The I Love You App

The I Love You App — Privacy Policy

Last updated: 2026-09-05

The I Love You App is operated by an independent developer. This policy explains what The I Love You App collects, why, how long it is kept, and what you can and cannot ask us to do about it.

We have tried to write this so that it describes what the app actually does rather than what a privacy policy usually says. Where our answer is unflattering — data we cannot currently delete, a ban we cannot currently let you appeal — it says so.


1. What The I Love You App is

You hold a button, record up to three seconds of your voice, and The I Love You App delivers that recording to another user. In exchange you receive one other user's recording. If nobody is waiting to be matched, you receive one of our own pre-recorded default clips instead.

There are no profiles, no usernames, no friend lists, and no way to choose who you are matched with or to reply to a specific person.

2. We do not ask who you are

The I Love You App signs you in anonymously. We do not collect your name, email address, phone number, date of birth, contacts, photos, precise location, or advertising identifier. There is no sign-up form, and there is nothing to log into.

One qualification, stated here rather than buried later: our analytics provider derives an approximate, city-level location from your IP address, the way any web request reveals one. We do not ask for the location permission, the app never calls a location API, and we cannot see where you are more precisely than that. Section 3.8 explains what else analytics records.

Your account is a random identifier generated by Firebase Authentication on first launch. We cannot connect it to you as a person, and — as section 8 explains — that cuts both ways.

3. What we collect, and why

3.1 Voice recordings

What: Audio you record by holding the record button, up to three seconds per recording.

Why: It is the entire product. Your recording is placed in a queue and delivered to one other user.

Where it goes: The audio file is uploaded to Firebase Storage under a path derived from your anonymous account identifier. When you are matched, the other user receives a temporary link to your audio that expires after 15 minutes.

Who hears it: Exactly one other The I Love You App user, chosen automatically by matching order within your selected language. We do not listen to recordings routinely and we do not use them to train anything.

How long we keep it: See section 4.

3.2 Your selected language

What: A language code (one of English, Spanish, French, German, Portuguese, Japanese). It is initialised from your device locale on first launch and you can change it in the app.

Why: Matching is per-language, so that you receive a recording you have some chance of understanding.

3.3 A device identifier, used only as a ban anchor

What: On Android, Settings.Secure.ANDROID_ID. On iOS, identifierForVendor. These are per-device values provided by the operating system. Neither is your advertising ID, and neither is used for advertising.

Why: To make a ban stick. Because accounts are anonymous and free, a ban attached only to an account is undone by reinstalling the app. The device identifier is what makes enforcement meaningful for users who record abusive content.

How it is handled — precisely: The raw identifier is transmitted to our servers, in the request your app makes each time you send a recording. On receipt, the server immediately combines it with a secret value and stores only an irreversible SHA-256 hash. We do not store the raw identifier, and it is not written to our database in a readable form. It is transmitted over an encrypted connection.

What that means for you: If your device is banned, we hold a hash that lets us recognise that device again. We cannot turn that hash back into your device identifier, and we cannot use it to identify you, contact you, or track you across other apps.

3.4 Usage counters and purchases

What: How many free connections you have used today, your balance of purchased credits, the date your daily allowance last reset, and how many connections we have given back to you today. We also keep, on your account, the date it was created, the date of your first and most recent connection, how many connections you have made in total, and — if you have bought credits — how many purchases you have made and when the first one was.

Why: The I Love You App gives three free connections per day; further connections require purchased credits. Connections are sometimes returned to you after a report, which is capped per day and therefore counted.

Purchases: The I Love You App sells consumable credit packs through Google Play Billing and the Apple App Store. We never see your payment details. Your card, billing address and store account are handled entirely by Google or Apple. What reaches us is a purchase receipt, which we verify with Google or Apple and then record as: the store transaction identifier, the product purchased, the number of credits granted, the platform, and a timestamp. We keep that record to prevent the same receipt being redeemed twice.

3.5 Moderation data

What: When you report a recording you received, you tell us what was wrong with it. We store, on the copy of that message in your inbox, the fact that you reported it and the reason you chose. We may download the recording, convert its speech to text using Google Cloud Speech-to-Text, and test the resulting text against a list of blocked words. We may also record technical measurements of the audio file itself, such as its size.

Why: So that a report leads to a consequence. The I Love You App delivers unreviewed audio from strangers; without this, reporting would do nothing.

Important: This runs only when someone reports a specific recording. We do not transcribe recordings routinely, in bulk, or in the background.

Strikes and bans: A recording whose transcript matches a blocked word applies a strike to whoever recorded it. Two strikes is a permanent ban. When a ban is applied we store, on the banned account: the time, the reason, and the transcript of the recording that caused it.

We keep that transcript indefinitely, so that a ban can be reviewed and reversed by a human rather than being permanent and unexaminable. It is the only text derived from user speech that we retain without a time limit, and it is deleted only when an account is unbanned. We are telling you this explicitly because it is the least obvious thing in this policy. See section 8 for the appeal situation, which is not good.

3.6 Crash reports and diagnostics

What: Firebase Crashlytics collects crash reports and a small number of non-fatal errors we record deliberately. A crash report includes the stack trace, your device model, operating system version, and app version, plus an installation identifier generated by Crashlytics.

Why: To find and fix crashes. It is not linked to your recordings.

