Legal

Privacy Policy

Last Updated: May 12, 2026


1. Scope

This Privacy Policy applies to the Spiral mobile app, including:

2. Summary

In summary:

3. Information We Collect

3.1 Information you create in the app

Depending on how you use Spiral, the app may store locally:

3.2 App preferences and settings

The app may store local preferences such as:

3.3 Device and app information

The app and integrated providers may process limited technical information such as:

3.4 Purchase and subscription information

If you purchase or restore premium access, the app and purchase providers may process:

Purchases are handled by Apple App Store, Google Play, and RevenueCat. We do not receive or store full payment card information, and purchase records are handled by those providers.

3.5 Notifications information

If you enable reminders or remote messaging features, the app and notification providers may process:

3.6 Diagnostics and usage information

The app and integrated providers may process:

4. How We Collect Information

Information is processed:

5. How We Use Information

Information may be used to:

Depending on your jurisdiction, we may rely on one or more of the following legal bases:

Where your jurisdiction requires consent for specific processing, your continued use of the app after reviewing this Privacy Policy constitutes acceptance of such processing.

7. Where Data Is Stored

7.1 On-device storage

Spiral stores substantial app data locally on the device, not on our backend, including journal entries, breathing sessions, meditation sessions, insights data, preferences, and certain cached states.

The app uses:

7.2 iCloud sync

If the user enables iCloud sync on iOS, the app may sync a snapshot of app data to the user's iCloud storage. Based on the current implementation, this snapshot may include:

iCloud sync is optional and user-controlled.

7.3 AI processing and OpenRouter

When a user requests AI insights, the app sends data through our API directly to OpenRouter, where it is routed to the user-selected AI model. Our backend does not store this data or keep copies of journal content. The data is transmitted for processing and is not retained on our servers.

The AI providers we route to may temporarily retain transmitted content for up to 30 days for service operation and abuse detection. This data is not used to train AI models. We configure our OpenRouter requests to route only to providers whose policies prohibit using customer data for model training.

Data sent for AI processing may include:

7.4 Backend operational data

While our backend does not store journal content, it does maintain short-lived operational state required to run the service safely:

This operational state does not contain journal text. It is held only for the period required by the related counter or is automatically cleaned up.

7.5 Backend request logs

Our infrastructure provider retains short-term request logs for operational monitoring. These logs include request metadata such as response status, timing, model identifiers, token and cost telemetry, and error traces. Journal content is not written to these logs. Logs are retained for up to 7 days for incident detection and debugging.

7.6 Operational alerts

When operational thresholds are crossed (for example, quota breaches or AI provider failures), our backend may send internal alerts to a third-party messaging service used by our operations team. Alerts do not contain journal content. Alerts are throttled to prevent flooding.

7.7 Third-party service infrastructure

The app may also use:

8. Third Parties and Service Providers

We may share information with service providers that process data on our behalf or provide infrastructure required for app functionality, including:

These providers process data under their own terms and privacy notices where applicable.

9. AI Features

9.1 User-triggered AI processing

AI insight generation is a user-triggered feature. Journal content is not sent for AI analysis unless the user uses an AI insight flow or another flow that explicitly invokes AI processing. When triggered, data is sent directly to OpenRouter and forwarded to the selected model; we do not store AI request data or journal content on our backend.

9.2 AI output

AI features may generate:

AI-generated content may be inaccurate, incomplete, or inappropriate, and should not be relied on as medical, mental health, legal, financial, or other professional advice.

9.3 AI data handling

AI-related output may be stored locally and may also be included in iCloud sync snapshots if sync is enabled.

10. Notifications

If you enable reminders:

If remote messaging support is available:

11. Analytics and Diagnostics

11.1 Analytics

The app may send analytics events and super-properties to Mixpanel. This may include:

11.2 Crash and error monitoring

The app may send error and crash information to Sentry, including:

12. Data Retention

We retain data for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required by law.

In practice:

13. User Choices and Controls

Users may be able to:

Users may also manage certain permissions and provider-level settings through their device or provider accounts.

14. Data Security

We use reasonable administrative, technical, and organizational measures designed to protect information. However, no method of storage or transmission is completely secure, and we cannot guarantee absolute security.

Based on the current implementation:

15. Children's Privacy

Spiral is not intended for children, and we do not knowingly collect personal information from children in violation of applicable law. If you believe a child has provided personal information, contact us so we can review and address the issue.

16. International Transfers

Your information may be processed in countries other than your own, including where our service providers operate. Those countries may have different data protection laws. Where required, we will use appropriate safeguards for international transfers.

17. Your Privacy Rights

Depending on your location, you may have rights such as:

Because journal content and most core app data stay on your device and are not stored on our backend, the practical scope of certain rights may depend on the nature of the data and whether any relevant provider-held records can reasonably be associated with you.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we may update the in-app version, website version, effective date, or provide additional notice where appropriate.

19. Contact Us

If you have questions about this Privacy Policy or our privacy practices, contact: