Alovy — Privacy Policy
This Privacy Policy explains what personal data Alovy collects, why, how long we keep it, and the rights you have over it, in line with the EU General Data Protection Regulation (GDPR) and the Bulgarian Personal Data Protection Act (Закон за защита на личните данни, LPPD).
1. Who this policy covers
This policy applies to anyone using the Alovy mobile or web application, as a Looker (Parent/Owner), a Sitter (Babysitter/Petsitter), or both.
2. Who is the controller
The company that will operate Alovy is being established, and this section will name it — its legal name, registered address and company number (ЕИК) — before the app is released publicly. While this draft is in testing, there is no controller to name yet, and this policy is shown for information rather than as a contract.
3. What we collect, why, and on what legal basis
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Account data | First/last name, email, password (hashed), auth session | Create and run your account | Contract necessity (Art. 6(1)(b)) |
| Profile data | Sitter bio, rate, service city/radius | Operate sitter/looker matching | Contract necessity |
| Verification data | Phone number + verification status; ID-check pass/fail + provider reference (never the document itself) | Enable the Sitter role; trust & safety (§6 of the Terms) | Contract necessity / legitimate interest (platform safety) |
| Care Profile data — includes CHILD DATA | Baby’s/pet’s first name, age/birth info, mode | Let you track routines and request sitting | Consent of the parent/legal guardian who holds parental responsibility (Art. 6(1)(a)) — see §10, Children’s Data |
| Routine / health-adjacent data | Feeding, sleep, medication schedule, vaccinations, weight, potty/toilet logs | The care-tracking feature itself | Explicit consent, special category (Art. 9(2)(a)) |
| Avatars | Your profile photo | Shown across the app (public bucket, one photo per user, overwritten on re-upload with no recovery — D25) | Consent / contract necessity |
| Baby photos | Any photo you attach to a baby Care Profile | Your own private record | Not collected — stored only on your device, never uploaded to our servers (see §4) |
| Pet photos | Any photo you attach to a pet Care Profile | Your record; also shown to a Sitter whose booking is about that pet | Consent / contract necessity — private storage, readable only by you and that booked Sitter (see §4) |
| Chat messages | Conversation text between a Looker and a Sitter | Enable booking-related communication | Contract necessity + legitimate interest (safety/reporting review) |
| Booking data | Requested/accepted times, rate discussed, status | Run the booking lifecycle | Contract necessity |
| Location during an active booking | Live GPS position (post-MVP feature) | Consent-based live sharing during a specific booking, streamed only while the parent’s map is open, never stored | Explicit, per-booking consent (Art. 6(1)(a)) |
| Device-calendar events | — | We do not collect this. See §6. | N/A |
| Push notification tokens | Device push token | Deliver push notifications you’ve opted into | Consent / legitimate interest |
| Ratings & reviews | Star rating + optional comment | Trust signal shown to other users | Contract necessity / legitimate interest |
| Support/feedback submissions | Your message, app version | Respond to problems/feature requests | Legitimate interest |
| Payment data | — (not collected yet) | Future — will be added when in-app payments launch | To be determined |
4. Routine data and baby photos: zero-knowledge and device-only
These are the strongest privacy guarantees in the product, and we describe
them precisely so we never claim more — or less — than is true
(D62/D69/D156/D157).
- Baby photos never leave your device at all (
D156): any photo you attach to a baby Care Profile is stored only in the app’s private storage on your own phone. It is never uploaded — our systems refuse such an upload even if the app misbehaved — so we could not show, leak, or hand over these photos even in principle: we never receive them. The flip side: baby photos do not sync to another device and are gone if you delete the app or lose the phone — you can always re-add them. - Pet photos (
D157) are different on purpose, because a pet’s photo is not sensitive personal data and is useful to the Sitter you book: they are uploaded to private storage readable only by you and by a Sitter whose booking is about that pet — never public, never browsable. - What encryption protects: routine-tracking entries (sleep, feeding, medication, and the rest) are encrypted on your own device, before they are ever sent to our servers, using a key that only you control.
