Effective date: September 18, 2026
App: Heart Knows — relationship journal for iOS and Android
Heart Knows is a privacy-first, on-device journal. Your meetings, pulses, debriefs, and question notes are stored on your phone in a SQLCipher-encrypted database, and we do not operate a server that receives them. There is no account and nothing to sign in to — the app never asks for a name, email address, phone number or password, and the encrypted journal leaves the device only inside your own phone backup or an export you make yourself.
The database file is included in this phone’s backup unless you turn that off in Settings → Backup. On iPhone, that is Apple’s encrypted iCloud/Finder backup; the key that opens the journal travels with it. On Android, the live file cannot leave the chip, so the app keeps a separate encrypted snapshot that Google Auto Backup can restore onto a new phone. Either way, restoring the phone from backup brings the notebook back without a passphrase. That also means Apple or Google hold a copy that could be restored by anyone with access to that account. Turn the switch off if you do not want that.
A passphrase export is still available if you want a file only you can open.
| Data | Collected? | Where it stays |
|---|---|---|
| Journal entries (people, meetings, pulses, notes) | Yes — you create it | Your device (encrypted). Also in this phone’s iCloud or Google backup unless you turn that off |
| App lock / biometric preference | Yes | Your device only |
| Purchase status (subscription or lifetime) | Yes — via Apple/Google/RevenueCat | Billing providers; entitlement flag on device |
| Install and store details sent to RevenueCat (anonymous install identifier, device model, OS version, locale, store country) | Yes — on every launch, whether or not you ever buy anything | RevenueCat |
| Diagnostics preference (on or off) | Yes | Your device only |
| Crash diagnostics (redacted error summary, Dart stack trace, app/device metadata) | In release builds when Firebase is configured and diagnostics are on | Firebase Crashlytics |
| Feedback emails | Only if you choose to send one | Your email client → our support inbox |
| Analytics events (onboarding and purchase-funnel actions, plus Firebase default install, session, and engagement events) | In release builds when Firebase is configured and diagnostics are on | Firebase Analytics |
| Session and installation records (random Firebase installation ID, bundle ID, OS and SDK version, network type, time in foreground) | In release builds when Firebase is configured and diagnostics are on | Firebase (Installations, Sessions) |
| Voice dictation audio and transcript | Not collected. Recognised on this device only when you tap the dictate button; the audio is never stored or uploaded, and the text lands in your encrypted journal | Your device only |
| Face ID / passcode | Not collected. iOS performs the check and tells the app only whether unlock succeeded | Your device only |
| Check-in reminders | Scheduled and shown by this phone; nothing is sent to a push server | Your device only |
We never collect person names, pulse values, debrief text, or question answers — not for analytics, not for advertising, and not inside a crash report.
A crash report is not the error object. Before anything is transmitted, the error is reduced to a fixed set of fields:
SqfliteDatabaseException)draft_save)787)Error messages are not included. This matters because a database error message can otherwise carry the statement that failed along with the values bound to it — which, for a failed draft save, would be the text of your debrief. Nothing derived from an error message, and no widget or screen contents, reaches Crashlytics.
requiresOnDeviceRecognition); if the phone cannot recognise speech locally, dictation is simply unavailable and you keep typing. There is no cloud fallback, so the recording of your voice is never uploaded to us, to Apple, or to Google by the app, and no audio is kept once the words appear in the text field. The transcript is ordinary journal text and is protected the same way.Settings → Privacy and lock → Share diagnostics. It is on by default in release builds. Crash reports and analytics events may be sent as described above. Switching it off stops crash reports and analytics events at once — including the native Crashlytics and Analytics collection — and the choice is stored on your device. Journal content is never included. Two things are not covered by this switch: subscription billing may still sync with Apple, Google, and RevenueCat to validate purchases, and the RevenueCat SDK still sends the install and store details listed above at launch.
The app has no user ID. The only identifiers involved are random, per-install values generated by the SDKs themselves: RevenueCat's anonymous app user ID, the Firebase installation ID and Google Analytics app-instance ID, and Crashlytics' installation UUID. None of them is derived from your name, email, phone number, Apple ID or Google account, none is the advertising identifier (IDFA) or vendor identifier (IDFV), and we do not join them to any other data set. We do not use them, or anything else, to track you across other companies' apps or websites, and the app has no App Tracking Transparency prompt because it does no tracking.
No third party receives your journal content, and this app does not upload your journal database to our servers. Apple's Face ID and on-device speech recognition run inside iOS on your phone; the app does not send anything to Apple for either feature. Phone backup is the exception you control: Settings → Backup is on unless you turn it off. On iPhone, iOS copies the database into your Apple device backup. On Android, Google Auto Backup may hold an encrypted snapshot plus the secret that opens it. That is Apple or Google storing it under your account, not us sending it.
For readers comparing this policy with the App Store "App Privacy" section: the label declares Crash Data, Other Diagnostic Data, Product Interaction and Purchase History — all not linked to you and not used for tracking — and nothing else. Voice dictation, Face ID and reminders appear nowhere on it because none of them collects data from the device. Journal content is not declared because it is never collected.
Heart Knows is intended for adults 18 and older. We do not knowingly collect data from anyone under 18.
We will update this policy when practices change. The effective date at the top will change accordingly.
Questions about privacy: 132.rishabh@gmail.com.