Privacy Policy
1. Scope
This Privacy Policy applies to the Spiral mobile app, including:
- journaling features
- breathing and meditation session features
- AI insight features
- reminders and notifications
- premium subscription and restore purchase flows
- iCloud sync and backup features
- import and export features
- analytics, crash monitoring, and support flows
2. Summary
In summary:
- Journal content and core app data are stored on the user's device, not on our backend.
- If the user enables iCloud sync, app data is synced to the user's iCloud storage.
- If the user requests AI insights, relevant journal content and related metadata are sent through our API to OpenRouter and routed to the selected AI model for processing. Our backend does not store journal content; it holds only short-lived operational state (usage counters, abuse-prevention identifiers, short-term request logs).
- Usage events and app-level properties may be sent to Mixpanel.
- Error and crash data may be sent to Sentry.
- Premium purchases are processed by Apple, Google, and RevenueCat. We do not directly process payment card data.
- Notifications require permission. If available, Firebase Cloud Messaging may generate a push token on-device.
3. Information We Collect
3.1 Information you create in the app
Depending on how you use Spiral, the app may store locally:
- journal entries
- journal entry text and content
- mood selections
- journal timestamps, dates, and times
- writing duration
- whether an entry followed a breathing or meditation session
- breathing session data
- meditation session data
- AI insight results generated for entries
- aggregated AI insight contribution data used for app analytics views
3.2 App preferences and settings
The app may store local preferences such as:
- journaling mode preferences
- word limit preferences
- ambient sound preferences
- reminder time and reminder enabled status
- PIN enabled status
- onboarding completion flags
- cached premium status
- haptic settings and similar local UI preferences
3.3 Device and app information
The app and integrated providers may process limited technical information such as:
- app version
- build number
- platform and platform variant
- iOS version, where applicable
- device-level support and debug information when you contact us through the app
3.4 Purchase and subscription information
If you purchase or restore premium access, the app and purchase providers may process:
- premium entitlement status
- product identifier
- package and offering metadata
- price and currency metadata returned by the purchase provider
Purchases are handled by Apple App Store, Google Play, and RevenueCat. We do not receive or store full payment card information, and purchase records are handled by those providers.
3.5 Notifications information
If you enable reminders or remote messaging features, the app and notification providers may process:
- local reminder time
- reminder enabled or disabled state
- local notification permission state
- push or FCM token generated on-device, if available
3.6 Diagnostics and usage information
The app and integrated providers may process:
- analytics events and event properties
- app open events
- feature usage events
- purchase and paywall events
- journal and session count or streak-related aggregate properties
- crash, exception, and error logs
4. How We Collect Information
Information is processed:
- directly from you when you type, tap, configure, save, import, or sync data
- automatically from the app when features are used
- from platform and infrastructure providers such as Apple, Google Firebase, Mixpanel, RevenueCat, Sentry, and iCloud
5. How We Use Information
Information may be used to:
- provide the app's core journaling, breathing, and meditation functions
- save and display your journal entries and sessions
- generate AI insights when you request them
- build local and AI-based insights views
- enable reminders and notifications
- verify premium access and restore purchases
- sync data to iCloud if you enable sync
- import and export backups
- monitor performance, diagnose bugs, and improve stability
- understand feature usage and product behavior
- respond to support requests and troubleshoot issues
- enforce our Terms of Service and protect the app
6. Legal Bases
Depending on your jurisdiction, we may rely on one or more of the following legal bases:
- performance of a contract with you—by using Spiral, you enter into a contract with us; we process data as needed to provide the app and its features
- our legitimate interests in operating, securing, maintaining, and improving the app (e.g., analytics, crash monitoring, stability)
- compliance with legal obligations
Where your jurisdiction requires consent for specific processing, your continued use of the app after reviewing this Privacy Policy constitutes acceptance of such processing.
7. Where Data Is Stored
7.1 On-device storage
Spiral stores substantial app data locally on the device, not on our backend, including journal entries, breathing sessions, meditation sessions, insights data, preferences, and certain cached states.
The app uses:
- SQLite-backed app storage
- AsyncStorage fallback and runtime support in some storage paths
7.2 iCloud sync
If the user enables iCloud sync on iOS, the app may sync a snapshot of app data to the user's iCloud storage. Based on the current implementation, this snapshot may include:
- journal entries
- breathing sessions
- meditation sessions
- app preferences included in the sync model
- weekly AI insights
- weekly AI insight history
- entry-level AI insights
- entry-level AI contribution data
- deleted insight ID markers
iCloud sync is optional and user-controlled.
7.3 AI processing and OpenRouter
When a user requests AI insights, the app sends data through our API directly to OpenRouter, where it is routed to the user-selected AI model. Our backend does not store this data or keep copies of journal content. The data is transmitted for processing and is not retained on our servers.
The AI providers we route to may temporarily retain transmitted content for up to 30 days for service operation and abuse detection. This data is not used to train AI models. We configure our OpenRouter requests to route only to providers whose policies prohibit using customer data for model training.
Data sent for AI processing may include:
- journal entry ID
- entry date, time, and timestamp
- journal content
- mapped mood value
- entry type
- breath or session linkage flags
- current weekly AI aggregate state
- most recent past entries from previous weeks, for context
- short snapshots of recent prior weeks' AI aggregate state
- state checksum and schema version
- in rebuild cases, multiple entries for the relevant week
7.4 Backend operational data
While our backend does not store journal content, it does maintain short-lived operational state required to run the service safely:
- per-user usage counters and abuse-prevention flags keyed by the user's subscription identifier (e.g., daily AI request count, daily AI cost total, block flags)
- hashed request identifiers used for rate limiting and duplicate request detection
- short-lived cached results of subscription entitlement checks to reduce repeated lookups
- global throttling state for internal operational alerts
This operational state does not contain journal text. It is held only for the period required by the related counter or is automatically cleaned up.
