Privacy Policy
Last updated: October 9, 2026
App name: Zyna: CBT Thought Journal
Legal entity: Zyna Mind Inc.
Package: com.zynamind.journal
Contact: privacy@zynamind.com
Policy URL: https://zynamind.com/privacy
Washington Consumer Health Data Privacy Policy: https://zynamind.com/wa-health-privacy
This Privacy Policy explains how Zyna Mind Inc. (“we”, “us”, “Zyna”, “the app”) collects, uses, stores, and shares information when you use Zyna: CBT Thought Journal, our cognitive behavioral therapy (CBT) reflections app on Android (and other platforms where available).
Zyna: CBT Thought Journal is a self-help reflections tool. It is not medical care, therapy, or a substitute for professional mental health treatment. If you are in crisis, contact the 988 Suicide & Crisis Lifeline (US and Canada), local emergency services (for example, 911), or a qualified professional immediately.
Summary
- We collect account and app data needed to sign you in, sync your encrypted reflections, run AI-assisted Reflections analyses you request, and process subscriptions.
- Inbox and Reflections are end-to-end encrypted when cloud sync is used. They are encrypted on your device before upload. We store only ciphertext for that clinical content — we cannot read your reflections without your password.
aiContextSettingsandappPreferencesare not end-to-end encrypted. When synced, they are stored in a server-readable form so the app can apply your settings across devices.- Cloud sync is enabled by default when you create an account (clinical content remains end-to-end encrypted). You can turn it off in Settings → Data.
- Thought analysis runs only after you agree on a just-in-time consent screen.
- Product analytics and crash reporting are off by default for all users. They run only if you turn on Diagnostics & usage metrics in Settings (Quebec Law 25–aligned opt-in posture, applied globally).
- When you request thought analysis, reflection text is sent to our backend over TLS plus an additional encrypted session layer, decrypted only in volatile server memory for that request, forwarded to Google Gemini Enterprise (Google Cloud Agent Platform), and not stored as plaintext on our servers afterward.
- Paid features use Google Play Billing and equivalent stores where available (including subscription status sync via RevenueCat when enabled).
- You can export your data and delete your account from the app.
Information we collect
Account and authentication
- Email address and sign-in password (passwords are hashed with scrypt; we do not store plain-text passwords).
- Encryption password — for Google/Apple/email-code accounts, chosen by you to protect your reflections. We never receive or store this password in plain text; we store only a password-wrapped encryption key.
- Email/password accounts use the same password for sign-in and encryption.
- Email sign-in codes when you use passwordless login.
- Google Sign-In or Sign in with Apple (where supported) — email and basic profile details allowed by those services.
- Authentication tokens and refresh tokens to keep you signed in securely.
- Welcome acknowledgements (Privacy/Terms, health-data processing, confirmation you are at least 13) stored on your device and, when signed in, on our consent ledger.
Profile and preferences (optional)
- Display name and profile photo (if you upload one).
- Mental health status preferences you choose to share (self-reported; not a diagnosis). Sensitive profile fields used for AI context stay on your device or inside your encrypted cloud blob.
- App preferences (appearance, accessibility, quiet progress mode, and similar). When cloud sync is on, synced
appPreferencesare server-readable. - AI context settings (
aiContextSettings) — when synced, these are server-readable and are not part of the end-to-end encrypted clinical blob. - Spoon budget values you set locally on your device. Spoon budget is not synced as server-held consumer health data.
- Consent choices (cloud sync, thought analysis, optional diagnostics).
Content you create
- Inbox thoughts, Reflections, clarification answers, drafts, and related metadata (titles, timestamps, emotional intensity, sort order, and similar fields you log).
- On cloud sync, this clinical content is stored as an encrypted clinical blob (
ciphertext_payload,iv,auth_tag). We cannot read it without your secrets.
Subscriptions and purchases
- Product IDs, purchase tokens, order/subscription status, expiry/renewal info, and billing metadata for Premium features and fraud prevention.
- Billing is processed by Google Play (or the applicable app store). We do not receive your full payment card number.
- Where enabled, RevenueCat may sync subscription status with your account.
