Privacy Policy
Last updated: June 13, 2026
This Privacy Policy explains how AlignAgain Inc. ("Align Again," "we," "us," or "our"), a Delaware corporation located at [CONFIRM registered business address with counsel prior to publication], collects, uses, stores, shares, and protects information about you when you use the Align Again website, mobile applications, and related services (collectively, the "Service").
Align Again is an emotional wellness and mood-tracking platform. Because the Service is built around how you feel, some of the information you share with us is sensitive — in many jurisdictions it is treated as "special category," "sensitive," or health-related personal data. We take that responsibility seriously, and this policy explains exactly what we collect, why, the legal bases we rely on, and the rights you have.
Important: Align Again is a wellness and self-reflection tool. It is not a medical device, and it does not provide medical or mental-health diagnosis or treatment. See our Health Disclaimer.
1. Information We Collect
Information you provide
- Account information — your name, email address, password (stored in hashed form by our authentication provider), and optional profile photo when you create an account, including via Google Sign-In.
- Mood logs — the emotions you record (such as joy, sadness, anger, or fear), their intensity, and the date and time of each check-in.
- Notes and reflections — free-text notes you optionally attach to mood entries or reflection exercises.
- Questionnaire responses — answers you give to onboarding assessments and the Insight Check questionnaire, along with the email address you provide to receive your results.
- Waitlist and marketing sign-ups — the email address you submit to join our waitlist or newsletter.
Information collected automatically
- Device and usage information — device type, operating system, app version, browser type, and how you interact with the Service.
- IP address and technical identifiers — including, where you grant or withdraw consent, your IP address and browser/device user-agent string, which we record as part of our consent audit trail to demonstrate compliance.
- Analytics data — aggregated usage statistics collected through Firebase Analytics (in the app) and Vercel Analytics (on the website, only where you accept analytics cookies via our consent banner).
- Crash and diagnostic data — error reports collected through Firebase Crashlytics to help us diagnose and fix problems.
2. How We Use Your Information
- To provide, maintain, and improve the Service, including your mood history, trends, and personalized insights.
- To generate AI-assisted reflections, summaries, and recommendations (see Section 3).
- To authenticate you and keep your account secure.
- To send transactional emails, such as questionnaire results, weekly insight reports, and account notifications.
- To send marketing emails where you have asked to receive them (you can unsubscribe at any time).
- To understand aggregate usage so we can improve features and fix bugs.
- To detect, prevent, and respond to fraud, abuse, security incidents, and other harmful activity.
- To comply with our legal obligations and enforce our terms.
We do not sell your personal information, and we do not use your mood or emotional-wellness data for advertising or to build advertising profiles.
3. AI Processing and Crisis Detection
Align Again uses artificial intelligence to help you reflect on your moods. When you log a mood or write a note, the content of that note and related mood context may be processed by OpenAI (our AI service provider, acting as our processor) to generate supportive responses, summaries, and personalized suggestions.
- We send only the minimum information needed to generate your response.
- We process this content through OpenAI's API. Under OpenAI's applicable API terms, data submitted via the API is not used to train its models. [CONFIRM current OpenAI data-processing terms / DPA on file before launch]
- Automated processing. The AI generates suggestions and narrative insights automatically. These do not produce legal or similarly significant effects about you, and we do not use them to make automated decisions of that kind within the meaning of Article 22 GDPR. You can disregard AI-generated content at any time.
- Crisis detection. To help keep you safe, our system screens the text you submit for signs of a severe mental-health crisis. If such signs are detected, the Service responds within the app only — for example, by showing supportive content and crisis-helpline information. This screening does not result in any human review of your message by our staff and does not cause us to contact you, emergency services, or any third party. [CONFIRM this remains accurate before launch]
- AI-generated content is for self-reflection only and is not medical or psychological advice. See our Health Disclaimer.
4. Sensitive / Special-Category Data and Your Consent
Mood logs, emotional-state data, notes, and questionnaire responses can reveal information about your mental health. We treat this as sensitive personal data (and as "special category data" under the GDPR and UK GDPR). We process it on the basis of your explicit consent, which you provide when you set up and use the Service, and which you can withdraw at any time. We use this data only to provide the Service to you and never for advertising.
5. How We Share Information and Who Processes It
We do not sell your personal information. We share it only with service providers ("processors") who help us operate the Service, and only as needed. Our key sub-processors are:
- Google LLC (Firebase & Google Cloud Platform) — authentication, database (Cloud Firestore), file storage, hosting, analytics, crash reporting, and push messaging.
- OpenAI, L.L.C. — AI processing of mood notes and context to generate reflections and insights (see Section 3).
- Vercel Inc. — hosting and analytics for our website.
- [CONFIRM email/communications provider] — delivery of transactional and marketing emails.
A current list of sub-processors is available on request at privacy@alignagain.com. We may also disclose information (a) to comply with law, legal process, or enforceable governmental requests; (b) to protect the rights, property, or safety of Align Again, our users, or the public; and (c) in connection with a merger, acquisition, or sale of assets, in which case we will notify you and honor the commitments in this policy.
6. International Data Transfers
Align Again is based in the United States, and your information will be stored and processed in the United States and in other countries where our service providers operate. These countries may have data-protection laws that differ from those in your country.
