This policy explains what tieHearts collects, why, who else ever sees it, how long we keep it, and what you can make us do about it. It is written to be read by the person it is about, not by a lawyer. Where the law gives you a right, we say so and tell you how to use it.
The whole thing in nine lines:
tieHearts is operated by TIE2INNOVATION PRIVATE LIMITED, a company incorporated in India. Under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act’’), we are the Data Fiduciary for your personal data — meaning we are the ones who decide why and how it is processed, and we are the ones answerable for it. You are the Data Principal.
In this policy, “we”, “us” and “tieHearts” mean that company.
| Detail | Value |
|---|---|
| Company | TIE2INNOVATION PRIVATE LIMITED |
| Registered office | 35B, Shyam Vihar Phase 2, Najafgarh, New Delhi 110043 |
| General contact | developertiehearts@gmail.com |
| Grievance Officer | Ravi Singh, reachable at developertiehearts@gmail.com |
Everything below is collected because a specific part of the app cannot work without it. There is no line item here whose purpose is “analytics”, “insights”, or “improving your experience”, because those phrases usually mean somebody could not name the real reason.
| What | Why it exists | Who can see it |
|---|---|---|
| Your phone number | It is your only login. It is also how we know a feeling locked for a number belongs to you when you join. Shared with one other person only in the two cases in section 5. | You. Us. One other user, only in the two cases in section 5. |
| Your date of birth | To check you are 18 or over, which Indian law and both app stores require of a service like this. Checked once, on the server, before any account row is written. | Nobody but us. It is never displayed anywhere in the app. |
| Your gender | Asked once at sign-up so we understand who uses tieHearts. It is never shown to anyone, never used to match, sort, rank or suggest people, and never sent to any third party. | Nobody but us. |
| Your name or alias | What another person sees if — and only if — you reveal yourself, or you tie. You choose it and you can change it. | You, until a reveal or a tie. |
| The feelings you lock | The core of the product: who you locked for, which feeling, how strongly, and when. | You and us. The recipient learns only that somebody did, never who, unless you say. |
| A private label you add to a lock | Your own note to yourself, so you can tell your locks apart. | You only. It is never shown to the other person, at any stage, including after a reveal. |
| Secret-chat messages | To deliver the conversation and to investigate a report if one is made about it. | The two people in the chat. Us, only if the chat is reported or we are legally compelled. |
| A push notification token | To ring your phone when something happens. It identifies a device, not a person. | Us, and the push service that delivers it. |
| Purchase records | To give you what you paid for, to handle refunds, and because tax law requires us to keep records of sales. | Us, and the app store or payment provider that processed it. |
| Reports you make or receive | To act on abuse, and to show a regulator or a court that we acted. | Us. The person reported is never told who reported them. |
| Basic technical logs | App version, device type, coarse error and crash information, and the timing of requests — to fix crashes and to detect someone attacking the service. | Us. |
These are not oversights. Each one was considered and refused, and refusing them is part of what the product is.
Under the DPDP Act, personal data may be processed on the basis of your consent or for certain legitimate uses defined by the Act. Here is which is which.
You can withdraw consent at any time, and it must be as easy to withdraw as it was to give. Deleting your account in the app is a complete withdrawal and takes about ten seconds. You can also withdraw narrower consents — turning off push notifications in your phone’s settings stops us using your device token, and it costs you nothing else.
Withdrawing consent does not undo something that already happened lawfully while consent was in place. Most importantly, it cannot un-share a phone number that has already been shared — see section 5, which is the single most important paragraph in this document.
We never reveal who locked a feeling for someone. Not for money, not to the recipient, not to anybody, ever.
You can pay to ask an admirer to show themselves. You can never pay to be told. Only the admirer can answer, and if they choose to stay hidden, they stay hidden — and you have still received exactly what was described to you before you paid. There is no amount of money, and no customer-support request, that produces a name.
Your phone number reaches another tieHearts user in exactly two situations. Both are caused by a deliberate act, and there is no third.
Once a number has been shared, it cannot be taken back. The other person has seen it. They can write it down, screenshot it, or save it to their phone, and none of that is something we control or can reverse. Deleting your tieHearts account afterwards removes it from us; it does not remove it from them.
Blocking works inside tieHearts and nowhere else. If you block someone after a reveal or a tie, they can no longer reach you through this app — not in chat, not with a new feeling, not at all. It does not stop an ordinary phone call or an ordinary text message, because that is your phone network, not us.
