Privacy Policy – Inner Gate
Effective Date: 2026-09-11
This Privacy Policy explains how [LEGAL_ENTITY_NAME] (“Inner Gate”, “we”, “us”) collects, uses, shares,
and protects personal data when you use the Inner Gate mobile application and related services (the “App”).
1. Controller and Contact
Data controller: [LEGAL_ENTITY_NAME], [REGISTERED_ADDRESS].
Contact: [PRIVACY_EMAIL].
2. Personal Data We Collect
- Account data: email, password (stored as a hash), date of birth (used only to confirm you meet the age requirement), profile fields (name/nickname, bio), avatar URL, account status.
- User content: diary/journal entries, practice/progress records, and other content you submit in the App.
- Community data: chat messages and optional file attachments (URLs and metadata such as MIME type).
- Subscription data: subscription status/plan, the RevenueCat customer identifier, and purchase/invoice metadata returned by the payment provider.
- Support and communications: emails you send to support and our replies.
- Analytics and diagnostics: event telemetry (for example, feature usage) and error reports.
- Security and audit data: IP address and device / browser information (User‑Agent) recorded when you take sensitive or administrative actions, for security, abuse‑prevention, and audit purposes.
Age signal from your app store. The App is for adults only, so your date of birth is checked when you
register. On a mobile device the App may also receive an age range for the store account you are signed in to. On
iOS this is Apple’s Declared Age Range, and the system asks you whether to share the range with the App; on Android
it is Google Play’s age signals, which Google Play may provide to the App under your Play account’s settings, without
a separate prompt from us. We use that range in one direction only: it can restrict an account, and
it never unlocks anything — an “adult” answer grants nothing. A restricted account keeps access to support, to your
data export, and to deleting the account. We store what the platform reported (the age range, which platform it came
from, how the platform established it where the platform says so, and when it was reported and applied); it is
included in your data export, and we do not send it to anyone else.
3. How We Use Personal Data
- Provide the App and its features (accounts, content storage, community, progress tracking).
- Generate and deliver your data export on request.
- Maintain security, prevent abuse, and enforce our Terms (including moderation and handling reports).
- Process subscriptions and verify access to paid features.
- Communicate with you about your account (verification, notices, support).
- Improve the App through aggregated analytics and diagnostics.
4. Legal Bases (GDPR – for EEA/UK users)
If you are in the EEA/UK, we process personal data under these legal bases:
- Contract: to provide the App, including content storage, community features, and account management.
- Legitimate interests: to secure the App, prevent abuse, and improve services (balanced against your rights).
- Consent: where we rely on your consent — including your separate, explicit consent to process special‑category data (see Section 4a) and any optional analytics or marketing features — which you can withdraw at any time in your Profile settings.
- Legal obligation: where we must comply with law.
4a. Special Category Data & Explicit Consent
Your private journal entries and your interactions with our AI features may reveal information about your health,
wellbeing, or religious or philosophical beliefs. Under the GDPR this is “special‑category” data (Article 9). We
process such content only where you give separate, explicit, feature‑specific consent — one for private‑journal
storage and one for AI features — which you can withdraw at any time in your Profile settings. Withdrawing consent
stops any further processing of that content and deletes the content we hold for that feature:
withdrawing journal consent deletes your stored journal entries, and withdrawing AI consent deletes your stored
AI‑guide conversations. The App asks you to confirm first and offers you a data export before the deletion runs.
Three copies can outlive that deletion: a data export you asked for earlier stays downloadable
until its link expires, because it is your own copy; an AI‑guide answer you reported to us stays
with your report so we can act on it, for as long as we keep reports; and residual copies may remain in
backups until they are overwritten on the normal backup rotation. Section 7 gives the periods.
Withdrawal does not affect the lawfulness of processing already carried out before you withdrew.
5. Sharing and Third‑Party Processors
We do not sell your personal data. We share it with service providers acting as processors to operate the App, including:
- DigitalOcean Spaces: storing avatars, community uploads, and data exports.
- Postmark: sending transactional emails (verification, exports, deletion notices). These messages carry private links. The email-confirmation, password-reset and account-deletion links stop working once they have been used; the link that downloads your data export is different — it keeps working for anyone who has it until the export expires after 7 days. Treat them all like a password-reset link and do not forward them.
- Amplitude: event telemetry linked to your user ID and event properties.
- Google Analytics: on our marketing website only, and only after you consent to analytics cookies: page views and interactions, with IP addresses truncated by Google.
- DigitalOcean: hosting for the App’s servers, database, cache and the object storage listed above (DigitalOcean Spaces), in which all of the data above is stored and processed, and the hosting platform’s own record of the App’s server logs, which carry request metadata such as IP address and your user ID.
- Grafana Cloud (Loki): application logs shipped for operational monitoring where enabled; log lines carry request metadata such as IP address and your user ID, with tokens and secrets redacted before they leave the server.
- Sentry: diagnostics; depending on configuration, this may include device/network metadata and IP address. We do not attach your account identifier to these reports, and request bodies, cookies and anything credential-shaped are removed before a report leaves our systems.
