InnerTale

Privacy policy

Last updated: 27 August 2026

This policy explains what personal data InnerTale processes (the mobile app and the website innertale.app), for what purposes, for how long, and what rights you have under Regulation (EU) 2016/679 (GDPR) and Spain’s Organic Law 3/2018 (LOPDGDD).

InnerTale is a personal journal assisted by artificial intelligence: you talk or write, the AI follows the thread and turns the conversation into a journal entry. What you write may include intimate information or information about your mental health or wellbeing. We treat it with care, only to provide the service, and we do not sell it.

Use of InnerTale is also governed by the terms of use .

1. What data we process

1.1 Account and authentication

  • User identifier (Firebase UID).
  • Email address (if you sign in with email, Google, or Apple and it is shared).
  • Display name and, if provided, profile photo from the sign-in provider.
  • Sign-in provider (email, Google, or Apple).
  • During onboarding an anonymous Firebase session may be used for the first experience only; the full journal requires a real account.

1.2 Journal content (high-impact data)

  • Chat messages (text you type or dictate).
  • Generated journal entries (title, body, date).
  • Context facts / “memories” the AI extracts for continuity (people, projects, events, preferences, states).
  • Follow-up reminders (based on what you wrote).
  • Cover images generated from the entry content.

This content may reveal aspects of your private life, emotions, or health. We treat it as special-category data where applicable (GDPR art. 9) and only with your explicit consent when you accept this policy and use the service.

1.3 Emotional evolution (optional)

  • Scores derived from your entries (e.g. positivity, energy, calm, focus, importance) and titles associated with the chart.
  • Your preference to turn this feature on, pause it, or delete it.

It is only enabled if you give specific consent in the app. You can pause it or delete those scores without deleting the journal.

1.4 Device and permissions

  • Microphone and speech recognition, only if you allow them, to dictate pages.
  • Push notification token, only if you turn on follow-up reminders.
  • Local app preferences on the device.

1.5 In-app analytics and campaign measurement (optional)

  • Singular — install attribution and advertising campaign measurement (MMP).
  • Google Analytics (Firebase Analytics) — app-usage analytics (product events such as onboarding steps, login, opening chat, creating a page, notification permissions), without journal or chat text.
  • Technical device identifiers (e.g. IDFV / app-instance identifiers; and the IDFA advertising identifier on iOS only if you also authorize tracking in the system dialog — App Tracking Transparency).
  • When available, information about the campaign or ad that led you to install InnerTale (including attribution via Apple’s SKAdNetwork when it applies).

This measurement is not anonymous in a strict sense (it uses technical identifiers), but we do not send Singular or Google Analytics your journal content, chat, name, or email.

It is only enabled if you tick the optional box in onboarding (“Help improve InnerTale…”) or turn it on later in You → Settings → Measurement and analytics. Without that consent we do not initialize Singular or Firebase Analytics. You can withdraw it at any time in Settings; when you turn it off we stop sending new data from the app. On iOS, the system ATT permission is separate and only affects IDFA.

1.6 Website and waitlist

  • Email address if you join the waitlist (handled with MailerLite).
  • Advertising measurement data (Meta Pixel) when Meta scripts load on the site, which may include online identifiers, pages visited, and events (e.g. waitlist signup).
  • Usual server technical data (e.g. IP in access logs, for a limited time).

1.7 Compliance after account deletion

After permanent deletion we keep a minimal record: a hash of the identifier and the request and purge dates, with no email and no journal content.

2. Purposes and legal bases

Purpose Legal basis (GDPR)
Create and manage your account, authenticate you, and provide the journal Performance of the contract (art. 6.1.b) and, where content is sensitive, explicit consent (art. 9.2.a)
Process text with AI (follow-up, drafting entries, context, covers) Contract (art. 6.1.b) + consent when you accept the terms/privacy policy and use those features
Emotional evolution and derived charts Specific, withdrawable consent (arts. 6.1.a and 9.2.a)
Follow-up notifications Consent (system permission + enabling in the app)
Waitlist / launch communications Consent when you leave your email (art. 6.1.a)
Ad measurement and optimization on the site (Meta) Consent for marketing cookies/technologies when requested; without consent they should not be used for advertising
Install attribution (Singular) and in-app usage analytics (Google Analytics / Firebase) Optional, withdrawable consent in the app (art. 6.1.a); on iOS, also the system ATT permission if IDFA is requested
Security, abuse prevention, and legal compliance Legitimate interest (art. 6.1.f) or legal obligation (art. 6.1.c)
Minimal record after account deletion Legitimate interest / duty to demonstrate compliance (arts. 6.1.f and 5.2)

You can withdraw consent at any time without affecting the lawfulness of prior processing. Turning off optional features (emotions, reminders, marketing) does not necessarily delete the journal; use account deletion for that.

