Last updated: September 1, 2026
Effective date: Not yet effective; pending publication
Publication status: Draft for legal and operational review. Do not publish until the publication blockers recorded in the source of this document have been resolved and the described controls have been verified in production.
The Inner Child mobile application (the “App”), the website at innerchild.care (the “Website”), and related services (together, the “Services”) are owned and operated by Inner Child Care Inc. (“Inner Child,” “we,” “us,” or “our”). Inner Child Care Inc. is the controller of personal data processed through the Services as described in this Privacy Policy.
- Controller / operator: Inner Child Care Inc., a Delaware corporation
- Delaware file number: 10676690
- California entity number: B20260319229
- Principal and mailing address: 2223 Santa Clara Ave, Suite B3, Alameda, CA 94501, United States
- Privacy and support email: headquarters@innerchild.care
- Privacy and support phone: +48 509 497 776
- Service availability: The Services may be made available internationally. Availability in a country does not mean that every feature is localized or that Inner Child has an office in that country.
1. Scope
This Policy applies when you:
- use the App or create an App account;
- complete an App or Website questionnaire;
- use daily questions, affirmations, tasks, feedback, or notification features;
- subscribe to a newsletter or release notification;
- contact us;
- apply for a role through the Website; or
- otherwise interact with the Services.
It does not govern a third-party website or service that has its own privacy policy.
Additional notices apply to particular processing:
- the Consumer Health Data Privacy Policy covers consumer health data under applicable United States state laws;
- the Cookie Policy describes Website cookies, local storage, and similar technologies; and
- the Applicant Privacy Notice covers recruitment and job applications.
Those notices supplement this Policy. If a supplemental notice provides a stronger protection for the same data, the supplemental notice controls.
2. Eligibility and children
The App, App accounts, Website questionnaires, newsletter signups, and other personal-data submission features are intended for people who are at least 18 years old. The App presents an 18+ confirmation during onboarding, and its store listing uses an adult age rating. We do not knowingly collect personal data through those features from anyone under 18.
If you are under 18, do not create an account or submit personal data. If you believe a person under 18 has submitted personal data, contact us so we can investigate and delete it where appropriate.
3. Personal data we collect
3.1 Account and authentication data
When you create or use an App account, we may process:
- email address;
- internal account and authentication identifiers;
- authentication session data and tokens;
- sign-in provider identifiers and, where provided, name and email from Google or Apple; and
- account status, security events, and password-recovery information.
Passwords are handled through our authentication provider. We do not intend to store passwords in plain text.
3.2 Profile, preferences, and onboarding
Depending on the feature, we may collect:
- name or username;
- adult age, gender, language, locale, and preferences;
- the chosen name, age, appearance, and configuration of an inner-child avatar;
- onboarding selections about needs, fears, confidence, self-criticism, external validation, self-perception, social anxiety, and related wellbeing topics; and
- derived categories, labels, progress state, or content groupings generated from your selections.
These data can be sensitive and may reveal or support inferences about mental, emotional, psychological, or behavioral wellbeing.
3.3 Reflections and daily-content data
We may collect content and interactions you submit through daily questions, affirmations, and tasks, including:
- written reflections, gratitude entries, task reports, and comments;
- content identifiers and the content presented to you;
- completion, skip, vote, feedback, and reason selections; and
- dates, progress, and related feature state.
The Services are not designed to store medical records. Please do not submit medical records, diagnostic documents, or information that is not needed to use the requested feature.
3.4 Photos, files, and attachments
If you upload a photo, screenshot, resume, or other file, we process the file and associated metadata, such as its name, type, size, upload time, owner or account identifier, and related feature or task.
App photos and feedback attachments are intended to be stored in private storage with owner- or role-based access. Job application files are covered by the Applicant Privacy Notice.
Publication blocker: Verify every deployed bucket is private and remove or authorize legacy filename-based signed-URL access before claiming that only the user and authorized personnel can retrieve uploads.
3.5 Feedback, support, and contact data
When you contact us or submit feedback, we may collect:
- your name and email address;
- message, feedback category, free text, and attachments;
- the App version, device/platform context, locale, and timezone; and
- information needed to investigate and respond to your request.
The Website contact form requires a name and email address.
3.6 Website questionnaire and release-notification data
The Website questionnaire may collect:
- name, email address, age, gender, and a chosen inner-child name;
- answers about childhood experiences, fears, conflict, self-criticism, body image, confidence, social anxiety, and related wellbeing topics; and
- submission time and operational request data.
We store the submission in Supabase. The complete submission may also be sent to an authorized administrator through Resend for review and release-notification administration. The questionnaire is not anonymous.
3.7 Newsletter, signup, and marketing data
When you subscribe to the blog newsletter, release notification, or another marketing list, we may collect your email address, subscription source, content-space identifier, signup time, consent record, and unsubscribe status.
