Skip to content
HAND MADE WITH LOVE
FREE SHIPPING ON ALL U.S. ORDERS $35+

Start Your Reset ✨ Explore Self Care Tools

Privacy Policy - Mobile

Privacy Policy — BodyByKeke: Mind

Last updated: 17 August 2026

This policy explains what the BodyByKeke: Mind mobile app collects, why, who else sees it, how long it is kept, and what you can do about it. Purchases made on our website are covered by our separate store privacy policy.

1. Who we are, and how to reach us about privacy

BodyByKeke: Mind (“the app”) is operated by ClarityCI LLC (“we”, “us”), Kissimmee, Florida, United States.

ClarityCI LLC is the controller of the personal information described here — the party that decides what is collected and why. Section 8 sets out which of our providers act on our instructions and which act for themselves.

Person responsible for privacy The Privacy Officer, ClarityCI LLC — the contact for any privacy question, request, or complaint. Under Quebec’s Law 25 the person in charge of the protection of personal information is the person exercising the highest authority at ClarityCI LLC, who may delegate that function in writing; privacy requests from Quebec residents reach the Privacy Officer at the addresses below and are handled under that authority.
Email privacy@clarityci.com, or support@clarityci.com — both reach the same team. Put “Privacy request” in the subject line and it is routed to the Privacy Officer.
Postal address 931 McInnis Ct Kissimmee, Florida USA 34744

2. Where this app is offered

BodyByKeke: Mind is offered in the United States and Canada only. It is not marketed or made available in the European Economic Area, the United Kingdom, or Switzerland, and we do not target users there.

Because of that, we have not appointed an EU Article 27 representative or a UK representative, and the transfer mechanisms those regimes require (Standard Contractual Clauses, the UK Addendum or IDTA) do not apply to this app. If that changes, this policy will be updated before the app becomes available in those regions. Section 13 covers Canadian users, whose data is stored in the United States.

3. The short version

  • Your journal entries are encrypted on your device before they are sent to us. We store them only in encrypted form and do not hold the key needed to read them.
  • We do not sell your personal information and we do not disclose it for cross-context behavioural advertising, and we do not track you across other companies’ apps or websites. We do disclose personal information to the service providers that run the app for us, listed in section 8.
  • We never use your mood data for marketing. It reaches our product analytics only if you switch that on yourself, under Profile → Privacy Choices — off until you turn it on, and the app works the same either way.
  • Our product analytics use a pseudonymous ID — random, and not your account ID. It is not the same thing as anonymous, and section 8.1 explains the difference honestly.
  • You can delete your account from inside the app. Section 10 is specific about what that reaches and what it does not.

4. What we collect

4.1 Information you give us

What Why
Email address and password To create and secure your account. Your password is sent from the app over an encrypted connection to our authentication provider, which stores it only as a hash. It does not pass through any server of ours, and we do not store plaintext passwords. If you sign in with Apple or Google, we never handle a password at all.
Name or display name (optional) To address you in the app.
Time zone, reminder time, notifications on/off To send reminders at the right local hour, and to know when your day rolls over.
Mood check-ins — a 1–5 rating, a word for it, an optional note, and a timestamp The core feature: tracking how you feel over time. This is health-related information — see section 5.
Me-time blocks and rituals — title, optional intention, steps, start and end time The self-care planner.
Journal entries The journal. Encrypted on your device — see section 6. Two things about an entry are not encrypted, because they are what let us list your entries without being able to read them: when it was written or changed, and how many words are in it.
Circle names, your nickname in each Circle, and your sharing switches The Circles feature. See section 7.
Reports you file — the reason, anything you type, and a copy of the wording you reported So a person on our team can look at it and act. Read by us on purpose; see section 7.4.
Accounts you block So the app can keep the two of you apart. Visible only to you — see section 7.4.
Product wishlists To remember what you saved in the shop.
Your privacy choices, and the date you made them So we can honour them, and show that we did.

4.2 Information collected automatically

The previous version of this policy under-described this. The full list:

What Where it goes, and why
A random pseudonymous analytics identifier, generated on first launch and stored on your device To our analytics provider, to count usage. Not your account ID. See section 8.1 for why we no longer call this “anonymous”.
Your IP address Unavoidably visible to every service your device connects to. Our analytics provider receives it and uses it to derive an approximate region (typically country or state). We do not store IP addresses in our own database.
Device and app characteristics — model, operating system version, app version, language, time zone, and screen size To our analytics provider, which collects these automatically with every event, and used for support and debugging.
Which screens you open, and when the app is opened and closed To our analytics provider, under the pseudonymous ID.
Error diagnostics — the text of an error message when the app crashes, and the name of whichever data request failed To our analytics provider, under the pseudonymous ID, so we can find and fix faults. See section 8.4.
Push notification token To deliver reminders, nudges, and session invites. See section 9.
Last-active timestamp Stored on your account, to power re-engagement email and push, and to know when an account has gone quiet.

