Privacy Policy
Effective July 9, 2026 · Last revised August 9, 2026
FutureSelf is a native iOS app for behavioral growth and reflection, operated by Future Self LLC (“FutureSelf,” “we,” “us,” or “our”). This Privacy Policy explains what information we collect, what stays on your device, what leaves your device, how we use it, who processes it, and the choices you have.
By using FutureSelf or this website, you agree to this policy. If you do not agree, do not use the app.
1. Scope
This policy covers:
- The FutureSelf iOS application
- The futureslf.com website
- Related support and account services we operate
It does not cover third-party websites or services you open through links (for example, crisis hotlines, Apple, or nutrition databases). Those have their own policies.
2. Our privacy posture in one sentence
FutureSelf is on-device first, not device-only. Your reflections, identity work, voice recordings, and most day-to-day data start on your iPhone. Private-iCloud mirroring is off by default and requires an explicit Apple-linked FutureSelf account, available iCloud, and an in-app backup action. Active health and fitness backup to iCloud is blocked. Other limited data can leave the device for user-requested AI guidance, a default-off Apple Calendar mirror you choose to enable, optional signed-in account services, crash diagnostics, and App Store purchases.
3. Categories of personal information we collect
In the prior 12 months, depending on how you use the app, we may collect the categories below. “Collected” here means information that can be transmitted off your device to us or to a processor we use. Data that stays only on your device, or only in your own Apple iCloud private database, is noted separately.
3.1 Information you provide
- Identifiers and account data. A user ID for authentication. If you sign in with Apple, we may receive your name (we do not request your email from Sign in with Apple). Device identifiers can be used for multi-device conflict resolution when sync is enabled and for App Attest security and abuse prevention. App Attest records associated with the authenticated service user include a device-generated key identifier, public key, replay counter, Apple attestation receipt, environment, validation category, and app build version.
- User content. Reflections, identity statements, goals, plans, journal entries, coaching prompts you type, meal notes, and similar content you author. Connect content can include a person's first name, relationship category, “What you know” portrait facts, a Connection-plan date and selected time, and an optional plan note.
- Voice recordings. Optional audio of your declarations and actions, stored as files on your device. After you explicitly link Apple to create a non-anonymous account, supported recordings can mirror to your Apple iCloud private database (CloudKit) while iCloud is available, not to FutureSelf's Supabase database.
- Purchase information. Subscription status and entitlements via Apple StoreKit. We do not receive your full payment card number.
3.2 Information from your device (with permission)
- Health and fitness data (HealthKit). Only after you grant permission, and only for features you use (for example training context, recovery signals, activity history, sleep, heart-rate variability, rings, and related metrics). The launch contract prohibits HealthKit-derived data from being added to AI prompts. HealthKit data is not used for advertising or sale.
- Location. Only with your permission, for optional outdoor routing or arrival reminders. Route data is intended to stay on your device.
- Microphone. Only when you choose to record. Recording is optional.
- Photos / camera. Only when you choose features that use them (for example meal capture). We do not scrape your photo library in the background.
3.3 Diagnostics
- Crash and performance data. In Release builds, crash reports and limited performance traces may be sent to our diagnostics processor (Sentry) so we can fix bugs. The submitted configuration, payload fields, IP handling, linkage, sampling, and retention must be verified in Sentry before this draft is approved. Diagnostics are not intended for advertising.
3.4 What we do not collect for advertising or tracking
- We do not use advertising identifiers (IDFA) for ads.
- We do not sell personal information.
- We do not “share” personal information for cross-context behavioral advertising as defined by the CCPA/CPRA.
- Product analytics funnels in the app are designed to stay on-device (closed-enum events with no free-text upload).
4. Sources of personal information
- Directly from you (onboarding, reflections, coaching turns, settings)
- Your device and Apple frameworks you authorize (HealthKit, microphone, location, StoreKit, Sign in with Apple, CloudKit, and Calendar / EventKit)
- Our service providers acting on our instructions (see Section 7)
5. How we use personal information
We use personal information for these business purposes:
- Provide the app. Run Self's Process, Coach, Active, Fuel, Connect, Today, recording, and related features.
- Personalize guidance. Build context so Coach and related AI features respond to your situation.
- Authenticate and sync. Sign you in and, if you enable it, sync eligible data.
- Process subscriptions. Confirm entitlements through Apple.
