This policy describes the absorvia mobile app. It explains what stays on your device, what is sent to service providers, and the choices available to you.
1. Who We Are
absorvia is a personal journaling and thought-capture app operated by Truffle Techs L.L.C-FZ. We determine how personal data is used to operate the app. Contact us at [email protected] about this policy or your data rights.
2. Your Writing, Recordings and Settings
Your journal, tasks and saved reflections are stored on your device. The app does not provide a public feed or automatically publish your writing.
Voice capture requests microphone and on-device speech-recognition access when you use it. Audio is not uploaded by absorvia. After successful transcription, temporary audio is removed. If transcription fails, a local recording may remain so you can recover or export it from Settings. Delete All Data also removes these recovery recordings.
Optional iCloud backup is off until you turn it on in Settings. When on, a copy of your thoughts, with their tasks and saved reflections, and supported app settings is written to absorvia's private folder in your own iCloud account. We cannot read it and it is not sent to our server. Audio is not backed up. Turning backup off stops new copies and lets you delete the iCloud copy; Delete All Data also removes it; if iCloud cannot be reached at that moment, the app removes it the next time it can, and does not offer to restore it in the meantime. Apple operates iCloud under its own terms and privacy policy. Local widgets read selected journal-derived text and settings through storage shared privately with the app; this widget channel does not send data to our server. Personal details may appear in widget text.
Reminders are scheduled locally. You can change them in the app and control notification permission in iOS Settings.
3. AI Features and Sharing
Thought categories and the orb’s category colours can be determined on your device without AI consent. These categories describe writing, not a medical assessment of your emotional state.
AI features are optional. With your consent, relevant writing, recent excerpts and context such as recurring themes and writing preferences are sent to our backend and, when needed, to OpenAI to generate reflections, pattern reports or classifications. A request can include more than one capture. This can include sensitive themes you choose to write about. AI involvement is identified in the app. Generated text can be inaccurate and may repeat personal details from your writing.
You can withdraw AI consent in Settings. Withdrawal stops future AI processing and cancels pending app requests; it cannot recall requests already received by a provider or undo earlier lawful processing. Retention is explained below.
Share cards can carry your personal invite link. If someone installs absorvia through it, our backend records, under pseudonymous identifiers, which invite brought them, and later checks through RevenueCat whether they started a subscription. It never receives their writing or who they are. If their first payment stands, the person who invited them may be given one Apple Offer Code for a free month, redeemed through Apple. Invite records are kept for up to four hundred days and are used to prevent abuse, which includes rate limits by network address.
When you choose to export or share a card, text or recovered recording, the selected destination receives what you share. Review the preview first. Copies saved to Photos, files or other apps remain outside absorvia's local deletion controls.
4. Subscription, Usage and Diagnostic Data
Apple processes iOS payments. We do not receive your card or bank details. RevenueCat manages subscription and receipt information. For paid backend access, we verify store-signed purchase evidence against the subscription record. Persistent purchase references and hashed purchase lineages let us associate entitlements and usage limits across restores, devices or reinstalls.
We also process app usage events, such as screens viewed, feature actions and subscription status, to understand use and operate the service. These use persistent pseudonymous identifiers. Pseudonymous does not mean anonymous: records can remain associated with an installation or purchase even when we do not know your name or email.
PostHog receives limited product analytics when enabled in the release configuration. Our backend maintains usage and cost counters and aggregate analytics. The analytics pipeline excludes journal text, task text and generated reflections. Session replay is disabled.
Sentry receives crash, performance and operational diagnostics, such as stack traces, app/OS details, timing and a persistent pseudonymous user identifier. We configure filtering to remove request bodies, credentials and inappropriate content. We do not deliberately include journal text in diagnostics.
