Privacy Policy
Future Self · Improvement Labs · Last updated: September 13, 2026 · Effective: September 13, 2026
This policy explains what personal data the Future Self app collects, why, who processes it, how long we keep it, and the rights you have. It is written to be readable — no legalese where plain words will do. It covers the app on iOS and Android, its widgets and notifications, this website and our support email.
The short version
- The app works without an email address: you get an anonymous account on first launch and can save it with Apple, Google or an email code later.
- Your own words — your name, life goal, personal line, free-text answers — are stored only in our database. They are never sent to analytics or crash-reporting tools, never used for advertising, and never used to train models.
- No ads, no selling of data, no tracking across other apps or websites, no precise location.
- Our database, analytics and crash reporting run in the EU. Subscription management (RevenueCat) and push relaying (Expo) run in the United States under EU Standard Contractual Clauses.
- You can delete everything yourself, in the app: Profile → Account & subscription → Delete account (or, on the paywall, Privacy choices → Delete my account & data).
1. Who is responsible (controller and contact)
The data controller for Future Self is:
Improvement Labs (sole proprietorship / eenmanszaak)
Van der Poelstraat 57c, 3021 VT Rotterdam, the Netherlands
KVK (Chamber of Commerce): 42039945 · BTW-id (VAT): NL005448561B16
hello@joinfutureself.com
We are established in the Netherlands, so no EU representative under Article 27 GDPR is needed, and we have not appointed a data protection officer (we are not required to). Future Self is not currently offered in the United Kingdom; if we make the app available there, we will update this section first. For any question about this policy or your data, email hello@joinfutureself.com.
Apple and Google are separate controllers for what happens in their stores (your purchases, refunds, store account) and for Sign in with Apple / Google sign-in; their privacy policies apply to that.
2. What we collect, why, and how long we keep it
We collect only what the app needs. The table lists each category, where it comes from, what we use it for, our legal basis under the GDPR, and how long we keep it. "Until deletion" means until you delete your account (section 6). Some categories only apply if you use the related feature.
| Category | Examples | Source | Purpose | Legal basis | Retention |
|---|---|---|---|---|---|
| A. Account | A random account identifier created on first launch (anonymous account); a random installation identifier. If you save your account: the identifier and email address Apple or Google pass to us (Apple may give a "Hide My Email" relay address), or, if you sign in by email code, your email address. | Created by the app; you; Apple; Google | Create your account, keep you signed in, sync your data across devices, restore purchases | Contract (Art. 6(1)(b)) | Until deletion |
| B. Profile and preferences | Optional first name; timezone and language; theme and app icon; notification preferences (how many quotes and affirmations per day, delivery window, quiet hours, streak and trial reminders); widget preferences. | You; your device settings | Address you by name; deliver reminders at the right local time; remember your choices | Contract | Until deletion (widget preferences and your pinned widget line live only on your device) |
| C. Onboarding answers | Your choices from pre-set options: goals, obstacles, motivation level, the traits you want, quote and affirmation topics, age band (or, in some versions, the age you type), gender (where asked), how familiar you are with affirmations and what you believe about them, habits, daily minutes, streak goal, practice modes, what you want to achieve, how you found us, which onboarding version you saw. Free text you choose to write: your life goal, your own affirmation line and, in some versions, short answers about a good or wasted day. | You | Personalise which quotes and affirmations you see and which reminders you get; show your own words back to you (feed, widget) | Contract | Until deletion |
| D. Activity | Saved (favourite) items; today's daily selection; which items you viewed each day; your current and longest streak. | Your use of the app | Saved Quotes, stable daily sets, streaks | Contract | Until deletion |
| E. Device and notification data | Push token, platform (iOS/Android), notification permission status, app version, timezone, language, installation identifier; a record of each notification we sent you (what, when, delivery status). | Your device; our servers; Expo delivery receipts | Deliver the reminders you asked for; avoid repeats; deactivate dead tokens; diagnose delivery problems | Contract; delivery diagnostics on legitimate interests (Art. 6(1)(f)). You control notifications through the OS permission. | Push tokens and device records until deletion (deactivated when you sign out or the OS reports them invalid); the record of each notification sent is deleted after 90 days |
