Privacy Policy
Last updated: 9 October 2026
This page is available in English.
PinkyLock turns promises and friendly challenges into cards that two people seal with a pinky swear. We built it to need as little personal data as possible: no account is needed, and we never ask for a phone number.
1. Who is responsible
The controller of your data is [Operator name and postal address, to be added before launch] (“we”, “us”). Contact: support@pinkylock.app.
2. What we collect
- An anonymous session. When you create or seal a card, we create an anonymous account: a random ID stored in a cookie on your device. It is not linked to your name, email or phone.
- If you sign in (optional): your email address. With Google, Google also shares your name and profile picture with our sign-in provider; we don’t use them. We use your email only to sign you in, never for newsletters or marketing.
- What you type on a card: your display name (up to 30 characters), the claim or promise, what the loser owes, an optional deadline and an optional comeback.
- Card activity: the card’s status (sealed, reported, settled…), who did what (by session ID) and when, and the card’s language.
- Your language choice, if you pick one, in a cookie.
- Reports: if you report a card, the reason, any note you add and your session ID, so we can review it and stop repeated reports.
- Abuse limits: to stop automated abuse we count actions (creating, sealing, sign-in codes…) per session and per IP address. IP addresses and emails are stored only as keyed hashes, and the counters reset within an hour.
- Technical data: like every website, our hosting providers process your IP address, browser type and request logs to deliver and protect the service. These logs are kept only briefly.
We do not collect your phone number, contacts, location or payment details, or your email unless you sign in. There are no ads and no analytics or tracking cookies. If we add analytics later, we will update this policy first and ask for your consent where the law requires it.
3. Who can see your cards
A card is meant to be shared: anyone who has a card’s link can see it, including the names, what was promised or claimed, what the loser owes and the card’s status. The link preview and the story image show the same. Please don’t put anything on a card that you wouldn’t want others to see, and don’t include other people’s personal details without their permission.
4. Why we use your data (legal bases)
- To run PinkyLock for you: create, seal and settle cards, show your cards on your device and the head-to-head score (performance of a contract, GDPR Art. 6(1)(b)).
- To keep the service secure, review reported cards, prevent abuse and fix problems (our legitimate interests, Art. 6(1)(f)).
- To meet legal obligations (Art. 6(1)(c)).
We do not sell your data or use it for advertising or profiling.
5. Cookies
We only use cookies that are strictly necessary: the session cookie that keeps you signed in to your anonymous account, and the language cookie that remembers your language choice. Because they are strictly necessary, we don’t ask for consent. Reminders you add to your calendar or send to a friend stay in your own apps; we don’t receive anything back.
6. Service providers
- Supabase (database, sign-in and sign-in emails). Your data is stored in the EU (Frankfurt, Germany).
- Vercel (hosting). Our server code runs in Frankfurt, Germany; Vercel is a US company, so some data may be processed in the US. Such transfers are covered by the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
If you choose “Continue with Google”, Google handles that sign-in under its own privacy policy and tells us your email address.
Supabase and Vercel act as our processors under data processing agreements and may only use the data to provide their services to us.
7. How long we keep it
We keep your cards for as long as PinkyLock runs, so both people can look back at them, unless you delete your data earlier. If you signed in, we keep your account until you delete it. Technical logs kept by our providers are deleted after a short period.
8. Your rights
You have the right to access, correct and delete your data, to receive it in a portable format, to restrict or object to its use, and to lodge a complaint with a data protection authority (for example in the EU country where you live). California residents have equivalent rights under the CCPA; we do not sell or share personal information.
On the Your data page you can download everything linked to your session, or delete it:
- Cards nobody else sealed are deleted.
- On cards you share with someone, your name is replaced with “Anonymous” and your comebacks are removed. The other person keeps the card, including what you both agreed to and the result, because it is part of their record too. If they delete their data as well, the card is deleted.
- Your account is deleted, including your email if you signed in, and you are signed out.
If you never signed in, we don’t know who you are, so we can only act on the cards linked to the session on your device. If you lost access to that device, email support@pinkylock.app with the card links and we will help.
9. Children
PinkyLock is not directed at children under 13. If we learn that a child under 13 has used it, we delete their data.
10. Security
Connections are encrypted (HTTPS). Only the two people on a card can change it, and every change is checked on our server. Access to the database is restricted and protected.
11. Changes
If we change this policy, we update the date above. For important changes we will also tell you on the site.