Reweave – Privacy Policy
Last updated: April 29, 2026
Copyright (c) 2026 Reweave LLC.
This Privacy Policy explains how Reweave LLC ("Reweave," "we," "us," or "our") collects, uses, and protects your information when you use the Reweave – Threads of Healing mobile application (the "App"). It applies to the App and to the legal pages we host at https://terms.reweaveapp.com and https://privacy.reweaveapp.com.
Plain-language summary. Your reflections live on your phone. We don't sell them. The only thing that briefly leaves your device is the text you choose to send to the AI Companion — and even then, our AI providers process it transiently and don't keep it for training. We don't ask for your name, email, or account.
1. Who we are
Reweave is operated by Reweave LLC. You can reach us at healingsupport@reweaveapp.com.
2. The data we collect
We deliberately collect as little as possible.
Stored only on your device
The following information is stored locally on your device using the operating system's secure on-device storage (AsyncStorage on iOS) and is not stored in our application database:
- Journal entries, reflections, sanctuary notes, and any text you write inside the App
- Your Tapestry — the constellation of memories and themes derived from your reflections
- App preferences (theme, language, breathing-exercise settings, completed paths)
- Whether you accepted the Terms of Use and the date you accepted them
- Subscription status surfaced by Apple's StoreKit (used only to unlock paid features)
If you delete the App, this information is removed with it.
Sent transiently to our AI providers
When you send a message to the AI Companion, the App transmits the text of that message — and the recent context needed to make the response coherent — through our API to OpenAI for processing; submitted content is not stored in our application database. Specifically:
- The transmission is over HTTPS.
- The provider processes the text on a transient basis under contractual data-protection terms (no model training on your data, no long-term retention, no resale).
- We do not attach any personal identifier to the request beyond a temporary session token used for rate-limiting and abuse prevention.
Crisis-screening events
To meet our safety obligations, when our on-device or server-side screening flags a message as a possible crisis signal, we log metadata only: an opaque session ID, the timestamp, which screening layer fired, and the user action that followed (e.g. "user tapped the crisis-resource button"). We do not log journal text or the content of the message.
Subscription information from Apple
Apple manages all subscription billing. We receive only the information Apple makes available to us (subscription status, product ID, expiration date) and we use it only to unlock or lock paid features. Payment-card details, billing address, and Apple ID are never visible to us.
Information we do NOT collect
We do not collect: your name, email address, phone number, contacts, photos, microphone audio (unless you explicitly use a voice feature in a future release), location, advertising ID (IDFA), or any cross-app tracking identifier. We do not use third-party analytics SDKs that profile users.
3. How we use your information
- To provide the App. Your on-device data powers your journal, your Tapestry, and your sanctuary.
- To generate AI Companion responses. Your text is forwarded to our AI provider as described above and the response is returned to you.
- To keep you safe. Crisis-screening events let us measure whether our safety paths are working and improve them.
- To honor your subscription. Apple's subscription status unlocks the paid tier.
- To meet legal obligations. We may use information to comply with applicable laws or to respond to lawful requests.
We do not use your information for advertising, profiling, or to train public models.
4. Sharing
We share information only with:
- Our AI providers, on a transient basis, solely to generate Companion responses (no training, no resale).
- Apple, for subscription processing.
- Legal authorities, where required by valid legal process.
We do not sell your information. We do not "share" it for cross-context behavioral advertising as defined under U.S. state privacy laws.
5. Children
Reweave is intended for users 17 and older. We do not knowingly collect information from anyone under 17. If you believe a child under 17 has used the App, contact us at healingsupport@reweaveapp.com and we will help.
6. How long we keep information
- On your device. Until you delete the entry, reset the App, or uninstall.
- AI provider transit. No retention beyond the immediate response, per provider contract.
- Crisis-screening metadata. Retained in server logs according to our hosting provider’s retention policy, currently up to 30 days.
- Subscription receipts. As long as required by Apple and applicable tax/accounting law.
7. Security
We use industry-standard safeguards: HTTPS for every network request, secure on-device storage for journal data, server-side rate-limiting, and no secret keys shipped in the App binary. No system is perfectly secure; if you believe you've found a vulnerability, please email healingsupport@reweaveapp.com.
8. Your rights
Depending on where you live, you have rights over the personal information we hold about you. Because we collect very little, most rights are easy to exercise:
- Access / portability. All of your journal content lives on your device — open the App to see and export it. For crisis-screening events, contact us.
- Deletion. Uninstalling the App deletes everything on your device. To request deletion of any server-side records, email healingsupport@reweaveapp.com.
- Correction. Edit or delete entries directly in the App.
- Opt-out of AI processing. You can decline to use the AI Companion. The rest of the App will continue to function.
- No discrimination. We will not penalize you for exercising any privacy right.
Region-specific notes
- California (CCPA / CPRA). You have the right to know, delete, correct, and limit use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising.
- EU / UK (GDPR / UK GDPR). Our lawful bases are: (i) contract performance (operating the App you've installed), (ii) legitimate interests (safety screening), and (iii) consent (where required, e.g., optional voice features). You may lodge a complaint with your local Data Protection Authority.
- Brazil (LGPD). You have rights of access, correction, anonymization, portability, deletion, and information about sharing.
- Other jurisdictions. Contact healingsupport@reweaveapp.com and we will honor any rights granted by your local law.
9. International transfers
Our AI providers may process your text in jurisdictions different from yours (commonly the United States). We rely on standard contractual clauses or equivalent safeguards required by applicable law.
10. Changes
We may update this Privacy Policy from time to time. Material changes will be highlighted in the App at next launch. The "Last updated" date at the top reflects the current version.
11. Contact
Questions, requests, or complaints: healingsupport@reweaveapp.com. Reweave LLC