Privacy Policy

Last updated: September 27, 2026

PinkyBond, a product of Veronata, Inc. (“we,” “our,” or “us”), is committed to protecting your privacy and the privacy of your partner. This policy explains what data we collect, what we don't collect, and how what you share with your partner is protected with end-to-end encryption. We never sell your data, show you ads, or share it with data brokers.

1. We cannot read what you share with your partner

PinkyBond is built so that we cannot read, access, or decrypt the data that flows between PinkyBloom (her app) and PinkyBond (your app). We never hold the key. Everything the two apps send each other is encrypted on the phone using AES-256-GCM before transmission. Our server (the Blind Relay) holds the content of what you share — messages, check-ins, photos, voice notes, videos and files — only as encrypted blobs it cannot decrypt. The few things it can read, such as the call log, are listed in Section 2. The Coach, the AI in PinkyBond, works differently and is described in Section 7.

2. What Our Server Stores

Our Convex backend stores the following for each message or data snapshot:

  • Pairing ID: A SHA256 hash of sorted public keys. Not tied to any identity.
  • Ciphertext: Base64-encoded AES-256-GCM encrypted data we cannot read.
  • Message type: “chat” or “snapshot” (we know the type but not the content).
  • Sender role: “bloom” or “bond” (we know which app sent it).
  • Timestamp: When the message was sent.
  • Size: The length of the ciphertext.

Messages are deleted on delivery. A message stays on our server only until your partner's phone receives it, and is deleted as soon as it has. If that phone stays offline, the message is deleted after 30 days at most (some types, such as status snapshots and call-setup messages, much sooner). What remains after delivery is a small delivery record with no content — which message it was, and whether it was delivered or expired, and when — kept for 30 days so the sender's app can show that a message was not delivered.

Photos, voice notes, videos and files (up to 2 GB each) are encrypted on the phone with a fresh key for every file. That key travels only inside the encrypted message, so only your two phones have it. The encrypted file is stored with Cloudflare R2, our storage provider, and deleted as soon as your partner's phone has downloaded it — after 30 days at most. We keep the file's size and upload and download times for the same 30 days. If your partner's app has not been updated to a version that supports large files, files go the older way instead: up to 25 MB, encrypted with your pairing key, stored with Convex, and kept for 30 days even after they have been opened.

So that calls and notifications work, the server also keeps:

  • A call log: for each call between you, which of your two phones called, when it started, rang, was answered and ended, whether it was voice or video, whether it was answered, missed or declined, and how long it lasted. This is not end-to-end encrypted — the server reads it to tell a phone that was switched off about the calls it missed. It never contains any audio or video: calls are end-to-end encrypted between the two phones and are never recorded. The call log is kept for 90 days, deleted when you unpair, and never combined with analytics.
  • Notification tokens: the push-notification token Apple or Google issues to the app. We delete it the moment Apple or Google tells us it is dead, and otherwise after 270 days without being refreshed — the point at which the address has expired anyway. It used to be 30 days, which meant your partner could not reach you after a quiet month. Notifications sent by our server never carry the text of a message.
  • Presence: whether each app is currently online or typing, so your partner can see it.
  • A weekly byte count of the files your pairing sends, for a fair-use limit, deleted after five weeks.
  • Couple activity counts: for each pairing, daily counts with no content — how many messages, media, calls and call minutes, and AI chats and voice calls there were that day, and which of the two apps was active — kept under the pairing ID to understand how couples use the apps, together with a record of when the pairing was first seen and which kind of app build each side used. They are kept after you unpair, and contain no health data and no message content.

3. What We Do NOT Collect

  • Names, email addresses, or phone numbers — except a first name you choose to give the Coach, which is sent with your Coach requests and not stored (Section 7), and an email address you choose to give when you contact support (Section 11)
  • Her cycle, mood or health information in readable form — except, only if she allows it in PinkyBloom, the context described in Section 7 (her life stage, cycle phase, the mood and energy she shares, your forecast and when your rough days tend to cluster), which reaches the Coach in readable form with your requests and is not stored
  • Journal entries or recordings of your calls
  • A copy of your conversations with the Coach (see Section 7)
  • Location data or GPS coordinates for our own use — if you send her a place, or share your live location with her, those coordinates are end-to-end encrypted on your phone first. We relay them; we cannot read them. See Section 4. If you allow the app to use your location, the Coach receives your approximate location to answer (Section 7).
  • Advertising IDs or hardware device identifiers (the app creates its own random identifiers instead: an install ID, used for anonymous analytics and the Coach's usage limits, and a wallet ID for voice minutes — see Sections 7 and 8)
  • Browsing history

4. Encryption Details

Key exchange: Curve25519 ECDH. Public keys are exchanged in person by scanning a QR code, or remotely with a one-time pairing code that expires after 24 hours. Only public keys ever pass through our server, and it cannot derive your shared secret from them.

