This Privacy Policy explains what personal data the BelieveBehaveBecome app (the "Service") collects, why we collect it, who we share it with, and the choices you have. The Service is operated by StrategyX ("we", "us", "our"), which is the controller of your personal data.
1. Data you give us
- Account details — your email address, first and last name, and a password (stored only as a salted hash, never in readable form).
- Profile details — optional profile photo, country, currency and timezone, and your date, time and notification preferences.
- Your content — goals, actions, subtasks, check-ins and progress records, comments and mentions, reminders and repeating schedules.
- Financial records you enter — accounts, transactions, categories, budgets and adjustments. These are figures you type in yourself; we do not connect to your bank and we never see your banking credentials.
- Connections — the people you invite or accept, and the items you choose to share with them.
- Messages to us — anything you send when you contact support.
2. Data we collect automatically
- Session and device information — for each sign-in we store a session record with the device name your app reports, a coarse location, and technical details such as the browser or app user agent, so you can review and revoke your active sessions.
- Push notification tokens — if you enable notifications, the device token issued by Apple or Google, together with the platform and app version, so we can deliver reminders.
- Subscription records — if you buy a Pro subscription through the App Store or Google Play, the store tells us the product and plan (monthly or annual), its status (active, in a grace period, on hold, paused, expired or refunded), its start, renewal and cancellation dates, whether it auto-renews, whether it is a test or real purchase, and the store's own identifier for the subscription (Apple's original transaction id or Google's purchase token). We also keep a log of the notifications the store sends us about it. We never receive your card, bank or billing address details — the store takes payment and holds those.
- Server logs — requests to our API, including IP address, timestamp, endpoint and a request identifier, kept for security, debugging and abuse prevention.
We do not use advertising trackers, and we do not sell your personal data.
3. Signing in with Google or Apple
You can create an account or sign in using Google or Apple. When you do, that provider sends us a signed token containing your identifier with them, your email address and, where you allow it, your name and profile photo. We use it to create or match your account. We never receive your Google or Apple password. If you use Apple's "Hide My Email" feature, we only receive the relay address Apple generates for you.
4. Subscriptions and in-app purchases
Pro subscriptions are sold and billed by Apple (App Store) or Google (Google Play) under
their own terms and privacy policies, not by us. To match a purchase to your account, the
app attaches your account identifier to the purchase (Apple's appAccountToken or
Google's obfuscatedExternalAccountId); that identifier is the only account data
the store receives from us. We then confirm the purchase server-to-server with the App Store
Server API or the Google Play Developer API, and re-check it periodically and whenever the
store notifies us, so that your access reflects renewals, cancellations, billing problems and
refunds. We use this information only to work out which plan you are on, to apply that plan's
limits, and to show your subscription status in the app. To change or cancel a subscription,
use your App Store or Google Play subscription settings.
5. How we use your data
- To provide the Service: create your account, authenticate you, and store and display your content.
- To deliver the features you turn on: reminders, push notifications, email notifications, sharing with your connections, and budget and progress summaries.
- To work out which plan you are on (free or Pro) and apply its limits.
- To send service emails you cannot opt out of while you have an account, such as email verification and password reset codes.
- To keep the Service secure: detect and investigate abuse, unauthorised access and technical faults.
- To improve the Service: understand which features are used and diagnose problems, using aggregated or minimal information.
- To comply with legal obligations and to establish, exercise or defend legal claims.
6. Legal bases
Where data protection law such as the UK GDPR or EU GDPR applies, we rely on:
- Performance of a contract — to give you the Service you signed up for.
- Consent — for push notifications, optional marketing email, and the AI-assisted features described below. You can withdraw consent at any time.
- Legitimate interests — to keep the Service secure and working, and to improve it, balanced against your rights.
- Legal obligation — where we must retain or disclose data by law.
