Belovd Privacy Policy
Last updated: 1 September 2026
The short version
- No advertising, and no tracking.
- We do not sell your data, and we never will.
- What you write in your check-ins never leaves your phone. We only ever learn the dates you showed up.
- You can delete your account, and everything in it, from inside the app at any time. It is permanent and immediate.
Please read the full policy below. It describes some genuinely sensitive information, and we would rather you know exactly what we hold.
1. Who we are
Belovd (“Belovd”, “we”, “us”, “our”) is operated by Febin Varghese, Bangalore, Karnataka, India.
For any question about this policy or your information, contact support.belovd@gmail.com.
For the purposes of the UK/EU General Data Protection Regulation, we are the data controller for the information described here. We are based in India and are also subject to India’s Digital Personal Data Protection Act, 2023.
2. What this policy covers
This policy covers the Belovd mobile application (the “app”). Belovd is a support app for women working through lust, including pornography, erotica, masturbation and fantasy. It provides daily check-ins, guided prayer and scripture, and a community where members can post and reply to one another.
3. Information we collect
3.1 Account information
When you create an account we collect:
- Your email address, used to sign you in and to recover your account.
- Your password, which is stored only as a salted cryptographic hash. We cannot see or recover your password.
- A first name that you choose. It does not have to be your real name. Other members never see it: anything you post in the community is shown with its first letter only, inside a small circle, and nothing else.
- The date your account was created.
3.2 Check-in information
Your check-in answers never reach us. This is the most important sentence in this policy, so we want to be exact about where the line falls.
When you complete a daily check-in, the only thing sent to our servers is:
- The date, and the fact that you completed a check-in on it.
That is all. We hold a list of dates on which you showed up. Nothing about what you said.
Everything else stays on your phone and is never transmitted:
- Whether you abstained that day.
- Whether you spent time with God that day.
- On a hard day: what you were struggling with, how you were feeling, where you were, and what time of day it was.
- Any custom struggle labels you add yourself.
Under the GDPR, information about sexual behaviour and about religious or philosophical beliefs is special category data. We deliberately do not collect it. It is stored only in the app’s own storage on your device, protected by your device’s passcode and encryption, and it is deleted when you delete the app.
This is a real trade and you should know the cost: because we never receive it, we cannot restore it. If you change phones, reinstall the app, or clear its data, your check-in dates will still be there, but your streak, your hard-day marks and your written reflections will not. Days you completed will show as completed, without their detail.
No part of your check-in is ever visible to another member, whether it is on your phone or on our servers.
3.3 Community content
If you post or comment in the Sisters community, or comment on a daily affirmation, we store the text you wrote, the account that wrote it, and the time you wrote it. Other members see the text, the time, and the first letter of your first name. They do not see your name or your email address.
Community content is visible to every other signed-in member of Belovd. It cannot be made private after posting. Please do not include your full name, contact details, address, workplace, or anything else that could identify you or another person. The app blocks some of this automatically, but it cannot catch everything.
We also store which posts and affirmations you have liked, which members you have blocked, and any content you have reported.
3.4 Information stored only on your device
Some information never leaves your phone and is never transmitted to us:
- Your entire check-in history apart from the dates, as described in section 3.2: whether you abstained, whether you spent time with God, your reflections, and your custom struggle labels.
- Your daily reminder time, and whether you set one.
- Your progress through a check-in you have started but not finished.
- Cached copies of your own data, so the app opens instantly without a loading screen. This includes your first name and the date you joined, which are held on your device so the app does not have to wait for our server before it can greet you. We already hold both, so this is a copy for speed and not a new collection.
- Your sign-in session, held in the iOS Keychain / Android Keystore, which is encrypted by the operating system.
Deleting the app removes all of this from your device.
3.5 What we do not collect
We want to be specific rather than vague, because these are real absences and not omissions:
- No third-party analytics. We do measure how the app is used, but we do it ourselves, on our own servers. No analytics company or advertising network receives anything about you. See section 3.6 for exactly what we record, and section 3.7 for the one case where an outside service is involved at all.
- No session timing. We do not measure how long you spend in the app or on any screen.