Encryption: AES-256-GCM with HKDF-SHA256 key derivation (salt: “PinkyBond-v1”).

Key storage: Shared secrets are stored in the iOS Keychain, protected by the device passcode, or in the Android Keystore, hardware-backed where available. The pairing keys never leave the device. If you turn on chat backup, the separate key that encrypts the backup is kept in your iCloud Keychain (or derived from a passphrase you choose) or in Android's Block Store (Section 12).

Nonce: 12 bytes, randomly generated per message to prevent pattern analysis.

5. Safety Mode

PinkyBloom includes a Safety Mode feature that sends synthetic (fake) data to PinkyBond when activated. This data is encrypted and transmitted through the same relay as real data, making it indistinguishable. Safety Mode is controlled entirely by the PinkyBloom user. The PinkyBond user is not notified when Safety Mode is active.

6. Payment

PinkyBond is free. Voice calls with the Coach are paid for with voice minutes, bought through Apple In-App Purchase or Google Play Billing; what we keep about those purchases is described in Section 7. We have never collected or stored payment details: purchases, including those made before 10 September 2026, when PinkyBond had a paid tier, are processed entirely by Apple or Google, and any subscription is managed and cancelled in your Apple Account settings or in Google Play.

7. The Coach (AI)

The Coach's answers are generated by a hosted AI service, not on your phone. Nothing described in this section is sent until you turn the Coach on and confirm that you are 18 or older. When you use the Coach, the app sends our server:

  • What you type to the Coach, with the recent turns of that conversation
  • In a voice call with the Coach, your voice, streamed live (see “Voice calls” below)
  • What you have told the app about yourself for the Coach (such as your first name, how long you have been together, whether you live together and what you want to work on)
  • Her context, only if she has allowed it in PinkyBloom (“Let his Coach use what I share”, off by default): her life stage, cycle phase, the mood and energy she shares, your forecast for the coming days and when your rough days tend to cluster. This goes, in readable form, to our AI model provider with your requests. Without her permission, none of her data and none of the Coach's earlier replies about her are sent — only your own messages
  • Your shared tasks, if you use them; any of her tasks that mention her health are replaced with “(private item)” before they are sent
  • Your approximate location, if you have allowed the app to use your location, and the events in a stretch of your calendar, only when you allow it for a request that needs it
  • A photo of a meal or a nutrition label you choose to add to the food log
  • Technical data: a random install identifier (used to apply usage limits), the app's language, your region, your phone's local date and time, the wallet identifier described below, and, if you are paired, a random pairing identifier used only to count how often couples use the Coach

The Coach never receives your chat with her, her messages or her health data beyond what is listed above.

Processing and retention. Requests pass through our server (hosted on Convex) to our AI model provider, Groq, Inc., with Zero Data Retention enabled on our account: it processes each request to produce the answer and does not keep it. Our server does not store or log what you send or what the Coach answers, and does not keep your photos. It keeps counts with no content, such as the number of requests per day. Your conversations with the Coach stay on your phone.

Voice calls. A voice call with the Coach streams your audio in real time through our voice service, LiveKit, Inc., which hosts the call. Your speech is transcribed by Deepgram, Inc. (through LiveKit), the reply is written by Groq, and it is spoken by X.AI Corp. (xAI) text-to-speech. These services process the call only to transcribe your speech, write the reply and speak it; the speech service turns the reply text into audio, and we do not use any of it for training. Calls are not recorded, and we do not store the audio or a transcript. The context described above (such as what you have told the app about yourself, and her context if she has allowed it) is passed to the call when it starts. The location, calendar events and tasks the app sends for a call are held with the call and deleted shortly after it ends, within about two hours.

Lookups. When you ask the Coach to search the web, find a place, check the weather or play music, our server sends the search, and your approximate location where the lookup needs it, to the service that answers it: Exa Labs, Inc. (web search), Google (Places), the Norwegian Meteorological Institute (weather) or StarSinger (music). A barcode you scan for the food log is looked up in Open Food Facts by our server, not by your phone. These lookups do not include your identifiers.

Voice minutes and purchases. The app creates a random wallet identifier, kept in the iOS Keychain or in the Android app's backed-up data, and attaches it to App Store or Google Play purchases of voice minutes. Under that identifier our server keeps your purchases (product, dates, renewal state and the store's transaction identifier), your minute balance, and a record of each voice call: when it started, how long it lasted, the minutes used and which lookups it used — never the audio or what was said. We do not link the wallet identifier to your name, email or store account. These records are kept to account for your minutes and for our financial records.

