Legal

Privacy Policy

This Privacy Policy applies to Hearthly, a registered fictitious name of Dunn Studios LLC, a Florida limited liability company ("we," "us," "our").

Effective date: June 18, 2026 (last revised July 19, 2026)

Contact: legal@gethearthly.app · Mailing address: 6503 Welle Ct., Saint Cloud, FL 34771

The short version. Hearthly is a private care journal. We don't sell your information, we don't use your care notes for advertising, and we don't use your content to train anyone's AI models. This policy explains, in plain language, what we collect, how we use and share it, and the choices and rights you have.

1. Scope

This Privacy Policy covers gethearthly.app and the Hearthly web and mobile apps, operated by Dunn Studios LLC ("Hearthly," "we," "us"). Hearthly is intended for users in the United States, and your information is processed in the United States. By using Hearthly, you agree to this policy. If you don't agree, please don't use Hearthly.

2. Information We Collect

2.1 Information you give us

  • Account information: your name, email address, and password (or your Google sign-in, if you choose that).
  • Phone number: if you turn on SMS reminders, the mobile number you provide so we (through Twilio) can text your reminders. SMS is strictly opt-in. We do not share, sell, rent, or otherwise disclose your mobile phone number or SMS opt-in data to any third party for their own marketing purposes. We only share your number with Twilio, our SMS delivery provider, solely to send you the messages you have opted into. Message frequency varies by the categories you enable — typically 1–10 messages per month per category. Message and data rates may apply. Reply HELP for help or STOP at any time to cancel.
  • Profile and care details: your care role, the conditions you choose to journal about, your time zone, and city-level location — never precise GPS — used to show local weather and, if you enable pattern views or day outlooks, to note when harder days in your own logs have coincided with weather conditions (Section 6).
  • Journal content: daily notes, medication and dosage entries, allergy information, symptom and mood logs, sleep notes, appointment details, meals, Life Story answers, and photos you add. Some of this is health-related information about your loved one or yourself.
  • Care-circle information: the names and email addresses of people you invite, and the role you assign them.
  • Community and games: the alias you choose, the posts you make in support groups, and your game scores and leaderboard standing. Community and games use aliases, not your real name.
  • Payment information: handled directly by Stripe when you subscribe through our website, or by the Google Play Store or Apple App Store when you subscribe through those stores. We receive confirmation of payment and your subscription status; we never see or store your full card number, security code, or bank details. Purchases through an app store are also subject to that store's privacy practices.
  • Communications: messages you send us through email or support.

2.2 Information we collect automatically

  • Usage data: which features you use, actions you take, and session length — collected through our own internal tracking, not a third-party advertising or analytics network.
  • Device and log data: browser type and version, operating system, device type, screen size, IP address, referring URLs, and error logs.
  • Cookies and local storage: used to keep you signed in, remember your preferences, and understand how Hearthly is used. We do not use advertising cookies. See Section 12.

2.3 Information from third parties

  • Google: if you sign in with Google, we receive your name and email.
  • Withings: if you connect a Withings account, we receive the health measurements described in Section 7A.
  • Stripe: payment and subscription status.
  • Weather provider: we request local weather using your city-level setting.
  • Deezer: Music Moments use Deezer's public API for previews. We do not store a history of what you listen to.

2.4 California disclosures

California's Online Privacy Protection Act (CalOPPA) asks Hearthly to describe the categories of personal information it collects and the outside parties it shares that information with. Sections 2 and 8 provide that detail. The table below groups what Hearthly collects:

Category of personal informationWhat Hearthly collects in it
IdentifiersName, email, account credentials, IP address, and (if you opt into SMS) phone number
Commercial informationSubscription plan, payment confirmations, and transaction status (not card numbers)
Internet or network activityFeature usage, session length, device/browser details, and error logs
Geolocation (coarse)The city-level setting you choose — never precise GPS
Audio and visual informationVoice notes you record and photos or documents you upload or scan
Sensitive personal informationHealth-related journal content (medications, symptoms, moods, and similar) about you or your Loved One
InferencesThe patterns and day outlooks generated from your circle's own entries, if you enable those features

We collect these from you and your circle, from your devices, and from the third parties listed in Section 2.3, for the purposes in Section 3, and keep them for the periods in Section 9. We do not sell any of this information, and we do not track you across other companies' sites or apps for advertising.

