English
Privacy Policy
Last updated: September 7, 2026
Who operates HardBeet
HardBeet is a product operated by ElseBranch Inc. ("ElseBranch," "we," "us," or "our"). ElseBranch Inc. is the controller of personal information processed for HardBeet.
- Company website: www.elsebranch.com
- Privacy and legal: legal@elsebranch.com
- Account and product support: support@gethardbeet.com
Product boundary
HardBeet is a daily check-in agreement for independent loved ones who choose what to share with each other. HardBeet is not an emergency response service, medical monitor, location tracker, or proof that someone is safe.
What HardBeet collects
- Email address or phone number used for sign-in. HardBeet does not show either to approved connections.
- Password authentication data for accounts configured to use a password. Supabase processes the password for authentication; HardBeet does not store or display the plaintext password.
- Apple or Google account identifier and authentication data when that sign-in method is chosen. HardBeet does not receive the user's Apple or Google password.
- First name or display name provided in the app.
- Expo push token for reminders and approved follower alerts.
- Daily check-in timestamps, including the most recent check-in time.
- Supporting signal timestamps and labels may remain from older app versions. The new release no longer collects app-open, motion, battery, or background-task signals.
- Approved connection records and optional private relationship labels a user adds to their own list.
- When someone stops sharing, a dated notice with their first name may remain visible to the former follower for up to 30 days. Reconnecting clears the notice; account deletion removes the associated record.
- Invite codes and invite status, including creation, acceptance, cancellation, and expiry.
- For each sharing direction, authorization records such as the person who approved it, consent timestamp, statement version and language when available, and a non-secret receipt reference shown to that person. Older connections may initially have only an activation record until the sharing person confirms the current statement.
- Temporary reach-out-plan records after an eligible missed check-in, including the account and exact sharing direction that created the plan, the missed-check-in local date, and creation and expiration timestamps. A plan lasts no more than 30 minutes and contains no recipient, message, delivery, reply, resolution, or safety outcome.
- Product-consent, Terms of Service, and Privacy Policy versions, timestamps, and the language of the legal documents shown. Translations are available for supported app languages.
- Reminder time, timezone, language, global and relationship-specific pause, quiet-hours, setup, and alert settings.
- Notification delivery records, including attempts, provider tickets and receipts, retries and failures. A hash of the attempted push token is held while a receipt is pending, then cleared. Provider acceptance is not proof that a phone displayed a notification or that a person read it.
- Device platform information needed for push notifications and troubleshooting.
If a phone is offline after the check-in button is tapped, the pending time and timezone may remain on that phone until delivery succeeds or the local queue is cleared. Approved loved ones cannot see it before the backend confirms it.
Requesting a sign-in code may create or access a provisional authentication record before the user finishes the consent screen. HardBeet shows links to this policy and the Terms before the user submits an email address or phone number. A provisional record does not activate check-in sharing. The user can request deletion if they do not complete setup.
Manual check-ins and private diagnostics
Only an explicit tap on I'm here today creates a daily check-in. Passive diagnostic collection has been retired in the new release. Historical diagnostics from older versions never create a check-in, change loved-one status, or appear to loved ones.
What HardBeet does not collect
HardBeet does not request location permission and never receives device location.
- Live location or location history.
- Messages, call logs, photos, contacts, browser history, app names, or screen content.
- Health records, medical data, biometric values, or diagnosis information.
- Continuous raw motion history.
- Audio or camera data.
What approved loved ones can see
Approved loved ones can see whether and when the person checked in, the person's reminder and follower-alert timing while that sharing direction is active, whether that direction is paused, and suggested next steps such as wait, call, text, or ask the person to open HardBeet.
After the one-hour grace period for an eligible missed check-in, currently eligible approved followers can see whether another approved follower has an active temporary reach-out plan and when it expires. They do not see who created the plan. A plan does not indicate that contact occurred or that anyone is safe.
They cannot see email addresses, phone numbers, sign-in providers, supporting signals, live location, private phone activity, messages, photos, apps, browser history, or health details through HardBeet.
Sources, uses, and legal bases
HardBeet receives information from the user, the user's device and operating system when permission is granted, a selected authentication provider, and another HardBeet user who sends or accepts an invitation. ElseBranch does not purchase personal information from data brokers.
ElseBranch uses information to authenticate users, secure accounts, operate approved agreements, display check-in status, coordinate temporary anonymous reach-out plans, attempt push delivery, apply settings, troubleshoot reliability, prevent misuse, comply with law, and protect legal rights.
