Plain-language promise. We do not sell personal information or use intimate content for advertising or analytics. until. uses relationship information to provide the shared experience you ask for.
Who controls your information
Eros Media LLC operates until. and is responsible for the processing described here. This policy applies to the mobile app, its support site, and related services at https://untilwithyou.com.
Information we handle
Account and relationship profile
When you sign in with Apple or Google, we receive a provider authentication identifier and, depending on your provider choices, an email address and profile name. Apple may provide a private relay email address instead of your personal address. We also handle the names or nicknames you provide, your selected city and time zone, relationship start date, pairing status, and the invite needed to join one shared space. City information is chosen by you; the app does not request device GPS permission.
Relationship content
Depending on the features you use, we handle answers, prompts, moments, memory captions and photographs, letters, trips and notes, dates, shared drawings, shared skies, touches, game and match records, recaps, reactions, and other content you intentionally create with your partner.
Photos and device features
If you choose a photograph, the app receives the selected image so it can be uploaded to your couple’s private storage. Photo access is optional. Widgets receive a limited local snapshot for partner name, city time, presence, and reunion information. Notifications use a device push token and your quiet-hour settings.
Purchases, analytics, and diagnostics
If subscriptions are enabled, the app and its billing provider handle product, entitlement, purchase, renewal, refund, and restore status. Apple or Google handles payment credentials; we do not receive full card numbers. When explicitly enabled for a release, Google Analytics for Firebase receives a small set of operational events such as app opens and coarse screen areas. We do not send names, account identifiers, intimate content, raw screen paths, advertising identifiers, or advertising signals. Native analytics collection is off by default. If production diagnostics are enabled, Sentry may receive a crash, release, device, and operating-system context. Our adapter disables default personal information, screenshots, view hierarchy, request capture, interaction tracing, traces, and profiles, and removes user and request fields before sending.
Support communications
We receive the email address and information you choose to include when you contact support. Please do not send intimate content, invite codes, payment credentials, or device tokens.
Why we use information
- Provide authentication, pairing, shared content, synchronization, and account controls.
- Deliver requested notifications and maintain quiet hours.
- Manage subscriptions and couple-scoped entitlements.
- Protect the service, prevent abuse, enforce limits, and troubleshoot failures.
- Meet legal obligations and respond to rights requests.
How information is shared
Content in a couple space is shared with the partner you pair with, according to the reveal and visibility rules of each feature. We also disclose information to service providers that process it for us: Apple and Google for account authentication when you choose their sign-in service; Google Firebase and Google Cloud for authentication, database, functions, storage, push delivery, and limited operational analytics when enabled; Apple and Google for app distribution and purchases; RevenueCat for subscription status when configured; and Sentry for restricted crash diagnostics when configured. We may disclose information when required by law, to protect rights or safety, or in a business transfer subject to appropriate safeguards.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use intimate relationship content to train advertising or generative-AI models.
Retention and deletion
You can export your account data and initiate deletion inside the app. You can also request deletion through the web deletion page. A deletion request enters a 30-day cancellation window. During that window ordinary account activity is paused and you may cancel the request.
After the window, the system removes your authentication record, personal user record, profile, presence, invitations, notification registrations, and pending notifications. Shared relationship history may remain available to the other partner with your profile removed and authorship replaced by an opaque “Former partner” label. Before deleting your account, use supported “delete for both” controls if you want eligible memories or letters removed from both partners’ shared history. Operational deletion audit records may be retained to demonstrate completion and protect the service.
Blocking and relationship separation
Either member may use Block & end relationship without the other member’s approval. The control immediately stops live shared activity, invitations, and relationship notifications; preserves a read-only shared-history archive for each account; and prevents the two blocked accounts from pairing with each other again. We retain the minimum block record needed to enforce that safety boundary. A private report or reason is not sent to the former partner.
Support messages and security records are retained only as long as reasonably necessary for the request, legal obligations, fraud prevention, dispute resolution, and enforcement.
Your choices and rights
You may access and correct profile details in the app, export your data, disable notifications, remove supported content, request account deletion, and cancel a pending deletion. Depending on where you live, you may also have rights to know, access, correct, delete, restrict, object, or receive a portable copy of personal information, and to appeal or complain to a regulator. Contact [email protected]. We may need to verify that a request comes from the account holder.
Security and international processing
We use access controls, authenticated service boundaries, default-deny database and storage rules, App Check in production, content-type and size limits, redacted diagnostics, and encrypted transport. No system is perfectly secure. Service providers may process information in the United States or other countries where they operate; when required, we use appropriate contractual and legal safeguards.
Age requirement
until. is intended only for people age 18 or older. It is not directed to children, and we do not knowingly collect personal information from anyone below that age. Contact us if you believe a child has provided information.
Safety reports
Use the safety reporting page to report non-consensual intimate content, abuse, impersonation, or a compromised shared space. We limit access to reports and use them only to investigate, protect people, enforce these terms, and meet legal obligations.
Changes
We may update this policy as the product or law changes. We will change the effective date and provide additional notice when a change materially affects how we handle personal information.
Contact
Eros Media LLC
1000 Brickell Ave, Suite 715, Miami, FL 33131
Privacy: [email protected]
Support: [email protected]