Privacy Policy

Last updated: March 31, 2026

Introduction

Safespace ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our app and services (the "Service"). By using Safespace, you agree to the collection and use of information in accordance with this policy.

Information We Collect

Personal Information

Safespace does not require traditional account creation or registration. When you first use the app, an anonymous account is automatically created through Firebase Authentication to secure communication with our servers. We do not collect your email address or require any login credentials.

During onboarding, you may provide your first name and journaling preferences (language, goals, tone). This information is stored locally on your device and sent to our servers only when needed to personalize AI-generated content.

Journal Entries and Content

Your journal entries and app data are stored locally on your device and synced through your personal iCloud account (managed by Apple). When you use AI-powered features such as conversations, reflections, or summaries, the relevant content is sent to our AI provider (OpenAI) for processing. This data is used solely to generate your response and is not used to train AI models. We do not permanently store your journal content on our servers.

User Profile

The app builds a lightweight personal profile from your journal entries to improve the relevance of AI responses. This profile includes themes, first names of people you mention, goals, and behavioral patterns. The profile is stored locally on your device and synced via iCloud. Profile data is sent to our servers only during active AI requests to provide context and is not permanently stored on our servers.

Health Data (Apple HealthKit)

If you grant permission, Safespace reads the following health data from Apple HealthKit:

Health data is read in a read-only manner from the past 14 days only, which is the minimum window needed to detect meaningful wellbeing patterns. We never write data back to HealthKit. When you use AI-powered features with health sync enabled, processed health signals (such as sleep quality labels, activity summaries, and weekly trends) are sent to our servers as context for the AI. This allows the AI to reference your wellbeing patterns during journaling conversations, generate personalized reflection cards on the home screen (e.g., a card about your sleep trend or recent activity), and provide more relevant prompts and summaries. Raw HealthKit data is not transmitted. You can disable health data access at any time in Settings.

Calendar Data (Apple EventKit)

If you grant permission, Safespace reads your calendar events from the past 7 days and up to 8 days ahead. We only access event titles, times, and calendar names on your device. Event titles are used locally to categorize events (e.g., work, social, health), but are never sent to our servers. Only event counts and category summaries (e.g., "3 work events, 2 social") are transmitted. This allows the AI to be aware of how busy your schedule is and gently reference relevant themes during conversations and in reflection cards, without ever knowing the specifics of your events. Individual event names, descriptions, attendees, and locations are never transmitted. You can disable calendar access at any time in Settings.

Analytics

We use Firebase Analytics to collect anonymous usage data in production builds. This includes events such as onboarding progress, feature usage (e.g., entry started, entry finished), and subscription interactions. Analytics data is not linked to your identity or journal content. We use this data solely to understand app usage patterns and improve the Service.

Crash Reports

We use Firebase Crashlytics to collect anonymous crash reports. This helps us identify and fix technical issues. Crash data does not contain your journal entries or personal content.

How We Use Your Information

We use the information processed through the app to:

Data Storage and Sync

All your journal entries, conversation messages, and app data are stored locally on your device using SwiftData. If you are signed into iCloud on your device, this data is automatically synced to your private iCloud account via Apple's CloudKit. This includes journal entries, conversation history, your user profile, emotion tags, and people/place tags. iCloud sync allows your data to be available across your Apple devices. This sync is managed entirely by Apple, and we have no access to your iCloud data. You can manage or disable iCloud sync for Safespace in your device's Settings > Apple ID > iCloud. Your iCloud data is governed by Apple's Privacy Policy.

We do not permanently store your journal content on our servers. We maintain minimal server-side data in Google Firebase Firestore limited to daily API usage counts for rate limiting purposes.

Data Sharing and Disclosure

We do not sell, trade, or rent your personal information. We share information with the following third-party services solely to provide the Service:

We may also disclose information when required by law or to protect rights and safety, or in connection with a merger, acquisition, or sale of assets (with continued protection of your data under this policy).

Data Security

Your local data is protected by Apple's device encryption and iCloud security infrastructure. Data sent to AI providers and our servers is transmitted over encrypted connections (TLS). Server-side data in Firebase is encrypted at rest. No method of transmission over the internet is 100% secure, but we take reasonable measures to protect your information.

Your Rights and Choices

For any additional requests, contact us at support@safespaceapp.health.

Data Retention

We do not permanently retain your journal content on our servers. Daily API usage counts in Firestore are maintained for rate limiting and are not linked to your journal content. Journal entries persist on your device and in your iCloud account until you choose to delete them. Analytics and crash data are retained according to Google Firebase's standard retention policies.

Children's Privacy

Safespace is not intended for anyone under 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and have concerns, please contact us.

International Data Transfers

Your journal data is stored in your iCloud account and may be processed in regions where Apple operates iCloud infrastructure. When using AI features, content may be processed by OpenAI in the United States. Analytics and crash data is processed by Google. We ensure appropriate safeguards are in place to protect your information.

California Privacy Rights

California residents have additional rights under the CCPA: right to know, right to delete, right to opt-out of the sale of personal information, and right to non-discrimination. We do not sell personal information. To exercise these rights, contact us.

If you make a request, we will respond within the timeframes required by applicable law.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review it periodically.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Safespace
Email: support@safespaceapp.health