3. How We Use Information

We use the information we collect to:

  • Create and manage your account and care circles;
  • Provide Hearthly — storing and showing your entries to you and the people you've authorized;
  • Generate the AI features you choose to use, such as summaries, pattern notes, provider-prep reports, and help chat (see Section 6);
  • Send reminders, notifications, and transactional emails (through Resend and SendGrid), and, if you opt in, SMS text reminders (through Twilio) and mobile push notifications (through OneSignal in our mobile apps, and Firebase Cloud Messaging for web push);
  • Process payments and manage subscriptions (through Stripe);
  • Provide support and respond to you;
  • Keep Hearthly working, fix bugs, and improve features using our own usage data;
  • Protect against fraud, abuse, and security problems; and
  • Meet our legal obligations.

We do not use your journal content or health-related notes to train AI models, to show you ads, or to build profiles of you for sale or outside marketing. We do not sell your personal information.

4. Health-Related Information

Much of what you record in Hearthly is health-related — medications, allergies, symptoms, moods, and so on. HIPAA does not apply to this information, because Hearthly is not a healthcare provider, a health plan, or a business associate of one. It is personal journal content, not a medical record. We still treat it with real care:

  • It is encrypted while moving over the internet (TLS) and while stored;
  • Access is limited to the people you invite and the small number of personnel and providers who need it to operate Hearthly;
  • We never share it with insurers, employers, pharmaceutical companies, marketers, or data brokers;
  • We don't analyze it for clinical or diagnostic purposes; and
  • We don't sell it.

In plain terms: HIPAA does not apply to Hearthly, but your health notes are still sensitive, so Hearthly treats them that way and uses them only to give you the service you asked for. Section 11 describes your choices.

5. Care Circles — Who Sees What

A care circle lets the people you invite view and add notes about one loved one. You decide who is in the circle and how much access each person has. The Circle Owner (the person who created the circle) always has full access, including managing members, access settings, and per-member feature settings. Each other Member is given a relationship label (Family, Extended Family, Friend, Helper, or Other), and the Owner sets their access along two independent controls: whether the Member can read and write or is read-only, and whether the Member sees the full dashboard or a simplified view. The Loved One may also be added, with whatever combination of those settings the circle chooses. The Owner can also turn individual features (like community or games) on or off per member. Care circles are for the family side of caregiving. A loved one's doctors, clinicians, and other healthcare providers are not circle members — you can keep them as saved care contacts instead.

You can change roles or remove members at any time in your settings. When you remove someone, they lose access going forward, though entries they already made remain part of the shared record unless you delete them.

Recording information about a loved one. Often the loved one is not the person using Hearthly, and — because of conditions like Alzheimer's or dementia — may not be able to give traditional consent. As explained in our Terms (Section 5), you are responsible for having the authority to record and share a loved one's information (for example, as the person themselves, a legal representative, or a family caregiver acting in their interest), and for honoring the loved one's wishes to the extent you know them. If a loved one asks that information about them be removed, you can delete it at any time.

If the Loved One joins Hearthly. A circle may invite the Loved One to hold their own account. When they do, they are a user in their own right: this policy applies to them directly, they hold their own access, export, and deletion rights over their account, and information they enter is their content. Their feature access within the circle is still managed by the Owner. Loved Ones with accounts must be adults — see Section 13.

6. AI Features and AI Providers

When you use Hearthly's AI features, here is exactly what happens to your information — in plain language.

6.1 What we send, to whom, and why

Hearthly's AI features run on a small set of providers. Some requests go directly to a model provider; most are routed through an AI gateway operated by Lovable, which passes your request to the model provider and returns the answer — the gateway is a service provider bound to use your data only to deliver the service to us.

