Us, Actually Privacy Policy
Private answers need clear rules.
Effective and last updated September 16, 2026
Us, Actually collects information to operate the experience a person chooses. It does not sell personal information, show third-party ads, or reveal paired answers before both people finish. Optional product analytics is off by default and has separate consent and deletion controls.
Data stored on a device
Names, preferences, one-phone round history, saved memories, plans, Tiny Thanks, quiz answers and results, and locally saved feedback remain in app storage on the device unless the person exports, erases, or uninstalls the app. Just Me reflections and quiz content stay out of paired spaces. In a paired space, only a count-only quiz completion event syncs for shared garden growth. It contains an opaque random identifier, not the quiz, answers, or result.
Data used for cloud features
If a person pairs or protects an account, Us, Actually stores an account identifier, optional email and display name, shared-connection membership, pairing codes, synced round and plan state, submitted answers, One Honest Question prompts and exact-text responses, planned activities, memories, fixed-choice connection signals and their sent times, count-only shared landscape totals and opaque quiz completion identifiers, and subscription entitlement status.
Shared reveals
A paired partner or friend cannot read current synced answers before both people finish. This includes exact-text One Honest Question responses. After reveal, both members can see the shared result, and a server-verified Plus entitlement permits expanded revealed Honest Question history. Skipping an Honest Question deletes any submitted response before reveal. Unfinished device drafts are cleared after submit or skip, when an orphaned draft is detected, and on sign-out or local erase. Unpairing deletes the shared workspace and its associated content.
Connection signals
Connection signals are limited to six predefined choices and cannot contain free text. Both people in a fully paired space can see the latest signal and sent time from each member. A signal does not provide a delivery or read receipt. Each new signal replaces that member's prior signal, and the shared rows are removed when the shared space or account is deleted. Connection signals are not an emergency service; a person should contact the other member directly for anything urgent.
Purchases and providers
Apple or Google Play processes payments. RevenueCat helps verify subscription and one-time purchase access. Us, Actually receives purchase and entitlement status, not a complete card number. One active purchase can unlock Plus for both people in a paired space.
Supabase provides account, database, and synchronization services. RevenueCat provides subscription entitlement services. Netlify processes voluntary app feedback and basic network information needed to filter spam and enforce submission limits. PostHog provides optional product analytics only when the conditions described below are met. Apple and Google provide store payment services. If remote notifications are enabled, Apple, Google, and Expo may process a device notification token. These providers process data to operate their part of the service under their own terms and privacy commitments.
Optional feedback
If a person sends an app idea, the submission includes its category and text. It does not attach answers, partner history, names, an account identifier, or an email address.
Optional product analytics
In versions that offer this feature, optional product analytics is off by default. We use it to understand feature use and improve the app. It sends nothing to PostHog unless you explicitly opt in on the welcome screen or in Settings and the app has a configured, privacy-verified analytics project. You can still use the app without opting in. Earlier versions without this feature do not gain analytics when this policy is updated. This policy update does not add analytics to the marketing website or its launch-list form.
Analytics data and purpose
If enabled through Share basic usage data on the welcome screen or in Settings, PostHog receives whether onboarding, a quiz or a game started or finished; whether Daily Five, quizzes, games or date ideas were selected; and whether Plus options were opened. Each event includes its time and a random analytics reference for this installation. No specific quiz, game or answer is identified. PostHog keeps a minimal record under that random reference so we can group basic usage and process deletion requests. Repeated events can be associated with that reference, so this is pseudonymous data, not anonymous data. We do not join it to your Supabase account or RevenueCat purchase identity. These analytics events do not include names, email addresses, private answers, prompts, result text, pairing codes, contacts, photos, free-text entries, visited URLs, app or device metadata, or purchase records. There is no session replay, screen recording or advertising tracking.
Analytics connection information
PostHog receives network information, including a source IP address, to accept and protect an internet request. The analytics feature requires project-level IP storage and location enrichment to be disabled before activation. The app also requests no GeoIP enrichment and does not put an IP address or location into analytics event properties. These controls do not make the network connection anonymous.
Analytics choices and deletion
Turning optional analytics off in Settings stops new collection and discards unsent events. It does not delete events PostHog already received or retract a request already sent. The app keeps prior random analytics references locally so you can copy them in Settings and email a deletion request. Copy these references before erasing all app data or uninstalling. Because analytics is not joined to your account, erasing your account does not automatically delete these events. We use references you provide only to handle your request, not to enrich analytics with your email or private content. Provider deletion is not immediate; we verify completion before confirming it.
Analytics retention
Optional analytics uses PostHog's U.S. cloud. Its current free plan lists a one-year event-retention window under the provider's retention rules and enforcement. This is not a promise of automatic erasure on day 365 or when analytics is turned off. You can request deletion using the analytics references described above. Before analytics collection is enabled, the project privacy settings and deletion process must be verified. PostHog may process information outside your country under its published privacy and processing terms. See PostHog's privacy policy and event-retention documentation.
Optional website launch list
A person may submit an email address, app interest, and email consent through the public website to receive launch and product updates. Netlify processes the form submission. BrightByte Apps uses this information only for the requested Us, Actually emails and does not connect it to relationship answers or in-app activity. A subscriber can unsubscribe using any marketing email or request deletion by contacting support.
Notifications
Reminders are optional. Local reminders stay on the device. Notification text never states that a partner is waiting.
No advertising sale or tracking
Us, Actually does not sell personal information. This version does not use third-party advertising, location tracking, contact importing, or cross-app behavioral tracking.
Retention deletion and choices
Device data remains until the person erases it or removes the app. Cloud data remains while the account is active. Settings lets a person export data and erase the account. Account deletion removes the cloud identity, shared workspaces, and synced private content, subject to short-lived backups and records required for fraud, tax, or legal compliance. Feedback is not linked to an account; a removal request can identify it by its approximate date, category, and text. Optional analytics events use the separate reference-based deletion process described above and are not automatically removed by erasing the account.
A person can use the one-phone experience without pairing, decline notifications or optional analytics, export data, unpair, or erase the account in Settings.
Age
Us, Actually is a relationship and connection app and is not directed to children under 13.
Changes
If this policy changes materially, the effective date will change and the updated policy will be available in the app and at the public privacy URL.
Contact
Email lillilkidssongs@gmail.com with privacy questions or requests.