7. AI-assisted goal generation
If you use the AI features, the short description you type — plus context needed to draft the suggestion — is sent to our AI provider, Anthropic, which returns generated goal and action text. Only the text needed for that request is sent; your financial records, your connections and your other goals are not. Anthropic processes this on our behalf as a service provider and, under our arrangement, does not use it to train its models. Please avoid putting sensitive personal information into AI prompts.
8. What other users can see
- Your goals, actions and financial records are private to you unless you explicitly share an item.
- When you share an item, the people on its share list can see that item and the activity on it — comments, progress and check-ins.
- Users you are connected to see a limited public profile: your name and profile photo. Your email address, settings and unshared content are never exposed to other users.
- Removing someone from an item's share list stops future access. It cannot retract what they have already seen.
9. Service providers we share data with
We share personal data only with providers that process it on our behalf, under contract, and only as far as needed to run the Service:
- Cloud hosting and database (Amazon Web Services, Mumbai region, India) — running the application and storing your data.
- Object storage (Amazon S3, Mumbai region, India) — storing profile photos you upload.
- Firebase Cloud Messaging (Google) — delivering push notifications to your device.
- Email delivery — sending verification codes, password resets and notification emails.
- Anthropic — the AI features described in section 7.
- Apple and Google — if you choose to sign in with them, and to verify and keep in sync any Pro subscription you buy through the App Store or Google Play (section 4).
We may also disclose data where the law requires it, to enforce our Terms and Conditions, or to protect the rights and safety of our users. If our business is ever transferred, your data may transfer with it, and we will tell you first.
10. International transfers
Your account data and content are stored on Amazon Web Services servers in Mumbai, India. Some of our providers process data outside India and possibly outside your own country: Anthropic (United States) receives the text you send to the AI goal builder, Google (Firebase Cloud Messaging) and Apple receive push tokens and, if you use them, sign-in and subscription data, and our email provider delivers messages from Australia. Where that happens we rely on the providers' contractual data-protection commitments and, for data originating in the EU or UK, on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, to protect your data.
11. How long we keep data
- Your account data and content are kept while your account is open.
- When you delete your account, we deactivate it immediately and revoke every session and device token, so nobody can reach your data through the app. The underlying records are then retained for 30 days to allow for recovery from mistaken deletion, after which they are permanently erased and your email address becomes free to register again. Goals and actions you delete individually, sessions you revoke, and invitations that were declined or revoked are erased on the same 30-day schedule; comments, transactions, categories and connections you delete are erased at once. See Delete your data for the step-by-step guide.
- Subscription records are kept while your account is open and are deleted with it. The log of store notifications about a subscription (the store's transaction identifiers, not your name or email) is kept for 7 years so that billing questions and refunds can be reconciled with the store.
- Verification and password reset codes expire within minutes and are deleted shortly after use.
- Server logs are kept for a short rolling window for security and troubleshooting.
12. Security
We protect your data with encryption in transit (HTTPS), hashed passwords, hashed session tokens that let us revoke a device instantly, and access controls that scope every read and write to the account that owns the data. No system is perfectly secure, so please use a strong, unique password and sign out of devices you no longer use.
13. Your rights
Depending on where you live, you may have the right to:
- access a copy of the personal data we hold about you;
- correct inaccurate data — most of it you can edit directly in the app;
- delete your account and data, from within the app or by contacting us (see Delete your data);
- object to or restrict certain processing, and withdraw consent you have given;
- receive your data in a portable format;
- complain to your local data protection authority.
To exercise any of these rights, contact us using the details below. We respond within the period required by applicable law.
14. Children
The Service is for adults only: you must be 18 or older to create an account. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has given us data, contact us and we will delete it.
15. Changes to this policy
We may update this Privacy Policy as the Service evolves or the law changes. The current version is always at this page, with its effective date at the top. If a change is material we will give reasonable notice in the app or by email before it takes effect.
16. Contact us
For privacy questions or to exercise your rights, contact us at support@believebehavebecome.io, or see our Support page.