- Secure and improve the service. Prevent abuse, debug crashes, and maintain reliability.
- Comply with law. Respond to lawful requests and enforce our Terms.
- Communicate with you. Respond to support and privacy requests you send us.
We do not use HealthKit data for marketing or advertising.
6. What leaves your device
When a feature requires it, the following may leave your device:
- Private iCloud mirroring. This is off by default. Eligible mirroring requires an explicit Apple-linked FutureSelf account, available iCloud, and an in-app backup action. The private schema contains 15 FutureSelf record types for eligible profile, Self, journal, recording, and account-binding data, including audio assets where you chose to record. The schema also retains a legacy Active record type solely for deletion and export compatibility. New Active health or fitness payloads are prohibited from being written to or restored from iCloud. The remaining eligible mirror stays off pending account-separation testing and counsel approval.
- AI prompts and context. Text you submit to an AI feature, plus the bounded context needed for that request, is sent through our Supabase backend proxy to our AI provider (xAI). This can occur before you link Apple because the app creates an anonymous service identity for authenticated backend calls. When you request an AI opener in Connect, the launch contract sends only the person's first name, relationship category, up to four user-authored “What you know” facts, and the minimum plan details needed for the request. Self identity qualities and HealthKit-derived data are excluded from that Connect payload.
- Apple Calendar mirror. This integration is off by default and writes only after you enable it. For a Connection plan, FutureSelf writes an all-day event into a dedicated
FutureSelfEventKit calendar. Its title contains the person's first name and any selected time; it can also contain your optional plan note and selected date. Apple Calendar may sync that calendar according to your Apple account settings. - Account and sync payloads. If you sign in, selected structured data may sync to our backend (Supabase) under your account.
- Device-security records. After an authenticated service session begins, App Attest can send a one-time challenge response and device-generated key evidence to our Supabase backend. Supabase retains the user-linked key identifier, public key, replay counter, Apple receipt, environment, validation category, and app build version for security and abuse prevention. Challenges expire after about five minutes and are consumed once. These records are restricted to our backend service role and are not used for advertising.
- Diagnostics. Crash and performance data to Sentry in Release builds.
- Nutrition lookups. Generic food queries to public nutrition databases (USDA FoodData Central / Open Food Facts). Those lookups are not intended to include your identity.
Circle and Connection-plan stores remain local sources of truth and do not sync to Supabase or CloudKit. Their selected data leaves only when you explicitly request an AI opener or enable Apple Calendar mirroring.
Voice recording files remain on your device unless you explicitly use an eligible private-iCloud backup path after linking Apple. When mirrored, they go to your Apple iCloud private database rather than FutureSelf's Supabase database. Private-database ownership does not by itself settle Apple's “collected” classification, which remains a counsel and App Store review item.
7. Service providers and third parties
We disclose personal information to providers that process it to operate the requested features. Before this draft is approved, the applicable account terms, retention, training-use, subprocessors, and configuration must be verified:
- Apple. App Store, StoreKit, HealthKit, Sign in with Apple, iCloud/CloudKit, Calendar / EventKit, and device security. A dedicated FutureSelf calendar may sync according to your Apple Calendar settings.
- Supabase. Authentication, optional sync, AI request proxy, App Attest security records, account deletion, and data export functions.
- xAI. AI response generation for Coach and related features.
- Sentry. Crash and performance diagnostics.
- USDA FoodData Central / Open Food Facts. Nutrition reference lookups.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
8. AI guidance and sensitive content
Your AI guide is artificial intelligence. It reflects your own words and supports your goals. It is not a substitute for professional care.
Coach is disclosed as AI at first contact and again where required. Content you write can be intimate (identity, relationships, health themes). We handle it as personal information and process it to provide the service. FutureSelf is behavioral coaching software, not a licensed healthcare provider. A draft Crisis Safety Protocol describes the current internal controls; its public availability and counsel approval must be confirmed before launch. See our Terms of Use for scope limits.
9. Retention
We retain personal information only as long as needed for the purposes above, unless a longer period is required by law.
- On-device content. Remains until you delete it or delete the app (subject to any backups you control).
- Cloud sync / account data. Retained while your account is active. When you delete your account in-app, we cascade deletion of cloud rows tied to your account.
- App Attest security records. User-linked key evidence and Apple receipts are retained while the service account remains active. One-time challenges expire after about five minutes. Deleting the service account cascades deletion of its key and challenge rows.