FeatureWhat is sentWhere it goes
In-app help chatYour chat messages and, where relevant, recent entries needed to answerDirectly to Anthropic (Claude)
Written summaries — morning orientation, weekly story, life story, trends narratives, insights reports, reflection prompts, day outlooksThe relevant text from your circle's entriesThrough the Lovable AI gateway to Google (Gemini) or OpenAI models, depending on the feature
Search and pattern matching ("From your past logs," help search)Short passages of your notes, converted into "embeddings" — numerical representations we store privately in your accountThrough the Lovable AI gateway to OpenAI (embeddings model)
Label and document scanningThe photo you take of a pill bottle or medical document, for reading and pre-filling fieldsThrough the Lovable AI gateway to Google (Gemini vision)
Voice notesThe audio you record, for transcription into textThrough the Lovable AI gateway to OpenAI (transcription model)

These are our current providers and routes. We send only what a feature needs — never your whole account — and only when you actually use the feature. If we add or change an AI provider or route, we will update this table and note what changed.

6.2 What this means for you

  • AI content is generated only from what you and your circle entered, and is shown only inside your Hearthly account — never published or shared elsewhere by us.
  • Your content sent through these providers is not used to train their AI models: our direct agreement with Anthropic, and the terms governing the Lovable AI gateway and the model providers it routes to (Google and OpenAI), each provide that API content is not used for model training. These are commercial API terms set by those providers; if any provider's terms change in a way that affects this, we will update this policy and notify you of any material change as described in Section 15. Providers may briefly retain content as needed to deliver the service and for limited safety and abuse-prevention purposes, per their API terms.
  • We send only what a feature needs — not your entire account — and only when you actually use an AI feature.
  • You can turn AI features off in your settings. When they're off, your entries are not sent to AI providers for those features.

In plain terms: AI helps summarize and organize what you've already written. Your words briefly travel to Anthropic or Google to do that, then come back to you. They aren't used to train AI, and you can switch this off anytime.

6.3 AI-powered logging & insights

A few features inside the daily log and respite tools use AI to help you notice patterns in what you have already written. These are advisory only — they don't interpret health data, they aren't medical advice, and you can dismiss or ignore any of them.

  • Reflection suggestion (in the daily log). When you choose a mood, we ask our AI provider for one short, warm follow-up question (for example, "Did anything help her settle today?"). The question is generated from the mood you picked and recent context from your own logs. You can answer it, dismiss it, or ignore it.
  • Past-log pattern continuity (in the daily log). As you type a note, we look for similar moments in your own logs from the last 30 days for the same loved one and show up to three short snippets you can tap to re-read. To make matching work, we generate "embeddings" (numerical vectors) of your notes through our AI provider and store them privately in your account. These stored embeddings are treated as part of your account content: they are never used to train any AI model, and they are deleted together with the underlying notes when you delete the content or your account (see Section 9).
  • "What's helped you before" (in respite). When the app notices a heavier caregiving stretch, we look at your past respite and well-being entries and ask our AI provider to summarize the coping strategies you have already used. We don't suggest new behavior — we reflect your own back to you.
  • Appointment talking points (in respite). When you have an appointment in the next 7 days, you can ask Hearthly to organize the last 30 days of your own log entries into observations, questions, and changes you've noticed. The output is plain caregiver language ("I've noticed…"), never a diagnosis.

These features only use data from your own circle. Output stays inside your account. They route through our AI providers as described in Section 6.1, and you can turn AI features off in settings.

7. Google Calendar (optional)

If you connect Google Calendar, you authorize Hearthly through Google's secure sign-in (OAuth) to read your calendars and their events. We use this only to show upcoming appointments and a sense of the day's schedule within the Care Circle you choose.

  • You control which calendars feed which Circle. If you're in more than one Circle, you can attach different calendars to each, and disconnect a Circle individually without affecting the others or your Google account.
  • We fetch your events live and don't warehouse them. We store the secure connection and your per-Circle calendar choices — not copies of your calendar's contents.
  • What other members see is limited. Your events contribute to the Circle's shared schedule view, but the specific titles of your events are not shown to other members; they see a generic "Appointment" with the time.
  • Limited Use. Hearthly's use of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including its Limited Use requirements. We do not sell this data, use it for advertising, or use it to train AI models.

