Privacy Policy
Last updated: 26 August 2026
This policy explains what Twoly collects, why, who else ever sees it, and what you can make us do about it. It is written to be read. Where the law requires a specific phrase we've used it, but nothing here is hidden in it.
Twoly is operated by Xspark LLP (LLPIN LLPIN), registered office REGISTERED_OFFICE, India. Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") we are the Data Fiduciary for your personal data and you are the Data Principal. Under the GDPR-style vocabulary used elsewhere, we are the data controller.
Contact for anything in this policy: xsparkllp@gmail.com
1. The short version
- We collect what the app needs to show two people to each other, and close to nothing else.
- We do not sell your data. We do not run ads. There are no advertising SDKs, no advertising identifiers, and no cross-app or cross-site tracking in Twoly.
- We do not use third-party analytics or attribution SDKs in the app. If that ever changes we will update this policy and say so in the changelog at the bottom.
- Location and battery sharing are off until you turn them on, and are coarse by design.
- Your phone number is used to sign you in and for nothing else. We never send marketing SMS.
- You can delete your account and everything in it, from inside the app or from the web, without emailing anyone.
2. What we collect
Everything below is either given by you or generated by your use of the app. We do not buy data about you, and we do not scrape it.
2.1 To create your account
| Data | Why | Can you avoid it? |
|---|---|---|
| Phone number | The only thing we use to sign you in, via a one-time code. It is also how a person is identified across a re-install. | No — it is the account. |
| Your name (whatever you type; a first name or a nickname is fine) | Shown to the one to three people you connect with. | No, but it does not have to be your legal name. |
| Your mascot — its look and colour | It's your face in the app. | No, but the defaults are fine. |
| Friend code (six characters, generated by us) | The only way anyone can connect to you. | No. |
2.2 About your relationship
| Data | Why |
|---|---|
| Circle type — couple, friends, or solo | Changes the whole app: what it calls the middle tab, what emoji you can send, what the vow says. |
| Your partner's name, look, and your anniversary date — before they have installed anything | This is the "partner sketch". A couples app that shows an empty frame until the other person accepts loses almost everyone in that gap, so we let you build them first. See §2.7 — this is data about someone else. |
| Who you are connected to, and when you paired | The connection itself, and the "together N days" counter. |
| Whether each person is on your widget | Your choice, per person. |
2.3 What you publish (the actual product)
| Data | Notes |
|---|---|
| Your current activity — e.g. "in class", "chai", "commuting" | Picked from a list, or typed. |
| Your mood, and an optional word or phrase of your own instead of the preset label | Up to a short label. |
| A note, up to 80 characters | Free text. Written by you, read by the people you're connected to. |
| When it started | Powers "since 2h ago". |
| A history of the above | Append-only. It's what makes streaks, "together N days" and your story possible. Kept until you delete your account. |
| "Only my mood" mode | When on, your activity and note are not sent to anyone — they're withheld at the database, so the other person's app never receives them rather than merely hiding them. |
2.4 Optional device signals — each one off by default or switchable off
| Data | What we actually do with it |
|---|---|
| Approximate location | Only if you grant location permission and leave "share distance" on. Your coordinates are rounded to roughly 1 km before they leave your phone. They are used for exactly one thing: computing a distance between you and someone you're connected to, in the database, so that the only thing the other person's app ever receives is a number like 6.4. We never send anyone your coordinates, we never resolve them to a place name, and we do not keep a location history — the previous value is overwritten. Turn off "Share distance" in Settings and the field stops being sent at all. |
| Battery percentage | Only if "share battery" is on. It exists so a friend understands why you went quiet. A whole number, nothing else. |
| Your sleep and wake times | These are times you set, not sensor readings. Twoly does not read your health data, your screen-time, or your sleep tracking. |
We do not collect: your contacts, your photos, your messages, your microphone, your precise or background location, your browsing, your installed apps, your advertising ID, or your IP address for geolocation purposes.
2.5 Your settings and preferences
Bedtime, sleep goal, your sharing toggles, notification preference, and what you tapped on the "what do you want out of this" step during onboarding — that last one is kept because the app argues with you later in your own words rather than ours.
How we know which country to price you in: we read the region setting of your phone (via the operating system, with no permission prompt). Not your language, and not your IP address — we do not do IP geolocation. You can override it by hand in Settings, and once you do, we never change it again.
2.6 The vow
If you write a vow, we store its text (up to 200 characters), the language you wrote it in, and — if you signed it by hand — the stroke data of your signature, which is a list of coordinates, not an image.
Vows are append-only on purpose: neither you nor we can edit one after it's sealed, because a promise you can quietly rewrite isn't one. You can still delete it, by deleting your account — see §6.