- How key recovery works, in plain terms: a random encryption key is generated the first time you use routine tracking. That key is itself locked (“wrapped”) using a second key derived from a recovery passphrase that you create and must save yourself. We store the wrapped key, never the passphrase. Logging in on a new device means entering that passphrase, which unlocks the key locally on your device — the passphrase itself never reaches our servers.
- What this means for us: Alovy cannot read your routine entries — not casually, not if asked internally, and not in response to most data requests, because we do not hold the key. Baby photos we cannot read for a simpler reason: they are never sent to us.
- What this means for you: if you lose every device you’re logged into and your recovery passphrase, this data is permanently unrecoverable — we cannot help, no matter who asks. The app warns you about this clearly when you set up routine tracking.
Sitter session logging (D73): during an active, accepted booking, a
Sitter can log routine entries (feeding, sleep, etc.) that appear
automatically in the parent’s history. These entries are encrypted by the
sitter’s device directly to the parent’s own key, so only the parent can
read them — the sitter keeps no readable copy after the booking ends.
5. Chat
Chat messages are encrypted in transit and encrypted at rest. Chat is
not end-to-end encrypted. By default, only the two participants in a
conversation can read it — Alovy does not give staff standing access. If a
conversation is reported, a member of our team may review it through an
audited, logged process reserved for that purpose (D67). Message text
never appears in logs, analytics, or crash reports.
Push notifications for new messages can show a preview of the message
text — this is a setting you control, and it defaults to on (D77). When
enabled, that preview text passes through Apple’s, Google’s, and Expo’s
push-delivery infrastructure to reach your device.
6. Location
Two very different things are both called “location” in Alovy, and we keep them clearly separate:
- Coarse location for matching: a Sitter’s service area is stored as a city plus a radius — never a home address — used to match Sitters and Lookers by distance. This is stored as long as your account/sitter profile is active.
- Live location during a booking (post-MVP feature): with your
explicit, per-booking consent, your precise GPS location can stream live
to the other party only while their map screen is open, for the
duration of one active booking. It is never stored — it is a live
broadcast only, with no location history kept (
D75/D80/D83).
7. Device calendar — what we deliberately don’t collect
If you use Alovy’s Calendar tab, the app can read events from your phone’s
own Google/Apple calendar to display them alongside your Alovy bookings.
These events are read locally on your device for display only and are
never transmitted to or stored on Alovy’s servers (D88/D100). The
only calendar-related data that flows in the other direction is one you
initiate yourself: when you accept a booking, you can choose to have that
booking’s details written into a calendar in your own Google/Apple
account, so it follows you across your own devices (D97). Your Care
Profile’s routine schedule is never exported to any external calendar,
under any circumstance (D100).
8. Who we share data with (processors)
We do not sell your personal data to anyone, ever.
| Processor | What for | Where | Notes |
|---|---|---|---|
| Supabase | Database, authentication, file storage, server-side functions | EU — Stockholm (eu-north-1) (D93) | Our primary infrastructure; EU-resident by design |
| Didit | Optional Sitter ID verification (D339, replaces Stripe Identity 2026-09-11) — document + selfie processed by Didit; Alovy keeps only a session reference and the result | — | — |
| Expo (push notification service) | Delivering push notifications (D63) | Routes through Apple Push Notification service and Google Firebase Cloud Messaging | — |
| Resend | Transactional email + the in-app feedback form (D54) | — | Get DPA before launch |
| Sentry | Crash/error monitoring, production builds only (D44 → built D363, 2026-09-14) | — | — |
| Google / Apple | Sign-in (SSO, D29); destination for your own calendar export/sync (D97) | Global | — |
9. How long we keep data
- Chat: kept long-term while your account and the conversation exist,
matching the retention rules in
docs/features/chats.md(D35). Typing indicators last seconds; presence is never stored; undelivered realtime events expire within minutes. - Routine data: kept (encrypted) until you delete your account or the specific entry.