If you use a public signup or preregistration form, we may process the name, email, and submitted credential long enough to handle the request. A Website acknowledgement does not necessarily mean an App account has been created; App account creation is completed through the App’s authentication flow.
We will send optional marketing communications only where we have the consent or other permission required by applicable law. Every marketing email must provide a working unsubscribe method.
Publication blocker: Implement and verify newsletter/release-list consent, consent evidence, and a functioning unsubscribe flow before marketing messages are sent. Remove personal data from public application logs.
3.8 Recruitment data
If you apply for a role, we collect the data described in the Applicant Privacy Notice, including required contact information, application answers, and a resume/CV. Recruitment data is not governed by the App-account deletion flow.
3.9 Notifications
If you enable notifications, we may process:
- an installation identifier and push token;
- platform and push provider;
- timezone and permitted notification categories;
- notification identifiers, delivery state, and interaction source; and
- notification preferences and permission state.
The operating system controls permission to display notifications. You can change notification choices in the App and device settings.
3.10 Device, network, security, and diagnostic data
We and our providers may process:
- IP address, user agent, browser, device model, operating system, App version, build, language, locale, timezone, and UTC offset;
- request timestamps, security events, rate-limit information, and operational identifiers;
- crash reports, exception information, and stack traces; and
- performance and reliability measurements.
Diagnostic records can unintentionally contain identifiers or limited request context. We prohibit intentionally logging passwords, authentication tokens, private reflections, wellbeing answers, or personal media.
Publication blocker: Remove release logging of authentication User/Session objects, OAuth PII, token prefixes, and profile/avatar data before publication. Verify Firebase Crashlytics redaction and collection configuration.
3.11 Session replay with password controls masked
Where enabled and permitted, PostHog may process pseudonymous session-replay and App-activity data, including:
- pseudonymous device, session, and replay identifiers;
- screen structure, navigation, taps, scrolling, positions, and duration;
- App/build version, platform, OS, device model, locale, timezone, and transiently derived country; and
- rendered screen text and images.
Replay may contain readable names, emails, onboarding and wellbeing content, reflections, feedback, notification content, and personal images or photos. Only password-input control regions are masked, including while a visibility control reveals the password on the device.
The approved PostHog configuration enables screen and application-lifecycle events and session replay. It leaves global text and image masking disabled and disables PostHog person profiles, feature-flag events and preloading, and surveys. Authentication tokens and other secrets must not be rendered or added to event properties, logs, or raw exception fields.
Readable content, screen structure, and interaction patterns may reveal or support inferences about wellbeing. We therefore treat replay data as potentially sensitive and pseudonymous, not anonymous.
Publication blocker: Do not enable session replay until any required prior affirmative consent, notice/choice/version record, and equally easy withdrawal are implemented and verified. Confirm the PostHog project token, host/region, DPA, replay retention, and deletion process.
3.12 Cookies and similar Website technologies
The Website may use authentication cookies, local storage, and performance measurement. Career pages use a local-storage marker to avoid repeatedly counting the same job view for approximately 30 days. Vercel Speed Insights may process Website performance measurements. See the Cookie Policy for details.
Non-essential storage or measurement must not be activated where consent is required until you have made a valid choice.
Publication blocker: Deploy and verify a consent manager that blocks non-essential local storage and analytics before consent for users where required. The current Website does not implement that control.
4. Sources of personal data
We collect personal data:
- directly from you;
- automatically from your device, browser, and use of the Services;
- from Google or Apple when you choose their sign-in service;
- from app stores, operating systems, and push-notification providers;
- from providers that operate the Services on our behalf; and
- from an applicant, recruiter, reference, or publicly available professional source in the recruitment context.
We may create inferences from your selections and interactions as described above.
5. Why we process personal data
We process personal data to:
- provide, personalize, and maintain the Services you request;
- create and secure accounts and authenticate users;
- store and display your content;
- deliver questions, affirmations, tasks, and notifications;
- respond to support, contact, and feedback requests;
- administer questionnaires, release notifications, newsletters, and job applications;
- protect the Services, prevent abuse, and investigate incidents;
- diagnose crashes and reliability problems;
- measure and improve product performance where permitted;
- comply with law and enforce legal rights; and
- obtain professional advice and manage legal claims.
We do not use wellbeing content or consumer health data for targeted advertising, credit, insurance, employment eligibility, or data-broker purposes.
6. EEA/UK legal bases
When we offer the Services to, or monitor use by, people in the EEA or UK, we rely on the following legal bases, depending on the processing:
- Contract: processing necessary to create an account, provide requested App features, store your content, and deliver service communications.
- Consent: session replay with password controls masked, non-essential cookies or local storage, marketing communications, and other optional processing where consent is required.