7A. Withings Health Devices (optional)

If you connect a Withings account, you authorize Hearthly through Withings' secure sign-in (OAuth) to receive health measurements from your loved one's Withings devices — currently blood pressure readings. We use this only to display those readings inside the care circle you connect, alongside the vitals your circle logs by hand.

  • You control the connection. You choose which circle the device data feeds, and you can disconnect at any time in your health settings. Disconnecting stops new readings; readings already saved remain part of the circle's record unless you delete them.

  • What we store. We store the readings themselves (for example, systolic/diastolic values, pulse, and the measurement time) and the secure connection. We do not receive your Withings account password.

  • How readings are used. Readings are shown to your circle like any other logged vital and are covered by the same protections as the rest of your journal content: we do not sell them, do not share them with insurers, employers, advertisers, or data brokers, and do not use them to train AI models. If you use AI features that summarize vitals, readings are handled exactly as described in Section 6.

  • Your use of Withings devices is also governed by Withings' own privacy policy.

In plain terms: If you link a Withings blood pressure cuff, its readings flow into your circle's record automatically so nobody has to type them in. You can unlink it anytime, and the readings get the same privacy protections as everything else you write in Hearthly.

8. How We Share Information

We share personal information only in these situations:

Service providers. We share what's needed with vendors who help run Hearthly. They may use it only to provide their service to us — not for their own purposes. Our key providers are:

ProviderWhat they help with
SupabaseDatabase, sign-in, and file/photo storage
CloudflareHosting and content delivery
StripePayment processing
ResendTransactional email delivery
SendGridEmail notifications (appointment reminders, trial expiration alerts, subscription receipts). When you receive an email from Hearthly, the message content is sent to SendGrid for delivery. SendGrid does not store the email content after it's sent.
TwilioSMS medication and appointment reminders. When you enable SMS notifications in settings, Hearthly sends your phone number and reminder text to Twilio, which delivers the message to your phone via SMS. Twilio does not store message content after delivery.
Firebase Cloud Messaging (Google FCM)Push notifications on mobile devices. When you enable push notifications, Hearthly sends notification text to Firebase, which delivers it to your phone's operating system. Firebase does not store notification content after delivery.
AnthropicAI help chat and related written responses (Section 6)
Lovable (AI gateway)Routes most AI requests (text, and the photos/audio described in Section 6) to Google and OpenAI models and returns the results. Acts only on our instructions.
OpenAIAI models reached through the gateway: embeddings for search/pattern matching and transcription of voice notes (Section 6)
Google / GeminiGoogle sign-in, optional Google Calendar (Section 7), push delivery (Firebase), and AI models reached through the gateway for written summaries, day outlooks, and photo/document scanning (Section 6)
GiphyGIF search and playback in circle messages. When you search for a GIF, your search words go to Giphy; chosen GIFs load from Giphy's servers. We restrict results to G-rated content.
SentryCrash and error monitoring, so we can find and fix failures. Error reports can include your device and browser details, IP address, and the screen where the error happened. We scrub identifiers such as share and invite tokens from these reports before they are sent, and error reports never include your journal content.
DeezerMusic preview search and playback
Open-MeteoLocal weather and air quality from your city-level setting

Legal reasons. We may disclose information if the law requires it (such as a valid subpoena or court order) or if we believe in good faith it's necessary to protect someone's safety, prevent fraud, or protect our legal rights. Where we're allowed to, we'll try to notify you first.

Business transfers, and what happens if we wind down. If Hearthly is ever sold, merged, or otherwise transfers its assets, your information may transfer as part of that deal. We'll notify you beforehand, and we'll require that your information stay subject to a policy at least as protective as this one. This applies even to an involuntary transfer in a bankruptcy or insolvency: because your care notes are sensitive, we will seek to bind any acquirer to protections at least as strong as this policy, and — to the extent the law and the circumstances allow — give you advance notice and a chance to export or delete your data before any transfer takes effect.

If instead we discontinue Hearthly without transferring it to anyone, we will give you notice and an export window as described in Section 16.4 of our Terms, and then delete user personal data on the schedule in Section 9 below, except records we must keep for legal, tax, or accounting reasons.

