Privacy Policy
Last updated 14 August 2026
Always is built for two people, and we collect the least we can get away with: an Apple account identifier and an email address so you can sign in, a nickname and birth date you choose, and whatever you and your partner send each other. Everything travels over an encrypted connection (TLS). Your messages, drawings and photos are stored on our servers and are not end-to-end encrypted today — technically we could open them; in practice we don't, except in the narrow cases described below. End-to-end encryption is on our roadmap, and this page will say so plainly the day it ships.
We do not sell your data. We do not show ads. We do not track you across other apps or websites, and we don't collect Apple's advertising identifier (IDFA).
1. Who we are
Always is an independent iOS app built and operated by Nikolai Portnov, a solo developer. For the purposes of the GDPR, the operator is the data controller. There is no dedicated data protection officer — writing to support@alwaysapp.cc reaches the person who built the app and runs the servers.
2. What we collect, and why
| Data | Why we have it |
|---|---|
| Apple account identifier and email address, from Sign in with Apple | To create and recognise your account, and to reach you about your account or a support request. If you chose Apple's Hide My Email, we only ever see the private relay address. |
| Nickname, birth date and profile photo you enter in the app | Your nickname and profile photo are shown to your partner. Your birth date confirms you meet our minimum age and lets the app mark your birthday. |
| An Apple sign-in refresh token, issued by Apple when you sign in | We store this single Apple-issued credential so that when you delete your account we can tell Apple to revoke the app's access on your behalf. It is not a password and it does not let us read your Apple account. |
| A push notification device token, if your device provides one | To deliver notifications to your device. (Remote push is still rolling out; the token may be stored before the feature is switched on.) |
| Pairing and referral data — invite codes, the link between two accounts, and, if you arrived through a referral or a campaign, a referral code, who referred you, a campaign/attribution tag and an A/B test group | To connect you with exactly one partner, to route content to the right couple, to credit whoever invited you, and to understand which channels bring people to Always. The referral relationship between two accounts is also kept in a separate referrals record. |
| Content you create — messages, canvas drawings, photos you send, and answers to questions | To deliver it to your partner and to keep your shared history in sync across devices. It is stored on our servers so it survives reinstalling the app. |
| Game and streak data — your Word Guess rounds, guesses and results, and your couple's connection streak and last-interaction dates | To run the games, sync them between the two of you, and keep your streak and milestones accurate. |
| A device identifier plus your couple id, on analytics events — the device identifier is a random ID generated on your device the first time you open the app; some events also carry the identifier of your couple | To count how features are used (screens opened, games finished, crashes) and how couples engage over time. Because a couple id is attached, this analytics data is pseudonymous, not fully anonymous — it is not the IDFA, it is never sold or shared with advertisers, and it is not joined to data from other companies. |
| Purchase history and identifiers, if you buy Always+ — the product, purchase, renewal and expiry dates, whether it is a trial, the store environment, and Apple's original-transaction and transaction identifiers | To unlock the features you paid for, keep your subscription status current, and handle support questions about a purchase. The original-transaction identifier is a persistent identifier tied to your Apple ID. Apple processes the payment; we never see or store your card details. |
| Abuse reports — if you use Report & unpair, the identifiers of the reporter and the reported person, the couple involved, and any free-text reason you write | To keep people safe and to act on abuse. These reports are retained even after the couple is dissolved and the accounts are gone — deliberately, so that a pattern of abuse can be acted on. See section 7. |
| Basic technical logs — IP address, timestamps, app version, error traces | To keep the service running, debug failures and stop abuse. Kept briefly and not used to profile you. |
What we do not collect
- No advertising identifier (IDFA), so the app never shows the App Tracking Transparency prompt.
- No contacts, no calendar, no location, no microphone, no health data.
- No third-party advertising or attribution SDKs.
- No card numbers or payment details. If you subscribe to Always+, Apple processes the payment and we only receive the subscription status attached to your account.
3. Analytics
We record a small stream of product events — things like "opened Thumb Kiss", "finished a game", "sync failed" — tagged with the device identifier described above, and on some events the identifier of your couple. Because a couple id is attached, this data is pseudonymous rather than fully anonymous: we don't attach your name or email to it, but it is not untraceable. This goes to our own backend, and in builds of the app distributed through the App Store it is mirrored to Firebase Analytics, a Google service. Firebase also collects standard technical attributes such as device model, OS version and coarse country. We do not enable Google Signals, ad personalisation or audience export, and no analytics data is sold or shared with data brokers.
If you would rather we collected nothing at all, email support@alwaysapp.cc and we will exclude your device. An in-app toggle is on the roadmap.
