You’re trusting us with honest, personal writing. This policy explains — in plain language — what we collect, why, who helps us run the app, and how you stay in control.
The short version: your answers and chats stay in your private account; we use them only to power the features you ask for; there are no ads and no tracking; we never sell your data; and you can delete everything in the app.
01Who we are
Aligned Future Self (the “app”) is a personal reflection and habit-coaching app for iPhone, published by Ömer Albayrak, trading as Crystal Fruit Studio (“we”, “us”). We are the controller of the personal information described in this policy.
This policy applies to the app and to this website (omeralbayrak.com/aligned). It explains what we collect, why, who we share it with, how long we keep it and what rights you have. Questions? Write to support@crystalfruitstudio.com.
02Information we collect
We collect only what the app needs to work. The categories are:
| Category | What it includes | Why we need it |
|---|---|---|
| Content you write | Your chosen path, answers to the onboarding questions, your first name (if you provide it), chat messages with “Future You”, evening check-in scores and notes, and which daily actions you complete. | To create your Future Profile, daily plan, chat replies, check-in reflections and progress. |
| Account & identifiers | A random account ID created by Firebase Authentication (anonymous by default). If you choose Sign in with Apple, Apple shares a stable user identifier and, if you allow it, your name and an email address or Apple’s private-relay address. | To keep your data private to you, restore it on a new device and secure the service. |
| Purchase information | Which subscription you hold, its status, dates and store transaction identifiers. We never see your payment card or Apple ID password — Apple processes payments. | To unlock premium features, restore purchases and prevent misuse. |
| Usage & diagnostics | Anonymous product events (for example “finished onboarding” or “completed a task”) without any of your text, app version, device model, iOS version, language, approximate location derived from IP address, crash reports and performance data. | To understand which parts of the app work, fix bugs and improve the experience. |
| Device & security signals | An App Check attestation from Apple (App Attest / DeviceCheck) confirming requests come from the genuine app, and technical data such as IP address in server logs. | To protect the service from abuse and fraud. |
| Settings | Your reminder times, notification permission status, time zone and language. | To schedule reminders and show the right “today”. |
What we do not collect
- Your contacts, photos, microphone, camera, precise location or health-app data.
- The advertising identifier (IDFA). The app contains no ads and does not track you across other companies’ apps or websites.
- Your payment card details.
03How we use information
- Provide the service — generate your profile, daily plans, replies and check-in reflections; store your progress; schedule reminders; manage your subscription. Legal basis (GDPR/UK GDPR): performance of a contract.
- Sensitive content you choose to write — processed to give you the features you ask for. Legal basis: your consent, given when you submit it; you can withdraw it by deleting the content or your account.
- Improve and secure the app — anonymous analytics, crash reporting, abuse prevention and rate limiting. Legal basis: our legitimate interests in a reliable, safe product.
- Comply with the law — tax, accounting and legal requests. Legal basis: legal obligation.
- Communicate with you — replying to support requests you send us.
We do not sell your personal information, do not share it for cross-context behavioral advertising, and do not use it to train our own or third-party AI models.
04AI processing
The app’s intelligent features are powered by a large language model provided by Anthropic (Claude). When you use a feature such as a quiz reflection, your Future Profile, the daily plan, an evening check-in or the Future You chat, our secure backend sends the minimum relevant text (for example your answers, or your profile summary and recent messages) to Anthropic’s API and returns the result to you. Requests are authenticated to your account; no AI provider key is ever stored on your phone.
- Under our agreement with Anthropic’s commercial API terms, content sent through the API is not used to train Anthropic’s models by default.
- We send only what is needed for the task. For example, daily plans use a short summary of your profile and recent progress, not your full quiz answers.
- Prompts and your text are not written to our server logs; logs use a hashed identifier and technical metadata only.
- AI can be wrong or incomplete. Outputs are for personal reflection and productivity only — see the Terms of Use.
06International transfers
Our providers process data primarily in the United States. Your app data is stored in Google Cloud’s North America multi-region (nam5). If you are in the European Economic Area, the United Kingdom, Türkiye or another region with transfer rules, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and our providers’ data-processing terms.
07How long we keep it
- Your content and progress: kept while your account exists so the app works across sessions and devices. When you use Profile → Delete account, we delete your profile, answers, chat, check-ins, plans and account record right away.
- Reset my journey: removes your answers, profile, plans, check-ins and chat but keeps your account and subscription.
- Technical caches (request de-duplication, rate-limit counters): expire automatically within days.
- Analytics and crash data: retained by Google for up to 14 months (analytics) and 90 days (crash reports).
- Purchase records: Apple and RevenueCat keep transaction records as required for accounting, fraud prevention and legal obligations, under their own retention policies.
- Support emails: kept for as long as needed to help you and for a reasonable period afterwards.
08Your rights and choices
Depending on where you live (for example under the GDPR, UK GDPR, Türkiye’s KVKK, or California’s CCPA/CPRA) you may have the right to:
- access the personal information we hold about you and receive a copy;
- correct inaccurate information (you can edit your name in Profile);
- delete your information (in the app, or by email);
- object to or restrict certain processing, and withdraw consent at any time;
- data portability, where applicable;
- not be discriminated against for exercising your rights, and to opt out of any “sale” or “sharing” of personal information — we do neither;
- lodge a complaint with your local data-protection authority.
How to exercise them
- In the app: Profile → Delete account, Reset my journey, Reminders (notification settings), Manage subscription.
- By email: support@crystalfruitstudio.com. We may need to verify that the request comes from you. We respond within 30 days. See also Delete your data.
- Device controls: you can turn off notifications in iOS Settings at any time.
09Security
We protect your information with encryption in transit (TLS) and at rest, per-user access rules so each account can read only its own data, server-side enforcement of subscriptions and limits, App Check to block non-genuine clients, secrets kept out of the app, and minimal logging. No system is perfectly secure, so please avoid including information in your writing that you would not want stored (such as full card numbers or passwords). If we learn of a breach affecting your data we will notify you and regulators as the law requires.
10Children
The app is intended for people aged 13 and over (or the minimum digital-consent age in your country, if higher). It is not directed to children and we do not knowingly collect personal information from them. If you believe a child has provided personal information, contact us and we will delete it.
11Notifications
Reminders are optional. Morning and evening reminders are scheduled on your device using iOS local notifications, and their text is always generic (for example “Future You left you a message.”) so nothing personal appears on your lock screen. If we introduce push notifications sent from our servers, we will ask for your permission, store a device token to deliver them, and update this policy.
12This website
This site is a static website. It sets no cookies and has no advertising or third-party analytics trackers. Its typeface is loaded from Google Fonts, which receives your IP address to serve the font, and our hosting provider (Google Firebase Hosting) processes technical data such as IP address in server logs for security and delivery. If you email us, we use your address only to reply.
13Changes to this policy
We may update this policy as the app evolves. We will change the “Last updated” date and, for material changes, tell you in the app or by another appropriate means before they take effect.
14Contact us
Ömer Albayrak / Crystal Fruit Studio · support@crystalfruitstudio.com. For privacy requests, please put “Privacy” in the subject line.