7.5 Backend request logs
Our infrastructure provider retains short-term request logs for operational monitoring. These logs include request metadata such as response status, timing, model identifiers, token and cost telemetry, and error traces. Journal content is not written to these logs. Logs are retained for up to 7 days for incident detection and debugging.
7.6 Operational alerts
When operational thresholds are crossed (for example, quota breaches or AI provider failures), our backend may send internal alerts to a third-party messaging service used by our operations team. Alerts do not contain journal content. Alerts are throttled to prevent flooding.
7.7 Third-party service infrastructure
The app may also use:
- RevenueCat for subscriptions and entitlement handling
- Mixpanel for analytics
- Sentry for crash and error monitoring
- Firebase App Check for request integrity and abuse protection
- Firebase Messaging for push-related functionality, if available
8. Third Parties and Service Providers
We may share information with service providers that process data on our behalf or provide infrastructure required for app functionality, including:
- Apple
- RevenueCat
- Mixpanel
- Sentry
- Firebase and Google Cloud services
- iCloud and Apple cloud services
- Cloudflare for backend infrastructure, request handling, abuse prevention, and short-term request logs
- OpenRouter for AI model routing (data is sent directly to OpenRouter and the selected model; we do not store it on our backend)
- Telegram, used only as an internal messaging channel for operational alerts to our team not used for any user-facing functionality
These providers process data under their own terms and privacy notices where applicable.
9. AI Features
9.1 User-triggered AI processing
AI insight generation is a user-triggered feature. Journal content is not sent for AI analysis unless the user uses an AI insight flow or another flow that explicitly invokes AI processing. When triggered, data is sent directly to OpenRouter and forwarded to the selected model; we do not store AI request data or journal content on our backend.
9.2 AI output
AI features may generate:
- entry-level insight summaries
- theme and mood-related classifications
- reflection text
- aggregate insight data used in AI Insights screens
AI-generated content may be inaccurate, incomplete, or inappropriate, and should not be relied on as medical, mental health, legal, financial, or other professional advice.
9.3 AI data handling
AI-related output may be stored locally and may also be included in iCloud sync snapshots if sync is enabled.
10. Notifications
If you enable reminders:
- the app may request notification permission
- reminder time is stored locally
- local notifications may be scheduled on your device
If remote messaging support is available:
- an FCM token may be created and stored locally on the device; it is only used by Google for push delivery—we do not store it on our backend
11. Analytics and Diagnostics
11.1 Analytics
The app may send analytics events and super-properties to Mixpanel. This may include:
- app opens
- onboarding completion state
- feature usage events
- paywall and purchase events
- notification enabled state
- iCloud sync enabled state
- premium or free tier state
- journal, breathing, and meditation counts
- streak counts and total words
- platform and app version metadata
11.2 Crash and error monitoring
The app may send error and crash information to Sentry, including:
- exceptions
- error messages
- console error payloads
- stack traces
- related extra debugging context
12. Data Retention
We retain data for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required by law.
In practice:
- on-device data remains until the user deletes it, removes the app, or overwrites it
- iCloud-synced data may remain in the user's iCloud storage until removed or replaced
- we do not retain AI request data or journal content on our backend; data sent for AI processing is passed through to OpenRouter and the selected model
- backend operational state is held only as long as needed for the counter or cache window and is cleaned up automatically
- backend request logs at our infrastructure provider are retained for up to 7 days for operational monitoring and incident response
- AI providers reached through OpenRouter may retain transmitted content for up to 30 days for service operation and abuse detection, and do not use it to train models
- analytics and diagnostic providers may retain data under their own retention settings
- app store and purchase providers retain purchase records under their own policies
13. User Choices and Controls
Users may be able to:
- delete journal entries and sessions in the app
- disable iCloud sync
- disable reminders
- disable PIN protection
- export data
- import replacement backup data
- restore purchases
- choose whether to trigger AI insight generation
Users may also manage certain permissions and provider-level settings through their device or provider accounts.
14. Data Security
We use reasonable administrative, technical, and organizational measures designed to protect information. However, no method of storage or transmission is completely secure, and we cannot guarantee absolute security.
Based on the current implementation:
- journal content and core app data are stored locally
- PIN values are stored as salted hashes
- API requests may include Firebase App Check tokens where available
15. Children's Privacy
Spiral is not intended for children, and we do not knowingly collect personal information from children in violation of applicable law. If you believe a child has provided personal information, contact us so we can review and address the issue.
16. International Transfers
Your information may be processed in countries other than your own, including where our service providers operate. Those countries may have different data protection laws. Where required, we will use appropriate safeguards for international transfers.
17. Your Privacy Rights
Depending on your location, you may have rights such as:
- access
- correction
- deletion
- portability
- restriction
- objection
- withdrawal of consent
- complaint to a supervisory authority
Because journal content and most core app data stay on your device and are not stored on our backend, the practical scope of certain rights may depend on the nature of the data and whether any relevant provider-held records can reasonably be associated with you.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we may update the in-app version, website version, effective date, or provide additional notice where appropriate.
19. Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact:
- Email: hello@spiralmind.co