Privacy Policy

Last updated: January 11, 2026

Introduction

Reasons Why ("we," "our," or "us") is operated by an individual developer based in the European Union. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (collectively, the "Service").

Reasons Why is a couples appreciation app that allows partners to send each other daily messages of appreciation, which appear on their home screen widget.

Information We Collect

Account Information

When you create an account, we collect:

  • Email address - Used for account authentication, partner invitations, and service communications
  • Name - Displayed to your partner and used in notifications
  • Password - Securely hashed and stored by our authentication provider; we never store or have access to your plaintext password

Messages and Content

When you use the Service, we collect:

  • Appreciation messages - The text content of messages you send to your partner (up to 500 characters)
  • Message timestamps - When messages are sent
  • Sender and receiver identifiers - To deliver messages to the correct recipient

Partner Connection Data

  • Partner relationship - We store the connection between you and your partner
  • Invite codes - 6-character codes used to connect partners, which automatically expire after 7 days

Device Information

  • Device token - Apple Push Notification service identifier, used solely to deliver notifications to your device
  • Timezone - Your device's timezone setting, used to send daily reminders at an appropriate local time

How We Use Your Information

We use the information we collect to:

  • Deliver appreciation messages between you and your partner
  • Send push notifications when your partner sends you a message
  • Send optional daily reminder notifications at noon your local time
  • Send partner invitation emails when you invite someone to connect
  • Authenticate your account and maintain security
  • Improve and optimize the Service

Legal Basis for Processing (GDPR)

Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:

  • Contractual necessity - Processing necessary to provide the Service you requested (delivering messages, maintaining your account)
  • Consent - For push notifications and optional email reminders, which you can disable at any time
  • Legitimate interests - For service improvement, security, and preventing abuse, balanced against your privacy rights

Third-Party Services

We use the following third-party services to operate our Service:

Supabase

Authentication and database hosting. Your data is stored in EU data centers.

Resend

Email delivery for partner invitations and service communications. Resend processes recipient email addresses and email content to deliver messages on our behalf. We use Resend's Ireland-based (EU) servers for data residency.

Apple Push Notification service (APNs)

Delivery of push notifications to iOS devices.

We do not sell your personal information to third parties.

Data Retention

  • Account data - Retained while your account is active
  • Messages - Retained as part of your shared message archive with your partner, for as long as your account exists
  • Invite codes - Automatically expire and are deleted after 7 days
  • Device tokens - Removed when you log out or unregister your device
  • Upon account deletion - All your data is permanently deleted, including your profile, messages, device tokens, and invite codes

Your Rights (GDPR)

Under the GDPR, you have the following rights regarding your personal data:

Note: As a small-scale individual operator, we are not required to appoint a Data Protection Officer under Article 37 of the GDPR. For all data protection inquiries, please contact us directly using the email address provided below.

  • Right of access - Request a copy of the personal data we hold about you
  • Right to rectification - Request correction of inaccurate personal data
  • Right to erasure - Request deletion of your personal data (you can delete your account directly in the app)
  • Right to data portability - Request a copy of your data in a portable format
  • Right to object - Object to processing based on legitimate interests
  • Right to withdraw consent - Withdraw consent for processing based on consent at any time

To exercise any of these rights, please contact us at privacy@notifs.reasonswhy.app. We will respond to your request without undue delay and within one month. For complex or numerous requests, we may extend this period by up to two additional months, in which case we will notify you of the extension and the reasons for the delay.

International Data Transfers

Your data is stored in the European Union through Supabase (EU data centers) and Resend (Ireland). Apple Push Notification service (APNs) is based in the United States. When data is transferred outside the EU, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.

Children's Privacy

The Service is not intended for users under 16 years of age, in accordance with GDPR requirements. We do not knowingly collect personal information from users under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@notifs.reasonswhy.app, and we will delete such information.

Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Secure password hashing (passwords are never stored in plaintext)
  • Row-Level Security (RLS) policies ensuring users can only access their own data
  • HTTPS encryption for all data in transit
  • Token-based authentication with secure session management

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top. We encourage you to review this Privacy Policy periodically.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

privacy@notifs.reasonswhy.app