For Apple advertising attribution, the app sends Apple's attribution token to Apple's own attribution endpoint and keeps what Apple returns: whether the install came from an ad, and the campaign, ad group and keyword identifiers of that ad. Those identifiers describe the advertisement, not you. The token itself is never stored, never shared, and never leaves the device except to Apple's own attribution endpoint. No advertising identifier (IDFA) is read and no App Tracking Transparency prompt is shown. TikTok attribution uses Apple's aggregate SKAdNetwork mechanism; no TikTok advertising SDK or IDFA is used. We do not sell personal information, share it for cross-company targeted advertising, or build advertising profiles by combining your data with other companies' data. Absence of an advertising identifier or cookie alone is not treated as a privacy-law exemption.
5. Service Providers and Support
The services involved include:
- OpenAI: selected writing and requests for AI processing.
- RevenueCat: subscription, receipt and entitlement records.
- PostHog: limited pseudonymous usage analytics, using its EU cloud service.
- Sentry: technical diagnostics, using the configured US service.
- Apple: payment processing, optional iCloud, on-device system features and Apple advertising attribution.
- Our backend hosting and database services: request processing, temporary response caches, security controls and usage records.
Providers' roles depend on the service. Those processing data on our behalf are subject to applicable processing terms; Apple also operates its own services under its own privacy terms. We do not represent every vendor as acting solely on our instructions for every activity.
If you voluntarily email support, we receive your email address and whatever you include. The app does not read your mailbox. We use support messages to respond, investigate issues and handle rights requests; avoid sending journal content that is unnecessary for your request.
6. Why We Process Data
We process necessary data to provide the app and subscriptions, respond to requests, protect the service and understand its operation. Where applicable, legal bases include performance of the service contract, legitimate interests in security and service improvement, legal obligations, and consent for optional AI processing.
For EU/UK users, AI processing of special-category information in writing—such as health, beliefs, political views, racial or ethnic origin, sex life or sexual orientation—relies on explicit consent under Article 9(2)(a) and the corresponding UK provision. You may withdraw that consent in Settings.
We provide visible AI disclosures. We do not claim that a visible caption or an HTTP header alone proves compliance with every technical marking provision of the EU AI Act.
7. Retention and Deletion
- Local data: journal content remains until deleted. Delete All Data clears local journal and derived data, credentials/identifiers, notification schedules, widget snapshots, recovered recordings and private temporary exports. The app reports cleanup failure when it cannot complete this process.
- Backend AI response caches: currently used feature caches expire after one hour for short reflections, four hours for daily reflections and twenty-four hours for classifications. Cache keys are derived from inputs; cached outputs can still contain personal information. Hashing an input does not make its output anonymous.
- Repetition controls: text digests used to prevent repeated processing expire after up to thirty-one days. Digests are not readable text but can still be sensitive, particularly for common or guessable writing.
- Security and usage records: installation authentication records expire after about thirty days; cost and usage records generally expire after forty to forty-five days. Individual operations can refresh the relevant expiry.
- Purchase protection: raw purchase proofs are handled transiently for verification and are not deliberately stored in our logs, analytics or database. A hash of the proof and its verified state may be held in memory for up to sixty seconds. Hashed Google purchase-lineage mappings and one-time purchase usage-import markers may remain for up to four hundred days to preserve subscription limits across restores and reinstalls. These remain pseudonymous records.
- Aggregate analytics: backend aggregate records may remain for up to four hundred days. Provider analytics, diagnostics, support and required transaction records follow their configured retention and applicable legal needs; contact us about a specific record or deletion request.
- OpenAI: API data is not used for training by default. Standard Chat Completions requests may be retained for abuse monitoring for up to thirty days, subject to provider exceptions. For background pattern reports, the updated backend requests automatic deletion of input files after two days and output/error files after seven days. Provider batch metadata and abuse-monitoring retention are separate. These settings apply to newly created files after deployment; older files follow their existing expiry or require separate deletion review.
Deleting local data or rotating an installation identifier does not automatically erase provider records, cancel an Apple subscription or guarantee retained purchase/security records can no longer be associated. We assess requests to erase retained personal data and explain any lawful reason we must keep limited records, such as fraud prevention or transaction obligations. Previously shared copies are controlled by their recipients.
