Skip to content
Amorby

Privacy policy

Last updated: 27 September 2026

Amorby is a private album for two people in a relationship. This policy explains what the app stores, why, and what you can do about it. In short: your memories are end-to-end encrypted — we can’t read them, we don’t sell anything about you, and ads are never personalized.

Who is responsible

Amorby is made by Vít Stöckl, an individual developer in the Czech Republic (the “controller” under the EU General Data Protection Regulation, GDPR). Contact: hello@amorby.app.

What’s end-to-end encrypted

Your photos, letters, voice notes, experiences, chat messages, comments, event notes, bucket-list items and answers to the daily question are encrypted on your phone before they are uploaded. Only you and your partner hold the keys (protected by your recovery code). We — and our hosting providers — see only scrambled data and cannot read, scan or recover it. If you lose every device and your recovery code, this content can’t be restored by anyone, including us.

What we store that isn’t encrypted

To make the app work, some basic information is stored readable on our servers:

  • Your account: email address and sign-in method (email, Google or Apple).
  • Your display name, your birthday and your partner link (which two accounts share a space).
  • Your couple’s dates: “together since”, first date, next visit, and whether long-distance mode is on; your time zone if you use long-distance mode.
  • Technical details of your content: dates of entries, who added them, reactions (likes), and the days you opened the app (for the togetherness streak) — not what the content says.
  • A notification token for your device, so we can send you notifications you turned on.
  • Whether your couple has bought “Remove ads”.

Why: to provide the service you asked for (GDPR Art. 6(1)(b)). We don’t use this data for marketing, profiling or anything else.

Ads

The free version shows a small banner on some screens (never in chat, letters or while viewing a memory), served by Google AdMob. We only request non-personalized ads: they are not based on your interests or tracking across apps. Google may still use device information to show ads, limit how often you see them and prevent fraud. In the EU/EEA and UK you are asked for consent first, and you can change it any time in Settings. Google’s policy.

Purchases

“Remove ads” is bought through the App Store or Google Play; we never see your payment details. RevenueCat confirms the purchase using an anonymous account ID.

Crash reports

If the app crashes, a report about the error is sent to Sentry so it can be fixed (legitimate interest, GDPR Art. 6(1)(f)). Reports contain the technical error, device and app version — no names, email, IP address, content or what you typed.

Who processes data for us

  • Supabase — database, sign-in and encrypted file storage.
  • Vercel — hosting of the website and app server.
  • Google (Firebase Cloud Messaging, Google sign-in, AdMob) — notifications, sign-in, ads.
  • Apple (Sign in with Apple, push notifications, App Store) — sign-in, notifications, purchases.
  • RevenueCat — confirming purchases.
  • Sentry — crash reports.

Some of these companies are based in the United States. Transfers are covered by the EU–US Data Privacy Framework or the EU Standard Contractual Clauses. Remember that your memories reach them only in encrypted form.

How long we keep data

As long as you have an account. When you delete your account, your data is deleted from our database and storage straight away; backups roll over within 30 days. If a couple splits, each person can save a copy, and the shared space is then closed and deleted as described in the app.

Your rights

You can access, correct, export or delete your data, object to processing or ask us to restrict it. You can do most of this yourself in the app: Settings → Download everything saves a copy of everything, and Settings → Delete my account deletes it. You can also email hello@amorby.app — we reply within 30 days. You have the right to complain to the Czech data protection authority (Úřad pro ochranu osobních údajů, uoou.gov.cz) or the authority in your country.

Children

Amorby is not meant for anyone under 16, and we don’t knowingly collect data from children.

Changes

If we change this policy, we’ll update the date above, and tell you in the app if the change is important.

Contact: hello@amorby.app