Skip to main content
selfsight
  • How it works
  • Inside the app
  • Privacy
  • FAQ
  • Join the waitlist
Join the waitlist
← Legal centre

Privacy Policy

What happens to your data.

A complete explanation of what SelfSight processes, what stays on your device, when providers are involved, and the controls available to you.

Effective August 20, 2026Version 1.1Applies to the SelfSight app and selfsight.org

On this page

  1. Scope and controller
  2. On-device data
  3. Accounts and purchases
  4. External processing
  5. Website and waitlist
  6. How data is used
  7. Providers and disclosures
  8. Retention and deletion
  9. Your choices and rights
  10. Other terms and contact

1. Scope and controller

This Privacy Policy explains how the operator of SelfSight ("SelfSight," "we," "us") processes personal data through the SelfSight iPhone and iPad app, selfsight.org, the waitlist, account features, and support.

The controller for the processing described here is Anna Welin, Sweden. You can contact the controller at privacy@selfsight.org. A provider may act as an independent controller under its own terms. This policy does not cover Apple's independent processing through iOS, HealthKit, WeatherKit, or the App Store.

2. Data that stays on your device by default

Core app data is stored in Apple's protected app storage on your device. A separate onboarding profile is stored with complete file protection in Application Support and excluded from device backup. Depending on the features and data sources you enable, local data may include:

  • intentions, journal text, mood ratings, and generated daily or weekly summaries;
  • inferred pattern chains and confidence information;
  • aggregate Screen Time totals, categories, and pickup counts;
  • HealthKit sleep, steps, active energy, workouts, walking distance, and resting heart rate;
  • calendar counts, durations, and free blocks;
  • Focus information, battery summaries, and weather summaries;
  • onboarding answers about goals, habits, triggers, priority contexts, estimated unintentional use, permission decisions, tailored recommendations, and onboarding progress.

Screen Time access is provided through Apple's Family Controls and Device Activity frameworks. SelfSight uses aggregate usage information and does not read the content of messages, photos, webpages, or other apps.

Calendar processing uses schedule timing and load. SelfSight is designed not to collect event titles, notes, attendee names, or attendee contact details. Focus and battery information are operating-system signals and do not use the same permission prompts as Screen Time, Health, Calendar, Location, Microphone, or Speech Recognition.

For weather, the app requests a one-time location and sends the coordinate returned by iOS to Apple WeatherKit. SelfSight does not write the coordinate to its persistent data store, although it may remain temporarily in memory while the app runs. Voice journaling requires Microphone and Speech Recognition permission; recognition is required to run on-device, and SelfSight stores the resulting text rather than the audio recording.

3. Account, support, purchase, and technical data

  • Account data: Sign in with Apple may provide an Apple account identifier, name, and email address or private relay address. Supabase processes the identity token, account identifier, session, and authentication metadata.
  • Support data: if you use in-app support, Supabase stores your account identifier, ticket and message text, chosen priority, timestamps, replies, and any image you choose to attach. Authorized support personnel can view this information. Closing a ticket runs a server deletion flow that removes its private Storage attachments before deleting the database conversation.
  • Notification data: after notification registration and sign-in, a device push token is associated with your Supabase account so SelfSight can notify you about support replies. Apple Push Notification service processes notification delivery data.
  • Purchase data: Apple processes payment details. RevenueCat processes app-user identifiers, products, purchase and entitlement status, renewal or expiration information, and related transaction metadata. We do not receive full payment-card details.
  • Technical data: Apple, Supabase, RevenueCat, Cloudflare, EmailOctopus, and network providers may receive device, IP address, request, security, and diagnostic metadata needed to deliver or protect their services.

4. External processing and cloud features

Encrypted cloud sync

If a signed-in SelfSight+ user enables cloud sync, eligible daily summaries, pattern chains, journal entries, and profile settings are encrypted on-device using AES-256-GCM before upload to Supabase. Synced daily summaries can contain derived Screen Time, HealthKit, calendar, Focus, battery, weather, intention, and mood information. Synced journal payloads can contain journal text and intention names. Synced pattern payloads can contain the on-device token map, including app names, but the entire eligible payload is encrypted before upload.

The 256-bit key is generated on the device, stored in Keychain with device-only protection, and is not uploaded or synced through iCloud. Losing access to the device and key may make encrypted cloud data unrecoverable. Encrypted cloud sync has its own setting and is off unless you enable it.

