Reflexy Privacy Policy
The privacy policy for the Reflexy app and reflexy.app website: what is stored on your device, what Apple and RevenueCat process, and your choices.
Applies to Reflexy for iOS and iPadOS 3.0 and later, and reflexy.app
What changed
· Version 1.0
Complete rewrite to describe the current app and website accurately. Replaced the previous template-based text, which listed services Reflexy does not use, and added an effective date, rights sections and website details.
Privacy at a glance
Reflexy works without a Reflexy account or a journal server operated by the developer. This policy explains what the Reflexy app and the reflexy.app website process, why, and the choices you have.
- Journal entries and attached photos are stored on the device with iOS file protection. The system photo picker gives Reflexy only the photo you select; the app does not request general photo-library access.
- App lock is enabled by default, but setup can be skipped and the lock can be disabled. The passcode is not stored in plaintext. iOS performs optional Face ID or Touch ID authentication; Reflexy receives the result, not biometric data.
- New
.reflexybackups are encrypted before export or iCloud upload. Automatic iCloud backups are off by default and create saved copies, not live synchronization. The recovery key normally follows through iCloud Keychain, and Reflexy provides a recovery code. Reflexy never asks for an Apple Account password. - Apple and RevenueCat process purchase metadata for access, restoration, and purchase analytics. Journal entries, photos, passcodes, and backup contents are not sent to the developer or RevenueCat.
- Reflexy has no ads, advertising tracking, cross-app tracking, or behavioral analytics about journal activity.
- Contact Support can prepare a previewable technical report from app/iOS versions and sanitized error codes held only for the current launch. You can exclude it, and nothing is sent until you choose to send the email. Journal content is never added automatically.
- Erasing the journal removes local journal data, photos, and retained local exports. It does not delete iCloud backups, files exported elsewhere, purchase records, or credentials. System iOS device backups are managed separately.
- On reflexy.app, Cloudflare delivers the site and blocks abuse. Analytics is cookieless and counts visits only. The contact form emails your message to our support mailbox and keeps short-lived, hashed rate-limit records; the website does not store your message.
Who we are
Reflexy is developed and published by an independent developer (“we”, “us”). Contact: [email protected] or https://reflexy.app/contact.
We are the controller of the little personal data we receive: purchase metadata handled for us by RevenueCat, your support messages and the website data described below. Apple is an independent controller for everything under your Apple Account.
Scope
This policy covers the Reflexy app for iPhone and iPad (iOS 17 or later), the reflexy.app website including its contact form (which sends from [email protected]), and email you send to [email protected].
It does not cover Apple’s services (the App Store, iCloud, iCloud Keychain, Face ID and Touch ID, system device backups), destinations you choose in the iOS share sheet, or websites we link to; each has its own terms and privacy policy. Opening the Privacy Policy or Terms of Use from the app loads this website, so the website part of this policy applies to that visit too.