4.3 Information from others

  • Apple or Google, if you use Sign in with Apple or Google Sign-In: the identifier and email address those services release to us. If you use Apple’s private relay, we only ever see the relay address.
  • Apple or Google, when you subscribe: your subscription status, renewal date, and whether there is a billing problem, by way of our subscription provider. We do not receive your card number or other payment credentials for those purchases. See section 8.3.

5. Mood check-ins are health-related information

How you feel is health-related information about you, and in several places it is a special or sensitive category with its own rules. We treat it that way.

What we mean by the term. We use health-related information throughout this policy as a plain-language description of information that may reveal something about your mental or emotional well-being — principally your mood check-ins and their notes. Different privacy laws define and name this kind of information differently, and where we mean a particular law’s term we say which law. Section 12 explains how it maps onto California’s “sensitive personal information”.

The app is not health care. BodyByKeke: Mind is a self-care tool. We do not provide medical or mental-health treatment, we are not acting as your health-care provider or health plan, and we do not bill any insurer. What you record here is not a HIPAA-covered medical record, and HIPAA does not apply to us merely because we collect health-related information. The protections that do apply to what you enter here are the ones described in this policy, together with the privacy, security, and consumer-protection laws that govern us — several of which treat this information as sensitive, as sections 12 and 13 describe.

5.1 Recording it, and using it inside the app

Recording your mood, showing it back to you, building your streak, and generating your insights is what the app is for. You choose whether to use mood tracking at all, and we use what you enter to operate that feature and nothing else.

How we ask. Before you begin, the app shows a consent screen that says in plain terms that it collects mood check-ins, that your journal is encrypted on your device, and that mood data is not used for analytics or email unless you turn that on. You continue by tapping “I agree”, and declining takes you back rather than into the app. We record which version of these documents you accepted and when. To the extent the law where you live requires express consent for health-related information, that screen is where we ask for it.

Stopping. You can stop checking in at any time — nothing else in the app depends on it. Changing today’s check-in overwrites it. The app does not currently offer a way to delete one past mood entry on its own; to remove your mood history you delete your account (section 10.1), or email us and we will delete the entries for you.

5.2 One opt-in, off by default

Agreeing to use a mood tracker is not agreement to have your moods fed to an analytics tool. That is a separate decision, it is asked separately, and it is off unless you turn it on under Profile → Privacy Choices:

Switch What it permits Default
Share mood ratings for product analytics Your mood rating (the 1–5 number) may be sent to our product analytics provider, attached to the pseudonymous ID described in section 8.1 — not to your account, name, or email. Never the note text. Off

Turning it off stops any further sending immediately. It does not reach back and delete what was already sent — and because we hold no record linking those events to your account, we cannot tell which of them are yours in order to remove them (section 8.1).

We do not use health information for marketing. Mood ratings are never sent to our email provider, under any setting — there is no switch for it, because we removed the capability rather than offering it. Our email is personalised on things like whether you have finished setting up, whether you subscribe, which features you use, and what you have saved in the shop.

5.3 What never happens to your mood data, whatever you switch on

  • Your mood note text is never shared with another user, never sent to our analytics provider, and never sent to our email provider. It stays in your account and on your devices.
  • Your exact rating is never shown to another user. Within a Circle, and only if you switch it on, your mood is shared as one of three coarse bands (low, okay, good). This is off by default.
  • We do not use your mood data to make automated decisions about you, we do not sell it, and we do not use it to train machine-learning models.

6. Your journal is encrypted, and we cannot read it

Journal entries are encrypted on your device with AES-256-GCM before they are transmitted. Our servers store the encrypted text, an initialisation vector, and a key fingerprint. They never receive the readable text or the encryption key.

Please understand what that means before you rely on it:

  • We do not hold the key needed to read your journal, so we cannot recover it — not for you, and not for anyone else. There is no administrative override, because there is no key for us to override with.
  • To read your journal on a second device, you set a passphrase. Your key is encrypted on your device using a key derived from that passphrase with PBKDF2-HMAC-SHA256, and what we store is that sealed key together with the random salt used to derive it. Your passphrase is never sent to us, and we do not store it, a hash of it, or a recovery copy of it. Deriving it back from what we hold would mean guessing it, which is what the key derivation function described in section 14 is chosen to make impractical.
  • If you forget that passphrase, there is no reset. Entries written on a device you no longer have may become permanently unreadable. This is a deliberate design choice and the direct cost of the guarantee above.
  • An export of your data will not contain readable journal entries. We can only give you what we hold, and what we hold is ciphertext. To keep a readable copy, copy the text out on a device where you can already read it.
  • Because we do not hold your journal in readable form, we generally cannot provide its readable contents in response to a legal demand. We can be compelled to produce what we do hold — the encrypted text, which we cannot decrypt, because we do not hold the key required to do so, along with account records and information about when entries were written or changed.

