Allin Privacy Policy
Effective Date: 31 August 2026 · replaces the version effective 3 September 2025
1. Introduction
This Privacy Policy explains how Allin ("we," "our," or "us") collects, uses, and protects information when you use our mobile application (the "App").
At this stage, Allin processes minimal personal data. The App is designed with user privacy as a priority, and we avoid unnecessary collection or storage of sensitive information.
We comply with applicable data protection regulations, including the General Data Protection Regulation (GDPR) where relevant.
2. Data We Collect
A. Sign-In Information
If you sign in using Apple, we may receive a unique identifier, your name (if shared), and your email address. This is used solely for authentication and account setup.
B. Usage Data
We collect information about how you use the App — including which screens you visit, which audio sessions you play, and check-in activity — tied to a persistent but non-identifying reference to your account, never your name or email. This helps us personalise your experience and understand how the App is used. Exactly which provider receives which of this, and what each one does with it, is described in full in Third-Party Services, below.
C. Check-ins & Reflections
Allin collects what you enter during check-ins and reflection — how you're feeling, what's on your mind, and any notes or journal entries you choose to write. This is sensitive, personal information, and we treat it accordingly.
We encrypt and detach your personal details from what you share, so no third party we work with ever receives your sensitive content linked to who you are — see Third-Party Services, below, for exactly who gets what. What you write is never used for analytics or advertising, and it's included in full when you delete your account (see Your Rights, below).
Your reflections and journal entries are not read by anyone at Allin, and nothing automated analyses them either — they exist solely so you can look back on your own journal. If we ever do study reflection content to help improve Allin, we will only ever look at broad, collective patterns across many people's entries — never by reading what any one person specifically wrote.
3. Data Retention & Security
We've put a lot of care into separating your identity from what you share. Your account details (email, sign-in) are never stored directly alongside your check-ins, journal entries, or beliefs plan — they're only connected through an internal reference used purely for that purpose, and the most sensitive parts of what you write are also encrypted as an extra layer of protection.
We built it this way so that even in the worst case — if someone gained unauthorised access to our systems — what you've shared couldn't be easily traced back to you personally. That separation carries through to how we work with outside providers too: whichever one holds your email or account details is never the same one that holds your check-in content or notes, and none of them ever gets both together (see Third-Party Services, below, for exactly who gets what). It also means deletion is clean: when you delete your account, there's one clear thread to pull, and everything connected to it goes with it completely.
One honest note: we can still reconnect your account to your data ourselves, when you ask us to — for example, to show you or delete everything we hold about you (see Your Rights, below).
4. Your Consent Choices
When you first use Allin, you choose independently whether to allow: reminder notifications, product/usage analytics, and advertising attribution. These are three separate choices, not one bundled setting — you can turn any of them on or off at any time in Settings → Privacy. Turning off analytics stops any further usage data described in this policy from being collected from that point forward.
5. Your Rights
Depending on your location, you may have the right to:
- Access the information we hold about you.
- Request correction or deletion.
- Object to or restrict processing.
- Withdraw consent where applicable.
You can delete your account and all associated data at any time directly in the app (Settings → Delete Account) — no need to contact us. This immediately and permanently deletes your check-ins, beliefs plan, journal entries, and account details from our database, and we ask our other service providers to delete your data where they're able to do so.
For any other rights, or a question about a specific provider, contact us at info@join-allin.com and we will respond within a reasonable timeframe (and within legal requirements).
6. Children's Privacy
Allin is not directed at children under the age of 16. We do not knowingly collect or process data from children. If we learn that a child's information has been inadvertently collected, we will delete it promptly.
7. Third-Party Services
Allin uses a small number of trusted providers to run the app and talk to you — each gets only what it needs to do its job, never more:
- Segment routes basic usage events (like which screen you're on) to the providers below — it doesn't use the data itself.
- Amplitude helps us see how people use Allin, using a reference to your account that's kept separate from your name or email — never the actual words you write.
- Customer.io sends you account and product emails, using your email address only for that, and only if you haven't opted out.
- Meta gets limited ad-attribution data (like whether you installed after clicking one of our ads), only if you've consented to tracking — never anything you've written.
- RevenueCat and Apple process your subscription — nothing more.
- Supabase is our database provider, where the protections described in Data Retention & Security, above, apply.
- Anthropic is the one provider that sees the actual words you write, because interpreting them is its job: matching you to a session, screening for crisis language, composing your plan. Never used for advertising or to build a profile of you, and never used to train its models. This is covered by Anthropic's own Data Processing Addendum, which applies automatically to how they handle this data.
We don't sell your data, and we don't share it for anything beyond running and improving Allin.
8. International Data Transfers
Some of what Allin shows you — including your matched audio session and your personalised beliefs plan — is generated with the help of AI (Anthropic). We use this to interpret what you've written, never to make decisions that have a legal or similarly significant effect on you.
One exception, included because it matters for your safety: if what you write suggests you may be at risk, our systems — including this AI screening — are designed to detect that so we can direct you to appropriate support resources (such as crisis text and phone lines for your region). This is the one case where automated screening actively changes what you see next, and it exists solely to get you help faster.
Some of our service providers, including our database provider (Supabase) and our AI provider (Anthropic), are located outside the UK/EEA. Where this happens, we rely on the EU Standard Contractual Clauses and, for UK data, the UK's International Data Transfer Addendum — the standard legal safeguards for this kind of transfer.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated via in-app notice or email (if available).
10. Contact Information
If you have questions or concerns about this Privacy Policy, please contact us:
Email: info@join-allin.com
Controller: Allin