Privacy Policy

Last updated: October 9, 2026

App name: Zyna: CBT Thought Journal
Legal entity: Zyna Mind Inc.
Package: com.zynamind.journal
Contact: privacy@zynamind.com
Policy URL: https://zynamind.com/privacy
Washington Consumer Health Data Privacy Policy: https://zynamind.com/wa-health-privacy

This Privacy Policy explains how Zyna Mind Inc. (“we”, “us”, “Zyna”, “the app”) collects, uses, stores, and shares information when you use Zyna: CBT Thought Journal, our cognitive behavioral therapy (CBT) reflections app on Android (and other platforms where available).

Zyna: CBT Thought Journal is a self-help reflections tool. It is not medical care, therapy, or a substitute for professional mental health treatment. If you are in crisis, contact the 988 Suicide & Crisis Lifeline (US and Canada), local emergency services (for example, 911), or a qualified professional immediately.

Summary

Information we collect

Account and authentication

Profile and preferences (optional)

Content you create

Subscriptions and purchases

Product analytics and diagnostics (opt-in)

Diagnostics & usage metrics are disabled by default for all users worldwide. Only if you enable them in Settings may the app send:

If you leave diagnostics off, we do not send these client analytics/crash events.

Usage and service data

Information we do not intentionally collect

How we use your information

We use information to:

Encryption and security

Cloud sync (end-to-end encryption for clinical content)

Cloud sync is on by default for accounts. When enabled:

  1. Your device generates a data encryption key.
  2. Inbox and Reflections (clinical content) are encrypted with AES-256-GCM on your device.
  3. Only clinical ciphertext is uploaded for that content to Google Cloud Firestore (ciphertext_payload, iv, auth_tag).
  4. Your password (via Argon2id) wraps the data key for restore on new devices. For email/password accounts, this is your sign-in password.
  5. Zyna Mind Inc. cannot decrypt your Inbox or Reflections without your password.

Not covered by end-to-end encryption: synced aiContextSettings and appPreferences are stored so our servers can read them to operate the service. Account fields (email, subscription status, consent records, wrapped keys, and similar) are also server-managed.

AI thought analysis (encrypted transit, transient processing)

When you run a Reflections analysis:

  1. You must be signed in and grant thought analysis consent.
  2. Your request body is encrypted with a per-session AES-256-GCM key (in addition to HTTPS).
  3. Our server decrypts it only in volatile memory for that request, calls Google Gemini Enterprise (Google Cloud Agent Platform), returns an encrypted response, and wipes plaintext references afterward.
  4. We do not persist your thought text on our servers for AI. Results are stored on your device and, if cloud sync is on, inside your encrypted clinical blob.

Important: Google’s AI service must process plaintext to generate a response. Google processes data under Google’s terms and privacy policies. We use the enterprise Agent Platform path (not consumer AI Studio API keys).

Reporting AI content

If you use the in-app Report control on AI-generated text, you intentionally send us the reported snippet (and any optional note you add) so we can review safety or quality issues. This does not upload your full encrypted vault—only the content you choose to report for that submission.

Sign-in passwords

Login passwords are hashed with scrypt (unique salt per account). For email/password accounts, the same password also protects your encrypted reflections on device.

Third-party services

Service Purpose
Google Cloud (Cloud Run + Firestore) API hosting and encrypted account/sync storage
Google Gemini Enterprise / Agent Platform Thought analysis and related AI features you request
Google Sign-In Optional authentication
Google Play Billing Subscriptions and purchase verification
Sign in with Apple Optional authentication (where supported)
Resend Transactional email
Sentry (only if you enable diagnostics) Crash and error diagnostics
RevenueCat (when enabled) Subscription status sync

Where data is stored

Production traffic uses HTTPS and strict transport security headers.

Your choices and rights

Export, clear, delete

Encryption password and recovery

Manage subscriptions

Subscriptions are billed through Google Play (or the applicable store where available). Canceling stops future renewals; it does not automatically delete your Zyna account.

California (CCPA/CPRA)

If you are a California resident, you have rights to know, access, delete, and correct certain personal information, and to limit use of sensitive personal information where applicable. We do not sell personal information and do not share it for cross-context behavioral advertising. To exercise rights, email privacy@zynamind.com. We will verify your request as required by law. You may use an authorized agent where permitted.

Canada (PIPEDA) and Quebec (Law 25)

Canadian users may request access to or correction of personal information we hold about them, subject to legal exceptions. Contact privacy@zynamind.com.

As noted above, API and AI processing occur in the United States (us-east4), while encrypted Firestore clinical ciphertext resides in Canada (Toronto) (northamerica-northeast2). If you access the app from Quebec or other Canadian provinces, some of your information is transferred outside Canada for API and AI processing.

This English policy applies to our English-language service. Quebec / French language materials will be expanded as we deepen Quebec-facing support.

Washington State residents: see our separate Consumer Health Data Privacy Policy.

Contact us

Email privacy@zynamind.com for data questions or export/deletion help.

Person in charge of the protection of personal information (Quebec Law 25)

In compliance with Quebec Law 25, our designated Privacy Officer is responsible for safeguarding your personal information.

Title: Chief Privacy Officer
Email: privacy@zynamind.com
Address: 2003-2967 Dundas St. W., Toronto, ON M6P 1Z2

Data retention

Security

We use password hashing (scrypt), authenticated API access, HTTPS, end-to-end encryption for cloud Inbox and Reflections, encrypted AI transit sessions, consent gating, audit logging, and access controls on Google Cloud. No method is 100% secure — use strong passwords and protect your device.

International transfers

Some processing occurs in the United States (API and AI inference in us-east4). Encrypted Firestore storage for clinical ciphertext is in Canada (Toronto) (northamerica-northeast2). By using the app, you understand your information may be processed in these locations.

Children

Not directed to children under 13. We do not knowingly collect data from children under 13. The app requires you to confirm you are at least 13 years old before continuing. Contact us to request deletion if you believe a child under 13 created an account.

Changes to this policy

We may update this policy and change the “Last updated” date at https://zynamind.com/privacy. Continued use after changes means you accept the updated policy where permitted by law.

Contact

Email: privacy@zynamind.com
Company: Zyna Mind Inc.
Mailing address: 2003-2967 Dundas St. W., Toronto, ON M6P 1Z2


This policy describes our current practices. It is not legal advice.