7. Circles — what other people can see

Circles are private, invite-only groups of 2–8 people. There is no directory, no search, no public profile, and no way for a stranger to find you. A Circle can only be joined with a code shared directly by an existing member.

7.1 What members of your Circle see

  • The nickname you chose for that Circle — not your account name
  • Whether you completed a me-time block today — a yes or no, never the title or intention of the block
  • Your check-in streak, if you have streak sharing on
  • A three-level mood band (low, okay, good), if you have mood sharing on — off by default
  • Short fixed-text encouragements (“nudges”) you send them, and shared session proposals you create
  • That you have not checked in today, if you switch on streak rescue — a per-Circle setting that is off by default. With it on, and only once you have a run of check-ins going, the other members of that Circle can be sent a notification saying you could use a nudge tonight. It exists so the people you chose can notice a quiet day, and it is the one thing in this list that tells them something about your mood tracking rather than showing them a number. It names you and nothing else: not your rating, not your streak length, and not why. Turn it off in that Circle’s settings, and turning nudges off for a Circle turns it off too.

7.2 What members of your Circle never see

Your journal, your mood notes, your exact mood rating, your block titles or intentions, your email address, your account name, your other Circles, or anything at all about your subscription.

7.3 What we cannot control once you have shared

This is the part worth reading twice. Sharing inside a Circle is a disclosure to other people, and the protections above are technical, not magical:

  • We cannot un-share what has been seen. Another member can screenshot, remember, or repeat anything your Circle shows them. Switching mood sharing off stops future disclosure; it does not retrieve past disclosure.
  • An invite code can be passed on. Anyone holding a valid code can join, up to the eight-member limit, and will then see what the Circle shows. Codes are not tied to the person you sent them to. Three things limit the damage if one is forwarded: a code expires 14 days after it is issued, the owner can rotate it at any time — which invalidates the old one immediately — and the owner can remove any member who has joined. Give codes only to people you would tell in person, and ask the owner to rotate if one gets out.
  • A coarse band is still information about your health. “Low” three days running says something real to someone who knows you. Share it with people you trust with that.
  • Once you share something with your Circle, we cannot control what its members do with it — how they use it, copy it, remember it, or repeat it to someone else. Our technical measures govern what the app shows them; they cannot reach anything that happens outside it.

7.4 Reporting and blocking

The app lets you report content or a person, and block a person, from inside a Circle. Both create a record, and it is worth knowing what is in it.

  • When you report something, we store: that it was you who reported it, who or what you reported, which Circle it was in, the reason you chose from the list, anything you typed in the optional box, and a copy of the reported wording as it stood at that moment — the nickname, Circle name, or session title. We take that copy on purpose: a name can be changed in seconds, and without it a report made in good faith would arrive with nothing to look at.
  • Your report is read by a person on our team. That is the one place in this app where a human being at our end deliberately reads something you have written. We do not tell the person you reported who reported them, and we do not show your report to anyone outside the small number of people who handle them.
  • Reports are not sent to our analytics or email providers. What reaches analytics is two labels — which kind of thing was reported and which reason you picked — and nothing else. Not the Circle, not either person, and never the text you wrote.
  • When you block someone, we store only that you blocked that account and when. They are not told, and the app gives them no way to find out: the record is readable by you and by nobody else. The effect is symmetric — neither of you appears to the other anywhere in the app — but the knowledge of it is not.
  • A block is not a report. Blocking protects you and tells us nothing. If someone has broken the rules, report them as well.

How long these records are kept, and what happens to them when an account is deleted, is in section 10.2. Reports are the one category we deliberately do not delete along with the reporter’s account — see that section for why.

7.5 Leaving

You can leave a Circle at any time, and a Circle owner can remove any member and rotate the invite code. Leaving takes you off the roster immediately: from that moment nobody in that Circle can see your shares or send you anything, because the server checks current membership on every one of those actions. The app provides no direct-contact or messaging relationship between users outside a shared Circle — no profiles to look up, no way to reach someone you once shared a Circle with.

What does not disappear is the record of what already happened. Nudges you sent or received, and your responses to shared-session invitations, remain in our database associated with both accounts. They are not visible to the Circle you left and cannot be used to contact you, and they are removed when the Circle is deleted or when either account is deleted — but until then they exist, and it would be inaccurate to tell you that leaving erases every trace of the connection.

8. Who else processes your data

We use the providers below. Each receives only what it needs. The role column matters: a processor (a “service provider” under California law) may only use your data to perform the job we hired it for, under contract with us. An independent controller decides its own purposes and applies its own privacy policy, which we do not control. The role shown is how we characterise that provider for the processing described in the same row, under the law that applies to you and our current contract with it. A provider can act in more than one capacity, and the same relationship can be characterised differently under different laws; where that happens, the row describes the arrangement rather than settling a legal question.

