Privacy Policy
Last updated: July 10, 2026
StrongTies ("we," "our," or "us") is a personal relationship management app that helps you stay connected with the people who matter. This Privacy Policy explains what information we collect, how we use it, and the choices you have regarding your data.
1. Information We Collect
We collect the following categories of information:
| Category | Details |
|---|---|
| Account Information | Name, email address, and profile photo provided via Firebase Authentication (Google Sign-In). |
| Email Metadata | Sender, recipient, subject line, date, and a short text preview (snippet, ~200 characters) of emails from your Gmail account. We do NOT read or store full email body content. |
| Contact Information | Name, email address, phone number, and company/organization from your Google Contacts. |
| OAuth Tokens | Encrypted access and refresh tokens for Google API access, stored with AES-256-GCM encryption. |
| App Usage Data | Feature interactions and preferences within the StrongTies app. |
2. How We Use Your Information
We use your data solely to provide and improve the StrongTies service:
- Relationship Insights — Analyzing email metadata to identify communication patterns and relationship strength.
- Contact Classification — Using AI to categorize your contacts (e.g., close friends, professional, family).
- Relationship Nudges — Generating personalized reminders to help you stay in touch with important contacts.
- Contact Management — Importing and organizing your contacts in one place.
3. Google API Services Compliance
Specifically, StrongTies:
- Only requests the minimum OAuth scopes necessary:
gmail.metadata,contacts.readonly, andcalendar.events.readonly. - Reads email metadata (From, To, Subject, Date) and a short text preview (snippet, ~200 characters) for AI-powered relationship insights. Does not read full email body content.
- Does not use Google user data for advertising or sell it to third parties.
- Does not allow humans to read user data, except where the user has given affirmative consent, it is necessary for security purposes, or it is required by law.
- Limits use of data to providing and improving the user-facing features of StrongTies.
4. Data Storage & Security
We take your data security seriously:
- Infrastructure — Our backend runs on Google Cloud, using Cloud Run and Firestore.
- Encryption at Rest — OAuth tokens are encrypted using AES-256-GCM before storage. All Firestore data is encrypted at rest by Google Cloud.
- Encryption in Transit — All data transmission uses TLS/HTTPS.
- Data Isolation — All user data is strictly isolated per user in Firestore. No user can access another user's data.
- Access Controls — Server-side access to user data is limited to authenticated, authorized requests only.
5. Third-Party Services
StrongTies integrates with the following third-party services:
- Google Gmail API — To read email metadata (read-only access).
- Google People API — To import contact information (read-only access).
- Firebase Authentication — For user sign-in and account management.
- Cloud Firestore — For secure, per-user data storage.
- Google Gemini AI — For AI-powered contact classification and nudge generation. Data sent to Gemini is processed in accordance with Google's AI terms and is not used to train models.
We do not share your data with any other third parties.
6. Data Retention & Deletion
You are in control of your data:
- Disconnect Anytime — You can disconnect your Google account from StrongTies at any time via the app's Settings screen. This revokes our access to your Gmail and Contacts data.
- Delete Your Data — You can request full deletion of your data through the app's Settings screen. Upon deletion, we remove all your stored data, including email metadata, contacts, OAuth tokens, and AI-generated insights.
- Account Deletion — You can delete your StrongTies account entirely, which removes all associated data from our systems.
- Retention Period — We retain your data only for as long as your account is active. After account deletion, data is purged within 30 days.
7. Your Rights (CCPA / GDPR)
Depending on your jurisdiction, you may have the following rights:
- Right to Access — Request a copy of the personal data we hold about you.
- Right to Deletion — Request deletion of your personal data.
- Right to Portability — Request your data in a portable, machine-readable format.
- Right to Correction — Request correction of inaccurate personal data.
- Right to Opt-Out — We do not sell personal data. There is nothing to opt out of.
- Non-Discrimination — We will not discriminate against you for exercising any of these rights.
To exercise any of these rights, contact us at privacy@strongties.app.
8. Children's Privacy
StrongTies is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy in the app and updating the "Last updated" date. Your continued use of StrongTies after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
- Email: privacy@strongties.app
- Support: strongties.app/support