Skip to main content

Privacy Policy

Last Updated: August 29, 2026 | Version: 2.0

Plain-Language Summary

This summary is for convenience only. Please read the full Privacy Policy below.

  • What we collect: account info (email, name, date of birth for age verification), the messages and check-in responses you and your partner submit, usage data, and payment info (handled by our payment/subscription processors — we never see your card number).
  • How we use it: to run the Service, generate AI reflections, detect safety concerns, improve the product, and communicate with you.
  • Who we share with: authentication, hosting, email, and payment/subscription processors that run the Service, plus AI providers that generate reflections — under pseudonyms, never your name or account ID. We do NOT sell your data, and we do not use third-party advertising or behavioral-tracking SDKs.
  • How long we keep it: your raw messages, check-in text responses, and AI-generated reflections are removed after 90 days, whether or not you've deleted your account. We keep AI-derived insights about communication patterns (message analysis and your Communication Style Graph) indefinitely. Deleting your account immediately scrubs your personal identifiers (date of birth, payment details) and signs you out everywhere, but does not delete shared conversation content early.
  • Crisis situations: if we detect concerning content, we show you crisis resources right away; in guided sessions we also stop the session's AI response. Check-ins still save and still receive their AI reflection. We do not contact emergency services or any other outside party — call 911 or 988 yourself if you or your partner need immediate help.
  • Your rights: access, correct, or delete your data, object to certain processing, or withdraw consent. California residents have additional CCPA rights.
  • Your partner: your partner can see your session messages and reflections, unless one of you turns on session privacy in settings. In paired check-ins, your partner can see your responses and reflection too — session privacy doesn't apply to check-ins. Individual check-ins are never shared with your partner. Don't share anything you're not comfortable with them seeing.

1. Information We Collect

Information You Provide

  • Account information: name, email address, authentication identifiers, profile settings.
  • Date of birth: collected once, to verify you meet the minimum age requirement (18+). It is removed if you delete your account.
  • Session content: messages, prompts, questions, and entries you and your partner submit during sessions, and check-in text responses.
  • AI-generated reflections: the personalized reflections our AI generates from your session and check-in content.
  • Derived data: topics discussed, emotional tone, communication patterns, and your Communication Style Graph — insights our system extracts from your messages over time.
  • Feedback: ratings, free-text feedback, support requests, and bug reports.

Information Collected Automatically

  • Usage data: IP address, device identifiers, browser or app version, pages/screens viewed, features used, timestamps.
  • Technical data: error logs, performance metrics, API response times.
  • Approximate location: derived from IP address for security and region-specific features.

Information from Third Parties

  • Authentication providers: user ID, verified email, session status from Clerk.
  • Payment and subscription processors: subscription status from Stripe (web), or from RevenueCat, the Apple App Store, or Google Play (mobile app-store subscriptions). We do not store your full payment card number.

2. How We Use Your Information

To Provide the Service

  • Authenticate you and manage your account;
  • Create and manage pairs and conversation sessions;
  • Generate AI-based reflections, summaries, and clarifications;
  • Track communication patterns to improve facilitation over time;
  • Process payments and manage subscriptions;
  • Check for and deliver app updates.

To Improve the Service

  • Debug issues and monitor performance;
  • Analyze usage patterns to improve user experience;
  • Develop and test new features.

To Maintain Safety and Security

  • Detect and prevent fraud, spam, and abuse;
  • Enforce rate limits and usage caps;
  • Run automated moderation on inputs and outputs;
  • Surface crisis resources when high-risk content is detected — see "Crisis Detection and Response" below.

3. AI Processing

Your messages are processed by AI systems (OpenAI and Anthropic) to run moderation, extract insights, and generate reflections. We minimize what we send them: your messages are processed under "Partner A" / "Partner B" pseudonyms, and your name, identity, and account identifiers are never sent to any AI provider. These providers have their own privacy policies and do not use your content to train publicly available models.

4. How We Share Information

We do NOT sell your personal information, and we do not use third-party advertising or behavioral-tracking SDKs. We may share information in the following circumstances:

Service Providers

CategoryPurpose
Authentication (Clerk)Identity verification, account security
Hosting (Fly.io, Vercel)Server hosting, data storage
Payment (Stripe)Web subscription billing
Subscriptions (RevenueCat)Mobile app-store subscription management — receives your app user identifier
Email (Resend)Transactional email (receipts, account notices)
App updates (Expo / EAS)Delivers app updates; checked once per app launch
AI/ML (OpenAI, Anthropic)Content moderation, analysis, and facilitation — under pseudonyms, see "AI Processing" above
Error tracking (Sentry)Debugging and performance monitoring using technical error data. On iOS, crash reports include a per-install identifier assigned by our error-tracking provider, so crash data is pseudonymous rather than fully anonymous.