This is why a reveal is worth thinking about before you tap it, and why we ask you to confirm.
This section explains the one part of tieHearts that can involve a person who never signed up. We are setting it out in full because it deserves to be understood by both sides.
tieHearts has no search, no browsing, no profiles, and no directory. You cannot find a stranger here. The only way to lock a feeling for someone is to type a phone number you already have. If that number does not belong to an existing tieHearts account, the feeling waits, and we may send one text message to that number telling the person that something is waiting for them.
When you enter another person’s number, you are making a set of promises to us and to them. They are set out in the Terms of Use, section 6, and in summary you confirm that:
You are the person who decided to contact them. We are the messenger. That distinction is why we keep a record of who caused every message, and why we can answer for it.
The text does not name the sender. It does not say which feeling was locked, or how strongly. It does not say anything a person standing next to you could read off your lock screen and use against you. It says that somebody has locked a feeling for you on tieHearts, gives a link that explains what tieHearts is, and tells you how to stop.
The wording is fixed. Under India’s telecom rules every template must be registered in advance with the DLT (Distributed Ledger Technology) platform operated by the telecom providers, and a registered template cannot be changed without re-registering it. So the message you receive is the message that was approved, and it is the same for everyone.
| Limit | What it means |
|---|---|
| One per feeling | A message is earned by somebody actually locking a feeling. Nothing is sent on a schedule, and nothing is sent to “re-engage” you. |
| A minimum gap | Feelings arriving close together do not each buy their own text. The next message carries the count instead. Nobody can make a stranger’s phone buzz on demand. |
| A hard ceiling | A number that has received five of these and not joined will never receive a sixth. Somebody who has had five has decided. |
| STOP is permanent | Reply STOP and that number is on our opt-out list for good. Not for thirty days, not per sender, not until you change your mind. Permanent. |
| DND is respected | Messages are sent through a registered Indian telecom route and are subject to the national Do Not Disturb preferences you have set with your operator. |
You have rights here even though you never signed up, and you do not need to install anything to use them.
tieHearts runs on a deliberately small number of outside services. Each one receives only what it needs to do its job, is bound by contract to process it only on our instructions, and none of them is permitted to use it for their own purposes.
| Service | What it receives | Where |
|---|---|---|
| Supabase — database and sign-in | Everything listed in section 2. This is where tieHearts lives. | Singapore (ap-southeast-1) |
| Expo push notifications and Google Firebase Cloud Messaging | Your device token and the contents of a notification. A notification carries only that something is waiting, the feeling type and a broad intensity band — never a name, never a number. | United States |
| An Indian SMS provider registered under the DLT framework | Your phone number and the registered message template, for sign-in codes and invites only. | India |
| Google Play (and, in future, the Apple App Store) | Purchase and refund information. We never receive your card details — the store handles payment and tells us only that a purchase succeeded. | Per the store’s own policy |
We have never sold personal data and we never will. We do not run advertising, we do not share data with data brokers, and we do not operate any business line that would create a reason to.
Our database is hosted in Singapore and our push notification providers operate from the United States. This means your personal data is processed outside India. The DPDP Act permits transfer to any country the Central Government has not restricted, and we will move promptly if any country we use is restricted. Wherever the data sits, the protections in this policy apply to it.
We will disclose data where we are required to by Indian law — a valid court order, a lawful direction from a government agency, or a legal obligation. We will also disclose where it is genuinely necessary to prevent serious harm to someone. Where we are permitted to tell you that this has happened, we will.
The DPDP Act requires us to erase personal data once the purpose it was collected for is served. Here is what that means in practice.
| What | Kept for | Why |
|---|---|---|
| Your account, profile, locks, chats and notifications | Until you delete your account, or until your account has been inactive long enough that keeping it serves no purpose | It is the service. Deleting is immediate and in your hands. |
| Purchase and tax records | As long as Indian tax and company law requires | We are legally obliged to keep records of sales. This is a legal obligation, not a choice. |
| The invite ledger — that a message was sent to a number, when, and who caused it | Retained after account deletion, in reduced form | It is the only record that can answer “who sent me this?” if somebody is later harassed. Removing it would make the service untraceable, which is precisely what we refuse to be. |
| The opt-out list | Permanently | It is what guarantees we never message that number again. Deleting it would break the promise it exists to keep. |
| Reports and the record of what we did about them | Retained after account deletion, in reduced form | To show a regulator or a court that we acted, and to stop somebody deleting their account to erase a record of abuse. |
| Technical and security logs | A short rolling window | Fixing crashes and detecting attacks. They age out on their own. |
You can delete your account yourself, inside the app, without asking us and without explaining yourself: Profile → Delete my account. If you no longer have the app, the instructions are at tiehearts.com/delete.html.
