Your little space, respected

Your privacy

Effective 2026-09-15 · Taimur Khaliq

A little space, with clear choices

Luvu is a private app for you and your person, operated by Taimur Khaliq. This policy describes the current beta. We do not sell your personal information, show advertising, track you across other companies’ apps or websites, or build a public social profile.

Your account

When you continue with Apple, Apple supplies an identifier and may supply your name and email, including a private relay email if you choose Hide My Email. Luvu stores the information needed to maintain your account, your chosen nickname, sign-in sessions and your active avatar reference. Session credentials are stored in the iPhone Keychain. We do not receive your Apple password.

Choosing photos stays on your iPhone

Help me choose runs only when you ask. It uses Apple Photos and Vision on your device to suggest technically suitable portraits. It does not identify who a person is or create identity embeddings. You decide which photos represent you. Limited Photos access and manual selection are supported. Library scans and their thumbnails are not sent to Luvu, Google Gemini or OpenAI. Local scanning previews are temporary; your original photos are never modified.

Optional AI avatar creation

Creating a character from scratch works without uploading photos. If you choose AI creation, Luvu identifies the image provider and asks permission before sending your selected photos through its Google Cloud backend. Updated versions use Google Gemini to make an avatar with facial expressions; older versions and an optional developer flow use OpenAI. Only the photos you confirm and Luvu’s avatar instructions are sent for generation. Photo orientation is normalized, images are resized, and metadata is stripped before upload. The selected provider processes those images and returns generated artwork. Luvu does not send your Apple identity, nickname, partner information, notes or the rest of your photo library to either image provider.

Photo and avatar retention

Luvu removes temporary reference photos from its cloud storage after processing, failure or cancellation. A cleanup task normally removes interrupted uploads within 10–15 minutes; outages can delay cleanup. Prepared photos on your device may remain for up to a day so you can retry. Google Gemini and OpenAI have their own retention rules. Gemini requests use Google Cloud Vertex AI; Luvu does not claim zero provider retention. For OpenAI, API content is not used to train its models by default; abuse-monitoring records may be retained for up to 30 days, with safety or legal exceptions. Generated avatars, candidates and generation records are kept locally and in private cloud storage so already-created artwork is not accidentally lost. Cloud copies are removed when you explicitly delete your account; local artwork is retained. This is not a complete backup of your local library or customizations.

Connecting with your person

Luvu stores invitations, your two-person connection and selected-avatar sharing copies on Google Cloud. Someone who has your invitation can see your nickname before deciding to join. After an explicit Join, your partner can see your nickname and selected avatar. Original reference photos are not shared with your partner. Disconnecting removes access to the active connection; a previously downloaded avatar may remain in the other device’s cache until it reconnects or the cache expires, and Luvu cannot recall screenshots. Boards, earlier local moods and existing local history remain on your device. New activity and feeling updates are shared as described below.

Little glimpses of your day

Activities and feelings are shared only when you choose them. Luvu stores each selected activity or feeling, any custom activity or feeling text, its start and expiration times, and your current two-person connection on Google Cloud. Only you and your currently connected partner can access it. Custom feelings show the words you enter with a neutral avatar expression; Luvu does not infer sentiment or send them to an AI provider. Selecting Driving does not collect or share location; no sensors or automatic detection are used. Your phone keeps a protected copy of the latest known activity and feeling so it can show a saved update while offline; expired updates stop displaying. A disconnected device may retain that copy until it reconnects, signs out or the update expires. We keep at most 200 recent events per couple for each of activity and feelings for future shared memories; events older than 30 days are removed on the next read or write. Disconnecting or deleting an account removes the couple’s shared activity and feeling records. Signing out removes this device’s activity and feeling caches without deleting your avatars or local memories.

