Privacy
How HeartCard handles your data
This page describes how the current HeartCard product works. It does not make promises that the code or provider configuration cannot verify.
Your account
Signing in is optional. If you sign in, Supabase Auth manages your user ID, email address, sign-in provider, and provider account details returned during sign-in. HeartCard does not currently keep a separate profile record.
Your cards and memories
While you create, editable card fields are saved in this browser’s local storage. Publishing stores the relationship, occasion, language, names, card text, design settings, optional sections, status, and timestamps in Supabase so the card can be opened and managed.
Photos
Uploaded photos are stored in HeartCard’s public Supabase Storage bucket at generated image URLs so a published card can display them. Anyone who has a direct photo URL can access that image. Photos are not sent in AI writing requests.
A signed-in owner can permanently delete a saved card from My Cards; the deletion flow also removes its associated uploaded photo objects. Disabling a card link does not delete its photos or revoke a direct photo URL someone already has.
Voice Signature
An optional Voice Signature is stored in private Supabase Storage and is used only as part of the card. HeartCard does not send the recording to OpenAI, transcribe it, analyze it, or include its content or private media path in analytics.
A published card authorizes short-lived playback links. Disable Link stops new playback links, although one already issued may work for up to about 120 seconds and an audio file someone already downloaded cannot be recalled. Delete Permanently removes the associated recording before the card deletion reports success.
AI assistance
When you ask for writing help, HeartCard sends OpenAI the relationship, occasion, selected language and tone, names, and the personal detail or message text needed to draft or refine the card. The app does not send uploaded photos in that request and does not log the prompt or generated response.
HeartCard’s code does not verify the provider account’s retention or training settings. We therefore do not claim that the provider never retains or uses submitted text for training. Avoid including passwords, ID numbers, financial details, medical records, or private documents.
Sharing
Anyone with a published card link can view the full card, including its names, message, optional sections, photos, and Voice Signature when present. Cards are not shown in a public HeartCard directory, and card pages ask search engines not to index them, but those measures are not access controls.
Disabling and deleting
Disable Link makes the HeartCard page unavailable while keeping the card and uploaded media stored in your library. Delete Permanently removes the card record, its content and interaction events, and associated uploaded photo and Voice Signature objects; the public card link then stops working.
Guest publishing is supported, but guest cards do not currently have self-service management. Signed-in owners can manage cards published to their account from My Cards.
Data retention
HeartCard does not currently set an automatic expiry for browser drafts or published cards. A browser draft remains until it is replaced, reset, or you clear browser storage. Published and disabled cards remain stored until they are deleted.
Analytics and recipient activity
When analytics is configured, HeartCard records structural product events such as selected relationship or occasion, generation completion, publishing, opening, and reactions. Raw memories, full messages, names, generated drafts, photo URLs, and public card URLs are excluded. Recipient opens and selected reactions are also stored with the card in Supabase.
Contact
Production support email required.