1. Overview
Peyla is responsible for the personal information described in this policy. “Peyla,” “we” and “us” refer to this service. This notice covers the Peyla app, its optional online features, this website and communications with support. Contact [email protected] with privacy questions.
Your everyday records are stored encrypted on your device. Cloud backup is optional. AI reflections require permission and a request from you. Basic onboarding analytics, subscription processing and technical diagnostics also involve the providers described below.
We do not sell personal information, use advertising identifiers, or share your journal for advertising. A random identifier is still personal information when it can distinguish one installation or user from another.
2. Information we handle
Records on your device
Your preferred name, onboarding answers, journal, mood check-ins, habits, saved tools and progress are stored in an encrypted local database. These records can contain sensitive wellbeing information. They are not uploaded as a whole unless you choose cloud backup. Exporting creates a copy in the destination you select.
Optional AI reflections
After you allow AI reflections, each request sends the selected journal entry’s text and language preference through Peyla’s server to Google Gemini. Names, health details or other personal information written inside that entry are included. Your profile name, onboarding answers and other journal entries are not added. Our server also checks subscription and app-security information to authorize the request; those identifiers are not forwarded to Gemini.
The generated reflection returns to the app and is saved with your entry. Peyla’s AI route does not store the entry or reflection in its server database. Google’s processing and retention terms apply, including security and abuse-prevention handling. We do not promise zero provider retention. Read the Gemini API terms before sharing information you consider sensitive.
Optional cloud backup
Sign in with Apple supplies an app-specific identifier and authentication information. A backup includes your app records, including your profile and journal. Peyla encrypts the snapshot before upload and stores it with Cloudflare, alongside account and backup metadata and protected recovery-key information.
Peyla can recover the backup key after you authenticate. This is not end-to-end encryption that prevents the operator from accessing the backup. Backups are manual; making a new backup replaces your previous snapshot.
Subscription information
Apple processes payments. RevenueCat helps Peyla determine whether you have access using purchase records, subscription status and app-user identifiers. Peyla does not receive your payment card number. Subscription processing is independent of optional cloud backup and AI consent.
Onboarding analytics
Peyla sends Mixpanel the onboarding step reached and a random installation identifier. Branch questions use shared labels so an event does not reveal your chosen wellbeing focus. These events exclude answers, names, journal text and check-in notes. Mixpanel records receipt times and derives approximate city and country from the connection’s IP address. There is no GPS permission or precise-location collection.
This limited analytics runs during onboarding without a separate opt-in switch. It measures the onboarding flow; it is not used for advertising or to follow activity across other companies’ apps.
Diagnostics, security and support
Sentry processes crash, app-hang and limited performance information. Payloads can include app and OS versions, stack traces, timestamps and diagnostic identifiers. The app removes user content and disables screenshots, session replay, view-hierarchy capture and content breadcrumbs.
Our servers process authentication, app-security information to secure requests. Service infrastructure receives IP addresses and other connection information. When you email support, we receive your email address and the details you choose to send. Avoid including journal content, payment details, passwords or authentication codes.
3. How we use information
We use information to provide the features you request, maintain subscription access, protect the service, diagnose failures, understand onboarding completion and answer support or privacy requests. We may also process information to meet legal obligations or resolve disputes.
Where a legal basis is required, requested service delivery relies on performance of our agreement; optional AI sharing relies on explicit permission; and proportionate security, reliability, support and onboarding measurement rely on legitimate interests, subject to applicable law and your rights. Legal obligations can require separate processing. Sensitive information shared through optional features is used for the requested purpose with the permission required by applicable law.
You can decline AI sharing and continue using the journal. Withdrawing AI consent prevents new requests but cannot recall a request already processed.
5. Security and retention
We use encrypted local storage, device Keychain protection, encrypted connections, authenticated cloud access and app-integrity checks. No service can guarantee absolute security. Protect your device and Apple Account, and keep exported copies secure.
Local records remain until you remove them or the app’s storage is removed. Device backups and exports may retain separate copies. Cloud snapshots remain until replaced or deleted. Cloud-account deletion removes the active account and backup metadata, invalidates its sessions and removes the stored snapshot. Failed storage cleanup can be queued for retry.
App-integrity keys expire after 90 days of inactivity. Authentication challenges and cleanup records have bounded lifetimes for their security purposes. Provider logs, infrastructure recovery copies, subscription records and support correspondence have separate retention requirements. We retain information only as needed for its purpose, security, resolving requests or legal obligations. Contact support for the retention and deletion scope relevant to your request. Deleting local data does not remove all provider-held records.
Want us to delete your information? Email [email protected] and ask us to delete it. We’ll help identify and remove information we hold, subject to any records we must retain by law. You can also delete local activity and your cloud account in the app.
6. Your choices, deletion and privacy rights
- AI permission: use Allow AI reflections in Profile & settings to stop future sharing.
- Local export: Export data creates a readable copy of your local records.
- Local activity deletion: Delete local activity removes journals, check-ins, habits, saved tools and progress. It keeps your profile, onboarding, settings, subscription and cloud backup.
- Cloud deletion: Backup & restore lets you delete a snapshot or delete your cloud account. You authenticate with Apple to confirm ownership.
- Subscription: cancel through your Apple Account. Deleting data, the app or a cloud account does not cancel a subscription.
Depending on your location, you may request access, correction, deletion, portability, restriction of processing, or object to processing based on legitimate interests. You may withdraw consent and complain to the relevant data-protection authority. These rights are subject to applicable exceptions, such as records that must be retained by law. We do not discriminate against people for exercising their rights.
Email [email protected] to exercise a right or object to analytics. The app currently has no analytics opt-out switch. We may request proportionate information to verify identity and locate records; we will not ask for your Apple password or require your private journal for verification. We respond within the period required by applicable law.
7. Children
Peyla is intended for adults aged 18 and over and is not directed at children. If you believe a child has provided information to our online services, contact support so we can investigate and take appropriate action.
8. Website, cookies and external links
Our hosting provider, Cloudflare, handles basic connection information to deliver and protect the website. We do not add advertising cookies or website analytics scripts. Fonts and images are hosted with the site. Your language choice is saved locally in your browser for future visits. We use your browser language to suggest an initial language.
External sites, including Apple, Google and helpline resources, have their own terms and privacy practices. Following a link does not send your Peyla journal to that site.
9. Contact and changes
For privacy questions or requests, email [email protected].
We may update this policy when practices or requirements change. The effective date appears at the top. Material changes will be communicated as required, and new permission will be requested before sharing where applicable.