8. Your Rights
Depending on the applicable law, you may request access, correction, deletion, restriction, portability or information about your data, object to certain processing, or withdraw consent. Contact [email protected]. We may ask for proportionate evidence needed to locate your records and verify that the request is yours; do not send passwords or full payment details.
For requests covered by EU/UK GDPR, we ordinarily respond within one month. Where permitted for complexity or multiple requests, an extension may apply and we will explain it within that first month. You may complain to your relevant data-protection authority. Other local rights and response periods apply where the relevant law covers our processing.
9. Children
absorvia is intended for people aged thirteen and over and is not directed to children under thirteen. Store content ratings do not replace local legal consent requirements. If you believe a child has supplied personal data contrary to this policy, contact us so we can investigate and take appropriate action.
10. Security and International Processing
We use encrypted transport, platform security, access controls and data minimisation. Data may be processed outside your country, including in the EU and United States, depending on the service. Where required, appropriate transfer mechanisms, such as applicable contractual safeguards, must cover those transfers. Contact us for information about the safeguards applicable to your data.
11. Changes
We will update this policy when practices change and provide additional notice or seek consent where required. The date above identifies this revision.
About this website
The policy above covers the absorvia app. This part covers absorvia.com, the marketing website for the app, published by Truffle Techs L.L.C-FZ. It explains what data the website collects, why, who it is shared with, and how you can exercise your rights under the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, and the California Consumer Privacy Act as amended by the CPRA. Contact us at [email protected].
W1. What we collect on this website
Browsing this site does not require an account. We do not run forms, checkout flows, or email-capture surfaces. The data that reaches us includes the following categories:
| Data | Purpose | Lawful basis (GDPR) | Where it lives |
|---|---|---|---|
| UTM parameters from the URL (utm_source, utm_medium, utm_campaign, utm_term, utm_content) | Preserve ad-campaign attribution from landing to App Store click | Legitimate interest (Art. 6(1)(f)) | Your browser’s session storage; cleared when you close the tab |
| Your cookie/pixel consent choice | Remember your choice so we don’t re-ask on every visit | Legal obligation (Art. 6(1)(c)); keeping a record of consent as required by Art. 7(1) | Your browser’s local storage; up to 12 months |
| Your IP address & User-Agent | Serving the requested page; security; basic diagnostics | Legitimate interest (Art. 6(1)(f)) | Hosting & edge logs (see “Who we share data with” below) |
| Data seen by marketing pixels after you accept them | Attribution, conversion measurement, retargeting | Consent (Art. 6(1)(a)) | See “Cookies & similar technologies” below |
Cookieless analytics also count page views, referrers and App Store clicks, as explained below. If you email support, we receive your email address and whatever you include. We use it to respond and handle your request. Please avoid sending private writing unnecessarily.
W2. Cookies & similar technologies
We ask for your consent before setting any non-essential cookie, pixel, or storage. Consent is global opt-in: nothing in the marketing categories loads before you click “Accept” on the banner. If the Global Privacy Control signal is present in your browser, we treat that as an automatic opt-out.
First-party storage
- absorvia.consent: records your cookie choice and the timestamp. Stored in
localStorage. Keeps you from being re-asked on every visit. You can wipe it using the “Cookie settings” link in the footer. - absorvia.utms: attribution data captured from the URL when you arrive. Stored in
sessionStorage, cleared automatically when you close the tab. Used to encode a campaign token into the App Store link when you click the badge. Analytics providers may also receive the page URL and its campaign parameters; avoid putting personal information in links.
Privacy-friendly analytics (cookieless)
- Plausible Analytics: EU-hosted, cookieless aggregate analytics. No cross-site tracking, no cookies set, no persistent identifiers. When it is configured it loads on every visit, independently of the marketing consent choice, and counts page views and App-Store-badge clicks.
- Vercel Web Analytics: cookieless aggregate analytics from our hosting provider. It counts page views and referrers without browser cookies. It processes request information to produce aggregate statistics and loads on every visit. The marketing consent choice does not switch it off.