Provider What it receives Purpose Role
Supabase Your account and the app data described in section 4.1 — journal entries as encrypted text only Hosting, database, authentication Processor
PostHog Product analytics events under a pseudonymous identifier, your IP address, device and app details, and mood ratings only if you switched that on Understanding feature usage — see section 8.1 Processor
Klaviyo Your email address, account identifier, name, and shop activity. No mood or other health data Lifecycle and marketing email — see section 8.2 Processor
RevenueCat Your account identifier and subscription status Managing subscriptions and access Processor
Apple App Store and Google Play Purchase and billing information Processing subscription payments. We do not receive your card number or other payment credentials Independent controller
Expo Your push token and the notification text Sending push notifications on our behalf — see section 9 Processor
Apple Push Notification service and Google’s Firebase Cloud Messaging Your push token and the notification text, passed on by Expo The operating-system networks that actually deliver a notification to your device — see section 9.1 Independent controller
Amazon Web Services (Amazon S3 and Amazon CloudFront) The guided-audio files themselves, and each request for one — which carries your IP address and your device’s network details. A request carries no account identifier, and the audio is the same for every listener Storing and delivering guided audio over a content delivery network. Access is controlled by short-lived signed links, so the files are not publicly reachable Processor
Shopify Order and delivery details, only if you buy something Storefront and checkout, under the store policy Independent controller

Changes to this list. The table above lists the third-party providers currently configured to receive personal information from the app. If we add or replace one, we will update this policy and change the “last updated” date before the new provider begins receiving data. If a new provider would receive health-related information, we will tell you in the app and ask again before any of it is sent — a consent you gave about one recipient does not carry over to a different one.

We may also disclose information where we are legally required to, or to protect the rights and safety of our users. Section 6 limits what we are able to disclose about journals regardless of who asks.

8.1 Analytics use a pseudonymous ID — which is not the same as anonymous

Our analytics use a randomly generated identifier created on first launch and stored on your device. It is not your account ID, not your email, and not a device advertising ID.

An earlier version of this policy called that identifier “anonymous”. That was wrong, and it is worth being precise about why. The identifier persists, so it links one install’s entire event history together, and your IP address travels with those events. Data that can be tied to a single person — even without their name — is pseudonymous, not anonymous. It is still personal information, this policy still applies to it, and your rights under section 11 still cover it.

What the identifier buys you is real, and it is this: we do not send our analytics provider your account ID, your name, your email address, your journal, your mood notes, or the name, identifier, or invite code of any Circle — specifically so that a social graph cannot be reconstructed there. Event properties pass a fixed allowlist inside the app before transmission; anything not on that list is discarded before the event leaves your device.

The identifier is reset if you delete and reinstall the app, or clear its data. Note the consequence, which we would rather state than hide: because our analytics identifier is intentionally not linked to your account, we hold no record connecting an account to the analytics identifier that account’s events were sent under. Our analytics provider can delete a person’s events when it is told which identifier to delete — but we cannot work out which identifier is yours, so we cannot make that request on your behalf from your account details alone. That is the direct cost of not linking them in the first place, and it is why section 10.1 lists analytics separately from everything else deletion reaches. Deleting the app, or clearing its data, ends the link between your device and the identifier it was using and starts a fresh one.

What the “Share mood ratings for product analytics” switch does and does not cover. That switch governs your mood ratings only. Turning it off stops any mood rating being sent, immediately. Ordinary product analytics — which screens you opened, whether a feature was used, error diagnostics — continue either way, under the pseudonymous ID and the allowlist described above. There is currently no in-app switch that turns off product analytics as a whole; if you want that, email us and we will tell you what we can do.

We do not track you across other companies’ apps or websites, and we do not use advertising SDKs.

8.2 Email uses your identity, carries no health data, and is opt-out

Our email provider intentionally receives your identity, because lifecycle email has to reach a person. It receives your email address, account identifier, name, and your shop activity.

It receives no health data. Your mood ratings, mood notes, and journal never go to it, and there is no setting that changes that. We personalise email on non-health signals only — whether you have finished setting up, whether you subscribe, which features you use, and what you have saved in the shop.

Every marketing email carries an unsubscribe link, and we treat re-engagement email — the messages that go out when an account has been quiet for a while — as marketing, so unsubscribing stops those too. What unsubscribing does not stop is essential service messages: password resets and other security notices, subscription, billing and receipt notices, and notices about your account or changes to these documents. Those are not marketing and there is no opt-out for them while your account exists.

8.3 Subscriptions and payment

This section is about subscriptions bought inside the app. Anything you buy from our online store is handled by that store and is covered by the store privacy policy, not by this section.

In-app subscriptions are sold through the Apple App Store and Google Play, and they process the payment. For those purchases we do not receive or store your card number, billing address, or any other payment credential — they go to Apple or Google directly, under their own privacy policies, and Apple and Google act for themselves in handling them.

