Privacy Policy – Couplio
Last Updated: November 15, 2025
Couplio ("we", "our", or "us") provides a private space for two people to exchange drawings and relationship updates. We are committed to handling your personal information responsibly. This policy explains what we collect, why we collect it, how long we keep it, and the choices you have.
1. Information We Collect
| Data Type | Details | Why We Collect It |
|---|---|---|
| Account info | Email address, password (hashed), display name | Create and secure your account, show your preferred name to your partner |
| Profile media | Optional avatar image | Personalize your experience |
| Drawings & captions | Artwork you create, optional notes, relationship milestones | Core product functionality—showing doodles to your partner |
| Device tokens | Firebase Cloud Messaging token, platform type | Deliver push notifications |
| Relationship metadata | Room pairing code, relationship start date, partner connection timestamp | Pair you with your partner and power widgets/timeline |
| Usage diagnostics | App version, crash analytics (aggregate) | Keep the app reliable |
We also receive your basic profile (name, email, avatar URL) when you choose Sign in with Google. We do not collect location data, contacts, or payment details.
2. How We Use Your Information
- Provide the service – authenticate you, keep rooms in sync, show your partner's latest doodles.
- Deliver notifications – let you know when a new drawing or update is available.
- Maintain safety – enforce pairing limits, detect suspicious activity, and respond to support requests.
- Improve the app – aggregate crash/usage metrics help prioritize fixes; they are not linked to specific drawings.
We do not sell or rent your personal data, nor do we use it for advertising or tracking across other apps.
3. How We Share Information
We only share data with service providers necessary to run Couplio:
- Supabase (database, authentication, storage) – https://supabase.com/privacy
- Firebase (push notifications, analytics) – https://firebase.google.com/support/privacy
- Google (optional account sign-in) – https://policies.google.com/privacy
Each provider is under contract to process data solely on our instructions. We do not give partners access to your drawings or profile unless you explicitly invite them.
4. Data Storage & Retention
- Location: Supabase (PostgreSQL + storage) hosted in the United States; Firebase Cloud Storage in Google Cloud's US region.
- Retention: We store data while your account remains active. When you delete your account, we remove Supabase records and storage objects within 30 days. Cached data on partner devices will clear once they refresh or reinstall.
- Backups: Database backups are encrypted and automatically purge on a rolling schedule (≤30 days).
5. Your Rights & Controls
- Access / export: Request a copy of your data (JSON export) via the in-app support form or by emailing us.
- Correction: Update your profile name/avatar at any time in the app.
- Deletion: Use the in-app "Delete my account" option (coming soon). We'll confirm deletion via email.
- Opt-out of notifications: Disable push notifications from Settings on your device.
Email support.couplio@skuza.app to exercise these rights. We respond within 30 days.
6. Security
- All traffic uses HTTPS/TLS.
- Supabase Row-Level Security ensures each user can only access their own room and drawings.
- Stored passwords are hashed using industry-standard algorithms; access to production systems is limited to authorized engineers.
- We monitor for suspicious spikes in activity and rotate API keys if compromise is suspected.
No online service is completely secure, but we continually review our safeguards and incident response plan.
7. Children's Privacy
Couplio is designed for individuals 13 years or older. We do not knowingly collect personal information from children under 13. If you believe a child has provided data, contact us and we will delete it promptly.
8. International Users
By using Couplio, you understand that your data will be processed in the United States. We rely on Standard Contractual Clauses when transferring data outside the EU/EEA and honor GDPR/CCPA rights outlined above.
9. Changes to This Policy
We may revise this policy as our service evolves. Material changes are announced via in-app notice or email, and the "Last Updated" date reflects the current version. Continued use after changes take effect constitutes acceptance.
10. Contact Us
All inquiries: support.couplio@skuza.app
If you have unresolved concerns, EU/UK residents may contact their local data protection authority, and US residents may contact their state attorney general.