Privacy Policy
Last reviewed: 16 July 2026
Wovin is built around data minimization. We do not sell your personal data and we do not use third-party analytics SDKs in v1.
What stays on your device
Your journal, intake/focus choices, comfort-card contents, local comfort marks that are not a yes, limit details, reflection drafts, and Private Intimacy Map labels and unselected cards stay on your device unless you explicitly choose to share a reflection.
What syncs
Wovin syncs account identifiers, pair membership, shared step lock-state, minimal Repair Room coordination, opaque boundary category keys, positive comfort-card yes IDs, explicitly shared reflections, entitlement records, and invite codes. An opaque boundary key can select a neutral shared exercise; it never includes its human label, a private note, a reason, or who set it.
Repair Room and Quiet Return
Repair words, prompts, answers, and private notes stay on the device. For a real paired repair, Wovin stores only the shared stage, caller-owned readiness/restart state, completion count, revision, and session timestamps needed to coordinate the room. After a completed repair, a person may optionally choose one private return window. Wovin then stores only an opaque return-window ID (not its display words), completion count, revision, and expiry metadata. The choice itself contains no words, notes, reasons, identity, person-specific timing, or decline; no partner choice or timing is returned or exposed.
Quiet Return is retained for up to seven days, can be cleared by its owner, and is deleted on a mutual repair restart, pair pause, unpair, or account deletion. It sends no push notification, uses no AI or analytics, and creates no relationship score or diagnosis. A neutral card appears only when two private windows are compatible; it never explains why it is absent.
Private Intimacy Map
For a real paired adult couple, the optional Private Intimacy Map temporarily stores only the minimum pair/session timing and completion state plus opaque IDs for cards a person affirmatively finishes. It never receives card labels, written responses, rankings, or an unselected card as a decline or “not now” response. A shared starter appears only after both people finish; the map expires after 24 hours and either person can clear it to start fresh. A shared starter is not consent; partners must check in and ask again in the moment.
Shared reflections
Only reflections you explicitly share are sent to the server. Shared reflection bodies are encrypted before they are stored, using a server-side key that never leaves our infrastructure.
Delete and export
Your personal records are yours. Journal and history export stays free in the app. You can delete your account in the app, including before onboarding is complete. After the app receives confirmation, it erases Wovin data on that device and removes the account's server data: account and session records, any active Private Intimacy Map, active Quiet Return state, active pairing state, opaque boundary keys, authored shared reflections, entitlement records, and related invite and purchase records. Deleting an account does not cancel an Apple subscription; manage or cancel subscriptions in Apple Subscription Settings.
Contact
Email megan@twohearth.com.