Shalem Privacy Policy
Effective date: May 4, 2026 Last updated: September 17, 2026
This is the privacy policy for Shalem, the iOS, Android, and web application operated by Zan - Zari Labs OÜ (Estonian registry code 17286420), with operating base in Rome, Italy. This policy describes what we collect, what we do not collect, where data lives, who can access it, and what rights you have.
We have written this in plain language. The goal is for you to understand what is happening with your data, not to bury commitments under defined terms. If anything here is unclear, email support@shalemapp.com and we will clarify.
1. The short version
- Reflection content stays out of our servers. When you type or speak something into Shalem to receive a reflection, that input is processed and immediately discarded. It is not retained, not aggregated into training sets, and not shared with model providers for training.
- Journals stay on your device. All journaling is local. There is no cloud sync. We made this choice deliberately, accepting the trade-off that journals do not migrate across devices.
- We collect your email if you give it to us. Signing up for a premium subscription creates a record with your email and subscription status. That is it.
- Anonymous usage events. We track which screens are visited (not what is typed) for product analytics. These are aggregated after 90 days.
- No third-party data sale, ever. We do not sell user data for money and we have no business model that would require us to.
- Advertising measurement. We use limited device- and event-level data — never the content of what you share — to measure whether our marketing campaigns work. See section 5.
The longer version follows.
2. What we collect
Email address. Collected when you create an account. Stored in our database (Supabase, EU region) until you delete your account.
Subscription status. When you start a trial or subscription, RevenueCat records your subscription state (active, cancelled, expired). We use this to grant or revoke access to subscription features.
Generated reflections & practices. The matched story, personalized reflection, and three practices generated during your sessions are stored under your account in Supabase (EU) with row-level security so you can access your reflection history. They are permanently deleted when you delete your account.
Anonymous usage events. Which screens you visit, how long sessions last, what features are used. These events are not tied to your reflection content. After 90 days, individual events are aggregated and de-individualized.
Audio playback metrics. If you use audio narration, we record aggregate playback metrics (duration, completion rate) without tying them to user input.
Device-level information that platform stores require. Apple and Google receive certain technical identifiers as part of distributing the app. We do not control or expand on what they collect — see Apple's and Google's privacy policies for that.
3. What we do not collect
Reflection input. What you share (voice or text) is transmitted in transit to our AI provider (Anthropic) to generate your reflection and is never stored by Shalem. A database trigger enforces this at the infrastructure level by force-nulling those columns on every write, so your input is never persisted regardless of app version.
Journal content. Your journal lives on your device. We never see it. If you uninstall the app or change device, journal content does not migrate, because it never left your device in the first place.
Voice recordings. If you use voice input for a reflection, the audio is transcribed via platform speech recognition and not retained. Voice files are not retained after processing.
Any use of your reflections, journal entries, or shared input for advertising or marketing purposes. Nothing you say to Shalem, and nothing Shalem generates for you, is shared with any advertising platform.
Separately, we use limited device- and event-level data (not the content of what you share) for advertising measurement — see section 5, Advertising Measurement.
4. Subprocessors and Where Data Lives
Under GDPR Article 28, data processing agreements are in place with our trusted subprocessors:
- Supabase: Cloud database and authentication infrastructure hosted in the EU under row-level security. Holds account data, matched stories, reflections, and practices.
- Anthropic: Reflection generation. User input is transmitted in transit to generate the reflection and is never retained by Shalem. Under commercial API terms, customer inputs are not used for model training.
- OpenAI: Embeddings only, used for semantic lookup against our 1,278-text database (not used for model training).
- ElevenLabs: Audio narration for spoken reflections. Audio is generated on request and not retained for model training.
- RevenueCat: In-app subscription receipt validation and billing status management (interfacing with Apple App Store and Google Play).
- AppsFlyer: Mobile attribution and advertising measurement — identifies which marketing campaign led to an app install and reports app events (install, trial, subscription) to connected ad platforms.
- TikTok for Business: Receives install and subscription event data from AppsFlyer, solely to measure and optimize advertising campaigns. TikTok does not receive your shared input, reflections, or journal entries.
5. Advertising Measurement
To measure whether our marketing campaigns are effective, we work with AppsFlyer as our attribution and measurement provider. When you install Shalem after tapping an ad or a shared link, AppsFlyer may share limited information with the advertising platform involved (for example, TikTok for Business), including:
- Device type and operating system
- IP address (used momentarily for matching, not stored by us)
- Advertising identifier (IDFA on iOS, only if you allow tracking; GAID on Android)
- App events: install, trial started, subscription started
We never share what you say to Shalem — your shared input, generated reflections, practices, or journal entries — with any advertising platform. Advertising measurement is limited to the technical events listed above.
On iOS, you will be asked for permission via Apple's App Tracking Transparency prompt before any of this data is shared. You can change your answer at any time in your device's Settings > Privacy & Security > Tracking. On Android, you can limit ad personalization in your device's Google Settings > Ads.
You can object to this processing at any time by emailing support@shalemapp.com with the subject "Advertising Opt-Out."
6. International transfers
Data may be processed in:
- The European Union (Supabase EU — primary storage).
- The United States (Anthropic, OpenAI, ElevenLabs, RevenueCat, AppsFlyer, TikTok for Business, Apple, Google).