Product analytics and diagnostics (opt-in)
Diagnostics & usage metrics are disabled by default for all users worldwide. Only if you enable them in Settings may the app send:
- First-party analytics events: app opens, screen views, feature usage, platform/version, and aggregate AI operation and cost token metrics used for budgeting and free-tier limits. These are not metrics of your psychological state and are not used for advertising.
- Crash and error diagnostics (e.g. via Sentry): stack traces, device model, OS version, and app version. They are configured to avoid thought-record contents.
If you leave diagnostics off, we do not send these client analytics/crash events.
Usage and service data
- Daily/monthly usage counts for free-tier AI limits (needed to run the service).
- Audit logs of account access (who, when, which API path) without clinical content.
- Basic server logs for reliability and security.
Information we do not intentionally collect
- We do not require your legal name, phone number, or precise GPS location.
- We do not sell your personal information.
- We do not share personal information for cross-context behavioral advertising.
- We do not use your reflections for advertising.
- We do not train our own models on your content.
- We do not implement geofences around in-person healthcare facilities to identify, track, or collect consumer health data.
How we use your information
We use information to:
- Create and manage your account and authenticate you.
- Store and sync encrypted inbox and Reflections, and sync server-readable preferences/settings, while cloud sync is enabled.
- Generate reflections and related AI features only when you request them and grant thought-analysis consent.
- Verify subscriptions and provide Premium features.
- Enforce usage limits and prevent abuse.
- Improve reliability when you opt in to diagnostics.
- Send transactional email (sign-in codes, password reset).
- Maintain security and audit access.
Encryption and security
Cloud sync (end-to-end encryption for clinical content)
Cloud sync is on by default for accounts. When enabled:
- Your device generates a data encryption key.
- Inbox and Reflections (clinical content) are encrypted with AES-256-GCM on your device.
- Only clinical ciphertext is uploaded for that content to Google Cloud Firestore (
ciphertext_payload,iv,auth_tag). - Your password (via Argon2id) wraps the data key for restore on new devices. For email/password accounts, this is your sign-in password.
- Zyna Mind Inc. cannot decrypt your Inbox or Reflections without your password.
Not covered by end-to-end encryption: synced aiContextSettings and appPreferences are stored so our servers can read them to operate the service. Account fields (email, subscription status, consent records, wrapped keys, and similar) are also server-managed.
AI thought analysis (encrypted transit, transient processing)
When you run a Reflections analysis:
- You must be signed in and grant thought analysis consent.
- Your request body is encrypted with a per-session AES-256-GCM key (in addition to HTTPS).
- Our server decrypts it only in volatile memory for that request, calls Google Gemini Enterprise (Google Cloud Agent Platform), returns an encrypted response, and wipes plaintext references afterward.
- We do not persist your thought text on our servers for AI. Results are stored on your device and, if cloud sync is on, inside your encrypted clinical blob.
Important: Google’s AI service must process plaintext to generate a response. Google processes data under Google’s terms and privacy policies. We use the enterprise Agent Platform path (not consumer AI Studio API keys).
Reporting AI content
If you use the in-app Report control on AI-generated text, you intentionally send us the reported snippet (and any optional note you add) so we can review safety or quality issues. This does not upload your full encrypted vault—only the content you choose to report for that submission.
Sign-in passwords
Login passwords are hashed with scrypt (unique salt per account). For email/password accounts, the same password also protects your encrypted reflections on device.
Third-party services
| Service | Purpose |
|---|---|
| Google Cloud (Cloud Run + Firestore) | API hosting and encrypted account/sync storage |
| Google Gemini Enterprise / Agent Platform | Thought analysis and related AI features you request |
| Google Sign-In | Optional authentication |
| Google Play Billing | Subscriptions and purchase verification |
| Sign in with Apple | Optional authentication (where supported) |
| Resend | Transactional email |
| Sentry (only if you enable diagnostics) | Crash and error diagnostics |
| RevenueCat (when enabled) | Subscription status sync |
Where data is stored
- On your device: Inbox, Reflections, drafts, encryption keys (in secure storage), preferences (including local spoon budget), and cached account data.
