Privacy Policy
Last updated 13 August 2026 · Applies to Riseful for iOS
Riseful is a self-reflection app. Most of what you put into it is private by nature — how you speak to yourself, what you're struggling with, what you wrote in your journal. This policy explains exactly what we store, where it goes, and what we don't do with it.
We do not sell your data. We do not share it with advertisers. There is no analytics SDK, no advertising SDK, and no cross-app or cross-site tracking in this app.
1. Who we are
Riseful ("we", "us") provides the Riseful mobile application. For any privacy question, or to ask us to delete your data, contact us at rimabas0102@gmail.com.
2. You do not create an account
Riseful does not ask for an email address, a password, or a social login. When you first open the app it signs you in anonymously through Firebase Authentication, which issues a random identifier for your installation. That identifier is how your entries are kept together across sessions.
We cannot look up a person by name or email, because we never collect either from an authentication provider. If you type your first name during onboarding so the app can address you, that name is stored with your entries — but it is something you chose to type, not something we verified or obtained elsewhere.
3. What we store
| What | Why | Where |
|---|---|---|
| Anonymous user identifier | Keeps your entries together across sessions | Firebase Authentication |
| Onboarding answers — the first name you type, how you've been feeling, your self-kindness rating, how you speak to yourself, where your sense of worth comes from, what gets in your way | Builds your initial self-love profile and personalises the app | Cloud Firestore |
| Daily check-ins and the reflections you write | Powers your profile chart and your history | Cloud Firestore |
| Journal entries | So you can read back what you wrote | Cloud Firestore |
| Report answers and results | Generates and stores your reports — your answers are sent to Google's Gemini model to write the report | Cloud Firestore, via a Cloud Function; Google Gemini API |
| Whether the daily reminder is switched on | Schedules a reminder on your device | On your device only |
| Progress through the 21-day journey, streaks, unlocked content | Keeps your place | Cloud Firestore |
| Subscription and purchase status | Unlocks paid features and restores purchases | RevenueCat |
| App settings and small preference flags | Remembers your choices between launches | On your device only |
How your reports are written
When you complete a report, your answers are sent from our server to Google's Gemini API, which writes the text of the report. The result is saved back to your own document and shown to you. We send only the answers for that report and the first name you typed — never your journal, your check-ins, or anything from another part of the app.
Google states that data submitted through the paid Gemini API is not used to train its models. We do not log the contents of these requests.
Sensitive content
Some of what you record — your journal, your check-in reflections, your answers about how you treat yourself on hard days — is personal and can be sensitive. It is stored under your anonymous identifier and our database rules are written so that only the account that recorded an entry can read it. No other user can read your entries, and entries cannot be listed across accounts.
4. What we do not collect
- No name, email address, phone number, or postal address from any sign-in provider
- No contacts, photos, microphone, camera, precise location, or health-kit data
- No advertising identifier (IDFA), and no App Tracking Transparency prompt, because we do not track you
- No third-party analytics or attribution SDKs
- No payment card details — Apple handles payment and we never see your card
5. Who processes data on our behalf
These are the only third parties involved, and each acts as a processor for us:
- Google Firebase (Authentication, Cloud Firestore, Cloud Functions) — stores your entries and runs the function that assesses your report answers. Firebase privacy
- Google Gemini API — writes the text of your reports from the answers you give. Gemini API terms
- RevenueCat — manages subscription state and purchase restoration. RevenueCat privacy
- Apple — processes payments and operates the App Store. Apple privacy
- Google Fonts — the app loads its typefaces through the Google Fonts service.
6. Where your data is held
Your entries are stored on Google Cloud infrastructure and may be processed in countries outside your own, including the United States. Where transfers are subject to UK or EU data-protection law, they rely on the safeguards Google offers for international transfers, including Standard Contractual Clauses.
7. How long we keep it
We keep your entries for as long as your installation remains active, so that your history and progress stay available to you. If you ask us to delete your data we will do so within 30 days. Backups are overwritten on a rolling basis and any residual copies are removed within 90 days.
Deleting the app is not the same as deleting your data. Because sign-in is anonymous and tied to your installation, removing the app from your device makes your entries unreachable to you but does not erase them from our database. To have them erased, email rimabas0102@gmail.com before you delete the app, and we will confirm once it's done.
8. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to how it's used, and receive a copy in a portable format. Under UK and EU law you also have the right to complain to your data-protection authority — in the UK, the Information Commissioner's Office.
Because we hold no identifying details, we may need you to make a request from the device holding your installation so we can locate the right records. Email rimabas0102@gmail.com and we'll explain what's needed.
9. Notifications
If you turn on the daily reminder, it is scheduled locally on your device for one fixed time each evening. There is no push service, no device token, and nothing is sent to us when it fires — we cannot tell whether you received it or opened it. Only the on/off setting is stored, on your device. Turning the reminder off in Settings, or revoking notification permission in iOS Settings, removes it.
10. Children
Riseful is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has provided us with data, contact us and we will delete it.
11. Security
Data is encrypted in transit and at rest by our infrastructure providers, and our database rules restrict every document to the account that created it. No system is perfectly secure, and we cannot guarantee absolute security, but we design for least access as a matter of course.
12. Changes to this policy
If we change how we handle your data we will update this page and change the date at the top. Material changes will be surfaced in the app before they take effect.
13. Contact
Questions, requests, or complaints: rimabas0102@gmail.com.