Reflective
Privacy-First Guarantee
Google Play & App Store Compliant

Privacy Policy

Operated by Just Write Apps, LLC • Effective Date: August 31, 2026

"At Reflective, our mission is simple: we build thoughtful, private tools for personal reflection. We do not sell ads, we do not track your behavior across apps, we never sell your data, and we never use your private journal entries to train public AI models."

1. Entity Identification & Overview

This Privacy Policy applies to the Reflective mobile application, desktop application, and web sanctuary (collectively, the "Service"), owned and operated by Just Write Apps, LLC ("Company", "we", "us", or "our").

We are dedicated to safeguarding the privacy and personal data of every individual who uses Reflective. This document details the technical mechanisms, security measures, and policies governing our data collection, processing, and retention practices in full compliance with Google Play Developer Policies, Apple App Store Review Guidelines, the General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA/CPRA).

2. Privacy & Security Architecture

Reflective is built with privacy and security at its core:

  • Local-First Storage: Your journal entries, notes, voice memos, and photos are saved directly on your device. You can use Reflective completely offline without creating an account.
  • Biometric App Lock: Protect your journal on your phone with Face ID, Fingerprint, or PIN authentication.
  • Optional Passcode Vault Encryption: You can set an optional private passcode to encrypt your local journal database on your physical device.
  • Secure Cloud Sync: If you choose to enable cloud sync, your data is transmitted over secure, encrypted connections (HTTPS/TLS) and stored in your private, authenticated cloud account with strict per-user access isolation.

3. Information We Collect & Data Safety Disclosures

To deliver synchronization, account recovery, and subscription services, we process the following categories of information:

Data Category Specific Data Elements Purpose & Encryption Status
Account & Authentication Email address, Firebase Auth UID, display name (optional). Account login, multi-device cloud synchronization, and security verification via Firebase Authentication.
Journal & User Content Reflections, notes, custom tags, audio memos, attached photos/videos. Stored on your device and synchronized to your private cloud account. Protected by encrypted transmission (TLS) and encryption at rest.
Location Data (Optional) Approximate or precise geographical coordinates attached to an entry. Captured only upon explicit user request per entry to display on your personal memory map. Never tracked in the background.
Purchases & Entitlements Subscription status, entitlement IDs, store transaction receipt tokens. Processed securely via Google Play Billing, Apple App Store, and RevenueCat. No payment card details are ever handled or stored by Reflective.
Diagnostics & Crash Logs Crash stack traces, device model, operating system version, app build number. App stability and bug triage via Firebase Crashlytics. Telemetry logs contain zero journal contents or personal notes.
App Analytics Aggregated feature interactions, retention metrics. Evaluated via Firebase Analytics to optimize app performance. No cross-app tracking or advertising profiles.

4. What We NEVER Collect, Share, or Sell

We maintain an absolute commitment to user privacy:

  • Zero Advertising Trackers: We do not integrate advertising networks or display ads.
  • Zero Data Selling: We do not sell, rent, lease, or trade personal data or journal information to third parties, data brokers, or advertisers.
  • Zero Background Location Tracking: We never track your location in the background or when the app is closed.
  • Zero Biometric Harvesting: Biometric unlock (fingerprint/Face ID) is processed entirely by your phone's operating system; biometrics never leave your physical device.
  • Zero Public AI Training: Your personal writings and reflections are never used to train public AI models.

5. Third-Party Service Providers

We engage vetted cloud and infrastructure partners strictly to provide core operational services:

  • Google Firebase & Google Cloud Platform (Google LLC): Used for secure authentication (Firebase Auth), database persistence (Cloud Firestore), media storage (Firebase Cloud Storage), intelligent reflection search & paper scan transcription (Vertex AI Gemini & text embeddings), crash triage (Crashlytics), and aggregate performance telemetry (Firebase Analytics).
    Google Privacy Policy
  • RevenueCat, Inc.: Used to validate in-app purchase receipts and manage cross-platform subscription entitlements.
    RevenueCat Privacy Policy
  • Google Play Services (Google LLC): Facilitates app distribution, updates, and in-app subscription billing.