With your direction. We share in other ways only when you ask us to or clearly direct it — for example, when you invite someone to your circle, export a provider-prep report to hand to a clinician, or create a share link (such as the emergency info card). A share link is a web address containing a private token: anyone who has the link can open what it shows, without logging in, until it expires or you revoke it. Treat share links like the information they carry, and revoke any link you no longer want live (you can do this in the app).

We do not sell personal information, and we do not track you across other companies' sites or apps for advertising. We have no advertising network and no data-broker relationships.

9. How Long We Keep Information

We keep your account information and journal content while your account is active so it's there when you need it. If you delete your account, we delete your personal data within 30 days, with the exceptions described below.

Type of dataHow long we keep it
Account and journal contentWhile your account is active; deleted within 30 days of account deletion
Proof of your deletion requestKept only as long as the law requires, so we can show your request was received and honored
Email and SMS opt-out / suppression recordsKept permanently, so we never contact you again after you opt out
SMS consent records (TCPA)Kept only as long as the law requires as proof of consent and revocation
Payment and tax recordsUp to 7 years, as required for tax and accounting
Security audit logsKept only as long as the law and our security obligations require
BackupsAged out on our normal backup rotation after deletion
Anonymized / aggregated dataMay be kept indefinitely — it can no longer identify you
Data tied to a legal hold or disputeKept as long as needed to meet a legal obligation or resolve the matter

Deletion by role. How deletion works depends on who you are in a care circle:

  • Circle member (not the Owner). Your personal identity and your private-only content are deleted within 30 days. Entries you authored about the Loved One that are shared with the circle stay part of the circle's record, with your name removed and the author shown as "Former member," so the family's history isn't broken.
  • Loved One with their own account. Deleting your account removes your login and your personal account data. The care record the circle keeps about you is managed by the circle Owner — it is their journal about your care and stays with the circle. You can ask the Owner to remove specific information at any time, or contact support@gethearthly.app and we'll help.
  • Circle Owner. As the Owner, you have two options: (a) transfer ownership to another circle member (see the Ownership Transfer section of the Terms), or (b) request deletion of the entire circle. If you request circle deletion, all members are notified immediately, and there is a 14-day window during which any member can export their data and you can cancel the request. After the window closes, the Loved One's record and all of the circle's care data are permanently deleted. Member accounts themselves are not deleted by this — each member's account continues if they use Hearthly in other circles. No refunds are issued for the current billing period.

Two different things live in a shared circle, and your deletion right treats them differently:

  • Your personal information — your account, profile, credentials, private caregiver entries (like the quiet check-in and your respite journal), embeddings of your notes, and the entries you authored — is deleted on your request, subject to the legal exceptions above.
  • The circle's shared record — entries other members authored, and shared entries the circle continues to rely on — is retained for the remaining members. Where you authored a shared entry, we remove your name and authorship from it; the de-identified entry may remain part of the circle's record. Retaining the shared record is needed to keep providing the service the remaining members asked for, and those entries are also the other members' own records, which deleting your account does not erase.

If information about you appears in entries another member wrote, that content belongs to their journal; you may ask us to review specific entries at legal@gethearthly.app, and the circle Owner can remove them at any time.

Paused accounts (after a trial ends without conversion, or after a lapsed or canceled plan) keep their data — we don't delete it just because a plan ended. You can still sign in to view and export data, and you can delete it anytime.

If Hearthly winds down. If we discontinue the service, we'll give you notice and a window to export your data (Terms Section 16.4), then delete user personal data on the schedule above, except records we must retain for legal, tax, or accounting reasons or that transfer to an acquirer under a policy at least as protective as this one (Section 8).

10. Security

We use industry-standard safeguards, including encryption of data in transit (TLS) and at rest, authentication through Supabase, and access controls that limit who can reach personal data. No online service can promise perfect security, and we can't guarantee it. If a breach occurs that is reasonably likely to put your information at risk, we'll notify affected users and regulators as the law requires.

