Privacy Policy for Amori
Last updated: 5 September 2026
Amori is a private app for two people in a relationship. It has no public profiles, no feed, no discovery and no advertising. Everything you put into Amori is visible only to you and the one partner you pair with.
Who is responsible
Amori is built and operated by an individual developer, not a company. Contact: eclipticrick@gmail.com.
What Amori collects, and why
| What | Why | When |
|---|---|---|
| Your email address | To identify your account and let you sign back in | At sign-in. If you use Sign in with Apple and choose Hide My Email, Amori only ever sees Apple’s relay address |
| An account identifier | To link your data to your account | At sign-in |
| A device identifier | So the app knows which of your devices are signed in. It is a random value generated by the app, not your phone’s hardware ID or advertising ID | At sign-in, and refreshed when you open the app |
| The pairing between the two of you | So the app knows whose data you are allowed to see, and vice versa. It is the two accounts that are paired, when the pairing was made, and the anniversary and meeting dates you choose to set. Pairing itself uses a short code, which stops working once it is used or after a day. The record of that code stays on the server, along with a count of failed attempts so nobody can guess a code | When you pair, and when you set those dates |
| Settings and read marks | So the app behaves the way you set it and does not tell you about something you have already seen: the hours you do not want to be disturbed, whether photos appear in the conversation, how exact photo places are, how far you have read in the conversation, and which photos you have opened. Your partner can see that you opened a photo of theirs | When you change a setting, and when you read or open something |
| Photos you choose to share | To show them to your partner | Only when you pick a photo |
| Status text you write | To show it to your partner | Only when you write one |
| Messages, stickers and drawings you send | So the two of you can have a conversation in the app. A message is text you type, a drawing is the lines the two of you draw on one picture, and a sticker is either one of the small drawings that come with the app or an image you added yourself. Emoji you react with are kept the same way | Only when you send or react. A conversation stays until one of you deletes a line, or until the account is deleted |
| Stickers you add or save | So you can send them again. An image you pick from your phone, or a copy of one your partner sent you, kept in your own collection of up to fifty. Your collection is yours: your partner sees a sticker only once you send it | Only when you add one, or save one your partner sent |
| Morning notes you write | So a short line you wrote tonight reaches your partner’s lock screen at the time you picked, in their own time zone. Until it is delivered your partner cannot read it, which is the point of it | Only when you write one |
| Special days, milestones, plans and memories you write | So the two of you share one calendar, one list of things to do together and one set of memories. Each carries the words you type, a date, and, where you added one, a place | Only when you add or edit one |
| Photo replies and reactions | To let the two of you answer a photo one of you shared | Only when you reply or react |
| Your birthday, if you set one | So the app can remind your partner. Optional, and you set your own | Only when you set it, in Settings |
| Whether your battery is low | So your partner knows why you may go quiet. It is the low-battery flag only, not the percentage, and never anything else about your phone | While the app is open |
| The language you are using | So notifications your partner’s actions send you arrive in your own language, since they are written on the server rather than on your phone | When you open the app, or change the language |
| The dates the two of you were near each other | So the app can count the days you spent together. It is a list of calendar dates and nothing else: no place is kept with them. A date is added when both of you have location on and the two positions are within about 25 km. It is only ever visible to your partner | Only on a day both of you have location turned on and are that close. It is added once and never changed |
| Counts of what the two of you have added | So the home screen can show how many photos, memories and plans there are without reading all of them. They are numbers, kept by the server, and they hold none of the content they count | Whenever either of you adds or removes something |
| Your time zone | To show your partner what time it is where you are | When you open the app |
| A name and picture you choose | So your partner sees you rather than the word “Them”. Both are optional, and you set your own, your partner cannot change them | Only when you set them, in Settings |
| Feedback you send | So problems get fixed. It is stored without your account identifier, so it cannot be linked back to you and cannot be replied to. That also means it is not deleted with your account: there is nothing on it to say it was yours. It can contain whatever you choose to type, so leave an email address in it only if you want one there | Only when you send some, under Settings › Send feedback |
| Your approximate location | To show the two of you how far apart you are, the name of the city you are in, and the weather there. Optional, the app works without it, and it is off until you turn it on. For this, it is rounded to about 11 km before it is stored, which is a city rather than a street. Amori keeps one current position and overwrites it each time, so no trail of the places you have been is kept. What is kept is the dates: on a day the two of you were close enough, that calendar date is added to the count of days you spent together, with no place attached to it, in the row above about the dates the two of you were near each other. Your position is only ever visible to your partner | While the app is open, and only if you allow it. Never in the background |
| The place a photo was taken, and places you name | So the two of you can see your own photos, memories and planned trips on a shared map. Off unless you turn it on, in Settings, and every single photo has its own switch that starts from that setting. You choose how exact it is: Broad, about 11 km, or Precise, the actual spot, and you can change that at any time in either direction. Unlike the position above, a photo keeps the place it was taken, because it belongs to the photo. You can also pick a place on the map yourself, by moving the map under the pin or by pressing use my location. Only your partner can see it, and deleting the photo deletes it | Only when you take a photo with the switch on, when you type a place name yourself, or when you pick a place on the map |
Amori never collects your contacts, your calendar, your health data, or anything about how you use other apps. There is no analytics SDK and no advertising identifier in the app.