What we receive, by way of RevenueCat, is: whether you have an active subscription, which product it is, when it renews or expires, and whether there is a billing problem. That is linked to your account ID so the app knows what to unlock. Apple and Google retain transaction records for their own tax and accounting obligations, on their schedules, not ours — deleting your BodyByKeke account does not delete a purchase record held by Apple.

8.4 Crash and error diagnostics

We do not use a dedicated crash-reporting service. When the app hits an error, it sends the error message text and the name of the failed data request to our analytics provider, under the pseudonymous ID, so faults can be found and fixed.

These messages are generated by the app and its libraries and are not intended to contain anything you wrote. We do not send journal text, mood notes, or message contents in them. We cannot promise that an error message from a third-party library will never quote a fragment of data back — no system that reports errors truthfully can — so we keep the allowlist tight and treat these reports as personal information covered by this policy.

9. Notifications, calendar, and other permissions

  • Notifications — used for your daily reminder and, if you use Circles, for nudges and session invites. You can turn them off in the app or in your device settings.
  • Calendar — requested only if you choose to mirror a me-time block to your device calendar. Both platforms grant calendar access as a single read-and-write permission, so what the app is technically able to do is broader than what it does. What it does: read the names of your calendars, so you can pick which one to write to; create, update, and delete the events it created for your own blocks; and store each event’s identifier on your block so the two stay in step. It does not read your existing events, and no calendar information leaves your device — the calendar you picked is remembered on the device itself, and the only thing stored on our servers is the identifier of an event we created.

Those two are the only permissions the app asks for. It does not request access to your photos, camera, microphone, contacts, or location, and it does not ask to track you across other apps.

Each is requested at the point of use, and each is optional: declining either does not prevent you from using the core features of the app. Declining notifications means you will not get reminders or hear from your Circle; declining calendar access means blocks stay inside the app.

9.1 What a push notification actually contains

Worth knowing, because a notification appears on your lock screen where other people can see it:

There are five kinds, and this is all of them:

  • Daily reminders carry a short prompt and that day’s affirmation — generic text from a fixed set, never anything you wrote.
  • Circle nudges carry a fixed phrase from a small set and the sender’s Circle nickname. Never a free-text message.
  • Shared session invites carry the Circle nickname of whoever proposed it, the time of the session, the title they gave the session, and the name of the Circle. Those last two are words a member typed, so they are the one case where text another user wrote can appear on your lock screen. They are the same words already shown to everyone in that Circle, and both are limited to 40 characters and checked against our prohibited-wording list before they can be saved (section 6.1 of the Terms).
  • Streak-rescue messages go to the other members of a Circle when someone who has switched this on has not checked in and a streak is at risk — see section 7.1. They carry that person’s Circle nickname, or, where more than one person is involved, the name of the Circle. They never say what her mood was, only that a check-in has not happened today.
  • Monthly recap and re-engagement messages carry generic text and no personal detail — that a recap is ready, or that it has been a while.
  • Never sent in a notification: journal text, mood notes, mood ratings, or your me-time block titles and intentions.

Push notifications travel from us through Expo’s push service and then through Apple’s or Google’s notification networks to your device. Those services can see the notification text in transit; this is how push notification works on every app on your phone, and it is why the contents are kept generic. You can turn notifications off entirely at any time.

10. How long we keep things, and what deletion actually reaches

10.1 Deleting your account

When you ask us to delete your account, the deletion process begins immediately, and for 30 days it can still be called off — so that a deletion made in a bad moment can be undone. During that period the account is restricted: it is scheduled for removal, you are excluded from Circle rosters, and we send you no notifications — no daily reminder, no nudge, no session invite, and no re-engagement push.

Stopping a deletion takes a deliberate act, not just a sign-in. To cancel, sign in and tap Cancel deletion on the notice shown in Profile. Signing in on its own does not cancel it — that is deliberate, so that someone who gets into your account cannot reverse a deletion you meant simply by opening the app.

After 30 days, a scheduled job permanently deletes your account. That removes your profile, mood check-ins, journal entries — including any still sitting in Recently Deleted — me-time blocks, rituals, Circle memberships, wishlists, push tokens, and your escrowed journal keys from our live database. It cannot be undone.