This end-to-end encryption statement applies to eligible sync payloads. It does not mean every local database file or account record is separately encrypted with that key; local files rely on Apple's platform data protection.

Cloud-generated insights

Cloud-generated insights are optional. Signing in, buying SelfSight+, enabling sync, or finishing onboarding does not enable external model processing. You must separately enable AI-powered insights, have a current consent version, and be eligible under an age range supplied through Apple's Declared Age Range API and accepted through an App Attest-protected server flow. App Attest helps establish that the request came from the genuine app and that the submitted payload was not altered; it does not independently prove that an age declaration is true. You can turn AI off at any time; local pattern detection and basic insights continue.

Before an external request, SelfSight converts information to coarse derived behavioral signals such as screen-time category, meeting load, focus, or intention-completion trends and how many observations support them. For the first release, the server removes every HealthKit-derived field, including sleep and activity summaries, before any external model call. The model prompt also excludes raw Screen Time timelines, app names, names, email, Supabase UUID, Apple identifier, RevenueCat identifier, journal text or rating, calendar titles, and exact intention records.

The SelfSight backend authenticates the request and links it to your account to enforce consent and its version, age/provider eligibility, subscription features, rate limits, weekly quotas, and cost controls. It selects the provider and model server-side. The external model prompt does not contain that account identifier, although the provider receives ordinary network/request metadata. Supabase stores provider, model, token counts, estimated cost, entitlement class, insight type, timestamp, success status, and a request identifier without storing prompt contents.

Providers are disabled by default. SelfSight will not enable one until its applicable commercial terms, DPA, processing role, retention, training setting, transfer safeguards, age conditions, processing locations, subprocessors, and review date have been verified and recorded. Raw sensitive context is not eligible for external model processing under the current architecture.

5. Website and waitlist

If you join the waitlist, we send the name and email address you enter to EmailOctopus to manage signup and requested product emails. Cloudflare Turnstile receives limited device, browser, network, and interaction data to distinguish people from automated abuse.

The site stores your light or dark theme choice in local storage. Cloudflare hosts and delivers selfsight.org and provides cookie-less Cloudflare Web Analytics, which reports aggregate page-view statistics (such as visits, referrers, and general device and browser categories). It does not use cookies or other client-side storage, does not track you across other websites, and does not identify you personally. We do not use advertising trackers, and we do not sell or share personal data for advertising. You can unsubscribe from marketing messages at any time.

6. How and why we use data

  • Provide the app, accounts, optional sync, support, purchases, exports, weather, and requested insights.
  • Authenticate users, restore entitlements, keep services reliable, prevent abuse, and diagnose failures.
  • Send waitlist or launch communications you requested.
  • Comply with law, enforce our Terms, and protect users, the Service, and others.

Where EEA or UK law applies, our legal bases are performance of a contract for requested account and service features; consent for optional device permissions and marketing; legitimate interests in security, support, service improvement, and preventing misuse; and compliance with legal obligations. You may withdraw consent through iOS settings, in-app controls, an email unsubscribe link, or by contacting us. Withdrawal does not affect earlier lawful processing.

7. Providers and disclosures

We use Apple (iOS, Sign in with Apple, App Store, HealthKit, Screen Time, WeatherKit, push notifications, and purchases), Supabase (authentication, database, encrypted sync, support messages and images, push-token storage, consent, quota and cost records, and Edge Functions), RevenueCat (subscription offerings, purchases, entitlements, and subscription lifecycle), EmailOctopus (waitlist and email delivery), and Cloudflare (hosting and delivery, Turnstile abuse prevention, and cookie-less Web Analytics for selfsight.org). An approved commercial AI API provider may process minimized derived signals only after the controls in section 4 are satisfied. The in-app policy or release notes will identify enabled providers; no provider is enabled merely because it appears in technical configuration.

We may also disclose information to professional advisers, authorities, or transaction counterparties when reasonably necessary and permitted by law.

We do not sell personal data or use attention, health, journal, or location data for advertising. We do not share personal data for cross-context behavioral advertising. If that practice changes, this policy and any choices required by law will be updated before it begins.

Providers may process information outside your country. The exact processing locations and transfer safeguards are provider- and contract-specific; they must be verified and disclosed before an AI provider is enabled. Other providers named above process data under their applicable terms and configured regions, which must be confirmed before release.

