Heartdue
Privacy Policy
Effective [to complete]
Heartdue helps you keep track of bills, subscriptions, spending and budgets, and lets you share that picture with people you trust. Money details are personal, so this policy says plainly what we collect, why, and what you can do about it.
The short version
- We never ask for your bank login and can't move money.
- We don't sell your personal information, and there are no ads.
- People in your Trusted Circle see only what you choose to share.
- You can download your data or delete your account at any time.
1. Who we are
Heartdue is run by [to complete], based in [to complete] (“Heartdue”, “we”, “us”). We decide how your personal information is used, which makes us the “controller” under data protection laws such as the EU and UK GDPR and the UAE Personal Data Protection Law.
Contact us about privacy at [to complete], or by post at [to complete].
2. What we collect
Information you give us
- Account details: your name, email address and password. Passwords are handled by our authentication provider and stored only in hashed form. If you sign in with Google, we receive your name, email address and profile picture from Google, and nothing else.
- Financial information you enter: bills and subscriptions (names, amounts, due dates, categories, notes and support phone numbers), budgets, balances you type in, savings goals and everyday spending entries. For accounts, we store only the last 4 digits of an account or card number, never the full number.
- Receipts: if you scan a receipt, the photo is processed once to read the total, shop and date, and then discarded. Location information is removed from the photo on your device before it is uploaded.
- Trusted Circle: the email addresses of people you invite, the access level you give them, notes left on bills, offers of help, and a log of activity such as who viewed your dashboard.
- Feedback: messages you send us and, if you choose, an email address to reply to.
Information collected when you use Heartdue
- Phone payment logging (if you set it up): the amount, shop name, date and card name from payment notifications your phone sends us. Card numbers are removed before anything is saved. Each phone has its own key, which we store only as a one-way fingerprint.
- Notifications: if you turn on phone notifications, your browser gives us an encrypted delivery address and keys for that device, plus a device label such as “iPhone · Safari”. We also keep a record of which reminders have been sent, so none is sent twice.
- Calendar sync: if you create a calendar link, we store only a fingerprint of it and when a calendar app last used it.
- Payments: if you subscribe or support us, Stripe processes your payment. We receive your plan, subscription status, renewal date and a Stripe customer reference. We never see or store your full card number.
- AI assistant usage: a daily count of AI assistant requests per feature, to apply fair-use limits. We don’t keep your questions or the answers.
- Technical information: your IP address and basic request details, used briefly to keep the service secure (for example, to stop repeated failed attempts) and recorded in our hosting provider’s logs.
3. How we use it, and why we're allowed to
- To provide Heartdue: your account, bills, budgets, reminders, sharing with your circle, calendar links and exports. Legal basis: performing our contract with you.
- To take payments and manage plans, including renewals, failed payments, and the 7-day notice before paid features are put away after a downgrade (kept, not deleted, and returned as they were if you move back to a paid plan). Legal basis: contract; legal obligations such as tax records.
- To send reminders and notifications you have switched on: bill reminders, the weekly summary, overdue heads-ups and phone notifications. You can switch each one off in Settings or from the link in every email. Legal basis: contract, and your consent for phone notifications.
- To keep Heartdue and your information secure, prevent abuse, apply rate limits and investigate problems. Legal basis: our legitimate interests in running a safe service.
- To reply to you and improve Heartdue from the feedback you send. Legal basis: legitimate interests.
- To meet legal obligations and respond to lawful requests. Legal basis: legal obligation.
We do not use your information for advertising, and we do not make decisions about you that have legal or similarly significant effects based solely on automated processing.
4. The AI assistant
On the AI Advisor plan, Heartdue’s AI assistant answers questions using Google’s Gemini AI service. When you ask something, we send Google only what the answer needs, and only what you are allowed to see: for example bill names, amounts, dates and budget figures. We never send account numbers, email addresses, phone numbers, notes or people’s names.
We use Google’s paid Gemini API service, under which Google does not use your prompts or the answers to improve its products. Answers are labelled as AI-generated, can be wrong, and are not financial, legal or tax advice. Nothing changes in your account unless you choose to apply a suggestion.
On every plan with everyday spending, the same service also reads payment notifications your phone sends, and the names of shops, to log and file each payment. On the AI Advisor plan it also reads a promise you write, to work out what to watch in your spending. For these we send only that text, with anything that looks like a card or account number removed first, and never your other figures.
6. Where your information is processed
Our providers may process information in countries other than yours, including the United States. Where the law requires it, we rely on safeguards such as the providers’ data processing agreements and the European Commission’s Standard Contractual Clauses, and on the transfer conditions set by the UAE Personal Data Protection Law.
7. How long we keep it
- Your account and everything in it: until you delete your account. Deleting it removes your data from our live systems straight away; copies in routine database backups are overwritten within 30 days.
- Things put away when an account moves to the free plan (extra bills, profiles, budgets, spending, phones): kept out of sight until you move back to a paid plan, when they come back as they were, or until you delete your account. They are in your data download meanwhile.
- Receipt photos: not kept at all, only the details read from them.
- Records of which reminders were sent: about 120 days.
- Feedback: until it's no longer needed to respond or improve Heartdue, or until you delete your account if you were signed in.
- Payment records: Stripe and we keep what tax and accounting laws require, which can be several years, even after an account is deleted.
- Security logs at our hosting provider: a short period, set by that provider.
8. How we protect it
- Everything travels over HTTPS, and browsers are told never to use an unencrypted connection.
- Database rules decide who can read each record, so a person only ever receives what they're allowed to see.
- Sign-in sessions are kept in secure cookies that scripts on the page can't read.
- Phone keys and calendar links are stored only as fingerprints, and full card or account numbers are refused.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authorities where the law requires.
9. Your choices and rights
Depending on where you live, you have the right to:
- Access your information and take a copy: use Settings → Your data to download everything.
- Correct it: edit it directly in Heartdue.
- Delete it: Settings → Danger zone, or see Deleting your account.
- Object to or restrict some processing, and withdraw consent (for example, turn off notifications) at any time.
- Complain to your data protection authority, for example your EU supervisory authority, the UK Information Commissioner’s Office, or the UAE Data Office.
For anything you can’t do in the app, email [to complete]. We’ll respond within one month and may need to confirm your identity first. We won’t treat you differently for using your rights.
People in the United States: depending on your state, you may have rights to know, access, correct and delete your personal information, and to opt out of its sale or use for targeted advertising. We don’t sell it or use it for targeted advertising.
11. Age
Heartdue is for people aged 18 and over. We don’t knowingly collect information from anyone younger. If you believe a child has created an account, contact us and we’ll delete it.
12. Changes to this policy
If we make meaningful changes, we’ll tell you in the app or by email before they take effect, and update the date at the top. Earlier versions are available on request.
13. Contact
[to complete] · [to complete] · [to complete]