Privacy Policy

What we collect, and why.

Placeholder draft. This reflects what the app actually does as of this build, but proper UK GDPR compliance (a registered ICO data controller entry, a named contact, defined retention periods, and a lawyer's review) should happen before real users' data is collected at any scale.

What we collect

Your email address (for sign-in), your assessment answers, journal entries, anything you add to your profile (life stage, interests, cultural background, etc.), and your subscription status. Nothing is ever collected from your social media, browsing activity, or any source outside what you directly type into the app.

How it's used

Solely to generate your personalised reports and guidance, and to run your account (login, subscription status). Your journal entries and profile details are sent to Anthropic's Claude API to generate that guidance, under Anthropic's standard API data policies — not used to train their models by default.

What we never do

We don't sell your data. We don't show you ads, targeted or otherwise, and we don't share your data with advertisers. We don't access your social media or any account outside Innerscape.

Where it's stored

In a Supabase-hosted database with row-level security, meaning the system is built so only you can ever read your own data — not other users, and not us casually browsing a database.

Payment data

Handled entirely by Stripe. We never see or store your card details ourselves.

Your rights

You can request a copy of your data or ask for your account and all associated data to be deleted at any time — email support.