Where we transfer personal data out of the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs), the UK's International Data Transfer Addendum (IDTA), and the Swiss addendum, as applicable, together with supplementary measures where needed. You may request a copy of the relevant safeguards by contacting us.
7. Where Your Data Is Stored and How We Protect It
Your data is stored on Google Firebase and Google Cloud Platforminfrastructure (Firebase Authentication, Cloud Firestore, and Cloud Storage), with our application backend hosted on Google Cloud Run. Data is encrypted in transit and at rest. We restrict access to personal data to personnel who need it, enforce authenticated, owner-scoped access controls at the database level, use application-layer security (including App Check), and maintain logging and monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Data Breach Notification
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required by applicable law, affected users without undue delay and within the timeframes the law requires (for example, within 72 hours of becoming aware of the breach under the GDPR).
9. How Long We Keep Your Data
We keep personal data only as long as necessary for the purposes described in this policy or as required by law, and we enforce automated retention limits. Our current retention schedule includes: [CONFIRM periods match production configuration]
- Account profile data — retained while your account is active.
- Mood check-in records — retained for approximately 90 days, then automatically deleted.
- AI usage logs — retained for approximately 365 days.
- Error / diagnostic logs — retained for approximately 30 days.
- Questionnaire and waitlist data — retained until you ask us to delete it or it is no longer needed.
- Analytics data — retained in aggregated or de-identified form per our analytics providers' settings.
- Consent records — retained for as long as needed to demonstrate compliance.
When you delete your account, we delete or anonymize your personal data within a reasonable period, except where we must retain it to comply with legal obligations or resolve disputes.
10. Your Rights and Choices
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data (the "right to erasure").
- Receive a copy of your data in a portable, machine-readable format.
- Object to or restrict certain processing.
- Withdraw consent at any time where processing is based on consent (without affecting prior processing).
- Not be discriminated against for exercising your rights.
The Align Again app includes built-in tools to export your data and delete your account and data directly from your profile settings. You can also contact us at privacy@alignagain.com. We will respond within the timeframe required by applicable law. If we cannot verify your identity or your request is excessive, we may decline or charge a reasonable fee as permitted by law. You may also authorize an agent to act on your behalf.
11. Children's Privacy
The Service is not directed to children. We do not knowingly collect personal information from children under 16 in the EEA/UK (or the lower age set by your country, but not below 13) or under 13 in the United States and elsewhere. We do not knowingly collect personal information from children under 13 in violation of the U.S. Children's Online Privacy Protection Act (COPPA). If you believe a child has provided us personal information, contact us at privacy@alignagain.com and we will delete it.
12. EEA, UK, and Switzerland (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, AlignAgain Inc. is the controller of your personal data. We process it under the following legal bases:
- Explicit consent (Art. 9(2)(a)) — for mood logs, notes, and other health-related special-category data, for marketing emails, and for analytics cookies. You may withdraw consent at any time.
- Performance of a contract (Art. 6(1)(b)) — to provide the Service you signed up for.
- Legitimate interests (Art. 6(1)(f)) — to secure, debug, and improve the Service, balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — where we must retain or disclose data by law.
Because we are established outside the EEA and UK, we have appointed representatives under Article 27:
- EU Representative: [CONFIRM name and EU address of appointed Art. 27 representative before launch]
- UK Representative: [CONFIRM name and UK address of appointed UK GDPR representative before launch]
- Data Protection Officer / privacy contact: privacy@alignagain.com
You have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office).
13. United States — California and Other States
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect and how we use it, to request its deletion, to correct inaccurate information, to opt out of the "sale" or "sharing" of personal information, and to limit the use of sensitive personal information. We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we use sensitive personal information (such as mood data) only to provide the Service. We will not discriminate against you for exercising your rights.
Residents of other U.S. states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and others) have similar rights to access, correct, delete, and obtain a portable copy of their data, and to opt out of targeted advertising, sale, and certain profiling. Because mood data is sensitive data under several of these laws, we process it based on your consent. To exercise any of these rights, use the in-app export and deletion tools or contact privacy@alignagain.com.
14. Canada (PIPEDA and Quebec Law 25)
If you are in Canada, we handle your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws, including Quebec's Law 25. We collect, use, and disclose personal information with your knowledge and consent, limit collection to what is necessary, and store it on servers located outside Canada (primarily the United States), which means it may be accessible to authorities in those jurisdictions under their laws. You have the right to access and correct your information and to withdraw consent. Our privacy contact for Canadian inquiries, including the person responsible for personal-information protection under Law 25, is privacy@alignagain.com.
15. Cookies and Similar Technologies
On our website we use a small number of cookies and similar technologies. Strictly necessary cookies are required for the site to function. Analytics cookies (used with Vercel Analytics) are set only if you accept them through our consent banner, and you can change your choice at any time. Our mobile apps use device identifiers and similar technologies for analytics and crash reporting as described above. You can control many of these through your device or browser settings.
16. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by email before the changes take effect. The "Last updated" date at the top of this page shows when this policy was last revised.
17. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
- AlignAgain Inc.
- [CONFIRM registered business address]
- Privacy inquiries: privacy@alignagain.com
- EU Representative (Art. 27): [CONFIRM]
- UK Representative: [CONFIRM]