8. Analytics

To see which features help and to find problems, PinkyBond collects anonymous usage analytics. It is on by default, and you can turn it off at any time in the app's Settings; the app works the same either way. The iOS and Android versions collect the same analytics:

  • Interaction events: app opens, sessions and their length, screens viewed, and which features you used — never what you wrote, logged, or sent.
  • Feature health: the steps of pairing; whether notifications are allowed and arrive; whether an AI answer appeared and roughly how fast; and for calls, their type (audio or video), how they connected, how long they lasted, and how they ended.
  • Error codes: a short category code when something fails (for example, a message that could not be sent), and on iPhone the same kind of code when the app crashes or freezes: which kind of failure it was, and for a freeze roughly how long it lasted — never an error message, content, a stack trace, or a file path. We use no third-party crash-reporting service: the crash and freeze reports come from Apple's own diagnostics, which iOS shares with us only if you allow it in your iPhone's settings, and we keep one category code from each and delete the rest.
  • Context: a random install ID the app creates (not tied to your Apple or Google account, and never stored together with your pairing ID), app and system version, device model, the app's language, the region set on your device (never GPS, and never worked out from your IP address), and whether you are paired and roughly how long ago, in ranges such as “4–7 days”.

Analytics never include cycle, mood, or health information, check-ins, messages, or anything that identifies you or your partner. Events go to our own backend (hosted on Convex), which does not store IP addresses with them, and they are never sold, shared, or used for advertising or cross-app tracking. Individual events are deleted after 180 days; daily summaries per anonymous install are kept to measure long-term trends. Turning analytics off stops all further collection.

9. Data Deletion

PinkyBond has no accounts, so there is no account to delete. What there is to delete is the pairing, and you can do that at any time from Settings → Remove Partner. This permanently destroys the pairing, removes all locally stored data, and deletes what our server holds for your pairing ID: undelivered messages and files, delivery records, the call log and notification tokens. Removing the pairing does not delete the voice-call and purchase records kept under your wallet identifier (Section 7), which we keep to account for your minutes and for our financial records. It also does not delete the couple activity counts described in Section 2.

10. Law Enforcement Requests

If we receive a valid legal request, we can only provide what is described in Sections 2 and 7: encrypted messages and files that have not been delivered yet, which we cannot decrypt because we do not possess the keys; content-free delivery records from the last 30 days; the call log from the last 90 days, which shows when the two phones in a pairing called each other, for how long and with what outcome, but never what was said; and the voice-call and purchase records kept under a wallet identifier (Section 7); the couple activity counts (Section 2); and any support request you sent us (Section 11). We do not store the content of conversations with the Coach, so we cannot provide it. We will notify affected users of legal requests unless prohibited by law.

11. Support requests and feedback

If you contact us from the app's support form, we receive what you write, any screenshots you attach, the email address you give (optional), your anonymous install identifier, and the app version, system version and device model. In the iPhone app, if you answer “Not really” when the app asks whether you are enjoying it and tell us what we could do better, we receive what you write with the same identifier and technical details. Both are stored by our backend (hosted on Convex) and sent to our team by email through an email delivery service, so that we can answer and improve the app. They are used for nothing else, and are kept for about 90 days, then deleted.

12. Chat backup

Backing up your chat is optional and off until you turn it on. On iPhone, the backup is written to your own iCloud Drive, in the app's own container, and encrypted on your phone first with a key kept in your iCloud Keychain (or, if iCloud Keychain is off, derived from a passphrase you choose), so that a new iPhone signed in to your iCloud account can restore it. We never receive the backup or the key. On Android, the backup is written to your own Google Drive — not to us. It goes into the app's private app-data folder: PinkyBond asks Google for one narrow permission, drive.appdata, which cannot see any other file in your Drive — not your documents, not your photos. The backup is encrypted on your phone before it is uploaded, with a key held in Android's Block Store; we never receive the backup and we never receive the key. Deleting the backup from inside the app removes it from your Drive, and you can revoke access at any time in your Google Account settings.

13. Children's Privacy

PinkyBond is not intended for use by anyone under the age of 17. We do not knowingly collect data from children. The Coach is available only to people who confirm they are 18 or older.

14. Changes to This Policy

We will notify users of material changes through the app. Continued use after notification constitutes acceptance.

15. Contact

For privacy questions or data deletion requests, please reach out through our contact form.

Veronata, Inc.
2261 Market Street STE 22406
San Francisco, CA 94114

Download on the App StoreGet it on Google Play