Lumi, the Say It Here mascot Say It Here

Privacy Policy

Effective date: July 16, 2026

Say It Here ("Say It Here," "we," "us," or "our") provides private writing tools, AI-assisted writing features, account services, and the Pulse community. This policy explains what information is processed, why it is processed, and the choices available to you.

1. Information stored on your device

Saved reflections, drafts, writing results, People profiles and notes, timeline entries, weekly plans, app settings, usage-limit state, and ad-frequency state are stored locally. Native app records are encrypted using XChaCha20-Poly1305 with a key protected by the device keychain. Browser records use AES-GCM with a key stored by the browser.

You may use the system contact picker to copy one contact's name into a People profile. Say It Here does not upload or scan your full address book. A name or other People information you choose to save may, however, be included in an AI request when you use a feature that uses that saved context, such as a weekly plan.

Local storage does not mean that every feature is offline. The information described below is transmitted when you use cloud, AI, community, notification, advertising, or purchase features.

2. Accounts and identifiers

3. Private writing, AI processing, and diagnostics

AI assistance

When a remote AI feature is used, we send the text needed for that request to our server and to our AI provider, currently DeepSeek. This may include a message or draft, selected People context, recent summaries, saved entries used for a weekly plan, and the generated result. The service uses this information to return the requested reflection, rewrite, reply, message check, plan, or moderation result. Some safety-sensitive requests are handled locally or by our server without being forwarded to the AI provider.

We do not send messages to another person for you. You decide whether to copy, share, or send any generated text.

Product diagnostics and usage records

The app sends product activity to Google Firebase so we can operate, troubleshoot, secure, and improve the service. Records may include:

These diagnostic records are not public, but authorized project administrators can inspect them. Our AI endpoint may also process a short-lived, hashed value derived from an IP address for abuse prevention and rate limiting.

4. Pulse community content

Pulse posts, comments, reactions, associated timestamps, optional usernames, and internal account identifiers are stored in Google Firebase. Posts and comments are visible to signed-in Pulse users. Linked users may post under their derived username; other users may appear as Anonymous.

Content is checked by local and, when available, remote moderation systems before publication. Feature activity such as reporting or hiding content may also be recorded in product diagnostics. Do not put names, contact details, locations, account handles, or other identifying information in Pulse.

5. Notifications

If you allow notifications, the app stores an Expo push token, platform, account identifier, and notification preferences in Firebase. Expo's Push Service is used to deliver Pulse activity notifications. Daily reflection reminders are scheduled locally on your device. Push text is designed to be generic and does not include the text of a post or private writing.

6. Purchases and subscriptions

Apple processes subscription payments. RevenueCat receives an anonymous customer identifier, App Store receipt and transaction information, product identifiers, subscription status, renewal and expiration information, and related device or app information so the app can validate Premium access. We do not receive your full card number or Apple Account password.

7. Advertising

The free version may show banner, interstitial, and rewarded ads through Google AdMob. The app requests non-personalized ads and uses Google's consent flow where required. Google may process device and app information, IP address, advertising or app identifiers, consent signals, and ad interactions to serve, limit, secure, and measure ads. We do not send your private writing to AdMob. Premium removes in-app ads while Premium access is active.

8. Service providers and international processing

These providers process information under their own terms and privacy policies and may process it in countries other than yours. We do not sell your personal information or use the content of your private writing for personalized advertising.

9. Retention and deletion

10. Your choices and rights

You can choose whether to link an Apple or Google account, post in Pulse, select a contact, allow notifications, or use an ad-supported feature. Device permissions can be changed in system settings. You may delete your account in the app or contact us to ask about access, correction, deletion, or other privacy rights available where you live.

11. Security

We use encryption for local private records, TLS for data in transit, Firebase access controls, authenticated deletion, and restricted database rules. No storage or transmission method is completely secure, so we cannot guarantee absolute security.

12. Safety and sensitive information

Say It Here is not therapy, medical care, legal advice, or an emergency service. Avoid entering information you do not want processed as described in this policy. If you are in immediate danger, contact local emergency services or someone you trust.

13. Children

Say It Here is not directed to children under 13. You must also meet the minimum age required in your country and by the applicable App Store account. If you believe a child provided personal information improperly, contact us.

14. Changes to this policy

We may update this policy as the app or legal requirements change. The effective date above identifies the latest version. Material changes may also be communicated in the app or through the App Store listing.

15. Contact

Lumi holding a padlock

Privacy questions or requests:
jmacaling001@gmail.com