11. Your Choices and Rights

11.1 Choices everyone has

  • Access and update: you can view and edit your account information and entries in the app.
  • Export your data: request a copy of your journal data anytime at support@gethearthly.app; we respond within 30 days. Export works even on paused accounts.
  • Delete your account: from settings, from our public Account & Data Deletion page (no login required), or by emailing support@gethearthly.app. We delete your personal data within 30 days, subject to the exceptions in Section 9. If you own a Care Circle with other members, you can either transfer ownership to another member (see the Terms) or request deletion of the entire circle on a 14-day window during which any member can export their data and you can cancel. Section 9 explains how deletion treats your personal information, the circle's shared record, and the different roles (member, Loved One with an account, and Owner).
  • Turn off AI features: in settings, which stops your content from being sent to AI providers for those features.
  • Email preferences: you can opt out of non-essential emails; we'll still send essential account and transactional messages.

11.2 California residents (CalOPPA)

California's Online Privacy Protection Act (CalOPPA) applies to Hearthly regardless of size, and this policy makes the disclosures it requires. The broader California law, the CCPA as amended by the CPRA, applies only to businesses that meet its revenue and data-volume thresholds. Hearthly does not meet those thresholds and does not sell or share personal information for advertising, so the CCPA does not currently apply. Even so, Hearthly gives you these choices:

  • Know and access the personal information we collect, where it comes from, why we collect it, and who we share it with;
  • Correct inaccurate personal information;
  • Delete your personal information, subject to legal exceptions;
  • Sensitive information. Hearthly treats your health-related notes as especially sensitive and uses them only to provide the features you've asked for — storing and showing your journal to your circle, and, if you enable them, the AI summaries and pattern features described in Section 6, which reflect your own entries back to you. Hearthly does not use your health information to build advertising profiles, to make decisions about you for anyone else, or for any purpose outside the service; and
  • No sale or sharing to opt out of. Hearthly does not sell your personal information and does not track you across other companies' sites or apps for advertising. Because none of that happens, there is nothing for a sale or share opt-out to act on. Section 12 explains how Hearthly treats browser Do Not Track signals.

We won't discriminate against you for exercising these rights. To make a request, email legal@gethearthly.app with "California Privacy Request" in the subject line, use the in-app options in Settings → Privacy, or use our public Account & Data Deletion page (no login required). We may ask you to confirm details we already have on file so we know the request is really from you, and you may use an authorized agent. We respond as quickly as we can, and we aim to respond within 30 days.

"Shine the Light." We don't share personal information with third parties for their own direct marketing, so there's nothing to disclose under California Civil Code § 1798.83.

11.3 Other U.S. state privacy rights

If you live in a state with a comprehensive privacy law (for example, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, or Montana), you may have similar rights to access, correct, delete, and obtain a copy of your personal information, and to opt out of targeted advertising, the sale of personal information, or certain profiling — none of which we do. Like California's law, these statutes have size and data-volume thresholds that may not yet apply to a company at Hearthly's stage, but we aim to honor these rights regardless and will comply fully where the law applies. To make a request, contact legal@gethearthly.app; if we deny a request, you may appeal by replying to our response, and we'll explain any further appeal options available to you.

Florida residents. Florida has its own privacy law (the Florida Digital Bill of Rights). Its obligations apply only to businesses above revenue thresholds that a company at Hearthly's stage does not meet, so it likely does not yet apply to us; even so, we aim to honor the access, correction, deletion, and portability rights described above for Florida residents, and will comply fully if and when the law applies to us. To make a request, contact legal@gethearthly.app.

12. Cookies and Tracking

We use a small number of cookies and similar technologies: ones that are strictly necessary to keep you signed in and secure, and ones that remember your preferences and help us understand usage through our own internal tracking. We do not use advertising or cross-site tracking cookies, and we don't allow third-party ad networks on Hearthly. You can control cookies through your browser settings, though turning off necessary cookies may affect sign-in. Some browsers can send a Do Not Track signal. Because Hearthly does not track you across other companies' websites or apps and allows no advertising networks, Hearthly does not change how it behaves when it receives that signal, and there is no cross-site tracking for it to stop.