6. Android OS & Device Permissions Explained

In accordance with Google Play Developer Policies, the following table details every runtime permission Reflective may request on your device:

Permission Android Identifier Purpose & Usage
Camera android.permission.CAMERA Allows you to scan paper notebooks with AI vision or capture photos/videos to attach to entries.
Microphone android.permission.RECORD_AUDIO Allows you to record voice notes and audio reflections within your personal journal.
Photos & Media READ_MEDIA_IMAGES, READ_MEDIA_VIDEO, READ_MEDIA_AUDIO Enables selecting existing pictures, videos, or audio files from your gallery to attach to entries.
Location (Optional) ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION Allows attaching optional geotags to entries when explicitly triggered. Never sampled in the background.
Notifications android.permission.POST_NOTIFICATIONS Delivers user-configured daily journaling prompts and reminder notifications.
Scheduled Alarms SCHEDULE_EXACT_ALARM, RECEIVE_BOOT_COMPLETED Ensures user-configured journaling reminders trigger accurately and persist across device restarts.
Biometrics USE_BIOMETRIC, USE_FINGERPRINT Enables unlocking your journal with fingerprint or facial recognition locally.

7. Artificial Intelligence & Private Processing

Reflective provides AI-powered features such as finding related past memories, thought linking, and transcribing handwritten paper notebooks. Our AI architecture adheres to strict privacy standards:

  • Zero Model Training: Your private reflections, entries, and writing prompts are never used to train, fine-tune, or improve public or proprietary foundational AI models.
  • Private Execution: AI features are processed securely for your authenticated account only and discarded from memory immediately after computation.

8. Data Retention & Complete Account Deletion

In compliance with the Google Play Account Deletion Requirement, Reflective provides straightforward, accessible mechanisms to permanently delete your account and all associated cloud data at any time.

Method 1: Direct In-App Deletion

Delete Inside the App

If you have the Reflective app installed on your Android or iOS device:

  1. Open the Reflective app.
  2. Navigate to SettingsAccount Settings.
  3. Select Delete Account.
  4. Confirm deletion to immediately delete your account and remove all cloud data.

Data deletion initiates instantly upon in-app confirmation.

Method 2: Web & Email Deletion Request

Remote Web Deletion

If you have uninstalled the app or cannot access your physical device:

  1. Send an email to support@justwriteapps.com.
  2. Use the subject line "Account & Data Deletion Request".
  3. Send the email from the address associated with your Reflective account.

Web requests are verified and executed within 30 days.

What Happens Upon Account Deletion:

  • Irrevocable Purge: Your user profile, authentication record, encryption metadata, synchronized encrypted database documents, and storage attachments are permanently deleted from active servers.
  • Rolling Backups: Cloud backup snapshots are systematically overwritten and permanently purged within 30 days.
  • Local Device Data: Deleting your cloud account removes all remote data. You may also clear local app data from your Android OS Settings or uninstall the app to erase local cache.

9. Children's Privacy (COPPA & GDPR-K)

Reflective is not directed toward children under the age of 13 (or under 16 within the European Economic Area / United Kingdom). We do not knowingly solicit or collect personal information from children under these minimum ages. If we discover that a child under the applicable minimum age has created an account or provided personal data, we will take immediate steps to delete their account and associated information permanently.

If you are a parent or guardian and believe your child has submitted personal data to Reflective, please contact us immediately at support@justwriteapps.com.

10. Your Privacy Rights (GDPR, CCPA/CPRA & International)

Depending on your jurisdiction, you are entitled to exercise the following statutory privacy rights:

  • Right to Access & Data Portability: You may export your entire journal vault as standard JSON or Markdown files at any time via the in-app backup utility.
  • Right to Rectification: You may correct or update your personal account information directly in your profile settings.
  • Right to Erasure ("Right to be Forgotten"): You have the right to request full and permanent deletion of your account and all associated cloud blobs.
  • Right to Restrict or Object to Processing: You may opt out of non-essential cloud synchronization by using Reflective in local-only offline mode.
  • Right to Non-Discrimination: We will never deny services, charge different prices, or provide a degraded experience for exercising your statutory privacy rights.

11. Contact Information & Legal Inquiries

For questions, legal notices, account deletion requests, or privacy inquiries, please contact our team at:

Entity Name: Just Write Apps, LLC

Application: Reflective Journal

Support & Privacy Inquiries: support@justwriteapps.com

Official Website: https://reflective.app

We review and update this Privacy Policy periodically. Any modifications will be published on this page with an updated Effective Date. Continued use of Reflective constitutes acknowledgment of the revised policy.