All international transfers are protected by Standard Contractual Clauses (SCCs) and Data Processing Agreements. We never sell your data.
7. Legal basis under GDPR
For users in the European Economic Area, we rely on the following GDPR Article 6 lawful bases:
- Contract performance (Article 6(1)(b)) — for processing necessary to provide the service you signed up for, including subscription management, reflection history, and audio narration.
- Legitimate interests (Article 6(1)(f)) — for basic diagnostics and technical stability.
- Consent (Article 6(1)(a)) — granted at account creation to generate personalized reflections. You can withdraw consent at any time by deleting your account.
- Consent (advertising) (Article 6(1)(a)) — where required by law, including for EU/UK/EEA users and for tracking on iOS, we rely on your specific consent, given via Apple's App Tracking Transparency prompt or an in-app consent notice, before sharing device identifiers or app events with advertising platforms. You may withdraw this consent at any time through your device settings, without affecting the lawfulness of processing before withdrawal.
8. Retention
- User input (text/voice): not stored by Shalem at all. Database triggers force-null input columns on write.
- Matched stories, reflections, and practices: stored under row-level security and deleted completely when you delete your account.
- Journal content: lives on your device only. We have no copy.
- Email addresses: retained until you delete your account.
- Subscription records: retained for the duration of the subscription plus the period required by tax and consumer-protection law (typically 7–10 years).
- Anonymous usage events: individual records retained for 90 days, then aggregated.
- Consent records: retained for 3 years after account deletion, as required by law.
When you delete your account, your account, reflections, and activity have been deleted; consent records are kept for 3 years as required by law.
9. Your rights
If you are in the EEA (or in any jurisdiction with comparable data-protection law), you have the following rights:
- Access — to know what we hold about you.
- Rectification — to correct inaccurate data.
- Deletion — to have your data deleted ("right to be forgotten").
- Portability — to receive your data in a portable format.
- Objection — to object to processing based on legitimate interests.
- Restriction — to ask us to limit processing while a dispute is resolved.
- Withdrawal of consent — for processing based on consent.
To exercise any right, email support@shalemapp.com from the address associated with your Shalem account. We respond within 30 days.
10. California residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Categories of personal information collected: Identifiers (email), user-generated content (text input — processed and immediately deleted), inferences (story matches, emotional path data), and technical data (device type, session analytics).
- Categories of third parties: AI service providers (OpenAI, Anthropic, ElevenLabs), cloud infrastructure (Supabase), subscription management (RevenueCat), attribution analytics (AppsFlyer), advertising platforms receiving app-event data via AppsFlyer (TikTok for Business).
- Sale of data: Shalem does not sell your personal information for money.
- Sharing for advertising: Shalem shares limited device and app-event data (see section 5, Advertising Measurement) with our attribution provider AppsFlyer and advertising platforms such as TikTok for Business, to measure and improve our ad campaigns. This may constitute "sharing" under the CPRA. We do not share your shared input, reflections, journal entries, or any other content you create in the app.
- Do Not Sell or Share: You can opt out of this sharing at any time by emailing support@shalemapp.com with the subject "Do Not Sell or Share," or on iOS by declining or disabling tracking permission in your device settings. Once you opt out, we stop sending your device identifier and app events to advertising platforms going forward.
11. Children's privacy
Shalem is rated 13+ on the App Store and is not directed at children. We do not knowingly collect data from anyone under 13. If you believe we have collected data from someone under 13, email support@shalemapp.com and we will delete it.
12. Third-party processors
Current processors:
- Supabase — database and auth infrastructure (EU).
- ElevenLabs — audio generation.
- RevenueCat — subscription state management.
- Apple App Store / Google Play — distribution and payment processing.
- Vercel — web hosting.
- Resend — transactional email delivery.
- AppsFlyer — mobile attribution and advertising measurement.
- TikTok for Business — receives app-event data via AppsFlyer for advertising measurement.
This list is current as of the last updated date above. Changes to the processor list will be reflected in updates to this policy. We notify users of material changes by in-app notice and email to subscribers.
13. Security
- All transit is TLS.
- Database access is keyed and audited.
- Application code is reviewed before deploy.
- The app does not embed third-party SDKs whose behavior we have not vetted.
- We do not have a public bug bounty program at this time, but we welcome responsible disclosure — email support@shalemapp.com with
[SECURITY]in the subject.
14. Breach notification
In the event of a personal-data breach affecting Shalem users, we will notify the relevant supervisory authority and affected users in accordance with GDPR Article 33 and Article 34 timelines. Notification will be issued by email to affected users at the address on file.
15. Changes to this policy
When this policy changes materially, we update the "Last updated" date at the top, post an in-app notice, and email all users with an active account. Non-material changes (typo fixes, clarifications) are made silently with the date updated.
16. Contact for privacy questions
All privacy questions, including requests to exercise GDPR rights, go to:
support@shalemapp.com (subject line: [PRIVACY] for fastest routing)
We do not maintain a separate Data Protection Officer email. Privacy queries land in the same inbox as everything else and are handled with the same priority as any other formal request.
17. Operator details
Shalem is operated by:
Zan - Zari Labs OÜ Estonian Business Registry code: 17286420 Operating base: Rome, Italy Founder: Zarihoun Traore
For formal legal notices, email support@shalemapp.com with [LEGAL] in the subject and we will provide the appropriate registered mailing address for your jurisdiction's requirements.