Privacy
How HeartCard handles your data
This page describes how the current HeartCard product works. It does not make promises that the code or provider configuration cannot verify.
Your account
Signing in is optional. If you sign in, Supabase Auth manages your user ID, email address, sign-in provider, and provider account details returned during sign-in. HeartCard does not currently keep a separate profile record.
Your cards and memories
While you create, editable card fields are saved in this browser’s local storage. Publishing stores the relationship, occasion, language, names, card text, design settings, optional sections, status, and timestamps in Supabase so the card can be opened and managed.
Photos
Uploaded photos are stored in HeartCard’s public Supabase Storage bucket at generated image URLs so a published card can display them. Anyone who has a direct photo URL can access that image. Photos are not sent in AI writing requests.
A signed-in owner can permanently delete a saved card from My Cards; the deletion flow also removes its associated uploaded photo objects. Disabling a card link does not delete its photos or revoke a direct photo URL someone already has.
AI assistance
When you ask for writing help, HeartCard sends OpenAI the relationship, occasion, selected language and tone, names, and the personal detail or message text needed to draft or refine the card. The app does not send uploaded photos in that request and does not log the prompt or generated response.
HeartCard’s code does not verify the provider account’s retention or training settings. We therefore do not claim that the provider never retains or uses submitted text for training. Avoid including passwords, ID numbers, financial details, medical records, or private documents.
Sharing
Anyone with a published card link can view the full card, including its names, message, optional sections, and photos. Cards are not shown in a public HeartCard directory, and card pages ask search engines not to index them, but those measures are not access controls.
Disabling and deleting
Disable Link makes the HeartCard page unavailable while keeping the card and photos stored in your library. Delete Permanently removes the card record, its content and interaction events, and associated uploaded photo objects; the public card link then stops working.
Guest publishing is supported, but guest cards do not currently have self-service management. Signed-in owners can manage cards published to their account from My Cards.
Data retention
HeartCard does not currently set an automatic expiry for browser drafts or published cards. A browser draft remains until it is replaced, reset, or you clear browser storage. Published and disabled cards remain stored until they are deleted.
Analytics and recipient activity
When analytics is configured, HeartCard records structural product events such as selected relationship or occasion, generation completion, publishing, opening, and reactions. Raw memories, full messages, names, generated drafts, photo URLs, and public card URLs are excluded. Recipient opens and selected reactions are also stored with the card in Supabase.
Contact
Production support email required.