- Explicit consent: processing wellbeing information that constitutes special-category health data when no other Article 9 condition applies.
- Legitimate interests: proportionate security, fraud prevention, service administration, support, non-sensitive reliability work, legal claims, and limited business administration, after balancing those interests against your rights.
- Steps before a contract: evaluating a job application at your request.
- Legal obligation: complying with law, court orders, and regulatory duties.
We do not rely on legitimate interests to avoid an explicit-consent requirement for special-category health data, optional marketing, or non-essential Website tracking.
You may withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal.
Publication blocker: Counsel must confirm the Article 6 and Article 9 basis for each wellbeing/questionnaire/replay purpose and whether a DPIA is required. The implementation must match the selected basis before publication.
Publication blocker: Because the Operator is established in the United States and the Services are offered internationally, determine whether an EU representative and a UK representative are required. If required, appoint them in writing and publish their contact details before offering or monitoring the affected processing in those territories.
7. Consumer health data
Some onboarding answers, questionnaire responses, reflections, screen-level behavior, derived labels, and related information may qualify as consumer health data under United States state law. The Consumer Health Data Privacy Policy describes the applicable categories, sources, purposes, disclosures, consents, and rights.
We do not sell consumer health data. We obtain consent before collecting or sharing it when applicable law requires consent and the processing is not necessary to provide a product or service you requested.
8. Disclosures and service providers
We disclose personal data only as described here and subject to appropriate contracts where required.
| Recipient/category | Purpose and possible data |
|---|---|
| Supabase | Authentication, database, Edge Functions, and private file storage; account data, content, submissions, and operational records. |
| Vercel | Website hosting, request handling, and Speed Insights; network, browser, and performance data. |
| Resend | Contact, questionnaire, recruitment, release-notification, and other operational email; message and recipient content required for the email. |
| PostHog | App screen and lifecycle events plus session replay; pseudonymous device/session context and readable rendered content, with password-input controls masked. |
| Google / Firebase | Crashlytics diagnostics, Google sign-in, Firebase Cloud Messaging, and related platform services. |
| Apple | Apple sign-in, App Store services, and Apple Push Notification service. |
| Google Workspace/Gmail | Privacy, support, and business mailbox administration. |
| Authorized personnel and professional advisers | Support, security, recruitment, legal, accounting, and compliance activities on a need-to-know basis. |
We may also disclose personal data:
- when you direct or consent to the disclosure;
- to comply with law or a valid legal process;
- to protect users, the public, or the security and integrity of the Services;
- in connection with a merger, financing, acquisition, reorganization, insolvency, or sale of assets, subject to applicable notice and protection requirements; or
- to establish, exercise, or defend legal claims.
We currently identify no affiliated company with which consumer health data is shared.
Publication blocker: Verify the complete processor/subprocessor inventory, legal entity names, processing locations, signed DPAs/SCCs, Firebase services, push providers, support mailbox provider, and any production vendors not listed above.
9. No sale or targeted advertising
We do not sell personal data or consumer health data. We do not use sensitive wellbeing data for targeted advertising or cross-context behavioral advertising. We do not knowingly share personal data for those purposes.
If these practices change, we will update the applicable notices and obtain any authorization or consent required before the change.
10. Retention
We use the following maximum retention targets unless law requires a different period or data is needed for a documented legal claim:
| Data | Retention target |
|---|---|
| Account and App content | Until account deletion or an earlier valid deletion request. |
| Website questionnaire/release-notification submission | Up to 12 months after submission or until the release-notification purpose is completed, whichever occurs first. |
| Newsletter subscription | Until unsubscribe, withdrawal, or 24 months of inactivity, subject to a minimal suppression record where needed to honor the request. |
| Contact, feedback, and support records | Up to 12 months after the request is closed, unless a longer period is needed for security or a legal claim. |
| Job applications | Up to 12 months after the applicable recruitment process ends; see the Applicant Privacy Notice. |
| Job-view local-storage marker | Approximately 30 days on the browser. |
| Security/access logs containing IP address or user agent | Up to 30 days, unless a documented incident requires longer preservation. |
| PostHog session replay with password controls masked | No more than 30 days from capture. |
| Firebase Crashlytics data | According to a verified production retention setting, not longer than necessary for crash diagnosis. |
| Push installation records | While the installation is active, then deleted or deactivated after logout, account deletion, token invalidation, or a defined inactivity period. |
| Deletion-integrity record | A non-content, non-reversible integrity record for up to 90 days where needed to prevent restored backups from reviving deleted data. |
When a retention period expires, we delete or irreversibly deidentify the data. We do not retain identifiable replay data indefinitely.
Backups are deleted as they rotate. Our target is to remove deleted App-account data from live systems within 30 days and from backups within 90 days. Where an applicable consumer health law requires a shorter or different deadline, that law controls.
