Infinite Heart
Hearts Geo-lock About Get the app

Legal

Privacy Policy

Last updated: 7 August 2026

This policy explains what personal data Infinite Heart ("we") collects when you use our mobile app and website, why we collect it, and the choices you have. Data controller: Infinite Heart sp. z o.o., Szlak 77/222, 31-153 Kraków, Poland. Contact: share@infiniteheart.love.

1. What we collect

  • Account information — your name, email address, and (if you sign in by phone) your phone number. You can also sign in with Google or Apple.
  • Your content ("memories") — the photos, videos, audio, letters, engraved text and songs you attach to a heart, and the AR videos you record. Content you mark private is stored encrypted and is never shown to anyone but you.
  • Precise location — when you geo-lock a heart or discover one in augmented reality, we use your device's precise location to anchor and find hearts on the map.
  • Identifiers — a user ID and device identifier used to operate your account and deliver notifications.
  • Purchase history — records of hearts and add-ons you buy.
  • Usage data — basic product-interaction data to understand how the app is used and improve it.
  • Instagram (optional) — only if you connect Instagram: your Instagram username and id, used to credit a sharing reward. See our Data Deletion page.

We do not collect your health data, your contacts, or your browsing history, and we do not use your data for third-party advertising or cross-app tracking. Payments are processed by Stripe; card details are entered outside our app and we never see or store them.

2. How we use your data

Only to provide the service: to create and geo-lock your hearts, store and display your memories to the people you choose, place and discover hearts in AR, process purchases, send you notifications, and keep the app secure and working. We use your data for these functions and for basic analytics of app usage — nothing else.

3. Who can see your content

Your memories are private by default. A memory is shown to another person only if you explicitly mark it public on a heart you share or geo-lock — and encrypted memories are never shared. You control who receives or finds each heart.

4. Third-party services

We use trusted providers strictly to run the service: Google Firebase (authentication, database, file storage, push notifications), Google Maps / Mapbox (maps), Stripe (payments), and, if you connect it, Instagram / Meta. These providers process data on our behalf under their own security and privacy terms.

5. Storage, security and retention

Data is stored on Google Cloud infrastructure. Private and encrypted memories are protected in transit and at rest. We keep your data for as long as your account exists; when you delete your account, your personal data and content are permanently deleted (backups purged within 30 days), except records we must keep by law (e.g. invoices) and any on-chain "eternalization" record, which by its nature cannot be erased.

6. Your rights

You can access, correct, or delete your data, and object to or restrict certain processing. The fastest way to delete everything is in the app: Profile → Settings → Delete account, or email us — see the Data Deletion page. Under the GDPR you may also lodge a complaint with a supervisory authority.

7. Children

Infinite Heart is not directed to children under 16, and we do not knowingly collect their data.

8. Changes

We may update this policy; we will revise the date above and, for material changes, notify you in the app.

9. Contact

For any privacy question or request, contact share@infiniteheart.love.