Effective 27 September 2026

Who we are

TwoYes is provided by Rootsi Capital OÜ, Estonia. Privacy contact: support@devrootsi.com. This policy covers the iPhone and Android apps: local storage, couple sync, purchases, optional notifications and product analytics.

What stays on your device

Your optional surname, preferences and passes stay on your device. We store your discovery history, favourites, matches and cached Pro access in private app storage. The TwoYes home-screen widget reads your match count, swipe count and latest match name from the app’s own storage (an App Group on iPhone). Device backups (iCloud or Android backup) may contain local app data, including a random secret that lets a restored backup reconnect to your couple.

Finding your shared yes

When you create or join a couple, Supabase assigns a random anonymous user ID without asking for an email or password. Its session stays on your phone and is never included in backups: in the iOS Keychain on iPhone, encrypted with an Android Keystore key on Android. We store the couple’s code, its two memberships, a one-way hash of each member’s reconnect secret, Pro status and your yes votes to find mutual matches. Passes are not uploaded. Your partner cannot read your list of likes; the server returns only the names you both said yes to. Couples can pair across iPhone and Android. Keep your invitation code private.

Your one-time purchase

Apple (App Store) or Google (Google Play) processes payment. We do not receive your card details. To unlock Pro for both of you, the app sends the purchase’s transaction ID (Apple) or purchase token (Google) to our server, which confirms it with the store and records it with your couple. One purchase unlocks one couple. If the store refunds or revokes the purchase, Pro is removed. Pro is cached locally for offline access. Restore is available on the Pro screen and in Settings.

Optional notifications

After pairing, you can choose to receive partner activity and match notifications. If allowed, we store your device’s push token with your membership: an APNs token on iPhone, a Firebase Cloud Messaging token on Android. Notifications are delivered by Apple’s or Google’s notification service and never include a name. You can turn notifications off in your phone’s settings.

Understanding what works

The release apps send PostHog explicit product events such as onboarding choices, ten-swipe totals, pairing, match counts, completed shares, paywall views, purchases and app opens. Events include an anonymous user ID, couple ID when paired, Pro status and the platform. We do not send names you like, surname values, invitation first names, passes, contacts, advertising IDs or screen recordings, and client IP addresses are anonymised. You can turn analytics off in Settings → Share usage analytics. Development builds do not send analytics. There are no ads or cross-app tracking.

Sharing is your choice

The optional first name on an invitation is used only to render the image on your device. When you use the system share sheet, the selected image and, for invitations, code and join link go to the destination you choose. On iPhone, saving an image to Photos needs your permission and adds only that image. Other services apply their own privacy policies. External source links open only when you tap them.

Providers and retention

Supabase hosts couple data in the United States (us-east-1); PostHog’s ingestion host is in the EU. Apple and Google process payments and notifications under their own terms. We keep couple data while you use the shared collection. Leaving a couple deletes your likes in it; Settings → Delete my data deletes your couple data and anonymous account from our servers. Purchase records (transaction ID or purchase token, product, date, refund status) are kept for legal and restoration purposes.

Delete your data

In the app: Settings → Delete my data. This leaves your couple and deletes your likes, matches and anonymous account from our servers at once; your own phone starts fresh. Without the app (for example after uninstalling it): email support@devrootsi.com with the subject “Delete my TwoYes data” and, if you have it, the support ID from the app’s privacy screen. We delete the couple data and anonymous account within 30 days and confirm by email. Purchase records are kept as described above; everything else is removed.

Your choices and rights

We process sync and purchase data to provide the service you request, optional push data with your permission, and limited analytics to improve the app. You may request access, correction or deletion, object to analytics, or raise a privacy concern by emailing support@devrootsi.com; include the support ID shown in the app’s privacy screen. You may contact your local data protection authority, including Estonia’s Andmekaitse Inspektsioon. Deleting the app removes its local files, but does not itself delete server records.

Children and changes

TwoYes is intended for adults choosing names, not for children to use. We do not ask for a child’s identity, birth date or health information. If this policy changes, the updated version and effective date will appear here before the changed processing begins.