Privacy Policy
Effective date: August 9, 2026
MHtoolkit ("the App") is a free self-reflection tool developed by Bolaji Agunbiade. Your privacy matters deeply to us. This policy explains what data we collect, how we use it, and what rights you have over it.
1. Data We Collect
We collect only the data necessary to provide the App's features. This includes:
- Account information: Email address for people who create an account or sign in. Anonymous sessions require no personal information.
- Mood entries: Mood ratings, notes, and timestamps you submit through the mood tracker.
- Assessment responses: Answers to mental health self-assessments (e.g., PHQ-9, GAD-7).
- Goals, habits, and routines: Goals you set, habit definitions, daily completion history, streaks, cues, tiny steps, and optional reward milestones.
- Planning and focus: Life-plan items, reflections, next steps, time horizons, and focus-session configuration and completion history.
- Reminders: Reminder schedules, timezone, generic delivery history, and an optional browser push subscription. We do not put private journal, mood-note, assessment, goal, habit, or AI content in push notification text.
- Chat history: Messages exchanged with the AI chat feature.
- Journal and library notes: Private writing and notes you save on books or videos.
- Voice recordings and transcripts: Audio recorded during voice support conversations and the resulting transcript, used to provide transcription and AI responses.
- AI personalization context: If you turn on individual context categories, recent moods, mood notes, assessment scores, goals, habits, journal entries, private library notes, and related timestamps may be included with that AI request. Every category is off by default. On iOS, Apple Health summaries require a separate preview and confirmation for each request.
- AI response reports: If you report an AI response, we collect that response, your selected reason, app version, and platform. We do not attach the rest of your conversation or your optional personalization context to the report.
- Apple Health data (iOS only): If you enable Apple Health insights, the App reads only the categories you choose: steps, exercise minutes, workouts, sleep, mindful sessions, and State of Mind. Raw Apple Health samples, dates, source devices, and identifiers stay on your device. If you explicitly choose Apple Health summary in AI Chat, the App shows the exact derived 7-day and 30-day aggregate first and sends it through the MHtoolkit backend to the selected AI provider only after you choose Share once. You can also explicitly include that aggregate in a Visit Brief and choose its recipient through the iOS share sheet. The aggregate payload is not stored in Supabase, automatically shared with accountability partners, or used for analytics, advertising, or marketing. The AI response may reflect the summary and is stored only if you choose to save that chat or report the response.
- Together: Partner invitations, Together-only commitments, check-in dates, comments, fixed support nudges, rewards, and your sharing choices. Together does not automatically include moods, assessments, AI chat, goals, or reflections.
- Anonymous page view analytics: Collected via Vercel Analytics (no cookies, no personal identifiers).
- Campaign attribution: After your first saved check-in, we may store allowlisted labels from an MHtoolkit link, such as source, medium, campaign, content variant, and platform. We do not store the referring URL, advertising identifiers, your mood value, notes, assessments, or AI content with these labels.
- Operational events: For authenticated web and iOS sessions, we may store a fixed event name, the web or iOS source, and a server timestamp when an app error boundary appears or an allowlisted notification step succeeds or fails. These events do not contain journal, chat, assessment, mood, note, tag, title, or prompt values; route URLs; related record IDs; exception messages or stacks; device IDs; email addresses; or arbitrary metadata. We do not record Android operational events or crisis and grounding tool usage events.
2. How Your Data Is Used
Your data is used solely to provide and improve the App's features:
- Displaying your mood history, trends, and progress.
- Showing optional, on-device Apple Health context beside your mood check-ins without claiming that a relationship is causal or diagnostic.
- Generating an optional, non-diagnostic reflection from a derived Apple Health aggregate after you preview and approve that single AI request.
- Powering AI chat conversations and generating affirmations after you consent to AI data sharing in the App.
- Transcribing voice recordings and playing responses aloud on your device.
- Tracking your goals, habits, and streaks.
- Saving life plans, focus sessions, routine templates, and optional reminder schedules.
- Sharing only the accountability counts you turn on and delivering fixed-format partner cheers or reward ideas.
- Showing an active Together partner only the commitments, progress, and notes you choose to share. Changing a sharing control or ending the connection stops that access.
- Providing self-assessment scores and mental health resources.
- Understanding aggregate, anonymous usage patterns to improve the App.
- Measuring aggregate activation and repeat check-in rates by campaign so we can focus on useful, permission-based distribution.
- Reviewing user-reported AI responses for safety and quality.
- Detecting app-boundary and notification reliability problems from the fixed, content-free operational event taxonomy.
We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes. The App contains no ads. Third-party AI sharing is limited to the optional AI features described below and requires in-app consent before data is sent.