13. Children

Hearthly is for adults. Every account (including an account held by a Loved One who joins their own circle) requires the holder to be at least 18. Hearthly is not directed to children, and we do not knowingly collect personal information from anyone under 13 (the age set by the federal Children's Online Privacy Protection Act) or knowingly allow anyone under 18 to create or use an account. If Hearthly learns that a child under 13 gave personal information without verifiable parental consent, Hearthly deletes that information promptly. A parent or guardian may review the information Hearthly holds about their child and ask Hearthly to delete it, and Hearthly honors verified requests.

Minors in a care circle. A minor may appear in your records only as a subject of care or as someone mentioned in entries — never as an account holder. Under our Terms (Section 5.2), information about a minor may be entered only by the minor's parent or legal guardian, or with the parent or guardian's documented permission; the parent or guardian's decision to enter it is their consent to our processing of it as described in this policy. We do not build profiles of, advertise to, sell or share the personal information of, or track any minor described in a circle — we don't do those things for anyone. If you believe someone under 18 has created an account, or that information about a child was entered without a parent or guardian's authority, contact legal@gethearthly.app and we will address it promptly, including deleting an underage account and, at a verified parent or guardian's request, deleting information about their child.

14. Third-Party Links

Hearthly may link to other websites or services we don't control. This policy doesn't cover them, so please review their privacy policies.

15. Changes to This Policy

We may update this policy. If a change is material, we'll let you know by email or in-app notice at least 30 days before it takes effect. If you keep using Hearthly afterward, the updated policy applies.

16. Contact Us

Privacy questions, data requests, or concerns: legal@gethearthly.app. We aim to respond within 30 days (and within the timeframes required by applicable law for formal rights requests).

17. Beta Testing & First Circle Recognition

This section applies if you participate in the Hearthly closed beta or are designated a Hearthly First Circle member. It supplements — and does not replace — the rest of this policy.

17.1 Data we collect during beta

Alongside the data described elsewhere in this policy, during the beta period we may collect:

  • Account information you provide at signup (name, email, profile details).
  • Usage data — how you interact with the app, features used, session timing, device and platform information.
  • Feedback and bug reports you send us through the in-app form, email, or other channels.
  • Care-circle content you voluntarily enter for testing (notes, logs, reminders, and similar entries).

We use this information to improve Hearthly, fix bugs, understand which features are working, and produce aggregated, de-identified analytics. We do not use it to build a separate "First Circle member" profile of you, to treat you differently from other users post-launch, or to share with third parties for marketing or recruiting purposes (except as required by law or as otherwise disclosed in this policy).

17.2 Public recognition (Friends of Hearthly page)

If you are designated a Hearthly First Circle member, we may display your name and profile photo on a public Friends of Hearthly page to thank you for your contribution. This is optional and opt-in — you will be asked at the end of the beta whether you want to be publicly recognized, and you may decline and still receive every other First Circle member benefit. You can request removal from the public page at any time by emailing legal@gethearthly.app; we'll act on the request within 30 days.

17.3 In-app avatar identifier

First Circle members see a distinctive ring around their profile avatar inside the Hearthly app. It is visible to you, to people in your care circle, and to other users who can already see your profile in shared contexts. It stays inside Hearthly — it is not exported to third parties or shown on the public web unless you opt in to public recognition (Section 17.2).

17.4 Retention of beta data

  • Usage data from the beta is retained for up to 12 months for analytics, then de-identified or deleted.
  • Feedback and bug reports may be retained indefinitely so they continue to inform product development.
  • Care-circle content you entered during the beta is treated like any other account data — kept if you continue using Hearthly, exportable on request, and deleted when you delete your account (see Sections 9 and 11).
  • The First Circle member designation (name, photo, status) is retained while your account is active or until you ask us to remove it.

17.5 Your rights as a First Circle member

In addition to the rights described in Sections 10 and 11, you may:

  • Decline or withdraw consent for public recognition on the Friends of Hearthly page.
  • Ask us to discuss visibility of the in-app avatar identifier.
  • Request deletion of your beta usage data in line with applicable privacy laws.
  • Ask what information we hold about your participation by emailing legal@gethearthly.app.

Historical references in our internal records may persist where needed for legal or accounting reasons, but future public-facing displays will be removed on request.