1. Who and what this covers
PairJar is a private appreciation and connection service for invite-only circles of two or more consenting adults. It is operated by Peter Hlavatik ("PairJar," "we," "us"), who is the data controller for information processed to provide the service.
This policy covers the PairJar iOS app, this public website, support communications, and the hosted account and synchronization service. PairJar is not offered to anyone under 18. Release candidate 26.07.10 (202607192247) is available only through a private internal TestFlight group; PairJar is not publicly available through external TestFlight or the App Store. The account-deletion subscription-transfer language below describes the release-candidate contract, not current live availability; separate Apple subscription-reconciliation credentials and rollout gates still must be activated and verified.
This website has no account form, advertising, analytics SDK, tracking pixel, or marketing cookie. Vercel hosts the independent project website on its Hobby plan and may process basic request information such as IP address, browser headers, requested URL, time, and security logs to deliver and protect it. PairJar does not run website functions or write application logs. Vercel's standard Hobby runtime-log interface has a one-hour retention window; Vercel may separately retain platform security and usage records under its terms and policies.
2. Information PairJar processes
Account and circle information
- Email address used as an unverified account identifier, display name, authentication user ID, policy acceptance, and account status. Supabase processes the password to authenticate the account; PairJar does not store the plaintext password in app storage.
- Circle name, active member identities, membership state, roles needed for a reward, and relevant timestamps.
- Circle-invitation state. Invite tokens are valid for seven days after issuance, can be used once, and are revoked when a replacement is issued. They are stored by the application backend as cryptographic hashes rather than readable tokens. Shared HTTPS invitations keep the token in a URL fragment, which is not sent in the normal request to the public website.
Content you choose to create
- Immutable ordinary appreciation moments, including the sender, recipient, note, category, time, and whether the server bound that moment to an eligible reward at creation. Optional intimacy moments follow the sensitive-content erasure rule below.
- Invitation text and reward proposals, exact proposal-version identifiers, titles, notes, stamp targets, approvals or declines, pause and removal state, and redemption time. PairJar conservatively discloses directed appreciation, invitation, and reward text as Emails or Text Messages as well as Other User Content in Apple's App Privacy form. PairJar has no public feed or general-purpose chat.
- Your own optional intimacy-category setting and the aggregate result of whether that category is available. The category is available only while the circle has exactly two active members and both independently enable it. Your raw choice is not displayed to another member, although aggregate availability in a two-member circle may allow an inference.
- Optional intimacy moments and invitations exist only while the exactly-two mutual-consent conditions hold. A third member joining, either member opting out, a member leaving or blocking, or account deletion resets the circle's intimacy opt-ins and atomically erases every intimacy moment and invitation. PairJar retains only content-free hashes of operation IDs needed to reject a delayed replay. Intimacy content is never attached to a reward or stamp.
- Safety reports, blocks, report reason, and any optional details you deliberately submit.
- Support messages and contact details you send when asking for help or exercising a legal right.
Purchase and entitlement information
If you use PairJar Plus, PairJar processes the product ID, transaction and original-transaction identifiers, an app-account token linked to your PairJar user ID, subscription environment and status, purchase, renewal, expiration, grace-period, revocation, and verification timestamps, and signed App Store transaction data needed for server verification. Apple processes the payment itself. PairJar does not receive your full payment-card or bank-account information.
Account-deletion subscription transfer record
After a purchaser's PairJar account is fully deleted, PairJar may retain a private, service-only tombstone so an eligible active subscription is not stranded or assigned to the wrong person. It contains the App Store environment; the raw original Apple transaction ID required by Apple's server API; one-way digests of a former or alternate appAccountToken; minimal claim, lifecycle, error, reconciliation, verified-expiry, signed, terminal, cleanup, and update timestamps and state; and a live target PairJar user UUID only while a transfer claim is active. It contains no email address, profile or circle content, appreciation or reward content, payment details, or signed transaction JWS. Ordinary app accounts cannot read it.
Operational diagnostics
Supabase and PairJar process short-retention IP and network request data, timestamps, function, database, and API logs, security events, and content-free replay-prevention state needed to authenticate requests, operate and protect the service, investigate abuse, and diagnose failures. PairJar discloses this as Other Diagnostic Data linked to your account for App Functionality. It is not used for behavioral analytics, advertising, or tracking.