Where EEA, UK, or similar law requires a legal basis, ElseBranch relies on performance of our contract to provide the requested service; legitimate interests in securing, debugging, and protecting the service; consent where law requires it for an optional permission or choice; and legal obligations or legal claims. Consent may be withdrawn through the relevant app or device control without affecting earlier lawful processing.
Account credentials, a display name, and data needed for a chosen sharing agreement are necessary for those features. Optional permissions, connections, private labels, and push notifications may be declined, although the related feature may not work.
HardBeet does not use SMS for product notifications. Email OTP, email and password for accounts configured with one, Apple, Google, or phone OTP may be offered where enabled and tested.
How information is disclosed
Information is disclosed to approved loved ones only as described above; to service providers that operate HardBeet; when required by law or reasonably necessary to protect users, the service, or legal rights; and as part of a merger, financing, acquisition, reorganization, or asset sale subject to appropriate confidentiality and notice.
Supabase provides authentication, database storage, row-level access controls, and backend functions. Expo provides push delivery. Apple and Google platform services may process authentication, installation, and operating-system notification information.
We do not sell personal information or share it for cross-context behavioral advertising, and we do not place targeted advertising in HardBeet.
International data transfers
ElseBranch and its service providers may process information in the United States and other countries with different privacy laws. Where applicable law requires a transfer safeguard, ElseBranch uses recognized safeguards available through provider terms or data-processing agreements, such as the European Commission's Standard Contractual Clauses, or another lawful mechanism. Contact legal@elsebranch.com for information about applicable safeguards.
Push notifications
Push delivery depends on each recipient's device settings, network, operating-system behavior, and provider delivery. Notifications are best effort and are not emergency alerts. Disabling notifications may prevent reminders or alerts from reaching that device, but it does not create a check-in or change the status shown in the app.
Followers can choose normal delivery, silent delivery from 10 PM to 7 AM, or delivery held until 7 AM in their saved timezone. These settings may delay or silence an alert.
Reach-out plans and native sharing
After an eligible missed check-in, one approved follower may create a temporary reach-out plan. The plan is active for no more than 30 minutes. Other followers who are currently eligible under the same person's approved sharing agreements see only that a plan exists and when it expires, not who created it. Only the creator can withdraw the plan. A follower cannot create another person's check-in or mark that person safe.
The follower may then open the operating system's share menu with generic pre-filled text. The selected app controls editing and sending. HardBeet does not request Contacts, SMS, Phone, or Call Log access for this action and does not receive or store the selected recipient, edited or sent message, delivery status, reply, resolution, or safety outcome.
Retention
- Account profile, settings, legal-acceptance records, connections, and check-ins are kept while the account is active, then deleted on account deletion unless limited retention is required for law, security, fraud prevention, or a legal claim.
- An active push notification token is kept while registered and removed on sign-out, detected permission revocation, or account deletion.
- Open invites remain available until accepted, canceled, or expired. Inactive invite and connection records stay with the active account to prevent reuse, preserve consent and revocation integrity, investigate abuse, and resolve disputes. They are deleted with the account unless a limited record must be retained for law, security, fraud prevention, or a legal claim.
- Notification delivery and escalation records stay with the active account to operate, retry, secure, audit, and troubleshoot the service. They are deleted with the account subject to the same limited exceptions.
- A reach-out plan stops being active and visible after no more than 30 minutes. It is deleted when the relevant daily check-in is recorded, that sharing direction is paused or removed, relevant eligibility settings or legal acceptance change, or the account is deleted. An expired record may remain in restricted operational storage until routine cleanup or replacement, but it is not shown as an active plan.
- Supporting signals store only the latest state rather than continuous raw motion history and are deleted with the account.
- Provider backups may retain deleted information for a limited backup cycle before being overwritten.
When a retention purpose ends, ElseBranch deletes or de-identifies the information unless law requires continued retention.
Deletion and privacy rights
Users can delete an account in Settings > Privacy and account > Delete account, or use the public deletion page if app access is unavailable.
Depending on location, users may request access, correction, deletion, restriction, or portability; object to certain processing; withdraw consent; learn about recipients; and complain to the privacy authority where they live or work. Send requests to legal@elsebranch.com. ElseBranch may verify identity before acting, and applicable rights and response periods vary by jurisdiction.
Automated decisions and children
HardBeet does not create advertising profiles or make solely automated decisions with legal or similarly significant effects. Reminder and alert timing follows the user's settings and the agreed product rules.
HardBeet is intended only for adults age 18 or older. ElseBranch does not knowingly offer accounts to children.
Security and changes
HardBeet uses authentication, row-level security, invite-based approved connections, and limited data collection. No online service can guarantee perfect security.
ElseBranch may update this policy as the product, providers, or law changes. Material changes will receive appropriate notice and a new acknowledgement when required.