Trust & security
Built so the private stays private
Higher Love holds some of the most sensitive material two people have: how they fight, what they long for, what they haven't said out loud. This page explains exactly how that is handled — the legal basis, what the AI does and doesn't do, every point where you give consent, and the technical isolation behind it.
Your partner can never read what you write in Talk. Not a message, not a summary, not an excerpt. The only thing that ever reaches them is a card you have read and chosen to send.
What we process, and on what basis
- Controller. Higher Love is the data controller for your account, profile, quiz results, check-ins and conversations. Our infrastructure and AI providers act as processors under written agreements.
- Special-category data (Art. 9). Relationship conversations can reveal information about your sex life, health or beliefs. We treat everything you write in Talk as special-category data and process it only on your explicit consent, given when you create your account and again before any optional module.
- Contract & legitimate interest. Account, pairing and delivery of the service run on contract necessity. Security logging and abuse prevention run on legitimate interest, minimised to what is needed.
- Data minimisation. Birth data, human-design fields and everything in the cosmic add-on are off by default and simply not collected unless you switch them on.
- Your rights. Access, rectification, erasure, restriction, portability and objection. In-app you can already export or delete your birth data, clear your entire Talk history, and delete your check-ins — no request needed. For a full account export or deletion, contact us and we respond within 30 days.
- No selling, no ad profiling. We never sell relationship data, never share it with advertisers, and never use it to build advertising profiles.
You are always talking to a machine
- Disclosure. Talk, the weekly ritual reflections and every partner card are generated by a large language model. There is no human reading along, and no counsellor on the other side.
- What the model receives. Your first name, your partner's first name, your profile results (love language, attachment, conflict, apology) and the conversation you are having. Never your email, never your partner's private messages, never another couple's data.
- No training on your relationship. Your conversations are not used to train or fine-tune any model. They are sent for a single response and are not retained by the model provider for training.
- Not therapy, not diagnosis. Higher Love is an educational wellbeing tool. It does not diagnose, does not treat, and is not a medical device. Frameworks such as attachment theory and Gottman-style repair research inform the questions — they are not clinical assessments of you.
- It can be wrong. Language models make confident mistakes. Read every card before you send it — nothing leaves your side of the app automatically.
- Language integrity log. If the model answers in the wrong language, a guard rewrites it and records that event in a private audit log visible only to you. The log stores which handler ran and a short sample — never the full conversation.
- No emotional manipulation. We do not design streaks, guilt prompts or artificial urgency around your relationship, and the AI never pressures you to stay, leave or spend.
1. Creating your account
You agree to the privacy policy and to processing of relationship data. Nothing is shared with anyone until you take a further step.
2. Linking with a partner
Pairing is a two-sided action: one person creates an invite code, the other enters it. Linking reveals your first name and your profile results to each other — not your conversations. Either of you can unlink.
3. The cosmic add-on
Birth date, birth time, birth place and human design are shown only after an explicit consent screen with a clear skip option. Off by default, revocable any time, and exportable or deletable from your profile.
4. Sending a partner card
The AI drafts; you decide. Nothing is delivered until you press send on a card you have read in full. There is no automatic sharing, no scheduled digest, no background sync of your Talk.
5. Monthly check-ins
Your six monthly scores are visible to your linked partner so you can read the trend together — this is stated on the page before you answer. Your written note stays private to you.
6. Withdrawing
You can clear your Talk history, delete your birth data, turn off the add-on or unlink from your partner at any time, without losing the rest of your account.
Two private rooms and one doorway
Your private messages and your shared cards live in different tables with different access rules. There is no path in the app — and no query in the database — that lets one partner read the other's Talk. The only thing that crosses is a card you send.
YOUR SIDE PARTNER'S SIDE
┌──────────────────┐ ┌──────────────────┐
│ Talk messages │ │ Talk messages │
│ owner: you only │ ✕ no read path │ owner: them │
└────────┬─────────┘ └─────────┬────────┘
│ used as context │
▼ │
┌──────────────────┐ │
│ AI translation │ strips names, quotes, │
│ → partner card │ and anything identifying │
└────────┬─────────┘ │
│ you read it, you press send │
▼ ▼
┌───────────────────────────────────────────┐
│ Shared cards (the one doorway) │
│ readable by sender and recipient only │
└───────────────────────────────────────────┘- Row-level security, not app logic. Access is enforced in the database itself. The rule on the Talk table is simply: the row's owner must be the person asking. Even if a bug in the interface asked for your partner's messages, the database would return nothing.
- A translation layer, not a forwarding layer. Partner cards are written as a need and a suggested action, tuned to your partner's own styles. They never say "she told me", never quote you, and never reference the conversation they came from.
- Pair-scoped everything. Shared items — cards, rituals, check-in scores — are readable only by the two people in your pair, verified server-side against the couple link rather than trusted from the browser.
- Profiles are narrow by design. A partner can read your profile results and first name. They cannot read your email, your Talk, your check-in notes or your language audit log.
- Encryption in transit and at rest. All traffic runs over TLS and the database is encrypted at rest by our infrastructure provider. Credentials for the AI provider live only on the server and are never exposed to the browser.
- Breakups are handled. Unlinking removes the partner's read access immediately. Your private Talk was never theirs to begin with, so nothing needs to be clawed back.
We are not certified under SOC 2, ISO 27001 or HIPAA, and we don't pretend to be. Higher Love is not a substitute for couples therapy, and it is not appropriate for situations involving abuse or danger — in those cases please contact local emergency services or a specialist organisation. If you find a security issue, write to us and we will respond.
