Privacy Policy
Last updated: 16 August 2026
your.move (the "app") is a private messaging and game app for two consenting partners. This policy explains what we collect, why, and what we do not.
What we collect
- Account: there is no email, password, or social login. On first launch we create an anonymous account for you, handled by Supabase Auth. We do not ask for or store your name, email, or phone number to sign in.
- Couple link: a randomly generated game code that links your account to your partner's account. The code is also how you get back into your game on a new device — there is nothing else to remember.
- Profile fields: optional display name, sex, relationship type. You enter these; you can edit or remove them anytime.
- Message and wishlist text: stored on our servers end-to-end encrypted. Only you and your partner hold the keys. We cannot read message contents or wishlist items. When you set up a new device, the encryption key is transferred directly from your partner's device to yours, encrypted so that our servers never hold a key that could read your messages.
- Invite treat: the treat you pick or write when creating an invite, including any photo, video, or voice note attached to it, is encrypted before it reaches our servers. That encryption uses a key generated from the invite code itself rather than a device-only secret, because your partner needs to unlock it before they even have an account. It is a weaker guarantee than messages get: the key comes from data we already store, so we could derive it ourselves. We do not, as a matter of policy, but you should know it is possible.
- Custom card text: the title and flavour text you write for your own task or reward card in your deck is stored on our servers as plain text, not encrypted. We can read this text, and may look at it internally to understand what couples create and to improve the game. We never sell it, publish it, or hand it to advertisers, and there is no name or email on your account to attach it to.
- Gameplay metadata: to run the game we store some move data unencrypted — which card was played, its category, status, timestamps, and deadlines. This lets us deliver and display moves, but it is not the private text you write.
- Custom photos / videos / voice notes: once you are linked, if you attach media to a move or to a custom card, the file is encrypted on your device before upload with your couple's own key. We store the encrypted bytes; we cannot decrypt them.
- Push tokens: Apple / Google push tokens so we can deliver notifications. Notifications contain no message content — only a generic alert.
- Diagnostics and usage analytics: error logs, plus a breadcrumb trail of in-app actions — screens opened, a move sent, a purchase attempted — so we can fix bugs and see which features get used. Events carry categories, counts and yes/no flags: for example, that a move in the heat category was sent. Never your card text, message text, wishlist wording, or media. This runs through Google Analytics for Firebase, Singular (install attribution) and DonkeyCat's own telemetry, tied to a per-install identifier rather than your name or email. On iOS that identifier survives reinstalling the app.
What we do not collect
- We do not read your messages.
- We do not sell or share your data with advertisers.
- We never send your private content — messages, wishlist items, invite treats, custom card text, or your media — to any analytics or advertising service. Messages, wishlist items, invite treats, and media are encrypted before they leave your device, so we could not forward the originals even if we wanted to. Custom card text is simply never forwarded anywhere, by policy.
- We do not collect contacts, calendar, location, or microphone unless you explicitly attach media or a voice note.
Who has access
- You and your linked partner — full access to your shared content via the app.
- Our servers (hosted on Supabase) — store your data. Message, wishlist, and post-link media content is encrypted with a key we never hold; we cannot read it. Invite treats are encrypted too, but with a key we could derive ourselves, so we do not treat that as an absolute guarantee. Custom card text is stored as plain text and can be read by us.
- Apple / Google push services — receive the push token and a generic alert payload.
- Google (Firebase Analytics), Singular, and DonkeyCat's own telemetry — receive the categorical usage events and diagnostics described above, never your content.
- No one else.
Data retention
Your data lives until you delete it. You can delete individual moves and rewards from the app. You can also delete your entire account from Settings → Account; that wipes all your messages, moves, rewards, and profile data from our servers within 30 days.
Children
your.move is intended for users aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has signed up, contact yourmove@donkeycat.com.
Your rights
Under GDPR / CCPA you have the right to access, correct, or delete your data, and to request a copy. Email yourmove@donkeycat.com and we'll respond within 30 days.
Changes
If we change this policy materially we will surface a notice in the app and update the date above. Continued use after a change means you accept the updated policy.
Contact
Questions? yourmove@donkeycat.com.