| F. Purchase and membership status | Whether your membership is a trial, active, expired or lifetime; product identifier; expiry date; the purchase receipt or token Apple/Google issue. Passed to us by RevenueCat from Apple/Google. RevenueCat's SDK also receives your account identifier, your IP address and, on iOS, the app-vendor identifier (IDFV) to validate purchases and restore them on a new device. We never receive card numbers or other payment details. | Apple; Google; RevenueCat | Unlock the app; restore purchases; send reminders only to members; trial-ending reminder | Contract; fraud prevention on legitimate interests | Until deletion (Apple, Google and RevenueCat keep their own purchase records under their policies) |
| G. Product analytics (PostHog) | Anonymous events tied to a random installation identifier (not your account): which onboarding step you reached, answered or skipped and which version you saw; screens and paywalls viewed; purchase completed or cancelled (package identifier); content viewed, saved or shared (content identifier); streak count; number of reminders configured; theme or icon chosen; sign-in provider name; plus app version and operating system. We turn off location lookup and instruct PostHog to discard your IP address after receipt. Never free text, names or email addresses — the app strips those before sending. | Your use of the app | Understand which onboarding version works better; find and fix confusing screens; measure whether the app is used | Legitimate interests (Art. 6(1)(f)) — see section 12 | Up to 12 months |
| H. Crash and error reports (Sentry) | For errors inside the app's code: a fixed error label, the area of the app where it happened (for example "notifications" or "sign-in"), the app environment and a timestamp — we strip everything else before sending. If the app crashes at the operating-system level, the Sentry SDK sends a crash report with the technical stack trace, device model, OS version and app version. No crash report contains your name, email, account identifier, IP address, screenshots, screen contents or anything you typed. | Automatic when an error occurs | Find and fix bugs | Legitimate interests | Up to 90 days |
| I. Support | Your email address, the content of your message and anything you choose to share. | You | Answer you; handle rights requests and complaints | Contract; legal obligation for rights requests (Art. 6(1)(c)) | Up to 24 months after the last message |
| J. Website visits | Server logs kept by our hosting provider (IP address, browser, page requested, time). No cookies, no analytics. | Your browser | Serve the site securely; abuse prevention | Legitimate interests | Short-lived logs held by the host |
| K. Security and server logs | IP address, request time, endpoint, response code and user agent in our hosting provider's authentication and server logs. | Automatic | Detect abuse, rate-limit, investigate incidents | Legitimate interests (Art. 6(1)(f)) | Up to 30 days (provider default); sign-in audit entries up to 90 days |
We do not collect your precise location, contacts, photos, microphone, health data from your device, or advertising identifiers. The pre-set onboarding options (including "Improve my mental health" as a goal) describe what you want from the app; we treat them as ordinary personal data about your motivation, not as health data, and we do not use them to infer any condition. Free-text fields can hold anything you type — please avoid entering sensitive information (such as health details) that you would not want stored.
3. What we do not do
- We do not sell or rent personal data, and we do not "share" it for cross-context behavioural advertising.
- We show no ads and use no advertising or attribution SDKs.
- We do not track you across other companies' apps or websites (no advertising identifier, no App Tracking Transparency prompt because there is nothing to ask).
- We do not use your data to train machine-learning models, and we do not send your free text anywhere except our own database and your own device.
- We do not send marketing emails. If we ever want to, we will ask for your consent first.
- We make no decisions about you by automated means that have legal or similarly significant effects. Choosing which quote to show you is content recommendation, nothing more.
4. Legal bases in more detail
Contract (Art. 6(1)(b) GDPR): everything needed to give you the app you asked for — your account, personalisation, reminders, streaks, saved items, purchases and support.