- No advertising, and no advertising identifiers.
- No tracking across other apps or websites. We do not use the App Tracking Transparency framework because we have nothing to ask you for.
- No crash or diagnostic reporting.
- No location data.
- No contacts, photos, camera, microphone, or health data. The app never requests these permissions.
- No payment or financial information. Belovd does not charge for anything.
- No cookies or web beacons. Belovd is a native app and does not use them.
- No notification content. A notification never contains anything a member wrote, and never names a member. A notification telling you that a sister replied says only that someone replied. A notification about a new post from the Belovd team names that team member, because she is not an anonymous member and her name already appears on her posts. See section 3.7.
3.6 How we measure use of the app
Belovd is new, and we cannot speak to every woman who uses it. So the app records which screens you reach, so that we can see where it is confusing, broken, or simply not working. This is stored on our own servers, alongside your account. It is never sent to an analytics company or anyone else.
We record which step you reached. We never record what you answered. This is the same boundary as section 3.2, and it is the important one. For example: we record that you saw the question about whether you stayed free, because we need to know how many women reach that point and how many finish. We do not record your answer, because we do not have it and do not want it.
What we record:
- Opening the app, closing it, and which of the three tabs you view.
- Your progress through onboarding and sign-up, including which step you stopped at, and whether sign-in failed because of a wrong password, an email already in use, or no connection. If you use the password reset, we record that you asked for a code and that you finished setting a new password. Never the code, and never the password.
- Your progress through a check-in: which step you reached, whether you finished, and whether you set a reminder and at what hour. If you fill in a day you missed, we record which of the two calendars you tapped and how many days back that day was. Never your answers.
- Your use of prayer: whether you reached the short introduction shown the first time you open it and whether you continued past it, which part of the home screen you opened prayer from, which feeling you chose from the list, whether you chose to pray or to declare, whether you played the audio and whether it reached the end, how many declaration cards you moved through, and where you placed the slider at the end.
- Your use of the community: viewing the feed, opening the composer, publishing a post and its category, opening and publishing a comment, and liking. If you close the composer without posting, we record only whether the box was empty or not — never what was in it. Never the words you wrote.
- Opening the daily affirmation, and liking or commenting on it. Never the words you wrote.
- Opening your account screen, viewing the daily reminder settings, looking back at earlier months on your journey, and opening this policy or the terms.
- Opening the guide (“How Belovd works”), which of its three sections you read, and whether you reached the end of one.
- Reading the community guidelines.
- Reporting and blocking, including which reason you chose from the list.
- Problems: when the app told you it had no connection, and when something you wrote failed to send and why.
- Technical details attached to each record: your account, the app version, whether you are on iOS or Android, and a random identifier for that opening of the app.
What we never record here:
- Anything you typed. Not posts, not comments, not your name, not your email, not your reflections.
- Your check-in answers, as above.
- How long you spend anywhere.
You can ask us to delete this at any time (section 11), and it is erased automatically when you delete your account.
3.7 Notifications, and the only outside services involved
Notifications are sent only if you allowed notifications. Your phone asks for that permission once, on the screen where you set up your daily check-in reminder, and it covers every kind of notification the app can send: your daily reminder, a note when a sister replies to you, and a note when the Belovd team shares something new. If you declined, or never set a reminder up, nothing in this section applies to you and no notification is ever sent.
You can stop them at any time by turning notifications off for Belovd in your phone’s settings. Note that this also stops your daily check-in reminder, because your phone treats them as one permission. Deleting your account, or signing out on a device, deletes the push token described below.
If you turn them on, we store a push token for each device you use. This is an identifier issued by Expo, which allows a notification to be routed to that device through Apple’s Push Notification service. It identifies the device, not you, and we hold it only so we know where to send a notification. It is deleted when you sign out on that device, and when you delete your account.
When another member replies to something you posted, we send a notification to your device. It is delivered by Expo (the framework the app is built with) and by Apple’s Push Notification service. This is the only case in which anything about you passes through a company other than the one hosting our database.
What those services receive is deliberately almost nothing:
- The notification says only “Someone replied to you. A sister wrote back. Come read what she said.” These words are fixed and are the same for everyone.
