What we collect
Account and security data
If you create an account, we keep your display name, email address, a one-way password hash, email verification and recovery records, and session records. A session can include a hashed token, expiry and revocation times, recent-use time, user-agent information, and an IP-address hash when one is stored. Request addresses are also read and hashed in memory for rate limiting. We do not store your plain-text password. When Google sign-in is connected, we store its account identifier and verified email. One-time email links store a hashed token and expire after 15 minutes; expired records are cleared when another link is requested.
Things you make and share
We store the content you choose to create, such as Love Drops, names, notes, memories, perspectives, rituals, date ideas, occasion titles and month/day dates, optional reminder preferences, Care Notes, responses, quiz answers, capsules, voice keepsakes, and personal websites with photos, captions, letters, optional song links, and short videos. These records include internal identifiers, authorship, and timestamps. Share records include a one-way token hash, open and response counts, and can include an expiry, view limit, notification time, or revocation time. A Love Drop recipient can leave a response without an account or name; the response itself is still stored.
If you add a gift password, we store a salted one-way hash, not the password itself. Unlock attempts are counted for rate limiting. A successful unlock stores a hashed session token and expiry in the database and an essential HttpOnly cookie on the recipient's device for up to 12 hours, shortened when the link expires. Revocation ends access even if that cookie remains. Gift passwords are not added to links, QR codes or WhatsApp messages.
Website opens and connected domains
Personal website creators can opt in to an aggregate open count. The recipient sees a notice when this is enabled. It counts page requests, including repeat opens and messaging previews; it is not a count of unique people and does not identify a visitor. Other unlimited private links do not expose read receipts. If you connect a domain, we store its hostname, ownership-verification records, provider connection status, and the published share it points to. Domain and hosting providers receive the technical information needed to connect and secure it.
Song embeds load only after the recipient chooses to play them. That action can send connection and device information to Spotify or YouTube. Template demo photographs are fictional AI-generated illustrations, not customer photos.
Private media
When private media storage is configured, the storage service receives the recording, image, or video bytes. The database keeps an object key, media type, byte size, checksum, status, and available dimensions or feature metadata. Signed upload and media viewing links are short-lived, but the stored object is not automatically deleted with an account today.
Keepsake requests
A keepsake request can include the chosen product, custom wording, colour, quantity, prices, quote and proof history, order status, rejection notes, and messages needed to arrange the request. Product-operation records can include an event name, account or order identifier, event properties, and time. The website does not currently collect card details or take payment. The current website records an empty delivery address when a quote is requested; an address may be collected separately only if a physical order is actually going ahead.
Essential browser data
Authentication uses secure cookies. Theme and motion preferences use local browser storage. The product does not include advertising cookies or a third-party behavioural tracking SDK.
The editor keeps a recovery copy of text in the current browser tab. Staged photos, video and recordings use tab-scoped browser storage and can be recovered for up to seven days before upload. Expired records are cleaned up when that storage is used again. Uploading begins only when you choose to save or share. Browser deletion, blocked storage or a different device can make a recovery copy unavailable. Signing out clears this tab's staged media.
Prepared digital checkout
Digital gifts are free for launch and live payments are disabled. The optional checkout infrastructure records the account and saved gift, provider order and payment identifiers, amount, currency, status, verification events and any branding entitlement when used in testing. Payment details are handled by Razorpay; we do not collect card numbers or UPI PINs. Payment records do not contain the gift text, gift password or private sharing link. These records are not part of the current couple-space export.
Why we use it
- To create your account, authenticate you, recover access, and protect the service.
- To save, render, and privately share the things you deliberately create.
- To operate a shared couple space after both people have joined it.
- To send account, response, or shared-space emails when email is configured.
- To prepare a keepsake quote, proof, and fulfilment only when you request one.
- To diagnose failures, prevent abuse, and record the product and order events described above.
We do not sell personal data, use private content for advertising, or train an AI model on your Love Drops, messages, voice notes, or shared-space content.