2.7 Data about other people that you give us
Two things you can hand us that aren't about you:
- Your partner's name, appearance and your anniversary, typed before they join.
- A note or a vow that mentions them.
When you do this you are asking us to hold a small amount of another person's personal data on your behalf. Please only enter what you'd be comfortable with them seeing — because as soon as they join, they can see it, and it becomes theirs to change. If someone contacts us saying you've entered their details and they want them removed, we will act on that: see Grievance Redressal.
We do not ask for your contacts and we never upload an address book.
2.8 Subscription data
Twoly Pro is sold only through the Apple App Store and Google Play. That means:
- We never see, receive, or store your card, UPI, or bank details. Ever. Payment happens entirely inside Apple's or Google's systems.
- What we do receive, through our subscription provider RevenueCat, is: an anonymous customer identifier, which product you bought, which store, whether you're in a free trial, when it renews or expires, and the raw purchase event from the store. We keep the raw event because when a refund or a grace-period edge case surfaces months later, it is the only record of what the store actually told us.
2.9 Notifications
If you allow notifications, we store a push token for your device — an identifier issued by Apple or Google that lets a message reach your phone. It is not readable as your identity and we delete it when you sign out, revoke permission, or delete your account.
2.10 Technical logs
Our hosting provider keeps standard server logs (timestamp, request path, response status and an IP address) for a short period, for security and abuse prevention. We do not use these to build a profile of you, and we do not use IP addresses to determine your location for pricing or any product feature.
3. Why we're allowed to hold it (legal bases)
Under the DPDP Act we rely on your consent, given when you sign up and again — separately, per feature — when you turn on location or battery sharing or accept notifications. Consent is specific, informed, and withdrawable; §6 explains how to withdraw it, and withdrawing it costs you the feature, not the account.
Where a legal system in your country asks for it in different words (e.g. UK/EU), our bases are:
| Purpose | Basis |
|---|---|
| Creating and running your account; showing you and your people to each other | Performance of a contract |
| Location, battery, notifications | Consent (separately given, separately withdrawable) |
| Preventing abuse, spam and fraud; keeping the service up | Legitimate interests |
| Keeping financial records | Legal obligation (Indian tax and LLP law) |
We do not engage in profiling or automated decision-making that has any legal or significant effect on you. There is nothing in Twoly that scores, ranks or judges you.
4. Who else ever sees your data
4.1 The people you choose
The point of the app. Anyone you're connected to can see your name, mascot, status, mood, note, and — if you've left those switches on — your distance from them and your battery. That is it. They cannot see your phone number, your friend code, your other connections, your settings, or your subscription status.
4.2 Our processors
Four companies, each doing one job under contract, each forbidden from using your data for their own purposes:
| Who | What they do | Where |
|---|---|---|
| Supabase (database, sign-in, realtime) | Stores essentially everything in §2 | SUPABASE_REGION |
| RevenueCat, Inc. | Subscription state and receipt validation | United States |
| Expo (Expo Application Services) | App builds, over-the-air updates, and relaying push notifications to Apple/Google | United States |
| Apple Inc. and Google LLC | Distributing the app, taking payment, and delivering notifications to your device | United States and globally |
The fonts in Twoly are bundled into the app at build time, not fetched from a font CDN while you use it — so using the app does not quietly call Google.
We have no other SDKs, trackers, pixels, or partners in the app. We do not share your data with data brokers, advertisers, or "audience" platforms, and we never will.
4.2a Our website, trytwoly.com
The website is separate from the app, and it collects less. There are no cookies, no analytics, no pixels and no tracking scripts on trytwoly.com — you can check with your browser's network inspector. Two things do happen that we want to name plainly:
- Vercel Inc. (United States) hosts the site. Like every web host, its servers see the IP address and browser user-agent of each request in order to serve the page.
- The site loads the Baloo 2 and Nunito typefaces from Google Fonts (
fonts.gstatic.com), which means Google's servers see your IP address when a page loads. This is the one place the website differs from the app, where the same fonts are bundled in and no such request is made. We consider it a fair trade for a site that costs nothing to run; if you would rather not make that request, a content blocker will stop it and the pages stay perfectly readable.
There is no account, no login and no form submission on the website. If you email us from a link on it, that email lands in the mailbox in §11 and nowhere else.
4.3 Legal disclosure
We will disclose data if we are legally required to by a valid order from a competent Indian authority or court. We will resist requests that are overbroad or improperly served, and unless we are legally forbidden from doing so, we will tell you.