Information PairJar does not seek
PairJar does not request your contacts, location, photo library, microphone, health data, payment-card or bank-account information, advertising identifier, or browsing history. It requests Camera access only after you choose Scan invitation QR. PairJar processes the live camera view on your device solely to recognize a QR payload; it does not save or upload camera frames, photos, or video. You can deny or turn off Camera access and paste the invitation code or link instead. Only the recognized invitation enters the normal preview and joining flow when you continue. PairJar does not use behavioral advertising or cross-app tracking.
PairJar declares an APNs device token as Device ID linked to the signed-in user, used only for App Functionality, and not used for tracking. The release candidate can register with APNs after sign-in when the authenticated server reports the delivery gate available. Device-token registration and silent background invalidation do not depend on permission to show alerts. PairJar separately asks whether it may show visible alerts and play sounds; declining that optional permission leaves silent registration eligible but prevents PairJar from intentionally sending visible alerts to that installation.
Silent payloads contain only a fixed refresh marker. Ordinary visible activity alerts use generic copy and contain no name, circle, note, reward, category, count, invitation token, intimacy signal, or other private content. An exactly-two, mutually enabled Intimacy Space may instead use the receiving installation's private Off, Discreet, or Spicy setting. Off produces no visible private-spark alert. Discreet uses only A private spark is waiting. Spicy may use only the approved phrase represented by the authorized signal kind. No mode includes a name, custom text, account, circle, or signal ID, counter, reward data, response state, or invitation token. Tightening or removing preview access clears delivered Intimacy Space alerts, while identity or account-access loss clears delivered PairJar alerts. Opening any notification only loads authorized state and routes into PairJar for confirmation; it never authenticates, recovers an account, approves an action, sends appreciation or a private spark, adds a stamp, or changes circle data by itself.
Apple controls APNs delivery. A silent update may be delayed, throttled, or not delivered, including while the app has been force-quit. PairJar therefore also reads authorized state once when a session launches, when the app returns to the foreground, or when you explicitly refresh. Those lifecycle- or user-triggered reads are correctness fallbacks, not continuous polling.
The hosted service contains all 33 migrations through 20260716190200_add_ephemeral_intimacy_signals. Guarded dispatch-push-notifications v7, its named dispatch boundary, Vault configuration, Edge-only APNs provider credentials, and both server delivery gates are active. Release candidate 202607192247 contains the matching client and no Supabase Realtime subscription or repeating or waiting-screen refresh poll. It performs one recovery read on launch, foreground return, or explicit refresh. Physical-device APNs registration and delivery, including Off, Discreet, and Spicy output, remain unverified end to end and are not claimed as release-ready.
Where information comes from
Information comes from you, other circle members, and service-generated state needed to operate PairJar. A circle member may create appreciation addressed to you, name you as a reward owner or contributor, invite you to a circle, or submit a safety report that identifies you. The service generates identifiers, timestamps, approval state, reward binding, progress, and security records from those actions.
3. Why the information is used
We process information only as needed to:
- authenticate you and keep each private space limited to its current invited members;
- synchronize reward proposals, exact-version approvals, immutable appreciation history, eligible reward-bound stamps, progress, and redemptions;
- recognize invitation QR codes on your device and open QR routes safely without treating a scan as appreciation or awarding a stamp automatically;
- verify and restore PairJar Plus, apply Free/Plus limits, give the subscriber's current circle Plus access, and prevent transaction replay or purchase fraud;
- safely reconnect an eligible direct subscription after full account deletion only when you initiate Restore purchases, the former PairJar account is gone, Apple replaces the subscription's
appAccountToken, newly signed Apple state matches the new signed-in account, and the server projects that verified entitlement; Family Sharing transactions are not eligible, and uncertain or incomplete verification does not grant Plus; - enforce circle membership, reward-participant choice, blocking, content, and safety rules;
- secure and maintain the service, investigate abuse, respond to reports, and comply with law;
- process account deletion and answer support or privacy requests.
We do not sell personal information, build advertising profiles, or share information for cross-context behavioral advertising.
4. What active circle members can see
Active members can see the circle name, member profiles, ordinary appreciation history with sender and recipient, shared reward proposals and states, which eligible moments counted toward reward progress, and recorded redemptions.
Each reward has one owner and one chosen contributor. Their role and approval state are visible as shared reward activity, but only those two participants control that reward. An eligible stamp is created only by appreciation from its chosen contributor to its owner.
Other members cannot see your raw intimacy opt-in value. PairJar shares only aggregate availability in an exactly-two circle, which may allow an inference. Intimacy stays separate from ordinary circle activity, cannot be a reward, and never adds a stamp.
