Privacy Policy
Effective 2026-09-14
Closely is a shared conversation space for two partners. This policy explains what information Closely handles, why, who can see it, and the choices you have.
Information Closely stores
- Sign-in identity: Google or Kakao sign-in is connected through Supabase Auth. Closely stores your Supabase user ID, identity provider, supplied name and verified email when available, account creation time, and last sign-in time. Closely does not receive your password.
- The name you choose for your space and your settings: language, turn reminders, and whether you allow AI.
- Everything written in your shared space: messages, answers, passed questions, shared memories, personal ideas, and the replies Closely generates.
- Invitation tokens are stored as hashes and cannot be used after seven days. Using or replacing an invitation invalidates the previous token.
- AI usage records: the day, outcome, model, and token counts of each AI request. These records never include message text.
- A language preference cookie (closely-language) kept for one year, an HttpOnly sign-in cookie (closely_session) lasting up to 90 days, and a temporary sign-in cookie (closely_auth). The server stores session-token hashes and expiry/last-use timestamps. If you enable notifications, it also stores your device’s push subscription endpoint, encryption keys, and delivery results.
Closely does not collect location, contacts, photos, or advertising identifiers, and does not use analytics or advertising trackers.
How Closely uses information
- To show your shared space to you and your partner.
- To generate AI questions, reflections, and ideas when both partners allow it.
- To enforce daily usage limits and prevent abuse.
- To keep the service running. Server logs contain request metadata such as timestamps and status codes, not message text.
Your partner can read everything
A space belongs to two people. Messages, answers, memories, ideas, and the journal are visible to both partners for as long as the space exists. Closely never promises secrecy from your partner. Do not write anything in this shared space that you need to keep from them.
AI processing by OpenAI (international transfer)
When both partners have allowed AI, Closely sends the current conversation, both partners’ chosen names, the current question and answers, and any memories you both approved to OpenAI’s API to generate a reply. Requests are sent with storage disabled. According to OpenAI’s API data policies, API inputs and outputs are not used to train OpenAI models and may be retained for a limited period for abuse monitoring. See OpenAI’s policies for details.
This is a transfer of personal information outside your country.
- Recipient: OpenAI, L.L.C. (United States)
- Items transferred: the conversation content, names, questions and answers, and approved memories described above
- Purpose: generating conversation replies
- Retention by the recipient: as described in OpenAI’s API data retention terms
- Each partner must agree to AI processing before creating or joining a space. Without agreement, you cannot create or join a space. After joining, you can withdraw permission at any time; future AI features stop, while shared messaging in the existing space still works.
Withdrawing AI permission
Either partner can withdraw AI permission at any time in the About dialog. Withdrawal stops future AI requests for the whole space. It cannot undo processing that already happened.
Hosting and service providers
Closely runs on Cloudflare’s platform (Workers and D1). Cloudflare processes request metadata such as IP addresses to deliver and protect the service. Supabase Auth handles Google/Kakao sign-in and the authentication user record for Closely. Those providers’ own privacy policies also apply. When you enable device notifications, your browser or operating system’s push service delivers an encrypted, generic turn reminder containing no names or conversation text.
Retention and deletion
- Use “Leave this space” in the About dialog to remove your membership, erase your message text, and remove your device push subscriptions. Your Closely account and sign-in remain available so you can join another space.
- When you leave, your membership is removed and the text of every message you wrote is deleted. Your partner keeps their own messages and Closely’s replies, which may mention things you shared. Shared memories and personal ideas are deleted for both of you.
- When the last partner leaves, all conversations, messages, memories, and ideas in the space are deleted. Anonymous AI usage counts without any content may be kept for cost accounting.
- “Delete my Closely account” is available even without a space. It performs the space-leaving cleanup and removes your Closely profile, its Supabase authentication user record, all device sign-in sessions, and push subscriptions. It does not delete your Google or Kakao account. If deletion fails, it is not reported as complete; retry or contact support. Provider logs and backups follow each provider’s retention policy. Cloudflare D1 recovery history may remain for up to seven or 30 days, depending on the plan.
Your rights and choices
- Withdraw AI permission at any time.
- Leave your space or delete your Closely account at any time.
- Change your language and turn reminders on or off.
- Ask for access to, correction of, or deletion of your information, or ask about this policy, using the contact below. You can also complain to your local data protection authority.
Children
Closely is for adults. Do not use Closely if you are under 18, or under the age of majority where you live.
Security
Connections use HTTPS. The AI provider key stays on the server and never reaches your browser. Access to a space is checked on the server for every request. No online service is perfectly secure, so please do not write anything you would not want stored.
Changes and contact
If this policy changes materially, the effective date at the top changes and the app will show a notice.
Contact: closetoea@gmail.com