Publication blocker: Implement and verify automated retention for Website questionnaires, newsletters, contact/support records, recruitment data, push installations, and provider data. Verify the production PostHog and Firebase settings and backup schedule before publishing these targets as commitments.
11. Your choices and consent controls
Depending on the feature and your location, you can:
- decline or withdraw session replay without losing core App functionality;
- change notification choices in the App or device settings;
- unsubscribe from marketing email using the link in the message;
- manage non-essential Website technologies through the consent control;
- stop submitting optional content; and
- request access, correction, deletion, or another applicable privacy right.
Opening a legal notice must not itself enable analytics or non-essential tracking. A consent request must clearly identify the relevant data, purpose, recipient or provider category, and withdrawal method. Consent is not bundled into general acceptance of the Terms where separate consent is legally required.
12. Account deletion and other deletion requests
You can start App-account deletion in Settings > Account > Delete Account. The App sends a deletion request and may show the request as pending while server-side deletion completes. You may leave the App after the request is accepted.
You may also email headquarters@innerchild.care for help or to request deletion of Website, recruitment, newsletter, support, or other data not connected to the App-account deletion flow.
Subject to legal exceptions, deletion includes:
- associated App-account content and profile data;
- personal files and storage objects;
- active push installations;
- processor and provider data where the data can reasonably be linked to the request; and
- backup data as backups rotate within the applicable deadline.
Local App cleanup does not by itself delete data already transmitted to a provider. We use server-side or manual provider processes where necessary.
We may retain limited data where required to comply with law, prevent fraud, protect security, resolve disputes, or establish legal claims. We will explain the applicable exception when required.
13. Privacy rights
13.1 EEA/UK
Subject to applicable conditions and exceptions, you may have rights to:
- access personal data and receive information about processing;
- correct inaccurate or incomplete data;
- delete personal data;
- restrict processing;
- object to processing based on legitimate interests or direct marketing;
- receive portable data where applicable;
- withdraw consent; and
- complain to a supervisory authority.
The Polish supervisory authority is the President of the Personal Data Protection Office (UODO). You may also contact the authority where you live or work.
13.2 United States
Depending on your state, you may have rights to:
- confirm processing and access personal data;
- correct inaccurate data;
- delete data;
- obtain a portable copy;
- obtain information about disclosures;
- opt out of sale, targeted advertising, or certain profiling;
- withdraw consent to sensitive-data processing;
- appeal a denied request; and
- exercise rights without unlawful discrimination.
We do not sell personal data or use it for targeted advertising. Consumer health data rights are described in the Consumer Health Data Privacy Policy.
13.3 How to submit a request
Email headquarters@innerchild.care with the subject Privacy Request. Describe the Service and email/account identifier involved and the right you want to exercise. Do not send a password or authentication token.
We may verify your identity and authority using information proportionate to the request. An authorized agent may submit a request where applicable, but we may require proof of authority and direct verification with the consumer.
We aim to respond within the period required by applicable law. If we deny a request, we will explain the reason and any available appeal method. To appeal, reply with the subject Privacy Appeal.
14. International transfers
We are a United States corporation and make the Services available internationally. We use providers that may process data in the United States, the EEA, and other countries. Where EEA/UK transfer rules apply, we use an applicable adequacy decision, approved contractual safeguards such as Standard Contractual Clauses, or another lawful transfer mechanism. We assess additional safeguards where required.
You may request information about the applicable transfer mechanism by contacting us.
Publication blocker: Verify provider regions and executed transfer mechanisms, including DPAs/SCCs and any Data Privacy Framework reliance, before publication.
15. Security
We use administrative, technical, and organizational safeguards proportionate to the sensitivity of the data, including encrypted transport, authentication, role- and capability-based access, row-level database controls, private storage, least-privilege service access, logging restrictions, deletion procedures, and security review of sensitive changes.
Access is limited to authorized people and providers who need it for the purposes described in this Policy. We do not represent that production access is held by only one named person unless that statement is continuously verified.
No system is completely secure. If an incident triggers a legal notification duty, we will notify affected people and authorities as required.
16. Automated decisions
The Services may derive labels or content groupings to personalize the experience, but we do not use solely automated processing to make decisions that produce legal or similarly significant effects concerning you.
17. Changes to this Policy
We may update this Policy when our practices or legal obligations change. We will update the date above and provide additional notice for material changes where required. If a change requires consent, we will request it before the new processing begins.
We will retain prior versions or a change summary where reasonably practical.
18. Contact
For privacy questions, rights requests, deletion, consent withdrawal, or a privacy appeal, contact:
Inner Child Care Inc.
2223 Santa Clara Ave, Suite B3, Alameda, CA 94501, United States
headquarters@innerchild.care
+48 509 497 776
Do not send passwords, authentication tokens, medical records, or unnecessary sensitive information by email.