4. Where your data is stored
Our servers and database run on Google Cloud in the us-central1 region, in the United States. Disks are encrypted at rest by the cloud provider, and connections between the app and our servers use TLS. If you are in the EEA, the UK or Switzerland, this means your data is transferred to the United States; we rely on the European Commission's Standard Contractual Clauses as incorporated into our cloud provider's terms.
5. Who we share it with
Your content is shared with exactly one person: the partner you paired with. Beyond that, we use a short list of service providers who process data on our behalf and are not permitted to use it for their own purposes:
- Apple — Sign in with Apple, App Store distribution, and payment processing for Always+ subscriptions.
- Google Cloud — hosting, database and storage.
- Google Firebase Analytics — pseudonymous product analytics in App Store builds.
- Google Analytics, Google Sheets and Apps Script — used only on this website, for visitor counts and the waitlist form.
We will also disclose data if we are legally required to — a valid court order or law-enforcement demand — and we will tell you unless we are legally barred from doing so. We never sell personal information, and we do not "share" it for cross-context behavioural advertising as those terms are defined by California law.
6. Security
Connections are encrypted in transit with TLS. Sign in with Apple means we never handle a password. Access to stored content is checked on every request, so only the two members of a couple can read it. The full and honest picture — including what we have not built yet — is on our Security page.
To be clear about encryption: your content is encrypted in transit, and the disks it sits on are encrypted at rest. It is not end-to-end encrypted, which means we hold it in a form we could technically read. We access content only to investigate an abuse report, to fix a bug you have asked us to fix, or where the law compels us. We never read it out of curiosity and we never mine it for advertising.
7. How long we keep it
- Your account and profile — until you delete your account.
- Messages, drawings and photos — until you or your partner delete them, or until the account is deleted.
- Analytics events — up to 14 months, then deleted or aggregated beyond recognition.
- Technical logs — around 30 days.
- Subscription records — kept while your subscription is active and afterwards for as long as accounting and tax law requires.
- Abuse reports — kept after a couple is dissolved and even after the accounts involved are deleted, for as long as we need them to keep people safe and to meet our legal obligations. They are stored separately from your account so that deleting your account does not erase a report made about conduct.
- Backups — encrypted backups roll over within 30 days, so deleted data disappears from backups within that window.
8. Deleting your account
Settings → Delete account, inside the app. No email, no waiting on us. When you confirm:
- Your account and profile are removed from our live systems.
- The shared content that belongs to your couple is deleted for both of you. Because messages, drawings, photos and game history are jointly held by the two of you rather than owned separately, deleting your account removes that shared history from your partner's side too. If you want to keep any of it, save it before you delete.
- Your Sign in with Apple link is revoked, so the app no longer has access to your Apple account.
- Backups age out within 30 days.
- Anything your partner already downloaded onto their phone stays on their phone — we cannot reach into someone else's device. The same is true in reverse.
- An abuse report made about conduct is kept (see section 7); deleting your account does not erase a report.
Deleting the app without deleting your account leaves your data with us; use the in-app action if you want it gone.
9. Your rights
Wherever you live, you can ask us to show you what we hold, correct it, delete it, or send it to you in a portable form. Most of it you can do yourself: edit your profile in the app, delete messages, delete your account. For anything else — including a copy of your data, which we currently assemble by hand — email support@alwaysapp.cc and we will respond within 30 days.
If you are in the EEA or the UK, you also have the right to object to or restrict processing and to complain to your local supervisory authority. Our legal bases are: performance of a contract (running your account and delivering your content), legitimate interests (keeping the service secure and understanding how it is used, in a way that does not identify you), and consent where the law requires it.
If you are in California, you have the right to know, delete, correct and to opt out of sale or sharing — and we do not sell or share, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights.
10. Children
Always is rated 17+ and is intended for adults. Some of its content — the Desire & Romance questions in particular — is mildly suggestive, which is why the rating is 17+ rather than lower. It is not directed at children, and we do not knowingly collect data from anyone under 13. If you believe someone under 13 has created an account, write to support@alwaysapp.cc and we will delete it.
11. This website
alwaysapp.cc uses Google Analytics to count visits. If you join the waitlist, your email address and the time you submitted it are stored in a Google Sheet and used only to tell you when Always launches. Reply to any message from us, or write to support, and we will remove you.
12. Changes
If this policy changes in a way that matters, we will update the date at the top and, for material changes, tell you in the app or by email before the change takes effect.
13. Contact
Questions, requests, complaints: support@alwaysapp.cc. A real person reads it.