Privacy Policy
Last updated: February 15, 2026
This Privacy Policy explains how HoldUs ("we," "us," or "our") collects, uses, and protects your personal information when you use our AI-powered relationship support service. Please read this policy carefully alongside our Terms of Service.
1. Information We Collect
1.1 Account Information. When you create an account, we collect:
- Email address (from Google OAuth)
- Name (from Google OAuth)
- Profile picture URL (from Google OAuth)
- Country of residence (selected during signup for geographic eligibility)
1.2 Onboarding Information. During setup, we collect relationship context to personalize your experience:
- Your gender and your partner's gender
- Your primary intent for using the service (e.g., save marriage, improve relationship)
- Relationship details you choose to share
1.3 Conversation Data. When you use our service, we collect and store:
- Messages you send to the AI assistant
- AI-generated responses
- Timestamps of conversations
- Conversation metadata (session identifiers)
1.4 Payment Information. If you subscribe to our paid service:
- Payment details are collected and processed directly by Stripe, Inc. We do not store your complete credit card information on our servers.
- We receive and store: subscription status, billing cycle dates, and transaction history (amounts and dates).
1.5 Usage Data. We automatically collect:
- Device information (browser type, operating system)
- IP address
- Pages visited and features used
- Date and time of access
- Referring website or source
2. How We Use Your Information
We use your information for the following purposes:
- Provide the Service: To deliver AI-powered relationship support, maintain conversation context, and personalize responses based on your conversation history.
- Account Management: To create and manage your account, authenticate your identity, and communicate with you about your account.
- Payment Processing: To process subscription payments, manage billing, and send payment-related notifications.
- Service Improvement: To analyze usage patterns, identify issues, and improve our service quality.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
- Safety and Security: To detect and prevent fraud, abuse, and security incidents.
3. Third-Party Service Providers
We share your information with the following third-party service providers who help us operate our service:
OpenAI
Purpose: AI response generation
Data Shared: Your messages are sent to OpenAI's API to generate AI responses. OpenAI processes this data according to their Privacy Policy and Terms of Use.
Stripe, Inc.
Purpose: Payment processing and subscription management
Data Shared: Email address, payment information (handled directly by Stripe). See Stripe's Privacy Policy.
Google (OAuth)
Purpose: User authentication
Data Shared: Authentication tokens. We receive your email, name, and profile picture from Google. See Google's Privacy Policy.
Mixpanel
Purpose: Product analytics and usage tracking
Data Shared: Anonymized usage events (page views, feature usage, conversion funnel steps), subscription status, and general user properties. We do not send personally identifiable information such as names or email addresses to Mixpanel. See Mixpanel's Privacy Policy.
Google Analytics
Purpose: Marketing attribution and advertising performance measurement
Data Shared: Page views, traffic sources, conversion events (signup, checkout, purchase), and anonymized browser and device information. This data helps us understand which marketing channels drive users to our service. We do not send personally identifiable information such as names, email addresses, or conversation content to Google Analytics. See Google's Privacy Policy.
Meta (Facebook) Pixel
Purpose: Advertising measurement and optimization
Data Shared: Page views, conversion events (signup, checkout, purchase), and anonymized browser and device information. This data helps us measure the effectiveness of our advertising campaigns. We do not send personally identifiable information such as names, email addresses, or conversation content to Meta. See Meta's Privacy Policy.
Railway
Purpose: Cloud hosting infrastructure
Data Shared: All service data is hosted on Railway's infrastructure. See Railway's Privacy Policy.
4. Cookies and Tracking Technologies
4.1 Essential Cookies. We use essential cookies that are necessary for the service to function:
- Authentication cookies: To keep you signed in and maintain your session
- Security cookies: To protect against cross-site request forgery and other security threats
- Preference cookies: To remember your settings (e.g., dark mode preference)
4.2 Session Storage. We use browser session storage to:
- Remember temporary preferences within a session (e.g., dismissed banners)
- This data is automatically cleared when you close your browser or sign out
4.3 Analytics. We use Mixpanel for product analytics and Google Analytics (GA4) for marketing attribution. Mixpanel collects anonymized usage events such as page views, feature usage, and conversion steps. Google Analytics collects traffic source data, page views, and conversion events to help us measure advertising performance. We do not send personally identifiable information to either service. You can opt out of analytics tracking by enabling "Do Not Track" in your browser settings.
4.4 Managing Cookies. Most web browsers allow you to control cookies through their settings. However, disabling essential cookies may prevent you from using certain features of the service.
5. Data Retention
We retain your information for the following periods:
- Account Information: Retained for as long as your account is active, plus a reasonable period after account deletion for legal and business purposes.
- Conversation History: Retained for as long as your account is active to provide contextual AI responses. Deleted upon account deletion or upon your request.
- Payment Records: Retained for 7 years to comply with tax and accounting requirements.
- Usage Data: Aggregated and anonymized usage data may be retained indefinitely for analytics purposes.
6. Your Rights and Choices
6.1 Access and Portability. You have the right to request access to the personal information we hold about you. You may also request a copy of your data in a portable format.
6.2 Correction. You may request that we correct inaccurate or incomplete personal information.
6.3 Deletion. You may request deletion of your personal information, including your conversation history. Please note:
- Some information may be retained for legal compliance
- Data already shared with third parties may not be retrievable
- Aggregated or anonymized data may be retained
6.4 Account Deletion. You may delete your account at any time through your account settings or by contacting us. Account deletion will result in the permanent deletion of your conversation history.
6.5 Communication Preferences. You may opt out of promotional emails by following the unsubscribe instructions in those emails. You cannot opt out of service-related communications (e.g., billing notifications, security alerts).
7. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You may request information about the categories and specific pieces of personal information we have collected, the sources of that information, our business purposes for collecting it, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale: We do not sell your personal information as defined by the CCPA.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
To exercise your CCPA rights, please contact us using the information in Section 11. We will verify your identity before processing your request.
8. Children's Privacy
Our service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
9. Data Security
We implement reasonable technical and organizational measures to protect your personal information, including:
- Encryption of data in transit using TLS/SSL
- Secure cloud infrastructure with access controls
- Regular security assessments
- Limited employee access to personal data
However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information.
Important: This service is NOT HIPAA compliant. Do not share information that you expect to be protected under HIPAA or other healthcare privacy regulations.
10. International Data Transfers
Our service is currently available only to users in the United States. Your data is processed and stored in the United States using our third-party service providers.
If you access our service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.
11. Contact Us
If you have questions about this Privacy Policy, want to exercise your rights, or have concerns about our data practices, please contact us:
Email: [email protected]
We will respond to your inquiry within 30 days, or as required by applicable law.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on our service prior to the change becoming effective.
We encourage you to review this Privacy Policy periodically for any changes. Your continued use of the service after any changes indicates your acceptance of the updated policy.