Sending and receiving love

Tapping Send love saves a private event identifying your connected couple, sender, recipient and time. It can be recovered inside Luvu even if a notification is disabled, delayed or lost. Automatic replay is limited to love sent in the previous 24 hours. Delivery and interaction records are scheduled for deletion after 30 days; cleanup delays may extend retention. Internal presentation acknowledgments help prevent repeated animations and are not shown to your partner as read receipts. Expired or replaced feelings and activities are not restored by opening an old notification. Nudges and their animations do not use AI generation.

Live hearts together

When Live hearts is enabled and you open your paired Home, Cloudflare operates the live connection. Starting a shared round requires both partners to choose to join. It processes opaque account, session, installation and couple identifiers, connection availability, heart taps, timing, round scores and celebration state. Our Google Cloud backend verifies that both people belong to the current connection. Live hearts does not send your photo library, reference photos, avatar artwork, nickname, activity or feeling text to Cloudflare and does not use AI or send a notification for each tap. Round and input records are scheduled for removal about ten minutes after a round ends; disconnected participation records are also temporary. Cleanup delays can extend retention. Minimal opaque room identifiers and revocation counters remain to prevent old connections from regaining access. Leaving Home or turning Live hearts off stops this device’s participation.

Your notification choices

Notifications are optional and request this iPhone’s permission. Luvu stores an APNs device token, installation identifier, account/session association and delivery configuration to route alerts to the correct device. Apple’s APNs processes notification payloads for delivery. You control incoming love, feeling and activity alerts separately. For a new account, these Luvu preferences start on, but iOS permission is still required; existing opt-outs are retained. Show details in notifications starts on when no preference has been saved. Alerts can include the shared activity or feeling, including custom words, subject to your iPhone’s preview settings. You can turn details off in Luvu’s Notifications settings to keep those words out of notification payloads. A saved choice to hide details is retained. Turning alerts off does not stop updates from appearing inside Luvu. Signing out detaches this device where possible and revokes its account session; offline cleanup is retried when connectivity returns. Already delivered notifications cannot always be recalled.

Service providers and diagnostics

Google Cloud hosts account, invitation, activity, feeling, love-event, notification and avatar services. Cloudflare operates Live hearts connections and temporary shared rounds. Apple handles Sign in with Apple, TestFlight distribution and APNs notification delivery. Google Gemini and OpenAI handle only optional AI image generation. Luvu stores generation status, timing, usage and error information to operate the service and control costs. Hosting infrastructure records request metadata, which can include IP addresses, request paths, status and latency. Application logs do not contain photo bytes, Apple authorization codes, session tokens, APNs device tokens or full notification text. If you contact support or send TestFlight feedback, we receive the information you choose to include, and Apple may provide beta crash or diagnostic reports. These services may process information in the United States and other countries where they operate.

Sign out, deletion and your choices

You can sign out or choose Delete Luvu account in Your account. Account deletion requires confirmation and Apple authorization. It removes your server account and profile, revokes sessions and ends the partner connection, including its shared activity and feeling records. Notification preferences and device registrations are removed; stored partner interactions and notification delivery records are removed or queued for retryable deletion. Cloud avatar copies, reference photos, generation details and partner-sharing copies are queued for deletion; temporary failures are retried. Minimal opaque cancellation receipts remain to prevent a delayed request from generating an avatar again, and service logs or provider safety records follow their separate retention rules. Local avatars, customization and saved moments remain on your iPhone to protect work you may have paid to create; signing out does not erase them. Contact us to request access, correction or deletion of personal data or for help with retained local files. We may ask for enough information to verify your request. Do not send your Apple password, sign-in codes or reference photos by email. Your original Photos library remains under your control in iOS Settings.

Who Luvu is for

Luvu is intended for adults in a private relationship and is not directed to children under 13. Please select only photos you have permission to use. If you believe a child’s information was provided to Luvu, contact us so we can investigate and address it.

Questions and updates

Contact the support and privacy email below with questions or requests. We update this policy as the product changes and show the effective date. Material changes to how optional photos are shared will require an updated explanation before upload.

OpenAI API data controls

Support & privacy: khaliq.taimur@gmail.com