4.4 If the company changes hands
If Xspark LLP is acquired or merged, your data may transfer to the acquirer, bound by this policy. We'll notify you in the app before that happens so you can delete your account first if you'd rather.
5. Where your data goes (cross-border transfers)
Our database is hosted in SUPABASE_REGION. Some processors listed in §4.2 are in the United States, so some of your data is transferred outside India.
Section 16 of the DPDP Act permits transfers except to countries the Central Government has restricted; we do not transfer to any restricted country. For users in the UK or EU, transfers rely on the standard contractual clauses in our processors' data-processing agreements.
6. Your rights, and how to actually use them
Under the DPDP Act you have the right to:
| Right | How |
|---|---|
| Know what we hold and who we've shared it with | Email xsparkllp@gmail.com. We reply within 30 days. |
| Correct or complete it | Most of it you can edit yourself in the app. For the rest, email us. |
| Erase it | Settings → delete account, or the web form. See §7 for timing. |
| Withdraw consent | Every optional switch is in Settings and takes effect immediately. Withdrawing consent for location or battery stops the sharing; it does not delete your account. |
| Grievance redressal | Grievance Redressal — we acknowledge within 24 hours and resolve within 15 days. You may escalate to the Data Protection Board of India if we fail you. |
| Nominate someone | The DPDP Act lets you nominate a person to exercise these rights on your behalf if you die or become incapable of exercising them yourself. Email us the nomination and we'll record it against your account. |
If you are in the UK or EU you additionally have rights of access in portable form, restriction, objection, and complaint to your local supervisory authority.
We will never charge you for exercising a right, and we will never make the app worse for you because you did.
7. How long we keep things
| Data | Kept for |
|---|---|
| Your account and everything in §2.1–2.7 | While your account exists |
| After you delete your account | Removed from live systems within 30 days; purged from encrypted backups within 90 days |
| Push tokens | Deleted on sign-out, permission revocation, or account deletion |
| Server logs | Short-lived, for security only |
| Financial and subscription records | Up to 8 years, because Indian tax and LLP law require us to keep books of account. This is the one category we cannot delete on request — but it is receipts, not your notes or your vow. |
Deleting your account deletes your status history, your vow, your notes, your partner sketch and your connections. It does not delete the copy of a note your partner already saw on their screen, for the same reason deleting a WhatsApp message doesn't unsee it.
8. Security
- Everything is encrypted in transit (TLS) and at rest.
- Sign-in is a one-time code to your phone. There is no password to leak.
- Access rules are enforced in the database, not in the app: every table has row-level security, and the read that powers your home screen filters for privacy before sending — so a modified app cannot ask for your coordinates or your friend code, because the database will not return them. Your friend code has no read permission at all; it is checked once, by exact match, when someone redeems it.
- The free tier's daily limit on emoji is enforced in the database too, which is a small example of the same principle: a rule that lives in the app is a suggestion.
No system is perfect. If you find a vulnerability, please tell us at xsparkllp@gmail.com before telling anyone else — we will thank you properly and we will not threaten you.
If a breach happens, the DPDP Act requires us to notify both the Data Protection Board of India and every affected user. There is no "it was small enough to ignore" threshold, and we will not look for one.
9. Age
Twoly is for people aged 18 and over. You must be 18 to create an account, and we ask for confirmation at sign-up.
We do not knowingly collect data from anyone under 18. If we learn that an account belongs to someone under 18 we will delete it and its data. If you are a parent or guardian and believe your child has an account, email xsparkllp@gmail.com and we will remove it — no forms.
Why 18 rather than 13: the DPDP Act treats everyone under 18 as a child, requires verifiable parental consent for their data, and separately prohibits tracking and behavioural monitoring of children. Twoly is an app about presence between two people. We would rather be honestly unavailable to under-18s than pretend that consent box was meaningful.
10. Notifications and messages we send
- Transactional only by default. Sign-in codes, and the in-app notifications you asked for (someone sent you something, someone's status changed).
- No marketing SMS. No marketing email you didn't ask for. We do not have a marketing list.
- You can turn off every optional notification in Settings, and revoke the OS permission entirely at any time.
11. Changes to this policy
If we change this policy in a way that affects you, we will tell you in the app before it takes effect — not by silently re-dating this page. Every version is listed below.
| Date | What changed |
|---|---|
| 26 August 2026 | First version. |
12. Contact and complaints
| Data Fiduciary | Xspark LLP, LLPIN LLPIN |
| Registered office | REGISTERED_OFFICE |
| xsparkllp@gmail.com | |
| Grievance Officer | GRIEVANCE_OFFICER — see Grievance Redressal |
If we don't resolve your complaint, you can escalate to the Data Protection Board of India.