Summary of what is processed
| What | Why | Where it goes | How long | Shared with |
|---|---|---|---|---|
| Journal content (stories, text, feelings, needs, activities, aims, tags, photos) | Keeping your journal | Your device, with iOS file protection | Until you delete it, use “Erase journal on this device” or remove the app | Nobody, unless you create a backup or export |
| App-lock passcode | Locking the app | Protected verification data in the device Keychain, not the passcode itself | Until you change it; disabling “App lock” keeps the credential | Nobody |
| Face ID or Touch ID | Optional unlock | Handled by iOS; Reflexy gets only the result | Not stored by Reflexy | Nobody |
| Backup files and recovery code | Saving and moving your journal | Your device, your iCloud or a share-sheet destination you pick; the recovery key in iCloud Keychain | 5 recent local exports and 5 automatic iCloud backups; manual iCloud backups until you delete them | Apple (iCloud) and destinations you choose |
| Purchase metadata (purchase history, product and transaction identifiers, dates, access status, anonymous app-user identifier) | Trial, lifetime access, restoring, refunds, purchase analytics | Apple and RevenueCat | Under their policies; the RevenueCat record is deleted on request | Apple, RevenueCat |
| Support email and optional technical report | Answering you | Your email provider and our Zoho Mail mailbox | As long as needed to help you | Zoho Mail |
| Website visit (IP address, request headers, requested page) | Delivering the site and blocking abuse | Cloudflare’s network | Short-lived logs under Cloudflare’s rules | Cloudflare |
| Website analytics (cookieless) | Counting visits | Cloudflare Web Analytics | Only aggregates are kept | Cloudflare |
| Contact form (name, email, message, Turnstile check) | Delivering your message and limiting abuse | Turnstile; a Cloudflare Worker with keyed hashes of IP and email plus counters in Cloudflare D1; Resend to Zoho Mail | Hashes and counters expire after 48 hours (duplicate check 15 minutes); Resend delivery logs for a limited period; the message is not stored by the website | Cloudflare, Resend, Zoho Mail |
Local storage (reflexy.theme) | Remembering your theme choice | Your browser only | Until you clear site data | Nobody |
The app
Your journal
Journal entries, feelings, needs, activities, aims, tags and attached photos are stored locally on your device using iOS file protection. There is no Reflexy account and no developer-operated server for journal content. Reflexy does not send journal entries, selected feelings, photos, app-lock passcodes or backup contents to us or to RevenueCat. Journal content leaves your device only through a backup, export or share destination you choose, or through your iOS device backup (see below).
App lock
App lock is enabled by default, but you can skip its initial setup or disable it in Settings. When disabled, Reflexy opens without requiring an app passcode, Face ID or Touch ID. If a passcode is set, protected verification data is stored in the device Keychain; the passcode is not saved in plaintext. Disabling “App lock” does not delete an existing credential. Biometric unlock is a separate opt-in setting. iOS performs Face ID or Touch ID authentication; Reflexy receives only the authentication result and does not receive or store biometric data.
Photos
Reflexy uses the system Photos picker. The app receives only an image you explicitly select and does not request general access to the photo library. The saved journal copy does not retain the original photo’s location or EXIF metadata.
Insights
Insights charts summarize what you recorded. Reflexy does not analyze your writing, does not use AI, and does not send your journal to any AI service.
Backups, iCloud and sharing
Backups contain the journal database and attached photos. You can create a local backup, export it through the iOS share sheet, save it to your private iCloud container, or explicitly enable automatic iCloud backups. Automatic iCloud backups are disabled by default. Reflexy does not copy these backups to a developer-operated server.
Automatic backups create saved copies of the journal; they do not provide live synchronization between devices. After you enable them, the app attempts a backup and saves later changes when it has an opportunity while running or moving to the background. It does not guarantee a background schedule. Completion and availability on other devices depend on iCloud, available storage and connectivity.
New Reflexy backup files are encrypted before they are exported or uploaded to iCloud. The journal database, photo names and photo contents are inside the encrypted file. The recovery key normally becomes available on another device through iCloud Keychain, and Reflexy gives you a recovery code to save privately. The 6-digit app-lock passcode is not the backup key. If iCloud Keychain does not provide the key on another device, you can enter the recovery code inside Reflexy. The app does not ask for or receive an Apple Account password. Without the matching Keychain key or recovery code, an encrypted backup cannot be opened. iCloud can see that a backup file exists, its name and its size, not the journal inside it.
Reflexy can import older plaintext backup formats. After an external legacy import it creates an encrypted replacement for you to save. Legacy backups inside Reflexy’s managed iCloud container are uploaded and verified in encrypted form before the plaintext originals are removed. The app cannot delete an original legacy file stored in a third-party location.
iCloud is provided by Apple and is governed by your Apple Account settings and Apple’s terms and privacy policy. A destination selected in the system share sheet processes the exported backup under that destination’s own terms. Share backups only with destinations you trust, because a backup contains private journal content.