Legitimate interests (Art. 6(1)(f)): pseudonymous product analytics and A/B tests of onboarding copy, crash reporting, delivery diagnostics, security and abuse prevention, and defending legal claims. We have balanced these interests against your rights: the data is pseudonymous, minimised, kept in the EU, never contains your own words, and is never used for advertising. You can object at any time (section 7, section 12).
Legal obligation (Art. 6(1)(c)): answering data-rights requests and keeping the limited records the law requires of a business.
Consent (Art. 6(1)(a)): your operating-system permission for push notifications, which you can withdraw at any time in your device settings. We do not otherwise rely on consent today; if we add something that needs it, we will ask.
5. Service providers, other recipients and international transfers
We share personal data only with the service providers below, which process it on our behalf under data-processing agreements (Article 28 GDPR), and with Apple and Google in their own role as stores and sign-in providers.
| Provider | What it does for us | Data (categories above) | Where the data is processed |
|---|---|---|---|
| Supabase, Inc. (infrastructure on Amazon Web Services) | Database, authentication, server functions and their logs | A–F, K | EU — Ireland (eu-west-1) |
| PostHog, Inc. | Product analytics | G | EU — Germany (PostHog EU Cloud) |
| Functional Software, Inc. (Sentry) | Crash and error reporting (including operating-system-level crash reports) | H | EU — Germany (Sentry EU data region); Functional Software is a U.S. company bound by EU Standard Contractual Clauses for any access from outside the EU |
| RevenueCat, Inc. | Validates purchases with Apple/Google, keeps membership status, restores purchases | A (account identifier), F (incl. purchase receipt, IP address and, on iOS, the IDFV) | United States — EU Standard Contractual Clauses |
| 650 Industries, Inc. (Expo) | Relays push notifications to Apple and Google | E (push token, notification text) | United States — EU–U.S. Data Privacy Framework (as stated by Expo) and Standard Contractual Clauses |
| Apple Inc. / Apple Distribution International Ltd. | App Store and in-app purchases, Sign in with Apple, Apple Push Notification service | A, E, F | Apple's own regions; Apple is an independent controller for the store and sign-in |
| Google LLC / Google Ireland Ltd. | Google Play and Play Billing, Google sign-in, Firebase Cloud Messaging (Android push) | A, E, F | Google's own regions; Google is an independent controller for the store and sign-in |
| Netlify, Inc. | Hosts this website | J | Global content-delivery network (incl. United States) — Standard Contractual Clauses |
| Resend, Inc. | Delivers sign-in code emails when you sign in by email | A (email address) | EU region |
| Cloudflare, Inc. (Turnstile) — only when enabled | Bot protection when a new account is created. This check is currently switched off; when we turn it on, Cloudflare receives the data listed here | IP address, browser and device signals from the sign-up screen (no account data) | Global network — EU–U.S. Data Privacy Framework and Standard Contractual Clauses |
| Development and operations tooling (cloud development environments and AI-assisted coding tools used by our developers, e.g. Cursor, Anthropic) | Building and maintaining the app; may process limited personal data only when we investigate a problem | Any category, minimised and where possible redacted | United States — Standard Contractual Clauses / EU–U.S. Data Privacy Framework where certified; configured for no data retention and no model training |
Other disclosures. We may disclose personal data to professional advisers under confidentiality; to a successor if the business is reorganised or sold (your data stays protected by this policy); or to authorities where the law compels us or it is strictly necessary to protect rights, safety or security. We never allow providers to use your data for their own marketing.
International transfers. Where a provider processes data outside the EU/EEA — RevenueCat, Expo, Netlify and our development tooling in the United States, Cloudflare on its global network (when enabled), and Apple and Google in their global regions — we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) included in their agreements, on the EU–U.S. Data Privacy Framework where the recipient is certified, and on additional safeguards such as encryption in transit and data minimisation (RevenueCat, for example, receives your account identifier, purchase data, IP address and device vendor identifier, never your name or your words). Email us for more detail on the mechanism used for a specific provider.