- Cloudflare Web Analytics: cookieless aggregate analytics from the network that sits in front of this site. It counts page views and the country a visit came from. It sets no cookies and stores nothing on your device, it does not follow you to other websites, and it does not build a profile of you. It is injected by the network on every visit and the marketing consent choice does not switch it off.
These count visits to this website. They are separate from the absorvia app and have no access to anything you write in it; the app’s own data handling is described in the policy above.
Marketing pixels (consent-gated)
These load only if you click “Accept” on the consent banner, and only if we have supplied the relevant pixel ID. Declining prevents them loading on a new page. Global Privacy Control is treated as an opt-out. Changing your choice cannot recall data already sent.
- Meta Pixel: records
PageViewandLeadevents, so our Meta ad campaigns can attribute installs. Cookies:_fbp,fr. Retention up to 90 days. - TikTok Pixel: records
BrowseandClickButtonevents for TikTok attribution. Cookies:_ttp. Retention up to 13 months. - Google Analytics 4: records pageviews and the App Store click event. Cookies:
_ga,_ga_*. IP anonymisation enabled; retention 14 months.
W3. Who we share website data with
Providers have different roles depending on the service. Those processing data on our behalf are subject to applicable processing terms; Apple and other providers also operate their own services under their own privacy terms. International processing is subject to applicable transfer safeguards. Contact us for details of the safeguards that apply to your data.
- Vercel (hosting, edge compute, cookieless Web Analytics): United States; DPF.
- Cloudflare (DNS, DDoS protection, edge proxy, cookieless Web Analytics): United States; DPF.
- Plausible Analytics (cookieless analytics): EU (Germany); no transfer needed.
- Meta Platforms (ad pixel; consent-gated): United States; DPF.
- TikTok / ByteDance (ad pixel; consent-gated): Ireland / United States / Singapore; Standard Contractual Clauses.
- Google (GA4 + Google Ads; consent-gated): United States; DPF.
- Apple: when you click the App Store badge, Apple receives your click plus our provider token and a campaign token derived from your UTMs. This handoff is initiated by you, on Apple servers, under Apple’s own privacy terms.
W4. How long we keep website data
- Your consent record: up to 12 months, then the banner re-appears and we ask again.
- UTM attribution: until you close the tab.
- Hosting request logs: typically up to 30 days at the hosting provider, then automatically purged.
- Analytics & pixel data: retained by each provider for the periods listed in section W2, which are the default retention windows of each service.
W5. Your rights on this website
Under the GDPR and UK GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- request correction of inaccurate data (Art. 16);
- request erasure of your data (Art. 17);
- request that processing be restricted or object to processing based on legitimate interest (Arts. 18 & 21);
- withdraw consent at any time, for any future processing (Art. 7(3));
- lodge a complaint with a supervisory authority (for EU residents the one in your country; for UK residents the Information Commissioner’s Office).
California residents additionally have the right to know, to delete, to correct, to opt out of sale or sharing, and to non-discrimination under the CCPA/CPRA. Because we do not knowingly “sell” personal information in the traditional sense, our Do-Not-Sell-or-Share affordance is the same “Decline” button on the consent banner: clicking it prevents data from reaching any marketing pixel. We also honour the Global Privacy Control signal.
To exercise any of these rights, email [email protected]. We will respond within one month under the GDPR/UK GDPR, or within 45 days under the CCPA.
W6. Children
This site is not directed to children under thirteen. We do not knowingly collect data from anyone younger. Section 9 above covers the app.
W7. Security
We serve the site over HTTPS only, with strict transport security, a restrictive content-security policy, and the other defensive headers recommended by OWASP. In the event of a personal-data breach that is likely to result in risk to your rights, we will notify the relevant supervisory authority within 72 hours and contact you directly where the risk is high (GDPR Arts. 33 & 34).
W8. Changes to this notice
If we change the scope of what this site processes (for example, if we add a new pixel or a new processor) we will update this page, bump the last-updated date above, and ask you to confirm your consent again. The last-updated date is the authoritative version marker.