Privacy Notice
Last updated: August 2026
Who we are
What we collect and why
- Account details — your email address, login credentials (or Google sign-in identifier) and display name, so we can create and secure your account. Legal basis: performance of our contract with you.
- Your practice and reflections — the words you pull, the dates, and anything you write in your journal, so we can show your history back to you. Legal basis: performance of our contract. These entries are private to your account.
- Membership status — your plan, status, and renewal date, so we know what to unlock. Legal basis: performance of our contract.
- Optional reminder preference — the hour you would like a nudge to practise. Legal basis: your consent.
- Technical and security data — IP address, device and browser information, and error or usage logs, to keep the app working and prevent abuse. Legal basis: our legitimate interest in security and reliability.
- Support messages — what you write to us when you ask for help. Legal basis: our legitimate interest in answering you.
What we do not do
We do not sell your personal data, and we do not read or share your private journal reflections for marketing or training purposes.
Who we share data with
- Service providers who host the app, its database, and its authentication, and who help us monitor errors.
- Paddle.com, our Merchant of Record, for the sale of membership, subscription management, payments, tax compliance and invoicing. Paddle collects your payment details directly; we never see or store your card number.
- Professional advisers such as legal and accounting support, where needed.
- Authorities, where we are required to by law.
How long we keep it
We keep your account, pulls and reflections for as long as your account is open. If you close your account, we delete or anonymise your data within 90 days, except where we must keep records (such as transaction records) for legal or tax reasons.
International transfers
Our providers may process data in the United States and other countries. Where data leaves the UK or EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision.
Your rights
Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit, encrypted storage, and per-account access rules that stop one member's data being visible to another.
Cookies
We use only essential cookies and similar local storage — enough to keep you signed in and to run the checkout. We do not use advertising cookies. You can clear them at any time in your browser settings, though you will then need to sign in again.