How we build the app. We build and operate Future Self with modern development tools, including AI-assisted coding tools. These tools help us write and maintain software; they do not make decisions about you, and your personal data is not used to train them.
6. Retention and deletion
We keep your data for as long as your account exists, and for the shorter periods listed in the table for analytics, crash reports and support. Deleting your account — Profile → Account & subscription → Delete account, or Privacy choices → Delete my account & data on the paywall — permanently deletes your account and everything attached to it in our database: profile, onboarding answers and free text, saved items, streaks, notification preferences, device records, notification history and membership status. Deletion is immediate and cannot be undone. Data on your own device (preferences, your pinned widget line) is cleared by the app on deletion or sign-out and is otherwise removed when you delete the app.
Anonymous accounts that were never saved with a sign-in method, never completed onboarding, never made a purchase and have shown no activity for 30 days are deleted automatically in a nightly clean-up. Purchase records remain with Apple, Google and RevenueCat under their own policies and retention obligations. Analytics events and crash reports expire on their own schedule (up to 12 months and 90 days respectively); if you ask, we delete them sooner. We may keep limited records longer where the law requires it (for example for tax or accounting) or to establish, exercise or defend legal claims.
After you delete your account we keep a hashed deletion receipt for 7 days so the app can confirm the deletion succeeded; it contains no personal data. Any encrypted database backups kept by our hosting provider are overwritten within their retention period (up to 7 days). Deleted records may remain in our providers' server logs for the short periods listed in row K.
7. Your rights (GDPR)
Where the GDPR applies, you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate data (most of it you can change yourself in the app);
- erase your data — the fastest way is deleting your account in the app;
- restrict processing in the cases the law provides;
- portability — receive the data you gave us in a structured, commonly used, machine-readable format;
- object to processing based on legitimate interests, including analytics (section 12);
- withdraw consent at any time where processing is based on consent (for push notifications: your device settings), without affecting processing before withdrawal.
How to exercise them. Deletion is in the app. There is currently no in-app export button; for access, a copy or export of your data, correction we cannot do in-app, restriction or objection, email hello@joinfutureself.com. If your account is linked to Apple, Google or an email, we will ask you to confirm control of that sign-in before acting. If your account is anonymous, we have no way to know it is yours from an email alone; we will work with you to identify it (for example from details only you would know), and deleting it in the app is always available without any verification. We respond within one month, extendable by two months for complex requests, and free of charge unless a request is manifestly unfounded or excessive.
Complaints. You can lodge a complaint with a supervisory authority — in the Netherlands the Autoriteit Persoonsgegevens (Postbus 93374, 2509 AJ Den Haag) — or with the authority of the country where you live or work. We would appreciate the chance to help first.
8. Your privacy rights if you live in the United States
Improvement Labs is a small business established in the Netherlands and does not currently meet the thresholds that make it a "business" under the California Consumer Privacy Act or similar state laws. We nevertheless honour the following for all U.S. residents:
- We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months. There is therefore no "Do Not Sell or Share" choice to make, and no need for a Global Privacy Control signal on this website (which sets no tracking cookies).
- We do not use "sensitive personal information" for anything other than providing the service, and we do not profile you in ways that produce legal or similarly significant effects.
- You can know/access the categories and specific pieces of personal information we hold, correct it, delete it and receive it in a portable format, as described in section 7. The categories we collect, their sources, purposes and recipients are set out in sections 2 and 5; we disclose them only to the service providers listed there.
- We will not discriminate against you for exercising these rights. An authorised agent may act for you if we can verify the authorisation.
- If we decline a request, we will say why, and you may appeal by replying to our email; we will answer the appeal within 45 days.
To exercise these rights, email hello@joinfutureself.com with "Privacy request" in the subject line, or delete your account in the app.
