1. What stays on your device
Most tools here — the journal, Love Map, Consent Keyrings, Kinship Map, Metamour Nexus,
Compersion Coach, Appreciation Jar, saved paths and quiz results — store what you write in your
browser's localStorage, under keys beginning pil.. That data is never
uploaded, and we cannot read it.
Be aware of two things. First, this data is stored in plain text in your browser — with one exception below — so anyone with access to your unlocked device could read it. Second, because it lives only in your browser, clearing your site data deletes it permanently and we have no backup to restore.
The single exception is the Vault, which encrypts entries on your device with a passphrase only you know (PBKDF2 → AES-GCM-256). What's stored there is ciphertext; without your passphrase it cannot be opened by us or anyone else.
You can see the full inventory, export it as one file, or erase it at any time on Your data.
2. What is stored on a server
Three features exist so that two people can share something, so they necessarily involve a server. If you never sign in and never use them, we hold nothing about you at all.
- Your account — a handle, a display name, a role, and a session token for each device you sign in on, plus the browser user-agent string.
- Live Rooms — the messages and appreciations you post, with the name you posted under.
- The Guardian (date safety) — the close contacts you add (including another person's name and phone number or email), your date plans, your safe word and duress word, and any alert records.
- The Compatibility Questionnaire — your answers, who you shared the questionnaire with, and its status.
- An audit log of actions taken on your account, for security and debugging.
This data is held in a Postgres database hosted by Supabase in the EU (Ireland). It is not end-to-end encrypted: it is encrypted in transit and at rest by the hosting provider, but the operator of this site can technically read it. Please do not put anything in the shared features that you could not bear to have read.
If you add someone else's contact details to the Guardian, please make sure they're content to be listed.
3. What we don't do
- No advertising, and no advertising or tracking pixels.
- No analytics product, no behavioural profiling, no session recording.
- No cookies used for tracking. Your sign-in token is kept in your browser's local storage.
- Your data is never sold, rented, or shared for marketing.
4. Third parties
- Google Fonts — typefaces are loaded from
fonts.googleapis.comandfonts.gstatic.com, which means Google receives your IP address and user-agent when a page loads. - Supabase — hosts the database behind the shared features described above.
- jsDelivr / esm.sh — if, and only if, you use the optional voice answering on the Compatibility Questionnaire, a speech-recognition model is downloaded from one of these public CDNs. Your audio never leaves your device — the transcription runs entirely in your browser, the recording is discarded immediately afterwards, and only the text you keep is saved.
5. Your choices
- See and export everything on this device — Your data.
- Erase everything on this device — same page, one button. It is immediate and permanent.
- Erase your server-side data — sign in and use Erase my data; this deletes your account, sessions, contacts, plans, alerts, questionnaire answers and personas.
- If you're in the UK/EU you have rights of access, correction, erasure, portability and objection under the UK GDPR / GDPR. The tools above cover most of these directly; for anything else, write to us.
6. Children
This site discusses adult relationships, intimacy and sexual health. It is not intended for anyone under 18, and we do not knowingly collect data from under-18s.
7. Changes and contact
If this policy changes materially, the date at the top will change and the change will be noted here. Questions, or a data request: privacy@partnersin.love.
See also: Terms · Your data · How the Vault's encryption works