission to read your photo library. If you choose "Save," iOS may ask for add-only photo-library permission so the app can save the art card you created.
  • Relationship and streak information is private to the account and the relationship members you choose; it is not a public feed.
  • Optional intimacy prompts are hidden by default and require an adult confirmation before being shown.
  • You can delete your account in the app. Account deletion also removes custom streak text you authored, subject only to the narrow retention described below.
  • Safety reports are reviewed privately. The reported person is not shown the reporter's identity through the Service.

2. Who is responsible for your information

For applicable privacy law, the controller or organization responsible for personal information is:

Daitoku Corp.
Privacy contact: Privacy Officer
Email: support@lovestreaks.app

If local law requires an EU, UK, or other regional representative, the representative's required details will be added here before the Service is offered in that region.

3. Information we collect

3.1 Account and identity information

We may collect:

  • the stable subject identifier Apple provides through Sign in with Apple;
  • an email address, including an Apple private relay address, if Apple provides one;
  • your LoveStreaks display name, internal account identifier, and friend code;
  • a unique pseudonymous App Store account token used to associate an Apple subscription with the correct LoveStreaks account;
  • account creation, onboarding, update, and last-login timestamps; and
  • encrypted Sign in with Apple credentials needed to maintain or revoke the Apple authorization.

We do not receive your Apple Account password.

3.2 Relationship, invitation, and streak information

Depending on the features you use, we collect:

  • relationship type, membership, role, display names, group name, colour, timezone, and invitation status;
  • the friend code of a person you invite and invitation metadata;
  • selected streak definitions, custom streak text, cadence, completion dates, current and longest counts, lives, inactive streak history, and aggregate relationship statistics;
  • relationship feature settings, such as an invite-banner preference and premium state; and
  • Streak Fruit balances and use.

Relationship members can see information needed for their shared relationship, including member display names and the relationship's shared streaks, custom streaks, completions, and statistics. Do not add information that you do not want the other relationship members to see.

3.3 Subscription information

Apple processes payment details. We do not receive or store your payment-card number. We receive and retain limited App Store transaction information needed to verify and provide Premium, including:

  • product, transaction, and original-transaction identifiers;
  • signed transaction and server-notification data;
  • purchase, renewal, expiry, revocation, and signed dates;
  • subscription status and StoreKit environment; and
  • the pseudonymous App Store account token associated with the purchase.

3.4 Device, security, and technical information

We automatically process limited technical information needed to operate and secure the Service:

  • IP address, HTTP method and path, response status, request identifier, timestamp, response duration, user-agent string, and relevant internal account or relationship identifiers in server logs;
  • access-token and refresh-token security records, including one-way token hashes, token-family and rotation metadata, expiry, and revocation status;
  • Sign in with Apple nonce records;
  • Apple App Attest key identifiers, public keys, receipts, environment, counters, challenge records, and last-use timestamps;
  • WebSocket connection and rate-limit metadata; and
  • deployment version and database-lineage identifiers used for reliable cache recovery.

App Attest helps us confirm that sensitive requests originate from a genuine instance of LoveStreaks on an Apple device. We do not use it for advertising or cross-app tracking.

3.5 Safety and moderation information

If you report content or block someone, we collect:

  • reporter and reported-account identifiers;
  • the report reason, optional details, source, status, and timestamps;
  • a privacy-minimized snapshot of the exact reported display name, group name, or custom streak text needed to review the report;
  • a cryptographic fingerprint and version of the reported content; and
  • block-list records.

We may automatically screen display names, group names, and custom streak text for objectionable terms before accepting them. This screening is for safety; it is not used to profile you or make decisions with legal or similarly significant effects.

If moderation email alerts are enabled, the email provider receives only the report ID, reason category, source category, and timestamp. Report details, names, relationship names, and custom text are not placed in the alert email.

