Privacy Policy
What Snowball collects, why, and the choices you have — in plain language. DRAFT — pending attorney review; highlighted items are unresolved.
Last updated · [REVIEW: effective date]
1. Who we are
Snowball is a personal habit-tracking and reflective-journaling app for iOS. It is operated by [REVIEW: legal entity / operator name], located at [REVIEW: business address]. If you have questions about this policy or your data, contact us at joeylograsso@gmail.com.
This Privacy Policy explains what personal information we collect, why we collect it, who we share it with, how we protect it, and the choices and rights you have.
2. Plain-language summary
- What Snowball is for: tracking habits and writing short, private journal entries and reflections, with AI-generated “recap” letters that look back on your week or month.
- The most sensitive data you give us is your journal content (typed text and, if you use voice journaling, the audio you record). We encrypt journal entries and recap letters at rest with a per-user encryption key.
- We use a small number of trusted service providers to run the App: Supabase (database, authentication, and server functions), Apple and Google (sign-in), Deepgram (voice-to-text), OpenAI (cleaning up transcripts), Anthropic Claude (writing recap letters), PostHog (analytics), and Expo (app infrastructure and notifications).
- We do not sell your personal information, and we do not use your journal content to advertise to you.
- You can delete your data at any time. Deleting your account permanently removes your habits, journal entries, recaps, and other associated records from our database. A full data-export feature is planned; until it ships, deletion and in-app access are the tools available.
This summary is for convenience only; the full policy below governs.
3. Information we collect
3.1 Information you provide
- Account and identity information. When you sign in with Apple or Google, we receive your name (Apple, on first sign-in, if you choose to share it) and email address. If you sign in with a one-time email passcode, we receive your email address.
- Journal content. The text you write in your journal entries, including answers to your selected reflection prompts. If you use voice journaling, we process the audio recording you make in order to transcribe it into text; the audio is processed in memory and discarded after transcription — we do not store your recordings.
- Habit data. The habits you create (names and settings) and your completion logs (which habits you marked complete, and when).
- Onboarding responses. Optional answers you give during onboarding, such as your motivations, the struggles you identify with, an “identity” statement, and a description of your typical day. These can be skipped.
- Preferences. Your notification preferences and reminder times, and whether journaling is enabled.
3.2 Information collected automatically
- Device time zone. We store your device’s time zone so reminders and weekly/monthly windows line up with your local day.
- Usage and product analytics. We use PostHog to understand how the App is used. This includes screen views, in-app actions (for example, creating or completing a habit, submitting a journal entry, or viewing the subscription screen), app lifecycle events, and touch interactions. Analytics are associated with a user identifier; we do not send your email or name to our analytics provider, we do not use session replay, and we never send your journal text, habit names, or reflection answers.
- Notifications. Reminders are scheduled on your device; we do not collect or store push notification tokens on our servers.
3.3 Payment and subscription information
Snowball offers paid features through Apple In-App Purchase. Apple processes your payment; we do not receive or store your full payment card details. We store subscription status and transaction identifiers necessary to provide paid features.
3.4 Information we do not collect
We do not intentionally collect precise geolocation, contacts, photos, or health-app data. We do not require a password (authentication is handled by Apple, Google, or a one-time email passcode).
4. How we use your information
- Provide the core service — store and display your habits, logs, and journal entries across your sessions.
- Transcribe voice journals — convert your recorded audio into editable text.
- Generate recap letters — produce personalized weekly/monthly reflections from your journal entries and habit history.
- Send reminders — deliver the habit and journal notifications you opt into.
- Operate, secure, and improve the App — including analytics, debugging, and preventing abuse.
- Communicate with you — for account, security, and support purposes. Sign-in passcode emails are delivered by Supabase, our authentication provider.
- Comply with legal obligations and enforce our Terms of Service.
We rely on the following legal bases where applicable (e.g., GDPR/UK GDPR): performance of a contract (providing the App you signed up for), consent (optional onboarding answers and voice journaling), legitimate interests (securing and improving the App, including analytics), and legal obligation.
