LEGAL INFORMATION
Privacy notice
How Woven Loves collects, protects and uses account, relationship, AI and device information.
Effective and last updated: 1 September 2026
Who we are
Woven Loves is operated by Digital Marketplace Designs, which is the controller responsible for the personal information described in this notice. Privacy and data-rights enquiries can be sent to [email protected].
This notice applies to the Woven Loves website, installable web app, account features, AI guide, support interactions and related communications worldwide.
Account and profile information
We collect the email address, display name and password hash used to create and protect an account. We may also store email-verification status, pronouns, relationship stage, timezone, onboarding choices and feature preferences.
We do not store your readable password. Passwords are processed using a one-way password hash.
Relationship and app information
We process relationship membership and invitation activity, Daily Five and Question of the Day responses, private Explorer responses, preferences and boundaries, compatibility signals, quests, rewards, saved content, notifications, progress and app interactions.
Some information may reveal intimate life, sexual orientation, wellbeing or other sensitive aspects of a relationship. Where applicable law requires it, we rely on explicit consent for this sensitive processing. Because personalisation and AI are core parts of Woven Loves, withdrawing that consent may mean closing the account.
Private and shared spaces
Each person has a separate account. Private Explorer answers and private AI-guide conversations are not automatically shown to other relationship members. Shared relationship features use deliberately shared information or permitted derived signals.
No technical system can prevent someone with access to your unlocked device from seeing its screen. Keep passwords and signed-in devices private and never pressure a partner to reveal a private space.
AI processing
Messages sent to the private guide, permitted relationship context and generated responses are processed to provide the AI feature. Private guide content is encrypted at rest in Woven Loves and decrypted only when needed to provide or display the feature.
Relevant information is transmitted securely to our AI service provider to generate a response. We also keep limited usage information such as model, token counts, estimated cost, whether a safety rule blocked a request and time of use. AI can be inaccurate and is not medical, legal, therapeutic, safeguarding or emergency advice.
Device, security and notification information
We process server-side session identifiers, hashed device-session tokens, IP address, browser or device information, login and security-event metadata, rate-limit information and timestamps to protect accounts and investigate misuse. Security events deliberately exclude passwords, authentication tokens and private relationship content.
If Push is enabled, we store an encrypted browser subscription and a digest of its endpoint. The browser or operating-system push service also processes delivery information under its own privacy terms.
Why we process information
We use information to authenticate accounts, provide the trial and subscription, manage relationship membership, provide private and shared features, generate AI responses, calculate compatibility and progress, deliver notifications, support users and process rights requests.
Our lawful bases include contract for core service delivery; explicit consent where sensitive information requires it; consent for optional marketing and non-essential analytics; legitimate interests in security, fraud and abuse prevention and reliability; and legal obligation where records must be kept or disclosed.
Safety checks and human access
Woven Loves applies automated scope and safety rules to AI requests and responses, including crisis wording and unsafe model output. These checks are not continuous human monitoring and Woven Loves is not an emergency service.
Authorised people may access the minimum information necessary to respond to a report, investigate security or abuse, comply with law or provide support. Access must be restricted and is not used for advertising or ordinary shared relationship recommendations.
Marketing and analytics
We may send marketing email only where the recipient has opted in or another lawful permission applies. Marketing choices do not affect core service access and every marketing message will provide an unsubscribe method. Account, security, billing and service messages are not marketing.
Woven Analytics uses a limited first-party statistical layer on public pages to count visits, pages, referral sources, selected campaign labels and coarse country information without creating an analytics visitor identifier. If the visitor actively accepts optional analytics, a signed random identifier also allows public-page events to be linked into anonymous journeys and unique-visitor counts. It does not record query strings, raw IP addresses, full browser user-agent strings, account identifiers, private relationship answers, private Explorer or intimacy content, or Private Guide messages.
Analytics page-view and visitor records are retained for up to 180 days. A visitor can reject analytics initially or withdraw later through Cookie settings without losing core service access. Withdrawing analytics removes the analytics identifier and the linked first-party page-view record where it can still be linked to that identifier. We do not sell private relationship information or AI conversations.
Who receives information
We disclose only what is necessary to providers supporting hosting, security, AI generation, email delivery, Push notifications, customer support and payments. Stripe processes checkout and payment information; Digital Marketplace Designs receives the subscription and billing records needed to administer the service. We do not store full payment-card details.
We may disclose information to professional advisers, regulators, courts, law enforcement or a successor business where lawful and necessary. Other active relationship members receive only information made available through shared relationship features and the privacy boundaries above.
International processing
Woven Loves is offered worldwide and some providers may process information outside the United Kingdom or the country where a user lives. Where required, we use adequacy regulations, approved contractual safeguards or another lawful transfer mechanism.
Retention and deletion
Active account and relationship information is kept while the account is used. Encrypted AI content is kept until the user deletes the relevant content or account. Temporary AI caches expire automatically. Support correspondence is normally deleted after 12 months.
Following a verified deletion request, active account, profile, private relationship and AI information is targeted for deletion within 30 days. Encrypted backups expire through the backup cycle within 30 days. Minimal payment, tax, fraud, dispute or legal records may be kept longer where required, including records held independently by Stripe.
Your choices and rights
Depending on location and lawful basis, users may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. Requests can be sent to [email protected]. We may verify identity before acting and will respond within the period required by applicable law.
UK users may complain to the Information Commissioner's Office at ico.org.uk. People elsewhere may also complain to their local privacy regulator. Mandatory local rights are not reduced by this notice.
Age limit and changes
Woven Loves is designed only for adults aged 18 or over. We do not knowingly permit children to create accounts. If we learn that an under-18 account exists, we may deactivate it and delete associated information.
We may update this notice when the service, providers or law changes. Material changes will be communicated in the app or by email where appropriate, and the date shown on this page will be updated.
Policy version 1 September 2026