← RelationshipOS

Privacy Policy — RelationshipOS

Last updated: 30 July 2026 Effective date: 30 July 2026

This Privacy Policy explains how RelationshipOS ("RelationshipOS", "we", "us", "our") collects, uses, shares, and protects personal data when you use the RelationshipOS platform and its apps at relationshipos.tech (the "Service").

We have written this policy to be read, not skimmed past. If anything here is unclear, contact us at hi@relationshipos.tech.

Our core promise, in plain language: We do not sell, rent, or trade your personal data. We do not use the private content you create — your letters, memories, postcards, moods, or messages — for advertising, profiling, or to train artificial intelligence or machine-learning models. We share data only with the limited set of service providers needed to run the Service, only with the partner you choose to link your account to, and only when the law requires it. The rest of this document explains exactly how that works.


1. Who is responsible for your data (Data Controller)

The data controller responsible for your personal data is:


2. The scope of this policy

This policy covers the RelationshipOS suite of apps, currently including Letters in Time, Storytime Timeline, Mood Postcards, Shared Bucket List, Firsts & Favorites, Dream Together, Daily Memory Match, and Heirloom, together with any additional apps added to the suite under the relationshipos.tech account system.

It does not cover planstoday.fun (Experience Composer), which is a separate product with its own branding and requires its own privacy notice. It also does not cover third-party websites or services we link to.


3. The personal data we collect

We collect the following categories of personal data:

3.1 Data you give us directly

3.2 Data we collect automatically

3.3 Data from third parties


4. Sensitive ("special category") data

The Service lets you write deeply personal content. The things you choose to record — about your relationship, feelings, and private life — may reveal information that data-protection law treats as special category data under Article 9 GDPR (for example, information that could indicate your sex life or sexual orientation).

We do not require you to provide this information, and we do not analyse your content to infer sensitive characteristics. Where your content does contain special category data, our legal basis for processing it is your explicit consent (Article 9(2)(a) GDPR) — which you give by opting in at signup and by voluntarily creating and storing that content within the Service. You can withdraw that consent at any time by deleting the content or your account (see Section 9).


5. Why we use your data, and our legal basis (GDPR Article 6)

Purpose Legal basis
Create and operate your account; provide the apps and store Your Content Performance of a contract (Art. 6(1)(b))
Link your account with your partner and share content between you as the app's function requires Performance of a contract (Art. 6(1)(b))
Process payments, manage subscriptions, prevent payment fraud Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax/accounting
Send service/transactional emails (e.g. "a letter is ready", payment receipts, security notices) Performance of a contract (Art. 6(1)(b))
Keep the Service secure, prevent abuse, debug errors Legitimate interests (Art. 6(1)(f))
Basic, privacy-friendly usage analytics to improve the Service Legitimate interests (Art. 6(1)(f))
Store and process intimate/special-category content Explicit consent (Art. 9(2)(a))
Send marketing or product-update emails Consent (Art. 6(1)(a)) — opt-in, withdrawable anytime
Set non-essential cookies / push notifications Consent (Art. 6(1)(a))
Comply with legal requests and obligations Legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have balanced those interests against your rights. You can object to this processing (see Section 9).


6. What we will never do with your data

To be explicit, because it matters:


7. Who we share data with (Recipients and Sub-processors)

We share personal data only with: (a) the partner you link to, as the Service's features require; and (b) the categories of service provider ("sub-processors") below, who process data on our instructions only and under contracts that require them to protect it.

Category of recipient Purpose Data involved
Hosting & storage provider Web hosting, application servers, database, scheduled tasks Account data, Your Content
Payment processor Processing payments, subscriptions, and billing Name, email, payment data, billing records
Email delivery (our hosting provider's mail servers — not a separate vendor) Transactional email: sign-in and password resets, letter-delivery notices, billing notices Name, email, email content
Push notificationsnot in use We do not send push notifications and have no push provider. Notifications appear inside the app only. If this changes we will name the provider here first. None
Website analytics provider (Statcounter) Privacy-friendly visitor statistics on our public marketing pages only (relationshipos.tech home, apps, and pricing) — e.g. page views, referring sites, and coarse/approximate location. In-app usage analytics remain first-party. We do not use a third-party real-time-messaging or error-monitoring vendor; if that changes, this policy and our sub-processor list will be updated first. IP address, browser/device characteristics, pages viewed on the marketing site

Our sub-processors, named in full: DreamHost (web hosting, database, and outbound email), Stripe (payments and subscriptions), DreamObjects (audio storage, used only by the Heirloom app), and Statcounter (visitor statistics on our public marketing pages). That is the complete list. We do not use a third-party push-notification provider, a third-party marketing-email provider, or an error-monitoring vendor; if that changes we will update this list before the change takes effect. Questions: hi@relationshipos.tech.