Blocking cancels pending invitations between the two accounts and prevents new invitations in either direction. If both accounts are current members of the relationship from which the block is made, the blocking member is immediately removed from that shared relationship. The other account is told only that a partner or group member left, not that a block caused the departure. In a one-to-one relationship, the remaining member keeps a solo copy and its existing non-deleted history. In a group, the group remains available to its other members and administration transfers when necessary.

3.6 Support communications

If you contact us, we collect the email address and information you choose to include, plus the correspondence and information needed to resolve the request. Please do not send passwords, full payment-card numbers, government identifiers, or unnecessary sensitive details.

3.7 Information stored only on your device

LoveStreaks stores authentication credentials in Apple's Keychain and may store preferences, category caches, reminder rules, notification choices, generated art cards, and a local app-login streak on your device. Local notification content is scheduled through iOS. When you choose a photo through Apple's system picker, the app processes that selected photo locally to create an art card; the selected photo and generated card are not uploaded to us. If you choose to save the result, the app asks iOS for add-only photo-library access and writes that card to your library; it does not browse your library. Signing out clears account-derived local state, scheduled and delivered LoveStreaks reminders, and cached relationship state. The device may retain its Keychain-protected App Attest key reference so the same genuine app installation can securely sign in again without unnecessary integrity-key churn. Signing out does not delete art cards you already saved. iOS retains app permissions until you change them in iOS Settings.

4. Sources of information

We receive information:

  • directly from you when you sign in, create content, change settings, report content, block someone, or contact support;
  • from relationship members when they invite you or interact with a shared relationship;
  • automatically from the app, device, and network when you use the Service; and
  • from Apple when it authenticates you, verifies an app instance, processes a subscription, or sends subscription status updates.

We do not purchase personal-information lists or obtain data from data brokers.

5. Why we use information

We use personal information only as reasonably necessary to:

  1. create, authenticate, secure, and administer accounts;
  2. provide invitations, relationships, streak tracking, reminders, realtime synchronization, Premium, account recovery, and customer support;
  3. verify purchases, restore entitlements, prevent subscription fraud, and keep subscription state accurate;
  4. prevent abuse, enforce rate limits, filter objectionable content, maintain blocks, investigate reports, and enforce our Terms;
  5. debug failures, preserve service availability, protect data integrity, and recover safely from an infrastructure incident;
  6. comply with law, valid legal process, tax and accounting obligations, and enforceable regulatory requests; and
  7. establish, exercise, or defend legal claims and protect users, the public, LoveStreaks, and our service providers from fraud or harm.

Where the GDPR, UK GDPR, or similar law applies, our legal bases are:

  • contractual necessity to provide the features you request;
  • legitimate interests in securing, maintaining, troubleshooting, and improving the Service, preventing fraud and abuse, and protecting legal rights, balanced against your rights;
  • consent for optional device permissions and other processing where the law requires consent; and
  • legal obligation or public-interest/legal-claims grounds where applicable.

LoveStreaks is not a medical service and does not ask for diagnoses or clinical records. A streak or free-form custom entry can nevertheless reveal health, fitness, intimacy, religious, or other sensitive information. We process such content only to provide the user-directed private relationship feature, safety review, and security. Do not enter sensitive information unless you want it stored and shared with the selected relationship members. Where local law requires a separate form of consent for such information, we will obtain it before offering the affected feature in that jurisdiction.

6. When we disclose information

We do not sell personal information. We disclose it only as follows.

6.1 Other relationship members

Members of a relationship receive the shared account names, membership, relationship settings, streak content, activity, and statistics needed for that relationship. A recipient may take screenshots or otherwise retain information outside our control. Choose members and content carefully.

6.2 Service providers

We use vendors acting under contract or their own applicable terms to perform limited services:

  • Apple and its affiliates — Sign in with Apple, App Store and StoreKit payments, subscription status, App Attest, device notifications, and related platform services;
  • Railway Corporation and its infrastructure providers — application hosting, networking, PostgreSQL database hosting, logs, backups, and private object storage in North America (East); and
  • Resend, Inc., if moderation alerts are enabled — delivery of the non-sensitive report-queue alert described above.