3.7 App integrity checks

What: The I Love You App uses Firebase App Check — Play Integrity on Android, App Attest or DeviceCheck on iOS. This asks the operating system to vouch that the app is a genuine, unmodified copy of The I Love You App.

Why: To keep automated abuse and modified clients out of the matching queue. This process involves your device and Google or Apple; we receive only a pass/fail token, not the underlying device signals.

3.8 Usage analytics

What: We measure how the app is being used, in two places.

On our servers, we record that a connection happened and how it turned out: whether you were matched with another person or received one of our default clips, how long the message waited to be matched, whether the message delivered to you was played, whether it was reported, and whether a purchase completed. Each of these is stored against your anonymous account identifier.

In the app, we use Google Analytics for Firebase to record which screens you open and a small number of specific moments: microphone permission being denied, how long a recording ran, an upload or playback failing, a clip being listened to all the way through, a purchase being started or cancelled, and a language change. It also records session and device information, and derives approximate location from your IP address as described in section 2.

Why: The I Love You App's core promise is that you get a real person's voice back. Without this we cannot tell how often that actually happens, whether people are waiting too long, which languages have nobody to match with, or which parts of the app are failing. Nothing here is for advertising.

What it is not: No recording content and no transcript is involved. These are counts and timings, not the audio. We do not build advertising profiles, and The I Love You App contains no advertising SDK — see section 5. Our analytics is configured so that no advertising identifier is collected on either platform.

4. How long we keep things

Data Retention
Your recording, after it is delivered and played Deleted about 4 hours after playback
Your recording, if it is delivered but never played Deleted about 48 hours after delivery
Your recording, if it is never matched with anyone Deleted after 7 days in the queue
The record that a queue entry was matched Deleted after 24 hours
That you reported a message, the reason you gave, and anything we measured about it Deleted with the message record, on the same schedule as the rows above
Temporary playback link Expires 15 minutes after it is issued
Individual usage records (that a connection happened and how it turned out) Deleted after 90 days
Analytics collected in the app by Google Analytics for Firebase Per that service's retention setting, currently 14 months
Aggregate daily and hourly totals, which identify nobody Indefinitely
Your account record (language, credits, daily counter, strike count, usage and purchase counters) Indefinitely — see below
Purchase records Indefinitely
Ban transcript, on a banned account Indefinitely, until the account is unbanned
Device hash, on a banned device Indefinitely, until the ban is lifted
Crash reports Per Firebase Crashlytics' retention, currently 90 days

Cleanup of recordings runs hourly and deletes both the audio file and its database record.

Be aware of the second half of that table. Audio has a short life; the account record around it does not. The I Love You App currently has no code path that deletes a user account record. If you uninstall the app, your recordings will age out on the schedule above, but your account record — your language, credit balance and strike count — remains in our database indefinitely. This is a real limitation, not a policy choice we are defending, and section 8 explains why it is hard for us to fix.

5. Who we share data with

We do not sell your data, and we do not share it with advertisers or data brokers. The I Love You App contains no advertising SDK.

We do use an analytics service, and we would rather say so plainly than hide it in a list of providers: app usage is measured using Google Analytics for Firebase, which is Google acting as our service provider on our instructions. It is configured not to collect any advertising identifier, and the data is not used to build advertising profiles or shared with anyone for their own purposes. Section 3.8 sets out exactly what is recorded.

Two categories of sharing do happen:

Other The I Love You App users. Your recording is delivered to one other user. That is the purpose of the app. Recordings are delivered without any name or profile attached, but please treat anything you record as something a stranger will hear — including anything audible in the background.

Service providers, acting on our instructions. The I Love You App runs on Google Cloud and Firebase (authentication, database, file storage, crash reporting, app integrity, analytics, and — only when a recording is reported — Speech-to-Text). Purchases are processed by Google Play Billing and the Apple App Store, and we verify receipts with them. These providers process data on our behalf under their own terms; they are not permitted to use your recordings for their own purposes.

We may also disclose data if we are legally required to.

6. Security

Data is transmitted over encrypted connections (HTTPS/TLS) and stored encrypted at rest by Google Cloud. Playback links are short-lived and signed rather than public. Device identifiers are hashed with a secret value before storage. The ban list and the device hash table cannot be read by the app at all — only by our servers.

No system is perfectly secure, and we cannot promise that one is.

7. Children

The I Love You App delivers unreviewed audio recorded by strangers and is not intended for children. You must be at least 13 years old, or the minimum age of digital consent in your country if that is higher, to use The I Love You App. We do not knowingly collect data from children below that age. If you believe a child has been using The I Love You App, contact us at support@theiloveyouapp.com.

8. Your choices, and the limits we currently have

What you can do in the app today:

What we currently cannot do, stated plainly:

If you contact us at support@theiloveyouapp.com we will do what we can, but you should know before you use The I Love You App that anonymity limits what we are able to do for you individually. If you have deliberately identifying information in a recording and want it removed, contact us quickly — recordings age out within hours, and after that there is nothing left to delete.

9. Where data is processed

The I Love You App's infrastructure runs on Google Cloud. Data may be processed in countries other than yours, including the United States.

10. Changes to this policy

If we change what we collect or how long we keep it, we will update this policy and change the date at the top. The current version is always at https://theiloveyouapp.com/privacy.

11. Contact

The I Love You App
support@theiloveyouapp.com
Iowa, United States