We may also disclose data: (i) to comply with a valid legal obligation, court order, or lawful request; (ii) to protect the rights, safety, or property of users or the public; or (iii) in connection with a merger, acquisition, or sale of assets, in which case we will notify you and this policy will continue to protect your data.


8. International data transfers

If our controlling entity or any sub-processor processes your data outside the EU/EEA or the UK (for example, in the United States), that transfer is protected by an appropriate safeguard under Chapter V GDPR, which may include:

You may request a copy of the relevant safeguard by contacting hi@relationshipos.tech.


9. Your rights (GDPR / UK GDPR)

Under the GDPR (and equivalent UK law), you have the right to:

To exercise any right, contact hi@relationshipos.tech or use the self-service data tools in Settings → Data (export and delete). We will respond within one month. We will not charge a fee unless your request is manifestly unfounded or excessive.

Right to complain. You may lodge a complaint with your local data-protection supervisory authority at any time.


10. Your US state privacy rights (California and other US states)

If you are a resident of California or another US state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, or Utah), you have rights over your personal information. These rights complement — and do not replace — the rights in Section 9.

You have the right to:

Sale and sharing. In the last 12 months we have not sold your personal information and have not shared it for cross-context behavioral advertising, and we do not do so now. We do not knowingly sell or share the personal information of anyone (the Service is 18+).

Sensitive personal information. The intimate content you create, your account credentials, and the contents of communications may be "sensitive personal information" under California law. We use it only to provide the Service you asked for and the purposes in Section 5; we do not use it to infer characteristics about you, and we do not disclose it for any purpose that would trigger a right to limit its use.

Categories we collect map to the categories in Section 3: identifiers (name, email, IP), customer/billing records, internet and usage activity, approximate geolocation derived from IP, and the content and sensitive information you choose to provide. Sources, purposes, and recipients are described in Sections 3, 5, and 7.

How to exercise these rights. Contact hi@relationshipos.tech or use Settings → Data. We will verify your request against your account, and you may use an authorized agent with proof of authorization. We honor opt-out preference signals such as Global Privacy Control (GPC) where required.

California "Shine the Light". We do not disclose personal information to third parties for their own direct-marketing purposes.


11. Partner linking, shared content, and relationships ending

The Service is built for two people. When you link your account with a partner and share content, that partner can see the content you share with them, and they may be able to keep their own copies (for example, by exporting or taking a screenshot). We cannot control or retrieve content once your partner has legitimately accessed it.

If a relationship ends, you can unlink your partner in Settings → Partner. After unlinking:

We are not responsible for how a linked partner uses content you chose to share with them.


12. How long we keep your data (Retention)


13. How we protect your data (Security)

We use technical and organisational measures appropriate to the sensitivity of the data, including: encrypted connections (HTTPS/TLS), hashed and salted passwords, authentication and access controls on every server endpoint, per-app secret isolation, scoped database queries so users can only access their own and their linked partner's data, an audited administrative layer with least-privilege access, and least-privilege access for staff and sub-processors.

No system is perfectly secure. If a personal-data breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay, as required by Articles 33–34 GDPR.


14. Children

The Service is intended for adults and is not directed at anyone under 18. We require you to confirm you are 18 or older at signup, we do not knowingly collect data from children, and we do not knowingly sell or share the data of minors. If you believe a minor has provided us data, contact hi@relationshipos.tech and we will delete it.


15. Cookies and similar technologies

We use a small number of strictly necessary cookies / local-storage items to keep you logged in and run the Service, and (with your consent) optional analytics. See our Cookie Policy for the full list and how to control them.


16. Changes to this policy

We may update this policy. If we make material changes, we will notify you by email or an in-app notice before the changes take effect, and where the change affects a basis that relies on your consent, we will ask you to accept the updated version. The "Last updated" date at the top always reflects the current version. Continued use after changes take effect means you accept the updated policy.


17. Contact us