Data processing
How we process personal data when you use My Reflections.
The short version
We process account details, the reflections you create, and basic technical logs so the app can run.
We use a short list of processors (hosting, auth, billing, push, this website). They see only what they need to do their job.
You can export from the app, or instruct us to delete your account by email.
1. Roles
Chris Winfield-Blum trading as My Reflections (Adelaide, South Australia) is the controller of personal data for your My Reflections account and this website. When you share a reflection or a report with a group, or publish a deep-dive link, the people who receive that content see only what you chose to share. Those recipients are not our processors.
2. What we process
Account identifiers (email, sign-in provider, profile), the content of reflections and reports, photos you upload, timezone and reminder settings, Expo push tokens when enabled, webhook API keys you create, billing and entitlement status if you are on a paid plan, support correspondence, and essential marketing-site data. We do not sell this data and we do not use what you write to advertise to you.
Optional Reflection Bot scoring processes reflection text with lexicon-based sentiment analysis and may store a score with the reflection. It is not a large language model API. Where dictation is offered, speech is processed on device; the resulting text is stored as journal content.
3. Processors
We use the following categories of processors. Each sees only the fields required for that job and is bound by their terms and applicable data-processing commitments:
| Processor | Role | Typical data |
|---|---|---|
| Google Firebase | Auth, database, storage, functions, app hosting | Account, journals, media, server traffic |
| Google Sign-In | Optional OAuth sign-in | Email / profile from Google |
| Apple | Sign in with Apple; App Store IAP | Apple identity; iOS subscription billing |
| Google Play | Android subscription billing | Google account billing; Play entitlements |
| RevenueCat | Subscription entitlements | App user id; entitlement events |
| Stripe | Web checkout and customer portal | Customer and subscription records |
| Expo | Push delivery | Device push tokens |
| Email via Firebase mail | Transactional group emails | Recipient email and message body |
| WordPress host | Marketing site | Page views; form submissions; editor sessions |
We do not use a separate crash-reporting product (such as Crashlytics or Sentry) in the current apps. If that changes, we will update this list.
4. Retention and deletion
We keep your writing for as long as the account exists. Delete individual reflections in the app to remove them from the live database. To delete the whole account, email us from the address on the account; we remove live account data and associated content, with a short backup window for recovery from mistakes, and except records we must retain for legal or billing reasons. Export from the app before you ask for deletion if you want a copy.
5. Your instructions
Email [email protected] to access, correct, export or delete personal data, or to ask who processes it on our behalf. We answer from Adelaide, South Australia. See also the Privacy policy.