System iOS device backups are separate from Reflexy’s iCloud backup feature and may include local app data according to your device and Apple Account settings. Turning off automatic backups in Reflexy does not turn off or erase system device backups.
Purchases
Apple processes payments. RevenueCat processes purchase history, product and transaction identifiers, purchase dates, access status and an automatically generated anonymous app-user identifier. This supports purchase validation, restoration, refunds and purchase analytics. The app does not provide RevenueCat with a name, email address, advertising identifier, custom account ID, journal content, photos or backups. It disables automatic device-identifier collection. An anonymous identifier is not a promise that every transaction is technically impossible to correlate.
The purchase SDK can initialize and refresh purchase information automatically during normal app use, before you choose to buy or restore access. Network activity for these purchase services is not limited to a purchase button press.
The trial starts only when you choose the free trial product. It lasts 14 days and never causes an automatic charge. Lifetime access is a separate one-time purchase. Apple’s signed purchase history is also used to preserve access for users of earlier versions. Local backups do not contain purchase credentials or reset the trial.
The App Store shows the price for your storefront. We do not receive your name, email address or payment details from Apple. Refunds are handled by Apple (reportaproblem.apple.com).
RevenueCat processes purchase data on our behalf under its data processing terms; Apple processes your purchase as an independent controller. See Apple’s privacy policy and RevenueCat’s privacy policy.
Diagnostics and Contact Support
When an operation fails, Reflexy can write technical diagnostics to the local Apple logging system. It also keeps up to 25 sanitized technical error records in memory for the current app launch. Those records contain a predefined operation context, a broad error category, numeric error codes and a timestamp. They do not contain raw error messages and are discarded when the app process ends.
You can open “Contact Support” and optionally include a technical report. The report adds the app and iOS versions, broad device family and a one-time report identifier to those sanitized records. Before leaving Reflexy, you can preview the full report or exclude it. Reflexy does not add journal entries, feelings, needs, activities, aims, tags, photos, passcodes, backup recovery codes, purchase details or stable device identifiers. It does not upload the report or send the email automatically.
Continuing opens your email app with [email protected] as the recipient. You can inspect, edit, cancel or send the message there. Text you type and any included technical report are processed by your email provider and by Reflexy support only if you send the message. The app does not operate a separate telemetry upload service. This does not control Apple’s system diagnostics or device settings. RevenueCat supports purchase-related functionality and purchase analytics, not recording journal activity.
Reflexy includes no crash-reporting or analytics SDK. Depending on your iPhone’s analytics settings, Apple may share crash and diagnostic data with developers; we do not control that setting.
Network-backed functionality includes Apple StoreKit, RevenueCat purchase services and optional Apple iCloud backup. Opening the Privacy Policy, Terms of Use or support email uses the appropriate system app. Any information you voluntarily include in a support email is processed for answering that request.
We keep support conversations for as long as needed to help you. Please do not paste journal content into a support message; a description of the problem is enough.
The website
Hosting and security
reflexy.app is a static site delivered by Cloudflare, which acts as our content delivery network, firewall and bot protection. When you load a page, Cloudflare processes your IP address, request headers (such as browser type and language) and the requested page to deliver the site and to defend it against abuse. Cloudflare keeps short-lived request and security logs under its own rules; we run no web servers of our own.
Fonts and the App Store badge are served from reflexy.app itself. Apart from Cloudflare’s analytics script and the Turnstile check on the contact page, the site loads no third-party resources. www.reflexy.app redirects to reflexy.app, and every response carries security headers that restrict where scripts and content may load from. Cloudflare may set the strictly necessary cookies __cf_bm (about 30 minutes) and, after a security challenge, cf_clearance.
Analytics
We use Cloudflare Web Analytics, which is cookieless: it sets no cookies, stores nothing in your browser and does not track you across websites. To count a visit, Cloudflare processes your IP address and request headers momentarily and derives your country; only aggregates are kept, such as page views, referring sites, browser and device types, countries and page load times. We cannot identify you from them. Our legal basis is our legitimate interest in understanding how the site is used. Because nothing is stored in your browser for analytics, there is no cookie banner.