Leaving, blocking, or deleting ends the departing member's access. The other current members keep the circle and content unrelated to the departing member. Open invitations and rewards involving that member become non-actionable historical records. Ordinary shared history may remain stored for integrity, but PairJar does not return an item as current-member content when its participants are no longer current members.
5. Service providers and transfers
Apple operates the App Store and StoreKit, processes subscription payments and refund requests, and provides PairJar with signed transaction and subscription-status information. Apple also operates APNs delivery to a registered device when PairJar's enabled server path and the receiving Apple device permit delivery. Physical-device delivery has not yet been verified end to end. Apple's storefront pricing, payment methods, tax handling, retention, and other processing are governed by Apple's terms and privacy policy. PairJar links a verified transaction to the signed-in PairJar user so one active subscriber can sponsor Plus for their current circle.
Vercel hosts this public website and processes technical request data to deliver and protect it.
Support and privacy messages sent to p.hlavatik@gmail.com are processed through Google's Gmail service under Google's privacy policy. This can include the message and attachments, sender and recipient details, timestamps, and technical metadata, and Google may process that information on servers in different countries. Do not email passwords or live circle-invitation tokens.
PairJar uses Supabase as a service provider for authentication, hosted PostgreSQL storage, the Data API, and Edge Functions, including account deletion, deployed subscription verification, and event-driven notification dispatch. The hosted service contains all 33 migrations through 20260716190200, and guarded dispatcher v7 plus both push-delivery gates are active. Release candidate 202607192247 does not subscribe to Supabase Realtime and does not run a repeating refresh poll. The hosted development project is on Supabase's Free plan, and its primary PostgreSQL database is in the eu-west-2 region in London, United Kingdom. Production Free-limit enforcement remains disabled until a compatible TestFlight build passes subscription lifecycle and reconciliation testing.
Supabase may use subprocessors and process limited information outside that primary database region. Covered international transfers are addressed through Supabase's applicable data-processing terms and safeguards, which may include the European Commission's Standard Contractual Clauses. Those safeguards do not mean every provider operation occurs only in the United Kingdom or EEA.
PairJar uses auto-confirmed email/password signup and sign-in with a 10-character minimum password; the entered email is only an unverified account identifier. PairJar configures no custom SMTP or outbound authentication-email provider. Supabase routes every attempted authentication email through PairJar's private no-op Postgres Send Email hook, which discards confirmation, sign-in-code, magic-link, recovery, email-change, and notification events without sending or storing their token-bearing payload. The app exposes no OTP, magic-link, confirmation-email, email-change, or password-recovery flow. Save the password in a trusted password manager; losing it together with access to every signed-in device may require a new account and invitation.
We may also disclose limited information where required by law, to respond to a serious safety risk, to investigate abuse, or if PairJar is transferred to a new operator, subject to appropriate notice and safeguards.
6. Legal bases
Where the GDPR applies, we rely on:
- Contract to create your account, provide the private PairJar you request, and deliver or restore paid PairJar Plus features.
- Explicit consent under GDPR Article 6(1)(a) and Article 9(2)(a) for optional intimacy-category settings and content. You can withdraw from Circle; withdrawal resets the circle's intimacy opt-ins and atomically erases all intimacy moments and invitations, leaving only content-free hashed operation IDs needed to prevent delayed replay.
- Legitimate interests to secure the service, prevent misuse, investigate reports, and maintain reliability, balanced against your rights.
- Legal obligation or vital interests where processing or disclosure is required by law or necessary to respond to a serious threat to a person.
You are not required to add optional notes, rewards, intimacy settings, or report details. Some account and circle information is necessary to provide the shared service; without it, PairJar cannot maintain a private synchronized circle.
7. Retention and deletion
- Account and active-circle information is kept while needed to provide the account and circle.
- Verified purchase and ordinary hosted entitlement records are kept while needed to provide or restore Plus. Account deletion removes those ordinary entitlement rows. Apple separately retains its own App Store purchase records under its policies.
- The private account-deletion subscription-transfer tombstone is kept while Apple reports that the subscription may remain active or its ownership or lifecycle state is uncertain. A verified terminal Apple state sets cleanup for exactly 180 days after the terminal timestamp. PairJar's private maintenance deletes a due available or completed tombstone once no reconciliation lease is active; a claimed or failed record is retained until uncertainty is resolved. If a completed transfer's current owner later deletes their PairJar account, PairJar rotates the proof to a one-way digest of that current
appAccountTokenfor a possible next restore, clears the earlier claim and target UUID, and does not preserve the earlier account UUID in raw form. - Unclaimed invitations are valid for seven days after issuance, can be used once, and are revoked when a replacement is issued. Claimed, revoked, or expired invite-token hashes are scheduled for removal within one day.