Your Partner

Content you submit in a session (including AI-generated reflections) is visible to your partner unless one of you turns on session privacy in your profile settings. Do not share information you are not comfortable sharing with your partner.

Session privacy: Either partner can turn on session privacy in their profile settings. While it's on for either of you, each of you sees only your own session entries and the reflection written for you. This only hides content from display — it doesn't delete anything — and if session privacy is turned off, that content becomes visible again.

Legal and Safety Reasons

We may disclose information to comply with applicable law, protect rights and safety, or respond to valid legal requests.

5. Data Retention

Data TypeRetention Period
Raw message text90 days, then automatically removed by a scheduled job
Check-in text responses90 days, then automatically removed by a scheduled job
AI-generated reflections90 days, then automatically removed by a scheduled job
Message analysis & Communication Style Graph (derived insights)Retained — this is how we track communication patterns over time. The raw text these insights were derived from is still removed after 90 days.
Account information (including date of birth)Until account deletion
Usage and technical logsUp to 2 years

Deleting your account is immediate for what is exclusively yours: we permanently scrub your date of birth and payment identifiers, delete your onboarding answers and email history, and sign you out everywhere. It does not immediately delete content shared with your partner — messages and AI reflections remain in your shared sessions, and responses and reflections from PAIRED check-ins remain in your shared check-ins (this is shared data, not solely yours) — all still removed on the same 90-day schedule described above, as are personal check-in responses and reflections from INDIVIDUAL check-ins, which are never shared with your partner. Message analysis and your Communication Style Graph continue to be retained, as described above, even after your account is deleted.

6. Crisis Detection and Response

We run automated detection for content that may indicate a crisis (e.g., self-harm, suicide, abuse). When it is triggered in a guided session, we stop that session and show you crisis resources instead of an AI response. In check-ins and onboarding we show you crisis resources, visible only to you; check-ins still save and still receive their AI reflection.

This is an automated safety measure, not a diagnosis or professional intervention, and it is not perfect. We do not contact emergency services, law enforcement, or any other outside party based on this detection. If you or your partner are in immediate danger, call 911 (or your local emergency number), or call or text 988 for the Suicide & Crisis Lifeline.

7. Your Rights & Choices

Depending on your location, you may have the right to:

  • Access: request access to the personal information we hold about you.
  • Correction: request that we correct inaccurate or incomplete information.
  • Deletion: request deletion of your personal information, subject to certain exceptions.
  • Object to certain processing.
  • Withdraw consent.
  • Data Portability: request a copy of your data in a machine-readable format.
  • Opt-Out: opt out of marketing emails using unsubscribe links.

To exercise your rights, email us at privacy@homonoia.ai. We will respond within 30 days.

8. Security

We use reasonable technical and organizational measures to protect your personal information, including:

  • Encryption of data in transit (TLS) and at rest;
  • Secure key management and access controls;
  • Regular security assessments and monitoring;
  • Incident response procedures.

No system is completely secure. We cannot guarantee absolute security, and you are responsible for maintaining the security of your account credentials.

9. Cookies & Similar Technologies

On the web, we use cookies; in the mobile app, we use secure storage tokens. Both are used only to:

  • Authenticate your session and keep you logged in;
  • Remember your preferences and settings;
  • Secure the Service against fraud and abuse.

We do not use cookies, tokens, or any SDK for third-party advertising or behavioral tracking.

10. Children's Privacy

The Service is not intended for, and we do not knowingly collect personal information from, individuals under 18 years of age. We ask for your date of birth at signup to verify this. If we become aware that we have collected personal information from someone under 18, we will delete it promptly.

11. California Privacy Rights (CCPA)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how we use it;
  • Request deletion of your personal information;
  • Request correction of inaccurate information;
  • Non-discrimination for exercising your rights.

We do not sell or share personal information for cross-context behavioral advertising.

To exercise your CCPA rights, email privacy@homonoia.ai with the subject line "CCPA Request."

12. International Users

Our servers are located in the United States. By using the Service, you consent to the transfer and processing of your data in the US. We comply with applicable data protection laws, including GDPR for EU users.

13. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide notice at least 30 days before the changes take effect. Your continued use of the Service indicates acceptance of the updated Policy.

14. Contact Us

If you have questions about this Privacy Policy, please contact us at: