Privacy Policy

Last updated: [DATE]

This Privacy Policy explains how HeyIro Ltda ("HeyIro", "we", "us") collects, uses, and protects your personal data when you use the Introspection mobile and web application (the "Service").

We take privacy seriously because the Service is a private space for self-reflection. Your journal entries describe your feelings and personal life, and we treat them accordingly.


1. What data we collect

We only collect what the Service needs to work.

1.1 Data you provide

1.2 Data collected automatically

We do not collect precise location, contacts from your phone's address book, advertising identifiers, or health data from device sensors.


2. How we use your data

We use your data to:

We do not sell your personal data. We do not use your journal content to train third-party AI models, and we do not serve advertising.


3. Legal basis for processing

Depending on your location, we rely on:

Sensitive data. Journal entries can reveal information about your emotional and mental well-being. We treat this as sensitive/special-category data and process it only to provide the Service to you, based on your consent.


4. How your data is shared

We never sell your personal data, and we do not share it for advertising.

To run the Service, we rely on third-party service providers that process your data on our behalf and under contract ("processors"), strictly to provide the Service to you. This includes processing the text and voice of your entries so the Service can transcribe, summarize, and reply to them — the Service cannot function without this. By using the Service, you acknowledge that your data, including the content of your entries, is transferred to such processors for these purposes.

We use processors in the following categories:

We may add or change the specific providers within these categories as the Service evolves. We require every processor to safeguard your data and to use it only to provide services to us — never for their own purposes. A current list of the specific providers we use is available on request at privacy@heyiro.com.


5. International data transfers

We are based in Brazil, and some subprocessors are located in the United States or the European Union. When we transfer your data across borders, we rely on appropriate safeguards — such as Standard Contractual Clauses (GDPR) and the international-transfer provisions of the LGPD (Arts. 33–36) — to protect it.


6. How long we keep your data

We keep your personal data for as long as your account is active. When you delete your account (see Section 7), we permanently erase your personal data from our production systems. Residual copies may persist in encrypted backups for up to [30] days before being overwritten. Aggregated, anonymized usage records that no longer identify you may be retained for accounting and capacity planning.


7. Your rights

Subject to applicable law (GDPR for the EU/EEA, LGPD for Brazil, and similar laws), you have the right to:

To exercise any right, use the in-app controls or email privacy@heyiro.com. We respond within the timeframes required by law.


8. Security

We protect your data with encryption in transit (HTTPS/TLS) and at rest, row-level access controls that isolate each user's data, hashed passwords, and an optional app lock (PIN / biometrics) on your device. No system is perfectly secure, but we work to protect your information and will notify you and the relevant authorities of a data breach as required by law.


9. Children

The Service is intended for adults (18+) and is not directed to children. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact privacy@heyiro.com and we will delete it.


10. Changes to this policy

We may update this Policy. If we make material changes, we will notify you in the app or by email before they take effect. The "Last updated" date above reflects the current version.


11. Contact

Questions or requests about your privacy: HeyIro Ltdaprivacy@heyiro.com