Contact form
The form asks for your name, email address and message. When you send it:
- Cloudflare Turnstile checks that the submission comes from a real browser. It analyzes browser signals and your IP address and does not use tracking cookies.
- A Cloudflare Worker validates the form and applies rate limits. For that it stores keyed hashes (not the values) of your IP address and email address, plus counters, in a Cloudflare D1 database. These records expire after 48 hours and are then deleted; a keyed hash of your email address and message together is kept for 15 minutes to ignore duplicates. Cloudflare’s rate limiting also counts requests per IP address for a short time.
- The Worker emails your message through Resend from [email protected] to our support mailbox at Zoho Mail, with your email address as the reply-to address. Resend keeps delivery logs for a limited period.
The website does not store your message. If the form is unavailable, email [email protected] directly.
Cookies and local storage
| Name | Set by | Purpose | Type | Duration |
|---|---|---|---|---|
reflexy.theme | reflexy.app | Remembers your theme choice when you pick light or dark | Local storage, strictly necessary | Until you clear site data |
__cf_bm | Cloudflare | Distinguishes real browsers from bots | Cookie, strictly necessary | About 30 minutes |
cf_clearance | Cloudflare | Records that you passed a security challenge | Cookie, strictly necessary | Set by Cloudflare’s challenge settings |
All of these are strictly necessary, so no consent is needed. Reflexy uses no advertising or tracking cookies.
Legal bases
Where the GDPR or UK GDPR applies, we rely on these legal bases:
| Processing | Legal basis |
|---|---|
| Journal content, app-lock passcode, Face ID or Touch ID | Not processed by us; it stays on your device and in the backup destinations you choose |
| Purchase metadata | Contract (Article 6(1)(b)); legitimate interest (Article 6(1)(f)) in fraud prevention and aggregated purchase analytics |
| Support requests | Contract or pre-contractual steps (Article 6(1)(b)); legitimate interest in helping you |
| Website delivery, security and contact-form anti-abuse records | Legitimate interest in a secure, available website free of spam |
| Website analytics (cookieless) | Legitimate interest in understanding how the site is used |
| Records the law requires us to keep | Legal obligation (Article 6(1)(c)) |
We do not make automated decisions with legal or similarly significant effects, and we do not profile you. Accepting the Terms of Use in the app is not consent to data processing.
International transfers
Apple, RevenueCat and backup/share providers you select may process the information they receive in the locations described by their policies. The app’s use of local journal storage does not determine where those providers process purchase information or user-directed backups and exports.
RevenueCat, Cloudflare, Resend and Zoho may process data outside your country, including in the United States. Where the GDPR or UK GDPR applies, those transfers rely on the EU-US Data Privacy Framework (and its UK extension) for providers certified under it, and otherwise on standard contractual clauses in the providers’ data processing terms.
Retention and deletion
Local journal data remains on the device until you delete individual content, use “Erase journal on this device”, or remove the app according to iOS behavior. The in-app erase action deletes the local journal database, including stories, activities, aims and tags, along with local photos, retained local backup exports and temporary working files. Built-in suggestions are then restored. It does not delete iCloud backups, copies previously exported to other destinations, system device backups, the device-only app-lock credential or the backup recovery secret kept in iCloud Keychain.
The normal retention limit is 5 recent local exports and 5 automatic iCloud backups; cloud cleanup depends on iCloud being available. Manual iCloud backups remain until deleted. You can delete iCloud backups separately in Reflexy or through Apple’s iCloud controls. Copies exported elsewhere must be managed at their destination.
Erasing the local journal does not erase Apple’s or RevenueCat’s purchase records, cancel ownership, or restart the trial. Purchase record retention and deletion requests are subject to the providers’ policies and applicable requirements. Contact support with purchase-data requests; do not include private journal content.