- RevenueCat: subscription and purchase metadata tied to an app-user identifier (native in-app purchases via the Apple App Store and Google Play).
- Google Firebase Cloud Messaging: device push tokens and notification content (title and body, which may include message previews) are sent to Google’s Firebase Cloud Messaging (FCM) to deliver push notifications to your device.
- OpenAI: inputs you submit to the AI guide may be sent to OpenAI (via LangChain) to generate responses, and — where live web search is enabled for the App — your question is also rewritten into a search query and sent to OpenAI’s web-search tool, which queries public websites. OpenAI states that data sent to its API is not used to train its models, and that logs it keeps for abuse monitoring are retained for up to 30 days by default unless it is required to keep them longer. We set the API’s no-retention option (store: false) where the API supports it, which stops OpenAI storing the response but does not by itself remove the content from those abuse-monitoring logs; we minimize what we send and send no account identifier with it.
- Pinecone: vector storage that powers retrieval for the AI guide; your questions may be embedded and matched against lesson content.
We may also share data if required by law, to protect rights/safety, or in connection with a corporate transaction.
6. International Transfers
Some providers process data outside your country (including outside the EEA); Section 5 states the processing region
for each of them. Where a transfer needs a specific legal safeguard, we use the transfer mechanism that provider makes
available in its data‑processing terms, which for several of them is the Standard Contractual Clauses.
7. Retention
- Account deletion: when you delete your account, we anonymize key identifiers and soft‑delete the account; after 30 days it is scheduled for permanent deletion.
- Chat messages: retained for up to 1 year and then scheduled for deletion.
- AI guide conversations: retained for up to 1 year after the last message in the conversation and then deleted; you can delete a conversation yourself at any time with “start over”.
- Data exports: download links expire after 7 days; export files are intended to be deleted after expiry.
- Reports/abuse handling: retained as needed to investigate and enforce rules, and in any case for no longer than 2 years from the report, after which the report — including any reported content stored with it — is deleted.
- Security/audit logs: records of sensitive and administrative actions (including IP address) are retained for approximately 2 years and then deleted.
- Server logs: our hosting provider, and our log‑storage provider where log shipping is enabled, keep technical logs of requests to the App. These carry request details such as your IP address and your user ID, with passwords, tokens and other credentials removed before the line leaves our servers. They are kept for a limited period for security and troubleshooting and are not used to profile you.
- Backups: residual copies of deleted data may persist in encrypted backups for a limited period after the deletion — whether you deleted your account, withdrew a consent, or deleted a single entry — before they are overwritten on the normal backup rotation.
8. Security
We use technical and organizational measures designed to protect personal data, including access controls and encryption in
transit. No method of transmission or storage is 100% secure.
9. Your Rights
Depending on your location, you may have rights to access, correct, delete, or export your data; and to object to or restrict
certain processing. If you are in the EEA/UK, you also have the right to lodge a complaint with a supervisory authority.
You can request a data export and delete your account within the App. You can also request account and
data deletion from the web at https://inner-gate.com/account-deletion-request, without the app. For other
requests, contact: [PRIVACY_EMAIL].
10. California and Other US State Privacy Rights
We do not sell your personal information, and we do not share it for cross‑context
behavioral advertising, as those terms are defined under the California Consumer Privacy Act (as amended by the CPRA)
and similar US state privacy laws. We have not done so in the preceding twelve months.
Depending on your state of residence, you may have the right to know about and access the personal information we hold,
to request its deletion or correction, to opt out of the sale or sharing of personal information, and not to be
discriminated against for exercising these rights. You can request a data export and delete your account within the
App; for any other request, or to exercise a right described here, contact
[PRIVACY_EMAIL]. We will verify your request against your account before acting on
it, and you may use an authorized agent where the law permits.
Consumer Health Data (Washington My Health My Data Act)
If you are a Washington State resident, the My Health My Data Act applies to us (the Act has no business‑size
threshold). We treat your private journal entries and wellness reflections as “consumer health data”. We collect and
process this data only with your consent, we do not sell or share it, and we honor your requests to delete it.
Withdrawing your consent for a feature in your Profile settings deletes what we have stored for it — your journal
entries, or your AI‑guide conversations — and you can also delete individual entries or your whole account in the App.
The same three exceptions apply as in Section 4a: a data export you already asked for stays
downloadable until its link expires, an AI‑guide answer you reported to us stays with your report,
and residual copies may remain in backups until they are overwritten.
To exercise these rights, contact [PRIVACY_EMAIL].
11. Children
The App is not intended for anyone under 18, and we do not knowingly collect personal data from anyone under 18. If you
believe a person under 18 has provided us personal data, contact us and we will delete it.
12. Changes
We may update this Privacy Policy from time to time. If changes are material, we will notify you in the App and/or by email.
The “Effective Date” above indicates when the policy takes effect.
13. Contact
Privacy inquiries: [PRIVACY_EMAIL].