The short version: LoveClock keeps your relationship to yourself. Used solo, everything you enter stays on your device and nothing is sent anywhere. If you choose to pair with your partner, the data you share is end-to-end encrypted on your phone before it leaves, and our server only ever stores scrambled data it cannot read. There is no account, no analytics, no advertising, no tracking, and no location access.
Using LoveClock solo (the default)
LoveClock works fully without pairing. Your relationship start date, an optional wedding date, milestones, reunion countdowns, plans, the moments in Our Story, and your theme preferences are stored locally on your iPhone or iPad using Apple's on-device storage. In solo use the app does not contact our server and nothing you enter leaves your device.
Pairing with your partner (optional)
You can optionally pair with one partner using a short code or invite link. Pairing is built so that we cannot read what you share:
- The pairing code never leaves your phones. The one exception is the optional iCloud backup, which also keeps it in your personal iCloud Keychain, and Apple end-to-end encrypts that, so we cannot read it either. The encryption key is derived from the code on your devices, and our server only ever sees a one-way fingerprint of the code used as a room address.
- Everything you sync (dates, milestones, reunions, plans) is encrypted on your device before upload. The server stores only this ciphertext and has no way to decrypt it.
- There are no accounts. Your devices authenticate with a random per-device secret; we never ask for a name, email address, or phone number.
What our server stores when you pair
When (and only when) you pair, our server holds these kinds of data:
- A room record: the hashed room address, hashed device credentials, and a version counter. No readable content.
- Your encrypted records: the end-to-end encrypted data described above, kept for up to 400 days after the last update. A room that is created but never joined is deleted after 15 minutes.
- A push token: your device's Apple push notification token, used only to deliver sync updates and nudges, kept for up to 90 days. This is the only piece of server-side data that is not encrypted, because Apple needs it in readable form to route notifications.
- Encrypted snap photos (in transit): a snap you send is encrypted on your device with a fresh one-time key before upload, and the key itself only ever travels inside your end-to-end encrypted records, so the photo blob on our server is unreadable to us. Blobs are deleted automatically within about a day, and the one-time key is destroyed on your devices when the snap fades, which makes any remaining ciphertext permanently meaningless. Both halves matter: brief unreadable storage on our side, key erasure on yours.
- Encrypted voice notes (in transit): a voice note works exactly the same way as a snap: encrypted on your device with its own one-time key, unreadable to us on the way through, deleted from our side within about a day, and made permanently meaningless when the key is erased on yours. The audio is only ever unscrambled in your phone's memory and is never written to your phone's storage unless you deliberately keep it.
Unpairing removes your device from the room, and the retention windows above age the rest out automatically.
Notifications and nudges
Anniversary and milestone reminders are scheduled locally on your device by iOS, with no server involved. When you are paired, sync updates arrive as silent pushes, and a partner's nudge shows a fixed, generic banner. The optional note attached to a nudge is end-to-end encrypted like everything else and is shown transiently on your partner's screen rather than stored. A snap photo behaves the same way: it is shown for about 20 minutes after your partner opens it and is then erased, unless they deliberately choose to keep it. If they keep a snap you sent, you are told, and a kept snap stays on their phone and can be saved elsewhere from there. The one exception is a snap kept while reporting it to us: that save is silent, so that reporting something never announces itself to the person being reported. We cannot see snaps, and we cannot prevent a phone from taking a screenshot; the fading is a promise between the two of you, not a technical impossibility.
A voice note follows the same rules, with one difference worth stating plainly: its twenty minutes start when your partner plays it, not when it appears. A voice note sitting on screen tells them nothing, so it would be unfair to start the clock before they had a chance to listen. A voice note that is never played is erased automatically a day after it was sent. Voice notes never play by themselves, not from a notification and not on arrival, and we cannot hear them any more than we can see a snap.
What never syncs
Sharing is selective: reunions and plans you keep private stay on your phone even while paired. Your theme and animation preferences, your pinned widget choice, and your purchase receipts never leave your device. If you are paired, a single encrypted yes/no flag shares your Premium status with your partner so one subscription can cover you both; it reveals nothing else.
If you lose your devices
Because we never have your pairing code or encryption key, data on the server cannot be recovered by us. If you enabled the optional iCloud backup, a new or reinstalled device signed into your iCloud account can offer to restore your pair from your personal iCloud Keychain, a path that runs entirely between your devices and Apple. Without that backup, losing both phones means the encrypted data ages out unread. That is a deliberate trade: it is the property that keeps us unable to read your relationship.
The same is true of the photos, voice notes and notes you keep: they live on your phone and never reach our servers at all. You can optionally turn on iCloud backup — a single switch that covers both your pair and your content — which copies your dates, moments, plans and kept keepsakes into your own iCloud Drive. Every file is encrypted on your device first, with a key stored only in your iCloud Keychain, so the backup is unreadable to us and to Apple. Content your partner sent that you did not keep is never backed up. It stays as temporary as it was meant to be. Turning the backup off deletes it.
Service providers
The sync server runs on Cloudflare (Workers, KV, and Durable Objects), which stores the ciphertext and push tokens described above on our behalf. Notifications are delivered through the Apple Push Notification service. Neither receives readable relationship data from us.
No account required
You can use every feature, including pairing, without creating an account, signing in, or giving us an email address. There is no login wall.
No analytics, ads, or third-party tracking
LoveClock contains no advertising, no analytics or telemetry SDKs, and no third-party tracking frameworks. We do not build a profile of you and we do not share data with advertisers or data brokers.
No location tracking
LoveClock never requests or uses your location. Reunion countdowns are time-zone aware, but that is calculated on your device from the dates and zones you choose. We do not track where you or your partner are.
Children
LoveClock is intended for a general audience and does not knowingly collect any personal information from anyone, including children.
Changes to this policy
If this policy changes, we'll update this page and revise the date above. Continued use of the app after an update means you accept the revised policy.
Contact
Questions about your privacy? Email pawels.apps@gmail.com.