I AM privacy policy
I AM is Strateal Oy’s daily affirmation app. The areas you choose, your reminders, and the lines you write stay on your device.
Effective · Strateal Oy
Who is responsible
Strateal Oy, a company registered in Finland (Business ID 1821241-5), is the controller of personal data described in this policy. Contact us at hello@strateal.com for privacy questions or requests.
Information stored on your device
I AM works without a Strateal account. It stores your onboarding choice, the areas your daily line is drawn from, a line you pin for the day, lines you write yourself, your reminder times, and whether the line is spoken during breathing sessions. This data stays on your device. Your operating system may include it in device backups, depending on your settings.
The affirmation library and the Neville Goddard quotations are bundled with the app. We do not receive the lines you write, the areas you choose, or a record of your breathing sessions, and we do not use them to build a profile. I AM does not include advertising or behavioural analytics. It does not access your microphone, camera, contacts, precise location, Apple Health, or Health Connect.
Reminders, spoken lines, and permissions
If you enable the bedtime reminder or, with I AM Plus, the morning reminder, I AM asks for notification permission and schedules the reminders locally on your device. Each reminder carries today’s line, including a line you wrote yourself, so it appears as notification text on your lock screen. You can turn reminders off in I AM or revoke permission in your device settings. If you start a free trial of I AM Plus, the app may schedule one local reminder before the trial ends. You can use the app without enabling notifications.
With I AM Plus, the line can be spoken on each breath out. Speech is produced by the text-to-speech engine on your device, provided by Apple, Google, or the engine you have selected, under its own terms. I AM does not send the text to us.
Purchase verification and restoration require an internet connection and use the services described below.
Purchases and RevenueCat
Unbend, Hush, and I AM use RevenueCat to check paid access and restore purchases. When the purchase service connects, including when the app starts, RevenueCat may process an automatically generated app user ID, IP address, app and operating-system version, device information, and purchase or entitlement status. This can happen even if you do not make a purchase.
If you purchase, Apple App Store or Google Play handles payment. The store and RevenueCat process transaction identifiers, product, purchase date, receipts or purchase tokens, and refund or subscription status to validate access. We do not receive your full payment-card details.
RevenueCat provides purchase infrastructure on our behalf. Apple and Google also act as independent controllers for their store accounts, payments, and legal obligations. Read the RevenueCat privacy policy, Apple privacy policy, or Google privacy policy.
When you contact us
We receive your email address, your name if included, the contents of your message, and any files or diagnostic information you choose to send. We use this information to reply, provide support, resolve purchase issues, and handle privacy requests.
Please do not send passwords, full payment-card details, or medical records. We may ask for limited information to verify your identity or locate a purchase before acting on a request.
Why we process data
- Providing a service or taking steps at your request (GDPR Article 6(1)(b)): answering product enquiries, providing support, verifying purchases, and restoring access.
- Legitimate interests (Article 6(1)(f)): keeping our website and services secure, preventing fraud, resolving faults, and managing business correspondence. We consider your rights when relying on these interests.
- Legal obligations (Article 6(1)(c)): records required by accounting, tax, consumer-protection, and other applicable laws.
- Consent (Article 6(1)(a)), where required: optional processing that we explain and ask you to agree to. You can withdraw consent without affecting earlier lawful processing. You can change device permissions in your device settings.
Providers and international transfers
We use Vercel for this website, RevenueCat for mobile purchase infrastructure, and email providers for correspondence. Providers receive the information needed for their services. We may also disclose information to professional advisers, public authorities when legally required, or a successor if our business transfers, subject to applicable safeguards.
Some providers process information outside the European Economic Area, including in the United States. Where a restricted transfer occurs, we rely on an applicable European Commission adequacy decision or appropriate safeguards such as Standard Contractual Clauses, with additional measures where required. Contact us for information about the safeguards relevant to your data or a copy of them.
We do not sell personal data or share it for cross-app targeted advertising.
How long we keep data
Local app preferences and history remain on your device until you clear or delete the app’s data. Device backups may retain copies under your Apple or Google settings. Offloading an app may keep its data.
We retain support correspondence for as long as needed to resolve the enquiry and any related complaint or claim. We keep purchase and entitlement records as needed to provide or restore access and meet legal obligations. We retain accounting records for the period required by law.
Vercel retains website logs for operation and security under its hosting retention settings. We may keep information longer to investigate abuse or establish, exercise, or defend legal claims. We restrict access to information that must be retained rather than using it for unrelated purposes.
Your rights and choices
Under applicable data-protection law, you may request access, correction, erasure, restriction, and a portable copy of your personal data. You may object to processing based on legitimate interests and withdraw consent where processing relies on it. These rights are subject to legal conditions.
Email hello@strateal.com. We normally respond within one month. If a legally permitted extension is needed because of the complexity or number of requests, we will explain it within that first month. See data deletion for app-specific instructions.
You can complain to the Finnish Data Protection Ombudsman or the data-protection authority where you live or work in the EEA.
Children, security, and changes
Our services are intended for a general audience and are not directed at children under 13. A parent or guardian should manage a child’s use of an app and any purchases. We do not knowingly collect personal data from children under 13. Contact us if you believe a child has provided personal data.
We use appropriate technical and organisational measures, including access restrictions and encrypted network connections, to protect the data we process. No method of storage or transmission is completely secure. We do not use your data for decisions based solely on automated processing that produce legal or similarly significant effects.
We update this policy when our practices change. The effective date appears above. We will explain material changes in the affected service where appropriate.