Privacy Policy
Reflact ("we", "us", or "our") is operated by Hur, a sole proprietorship based in Japan. This Privacy Policy describes what data Reflact collects, how it is used, and with whom it is shared when you use the Reflact iOS application.
1. Data We Collect and Where It Goes
The table below summarizes every category of data and where it is stored or sent.
| Data | Storage | Sent to |
|---|---|---|
| Objectives, habits, tasks, focus sessions, check-ins | Device only | Not sent externally |
| Journal entries (text) & Quiet Draw sketches | Device only | Not sent externally |
| Journal photos (pictures you take of your paper journal) | Device only | Not sent externally |
| Google OAuth tokens | iOS Keychain | Google (token refresh / revoke) |
| Apple Calendar events (habit blocks) | Your iOS calendar | Apple (via your own iCloud account, if enabled) |
| Google Calendar events | Google servers | Google Calendar API (see §3) |
| Location (geofence coordinates) | Device only | Not sent to our servers |
| Place search keywords | Not stored | Google Places API (see §4) |
| Purchase & subscription status | RevenueCat | RevenueCat (see §5) |
| Crash logs / analytics | Not collected | |
2. AI Features
The current version of Reflact contains no active AI features, and no journal or personal text leaves your device.
If AI-assisted features (such as goal coaching or voice reflection) are introduced in a future update, the relevant text or audio will be relayed through our authenticated proxy to an AI provider (such as Anthropic or OpenAI) solely to generate a response, and will not be stored on our servers. This policy and the App Store privacy label will be updated before any such feature ships.
3. Calendar Integrations (Apple & Google)
Apple Calendar. If you enable Apple Calendar sync, Reflact writes habit blocks and focus blocks into a calendar on your device using iOS's calendar framework (expo-calendar). This data lives in your own iOS calendar; if your calendar syncs with iCloud, it is stored in your Apple account under Apple's Privacy Policy. Reflact never reads your existing Apple Calendar events' contents.
Google Calendar. If you connect a Google account, Reflact communicates with the Google Calendar API to:
- Create habit blocks: Sends habit title, time, and recurrence rule to create recurring calendar events.
- Create task events: Sends task title, start time, and end time when you place a task on your calendar.
- Create focus blocks: Sends a "🎯 Focus Time" event when a Pomodoro session starts.
- Read free/busy data: Fetches your busy time slots (not event titles or details) to find open scheduling windows.
OAuth access tokens are stored securely in your device's iOS Keychain (via expo-secure-store) and are never persisted in plain storage. You can connect up to 5 Google accounts. Disconnecting an account from Settings immediately revokes the token with Google. See Google's Privacy Policy.
4. Location Data
If you set a location-based habit trigger, Reflact uses your device's location to detect when you arrive at a specified place.
- Geofencing runs on-device using iOS. The coordinates you set are stored locally and are not sent to our servers.
- When you search for a place in the location picker, the search keyword and your current coordinates are sent to the Google Places API to return results. See Google's Privacy Policy.
- Displaying the map view loads map data from Google Maps; like any map, this sends standard network requests (including your IP address and the displayed region) to Google.
- Background location permission is requested only when you enable a location-based trigger. You can revoke it at any time in iOS Settings.
5. Purchases — RevenueCat
In-app purchases and subscriptions (Reflact Pro) are processed through Apple's App Store. Reflact uses RevenueCat to verify purchase status and manage subscription entitlements. RevenueCat receives your purchase receipt and subscription state under a randomly generated anonymous ID. Your payment details are handled entirely by Apple and are never seen by us or RevenueCat. See RevenueCat's Privacy Policy.
6. Local Storage
All personal data — objectives, habits, journal entries, journal photos, check-ins, focus sessions, settings — is stored locally on your device. We do not operate a backend database. Deleting the app permanently removes all locally stored data.
Camera and photo library access is used solely to let you photograph your paper journal. Photos are saved inside the app's private storage on your device and are never uploaded.
7. Push Notifications
Habit reminders and location-trigger notifications are scheduled locally on your device. We do not operate a remote push-notification server. You can disable notifications at any time in iOS Settings.
8. Analytics, Tracking & Advertising
Reflact does not use any analytics SDK (e.g., Firebase Analytics, Mixpanel) or crash reporting service (e.g., Sentry, Crashlytics). No behavioral or diagnostic data is collected or transmitted. The app contains no over-the-air update client — it does not contact our servers in the background.
- No tracking: We do not track you across other companies' apps or websites, and the app will never show Apple's App Tracking Transparency prompt because there is nothing to ask for.
- No advertising: Reflact contains no ads and no advertising SDKs.
- No sale of data: We do not sell, rent, or trade personal information — yours or anyone's.
9. Website Waitlist
If you join the waitlist on hurcreations.com, we store the email address you submit in order to send launch invitations. It is processed and stored on Cloudflare infrastructure (our hosting processor) and is not shared with any other party or used for any other purpose. We keep waitlist emails only until invitations are complete or you ask us to delete yours — email us at the address below and we will remove it promptly.
10. Children's Privacy
Reflact is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information through the app, please contact us.
11. Your Rights and Data Deletion
Since all personal data is stored locally on your device, you have full control:
- Delete all data: Uninstall the app. All locally stored data is permanently removed.
- Revoke Google Calendar access: Disconnect your account in Settings, or visit Google Account Permissions.
- Disable location tracking: Go to iOS Settings → Reflact → Location → Never.
- Disable notifications: Go to iOS Settings → Reflact → Notifications.
- Manage your subscription: iOS Settings → Apple ID → Subscriptions.
12. International Users
Data controller / business operator: Hur (sole proprietorship, Japan) — contact below. Because Reflact keeps personal data on your device, our server-side processing is limited to the waitlist email you may submit and the anonymous purchase state handled by RevenueCat.
- EU/EEA & UK (GDPR): Where we process personal data, we rely on performance of a contract (operating features you request), consent (waitlist), and legitimate interests (fraud-free purchase verification). You have the rights of access, rectification, erasure, restriction, portability, and objection — exercisable by email. Service providers we use (Apple, Google, RevenueCat, Cloudflare) may process data outside your country under their own safeguards.
- Japan (APPI): Hur handles personal information in accordance with the Act on the Protection of Personal Information; the purposes of use are those described in this policy.
- California: We do not sell or share personal information as defined by the CCPA/CPRA.
13. Changes to This Policy
We may update this Privacy Policy as the app evolves. Material changes will be communicated by updating the "Last updated" date above. Continued use of the app after changes constitutes acceptance of the updated policy.
14. Contact
For privacy-related questions or requests, contact us at:
contact@hurcreations.com
Hur — hurcreations.com
This policy applies to the Reflact iOS application and the hurcreations.com website.