9. Children
Future Self is not directed at children under 16, and we do not knowingly collect personal data from anyone under 16. In the Netherlands, 16 is also the age from which a person can consent to online services without a parent. If you are 16 or 17 you may use the app with a parent's or guardian's permission. If you believe a child under 16 has an account, email us and we will delete it. (In the United States, we also comply with the Children's Online Privacy Protection Act by not directing the app at, or knowingly collecting data from, children under 13.)
10. Security
We protect your data with encryption in transit (TLS) between the app, our servers and every provider. Our database and its backups are encrypted at rest (AES-256) by our hosting provider, Supabase, in the EU. Your data is not end-to-end encrypted: our servers need to read your preferences and text to build your notifications and sync your devices, so people and tools with administrative access to our database can technically read it. We limit that access to what operating the app requires, and we do not copy production data into development tools. We further protect your data with database access rules that let each account read and write only its own rows (row-level security); by keeping server-side keys only in server functions, never in the app; by requiring secrets for our internal jobs and webhooks; and by collecting as little as possible in the first place — the most personal thing you give us, your own words, never leaves our database for analytics or crash tooling. On your device, your session and preferences are kept in the app's private storage, protected by your device's passcode and encryption. No online service can guarantee absolute security. If a personal-data breach is likely to put your rights and freedoms at risk, we will notify the Autoriteit Persoonsgegevens within 72 hours where required and tell you without undue delay where the risk is high. If you suspect a problem involving your data, contact us immediately.
11. Push notifications
If you allow notifications, the app registers a push token with our server together with your timezone and preferences. Our server chooses the content and timing within the window and daily limits you set (with quiet hours if you set them) and sends each notification through Expo's push service to Apple or Google, who deliver it to your device. Notifications contain a quote or affirmation, a streak reminder, a reminder before a free trial converts, or occasionally a short message about the app itself — never your name, email or your own words. Each notification carries a content identifier so that tapping it opens the right item.
You can change how many notifications you get and when in Profile → Notifications, and turn them off entirely there or in your device settings at any time. Tokens are deactivated when you sign out or when Apple/Google report them as no longer valid.
12. Analytics and crash reporting — and how to object
We use PostHog (EU) to understand, in aggregate, how the app is used — for example which of a few onboarding versions leads to a better experience — and Sentry (EU) to find crashes. Both start when the app starts, so we can see the onboarding funnel; both are configured to receive pseudonymous data only, as described in rows G and H of the table above. There is currently no in-app switch to turn analytics off. If you object, contact us at hello@joinfutureself.com: we will delete the analytics and crash data linked to your installation identifier and, if you continue using the app, the practical way to prevent new events under that identifier is to delete the account and reinstall the app (which resets the identifier). Crash reporting is anonymous and stays on because we need it to keep the app working. We do not use analytics for advertising, and we do not combine it with data from other companies.
13. Storage on your device, widgets and the website (no cookies)
The app does not use cookies. It stores on your device only what it needs to work: your sign-in session, a random installation identifier, your onboarding progress and preferences, a cache of today's content, your widget settings and pinned line, and — for the widgets — the text they display, which on iOS is shared with the widget through an app group. This storage is strictly necessary for the service you asked for and therefore does not require consent under the ePrivacy rules (Article 5(3) of Directive 2002/58/EC; Article 11.7a of the Dutch Telecommunicatiewet). Widgets read only from this local storage; they do not send data anywhere.
This website (joinfutureself.com) is a set of static pages. It sets no cookies, loads no analytics and no third-party trackers or fonts. Our hosting provider keeps ordinary server logs (row J).
14. Changes to this policy
When this policy changes, we publish the new version here and update the "Last updated" date. If a change is material — for example a new purpose or a new category of provider — we will also tell you in the app before it takes effect and, where the law requires it, ask for your consent.
15. Contact and complaints
Questions, requests or concerns about your privacy: email hello@joinfutureself.com or write to the postal address in section 1. The controller details are in section 1, the supervisory authority in section 7, and the terms that govern the app in the Terms of Service.