Privacy Policy · Hersign: Relationship Decoder
Hersignby Creaeza

Hersign: Relationship Decoder

Privacy Policy

Last updated 24 September 2026

Hersign is a private relationship companion made by Creaeza. What you share with it is personal, so this policy explains in plain language what we collect, why, and the control you have.

The short version

  • Your journal, unsent letters, healing reasons, log notes and log screenshots are encrypted on your phone before they’re saved. We can’t read them.
  • We use what you log (events, moods, dates) to calculate your scores and patterns.
  • We never sell your data, show ads, or collect your contacts or location.
  • You can export everything or delete your account at any time in the app.

01Who we are

Hersign is provided by Creaeza ([Registered legal name, if different from Creaeza], [Registered address]), “we” or “us”. We are the controller of your personal data.

Contact: contact@creaeza.com

[If required: our UK/EU representative is … / our Data Protection Officer is …, or delete this line]

02What we collect

Account information

Your email address (and, with Google sign-in, the basic profile Google shares), a user ID, and the name you’d like us to call you (optional).

Profile and settings

Your year of birth (used only to confirm you’re 18 or over), your country and timezone (for local support lines and notification times), your stage and your preferences.

What you add in the app

  • Connections: a nickname only (never a phone number or social handle), a pronoun, and optional context you write
  • Logs: the type of event, when it happened, and your mood
  • Standards, reflections, check-ins, quiz results, challenges, healing progress and important dates
  • Partner Mode, if you use it: couple game answers, shared date ideas, check-ins and shared dates

End-to-end encrypted content

Journal entries (and their tags), unsent letters, healing “reasons”, log notes and log screenshots are encrypted on your device with a key only you hold, backed up by your recovery phrase. We store them but cannot read them. If you lose your phone and your recovery phrase, we can’t recover them.

Purchases

Subscription and purchase status from Google Play, through RevenueCat. We never see your card details.

Device information

A push-notification token, the app version and your phone’s operating system.

Safety signals

If the app’s safety check is triggered, we record only the type of trigger (for example “stalking” or “self-harm”) and where in the app it happened. We never record the words you wrote.

Optional analytics and crash reports

If you turn analytics on (it’s off by default in the UK and EEA), we collect app usage events such as “log created” or “paywall viewed”. They never include note text, names or journal content. If the app crashes, we may collect technical diagnostics with personal content removed.

What we don’t collect

Your contacts, your location, your advertising ID, or anyone else’s contact details. We don’t use third-party advertising or tracking tools.

03How we use it, and our legal bases

Under the UK GDPR and the EU GDPR, we rely on these legal bases:

PurposeLegal basis
Providing the app: your account, sync, scores, reminders, Partner ModePerformance of our contract with you
Processing information about your relationships, sex life and wellbeing, which is special category dataYour explicit consent, given when you sign up. You can withdraw it by deleting your account.
Safety features: noticing risk and showing support linesYour explicit consent. Where someone may be at risk, the vital interests of you or others.
Subscriptions and purchasesContract
Security, preventing abuse and fair-use limitsOur legitimate interests in keeping Hersign safe and available
Product analytics, only if you turn it onYour consent
Crash diagnosticsOur legitimate interests in fixing problems
Complying with the lawLegal obligation

We don’t make decisions about you that have legal or similarly significant effects using automated processing. Your scores and patterns are calculated from what you log. They’re there for you to consider, and you decide what to do.

04AI features

Hersign’s AI features, such as an AI coach, aren’t available yet, and no information is sent to an AI provider.

Before we turn any AI feature on, we’ll update this policy to explain what would be shared, with which provider and why, and we’ll tell you in the app first.

05Who we share it with

We use these service providers (processors). They handle data only on our instructions.

ProviderWhat forWhere
SupabaseDatabase, sign-in, file storage and server functions[Region, e.g. London, UK]
RevenueCatSubscription managementUnited States
Google (Play Billing, Firebase Cloud Messaging)Payments and push notificationsGlobal
Expo (EAS)Push notification delivery and app updatesUnited States
[Email provider, e.g. Resend]Sign-in emails[Region]
PostHog, only if analytics is onProduct analyticsEuropean Union
Sentry, if we enable crash reportingCrash reports[Region, or delete this row]

Partner Mode: if you link with a partner, they can see only your display name and what you both put in the shared space: couple game answers, shared date ideas, check-in results and shared dates. They never see your logs, journal or scores. Either of you can leave at any time, and leaving deletes the shared data.

We may disclose data if the law requires it, or to protect someone’s safety. If Hersign is sold or merged, your data would transfer under this policy and we would tell you first. We never sell your data.

06International transfers

Some providers process data outside the UK or EEA. Where they do, we rely on adequacy decisions, or on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, with extra safeguards where needed.

07How long we keep it

  • Your account data: while your account is active.
  • When you delete your account, everything is deleted from our live systems straight away. Backups are overwritten within 30 days.
  • Safety trigger records (the type only): deleted after 12 months, or sooner if you delete your account.
  • Usage counters for fair-use limits: 60 days.
  • Purchase records held by Google Play and RevenueCat follow their own retention rules.

08Security

  • All connections are encrypted (TLS), and our database is encrypted at rest.
  • Sensitive content is end-to-end encrypted with AES-256-GCM on your device.
  • Access controls make sure an account can reach only its own data.
  • In the app: a lock with PIN or fingerprint, auto-lock, a blank preview in recent apps, a Quick Exit, a disguised icon and discreet notifications.

No system is perfectly secure, but we work hard to protect your data, and we’ll tell you and the regulator about a breach where the law requires it.

09Your rights

You can:

  • access or export your data: Me → Your data → Export my data
  • correct it
  • delete it: Me → Your data → Delete account
  • restrict or object to processing
  • ask for portability
  • withdraw consent at any time: turn analytics off in the app’s settings, or delete your account to withdraw consent to processing sensitive data

Email contact@creaeza.com for anything you can’t do in the app. We’ll reply within one month.

If you’re unhappy with how we handle your data, you can complain to the UK Information Commissioner’s Office (ico.org.uk) or your local data protection authority.

Can’t get into the app? See how to delete your account without it.

10Age limit

Hersign is only for people aged 18 or over. If we learn that an account belongs to someone under 18, we delete it.

11Changes

We’ll update this page when things change, and tell you in the app before significant changes take effect.

12Contact

Creaeza · · contact@creaeza.com