Última atualização:
HourStory — Privacy Policy
Este documento legal está disponível apenas em inglês. Onde uma tradução normalmente se aplicaria neste site, prevalece a versão em inglês mostrada aqui.
HourStory is operated by Faizan Gillani ("we," "us," "our," "HourStory"). This document has two parts: a Privacy Policy — what we collect, why, and your rights — and a Terms of Service — the rules for using the app.
Both apply to the HourStory mobile application (iOS and Android) and any related services (collectively, the "App" or "Service"). By creating an account or using the App, you agree to both.
If you have questions at any point, email fyizannn@gmail.com.
1. Overview
HourStory is a private, two-person journal. It exists so you and one paired partner can capture small moments — a photo, a short video, a voice note, a few words — throughout the day, and see each other's day unfold hour by hour. There is no public feed, no stranger discovery, no algorithmic timeline, and no advertising.
We designed HourStory around a simple principle: collect as little as possible, share it with no one but the two of you, and never sell it. This policy explains exactly what that means in practice.
This policy is written to comply with the Apple App Store Review Guidelines, Google Play's Developer Program Policies (including the Data Safety and User Data Policy requirements), the EU/UK General Data Protection Regulation ("GDPR"/"UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the U.S. Children's Online Privacy Protection Act ("COPPA").
2. Information We Collect
a. Account information. When you sign up, we collect your name, email address, and a password. Your password is processed by Firebase Authentication and is never visible to us in plain text.
b. Your content. The photos, short videos, voice notes, text entries, and captions you create ("Snaps"), plus the messages, photos, videos, and voice notes you send in your shared chat thread with your paired partner ("Messages").
c. Partner-pairing data. A unique invite code generated for your account, and — once you pair — your partner's user ID (not their email or password), the date you paired, and (if applicable) when your shared free-trial period started.
d. Presence & device data. The approximate time you last opened the app ("last seen"), your device's UTC time-zone offset (so your partner's hourly timeline lines up correctly with your local time), and a device push-notification token (see Section 8).
e. Subscription status. Whether your account is on the free tier, a paid plan, or the honeymoon trial, and — if you subscribe — a subscription identifier from Apple/Google and RevenueCat used to verify your entitlement. We do not receive or store your credit card, debit card, or full payment details — those are collected and processed directly by Apple (App Store) or Google (Google Play) under their own privacy policies.
f. Biometric authentication (optional, on-device only). If you enable App Lock with Face ID, Touch ID, or your device passcode, authentication is handled entirely by your device's operating system. HourStory never receives, transmits, or stores your biometric data or facial/fingerprint templates — your device simply tells our app "yes" or "no."
g. Customer support communications. If you email us, we retain that correspondence to help you and to improve the app.
3. Information We Do Not Collect
To be equally explicit about what we deliberately avoid:
- No location or GPS data. We do not request or use your device's location.
- No location metadata in photos. EXIF location data embedded in photos is stripped before upload.
- No advertising identifiers. We do not collect IDFA (iOS), Android Advertising ID, or any identifier used for cross-app/cross-site advertising.
- No contacts, calendar, or other app data. HourStory does not request access to your address book, calendar, or other apps' data.
- No browsing history or web tracking.
- No health, financial, or government-ID data.
- No analytics or crash-reporting SDKs are currently integrated into the app, so no behavioral analytics profile is built from your usage.
4. How We Use Your Information
We use the information above only to:
- Create and secure your account, and let you sign in.
- Let you and your paired partner see each other's Snaps and Messages, and no one else's.
- Generate and validate invite codes so two people can pair.
- Show accurate hourly timestamps across time zones.
- Deliver push notifications about your partner's activity (new Snaps, reactions, messages).
- Process and validate your subscription/trial status.
- Respond to support requests.
- Maintain the security, integrity, and reliability of the Service (e.g., detecting abuse of the security rules that protect your data).
We do not use your content or account data to train third-party AI models, to build an advertising profile, or to sell or rent to data brokers.
5. Legal Bases for Processing (EEA/UK/Switzerland)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data under the following legal bases:
- Performance of a contract — to provide the core pairing, capture, and messaging features you signed up for.
- Consent — for optional features you affirmatively opt into, such as push notifications, App Lock, or starting the honeymoon trial.
- Legitimate interests — to secure the Service, prevent abuse, and maintain reliability, balanced against your rights.