- Leaving or blocking ends the departing member's access. Other current members keep the circle and unrelated content. Open invitations and rewards involving the departing member become non-actionable historical records. Ordinary shared history may remain stored for integrity, but it is not returned as current-member content when its participants are no longer current members.
- Account deletion requires a fresh password sign-in for the same PairJar user and ends that person's access. It removes the Supabase Auth user, PairJar profile, consent rows, and ordinary hosted entitlement rows. The limited service-only transfer tombstone described above may remain, without email, content, signed transaction JWS, or the deleted account's raw UUID. The circle and unrelated content remain available to other current members under the same lifecycle rule above. Deleting a PairJar account or app does not cancel an Apple subscription; the Apple Account holder must manage or cancel it in the App Store, and Apple retains its own purchase records under its policies. When the separately gated restore service is available after deletion fully finishes, you may sign in to a new PairJar account and initiate Restore purchases for an eligible active subscription bought directly rather than through Family Sharing. Plus remains unavailable unless Apple reassigns the
appAccountToken, newly signs matching state for the new account, and PairJar's server projects the verified entitlement. - Safety reports are retained for no more than 90 days from submission, unless applicable law requires a longer period.
- Optional intimacy is available only with exactly two active members and both opt-ins. A third member joining, either opt-out, a member leaving or blocking, or account deletion resets the circle's intimacy opt-ins and atomically erases all intimacy moments and invitations. PairJar retains only content-free hashes of operation IDs needed to reject delayed replay.
- Support communications are kept only as long as needed to resolve the request and meet applicable legal obligations.
- With push enabled, PairJar permits at most five device registrations per account, removes or reassigns registrations during sign-out, account change, token rotation, or invalid-token handling, and purges terminal content-free delivery metadata after seven days. The deployed database contract makes each dispatch claim terminal before the APNs call and does not keep failed work for a polling retry. Turning the database delivery gate off atomically deletes every APNs registration and pending or terminal outbox row; devices must register again after a later re-enable.
- On the current Supabase Free plan, API and database logs available to the project are retained for one day. Provider security, abuse-prevention, or compliance records may follow separate retention rules under the provider's terms.
- The current Supabase Free plan does not include automatic database backups. PairJar will update this policy with the applicable retention and deletion schedule if the plan or backup configuration changes.
You can start account deletion in PairJar from Circle > Account > Delete account. If you cannot access the app, use the contact in Section 11.
8. Your privacy rights
Depending on where you live, you may request access to, correction of, export of, restriction of, objection to processing of, or deletion of your personal data. You may withdraw consent for optional processing without affecting earlier lawful processing.
We may need to verify your identity before completing a request. We will respond without undue delay and within the period required by applicable law.
If you are in the EEA, you may complain to the competent data-protection authority, including the Office for Personal Data Protection of the Slovak Republic where applicable. California residents may request access, correction, or deletion and will not be discriminated against for exercising privacy rights. PairJar does not sell or share personal information for cross-context behavioral advertising.
9. Security
The hosted service uses TLS in transit, row-level database authorization, membership checks, explicit API grants, hashed single-use invitation tokens, authenticated server functions, fresh-password reauthentication for account deletion, server verification of signed App Store transaction data, replay-resistant entitlement updates, and protected local iOS storage. The iOS client contains only a modern Supabase publishable key; secret, service-role, and APNs-provider keys are not shipped in the app bundle. Camera-based invitation recognition stays on the device, saves or uploads no imagery, and has a manual code-or-link fallback. QR opening and notification opening never create appreciation, approve an action, or add a stamp by themselves; an authenticated eligible circle member must explicitly confirm an action in the app.
Ordinary app accounts cannot browse safety reports or another purchaser's transaction details. No transmission or storage system is perfectly secure. If you believe an account or data is at risk, contact us promptly.
10. Adults only and policy changes
PairJar is for people aged 18 or older. We do not knowingly offer the service to minors. Contact us if you believe a minor created an account so we can investigate and delete it where appropriate.
We may update this policy as PairJar changes. The current version will remain available at this URL, with its effective and last-updated dates. We will provide appropriate notice before a material change takes effect where required.
11. Contact
Data controller and operator: Peter Hlavatik
Project status: Independent project based in Slovakia
Privacy and support email: p.hlavatik@gmail.com
Data-protection authority: Office for Personal Data Protection of the Slovak Republic
Website: https://pairjar.vercel.app/