Skip to content
LoveInk
SupportTermsPrivacy

Privacy Policy

Effective date: Month D, YYYY

LoveInk (“LoveInk,” “we,” “us,” or “our”) is operated by Roman Gurov, a company registered in [country] / an individual based in [city, country]. This Privacy Policy explains how information is handled when you use the LoveInk mobile application, this website, and related services (the “Service”). Roman Gurov is the controller of personal information processed for LoveInk.

1. Information We Handle

Account information

When you sign in with Apple, Apple and our authentication provider, Supabase, provide or process an account identifier, authentication tokens, and, depending on your Apple settings and what Apple makes available, your email address and name. We use this information to create and authenticate your LoveInk account. We also keep, on our Supabase backend, the Apple refresh token issued for your sign-in, encrypted at rest and used for one purpose only: when you delete your LoveInk account, we present it to Apple to revoke LoveInk’s Sign in with Apple authorization, as Apple requires. It is deleted with your account.

Mailing list

If Apple makes an email address available, we keep a contact record holding that address alongside your account identifier, so that we can send you occasional emails about LoveInk, such as new features and release announcements. If you chose Apple’s Hide My Email option, the address we hold is the forwarding address Apple generated, and messages reach you through Apple’s private email relay rather than directly. Every such email carries an unsubscribe link, and unsubscribing does not affect your account or your use of the Service. We do not send marketing email on behalf of anyone else.

Waitlist

Before LoveInk is released, this website carries a waitlist form. If you enter your address into it, we hold that address so that we can tell you when LoveInk is available. That is the only thing it is used for, and entering it is the whole of the consent we rely on — there is no account, no profile, and nothing else collected with it. The form records the address and the moment you submitted it. The page sets no cookies; the only third party it loads is the visit counter described next. You can unsubscribe from the release email when it arrives, or ask us to remove the address at any time using the contact address below. If you later create a LoveInk account with the same email address, the two records become one. At launch, rewrite this paragraph in the past tense: the form is gone, the addresses collected are still held.

Website analytics

Pages on this website load Cloudflare Web Analytics, which counts visits without cookies, without local storage, and without building a profile of you across sites. Cloudflare receives the page you opened, the site you arrived from, and the coarse technical details any browser sends with a request — country, browser and device type, and how quickly the page loaded. It does not receive your email address, and nothing it collects is joined to a waitlist entry or to a LoveInk account. There is no cookie to refuse, which is why this site asks you to accept nothing.

Onboarding and product-use information

During onboarding, you may answer questions about your goals and habits relevant to the app. We also collect information about how the Service is used, such as onboarding progress, which screens are viewed, which features are turned on, trial and paywall interactions, product identifiers for purchases, and account-deletion events. Name here any content the user types that leaves the device, and where it goes. If none does, say so.

Subscription information

If you view a paywall, buy or restore a subscription, or manage a subscription, Apple, RevenueCat and Superwall process purchase and subscription information. Superwall decides which paywall you see and draws it; RevenueCat and Apple handle the purchase itself. LoveInk receives entitlement and customer-status information needed to determine whether LoveInk Pro is active. We also record paywall and purchase events, such as the product identifier, successful restore, dismissal, or an error message.

So that a paywall can be tailored, LoveInk also sends Superwall a small profile: your account identifier once you sign in, the answers you gave during onboarding, and any other attribute the paywall copy interpolates.

App install attribution

If you installed LoveInk after tapping an ad we placed in the App Store, Apple can tell us which ad it was. On first launch LoveInk asks Apple’s AdServices framework for a short-lived attribution token, and one of our Supabase server functions exchanges that token with Apple. Apple returns identifiers for the campaign, ad group, keyword, and ad, the country the tap happened in, and whether the install was a first download or a re-download. Those identifiers describe the ad rather than you: they are identical for everyone who arrived through the same ad, and they carry nothing about your device, your identity, or what you do in other apps. We keep the result on your device and attach it to the analytics described below, to our subscription provider, and to the paywall profile sent to Superwall, so that we can tell which ads bring people who go on to find LoveInk useful. RevenueCat separately collects the same Apple token for the same purpose. None of this uses Apple’s Identifier for Advertisers and none of it involves the App Tracking Transparency prompt. If you did not arrive through one of our ads, nothing is recorded beyond the fact that no campaign applies.