8. Retention, security, and deletion

Retention

Local SwiftData records remain until you delete them in the app, delete the account, delete the app, or erase the device, subject to Apple backup behavior you control. The onboarding profile remains in protected, backup-excluded Application Support until app or account data is removed. Temporary JSON exports remain in the app's temporary directory until iOS, account deletion, or the app removes them; anything you share is then handled by the destination you choose.

Account, encrypted-sync, subscription-mirror, push-token, consent, quota, cost, and support records are generally retained while needed for the account or related service. Closing a support conversation removes its Storage attachments and database conversation through the same server workflow. We retain other data only as long as reasonably necessary for the purposes above or applicable law.

Waitlist data is retained until the waitlist purpose ends, you unsubscribe, or you request deletion, subject to limited suppression, security, legal, and backup records. Providers may retain transaction, fraud-prevention, security, or backup data for their own legal periods.

Deletion

The in-app Delete Account flow authenticates the current session, removes user-owned Storage objects through Supabase's supported Storage API, verifies that cleanup, deletes live database records and sessions, and deletes the Supabase Auth user last. Only after the server reports success does the app clear local SwiftData, onboarding and quarantine files, privacy/preferences, widget snapshots, pending and delivered notifications, temporary exports, the device encryption key, and the local account binding. The server flow records progress so a partial failure can be retried without falsely reporting success. Export anything you need first. Deleting the account does not cancel an App Store subscription; cancel it separately in Apple subscription settings.

Some information may remain where required for transaction records, fraud prevention, security, legal obligations, or time-limited backups. Provider-specific deletion and retention obligations must be verified before that provider can be enabled.

Security

We use platform data protection, Keychain, encryption in transit, access controls, row-level database policies, server-side entitlement checks, and encrypted sync payloads. No security method is perfect. You are responsible for protecting your device, Apple account, and device passcode and for keeping a copy of any export you need.

9. Your choices and privacy rights

You can decline or revoke optional system permissions in iOS Settings; choose not to sign in; independently disable encrypted cloud sync or AI-powered insights; export app records as a JSON file; unsubscribe from email; delete local data; close a support ticket; or delete a signed-in account in the app. Turning off AI-powered insights immediately stops new app requests and does not disable local functionality.

Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal data, and to withdraw consent. You may complain to your local data-protection authority. We may need to verify your identity and may retain data where law permits or requires it.

Residents of California and similar U.S. states may request access, correction, deletion, or portability and may appeal a denied request by replying to our decision. We do not discriminate against you for exercising privacy rights. In the preceding 12 months, the categories collected and disclosed for business purposes are those described in sections 2–7; we have not sold them or shared them for cross-context behavioral advertising.

To exercise a privacy right, email privacy@selfsight.org. We will respond within the timeframe required by applicable law.

10. Children, changes, and contact

SelfSight does not request a date of birth. On supported Apple platforms, the app implements Declared Age Range gates around 13, 16, and 18 and stores only the returned bounds and limited evidence metadata after server acceptance. Declining to share or using an unsupported platform leaves local functionality available and cloud AI disabled. The server acceptance path is designed to use App Attest, but its verifier deployment, Apple capability registration, runtime validation, and legal interpretation are not complete. Until those steps are complete and approved, external AI remains unavailable even when the rest of SelfSight and SelfSight+ are available. The final minimum account age, guardian-consent requirements, and territory-specific handling require legal confirmation before release. If you believe a child supplied personal data contrary to applicable requirements, contact us so we can investigate and delete it where required.

We may update this policy as the product or law changes. We will post the new effective date and provide additional notice when required. Material changes apply prospectively.

Privacy questions and requests: privacy@selfsight.org. General support: support@selfsight.org.

Controller: Anna Welin
Country: Sweden
Email: privacy@selfsight.org

This document should be reviewed whenever SelfSight changes a data source, model provider, analytics service, subscription flow, account-deletion flow, or retention practice.

selfsight

Awareness without enforcement.

Product

  • How it works
  • Inside the app
  • Join the waitlist
  • FAQ

Contact

  • General enquiries
  • Support

Legal

  • Legal overview
  • Privacy Policy
  • Terms of Service

© 2026 SelfSight. All rights reserved.

PrivacyTermsContact