1. Introduction
Welcome to LoveTanked. We are committed to protecting the privacy of your relationship workspace. LoveTanked is designed from the ground up to ensure that your private relationship logs, Tank Tips, Tank Maintenance notes, quizlet content, and Message in a Bottle conversations remain completely private to you and your partner.
2. Data Collection and Sharing
LoveTanked does not upload or share your private relationship content in readable form. Tank Tips, Tank Maintenance notes, quizlet text and answers, Message in a Bottle text, topic titles, drafts and journal entries, love tank levels, profile nicknames, partner relationship details, and decrypted payloads are not collected for analytics and are not readable by LoveTanked operators.
LoveTanked includes optional, privacy-safe usage analytics that are off by default. If you choose to enable analytics, the app may share generic events such as screen names, feature areas, app version, platform, results, and subscription product identifiers. Analytics must not include relationship content, partner identifiers, mailbox identifiers, push tokens, nicknames, Tank Tips, quizlet content, notes, or love tank levels.
3. Crash and Performance Diagnostics
Technical diagnostics are enabled by default to help us identify crashes and performance problems. You can turn them off in LoveTanked Settings; doing so also deletes Crashlytics reports still waiting locally to be sent. Firebase Crashlytics may process crash stack traces, exception details, app version, device model and operating-system information, and app-install identifiers. Firebase Performance Monitoring may process app-install identifiers, device and network characteristics, response codes, timing and payload-size measurements, and country inferred from an IP address. Network measurements do not include request URL parameters or request/response payload content.
We prohibit relationship content from diagnostic reports and do not deliberately attach names, partner identifiers, Tank Tips, quizlet content, Message in a Bottle text, Tank Maintenance notes, love tank levels, precise location, or decrypted payloads. Firebase currently states that Crashlytics data and associated identifiers are retained for 90 days before removal begins, IP-associated Performance events for 30 days, and installation-associated or de-identified Performance data for 60 days.
4. GoFish Location and Venue Processing
GoFish can find real-world venue suggestions in either of two user-selected modes. In manual-area mode, you provide a city, state, or ZIP code and LoveTanked does not request device GPS. In device-location mode, LoveTanked requests one current foreground location only when you ask GoFish to find venues. LoveTanked does not request background or continuous location. Your operating system lets you choose approximate or precise location access, and you can change or revoke that choice in system settings.
To fulfill a venue request, LoveTanked sends the selected GoFish suggestion text and either the manual area or current coordinates to an authenticated LoveTanked cloud function. The function may use Google's Gemini service to convert the suggestions into venue-search queries and Google Places to locate matching venues. LoveTanked does not intentionally save the submitted coordinates in the relationship database or Firestore. Google processes these requests as a service provider under its applicable terms, and ordinary cloud services may temporarily process technical information such as IP addresses to deliver and protect the service.
5. Local Cryptography & Sandbox Security
All personal relationship tracking logs are zero-knowledge, encrypted client-side using native AES-256 (sqlcipher), and reside exclusively on the device storage hardware sandbox. Because your database key is generated on your device and stored in the secure hardware enclave (Keychain/Keystore), no one—not even the developers of LoveTanked—can read or access your local database.
6. Ephemeral Message Relay
Asynchronous data synchronization is facilitated via ephemeral, stateless cloud transport mailboxes that temporarily queue unreadable ciphertext string blobs. Once a receiving device successfully decrypts, saves, and acknowledges a sync message, the ciphertext is deleted from the mailbox immediately. Undelivered ciphertext automatically expires after no more than seven days. Our relay servers act as blind mailboxes. They do not store relationship history or unencrypted relationship data, and they cannot decrypt queued messages.
7. Encrypted Recovery
LoveTanked can create an encrypted recovery capsule so you can restore approved local app data after reinstalling or replacing a device. The capsule is encrypted on your device with a recovery password that LoveTanked does not receive, store, or have the ability to recover. LoveTanked cannot decrypt the capsule without that password.
On iOS, the encrypted capsule may be stored in your private iCloud CloudKit database. On Android, it may be stored in Google Drive's hidden application-data folder, which does not give LoveTanked access to your normal Drive files. Android device transfer or system backup may also carry a local copy of the encrypted capsule as a secondary fallback. The app verifies cloud uploads by reading back the encrypted capsule; decrypted relationship content is not sent to LoveTanked services as part of this process. Google account authorization remains between your device and Google, and LoveTanked does not send your Google account identity to its own services for recovery.
8. Peer Connection & Deletion
You have total control over your local data. You can terminate the connection with your partner at any time. Unpairing your device automatically and permanently deletes all locally stored partner tank levels and pairing information from your device.