- Baby photos: exist only on your device (§4). Deleting the profile removes the photo, and deleting your account also wipes the app’s local photo store on that device.
- Pet photos: kept in private storage until you replace them, delete the profile, or delete your account (erasure removes the stored files).
- Live location: never stored, at any time — broadcast only (§6).
- Verification data: kept while your Sitter role is active.
- Account deletion: deleting your account (guarded by a fresh one-time
OTP,
D33) triggers full erasure — your account, care profiles, routine data, chats, avatar, and any other stored content are permanently deleted, including from file storage. You can also ask by email from the address you signed up with; we confirm with you at that address and erase within 30 days (D374). - Ratings you gave (
D373): the review text is deleted with your account. The stars you gave remain inside the other person’s overall score only as an anonymous count (a running total and a number of ratings on their profile) — nothing in it identifies you. Ratings you received are deleted with your account.
10. Children’s data — read this section carefully
This is the part of Alovy’s privacy design we take most seriously.
-
Alovy’s accounts are for adults. Children are never Alovy account holders. Sitters must be 18 or older (
D66).self-declaration unless the Sitter completes the currently optional ID verification (
D19/D50). This is a genuine gap between the product’s policy and its enforcement mechanism — flagged as an open question indocs/legal/README.md. Please advise whether ID verification (or another age-check mechanism) needs to become mandatory before public release. -
Data about a child — a baby’s Care Profile — is entered and controlled by that child’s parent or legal guardian, who is the one giving consent for us to process it and who is responsible for what they enter. Our relationship for this data is with the parent, not the child.
that GDPR Art. 8 (which concerns a child’s own consent to being offered an information-society service directly) does not apply here, since children never hold Alovy accounts or give consent themselves. This confirmation is central to
D46’s “children’s data first” mandate and should not be left as an engineering assumption. -
Baby photos and identity are never shown publicly or to any other user, under any circumstance. Baby photos are never even uploaded — they exist only on the parent’s own device (§4,
D156). Anywhere another user might see some visual context — a discovery card, a sitter’s view of a booking, a chat — they see only the parent’s own avatar and an age band (e.g. “6–12 months”), never the child’s photo or full name (D24/D52). -
Health-adjacent fields (medication, vaccination records) require your explicit, separate consent, and are additionally protected by the zero-knowledge encryption described in §4.
-
Deleting your account deletes all Care Profile and routine data for every child profile under it (§9).
to use (an explicit checkbox: “I am this child’s parent or legal guardian and I consent to Alovy processing their data as described here”) is legally sufficient, or whether something stronger is needed.
11. International transfers
Our core infrastructure is EU-hosted (Supabase, Stockholm — §8). Several supporting processors are outside the EU and are flagged in §8 pending confirmed transfer mechanisms (Standard Contractual Clauses or an adequacy decision, as applicable).
12. Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data;
- Erase your data (in-app: Security → Delete Account, guarded by a
one-time OTP,
D33— see §9 for what “erasure” covers); - Restrict or object to certain processing;
- Withdraw consent at any time, where processing relies on consent (this won’t affect processing done before you withdrew it);
- Data portability, where technically applicable;
- Lodge a complaint with Bulgaria’s supervisory authority, КЗЛД (Комисия за защита на личните данни / Commission for Personal Data Protection).
To exercise any of these rights beyond in-app account deletion, contact us — see §14.
13. No sale of personal data
We do not sell your personal data to third parties, and we never will.
14. Contact
A dedicated privacy contact address will be published here together with the controller’s details (§2), before public release. Until then, you can reach us through the feedback form in the app: Profile → Help.