Be clear about what that does not immediately reach, because “all of your data, everywhere, instantly” is not something any honest service can promise:

Where What happens on deletion
Our live database Deleted at the end of the 30-day period.
Encrypted database backups Backups run on a rolling window and each expires on its own schedule — see 10.2. The deletion happens at the end of the 30-day period, so backups taken before then still contain your data; every one of those ages out of the window within 7 days of the deletion, and backups taken afterwards do not contain it. Backups are not used to restore individual records and are only ever restored wholesale after a disaster.
Server and API logs Operational logs may contain your account identifier and IP address; they expire on the schedule in 10.2 rather than on request.
Analytics events These are held under a pseudonymous identifier we hold no record of linking to your account, so we cannot tell which events are yours in order to have them deleted. They contain no name, email, or account ID. See section 8.1.
Email provider We request deletion of your marketing profile — tell us when you delete your account, or email us any time. We may keep a minimal suppression record, such as your email address, so that we do not email you again; see 10.2.
Apple, Google, and our subscription provider Transaction and subscription records are retained by them for their own legal and accounting obligations. We cannot delete those.
Other members of your Circles Anything they already saw, they already saw. See section 7.3.
Reports you filed about someone else The report survives, with your name taken off it. Deleting your account removes the link to you, so the report can no longer be traced back or replied to — but the reason, the wording you reported, and the account it was about remain in the moderation record. We do this deliberately: a report is also evidence about somebody else, and an account that has been reported eleven times by eleven people who have since left should not read as an account nobody ever complained about.
Reports somebody else filed about you The same. They are not deleted with your account, and the copy of the wording that was reported stays with them.
Shared sessions you proposed The session and the title you gave it stay in the Circle until that Circle is deleted, with your name taken off. This is the same choice we make for a Circle you created, and for the same reason: other people put that session in their calendars and answered it, and deleting it out from under them would rewrite their week rather than yours. Your responses to other people’s sessions, and the record of your having been invited, are deleted with your account.
Accounts you blocked Deleted with your account. A block only ever existed to shape what you saw.

10.2 Retention periods

Data Kept for
Account, profile, moods, blocks, rituals, wishlists As long as your account exists, then deleted 30 days after you request deletion.
Journal entries (encrypted) As long as your account exists. Deleting an entry moves it to Recently Deleted, where you can restore it; a scheduled job permanently purges it 30 days later. You do not have to wait — Recently Deleted also lets you delete a single entry, or empty the whole list, immediately and irreversibly. If you delete your account while entries are sitting in Recently Deleted, they go with the account at the end of its 30-day period, whether or not their own 30 days have run — whichever of the two comes first is when an entry is actually gone.
Circle nudges and shared-session responses Kept while the Circle exists — including after you leave it, as section 7.5 explains. Deleted when the Circle is deleted, or when either the sending or the receiving account is deleted.
Shared sessions themselves, and their titles Kept while the Circle exists, and not deleted with the account of whoever proposed one — only the link to that account is removed. See 10.1. They go when the Circle does.
Reports of content or of a person 3 years from the date of the report, or longer where we need them for a legal claim or an ongoing investigation. Each holds who reported it, who or what was reported, the reason, anything the reporter typed, and the copy of the wording taken at the time. Kept that long for one reason: a pattern across years is often the only thing that distinguishes one bad afternoon from a person who behaves this way. Deleting either account does not delete the report — it removes the link to that account. See 10.1.
Accounts you have blocked Until you unblock them, or until either account is deleted. The record is one row saying that you blocked that account and when, readable by you and by nobody else — not by the person blocked.
Push tokens Deleted when you sign out or delete your account. Turning notifications off stops us sending but does not by itself remove the token. Tokens the push service reports as invalid — after you uninstall, for example — are deleted automatically.
Encrypted database backups 7 days
Server, API, and authentication logs Retention depends on the system that produced the log, and is between 1 and 7 days across all of them. Authentication logs are held by our authentication provider on the same schedule.
Analytics events 1 year
Email marketing profile Until you unsubscribe or delete your account. We then request its deletion from our email provider. We may retain a minimal suppression record — your email address or an equivalent identifier, and nothing more — indefinitely, because honouring an unsubscribe requires remembering it. Our email provider may also keep such a record under its own obligations.
Email engagement history (opens, clicks, and the events we send) Up to 24 months after your last interaction, after which it is deleted or anonymised.
Subscription records Held by Apple, Google, and our subscription provider for as long as their own legal and accounting obligations require.
Your privacy choices and consent record For as long as your account exists, and for a reasonable period afterwards where we need it to show that we honoured them.

11. Your choices and your rights

Wherever you live, you can:

  • Access the data on your account, and get a copy of it
  • Correct your profile information, in the app under Profile
  • Delete your account and its data, in the app under Profile → Delete Account, or by emailing us. Section 10.1 sets out exactly what deletion reaches — in particular, analytics events are held under an identifier deliberately not linked to your account, so we cannot tell which events are yours in order to have them deleted
  • Withdraw consent to mood analytics at any time, in the app under Profile → Privacy Choices — as easily as you gave it
  • Unsubscribe from marketing email, from any marketing email
  • Object to or restrict processing, and complain to a regulator (section 12 and 13 name the right one)

We do not sell your personal information, and we do not disclose it for cross-context behavioural advertising. We do disclose it to the service providers listed in section 8, which process it on our behalf to run the app. We do not use it to train machine-learning models.