3. How we use artificial intelligence

We send AI providers the text needed to: ask follow-up questions, draft the journal entry, extract context, generate covers, and — only if you enable it — compute emotional scores. We do not use your journal to train InnerTale’s own models. How providers use request data is governed by their terms and the relevant data-processing agreement.

InnerTale is not a medical or psychological service. It does not diagnose and does not replace professional help. If you are in crisis, seek local emergency support.

4. Who we share data with (processors)

We do not sell your data. We share it only with providers that help us operate the service (processors), under instructions and with appropriate security measures:

  • Firebase / Google — authentication and account; and, with measurement consent, Firebase Analytics.
  • Apple — if you use Sign in with Apple.
  • Server infrastructure (Hetzner, EU) — API and self-hosted MongoDB.
  • Groq — LLM processing (follow-up, journal, context, emotions).
  • Runware — cover-image generation.
  • MailerLite — website waitlist.
  • Meta (Facebook) — advertising measurement on the website, when applicable.
  • Singular — install attribution and campaign measurement in the mobile app, only if you give measurement consent.
  • Google / Firebase Analytics — app-usage analytics (aggregated events, without journal content), only with the same consent.
  • App stores (Apple / Google) under their distribution rules.

We may also disclose data if a competent authority requires it under the law.

5. International transfers

Journal and account data are stored primarily in the European Union (server in Helsinki, Finland). Some processors (e.g. Firebase/Google, Groq, Runware, Meta, MailerLite, Singular) may process data outside the EEA, in particular in the United States.

Where there is no adequacy decision, we rely on the European Commission’s Standard Contractual Clauses or other Chapter V GDPR safeguards, plus any additional measures each provider offers.

6. Retention

  • Account and journal: while you keep the account active.
  • Account deletion: immediate deactivation; permanent deletion of content and account after 30 days (you can cancel deletion if you sign back in before then). Details at Delete account .
  • Emotional-evolution data: if you ask to turn it off and delete it, it is permanently removed within about 15 days.
  • Waitlist: until you unsubscribe, ask for deletion, or we no longer need the email for launch.
  • Deletion record (hash): as long as needed to demonstrate compliance (indicatively up to 3 years).
  • Technical logs: the minimum reasonable for security and operations (usually days or a few weeks).
  • Measurement and analytics (Singular and Google Analytics): while consent remains active and, after you withdraw it, for as long as each provider retains data under its policy (e.g. attribution windows or Analytics retention, indicatively up to 14 months for event/user data in GA4). Turning measurement off in Settings stops new data being sent from the app.

7. Data controller

Controller: Óscar Ares Bascon, tax ID 54131325C, Simón Bolívar 15, 1º A, A Coruña (Spain).

No Data Protection Officer (DPO) has been appointed. If one becomes mandatory, we will update this policy with their contact details.

8. Security

We apply reasonable technical and organizational measures: encryption in transit (HTTPS/TLS), account access control, environment separation, and scheduled account deletion. No system is 100 % secure. Journal content is processed on our servers and those of the AI processors; we do not offer end-to-end encryption with respect to those providers, because we need to read the text to provide the service.

9. Cookies and similar technologies

On innertale.app we may use:

  • Necessary: basic site operation (e.g. technical preferences).
  • Marketing / measurement: Meta Pixel, to measure and optimize ads.

Non-essential cookies require your consent. You can manage preferences from the site banner (when it is active) and from your browser settings.

The mobile app does not use web cookies. It uses local storage, system tokens, and, only with your measurement consent, the Singular and Firebase Analytics SDKs (and, on iOS, the App Tracking Transparency dialog if access to the advertising identifier is requested).

10. Your rights

You may exercise, regarding your personal data:

  • Access (art. 15)
  • Rectification (art. 16)
  • Erasure (art. 17)
  • Restriction of processing (art. 18)
  • Portability (art. 20)
  • Objection (art. 21)
  • Withdrawal of consent, where the basis is consent

How to exercise them:

  • Deleting the account and journal: in the app, You → Settings → Delete account (or the instructions at Delete account).
  • Name: editable in Settings.
  • Emotional evolution: pause or delete scores in Settings.
  • Measurement and analytics: turn on or off in You → Settings → Measurement and analytics (turns off Singular and Google Analytics together). On iOS you can also limit app tracking in system Settings (ATT / IDFA).
  • Other rights / waitlist: write to support@innertale.app from your account email. We will reply within one month.

You may also lodge a complaint with the Spanish Data Protection Agency (AEPD): www.aepd.es .

11. Children

InnerTale is intended for people aged 16 or over. We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe a child has given us data, contact us so we can delete it.

12. Changes

We may update this policy when the product or the law changes. We will publish the current version at this URL and show the update date. If a change is material, we will tell you in the app or by email when it is reasonable to do so.

13. Contact

Privacy questions: support@innertale.app