Advertising we place outside the App Store — name the networks you actually run, or delete this paragraph and remove AppsFlyer; see docs/attribution.md — cannot be measured that way, because those companies are not Apple and get no token. For that we use AppsFlyer, an attribution provider. AppsFlyer receives an installation identifier it generates for this app on this device, the technical details of the install, and, once you sign in, your LoveInk account identifier, so that an install can be matched to the ad that produced it; our subscription provider reports subscription events to AppsFlyer on our servers for the same reason. Apple also sends AppsFlyer its own privacy-preserving install reports, which are aggregated and contain no identifier.

Matching an install to an ad shown in another company’s app additionally needs Apple’s Identifier for Advertisers, and iOS will only release it if you allow it. That is the App Tracking Transparency prompt LoveInk shows once during onboarding. Allowing it is optional and nothing in LoveInk depends on it. If you decline — or never answer — no advertising identifier is collected, AppsFlyer still records the install, and everything in the app behaves identically. Because we ask, LoveInk declares tracking in its App Store privacy labels.

Notifications

LoveInk can show two kinds of notification, and only if you allow notifications when iOS asks. Local notifications — for example a reminder before a trial ends — are scheduled on your device and involve no server. Remote notifications are sent through Apple Push Notification service; to send them we store the device token Apple issues, together with your account identifier and the push environment, on our Supabase backend. A device token identifies an app installation on one device and nothing else. Notifications are never required: refusing them changes nothing about the rest of the Service.

Device and interaction analytics

When analytics is configured, PostHog receives the LoveInk account identifier, product-use events described above, native app lifecycle events, and automatically captured touch interactions. Screen names are reported as route patterns, not as content. The PostHog SDK also stores analytics state on your device.

Crash and reliability information

When crash reporting is configured, Sentry receives crash reports and unhandled application errors, together with the LoveInk account identifier when you are signed in, and technical information about the device and the app such as device model, operating-system version, and app version and build. The start and end of app sessions are recorded so that we can measure how often LoveInk crashes. Your email address and the content you enter are not sent to Sentry, and performance tracing and session replay are switched off.

2. How We Use Information

We use information to:

  • create, authenticate, support, and delete LoveInk accounts;
  • provide the features you turn on and carry out the actions you request;
  • determine trial and subscription access and provide purchase-management features;
  • send the notifications you have allowed;
  • understand onboarding, feature use, reliability, and conversion so we can operate and improve LoveInk;
  • measure which advertising campaigns — in the App Store and elsewhere — lead to installs and subscriptions, so that we know which of our own ads are worth running;
  • send occasional emails about LoveInk to the address associated with your account, unless you have unsubscribed;
  • tell you about the release, if you joined the waitlist; and
  • protect the Service, diagnose errors, and respond to account-deletion requests.

3. Where Information Is Stored

Much of LoveInk’s functional data is stored locally on your device: list the local stores — settings, onboarding status, access state, and any content the app keeps on-device.

Account data, push-notification tokens, the Apple refresh token described above, and the mailing-list contact record are processed by Supabase. Analytics data is processed through PostHog Cloud in the United States / the EU. Subscription and entitlement data is processed by RevenueCat and Apple, and paywall presentation data by Superwall. Crash and error reports are processed by Sentry in the United States / the EU. Email is delivered by Resend. This website is served by Cloudflare.

4. When We Share Information

We disclose information only as needed to operate the Service with the following categories of recipients:

  • Apple — Sign in with Apple, App Store purchases and subscriptions, Apple Push Notification service, and Apple Ads, which receives the attribution token described in the Privacy Policy and returns the campaign that produced an install;
  • Supabase — authentication, account deletion, push-notification token storage, the mailing-list contact record, the waitlist, and the server functions that exchange the Apple attribution token and revoke the Sign in with Apple grant;
  • PostHog — product, interaction, and lifecycle analytics used to understand and improve LoveInk;
  • Sentry — crash reports and error diagnostics;
  • RevenueCat — purchases, subscriptions, entitlements, restore, and subscription management;
  • Superwall — deciding which paywall to show, drawing it, and measuring how paywalls perform;
  • AppsFlyer — measuring which advertising outside the App Store produced an install and a subscription, using an installation identifier and, only if you allow it, Apple’s Identifier for Advertisers;
  • Resend — email delivery, including delivery and unsubscribe status, for the emails described in the Privacy Policy;
  • Cloudflare — serving this website and the cookieless visit counting described in the Privacy Policy.