- AI request processing. Processed to generate a response. Retention by the AI provider is governed by our agreement with that provider; we do not use your content to train a public model under our control.
- Diagnostics. Retained for a limited operational window needed to debug and improve stability.
- Support emails. Retained as needed to resolve your request and for ordinary business records.
10. Your choices and controls
- Permissions. You can revoke Health, Microphone, Location, and similar permissions in iOS Settings.
- Connect AI opener. Selected Circle details leave the device for AI only when you ask Coach to suggest an opener. You can write your own message without making that request.
- Apple Calendar mirror. Mirroring is off by default. You can turn it off in Privacy and Data. While Calendar access remains available, turning it off removes the dedicated FutureSelf calendar and its mirrored events. You can also hide or delete that calendar in Apple Calendar.
- Cloud backup. Eligible private-iCloud backup is off by default and requires an Apple-linked FutureSelf account, available iCloud, and your explicit backup action. Active health and fitness backup to iCloud is blocked. The remaining mirror will not be enabled until account-separation, restore, deletion, unavailable-iCloud, and privacy-review gates pass.
- Export and access. “Export FutureSelf archive” creates a versioned archive with a category manifest and includes supported local records, settings, and binary assets, including full-fidelity Active plans, schedule history, evidence, check-ins, feedback, and sessions. Signed-in export also attempts supported Supabase categories and reports each remote source as included, unavailable, excluded, or failed. Physical-device, large-archive, interruption, and provider-held completeness remain release-verification items. Contact privacy@futureslf.com for an access request covering other information we hold.
- Delete. You can delete your data and account from within the app. The app attempts to remove in-app content, cloud rows we control, and supported private CloudKit records and assets. Release testing must verify complete behavior, including partial cloud failures.
- Subscriptions. Manage or cancel in your Apple Account settings (Settings → [your name] → Subscriptions).
11. California privacy rights (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose, sell, or share
- Access a copy of personal information we hold about you
- Correct inaccurate personal information
- Delete personal information, subject to legal exceptions
- Opt out of the sale or sharing of personal information (we do not sell or share)
- Limit use and disclosure of sensitive personal information in certain cases
- Not be discriminated against for exercising these rights
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We have no actual knowledge of selling or sharing personal information of consumers under 16.
How to exercise rights: email privacy@futureslf.com with the subject “California Privacy Request.” The in-app archive provides the supported categories and per-source statuses described above; use the email path for a request covering other information we hold. We will verify your request using information reasonably related to your account or device use, and respond within the timeframes required by law (generally 45 days, with one permitted extension when reasonably necessary).
Sensitive personal information. Depending on what you write or authorize, we may process health-related or other sensitive themes to provide the service, including reflections you author. The launch contract prohibits HealthKit-derived context from leaving the device in AI prompts. We use this information to provide the features you request, not for advertising.
Notice at collection. Before you write personal content, the app presents a consent notice describing AI disclosure and linking to this policy.
12. Children
FutureSelf is intended for adults age 18 and older. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Companion AI features may not be suitable for some minors. If you believe a child has provided us personal information, contact privacy@futureslf.com and we will take appropriate steps to delete it.
13. Security
We use administrative, technical, and physical safeguards appropriate to the nature of the data, including transport encryption for network traffic, Keychain storage for secrets on device, and access controls on our backend. No method of transmission or storage is perfectly secure. You are responsible for keeping your device and Apple Account secure.
14. International users
FutureSelf is operated from the United States. If you use the app from outside the United States, you understand that your information may be processed in the United States, where laws may differ from those in your country.
15. Crisis resources
FutureSelf is not an emergency service. If you are in crisis or thinking about harming yourself, you are not alone.
Call or text 988 to reach the Suicide and Crisis Lifeline, available 24/7. You can also text HOME to 741741 for the Crisis Text Line.
A draft description of our detection and referral protocol is linked at futureslf.com/safety. Availability of that public URL and counsel approval must be confirmed before launch.
16. Changes
We may update this policy from time to time. We will post the revised policy on this page and update the “Last revised” date. Material changes may also be called out in the app. Continued use after the effective date means you accept the updated policy. We review this policy at least once every 12 months.
17. Contact
- Privacy requests: privacy@futureslf.com
- General support: support@futureslf.com
- Operator: Future Self LLC