- On our servers: Account fields, encrypted clinical blob (while cloud sync is on), wrapped encryption keys, server-readable
appPreferencesandaiContextSettings, subscription status, consent records (including welcome acknowledgements), audit logs, and (if opted in) analytics summaries. No plaintext inbox or Reflections stored for sync. - API and AI inference: Google Cloud United States — Northern Virginia (
us-east4). - Firestore (clinical ciphertext and sync database): Google Cloud Canada — Toronto (
northamerica-northeast2).
Production traffic uses HTTPS and strict transport security headers.
Your choices and rights
Consent
- Cloud sync: On by default (clinical content encrypted). Turn off in Settings → Data. Revoking removes your encrypted clinical blob from our servers.
- Thought analysis: Granted only via a just-in-time prompt before analysis. Decline anytime; reflecting still works. We will ask again before the next analysis.
- Diagnostics & usage metrics: Off by default for all users. Opt in or out in Settings.
- Welcome screen: You must agree to the Privacy Policy and Terms, acknowledge health-data processing for app functions, and confirm you are at least 13 years old before continuing.
Export, clear, delete
- Export: Settings → Data & export → Export my data (JSON file).
- Clear local data: Removes content from this device only.
- Delete account: Permanently deletes your account and synced server data. See also https://zynamind.com/delete-account.
Encryption password and recovery
- Choose a strong password (8+ characters with upper, lower, number, and symbol).
- Forgot your password? Use in-app reset — we email you a code. Without your current password, cloud reflections cannot be recovered (by design).
Manage subscriptions
Subscriptions are billed through Google Play (or the applicable store where available). Canceling stops future renewals; it does not automatically delete your Zyna account.
California (CCPA/CPRA)
If you are a California resident, you have rights to know, access, delete, and correct certain personal information, and to limit use of sensitive personal information where applicable. We do not sell personal information and do not share it for cross-context behavioral advertising. To exercise rights, email privacy@zynamind.com. We will verify your request as required by law. You may use an authorized agent where permitted.
Canada (PIPEDA) and Quebec (Law 25)
Canadian users may request access to or correction of personal information we hold about them, subject to legal exceptions. Contact privacy@zynamind.com.
As noted above, API and AI processing occur in the United States (us-east4), while encrypted Firestore clinical ciphertext resides in Canada (Toronto) (northamerica-northeast2). If you access the app from Quebec or other Canadian provinces, some of your information is transferred outside Canada for API and AI processing.
This English policy applies to our English-language service. Quebec / French language materials will be expanded as we deepen Quebec-facing support.
Washington State residents: see our separate Consumer Health Data Privacy Policy.
Contact us
Email privacy@zynamind.com for data questions or export/deletion help.
Person in charge of the protection of personal information (Quebec Law 25)
In compliance with Quebec Law 25, our designated Privacy Officer is responsible for safeguarding your personal information.
Title: Chief Privacy Officer
Email: privacy@zynamind.com
Address: 2003-2967 Dundas St. W., Toronto, ON M6P 1Z2
Data retention
- Account data is kept while your account is active.
- AI request plaintext exists only transiently during processing — not stored afterward.
- Account deletion removes associated server data, subject to limited legal/security exceptions (for example, audit records retained as required).
- Local device data remains until you clear it or uninstall.
Security
We use password hashing (scrypt), authenticated API access, HTTPS, end-to-end encryption for cloud Inbox and Reflections, encrypted AI transit sessions, consent gating, audit logging, and access controls on Google Cloud. No method is 100% secure — use strong passwords and protect your device.
International transfers
Some processing occurs in the United States (API and AI inference in us-east4). Encrypted Firestore storage for clinical ciphertext is in Canada (Toronto) (northamerica-northeast2). By using the app, you understand your information may be processed in these locations.
Children
Not directed to children under 13. We do not knowingly collect data from children under 13. The app requires you to confirm you are at least 13 years old before continuing. Contact us to request deletion if you believe a child under 13 created an account.
Changes to this policy
We may update this policy and change the “Last updated” date at https://zynamind.com/privacy. Continued use after changes means you accept the updated policy where permitted by law.
Contact
Email: privacy@zynamind.com
Company: Zyna Mind Inc.
Mailing address: 2003-2967 Dundas St. W., Toronto, ON M6P 1Z2
This policy describes our current practices. It is not legal advice.