5. Third-party service providers
We share limited data with the providers below strictly to operate the App. Each is bound by its own terms and privacy commitments. We do not sell your personal information, and we do not permit these providers to use your data for their own independent purposes beyond providing their service to us.
| Provider | Role | Data shared with them |
|---|---|---|
| Supabase | Database, authentication, and server (edge) functions | All stored account and app data, including habits, journal entries and recaps (encrypted at rest), preferences, and subscription records |
| Apple | Sign in with Apple; app distribution; In-App Purchase | Name (first sign-in), email; purchase transactions |
| Google Sign-In | OAuth identity token (email) | |
| Deepgram | Speech-to-text for voice journaling | The audio recording you make for a journal entry |
| OpenAI | Cleaning up raw voice transcripts into readable text | The raw transcript text produced from your audio |
| Anthropic (Claude) | Generating recap letters | Your journal entry text and habit history for the recap period |
| PostHog | Product analytics | User identifier and usage/interaction events (no journal or habit content) |
| Expo | App runtime, build/update infrastructure, and notification scheduling | Technical app and device data needed to run and update the App |
| ElevenLabs (planned) | Text-to-speech audio for recap letters (paid feature; not yet active) | Recap letter text to be voiced |
Provider policies: Supabase · Apple · Google · Deepgram · OpenAI · Anthropic · PostHog · Expo · ElevenLabs
6. How AI processing works with your data
Snowball uses three AI providers, all invoked server-side from our backend — never directly from the app, and never with your account credentials:
- Deepgram receives only the audio you record for a voice journal entry and returns text.
- OpenAI receives only the transcript text from that audio and returns a cleaned-up version.
- Anthropic (Claude) receives your journal text and habit history for a recap period and returns a recap letter.
We send these providers only the content required to perform the task, and we do not attach your name or email to those requests. These providers act as our processors and are contractually restricted in how they may use the data. [REVIEW: confirm each provider’s current data-retention and no-model-training terms and state the accurate position here.]
Voice journaling is optional — if you prefer, type your entries and no audio is ever created. Recap letters are generated from your stored journal and habit data as part of the core product.
7. How we protect your data
- Encryption in transit. Data moves between the App, our backend, and our providers over encrypted (HTTPS/TLS) connections.
- Encryption at rest for your most sensitive content. Your journal entry answers and recap letters are encrypted in our database. Each user has an individual data encryption key, which is itself encrypted (“wrapped”) by a master key stored in a separate secrets vault. Only our secured server role can decrypt this content to provide it back to you; the encryption keys are not accessible to ordinary application or client access.
- Access controls. We use row-level security so that users can access only their own records, and we restrict server-only data (such as recaps and subscription records) to privileged backend processes.
- No system is perfectly secure. While we work to protect your information, we cannot guarantee absolute security.
8. Data retention
- Account and app data (habits, logs, journal entries, recaps, preferences) is retained until you delete it or delete your account.
- Voice audio is processed in memory to produce your transcript and is not stored on our servers.
- Analytics data is retained according to our analytics provider’s retention settings, and is not deleted when you delete your account. [REVIEW: state the configured PostHog retention period.]
[REVIEW: state any short backup-retention window after which backups are overwritten.]
9. Your rights and choices
Depending on where you live (for example, under GDPR/UK GDPR or the CCPA/CPRA), you may have the right to access, correct, export, delete, or restrict the processing of your personal information, and to withdraw consent.
- Access. You can view your entries, habits, and history in the App.
- Correction. You can edit or update your journal entries, habits, and preferences in the App.
- Deletion. You can delete individual entries in the App, and you can delete your entire account, which permanently removes your associated data — habits, habit logs, journal entries, reflection history, recaps, and subscription records — from our primary database.
- Portability. A full data-export feature is planned. Until it ships, contact us and we will assist with access requests.
- Analytics. Product analytics is integral to operating the App and does not currently offer an in-app opt-out; it never includes your journal content, habit names, or reflection answers.
- Exercising your rights. Contact us at joeylograsso@gmail.com. We will respond within the time required by applicable law, and we will not discriminate against you for exercising your rights.
10. Data location and international transfers
Our providers may process and store data in the United States and other countries. If you access Snowball from outside [REVIEW: primary operating country/region], your information may be transferred to and processed in countries whose data-protection laws differ from your own. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for these transfers. [REVIEW: confirm Supabase hosting region and transfer mechanism.]
11. Children’s privacy
Snowball is not directed to children, and we do not knowingly collect personal information from children under [REVIEW: 13 / 16 — set to match target markets]. If you believe a child has provided us personal information, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date and, where appropriate, provide additional notice in the App. Your continued use of Snowball after an update means you accept the revised policy.
13. Contact us
[REVIEW: legal entity / operator name and business address]
Email: joeylograsso@gmail.com · or use our support page.