3. AI Processing
The App uses third-party AI services to power optional AI features. Before your first AI request, the App asks for permission to send selected data to AI providers through the MHtoolkit backend. If you decline, chat messages, voice recordings/transcripts, and personalized context are not sent for AI processing.
- Google Gemini: Processes standard chat messages, may generate personalized affirmations, and transcribes push-to-talk recordings. It also generates spoken audio from AI response text.
- Anthropic Claude: Handles complex or crisis-related chat interactions.
- OpenAI: Powers live voice transcription and is a fallback for compatible push-to-talk recordings and generated spoken playback.
Data sent to these providers can include the message or audio you submit, the generated transcript, and only the optional context categories you select for that conversation. Journal entries and private library notes are not sent unless you select those categories explicitly. On iOS, an Apple Health aggregate is never part of the reusable full-context choice: you must preview and confirm it for each request. It includes averages and counts only, not raw samples, dates, source devices, or identifiers. We do not intentionally send your email address or account identifiers to AI providers. AI providers process data according to their own data processing terms and privacy policies.
4. Data Storage and Security
- Your data is stored in a PostgreSQL database hosted by Supabase in the EU West (Ireland) region.
- All data is transmitted over HTTPS and encrypted in transit using TLS.
- Data at rest is encrypted by Supabase's infrastructure.
- Row Level Security (RLS) policies ensure that users can only access their own private rows. Accountability partners can call only a database function that returns enabled counts; they cannot select journal entries, AI chat history, assessment scores, or mood notes.
- Growth reports contain cohort counts only. They do not expose user IDs or any mental-health content.
- Anonymous use is assigned a random Supabase Auth user ID without requiring an email address or other direct identifier. On the mobile app, its session credential is stored using the device's protected credential storage.
- Life-plan text, focus sessions, push subscriptions, reminders, and dismissed notice preferences use the same owner-scoped Row Level Security model.
- Together uses separate tables and Row Level Security. A partner cannot query your private mood, assessment, journal, AI chat, goal, or reflection tables through Together.
- Operational events are written directly to Supabase through an authenticated, fixed-input database function. We do not send these events to Sentry or another crash-reporting provider.
5. Third-Party Services
The App relies on the following third-party services:
- Supabase — Database hosting and authentication.
- Vercel — Application hosting and anonymous page view analytics (no cookies, no personal identifiers).
- Google (Gemini API) — AI chat, affirmation generation, push-to-talk transcription, and generated spoken playback of AI response text.
- Anthropic (Claude API) — AI chat for complex interactions.
- OpenAI — Live voice transcription, fallback transcription for compatible push-to-talk recordings, and fallback generated spoken playback.
- Operating-system speech services — Voice responses may use a voice configured on the device if generated playback is unavailable.
- Browser push services — If you explicitly enable background reminders, the push service selected by your browser or operating system delivers a generic encrypted notification payload to that browser installation.
Each service processes data in accordance with its own privacy policy. We encourage you to review their respective policies.
6. Data Retention
- Your data is retained for as long as your account exists or your anonymous session remains active.
- Voice recordings are processed after each turn for transcription and are not permanently stored by MHtoolkit.
- AI provider retention is governed by each provider's data processing terms and privacy policy.
- User-submitted AI response reports are retained for safety review for up to 90 days, unless you delete your data sooner.
- Campaign attribution is retained with your anonymous or signed-in account and is deleted when you delete your data or account.
- Operational events are retained with your authenticated account, included in your export, and removed when you delete your data or account.
- A browser push subscription is retained until you turn it off, delete your data, or the browser reports that the subscription has expired.
- When you delete your data (see Section 7), it is permanently removed from our database.
- Anonymous sessions are not automatically purged. Their data remains available until you delete it from Settings.
7. Your Rights
You have the following rights regarding your data:
- Access: You can view all your data within the App at any time.
- Export: You can export all your data from the Settings page in a portable format.
- Deletion: You can permanently delete all your data or your full account from the Settings page. This action is irreversible.
- Together controls: You can unshare a note, archive a commitment, end a connection, or block a partner. Your own private history remains yours after sharing stops.
- AI consent: You can decline AI data sharing before using AI features, and you can revoke prior AI consent from the Settings page. AI features will ask again before sending data.
- Correction: You can edit or update your entries directly within the App.
If you need assistance exercising any of these rights, please contact us at the email address listed below.
8. Children's Privacy
MHtoolkit is not intended for use by children under the age of 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will promptly delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Effective date" at the top of this page. We encourage you to review this policy periodically. Continued use of the App after changes constitutes acceptance of the updated policy.
10. Contact
If you have any questions or concerns about this Privacy Policy or your data, please contact:
Bolaji Agunbiade
Email: bolajiag10@gmail.com