To exercise any right, email privacy@clarityci.com, or write to us at the postal address in section 1. We will acknowledge your request promptly and respond within the time the law applicable to your request requires. For example, Canada’s federal privacy law generally requires a response to an access request within 30 days, and California law generally provides 45 days for a verifiable consumer request — both subject to the extensions those laws permit, which we would tell you about. We may need to verify that you control the account before acting, and we will not charge you or treat you differently for asking.

11.1 Getting a copy of your data

Ask us at privacy@clarityci.com and we will send you a copy of the personal information we hold about you, in a commonly used machine-readable format. An export covers your account and profile, mood check-ins and their notes, me-time blocks and rituals, Circle memberships and the sharing settings you chose, wishlists, your consent record, your subscription status, the reports you have filed, and the accounts you have blocked.

Two things an export leaves out, both because they are about someone else rather than about you: the other members of your Circles, and reports about you. On the second — we will tell you what action was taken on your account and why, which is what section 6.6 of the Terms promises, but we will not hand over a report in a form that identifies who made it. Naming a reporter to the person they reported is how reporting stops happening.

Journal entries are the exception, and it is worth understanding why before you ask. They are provided in the encrypted form we hold, because that is the only form we have — they will not be readable outside the app, and no export we can produce will change that. To keep a readable copy, copy the text out on a device where you can already read it. See section 6.

12. California residents

If the CCPA/CPRA applies to us and you are a California resident, this section describes your California rights and the disclosures that law requires. Section 11 sets out the access, correction, deletion, consent-withdrawal, and objection choices we offer to every user wherever they live — subject to applicable law and the limits this policy describes — so most of what follows is available to you in practice regardless of whether the statute reaches us.

12.1 Categories of personal information

Category (CCPA/CPRA) Collected? Disclosed to whom, and why
Identifiers (email, name, account ID, device ID, IP address) Yes Service providers: hosting, email, analytics, subscriptions
Customer records (name, contact details) Yes Service providers: hosting, email
Commercial information (subscriptions, wishlists, orders) Yes Service providers and the app stores, to process and manage purchases
Internet or network activity (screens viewed, app usage, error diagnostics) Yes Service provider: analytics
Geolocation Approximate only, derived from IP by our analytics provider Service provider: analytics. We do not collect precise location and the app never requests location permission
Sensitive personal information — health-related information, including mood check-ins and their notes, and any journal content that reveals information about your health Yes Held in your account. Mood ratings are disclosed to our analytics provider only where you switched that on (section 5.2), and to no one else. Health data is never disclosed to our email provider. Journal entries are encrypted on your device, so neither we nor any provider can read them or tell whether a given entry concerns your health at all
Biometric information, precise geolocation, race, religion, union membership, immigration status, genetic data, contents of your mail No Not collected

We collect these from you directly, from your device, and from Apple and Google when you sign in or subscribe. We keep each category for the period in section 10.2, and no longer than is reasonably necessary for the purpose it was collected for.

12.2 Sale, sharing, and sensitive information

We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the preceding 12 months — including the personal information of anyone we know to be under 16.

We use sensitive personal information only to provide the app you asked for and for the one optional purpose you switch on yourself, and we do not use or disclose it to infer characteristics about you or for any marketing purpose. California’s right to limit the use of sensitive personal information is directed at uses beyond those permitted by the statute, and we do not believe we make any. You may nevertheless write to us to limit our use or disclosure of sensitive personal information, and we will handle the request as the law requires. The switch in Profile → Privacy Choices gives you immediate control over the one optional use without waiting for a request, and turning it off is the fastest route to the same result.

12.3 Your California rights, and how to use them

  • Know what we collect, use, and disclose — this policy, plus a specific copy on request
  • Delete your personal information, subject to the limits in section 10.1
  • Correct inaccurate personal information
  • Opt out of sale or sharing — there is nothing to opt out of, as above
  • Limit the use of sensitive personal information
  • Non-discrimination for exercising any of these

There are two ways to make a request: email privacy@clarityci.com, or write to us at the postal address in section 1. Either reaches the Privacy Officer. You may use an authorised agent; we will ask for proof of their authority and may ask you to verify the request directly.

Global Privacy Control. GPC is a signal sent by web browsers. BodyByKeke: Mind is a native mobile app and does not process browser-based GPC signals. Our website handles GPC according to its own privacy notice. You can send us an opt-out request by email at any time, and the switch in Profile → Privacy Choices remains available to you regardless.

You may also appeal a decision we make about a request by replying to it, and you may complain to the California Privacy Protection Agency or the California Attorney General.

13. Canadian users

If you are in Canada, we handle your personal information in accordance with the Canadian privacy law that applies to us — which, depending on where you live, may be the federal PIPEDA or a provincial regime, including Quebec’s Law 25. The commitments in this section apply to Canadian users generally.

