Privacy Policy

Last updated: September 18, 2025

This Privacy Policy describes how TwoGether ("Company", "we", "us", or "our") collects, uses, discloses, and protects information when you use the TwoGether mobile application and related services (the "Service" or "App"). It also explains your privacy rights and how the law protects you.

By using the Service, you agree to the collection and use of information in accordance with this Policy.

1) Interpretation and Definitions

  • Account: A unique account created for you to access our Service.
  • Affiliate: An entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of the shares or other securities entitled to vote.
  • Application: TwoGether, the software program provided by the Company.
  • Company: TwoGether (also referred to as "we", "us" or "our").
  • Device: Any device that can access the Service, such as a smartphone or tablet.
  • Personal Data: Any information relating to an identified or identifiable individual.
  • Service: The Application and related functionality.
  • Service Provider: Any natural or legal person who processes data on behalf of the Company (e.g., Supabase, RevenueCat, Apple/Google billing, Expo push infrastructure).
  • Usage Data: Data collected automatically, generated by the use of the Service or the Service infrastructure.
  • You: The individual using the Service, or the company or other legal entity on whose behalf the individual is using the Service, as applicable.

2) What We Do

TwoGether helps paired users collaborate through shared to-do lists, calendar events, and messages. The App supports push notifications and optional premium subscriptions managed through Apple App Store/Google Play via RevenueCat. The backend uses Supabase for authentication, database storage, real-time channels, and Edge Functions.

3) Types of Data Collected

Personal Data

  • Email address (for authentication via sign-in codes)
  • Display name and avatar (optional)
  • Pairing information (pair codes, expirations, partner pair membership)
  • Subscription/entitlement status from RevenueCat
  • Notification preferences (messages, tasks, events, deadlines, reminders, suggestions)

Content You Provide (shared with your partner when paired):

  • Messages between paired users
  • To-do lists and tasks
  • Calendar events and event types

Usage Data

  • IP address; device type; OS; app version; language/locale
  • Mobile identifiers (e.g., IDFV/Android ID where accessible), Expo push token
  • Timestamps, session activity, crash/diagnostic logs
  • Limited presence/activity metadata to optimize notifications

4) Sources of Information

  • Directly from you (account setup, pairing, messages, tasks, events)
  • From your device (push token, diagnostics, Usage Data)
  • From Service Providers we use to operate the Service (e.g., RevenueCat, Supabase, app stores)

5) How We Use Information

  • Provide, operate, and improve the Service
  • Deliver notifications via Expo push
  • Manage subscriptions and entitlements via RevenueCat
  • Provide support, ensure security, prevent abuse, and enforce terms
  • Comply with legal obligations

Legal bases where applicable (EEA/UK/Switzerland): contract, legitimate interests, consent where required, legal obligation.

6) Use of Your Personal Data (Expanded)

  • Provide and maintain the Service; monitor usage
  • Manage your Account and access
  • Perform contracts (including subscriptions)
  • Contact you about Service updates and security notices
  • Provide news/offers where permitted or with consent
  • Manage your requests and support
  • Business transfers evaluation
  • Analysis and Service improvement

7) Sharing of Information

  • With your paired partner: intended shared content
  • With Service Providers: Supabase, RevenueCat, Apple/Google, Expo push
  • Business transfers and affiliates
  • Business partners where applicable
  • Legal compliance and protection
  • With your consent

We do not sell your Personal Data.

8) Disclosure Grounds (Detail)

  • Business transactions (merger, acquisition, asset sale)
  • Law enforcement requests
  • Other legal requirements (comply, protect rights, safety, prevent fraud, liability)

9) Security

  • HTTPS transport; Supabase-managed storage
  • Messages may be stored in plain text and are not end-to-end encrypted; avoid sensitive content
  • No method is 100% secure

10) Data Retention

  • Retained while your Account is active and as needed to provide the Service
  • Upon deletion requests, backend attempts to remove pair-scoped content and profile; some records may be retained
  • Retention varies by data type and legal requirements

11) International Transfers

We and our Service Providers may process and store information in the United States and other countries with different data protection laws. Where required, appropriate safeguards are used.

12) Your Choices and Rights

  • Notifications: manage in-app and OS settings
  • Profile and preferences: update in the App
  • Email changes: synced via secure webhook
  • Data requests: access, portability, correction, deletion, restriction, objection
  • How to exercise: contact gettwogether.com/support

Regional rights (illustrative): EEA/UK/CH supervisory authority; California CCPA/CPRA rights. We do not sell your Personal Data.

13) Delete Your Personal Data

You may request deletion via the App or by contacting us. We will assess and process your request, subject to legal exceptions and technical constraints.

14) Children’s Privacy

The Service is not directed to children under the age of 16 (or the age of digital consent in your jurisdiction). If we learn a child provided Personal Data, we will take appropriate steps to remove it.

15) Links to Other Websites

The Service may contain links to third-party websites or services not operated by us. Review their privacy policies before providing information.

16) Third-Party Services

Your use of app stores (Apple/Google) and RevenueCat is subject to their privacy policies and terms. Notification delivery uses Expo push services; their processing is subject to their terms.

17) Changes to This Policy

We may update this Policy and will post the updated Policy in-app or on our site with an updated "Last updated" date. Where required by law, we will notify you before changes take effect.

18) Contact Us

For questions about this Policy, data requests, or complaints, contact: gettwogether.com/support

19) Controller Information

TwoGether is the controller of your Personal Data processed through the App. Additional details provided upon request via the contact method above.

20) Automated Suggestions Disclosure

The App may send opt-out suggestions (e.g., weekend planning prompts) based on simple logic (e.g., empty shared calendar on a weekend). You can disable suggestions in notification settings.