mood-mirror-legal

Privacy Policy

Last updated: August 29, 2026

Etchloom is designed to keep your personal mood and Journal content private. This Privacy Policy explains what information is stored on your device, what you may choose to synchronize, what limited product metrics we process, and how you can manage your data.

Who we are

Etchloom is a private mood journaling and reflection app provided by whilework. If you have questions, support requests, or privacy requests, contact us at mood.mirror.bot@gmail.com.

Summary

Data stored on your device

Etchloom stores app data locally in its database and settings storage on your device. This may include:

Your mood entries, notes, tags, context answers, and Journal content remain on your device unless you sign in and explicitly enable Cloud Save. Your device operating system may also include app data in device backups depending on your personal backup settings. Those backups are controlled by your device platform, not by Etchloom.

Accounts, sign-in, and Cloud Save

You can use the free local features without an account. An Etchloom account is required to purchase or restore Etchloom Space and to use Cloud Save.

Authentication and Cloud Save are provided through Supabase. Depending on your platform and availability, sign-in may use Apple or Google. When you create or use an account, the relevant services may process:

On mobile, authentication session data is stored using secure device storage where available. On web builds, session data may be stored in browser or app storage.

Cloud Save is optional and remains off until you explicitly enable it. When enabled, supported content is synchronized to Supabase under the cloud copy attached to your Etchloom account. This may include:

Supabase row-level security rules are intended to allow only the authenticated owner to read, create, update, or delete that account’s cloud archive.

Etchloom does not send your mood entries, notes, tags, context answers, or Journal content to analytics, advertising, or payment providers.

Anonymous product analytics

Etchloom processes a small set of first-party product metrics to understand whether core features work and which product flows are useful. These metrics are designed to be anonymous and aggregate-only.

The metrics may include:

Etchloom does not include your mood score, tags, notes, context answers, Journal titles or text, search text, selected dates, email address, Etchloom account ID, RevenueCat user ID, receipts, purchase tokens, advertising ID, device ID, contact information, or precise location in product analytics.

Product events are placed in a bounded queue on your device when they cannot be sent immediately. The queue keeps no more than 500 items, removes items older than 30 days, and is cleared when you delete local app data. After a batch is accepted, its local items are deleted.

Analytics batches are sent to a dedicated Supabase endpoint without your Etchloom login session. Each batch uses a random one-time delivery token only to prevent duplicate counting. The server immediately adds accepted values to daily aggregate totals; it does not store a raw event history or a user-level analytics profile. One-time delivery tokens are removed after 35 days, and daily aggregate totals are retained for up to 24 months.

Supabase acts as our infrastructure provider and may process ordinary network information, such as an IP address, in operational logs under its own policies. Etchloom does not copy an IP address into its analytics tables or use it to build an analytics profile. We do not sell analytics data or provide it to third parties for advertising or their own purposes.

Purchases and subscriptions

Etchloom Space subscriptions are processed by Apple App Store or Google Play and managed through RevenueCat.

When you view plans, purchase, restore, or check a subscription, Apple, Google, and RevenueCat may process purchase and technical information needed to provide and validate access. This may include:

Etchloom does not send mood entries, notes, tags, context answers, or Journal content to RevenueCat, Apple, or Google.

For more information, see:

Reminders and notifications

If you enable daily reminders, Etchloom asks your device for notification permission and schedules reminders through the device notification system. Reminder settings are stored on your device. Reminder content does not include your private notes, Journal pages, or mood entries.

Etchloom does not use push notification tokens for reminder delivery in the current app. You can turn reminders off in the app settings or in your device notification settings.

Import, export, sharing, and support

If you export your archive, Etchloom creates a CSV file on your device and lets you share it through your device’s share sheet. If you import an archive, the app reads the CSV file you choose. These actions are initiated by you.

If you contact support, we process the email address you use, your subject, your message, and any information you choose to include. Do not include private mood or Journal content unless it is necessary for your request.

Diagnostics and crash information

Etchloom does not include a third-party crash-reporting SDK. The anonymous product analytics described above is first-party, limited to allowlisted product actions, and does not include crash logs or private content. Apple, Google, your device operating system, Supabase, RevenueCat, or other service providers may process technical, network, diagnostic, or crash information as part of their services and platform operations under their own policies.

How we use information

We use information to:

We do not use your personal mood archive for advertising.

Third-party services

Etchloom uses service providers and platform services to operate the app:

These services may process data as described above and under their own policies. We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate notice where required.

Store privacy disclosures

For Apple App Privacy and Google Play Data safety disclosures, data transmitted off the device depends on the features you choose to use:

Your choices

You can use Etchloom locally without signing in. You can:

Data retention and deletion

Local app data remains on your device until you delete it in the app, uninstall the app, or your operating system removes it. Device backups may retain app data depending on your personal device backup settings.

Cloud archive data remains associated with your signed-in account while Cloud Save is used. You can remove data from inside the app:

The synchronization system may retain minimal deletion markers, such as dates and deletion timestamps, to prevent deleted entries from reappearing during later synchronization. Aggregate metrics that do not identify an event or user cannot be connected back to your account.

If you cannot use the in-app controls, see Delete your Etchloom account or Delete Etchloom data without deleting your account, or contact mood.mirror.bot@gmail.com. We may need to verify that you control the account before completing a request.

Deleting local data, cloud data, or your account does not automatically cancel an active subscription. Subscription and purchase records controlled by Apple, Google, or RevenueCat may be retained under their own policies. Manage or cancel the subscription through the store where you purchased it.

Security

We use reasonable technical and organizational measures designed to protect personal and sensitive user data. Cloud communications use encrypted transport where supported, Supabase access is restricted by authentication and row-level security rules, and mobile authentication sessions use secure device storage where available.

No method of storage or transmission is completely secure. Protecting access to your device and Etchloom account helps protect your app data. We recommend using your device passcode, biometric lock, and operating system security updates.

Children

Etchloom is not directed to children under 13 or to children below the minimum age required by applicable law in their country. If you believe a child has provided personal information through the app, contact us at mood.mirror.bot@gmail.com.

International processing

Your information may be processed in countries other than the country where you live, including where our service providers operate. Those countries may have different data protection laws.

Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the “Last updated” date and, where appropriate, provide additional notice.

Contact

mood.mirror.bot@gmail.com