On the website, contact-form hashes and counters expire after 48 hours (the duplicate check after 15 minutes), Resend keeps delivery logs for a limited period, Cloudflare keeps request and security logs for a short time under its own rules, and support emails stay in our mailbox for as long as needed to help you.
How to delete everything
- Delete entries in the app, or use “Erase journal on this device” in Settings.
- Delete iCloud backups in Reflexy or through Apple’s iCloud controls.
- Delete backup files you exported to other apps, folders or services.
- Review your iOS device backups if you do not want app data kept there.
- For purchase records, contact us (we can ask RevenueCat to delete your record) or Apple.
Your rights
If you are in the EU, the EEA or the UK, you can ask for access to the personal data we hold about you, have it corrected or erased, restrict or object to its processing, receive it in a portable format, withdraw consent where processing is based on consent, and complain to a data protection supervisory authority. Similar rights may apply where you live under other laws; we honor them in the same way.
How to exercise your rights
Email [email protected] or use the contact form. We answer within 1 month, free of charge; for complex requests we may take up to 2 more months and will tell you if so. Because Reflexy has no account, we verify requests with the email address you write from and details only you would know; for purchase records, that means the purchase date, the product and the order ID from your Apple receipt.
We cannot see, correct or delete journal content: it is on your device and in the backups you choose, so you delete it there. We can ask RevenueCat to delete the record linked to your anonymous app-user identifier; that may affect restoring your purchase, and Apple’s own purchase records stay with Apple.
California residents
We do not sell or share personal information as California law defines those terms, and we do not use it for targeted advertising. You have the right to know what personal information we hold, to delete it, to correct it, and not to be discriminated against for exercising these rights. Send requests to [email protected]; we respond within 45 days. You may use an authorized agent; we will ask for proof that you authorized them.
Children
Reflexy is not directed to children under 13. If you are under that age where you live, use Reflexy only with a parent’s or guardian’s consent, and ask them to read this policy with you. We do not knowingly collect personal information from children. Purchases by minors are governed by Apple’s settings, such as Ask to Buy. If you believe a child has sent us personal information, contact us and we will delete it.
Security
On your device, the journal and photos are stored with iOS file protection. The app-lock verification data is kept in the device Keychain, and the backup recovery secret in iCloud Keychain. New .reflexy files are encrypted by Reflexy before they are exported or uploaded to iCloud, using Reflexy’s application-level authenticated encryption. The 6-digit app-lock passcode is not the backup key.
On the website, all traffic uses HTTPS, responses carry security headers, and Cloudflare provides a firewall, bot protection and rate limiting. The contact form stores keyed hashes rather than IP or email addresses.
No system is perfectly secure. Keep your recovery code private and choose backup destinations you trust.
Third parties
| Provider | Role | What it handles |
|---|---|---|
| Apple | Independent controller | App Store and StoreKit purchases, iCloud, iCloud Keychain, Face ID and Touch ID, the Photos picker, the App Store review prompt, system diagnostics |
| RevenueCat | Processor for us | Purchase metadata and the anonymous app-user identifier |
| Cloudflare | Processor for us | Website hosting, firewall and bot protection, Web Analytics, Turnstile, the contact Worker and its D1 database |
| Resend | Processor for us | Delivery of contact-form emails from [email protected] |
| Zoho Mail | Processor for us | Our support mailbox |
Reflexy does not use advertising networks, crash reporters, analytics SDKs, social logins, or AI services.
Changes to this policy
If Reflexy’s data practices change, this policy and the App Store privacy answers are updated before the changed version is released. Material changes get a new effective date and an entry in the change log on this page. We cannot notify you personally because we do not have your email address; the app links to the current version from Settings and from the introduction.
Contact
Email [email protected] or use the contact form at https://reflexy.app/contact. Please do not include journal content in your message.
Version history
· Version 1.0
Complete rewrite to describe the current app and website accurately. Replaced the previous template-based text, which listed services Reflexy does not use, and added an effective date, rights sections and website details.
Questions about this document? Email [email protected].
Back to top