Privacy Policy
Last updated: May 2026
1. Controller
The controller responsible for data processing is:
Maximilian Wardenbachc/o Online-Impressum #4456, Europaring 90, 53757 St. Augustin, Germany
max@drawn.love
2. What Data We Collect
Account & Profile
- Email address (used for login via one-time password)
- Display name (chosen by you)
- Profile avatar (optional, uploaded by you)
Content You Create
- Love notes: drawings and text messages you send to your partner
- Important dates you add to your profile
Technical Data
- Push notification tokens (to deliver notes to your device)
- Device platform (iOS or Android)
- App usage timestamps (e.g. when notes are sent or read)
Analytics Data
We collect product analytics data to understand how the app is used and to improve it. This includes:
- Your user ID and email address (to associate events with your account)
- Screen and navigation history (which screens you visit in the app)
- App lifecycle events (installs, opens, closes)
- Device metadata (operating system, app version, locale)
- Behavioral events: OTP requests, sign-ins, note sends, paywall views, subscription purchases (event type only — no payment details), couple pairing and unpairing, and logouts
- Feature flag evaluations (which variant of a feature you see)
This data is processed by PostHog — see Section 4 for details.
Payment Data
Subscription status and purchase history are managed by RevenueCat and the respective app store (Apple App Store / Google Play). We do not process or store payment card details.
Android Waitlist
If you join the Android waitlist at drawn.love/android, we collect your email address to notify you when the Android app is available on Google Play. Waitlist entries are stored in a Google Sheet operated by us. You can ask us to remove your address at any time via max@drawn.love.
3. How We Use Your Data
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing the app (account, notes, pairing) | Art. 6(1)(b): performance of a contract |
| Sending push notifications | Art. 6(1)(b): performance of a contract |
| Processing subscriptions | Art. 6(1)(b): performance of a contract |
| Product analytics (understanding how the app is used to improve it) | Art. 6(1)(f): legitimate interest |
| Android launch notification (waitlist) | Art. 6(1)(a): consent |
We do not use your data for advertising, profiling, or sale to third parties.
4. Third-Party Services
Supabase
We use Supabase (Supabase Inc., 970 Tresidder Memorial Hall, 450 Serra Mall, Stanford, CA 94305, USA) as our database and file storage provider. Your account data, notes, and media are stored on Supabase servers located in the EU (eu-west-1, Ireland). Supabase processes data under a Data Processing Agreement compliant with GDPR. See supabase.com/privacy.
RevenueCat
Subscription management is handled by RevenueCat, Inc. (633 Tasman Drive, Sunnyvale, CA 94085, USA). RevenueCat receives your app user ID and subscription event data. See revenuecat.com/privacy.
PostHog
We use PostHog (PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA) as our product analytics provider. We have configured PostHog to use its EU Cloud (hosted in Frankfurt, Germany), so your analytics data is processed and stored within the EU.
PostHog receives the analytics data listed in Section 2 above, including your user ID, email address, and behavioral events. The legal basis for this processing is Art. 6(1)(f) GDPR (legitimate interest in understanding and improving the app).
PostHog retains event data for up to 1 year. You can request deletion of your PostHog analytics data by contacting max@drawn.love — we will submit a person-deletion request to PostHog on your behalf within 30 days. See posthog.com/privacy.
Apple / Google
Push notifications are delivered via Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM). Only your notification token and the notification payload are transmitted.
5. Couple Pairing & Shared Data
drawn is a two-person app. When you pair with a partner, they can see notes you send and your display name and avatar. Your partner cannot access your email address or device information.
When a couple is dissolved (“break up” feature), both accounts are unlinked. Notes previously exchanged remain in the database but are no longer accessible through the app.
6. Data Retention
- Account data is retained for as long as your account exists.
- Notes and media are retained until you or your partner delete them, or until the couple is dissolved.
- Push tokens are deleted when you log out or uninstall the app.
- Analytics events (PostHog) are retained for up to 1 year.
- You can request deletion of all your data at any time (see Section 8).
7. Data Transfers Outside the EU
Supabase and PostHog (EU Cloud) store data within the EU — no international transfer applies to those services. RevenueCat and Apple/Google notification services are US-based. Transfers to the US are covered by Standard Contractual Clauses (SCCs) as provided by the respective processors.
8. Your Rights (GDPR)
As a data subject under GDPR you have the right to:
- Access: request a copy of the personal data we hold about you
- Rectification: correct inaccurate data
- Erasure: request deletion of your personal data (“right to be forgotten”)
- Restriction: request that we limit processing of your data
- Portability: receive your data in a machine-readable format
- Objection: object to processing based on legitimate interest
- Withdraw consent: where processing is based on consent, you can withdraw it at any time
To delete your account, use drawn.love/delete-account. For other requests, contact max@drawn.love.
You also have the right to lodge a complaint with a supervisory authority. In Germany, the competent authority is the state data protection commissioner of the state in which you reside.
9. Children
drawn is not intended for children under the age of 16. We do not knowingly collect data from children. If you believe a child has created an account, please contact us for immediate deletion.
10. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via the app or email. The date at the top of this page always reflects the latest revision.