Support email may also pass through the email providers used by you and us. These providers process information only for the relevant service, subject to their contracts and legal obligations.

6.3 Legal, safety, and corporate events

We may disclose information when we reasonably believe disclosure is necessary to comply with applicable law or valid legal process; protect rights, safety, property, or users; investigate fraud or security incidents; or enforce our agreements. We review government and legal requests for validity and scope where the law permits.

If the Service is involved in a merger, financing, reorganization, bankruptcy, sale of assets, or transfer of operations, information may be disclosed under appropriate confidentiality and used only consistently with this Policy unless lawful notice or consent permits otherwise.

7. International processing

LoveStreaks and its providers may process information outside your province, state, or country, including in Canada and the United States, where privacy laws may differ. Before offering the Service where restricted-transfer rules apply, we will use an available lawful transfer mechanism, such as an adequacy decision, approved contractual clauses, or another legally recognized safeguard, and complete any required transfer assessment. Contact us to request available information about applicable safeguards.

8. Retention

We keep personal information only for the purposes described above, then delete or de-identify it, subject to technical, legal, and security constraints.

Information Normal retention
Active account, relationship, streak, and invitation records While the account or shared relationship remains active, until the relevant content or account is deleted
Auth nonces and unused App Attest challenges Until their short expiry; expired records are removed by automated maintenance
Refresh-token records Until expiry; revoked records may remain for up to 30 days to detect replay and investigate abuse
Consumed App Attest challenges and processed subscription outbox jobs Up to 30 days
App Attest registered keys While needed to protect an active account; deleted with the account
Open safety reports Until reviewed, the related account is deleted, or the report is no longer needed
Removed or dismissed safety reports Up to 365 days after resolution, unless a longer period is required for an active dispute, investigation, or legal obligation
Block records Until unblocked or either account is deleted
Operational request logs The shortest period reasonably needed for security and reliability under the production hosting plan; the production target is no more than 30 days unless an incident or legal hold requires longer
StoreKit transaction and subscription-integrity records While linked to an active account and, after unlinking, for the period reasonably necessary for purchase restoration, fraud prevention, accounting, dispute handling, and legal compliance; the production target is no more than seven years after the last relevant transaction unless law requires longer
Account-deletion recovery receipts Pseudonymous identifiers only, for the configured backup-restoration window; the production target is 400 days, unless a legal hold or longer backup cycle requires more
Support correspondence Normally up to 24 months after the matter closes, unless needed longer for a dispute or legal obligation
Database backups According to the documented production backup cycle; access is restricted, backups age out, and the deletion ledger is reapplied before a restored database is reopened

The stated "production targets" require matching host retention and lifecycle settings. We will not represent those targets as active until the corresponding production configuration is verified.

9. Account deletion and shared records

You can delete your account in Settings → Delete Account. Deletion:

  • removes your account profile, credentials, invitations, memberships, blocks, reports, device-integrity records, and custom streak definitions you authored;
  • removes active and inactive tracked copies of your authored custom streaks;
  • deletes a relationship that no other member retains;
  • leaves a shared relationship available to its remaining members, transfers a group administrator when necessary, and removes your membership and identity fields; and
  • unlinks App Store records from your deleted LoveStreaks account.

A small pseudonymous deletion receipt is written outside the primary database before deletion so a later backup restoration does not resurrect a deleted account. Apple transaction records and deletion receipts may remain for the narrow purposes and periods in Section 8.

Deleting LoveStreaks does not cancel an Apple auto-renewable subscription. Manage or cancel Apple billing in Apple Account subscription settings.

