Privacy policy
What we collect, why, and what you can do about it. In plain English first, with the formal version underneath.
The short version
Your reflections are private. Nothing is shared with a group, a coach or anybody else until you share it.
We do not sell data, and we do not use what you write to advertise to you.
You can export your reflections from the app, or ask us to delete your account and everything on it.
1. Who we are
My Reflections is operated by Chris Winfield-Blum trading as My Reflections, from Adelaide, South Australia. Where this policy refers to “we”, “us” or “My Reflections”, it means that operator. Our contact address for privacy matters is at the end of this page.
2. What we collect
We collect the information needed to run your account and the service:
- Account details: email address, password (stored hashed by our auth provider), display name, biography, profile photo, timezone, and sign-in provider if you use Google or Sign in with Apple.
- Reflections and related content: ratings, notes, titles, highlights, lowlights, adjustments, tags, daily check-ins, long-form journals, goals, deep-dive reports, group membership, group asks and threads, scheduled reflection settings, and inbound webhook metadata and API keys you create.
- Media: photos you attach to a profile, photo journal, or group cover, stored in our cloud storage.
- Device and delivery data: app or browser version as needed for support, Expo push tokens if you enable reminders, and basic server logs from our hosting providers.
- Billing status: whether you are on Free or Professional, subscription period, and which store or payment provider you used (Apple App Store, Google Play, or Stripe via RevenueCat). We do not store full card numbers.
- Support mail: messages you send to support or privacy, and any reflection you choose to attach for troubleshooting.
- This website: pages you load, form submissions on the marketing site, and essential cookies described in our Cookies page.
We do not request location, HealthKit or health records, contacts, calendar access, advertising identifiers, or clipboard monitoring. Camera, photo library, microphone and speech recognition on iOS and Android are used only when you choose features that need them (QR invites, photos, dictation).
We use a small number of third-party services to run the app; they are listed in section 6, along with what each one sees.
3. How we use it
To run your account, sync your writing across devices, produce Insights and reports, send the reminders you have asked for, process Professional subscriptions, operate groups and webhooks you configure, and respond when you contact us. Nothing you write is read by us except where you explicitly ask for support with it, or where we must review content to enforce our terms or comply with law.
4. Sharing, groups and public links
Reflections stay private to your account until you share them. When you join or create a group, members see only what that group’s settings and your share choices allow (for example rating and tone, a full reflection, or a monthly report). Closed groups limit what members can see of each other’s writing; open groups share completed reflections according to the group settings.
Deep-dive summary links use a public URL. Anyone with the link can open the summary without an account. Treat that link like a document you emailed: revoke or stop sharing it if you no longer want it public.
5. Reflection Bot and dictation
Reflection Bot is optional tone scoring on the text of a reflection (lexicon-based sentiment analysis). It is not a chatbot, not generative AI, and not therapy. Results may be stored with the reflection. You can turn Sentiment analysis off in You (iOS or Android) or Profile (web). We do not send your journal text to OpenAI, Google Gemini, Anthropic or similar large language model APIs.
Where the app offers dictation, speech recognition runs on the device. The transcribed text is then stored as journal content like any other note you type.
6. Who we share with
We do not sell your personal data. We do not use the content of your reflections to advertise to you. We share data only with processors that help us run the service, and only as needed for their role:
- Google Firebase (Authentication, Firestore, Storage, Cloud Functions, App Hosting): account, reflections, media and app backends. Primary project region includes australia-southeast1.
- Google Sign-In and Apple (Sign in with Apple): identity when you choose those sign-in methods.
- Apple App Store and Google Play: mobile subscription billing when you subscribe on that store.
- RevenueCat: subscription entitlements linked to your account.
- Stripe: web checkout and customer portal when you subscribe on the web.
- Expo: push notification delivery when you enable reminders.
- Email delivery via our Firebase mail pipeline: transactional messages such as group reflection notifications you trigger.
- WordPress host for this marketing site: pages, forms and essential cookies.
Group members and people who open a public deep-dive link are recipients you choose, not our processors. More detail sits on our Data processing page.
7. Retention
We keep your account and writing for as long as the account exists. If you delete individual reflections, we remove them from the live database. If you ask us to delete the account, we delete the account data and associated reflections and media from the live systems, subject to a short backup window needed to recover from mistakes, and any records we must keep for tax, fraud, dispute or legal reasons (for example billing records).
8. Security and international transfers
We use reputable cloud providers and standard access controls. No method of transmission or storage is perfectly secure. Some processors operate infrastructure outside Australia. Where personal data is transferred internationally, we rely on the safeguards those providers offer under their terms and applicable law.
9. Your rights
Depending on where you live, you may have rights to access, correct, export or delete personal data, or to complain to a regulator. In practice you can:
- Edit your profile and reflections in the app.
- Export reflections as a CSV from the iOS or Android app, or from the web app (You / export).
- Turn Reflection Bot off at any time.
- Ask us to delete your account by emailing from the address on the account (there is no in-app delete yet).
Australian privacy complaints can be taken to the Office of the Australian Information Commissioner (OAIC) if we cannot resolve them. Email [email protected] first and we will respond from Adelaide, South Australia.
10. Children
My Reflections is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has created an account, contact us and we will delete it.
11. Changes and contact
We may update this policy when the product or the law changes. The “Last updated” date on this page will change when we do. Continued use after an update means you accept the revised policy for that use.
Questions about any of this go to [email protected].