15. Changes to this policy
We will update this policy as the product changes, and we’ll notify you of material changes before they take effect. The effective date will always be shown at the top of this document.
v0.2 — added 2026-09-23
Everything above is the v0.1 draft of 2026-08-20. Since then the product gained places and precise coordinates, a record of how often an account opens the app, a money notebook, a staff console and a website. Each gets its own section below, numbered on from §15 so nothing above renumbers. §8’s processor table is amended in §22 rather than rewritten in place.
16. Where you are: cities, areas and precise coordinates
Alovy now knows three different things about “where”, and they are not the same:
- A place you picked. A city (“Пловдив”) or an area inside one (“Каменица 1”). It is a public place, not an address, and it is stored on your listing, your work period or your post so that people can find you. An area is more precise than a city, so the app says exactly that where you pick one, and picking one is always your choice.
- A position your phone took. Tapping “Use my location” reads your device’s coordinates ONCE to work out which area you are in. That reading stays on your phone unless you switch on “share my exact position” — and even then it is stored in a table only you can read (row-level security ties each row to its owner), never returned to anybody else.
- A distance. What other people see is a distance and its kind (”≈ 550 m from you”, ”≈ 2 km · Каменица 1”) — never a coordinate, never a point on a map. The distance is computed on the server from positions it will not disclose.
Live location during a booking (§6) is unchanged: a stream, never a history.
17. How often you open the app
To pay a referral only for accounts that are really used — and so that one person with two e-mail addresses cannot farm free months — we record one row per account per calendar day on which the app is opened. It holds the account id and the date, nothing else: no times, no screens, no location. The rows are not readable through the app by anybody, they are counted only by the referral rule, and they are deleted automatically after 180 days.
18. Records of money between a Looker and a Sitter
Alovy processes no payments (Terms §20). What we store is what the two of you enter: an hourly rate and its changes, the hours each day with who confirmed them, payments logged and their confirmation or dispute (with the reason you give), and an append-only history of those events. Both participants can read all of it; nobody else can, and no client can edit or delete an entry once written.
Retention follows the booking: these records live as long as the booking does, and go with it when either account is erased (§9).
19. Staff access and the admin console
A small number of people can use an internal console to run the service: answering account-deletion requests, handling reports, correcting translations, changing feature settings. Access is role-based, every role’s powers are explicit, and every action is written to an audit log that names the operator, the action and when. Staff do not have, and cannot obtain, the keys to your encrypted routine data, and cannot read message bodies.
20. The website, and cookies
alovy.care is a static marketing and support site. It sets no
cookies, runs no analytics, and embeds nothing from a third party.
The only thing it stores in your browser is your light/dark choice, in
localStorage, and only once you change it. Because that is strictly
necessary to provide the appearance you asked for and is never read by
us, we understand no consent banner to be required (Art. 5(3) ePrivacy,
as transposed in Bulgaria).
21. Automated decisions
Nothing in Alovy makes a decision about you with legal or similarly significant effect without a person. Search results are filtered and ordered by criteria you choose (the parameters are described in Terms §22); a coverage percentage is arithmetic over times you both entered; identity verification is decided by our verification provider on a document you chose to submit, and its outcome only adds or withholds a badge.
Alovy contains no artificial-intelligence system: nothing in the app profiles you, predicts anything about you, or generates a recommendation from a model. Search ranking is a sort over fields you can see.
22. Processors — amendments to §8
In addition to the table in §8:
| Processor | What for | Where | Notes |
|---|---|---|---|
| Google Maps Platform | Place search and details for the city/area picker, and one reverse geocode when you tap “Use my location” | Global | — |
| RevenueCat (when store billing goes live) | Subscription state for Alovy Plus | USA | — |
| Cloudflare Pages | Hosting the static website and the deletion-confirmation page | Global edge | — |
| Apple / Google (sign-in) | Native sign-in with your Apple or Google account | Global | They act as independent controllers of their own account service; we receive an identity token and your e-mail |
