Legal
Privacy Policy
Last updated: March 13, 2026
Outspiral ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share information when you use the Outspiral mobile application ("App").
1. Information We Collect
Account Information
- Email address (for email registration)
- Apple ID identifier (if you sign in with Apple; we do not receive your Apple password)
- Display name (optional)
Episode & Journal Data
- Episode logs you create, including triggers, intensity ratings, body sensations, context notes, and timestamps
- Post-episode reflections
- Toolkit entries (strengths anchors, if/then plans, response scripts)
Usage Analytics
- App usage patterns (screens visited, features used, session duration)
- Device type, operating system version, and app version
- Crash logs and error reports
Subscription Data
- Subscription status and transaction identifiers (managed through RevenueCat)
- We do not store or have access to your payment card details
2. How We Use Your Information
- To provide and maintain the App and its features
- To authenticate your account and manage your subscription
- To perform on-device pattern analysis of your episode data
- To send local notifications you have opted into (evening check-ins, post-episode follow-ups, monthly reports)
- To improve App performance, fix bugs, and develop new features
- To respond to your support requests
3. Data Storage & Security
Your data is stored securely using Google Firebase (Authentication and Cloud Firestore). Firebase infrastructure is hosted in the United States and complies with SOC 1, SOC 2, and SOC 3 standards. Data is encrypted in transit (TLS) and at rest.
Pattern analysis is performed on your device. Raw episode data is not sent to external analytics services.
4. Third-Party Services
We use a limited number of third-party services to operate the App:
- Firebase Authentication & Cloud Firestore (Google): account management and secure data storage
- RevenueCat: subscription management and receipt validation
- Apple App Store: payment processing for subscriptions
Each service processes only the minimum data required for its function. We do not use advertising SDKs or sell your data to any third party.
5. Data Sharing
We do not sell, rent, or trade your personal data. We share data only in these limited circumstances:
- With the third-party services listed above, strictly to operate the App
- When required by law, regulation, or valid legal process
- To protect the safety, rights, or property of Outspiral, our users, or the public
6. Data Retention
We retain your data for as long as your account is active. If you delete your account, we will delete your personal data and episode logs within 30 days. Anonymized, aggregated data (which cannot identify you) may be retained for analytics purposes.
7. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: request a copy of the personal data we hold about you
- Correction: request correction of inaccurate data
- Deletion: request deletion of your data (also available via Settings > Delete Account in the App)
- Portability: request your data in a portable format
- Objection: object to processing of your data for certain purposes
To exercise any of these rights, contact us at support@outspiral.app. We will respond within 30 days.
8. Children's Privacy
Outspiral is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy in the App and updating the "Last updated" date above. Continued use of the App after changes constitutes acceptance of the revised policy.
10. Contact Us
If you have questions about this Privacy Policy or your data, contact us at support@outspiral.app.