H HardBeet

Privacy Policy

Last updated: September 7, 2026

Who operates HardBeet

HardBeet is a product operated by ElseBranch Inc. ("ElseBranch," "we," "us," or "our"). ElseBranch Inc. is the controller of personal information processed for HardBeet.

Product boundary

HardBeet is a daily check-in agreement for independent loved ones who choose what to share with each other. HardBeet is not an emergency response service, medical monitor, location tracker, or proof that someone is safe.

What HardBeet collects

If a phone is offline after the check-in button is tapped, the pending time and timezone may remain on that phone until delivery succeeds or the local queue is cleared. Approved loved ones cannot see it before the backend confirms it.

Requesting a sign-in code may create or access a provisional authentication record before the user finishes the consent screen. HardBeet shows links to this policy and the Terms before the user submits an email address or phone number. A provisional record does not activate check-in sharing. The user can request deletion if they do not complete setup.

Manual check-ins and private diagnostics

Only an explicit tap on I'm here today creates a daily check-in. Passive diagnostic collection has been retired in the new release. Historical diagnostics from older versions never create a check-in, change loved-one status, or appear to loved ones.

What HardBeet does not collect

HardBeet does not request location permission and never receives device location.

What approved loved ones can see

Approved loved ones can see whether and when the person checked in, the person's reminder and follower-alert timing while that sharing direction is active, whether that direction is paused, and suggested next steps such as wait, call, text, or ask the person to open HardBeet.

After the one-hour grace period for an eligible missed check-in, currently eligible approved followers can see whether another approved follower has an active temporary reach-out plan and when it expires. They do not see who created the plan. A plan does not indicate that contact occurred or that anyone is safe.

They cannot see email addresses, phone numbers, sign-in providers, supporting signals, live location, private phone activity, messages, photos, apps, browser history, or health details through HardBeet.

Sources, uses, and legal bases

HardBeet receives information from the user, the user's device and operating system when permission is granted, a selected authentication provider, and another HardBeet user who sends or accepts an invitation. ElseBranch does not purchase personal information from data brokers.

ElseBranch uses information to authenticate users, secure accounts, operate approved agreements, display check-in status, coordinate temporary anonymous reach-out plans, attempt push delivery, apply settings, troubleshoot reliability, prevent misuse, comply with law, and protect legal rights.

Where EEA, UK, or similar law requires a legal basis, ElseBranch relies on performance of our contract to provide the requested service; legitimate interests in securing, debugging, and protecting the service; consent where law requires it for an optional permission or choice; and legal obligations or legal claims. Consent may be withdrawn through the relevant app or device control without affecting earlier lawful processing.

Account credentials, a display name, and data needed for a chosen sharing agreement are necessary for those features. Optional permissions, connections, private labels, and push notifications may be declined, although the related feature may not work.

HardBeet does not use SMS for product notifications. Email OTP, email and password for accounts configured with one, Apple, Google, or phone OTP may be offered where enabled and tested.

How information is disclosed

Information is disclosed to approved loved ones only as described above; to service providers that operate HardBeet; when required by law or reasonably necessary to protect users, the service, or legal rights; and as part of a merger, financing, acquisition, reorganization, or asset sale subject to appropriate confidentiality and notice.

Supabase provides authentication, database storage, row-level access controls, and backend functions. Expo provides push delivery. Apple and Google platform services may process authentication, installation, and operating-system notification information.

We do not sell personal information or share it for cross-context behavioral advertising, and we do not place targeted advertising in HardBeet.

International data transfers

ElseBranch and its service providers may process information in the United States and other countries with different privacy laws. Where applicable law requires a transfer safeguard, ElseBranch uses recognized safeguards available through provider terms or data-processing agreements, such as the European Commission's Standard Contractual Clauses, or another lawful mechanism. Contact legal@elsebranch.com for information about applicable safeguards.

Push notifications

Push delivery depends on each recipient's device settings, network, operating-system behavior, and provider delivery. Notifications are best effort and are not emergency alerts. Disabling notifications may prevent reminders or alerts from reaching that device, but it does not create a check-in or change the status shown in the app.

Followers can choose normal delivery, silent delivery from 10 PM to 7 AM, or delivery held until 7 AM in their saved timezone. These settings may delay or silence an alert.

Reach-out plans and native sharing

After an eligible missed check-in, one approved follower may create a temporary reach-out plan. The plan is active for no more than 30 minutes. Other followers who are currently eligible under the same person's approved sharing agreements see only that a plan exists and when it expires, not who created it. Only the creator can withdraw the plan. A follower cannot create another person's check-in or mark that person safe.

The follower may then open the operating system's share menu with generic pre-filled text. The selected app controls editing and sending. HardBeet does not request Contacts, SMS, Phone, or Call Log access for this action and does not receive or store the selected recipient, edited or sent message, delivery status, reply, resolution, or safety outcome.

Retention

When a retention purpose ends, ElseBranch deletes or de-identifies the information unless law requires continued retention.

Deletion and privacy rights

Users can delete an account in Settings > Privacy and account > Delete account, or use the public deletion page if app access is unavailable.

Request account deletion

Depending on location, users may request access, correction, deletion, restriction, or portability; object to certain processing; withdraw consent; learn about recipients; and complain to the privacy authority where they live or work. Send requests to legal@elsebranch.com. ElseBranch may verify identity before acting, and applicable rights and response periods vary by jurisdiction.

Automated decisions and children

HardBeet does not create advertising profiles or make solely automated decisions with legal or similarly significant effects. Reminder and alert timing follows the user's settings and the agreed product rules.

HardBeet is intended only for adults age 18 or older. ElseBranch does not knowingly offer accounts to children.

Security and changes

HardBeet uses authentication, row-level security, invite-based approved connections, and limited data collection. No online service can guarantee perfect security.

ElseBranch may update this policy as the product, providers, or law changes. Material changes will receive appropriate notice and a new acknowledgement when required.