Privacy Policy
Last updated: [DATE]
This Privacy Policy explains how HeyIro Ltda ("HeyIro", "we", "us") collects, uses, and protects your personal data when you use the Introspection mobile and web application (the "Service").
We take privacy seriously because the Service is a private space for self-reflection. Your journal entries describe your feelings and personal life, and we treat them accordingly.
- Controller: HeyIro Ltda [CNPJ], [registered address, Brazil]
- Privacy contact: privacy@heyiro.com
1. What data we collect
We only collect what the Service needs to work.
1.1 Data you provide
- Account: email address and password (passwords are stored only as salted hashes by our authentication provider — we never see them).
- Profile ("about you"): optional details you choose to share — name, age range, gender, occupation, family situation, children, parents, hobbies, pets, and living situation.
- Journal entries: the text (or transcribed voice) of your reflections, the emotions and intensity you record, the time of day, and any place, people, or tags you attach.
- People in your life ("environment"): names or labels of contacts you add and how they affect you emotionally.
- Conversations: messages you exchange with the in-app assistant ("Iro") and notes you save.
- Tasks, goals, and summaries you create or that the Service generates from your entries.
1.2 Data collected automatically
- Device push token (if you enable notifications), to deliver reminders.
- Diagnostics/telemetry: app version and last-active timestamp, to operate and secure the Service.
- Usage metering: counts of AI text tokens and speech-to-text minutes, to enforce fair-use limits and account for costs.
- Subscription status (tier, trial, renewal state) from the app store / billing provider.
- Crash reports (if enabled): technical diagnostic data when the app fails.
We do not collect precise location, contacts from your phone's address book, advertising identifiers, or health data from device sensors.
2. How we use your data
We use your data to:
- provide the Service — store and display your journal, generate summaries, tasks, and reflective replies;
- transcribe your voice recordings into text (only when you use dictation);
- send reminders and notifications you have enabled;
- maintain security, prevent abuse, and enforce usage limits;
- process your subscription;
- respond to support requests and legal obligations.
We do not sell your personal data. We do not use your journal content to train third-party AI models, and we do not serve advertising.
3. Legal basis for processing
Depending on your location, we rely on:
- Performance of a contract — to provide the Service you signed up for (GDPR Art. 6(1)(b); LGPD Art. 7, II).
- Your consent — for optional processing such as push notifications and, where required, for processing the sensitive content of your entries (GDPR Art. 6(1)(a) / Art. 9(2)(a); LGPD Art. 7, I / Art. 11, I). You can withdraw consent at any time (see Section 7).
- Legitimate interests — to keep the Service secure and operational (GDPR Art. 6(1)(f)).
- Legal obligation — to comply with applicable law.
Sensitive data. Journal entries can reveal information about your emotional and mental well-being. We treat this as sensitive/special-category data and process it only to provide the Service to you, based on your consent.
4. How your data is shared
We never sell your personal data, and we do not share it for advertising.
To run the Service, we rely on third-party service providers that process your data on our behalf and under contract ("processors"), strictly to provide the Service to you. This includes processing the text and voice of your entries so the Service can transcribe, summarize, and reply to them — the Service cannot function without this. By using the Service, you acknowledge that your data, including the content of your entries, is transferred to such processors for these purposes.
We use processors in the following categories:
- Cloud hosting, database & authentication — storing your account and app data.
- AI text processing — generating summaries, tasks, and assistant replies.
- Speech-to-text — transcribing voice recordings you dictate.
- Push notification delivery — sending reminders you enable.
- Diagnostics & crash reporting — keeping the app stable and secure.
- Payments & subscription management — processing your subscription.
We may add or change the specific providers within these categories as the Service evolves. We require every processor to safeguard your data and to use it only to provide services to us — never for their own purposes. A current list of the specific providers we use is available on request at privacy@heyiro.com.
5. International data transfers
We are based in Brazil, and some subprocessors are located in the United States or the European Union. When we transfer your data across borders, we rely on appropriate safeguards — such as Standard Contractual Clauses (GDPR) and the international-transfer provisions of the LGPD (Arts. 33–36) — to protect it.
6. How long we keep your data
We keep your personal data for as long as your account is active. When you delete your account (see Section 7), we permanently erase your personal data from our production systems. Residual copies may persist in encrypted backups for up to [30] days before being overwritten. Aggregated, anonymized usage records that no longer identify you may be retained for accounting and capacity planning.
7. Your rights
Subject to applicable law (GDPR for the EU/EEA, LGPD for Brazil, and similar laws), you have the right to:
- access the personal data we hold about you;
- correct inaccurate data (edit your profile and entries in the app);
- export your data in a portable format;
- delete your account and all associated data — from Settings → Account → Delete account inside the app, or by contacting us;
- withdraw consent at any time, without affecting prior processing;
- object to or restrict certain processing;
- lodge a complaint with your supervisory authority — the ANPD in Brazil or your local Data Protection Authority in the EU/EEA.
To exercise any right, use the in-app controls or email privacy@heyiro.com. We respond within the timeframes required by law.
8. Security
We protect your data with encryption in transit (HTTPS/TLS) and at rest, row-level access controls that isolate each user's data, hashed passwords, and an optional app lock (PIN / biometrics) on your device. No system is perfectly secure, but we work to protect your information and will notify you and the relevant authorities of a data breach as required by law.
9. Children
The Service is intended for adults (18+) and is not directed to children. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact privacy@heyiro.com and we will delete it.
10. Changes to this policy
We may update this Policy. If we make material changes, we will notify you in the app or by email before they take effect. The "Last updated" date above reflects the current version.
11. Contact
Questions or requests about your privacy: HeyIro Ltda — privacy@heyiro.com