Current controls and export limits
The studio dashboard lets a signed-in account holder download the current couple-space export described below, leave their current couple, unpair both people from an active couple, and request account deletion. Leaving removes only your membership. Unpairing removes both active memberships and archives the couple, but does not delete either account or the shared history.
The dashboard also lets an account holder delete an entire Love Drop. That removes its database artifact, share records, and linked responses, so its links stop opening. The sharing panel also provides per-link expiry, view limits, and recall controls.
The current technical export is limited to your basic account record and current couple space. It includes the current couple status and title, both members' moments and perspectives, Care Notes and responses, rituals, date ideas, and memory capsules, with author identifiers. A sealed capsule's body stays hidden until its date.
That export does not include earlier couple spaces, ordinary Love Drops and other artifacts, share and response history, media files or metadata, sessions and security records, play sessions and answers, orders and proof records, product events, or privacy request history. The dashboard downloads this limited export as an unencrypted JSON file only while you have a current couple space. To ask what else is held or request a correction, use the general contact below. A request is not completed merely because an email was sent; wait for confirmation after identity is verified.
Retention and deletion
Account data and saved content remain while the service retains them. The data model can apply a share expiry of up to 365 days, a view limit, or a revocation time. New links default to the duration shown in the sharing dialog, with unlimited views. You can choose another duration, a view allowance, or access until recalled. A link with no expiry remains active until it is recalled, its gift is deleted, or another access control applies.
Requesting account deletion through the dashboard locks the account immediately, marks active memberships as left, revokes active sessions, and schedules the primary account row for purge after a 30-day recovery period. During that period, use the Restore account screen with the previous email and password, or choose the explicit undo-deletion option on email/Google sign-in when that service is connected. Restoration reactivates the account and creates a new session, but it does not reinstate memberships that were marked left. Once the recovery deadline passes, the account cannot be restored even if the purge job is late. The purge runs only when the production scheduler and its secret are correctly configured, so a delayed job delays anonymisation but does not extend the recovery period.
When that purge runs, it replaces the email in the primary account row with a tombstone, changes the display name to "Someone", clears the handle and avatar reference, deletes the sign-in credentials, email-verification records, password-reset records, email sign-in links for that address, your saved occasions, and session records, and marks the request complete. This is partial anonymisation, not complete erasure.
The current purge does not delete the internal account row or identifier, membership and privacy-request history, product events, orders and proof records, unshared drafts, shared content, media database records, or stored media objects. Shared and unshared material can therefore remain after an account purge, with authored shared records still linked to the tombstoned internal account. Provider logs and some registration, security, transaction, or dispute records can also remain where they are operationally or legally required. This page does not claim that account deletion removes all identifying data or all content.
A plan to contact accounts after 24 months of inactivity is not active. No automatic dormant-account deletion currently runs.
Security and processing location
The service uses access controls, hashed credentials and tokens, short-lived signed media links, rate limits, and transport encryption. No online service can promise perfect security. Notifications to people or authorities will be made where applicable law requires them; this sentence does not promise a broader notification right.
Hosting, database, private-media, and email providers may process data in India or in other countries where the configured providers operate. The repository does not establish their processing locations, contractual limits, or a compliance certification. Those facts must be verified against the production providers and their agreements.
This is an early service and backups are not yet guaranteed. Keep your own copy of any photograph, recording, or message that would be impossible to replace.
Contact and complaints
For a privacy request, correction, content complaint, or question, write to the current general mailbox at hello@willyoubemygirlfriend.in. Include the account email and enough detail to locate the relevant record, but do not send a password, reset token, or private-link token by email.
The verified legal name and postal address of the operator, and the name, designation, and contact details of the applicable Grievance Officer, have not yet been supplied for publication. They must be added before public launch or systematic paid commerce. This general mailbox is not represented as a complete statutory grievance disclosure, and no missing business detail has been invented. Applicable complaint deadlines are not reduced by this notice.
We will update this page when a data practice or material service provider category changes. The review date at the top shows the latest policy check.