  • Your data is stored in the United States by our hosting provider, and our other providers process personal information in the United States and, in some cases, elsewhere. While it is outside Canada it is subject to the law of the country it is in, and may be accessible to that country’s courts and to law-enforcement or national-security authorities under that law. We tell you this because you are entitled to know where your information goes before you decide to use the app.
  • We contract with our providers to protect your information at a level comparable to what Canadian law requires, and we assess that protection before a provider begins handling your data. Where Quebec law requires an assessment of privacy-related factors before information is transferred outside Quebec, or before a service provider outside Quebec handles it on our behalf, we carry that assessment out and record its conclusion.
  • Mood and journal information is sensitive personal information, particularly given its potential to reveal information about your mental or emotional health. We therefore ask for your express consent — on the screen described in section 5.1 before you begin, and again, separately, for the optional analytics use in section 5.2.
  • You may access, correct, and withdraw consent as described in section 11, and you may ask us how your information has been used and to whom it has been disclosed.
  • The Privacy Officer named in section 1 handles privacy requests and complaints, including those from Quebec residents, under the authority described there.
  • If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, or, in Quebec, the Commission d’accès à l’information.

14. Security

Specifically, and each of these is implemented rather than aspirational:

  • Data is encrypted in transit with TLS. Our database, its backups, and our object storage are encrypted at rest by the providers that hold them; we rely on their implementations and do not claim that every store uses an identical scheme.
  • Journal entries are additionally encrypted on your device with AES-256-GCM, so the server holds only ciphertext (section 6).
  • The passphrase that moves your journal key between your devices is stretched on your device with a password-based key derivation function chosen to resist offline guessing, and what is stored is the key sealed under the result, together with the random salt used to derive it. Your passphrase itself is never sent to us, and neither is your journal key. We review the parameters periodically and will raise them as hardware improves.
  • Your session credentials are held in your device’s secure keychain or keystore, not in ordinary app storage.
  • Access to your data on our servers is enforced at the database level, row by row, so one account cannot read another’s.
  • A user cannot grant themselves a subscription: entitlement is decided by the subscription provider, and the columns that record it are not writable by the app.
  • Premium audio is served through signed, expiring URLs checked against your live entitlement, not through a public link.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your data, we will notify you and the relevant regulators as required by law — see section 15.

15. If there is a breach involving health information

Because the app handles health-related information, certain United States health-data breach laws may apply to us — including the FTC Health Breach Notification Rule, whose scope turns on the nature of the service we provide and the information we maintain. We maintain an incident-response process designed to meet the breach-notification requirements applicable to us, built to that Rule’s standard. If unsecured health-related information is acquired without your authorisation, we will:

  • notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering it, using the method required by applicable law — which will normally include email and an in-app notice;
  • notify the Federal Trade Commission where that Rule requires it. Where 500 or more people are affected, that notice goes at the same time as notice to individuals and no later than 60 calendar days after discovery. For smaller incidents, the Rule’s annual reporting deadline applies instead;
  • notify prominent media in a state or jurisdiction where 500 or more residents are affected;
  • tell you what happened, what information was involved, what we are doing about it, and what you can do.

This is in addition to any state breach-notification law, and to our obligations to Canadian users — where Canadian law requires it, we report a breach to the applicable privacy commissioner, which for a breach engaging the federal law means the Office of the Privacy Commissioner of Canada, and we keep the records of breaches that law requires us to keep.

16. The app is for adults

BodyByKeke: Mind is intended for people aged 18 and over, and we do not knowingly collect personal information from anyone under 18.

The reason is the subject matter. The app asks you to record how you feel, keeps that history, shows it back to you, lets you share a coarse version of it with a private group of other people, and takes subscription payments. That is a real decision about your own mental well-being, and it is one an adult should be making for themselves. Setting the line at 18, rather than at the lowest age a privacy statute would allow, is a deliberate choice: we are not building this for younger users, we have not built a parental-consent process, and we do not want a child’s mood history in our database at all. Section 3 of the Terms of Service says the same.

If you believe someone under 18 has created an account, email privacy@clarityci.com and we will delete the account and the information in it promptly. That commitment covers — and goes well beyond — the protection United States law gives to children under 13.

We do not sell personal information and do not disclose it for cross-context behavioural advertising, so the separate California restriction on selling or sharing the information of consumers under 16 has no application here either.

17. Changes to this policy

If we change this policy materially, we will tell you in the app before the change takes effect. Where a change would mean using health-related information in a new way, we will ask for your consent again rather than rely on this notice. The “last updated” date at the top always reflects the current version.

18. Contact

Privacy Officer, ClarityCI LLC — privacy@clarityci.com or support@clarityci.com.
931 McInnis Ct Kissimmee, Florida USA 34744

We aim to acknowledge privacy requests quickly, and we answer within the deadlines set out in section 11.