These providers process information under their own terms and privacy policies. We may also disclose information if required by law or when reasonably necessary to protect the rights, safety, and security of users, the Service, or others.

We do not sell personal information and we show you no advertising inside LoveInk. What we do is measure our own advertising: the campaign identifiers described above tell us which of the ads we paid for produced an install, and, where you have allowed it, Apple’s Identifier for Advertisers lets an ad shown in another company’s app be matched to that install. That identifier is used for attributing and measuring our own advertising, and is not used to build a profile of you or to target advertising at you. Because iOS classes it as tracking, we ask for it with the App Tracking Transparency prompt, and declining loses nothing but the match.

5. Permissions and Your Choices

Notification permission is controlled through Apple’s permission and device-settings interfaces. You may decline it when asked, or turn it off later in iOS Settings; the rest of the Service works without it.

Tracking permission — the App Tracking Transparency prompt shown once during onboarding — is controlled the same way, under Privacy & Security → Tracking in iOS Settings, and you may change your answer there at any time. Declining means no advertising identifier is collected and changes nothing else about the Service.

You may delete your LoveInk account from Settings. Account deletion revokes LoveInk’s Sign in with Apple authorization, deletes the Supabase authentication user and the records attached to it, and then removes LoveInk’s device-local account data from that device. Deleting your LoveInk account does not cancel an App Store subscription; subscriptions must be managed through Apple or the subscription-management interface provided in the app.

You may stop receiving emails about LoveInk at any time by using the unsubscribe link in any such message, or by emailing us at the address below. This applies equally to a waitlist address, which you may have removed on request even though it is attached to no account. Unsubscribing removes you from the mailing list only; it does not delete your account, and we may still contact you about your account, a purchase, or a security matter where that is necessary.

LoveInk currently does not provide an in-app data-export tool or an analytics opt-out setting. You may ask to access, correct, delete, or restrict our use of your personal information, or object to its processing, by emailing hello@loveink.app. We may need to verify your identity before completing a request. These choices do not limit rights that cannot lawfully be limited.

6. Retention

Device-local information is generally retained until you delete it through the relevant feature, sign out, delete your account, or remove the app, subject to device backups and operating-system behavior outside our control.

Supabase account data, including push-notification tokens and the mailing-list contact record, is retained while your LoveInk account remains active and is deleted when you delete the account. A waitlist address is kept until the release announcement has been sent, or until you ask us to remove it, whichever comes first. If you unsubscribe without deleting your account, we keep a record that you unsubscribed, because that is what stops us mailing you again. Limited copies may remain temporarily in provider backups or security logs under the provider’s standard retention practices. Analytics is retained for N months and is then deleted or aggregated. Crash reports are retained for N days. Cloudflare’s website analytics is aggregate from the start and is kept under Cloudflare’s own retention schedule; there is no record in it that identifies you. Subscription, transaction, security-log, and provider records may be retained for the periods required by Apple, RevenueCat, Superwall, Supabase, PostHog, applicable law, fraud prevention, or dispute resolution.

7. Security

We use technical measures visible in the Service’s implementation, including HTTPS connections for every remote endpoint used by LoveInk, authenticated bearer tokens for protected requests, caller authentication before server-side account deletion, and encryption at rest for the Apple token held on our backend. Authentication sessions are stored in the app’s local storage; the current application code does not add a separate encryption layer to that storage. No method of storage or transmission is completely secure.

8. Children

LoveInk is not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided information to us, contact hello@loveink.app.

9. International Processing and Legal Bases

LoveInk is operated from [country]. Our service providers may process information in the United States and other countries where they operate. Those countries may have data-protection laws different from the laws where you live. Where applicable law requires it, we rely on contractual or other recognized safeguards for international transfers.

Where a legal basis is required, we process information as necessary to provide the Service and perform our agreement with you; to comply with legal obligations; with your consent when requested for device permissions or the waitlist; and for our legitimate interests in securing, maintaining, and improving LoveInk, provided those interests are not overridden by your rights.

10. Changes to This Policy

We may update this Privacy Policy when our practices or the Service change. We will post the updated policy and change the effective date above. If applicable law requires additional notice or consent for a material change, we will provide it.

11. Contact

Roman Gurov
Street address
City, postal code
Country
Email: hello@loveink.app

© 2026 Roman Gurov
HomeTerms of ServiceSupport