Legal

Privacy Policy

Last updated: September 26, 2026

This policy explains what data the app stores and how your vault content is handled.

Your photos, chat, and prompt answers are encrypted in your browser before upload, and the service stores ciphertext. This is client-side encryption, not a zero-knowledge service: we receive your shared password at the server to verify unlock, and canvas text and drawings are not encrypted in the same way.

1. Overview

Love as a Story (LaaS) is built for private use by two partners sharing one vault. Every new vault begins with a 15-day free trial.

This policy explains what data is stored, why it is stored, and how your content is protected.

2. How You Sign In

New vaults are created by signing in with Google. We receive your Google account identifier, name, email address, and profile photo, which we use to identify you and link your vault to your account.

Vaults created before public launch (and existing password-only vaults) sign in with a Vault ID, Vault Key, and shared password.

3. Data Collected

  • Vault records (vault ID and related metadata).
  • Vault Key and shared password — sent to our server to verify unlock and stored only as salted scrypt hashes, never in plain text. We keep the hashes, not the secrets themselves.
  • Google sign-in profile (account id, name, email, photo) for vaults created or linked with Google.
  • Canvas data used to restore your boards and sub-canvases.
  • Uploaded photos, chat messages, and daily-prompt answers, stored encrypted (see Security).
  • File metadata such as name, type, and size.
  • A free-trial record tied to your Google account (see Free Trial & Fair Use).
  • Session and access-control data to protect your vault.

4. Where Data Is Stored

  • A hosted database for vault metadata, sessions, canvas data, and the free-trial record.
  • A cloud storage service for your encrypted images.
  • A real-time sync service for live collaboration between you and your partner.
  • A caching service used only for rate limiting. No vault content is stored there.

5. How Data Is Used

  • Identify you when you sign in with Google and unlock your vault.
  • Save and load your canvases and sub-canvases.
  • Store and deliver your encrypted images.
  • Enable real-time collaboration between you and your partner.
  • Run the free trial and keep usage limits fair.
  • Protect your vault from unauthorized access and abuse.

6. Security & Encryption

Photos, chat messages, and daily-prompt answers are encrypted in your browser with AES-256-GCM before they are uploaded, so what we store is ciphertext. Our servers do not store your original media or messages.

This is client-side, at-rest encryption — not a zero-knowledge design. To unlock a vault we do receive your shared password and Vault Key at our server in order to verify them, and the encryption key is derived from your password using your vault ID as a salt (the vault ID is not secret). That means a party who obtained your password, or who controlled the server or the login flow, could in principle derive the key; and whoever controls the JavaScript your browser downloads could change what runs. We do not claim to be technically unable to decrypt your content.

Canvas content (text, drawings, and element positions) is not encrypted the way media is. It is stored on our servers and relayed to your partner through our real-time sync service, which uses TLS for the browser connection but is not end-to-end encrypted — treat anything you type or draw on a canvas as visible to the service.

Transport between your browser and our edge uses TLS. We do not currently guarantee TLS on every internal hop between our own services, so do not treat transport alone as a guarantee of secrecy.

No internet service can guarantee absolute security. Use strong, unique secrets and store them safely.

7. Data Sharing

  • Your vault content is never sold.
  • No advertising profiles are built from your memories.
  • Google sign-in is used only to authenticate you and identify your vault.
  • Infrastructure providers host and deliver your encrypted media as ciphertext; they do not hold your vault key.
  • Voice notes: if you use voice transcription, the raw audio recording is sent through our server to Groq (Whisper) to produce the text. Only record what you are comfortable sharing with that provider.
  • Feedback: if you send feedback, the text you write is posted to our Notion workspace, and any screenshot you attach is uploaded to our cloud storage unencrypted — it is not protected by vault encryption.

8. Free Trial & Fair Use

To keep the one-per-account free trial fair, we keep a small record that a Google account has used its free trial.

This record is retained even if you later delete your vault, so the free trial cannot be reset by signing up again. It contains no vault content.

9. Retention and Deletion

Data remains stored while your vault is active. Signing in with Google lets you find the vaults linked to your account.

There is currently no self-service "delete vault" action. You can delete individual canvases, photos, and messages inside the app, but our media storage keeps version history and backups, so recently deleted objects may persist there for a period. To request full vault deletion, contact support.

The free-trial record described above is retained even after a vault is deleted, so the trial cannot be reset by signing up again. It contains no vault content.

10. Your Control

  • Do not store your secrets in only one place.
  • Export or back up important memories outside the app when possible.
  • Avoid uploading content that you would not want stored on server infrastructure.

11. Policy Updates

This policy may be updated as the app evolves. Continued use after updates indicates acceptance of the revised policy.