What is destroyed: your profile, your name or alias, your date of birth, your gender, every feeling you locked and every private label on it, every secret-chat message you sent, your notification tokens, and your login. This is irreversible. There is no restore, no grace period, and no copy kept in the background for us to change our minds about.
What survives, and why: only the four narrow items in the table above — tax records, the invite ledger, the opt-out list, and abuse reports. These are reduced so they no longer describe you as a person, and they exist because the law requires them or because deleting them would let somebody erase evidence of harm to someone else.
What we cannot reach: a phone number that was already shared with another user through a reveal or a tie is now in that person’s possession. See section 5.
Under the DPDP Act you have the following rights over your personal data. You do not need a reason and you will never be charged.
| Right | What it lets you do | How |
|---|---|---|
| Access | Ask for a summary of the personal data we hold about you, what we are doing with it, and who we have shared it with. | Email us |
| Correction and completion | Have inaccurate or incomplete data corrected. Your name or alias you can change yourself in the app at any time. | In the app, or email us |
| Erasure | Have your personal data deleted, subject only to what the law makes us keep. | In the app, in about ten seconds |
| Withdraw consent | Stop us processing data you previously consented to. As easy as giving it. | In the app, or email us |
| Grievance redressal | Complain about how we handled your data and get an answer within a fixed time. | See section 11 |
| Nominate | Name another person to exercise these rights on your behalf if you die or become incapable of doing so yourself. | Email us |
One honest limit: because a phone number is the only identifier we hold, we have to be certain a request really comes from the owner of that number before we act on it. We will verify, usually by sending a code to the number in question. This protects you.
If you are unhappy with anything about how tieHearts handles your data or your safety, you can complain, and we are bound to timelines.
Grievance Officer
Ravi Singh
TIE2INNOVATION PRIVATE LIMITED
35B, Shyam Vihar Phase 2, Najafgarh, New Delhi 110043
developertiehearts@gmail.com
In line with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021:
Some complaints move faster than that. A report of harassment or of content that puts someone at risk is acted on as quickly as we can, not at the end of a fifteen-day clock.
If we do not satisfy you, you may escalate to the Data Protection Board of India, which is the authority established under the DPDP Act to hear exactly these complaints. You are also free to pursue any other remedy the law gives you. Nothing in this policy takes away a right you have under Indian law.
tieHearts is for adults. You must be 18 or over.
This is not a preference. Under the DPDP Act anyone under 18 is a child, and processing a child’s data lawfully requires verifiable parental consent along with a ban on tracking and on behavioural advertising directed at them. Google Play’s policies additionally restrict apps whose function conceals a user’s identity from being available to minors. tieHearts is not designed for children, is not directed at them, and we do not want their data.
We are honest about the limit here, because a policy that pretends otherwise is worth nothing. A date-of-birth gate is the standard the law and both app stores require of a service like ours, but it is a declaration, and a determined person can lie to it. We do not currently demand government ID, because collecting identity documents from everybody to catch a few would create a far larger privacy risk than it solves — and the DPDP Act’s own principle of data minimisation points the same way.
So we treat a false declaration as something to detect and undo:
If you are a parent or guardian and you think your child has an account here, email the Grievance Officer. We will treat it urgently, and we will not ask you to jump through hoops to be believed.
No service can promise it will never be breached, and we are not going to pretend to. What we can promise is that we hold as little as possible, so that there is as little as possible to lose — which is why there are no photographs, no contact lists and no location data anywhere in this document.
If a personal data breach occurs, we will notify each affected person and the Data Protection Board of India in the manner and within the timelines the DPDP Rules require. Our notice to you will describe, in plain language, what happened, what data was involved, what we have done about it, and what you should do.
If this policy changes in a way that affects you, we will update the date at the top and tell you in the app before the change takes effect. If a change requires fresh consent under the DPDP Act, we will ask for it rather than assume it. We will never make a change retroactive.
Anything at all: developertiehearts@gmail.com.
For a formal complaint, address it to the Grievance Officer at the same address and say so in the subject line, so the 24-hour and 15-day clocks in section 11 start properly.