← Back to Tafakkari
PRIVACY POLICY

How we protect your reflections.

Effective: 21 June 2026 · Version 3.0

1. Who we are

"Tafakkari" is operated by Tafakkari (the "Service", "we", "us"). This Privacy Policy explains how we collect, use, store, share, and protect personal information when you use the Tafakkari mobile app and related services.

For privacy questions or to exercise any of the rights described below, contact us at privacy@tafakkari.app.

2. Our core promises

• We do not sell your personal information to anyone.

• We do not show advertising in the app.

• We do not use your journal entries to train AI models.

• We do not share your entries with third parties without an explicit action from you (e.g., creating a therapist-share link).

• We encrypt journal content and mood notes at rest with AES-256-GCM. You can additionally enable Zero-Knowledge mode for client-side encryption that only you can unlock.

3. The information we collect

(a) Account information. Your email address, your display name (optional), a bcrypt-hashed password, and — if you sign in with Google — your Google account ID and basic profile fields (name, email).

(b) Journal content. The text of your entries, the prompts you used, attached mood tags, and any "next step" or AI reflection generated for that entry. Stored encrypted (AES-256-GCM) at rest; optionally encrypted client-side under Zero-Knowledge mode.

(b-2) Worst-hour module data. When you use the specialised modules — Loops (recurring thoughts), Inner Critic (the voice that attacks), Grief (carrying someone), Scripts (hard conversations), Release (letting go), and Before You Send (the message coach) — the text you write, the labels you choose, and any AI "witness" response shown back to you are stored in the same encrypted store. These entries can be auto-deleted on a schedule you set (Loops, Critics, Scripts and Release support 7-day, 30-day, or "keep" retention per item).

(c) Mood and behavioural signals. Mood check-ins, optional mood notes (encrypted), streaks, daily prompt swap history, adaptive theme weights, lesson progress, and badges.

(d) Device and technical data. App version, OS, device type, push notification token (if enabled), crash diagnostics. No advertising identifiers; no precise location.

(e) Share links. When you create a read-only therapist share link, we store the link ID, the entries it points to, expiry date, and view count.

We do not collect: contacts, photo library, precise location, browsing history, social-media data, or biometric templates (Face ID / Touch ID is verified by your device's secure enclave; we never receive the biometric data).

4. Legal bases (UK & EU users)

Where the EU/UK GDPR applies to you, we process your personal data on the following legal bases under Article 6:

Contract (Art. 6(1)(b)) — to provide the Tafakkari Service after you create an account.

Consent (Art. 6(1)(a)) — for optional features like notifications and Zero-Knowledge mode; withdrawable at any time in Profile.

Legitimate interests (Art. 6(1)(f)) — to maintain security, prevent abuse, and improve features. We balance this against your interests and you can object at any time.

Legal obligation (Art. 6(1)(c)) — to comply with applicable law, regulator orders, and lawful requests.

5. How we use your information

• Provide the journaling experience (entries, prompts, worksheets, mood tracking, lessons, badges).

• Generate AI-assisted prompts and reflections tailored to your recent themes and mood patterns.

• Send local push reminders (only on devices you've enabled notifications on; scheduled by your device, not via push servers).

• Maintain account security (rate-limiting, abuse prevention).

• Communicate with you about service updates and respond to support enquiries.

We never use your information for: advertising, profiling for third-party marketing, or automated decisions with legal effect.

6. Encryption and security

At rest. Journal entries and mood notes are encrypted in our database using AES-256-GCM. Encryption keys are held under restricted access on our server infrastructure. Backups and database snapshots contain only ciphertext.

In transit. All traffic between the app and our servers uses TLS 1.2 or higher (HTTPS).

Zero-Knowledge (ZK) mode. If you enable ZK mode, entries are additionally encrypted on your device with a key derived from your password using scrypt (N=2^15) and AES-GCM. When ZK is on, we cannot read your entries and cannot recover them if you lose your password.

Passwords. Stored as bcrypt hashes (cost 12+). Plaintext passwords never touch persistent storage.

Biometrics & PIN. Optional unlock via Face ID / Touch ID uses your device's secure enclave only — we never receive the biometric data. The PIN is stored locally on your device.

7. Third-party processors

We disclose the third parties that process personal data on our behalf, as required by GDPR Article 28:

Anthropic, PBC (San Francisco, USA) — provides the Claude AI model for prompt generation and reflection. We send only the minimum text needed (entry excerpt or mood string); we do not send your name or email. Anthropic's API terms state that input is not used for training. Region: USA.

MongoDB Atlas — managed database storing the encrypted entries and account records. Region: USA / EU options depending on cluster.