- It does not contain the reply, the name or initial of the member who wrote it, your name, or your email address.
- It contains one identifier for the post being replied to, so that tapping the notification opens the right post. This identifier is a random string and is meaningless to anyone without access to our database.
- The reply itself is never sent. It is fetched from our own servers, over an authenticated connection, only once you open the app.
We chose this design so that a notification arriving on your lock screen tells anyone who sees it nothing at all about you, what you are working through, or who you are speaking to.
Notifications about posts from the Belovd team. The Belovd team posts in Sisters, and when that happens we send a notification to every device that has notifications turned on. This is delivered by the same two services, and carries the same kind of almost-nothing:
- The notification names the team member who posted, for example “Gabi’s daily encouragement ✨ Come see what she shared in Sisters today.” The exact wording varies with the kind of post, but it is always fixed text plus that name.
- It does not contain the post, your name, your email address, or the name or initial of any member.
- The name it does contain belongs to a member of the Belovd team, not to another woman using the app. Team posts already carry that name openly in the app, so that you can tell an official post from a member’s. No member is ever named in a notification.
- It contains one identifier for the post, so that tapping the notification opens it. As above, this is a random string and is meaningless to anyone without access to our database.
These are the only notifications the app sends without something you did causing them, and they are the reason the permission described at the top of this section covers more than your daily reminder. If you would rather not receive them, turning notifications off for Belovd in your phone’s settings stops them, along with your other notifications.
4. How we use your information
We use your information only to:
- Sign you in and keep you signed in.
- Show you which days you have checked in, and the daily affirmation. (Your calendar detail and streak are assembled on your own device from information we never receive.)
- Show your posts and comments to other members, and theirs to you.
- Operate blocking, reporting and content moderation (see section 7).
- Send you the daily reminder you scheduled, which is generated on your own device.
- Tell you that a sister replied to something you posted, and that the Belovd team has shared something new, if you have turned notifications on (section 3.7).
- Respond to you when you contact support.
- Understand where the app is confusing or broken, so we can fix it (section 3.6).
- Comply with the law.
We do not use your information to profile you, to target advertising, to train machine learning models, or for any commercial purpose.
5. Our legal basis (UK/EU users)
- Contract: we process your account information because it is necessary to provide the app you asked for.
- Special category data: we do not collect any. Your check-in answers, which would constitute data about sexual behaviour and religious belief, are held only on your own device and are never transmitted to us (section 3.2). The dates on which you completed a check-in are processed as ordinary usage data, necessary to provide the app.
- Legitimate interests: we process reports and blocks in order to keep the community safe, and we record which screens you reach in order to find and fix problems in the app (section 3.6). We consider this proportionate because it excludes everything you write and everything you answer, it never leaves us, and you can ask us to erase it. You have the right to object to it (section 11).
- Consent: notifications are sent only if you allowed notifications when your phone asked. You can withdraw that at any time by turning notifications off for Belovd in your phone’s settings, and you can remove the push token entirely by signing out or deleting your account (section 3.7).
- Legal obligation: where we are required by law to retain or disclose information.
6. Who we share your information with
We do not sell your information. We do not share it for advertising. We have no marketing partners.
We share information only with:
- Supabase, Inc., which provides our database, authentication and hosting. Supabase stores your information on our behalf and is contractually bound to protect it. Supabase holds everything we hold.
- Expo (650 Industries, Inc.) and Apple’s Push Notification service, but only if notifications are on for you, and only to deliver them. They receive your device’s push token, the fixed wording of the notification, and a random identifier for the post concerned. For a notification about a post from the Belovd team, they also receive the name of the team member who posted. They do not receive any post or reply, the name or initial of any member, your name, or your email address. Section 3.7 sets this out in full.
- Apple, in the ordinary course of distributing the app. Apple does not receive your check-in or community content from us.
- Law enforcement or regulators, only where we are legally compelled, or where we believe in good faith that disclosure is necessary to prevent serious harm to someone.
- A successor, if Belovd is ever acquired or transferred. You would be notified before your information became subject to a different privacy policy.
