Legal
Privacy Policy
Last updated: June 9, 2026
This Policy explains what personal data Tides processes, why, on what legal basis, with whom we share it, and what rights you have. The data controller is Axora FZE, Sharjah Publishing City Free Zone, UAE ("we", "us"), represented by Tendriniavo Nanny Nomia Harivololonisainana.
1. Data we collect
- Account: email, hashed password (or Google identifier), display name.
- Check-ins & journaling: mood, energy, needs, free-text notes you write.
- Optional cycle data: if you choose to track a cycle, the phase and dates you enter. This is sensitive health-related data; see §4.
- Partner link: whether you are linked to a partner account and what you choose to share.
- Usage: feature events (e.g. trial quota), device/browser type, IP, timestamps.
- Billing: Stripe customer ID and subscription status. We never see your full card number.
2. Why we use it (purposes & legal bases — GDPR)
- Provide the Service (contract, Art. 6(1)(b)): account, check-ins, translations, partner sync.
- AI features (contract): generating Whisper translations and reflections from your input.
- Billing & fraud prevention (contract / legal obligation).
- Service security & abuse prevention (legitimate interest).
- Product analytics (legitimate interest, aggregated and minimised).
- Sensitive data (cycle, intimate notes) — processed only with your explicit consent (Art. 9(2)(a)). You can withdraw at any time.
- Communications about your account (contract). Marketing only with separate opt-in.
3. Who processes data for us (sub-processors)
- Supabase — database, authentication, file storage (EU region where available).
- Stripe — payment processing.
- Lovable AI Gateway / underlying model providers (e.g. Google, OpenAI, Anthropic) — to generate AI suggestions from your input. Prompts are sent transiently; we do not allow training on your content.
- Cloudflare — hosting and edge delivery.
- Email provider — for transactional emails (sign-in, billing, reset).
Each sub-processor is bound by a data-processing agreement and appropriate safeguards (SCCs where data leaves the EU/EEA).
4. Sharing with your partner
Your raw thoughts stay private. Your partner only sees what you explicitly choose to share (e.g. a translated Whisper message). Cycle phase, when enabled, can be shown to your linked partner only with your consent and at the level of detail you allow.
5. International transfers
Some sub-processors may process data outside the EU/EEA or the UAE. When that happens, we rely on adequacy decisions or Standard Contractual Clauses to protect your data.
6. Retention
- Account & check-ins: kept while your account is active.
- After account deletion: removed within 30 days, except where law requires longer retention (e.g. billing records — up to 10 years).
- Backups: rotated within 90 days.
7. Your rights
Under GDPR and similar laws you can:
- access, rectify, or delete your personal data;
- restrict or object to processing;
- port your data;
- withdraw consent at any time (for sensitive data and marketing);
- lodge a complaint with your local data-protection authority.
To exercise these rights, email support@trylovetides.com. We respond within 30 days.
8. Security
We use encryption in transit (TLS), encryption at rest for the database, scoped access controls (RLS), and audit logging. No system is 100% secure; we will notify affected users and authorities of any breach as required by law.
9. Children
Tides is not intended for users under 18 and we do not knowingly collect their data.
10. Cookies
We use strictly necessary cookies/local storage for authentication and session management. We do not use advertising cookies. If we ever add analytics that require consent, we will ask first via a banner.
11. Changes
We will notify you of material changes by email or in-app at least 14 days before they take effect.
12. Contact
Axora FZE, Sharjah Publishing City Free Zone, UAE
Authorised representative: Tendriniavo Nanny Nomia Harivololonisainana
Contact: support@trylovetides.com