About picking a place on the map, which changed on 26 August 2026. You can now choose a place by moving the map under a pin, and there is a button that moves the map to where you are. Pressing that button reads your position, and to turn the pin into a place name Amori’s own server asks the mapping service below what is nearest to it. So a coordinate you picked can now leave Amori’s server, and it is your own position when you use that button. It is rounded to about 110 metres before it is sent, it is sent on its own with nothing that says who is asking, and the point that is saved on your memory or your trip is the one you put the pin on. If you never press that button and never pick a place, nothing about your position is sent anywhere by this feature.
About precise location, which changed on 25 August 2026. Amori can now read your exact position, and it does so for one purpose only: putting a photo on your shared map, when you have switched that on and set it to Precise. Your phone asks you whether to give Amori the exact position or only an approximate one, and that answer is yours to change in your phone's settings at any time. The distance between the two of you is unaffected and is still rounded to about 11 km, whatever you choose here. Before this date the app could not read a precise position at all, because the permission was removed from it.
Who else can see it
No one, other than your partner. Amori does not sell your data, does not share it with advertisers, and has no analytics or marketing partners.
Five service providers process data so the app can work, acting on Amori’s instructions:
-
Google Firebase, accounts, sign-in and the database.
Data is stored in Google’s
europe-west1region (Belgium). - Cloudflare R2, photo storage, in Cloudflare’s Western Europe region. Photos are stored in a private bucket with public access disabled, and are reachable only through short-lived signed links that Amori generates for you and your partner.
- Photon, run by Komoot, which turns a place name you type into a point on the map, and a point on the map into the name of what is nearest to it. Amori's own server asks it, never your phone, and it is sent one thing: either the words you typed, or a coordinate you picked, rounded to about 110 metres. That coordinate is your own position when you press use my location in the place picker. No name, no account identifier, no device identifier, and nothing that says who is asking. Place data from OpenStreetMap, used under ODbL.
- Google Maps, which draws the map itself on Android. Drawing a map means asking Google for the piece of the world you are looking at, so Google sees that part of the map was requested. On iPhones the map is Apple's and no request reaches Google. The map is only ever drawn when you open it.
- Open-Meteo, the weather where your partner is. Amori’s own server asks it, never your phone, and it is sent one thing: a coordinate already rounded to about 11 km. No name, no account identifier, no device identifier, and nothing that says who is asking or how many people are. Weather data by Open-Meteo.com, used under CC BY 4.0.
How it is protected
All traffic between the app and these services is encrypted in transit using HTTPS/TLS. Photos are never publicly readable. Your data is scoped to your couple: the database rules reject any attempt to read another couple’s data, whoever is asking.
How long it is kept
Photos shared as 24-hour stories stop being shown after 24 hours but are kept in your shared archive, which is the point of the feature. If a photo carries the place it was taken, that place is kept with it for as long as the photo is, and goes when the photo goes. Everything else is kept until you delete it or ask for your account to be deleted.
Deleting your data
Delete your account inside the app, under Settings › Account › Delete account. Your sign-in, your account record and your devices go immediately. Your couple ends at the same moment, and everything the two of you shared is frozen and then deleted for both of you 30 days later, the shared archive is not only yours, so both of you get that window to export it first.
Feedback you sent is the one thing that stays, because it was never stored with anything that says it was yours. It carries no account identifier, so there is nothing to find and delete, and nothing that could point back at you.
If you cannot open the app, email eclipticrick@gmail.com from the address you sign in with and it will be done for you within 30 days. Full details are here.
Children
Amori is intended for adults and is not directed at children. It is not offered to anyone under 18.
Changes
If this policy changes, the date at the top changes with it. Material changes will be announced in the app before they take effect.