Emergent — application hosting and Google OAuth proxy. Region: USA.

If you are in the EU or UK, your data may be transferred to the United States. We rely on Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework (where applicable) for these transfers, as supplementary measures alongside encryption.

8. AI processing details

When we generate a prompt, reflection, or weekly worksheet, we send a small relevant excerpt of your text to Anthropic's Claude model via a managed proxy. Each request is ephemeral and is not retained by the model provider for training purposes.

If you have Zero-Knowledge mode enabled, encrypted entries are excluded from AI features because we cannot read them.

AI output can be wrong, incomplete, or unexpected. It is never medical, psychological, or legal advice. See our Terms of Service for the full disclaimer.

The witness contract. Inside the worst-hour modules (Loops, Inner Critic, Grief, Scripts, Release, Before You Send), the AI is constrained to act as a witness: it names what is present in your writing without diagnosing, reframing, rewriting, predicting other people's reactions, or suggesting actions. A banned-phrase list governs every reply; output containing any of those phrases is suppressed and replaced with a calm template. This contract is documented internally and audited on every release.

9. Retention

We keep your account and journal content for as long as your account is active. You can delete your account at any time via Profile → Sign out (then "Delete account") or by emailing privacy@tafakkari.app. Deletion is permanent: entries, moods, badges, share links, and the account record are removed from primary storage within 30 days, and from encrypted backups within 90 days.

Limited records may be retained where required by law (e.g., tax records, regulator orders) or to defend legal claims, for no longer than the statutory minimum.

10. Your rights

Depending on where you live, you have the following rights:

Access — request a copy of the personal data we hold about you.

Rectification — correct inaccurate or incomplete data.

Erasure ("right to be forgotten") — delete your data, subject to limited legal exceptions.

Portability — receive your entries in a portable PDF format (export available from Profile).

Restriction — restrict our processing while a complaint is resolved.

Objection — object to processing based on legitimate interests.

Withdraw consent — for any feature that relies on consent (e.g., notifications), without affecting prior lawful processing.

To exercise any right, email privacy@tafakkari.app. We respond within 30 days. If you're in the EU/UK, you also have the right to lodge a complaint with your local supervisory authority (e.g., ICO in the UK, your national DPA in the EU).

11. California residents (CCPA / CPRA)

In addition to the rights above, California residents have:

• The right to know what categories of personal information we collect (listed in section 3) and the categories of recipients (listed in section 7).

• The right to delete personal information (covered in section 9).

• The right to correct inaccurate personal information.

• The right to opt out of "sales" or "sharing" of personal information — but we do not sell or share personal information as those terms are defined under the CCPA, so there is nothing to opt out of.

• The right not to be discriminated against for exercising any of these rights.

To submit a verifiable request, email privacy@tafakkari.app.

12. Children (COPPA & GDPR Art. 8)

Tafakkari is intended for people aged 13 and older. During sign-up we require confirmation of age and we do not knowingly collect personal information from anyone under 13. If you believe we have collected data from a child under 13, email privacy@tafakkari.app and we will delete it promptly.

In some EU countries the minimum age for online consent under GDPR Article 8 is 16; if you live in such a country, you must be at least that age.

13. Therapist-share links

When you create a read-only therapist share link, we store the link's metadata so that a person you give the link to can view the selected entries, modules, or date range without logging in. You choose which scopes to include — Loops, Inner Critic, Grief, Scripts, Release, and the optional Patterns roll-up. AI replies are never shared; the recipient sees only your own words. The link expires automatically (you choose 24h, 7d, or 30d) and you can revoke it at any time in Profile → Active therapist links.

Because the link does not require authentication, treat it like a private URL: anyone who receives it can open it until you revoke it or it expires.

14. Notifications

Notifications are scheduled locally on your device by Expo / OS schedulers. We do not run a push notification server. You can disable any reminder at any time in Profile → Reminders.

15. We are not a HIPAA-covered entity

Tafakkari is a consumer wellness tool. It is not a HIPAA- covered entity and does not, by itself, qualify as a "business associate" under HIPAA. If you are a US healthcare provider seeking to use Tafakkari in a covered care context, contact support@tafakkari.app before doing so.

16. Security incidents

If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify affected users without undue delay, and within 72 hours where required by GDPR Article 33–34 or comparable laws.

17. Changes to this Policy

We may update this Policy as Tafakkari evolves. If we make material changes, we'll notify you in-app or by email at least seven days before the change takes effect. The "Effective" date at the top reflects the current version.

18. Contact

Privacy questions, rights requests, or complaints: privacy@tafakkari.app.

General support: support@tafakkari.app.