7. Content moderation and automated filtering
To keep the community safe, and as required by the App Store:
- Posts and comments are automatically screened before they are published. A blocklist checks for slurs, harassment, links, contact details and references to explicit content. If your post is blocked you are told which words were flagged so you can edit it. This screening is automated, applies only to community content, and never applies to your check-ins.
- Any member can report content. We store what was reported, who reported it, and the reason given.
- Content reported by more than one member is hidden automatically, pending review, and reviewed within 24 hours.
- We can remove content and suspend or terminate accounts that breach our Community Guidelines.
8. Where your information is stored
Your information is stored on servers operated by Supabase, located in the United States (Northern Virginia).
We operate from India. If you are outside the United States, your information will be transferred to and stored in the United States, which may not offer the same level of data protection as the country you live in. Where required, these transfers rely on the appropriate safeguards under applicable data protection law, including the European Commission’s Standard Contractual Clauses for members in the UK and EU.
9. How long we keep it
We keep your information for as long as your account exists.
If you delete your account, your information is deleted immediately and permanently (see section 10). We do not keep backup copies of deleted accounts for archival purposes.
Reports you have submitted about other members may be retained after your account is deleted, without your identity attached, so that decisions already taken about the reported content remain reviewable.
The records described in section 3.6 are deleted with your account. Push tokens (section 3.7) are deleted when you sign out on that device, or when you delete your account, whichever comes first.
10. Deleting your account
You can delete your account inside the app: My account → Delete account.
This permanently erases your account and everything attached to it, including your email address, your first name, your check-in dates, all your posts and comments, your likes and blocks, and any push tokens held for your devices. It also erases the check-in detail held on your device. It happens straight away, it cannot be undone, and we cannot restore it afterwards.
You do not need to contact us, give a reason, or wait for approval.
11. Your rights
Depending on where you live, you may have the right to:
- Access the information we hold about you.
- Correct it if it is wrong.
- Delete it. You can do this yourself at any time (section 10).
- Object to or restrict how we use it.
- Receive a copy of it in a portable format.
- Complain to your data protection authority.
If you are in California, you also have the right to know what personal information we collect and to request its deletion. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not offer financial incentives in exchange for personal information.
If you are in India, you have the right under the Digital Personal Data Protection Act, 2023 to access a summary of your personal data, to have it corrected or erased, to nominate another person to exercise your rights in the event of your death or incapacity, and to raise a grievance with us. Our grievance contact is support.belovd@gmail.com.
To exercise any of these rights, email support.belovd@gmail.com. We will respond within 30 days.
12. How we protect your information
- All traffic between the app and our servers is encrypted in transit (TLS).
- Your information is protected at the database level by row-level security, so one member’s account cannot read another member’s private data even if the app is modified.
- Your sign-in session is stored in the iOS Keychain or Android Keystore, which is encrypted by the operating system, rather than in ordinary app storage.
- Passwords are stored only as salted hashes and are never readable by us.
- Length limits and rate limits are enforced by the database rather than only by the app.
No system is perfectly secure, and we cannot guarantee that our safeguards will never be defeated. If a breach affects your information, we will notify you and the relevant regulator as required by law.
13. Belovd is not a medical service
Belovd is a self-help and faith-based support app. It is not a medical service, a therapy service, a crisis service, or a substitute for professional care. We are not a healthcare provider and we are not a HIPAA covered entity. Nothing in the app is medical advice.
Moderators are not continuously available and posts are not monitored in real time. If you are at risk of harming yourself or another person, or you are in immediate danger, contact your local emergency number or a crisis helpline.
14. Age requirement
Belovd discusses pornography, sexual behaviour and related subjects in direct terms. You must be at least 18 years old to create an account.
We do not knowingly collect information from anyone under 18. If we learn that we have, we will delete the account and its information. If you believe a minor has an account, email support.belovd@gmail.com.
15. Changes to this policy
If we change this policy in a way that materially affects how we handle your information, we will update the date at the top and notify you in the app before the change takes effect. Continuing to use Belovd after that means you accept the updated policy.
16. Contact
If you have a question about your information, want a copy of it, or want something explained, write to us. You do not need to use formal language or cite a regulation.