Privacy

Last updated: 30 July 2026 · This is a plain-language policy. It means what it says.

love&truth is built so there is almost nothing to collect. We hold your number. We never hold your words.

Who we are

[LEGAL NAME · IČO · REGISTERED ADDRESS], trading as mutinoise, Czech Republic — the data controller for everything described on this page. A person made this, and a person answers: peace@mutinoise.com. We are small enough that the law does not require us to appoint a Data Protection Officer, and honest enough to say so rather than invent one.

What stays on your device

What you share — sealed, so even we can't read it

love&truth is a place to be read by the people you choose, so some of what you write is meant to travel. When it does, it is end-to-end encrypted on your phone first — sealed to its reader — so the server only ever carries an envelope it cannot open:

In both cases we hold the sealed envelope only in transit, and can never read the words inside.

What we do hold, and why

That is the whole list. There is no more, by design.

How long we keep it

Nothing here has a long tail. We keep no backups of your words, because we never had your words.

What we never do

Where it is stored, and where it travels

The little we hold lives with Supabase, in the European Union, with row-level security on every table so your rows are reachable only through your own authenticated session. Traffic is encrypted in transit (TLS). The account itself is anonymous: there is no email, no password, no phone number.

If you live outside the European Union, that means the little we hold travels into the EU and stays there. This is the opposite of the transfer most policies ask you to accept: we do not move European data out into a weaker jurisdiction — we bring everyone's under the strictest data-protection law there is, and keep it there. Where such a transfer needs a legal basis, it is the performance of our agreement with you.

The website

mutinoise.com sets no cookies, runs no analytics, and loads nothing from anyone else's server. It stores exactly one thing in your browser, and only if you change it: whether you are reading in the light room or the dark one. Nothing about you leaves the page.

Paying for it

When love&truth costs money, Apple takes the payment, not us. Apple tells us that a subscription is active and nothing more — we never see your card, your name, your address, or your Apple ID. What Apple does with that transaction is covered by Apple's own privacy policy, not this one.

Encryption, honestly

Letters and shared pages use end-to-end encryption built on standard, published cryptography (X25519 and ML-KEM-768 for key exchange, Ed25519 for signatures, ChaCha20-Poly1305, HKDF, SHA-2). Your keys are generated on your device and never leave it. We have designed this carefully and hold ourselves to a high bar — but no system that touches the real world is ever perfectly secure, and we will never tell you otherwise.

If something goes wrong

We hold so little that the worst realistic breach of our server would expose numbers, and the graph of who added whom — not words, because we do not have the words. If it ever happened we would tell the people affected and the relevant authority, promptly and plainly, and we would tell you what we did not know as readily as what we did.

Age

love&truth includes private messaging between people, so it is meant for older teens and adults. You must be at least the minimum digital-consent age where you live — for example 16 across much of the EU (some countries set it lower; the Czech Republic sets it at 15) and 13 in the United States. We never knowingly collect data from children below these ages. If you believe a child has an account, write to us and we will delete it.

Your rights, wherever you live

What follows is the law in different places. We give all of it to everyone, because writing two versions of a promise is how a promise stops meaning anything. Almost all of it you can do yourself, right now, without asking us: export and delete your account are both in the account menu inside the app. Deletion is immediate and complete — your number, your connection graph, and any sealed items still awaiting delivery are erased. Your on-device diary is yours to keep or to wipe with the app. For anything else, write to peace@mutinoise.com. We never charge for any of it, and we will never treat you differently for asking.

Europe and the United Kingdom

Under the GDPR and the UK GDPR you have the right to access your data, correct it, erase it, restrict or object to how we use it, take it with you, and withdraw consent at any time. Our lawful basis is the performance of our agreement with you — holding your number and your connections is the only way a letter can find its way — and, for notifications, your consent. There is no legitimate-interest processing hiding behind this policy, because there is nothing we want to do with your data that you have not asked for.

You may complain to a supervisory authority: in the Czech Republic, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů); in any other EU or EEA country, your national authority; in the United Kingdom, the Information Commissioner's Office.

California

Under the CCPA, as amended by the CPRA, the categories of personal information we collect are identifiers (your number, the numbers you have added, and a notification token if you allow notifications) and user content (sealed pages and letters, in transit only, which we cannot read). We collect them for one business purpose: to deliver what you asked us to deliver. We collect no sensitive personal information and infer nothing from anything.

We have never sold or shared personal information, and never will. There is no “Do Not Sell or Share My Personal Information” link on this site because there is nothing to opt out of. You have the right to know, delete, and correct; the right to opt out of sale, sharing, and targeted advertising, none of which occur; and the right not to be discriminated against for exercising any of them. An authorised agent may act for you, with proof.

The rest of the United States

If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, or another state with a consumer privacy law, you have the same rights and we give them the same way. We do not sell personal data, do not use it for targeted advertising, and do not profile anyone. You may complain to your state Attorney General, or to the Federal Trade Commission.

Everywhere else

Brazil (LGPD), Canada (PIPEDA), Australia, Japan (APPI), South Korea (PIPA), Switzerland (FADP) and the rest: the same rights, exercised the same way, with the same regulators available to you if we fall short. And in general — where the law where you live gives you a right this policy has not named, you have it. We would rather be bound by all of them than argue about which one applies.

Changes

If this policy ever changes, we will update the date above and, for anything that matters, tell you in the app before it takes effect.

Contact

Write to peace@mutinoise.com — for a privacy request, a safety concern, or anything at all. A person made this, and a person answers. If you need help using the app rather than a question about your data, the support page is the shorter road.

← mutinoise