Legal
Privacy Policy
Last updated: 24 June 2026 · Working draft pending legal review.
This Privacy Policy explains what personal data Infinite Heart ("we", "us") collects through the Infinite Heart mobile app and website, why we collect it, who we share it with, and the rights you have. We are committed to handling your data — especially the private memories you attach to your hearts — with care.
1. Who we are
The data controller is Infinite Heart sp. z o.o., Szlak 77/222, 31-153 Kraków, Poland (VAT PL 6762666752). For any privacy question or request, contact us at share@infiniteheart.love.
2. What we collect
| Category | Data | Why |
|---|---|---|
| Account | Email, display name, profile photo, and (optionally) your Instagram handle and public-profile details (bio, links) if you choose to add them. | To create and secure your account and let others recognise you on shared hearts. |
| Location | The precise coordinates where you "geo-lock" a heart, and the place name/city. | To anchor your heart to a meaningful place and let it be discovered in augmented reality at that spot. |
| Your content ("memories") | Photos, videos, audio, and letters you attach to a heart; the text you engrave (initials, dates, messages); names of co-creators you invite. | To create your personalised heart and the memories it holds. |
| Payments | Order and transaction details. Card data is processed directly by Stripe — we do not store card numbers. | To process purchases. |
| Blockchain | If you "eternalize" a heart, a cryptographic record (hash + timestamp) is written to the Solana blockchain. | To certify and timestamp the moment. See section 6. |
| Social rewards | If you tag us on Instagram to earn a reward, we receive the mention (e.g. a Story mention) via Instagram's official API. | To detect your tag and grant a voucher. |
| Technical | Device and app diagnostics needed to run the app (e.g. authentication tokens, basic logs). | To operate, secure, and troubleshoot the service. |
3. How we use your data
- To provide the app: create hearts, customise them, attach memories, place them in AR, and let you and authorised people view them.
- To process orders and deliver what you bought.
- To enable optional features you choose: public sharing, co-creation, blockchain eternalization, and social-tag rewards.
- To keep the service secure and prevent abuse.
- To support you and answer your requests.
Each memory can be set private or public by you. Private content is restricted to you and the people you authorise; public content is visible to others in the app (and, for shared hearts, to anyone you share it with).
4. Legal bases (GDPR)
- Contract — to provide the service you signed up for.
- Consent — for optional features (e.g. location geo-locking, public sharing, Instagram rewards). You can withdraw consent at any time.
- Legitimate interests — to secure the service and prevent abuse.
- Legal obligation — to meet accounting and tax requirements.
5. Who we share data with
We do not sell your personal data. We share it only with service providers that help us run the app, under appropriate agreements:
- Google Firebase — authentication, database, storage, hosting, push notifications.
- Stripe — payment processing.
- Mapbox / Cesium — maps and the 3D globe used to fly to your heart.
- Meta / Instagram — to receive your tags for the social-reward feature (only if you opt in).
- Solana — the public blockchain used for eternalization (see section 6).
6. Blockchain — important
If you choose to eternalize a heart, a record is written to the Solana public blockchain. Blockchains are public and permanent: a record written there is visible to anyone and cannot be edited or deleted, by us or by you. We only write a minimal cryptographic record (a hash and timestamp) — your photos, videos, messages and personal details are NOT written to the blockchain. Please consider this before eternalizing.
7. Storage & security
Your data is stored on Google Firebase infrastructure and encrypted in transit (HTTPS) and at rest by the provider. Access to your private files is controlled by security rules. We are working to add end-to-end encryption for private memories so that this content is readable only by you and the people you authorise. No method of storage is perfectly secure, but we take reasonable measures to protect your data.
8. Data retention
We keep your data for as long as your account is active or as needed to provide the service. When you delete your account, we delete your personal data, except where we must keep limited records to meet legal obligations (e.g. tax/accounting) and except for any record already written to the blockchain, which is permanent by nature (section 6).
9. Your rights
Under the GDPR you have the right to access, correct, delete, restrict, and port your data, and to object to certain processing. The app provides:
- Download my data — export a copy of your data.
- Delete User — delete your account and associated personal data.
You can also exercise any right by writing to share@infiniteheart.love. You have the right to lodge a complaint with your local supervisory authority (in Poland, the UODO).
10. Children
Infinite Heart is intended for users aged 18 and over. We do not knowingly collect data from minors. If you believe a minor has provided us data, contact us and we will remove it.
11. International transfers
Some providers (e.g. Google, Stripe, Meta) may process data outside the EEA. Where they do, they rely on appropriate safeguards such as the EU Standard Contractual Clauses.
12. Changes
We may update this policy as the app evolves (for example, when we add end-to-end encryption). We will post the new version here with an updated date.
13. Contact
Infinite Heart sp. z o.o. — Szlak 77/222, 31-153 Kraków, Poland — share@infiniteheart.love.