Legal

Privacy Policy

Draft pending legal review. This document is a working draft. Bracketed items such as [LEGAL_ENTITY_NAME] and [GOVERNING_LAW] must be completed and the whole policy reviewed by qualified counsel before publishing.

This policy explains what we collect, why, how we protect it, and the choices you have. EVERLIFT is designed to collect as little as possible to run a calm, reliable app.

1. Information we collect

You give us

  • Account details — email address and an optional display name when you create an account.
  • Your content — affirmations, journal entries, reflections, favorites, and collections you create.
  • Preferences — settings such as topics, theme, notification times, language, and content preferences.
  • Support messages — anything you send us when you contact support.

Collected automatically

  • Usage & device data — app version, device type, and basic interaction events used to keep the app stable and improve it.
  • Diagnostics — performance and error logs.

2. How we use your information

  • To provide core features — saving your content, syncing across sessions, and tracking your streak.
  • To personalize the content you see based on the preferences you set.
  • To send the notifications you have turned on.
  • To process subscriptions and verify entitlements through the app stores.
  • To keep the service secure, prevent abuse, and fix problems.

We do not sell your personal data, and we do not use your journal entries to target advertising. EVERLIFT shows no ads.

3. Service providers we use

We rely on a small set of trusted processors to operate the app. They process data on our behalf under their own terms:

  • Supabase — database, authentication, and backend functions (your account and content).
  • RevenueCat and the Apple App Store — subscription and purchase management.
  • Stripe — web-based subscription billing, where applicable.
  • PostHog and Plausible — privacy-conscious product and website analytics.

Payment card details are handled by the app stores or Stripe; we never receive or store full card numbers.

4. Legal bases & your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these, use in-app controls or contact us at [SUPPORT_EMAIL]. We will respond within the timeframe required by applicable law.

5. Data retention & deletion

You can delete your account at any time from Account → Delete my account. When you request deletion, we disable access immediately and permanently remove your personal data within [RETENTION_WINDOW, e.g. 30 days], except where we must retain limited records to comply with law, resolve disputes, or prevent fraud. You can also delete individual journal entries and saved items at any time.

6. Security

We protect your data with per-user access controls (row-level security), server-side handling of sensitive operations, and rate limiting on sensitive actions. No system is perfectly secure, but we work to safeguard your information and to limit what we collect in the first place.

7. Children

EVERLIFT is not directed to children under [MINIMUM_AGE], and we do not knowingly collect personal data from them. Some mature-language settings require an additional age confirmation. If you believe a child has provided us data, contact us and we will delete it.

8. International transfers

Your information may be processed in countries other than your own. Where required, we use appropriate safeguards for such transfers.

9. Changes to this policy

We may update this policy from time to time. We will post the new version here and update the “Last updated” date, and we will provide additional notice where required.

10. Contact

Questions about privacy? Email [SUPPORT_EMAIL] or write to [LEGAL_ENTITY_NAME], [MAILING_ADDRESS].