10. Security

We use administrative, technical, and organizational safeguards proportionate to the sensitivity of the information, including:

  • TLS for network transport;
  • Keychain storage for app credentials;
  • short-lived access tokens, rotating refresh tokens, replay detection, and server-side revocation;
  • encryption of stored Sign in with Apple refresh credentials;
  • App Attest verification for production mutations;
  • signed StoreKit verification and authoritative Apple checks;
  • access controls, rate limits, request-size limits, security headers, content filtering, and private database/object storage;
  • minimized moderation email alerts; and
  • a recovery barrier and deletion ledger for safe database restoration.

No system can guarantee absolute security. Keep your Apple Account and device secure, use only relationships you trust, and contact us promptly if you suspect unauthorized access.

11. Your choices and rights

Depending on your location, you may have rights to:

  • know whether and how we process your personal information;
  • access or receive a portable copy of eligible information;
  • correct inaccurate information;
  • delete information or your account;
  • restrict or object to certain processing;
  • withdraw consent, without affecting processing already performed lawfully;
  • appeal a denied privacy request where applicable;
  • lodge a complaint with a privacy regulator; and
  • receive equal service and pricing without unlawful discrimination for exercising a privacy right.

You can edit your display name, remove custom streaks, leave or delete eligible relationships, manage blocks, hide optional intimacy prompts, change local reminders, and delete your account in the app. For other requests, email support@lovestreaks.app with "Privacy Request" in the subject.

We may verify a request using the signed-in account or information reasonably necessary to prevent disclosure or deletion by an impostor. Authorized agents must provide legally sufficient authorization, and we may still verify the account holder directly where allowed. We will respond within the period required by applicable law.

Some rights have lawful exceptions, including protection of other users' rights, fraud prevention, security, legal claims, and records we must retain. A copy of shared data may be limited where disclosure would adversely affect another person.

California and similar U.S. state notices

During the preceding 12 months, we may have collected the categories described in Section 3: identifiers and contact information; commercial and purchase information; internet or network activity; user-generated content; relationship and app interaction data; possible health, fitness, or other sensitive information reflected in streak activity; and security/diagnostic data. We collect these from the sources in Section 4, use them for the purposes in Section 5, and disclose them to the recipient categories in Section 6.

We have not sold these categories or shared them for cross-context behavioural advertising. We do not use or disclose sensitive personal information to infer characteristics or for purposes outside those permitted by applicable law. We therefore do not provide a "Do Not Sell or Share" link. If our practices change, we will provide required notice and controls first. Because we do not sell or share data for targeted advertising, browser Do Not Track and Global Privacy Control signals do not alter current processing.

Canada

You may request access to and correction of personal information and challenge our compliance by contacting the privacy contact in Section 2. You may also contact the Office of the Privacy Commissioner of Canada or the applicable provincial regulator.

EEA, Switzerland, and United Kingdom

You may have the rights listed above and the right to complain to the supervisory authority where you live or work. You may also contact us about the applicable legal basis, legitimate-interest balancing, or transfer safeguard. Required controller and representative details must be completed in Section 2 before launch in these territories.

12. Children and age-restricted content

The Service is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. A higher minimum age may apply where local law requires it. If you are under the age of legal majority, you may use the general Service only with permission from a parent or legal guardian.

Optional intimacy prompts are intended only for people aged 18 or older, are hidden by default, and require an adult confirmation in the app. We do not ask for or store a date of birth for that local confirmation. If you believe a child provided personal information improperly, contact us so we can investigate and delete it as required.

13. Changes to this Policy

We may update this Policy to reflect product, legal, or operational changes. We will change the "Last updated" date and provide additional notice in the app or through another appropriate channel if a change is material or consent is required. We will not materially expand an incompatible use of previously collected information without a lawful basis and any required notice or consent.

14. Contact and complaints

Questions, privacy requests, or complaints may be sent to:

Privacy Officer
Daitoku Corp.
Email: support@lovestreaks.app

We will investigate privacy complaints and explain the outcome. You may also contact the privacy or data-protection authority with jurisdiction over you.

© 2026 Daitoku Corp. All rights reserved.

support@lovestreaks.app