- Legal obligation — where we must retain or disclose information to comply with law.
7. Third-Party Service Providers
We use the following service providers to operate HourStory. Each acts as a data processor on our behalf under its own security and privacy commitments — none of them are permitted to use your data for their own advertising purposes.
| Provider | Purpose | Data involved |
|---|---|---|
| Google Firebase (Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging) | Account sign-in, database, media storage, backend logic, push delivery | Account info, content, device push tokens |
| RevenueCat | Subscription/entitlement management | Subscription status, anonymized purchase/receipt identifiers |
| Apple App Store / Google Play Billing | Payment processing | Payment details (held entirely by Apple/Google, not by us) |
We do not use any advertising network, analytics-for-advertising SDK, or data broker.
8. Push Notifications
If you allow notifications, your device receives a push token which we store so we can notify you when your partner captures a Snap, reacts to one of yours, or sends a message. You can disable notifications at any time in your device settings; doing so stops future pushes and we remove the token when you sign out.
9. Data Retention
We retain your account information and content for as long as your account is active, so the core pairing and history features work as intended. If you delete your account, your data is deleted as described in Section 10. We may retain minimal information (such as an email address) where necessary to comply with legal obligations, resolve disputes, or enforce our agreements.
10. Deleting Your Data
You can permanently delete your account at any time from Settings → Delete Account. Deleting your account:
- Removes your shared chat thread with your partner (for both of you) and unpairs you from them.
- Permanently deletes every Snap you created, including its stored photo/video/voice media.
- Permanently deletes your profile document (name, email, invite code, subscription status, device tokens).
- Removes your Firebase Authentication record.
This action is immediate and cannot be undone. Your partner's own Snaps and profile are not affected, other than losing the pairing link and the shared chat history.
11. Data Security
We protect your data with:
- Encryption in transit (TLS) for all traffic between the app and our backend.
- Backend security rules that scope every read and write to the content's owner and, where applicable, their linked partner only — enforced at the database level, not just in the app's UI.
- Password-based re-authentication required before sensitive actions like account deletion.
- No storage of raw payment card data on our systems.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security, but we design every part of the system around minimizing what could ever be exposed.
12. International Data Transfers
Our infrastructure (Google Firebase / Google Cloud) may process and store data in the United States or other countries where Google operates data centers. Where required, such transfers rely on appropriate safeguards, such as standard contractual clauses, as implemented by our service providers.
13. Your Privacy Rights
Regardless of where you live, you may contact us at fyizannn@gmail.com to:
- Request a copy of the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data (or use in-app account deletion directly).
- Withdraw consent for optional features (e.g., notifications).
- Ask questions about how your data is handled.
We will respond within the time required by applicable law (generally within 30 days).
14. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose.
- Request deletion of your personal information.
- Correct inaccurate personal information.
- Opt out of the "sale" or "sharing" of personal information — we do not sell or share your personal information, so no opt-out action is necessary, but you may still submit a request for confirmation.
- Not receive discriminatory treatment for exercising your privacy rights.
We do not sell personal information as defined by the CCPA/CPRA, and have not done so in the preceding 12 months.
15. European Privacy Rights (GDPR/UK GDPR)
If you are in the EEA, UK, or Switzerland, you additionally have the right to:
- Access, rectify, or erase your personal data ("right to be forgotten").
- Restrict or object to certain processing.
- Data portability — receive your data in a structured, machine-readable format.
- Lodge a complaint with your local data protection supervisory authority.
16. Children's Privacy
HourStory is not directed at children and is not intended for use by anyone under 13 years old (the age threshold under COPPA). If you are in the EEA/UK and your country sets a higher age of digital consent (up to 16), you must have parental permission to use the Service. We do not knowingly collect personal information from children below the applicable minimum age. If we learn that we have, we will delete it promptly — contact us at fyizannn@gmail.com if you believe this has happened.
17. Tracking & Advertising
HourStory does not track you across other companies' apps or websites, does not use advertising identifiers, and does not serve third-party ads. Because we do not track users for advertising purposes, the App does not require an App Tracking Transparency (ATT) prompt on iOS.
18. Changes to This Privacy Policy
We may update this Privacy Policy as the app evolves. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app. Continued use of HourStory after an update means you accept the revised policy.
19. Privacy Contact
Questions, requests, or concerns about your privacy: fyizannn@gmail.com.