Your privacy is sacred to us. Here is exactly what we collect, why, and how we protect it.
Last updated: July 3, 2026
Short version: FREE HEART collects only what is strictly necessary to run the app. We never sell your data, never serve ads, and never share your personal struggles with third parties for marketing purposes.
1. What we collect
Information you provide
Email address — used for account authentication and password recovery.
Display name (optional) — a name you choose to personalize the app.
Bio (optional, up to 500 characters) — a short free-text statement you may add to your profile (e.g., "Walking in faith, one day at a time"). You may leave this blank or edit it at any time.
Sobriety start date — to calculate your streak and counter.
Prayer and Bible reading minutes — to track your Daily Faith Practice goals.
Sin category / struggle area — the area(s) you choose to work on (e.g., "Lustful Thoughts"). Stored as a category label only — no free-text descriptions.
Daily check-in status — whether you marked a day sober or logged a relapse.
Emergency contacts (optional) — names and phone numbers you may save for crisis moments. Stored only on your device using encrypted secure storage. Never uploaded to our servers.
Reminder push token (optional) — if you turn on reminders, a device push token is stored so we can deliver your notifications. Turn reminders off and it is deleted.
Optional diagnostics — off by default
Nothing below is sent unless you opt in. Crash reporting and analytics are disabled by default and only activate if you enable them — via the optional checkbox at the end of onboarding or in Settings. You can switch them off again at any time.
Crash reports — via Sentry, to fix bugs. Reports include device model, OS version, and a pseudonymous account ID — never your name, email, or struggle details.
Usage events — via PostHog (e.g., "user opened Progress tab"), tied to a pseudonymous account ID. No names, no emails, no ad IDs, no behavioral profiling.
Device type and OS version — for compatibility debugging only.
2. What we do NOT collect
Free-text journal entries or personal notes
Advertising identifiers (IDFA, GAID) — we do not use them
Location data
Contacts or address book
Camera or microphone data
Biometric data of any kind
Social graph or communication metadata
3. Who we share data with
We use a small set of trusted infrastructure providers. We do not sell data to anyone.
Supabase
Our backend database and authentication provider. Your account data and sobriety records are stored in Supabase's cloud infrastructure with row-level security (RLS) so authenticated users can access only their own records. Data is protected in transit and at rest by Supabase's security controls. Supabase Privacy Policy →
PostHog
Limited product analytics. We use PostHog to understand which features are most useful, so we can improve the app. We do not send names, emails, free-text intentions, or struggle labels to PostHog, and session replay plus heatmaps are disabled. PostHog Privacy Policy →
Sentry
Error and crash monitoring (only if you enable it in Settings). When the app crashes, Sentry captures a diagnostic report (stack trace, OS version, app version, pseudonymous account ID). Reports never include your name, email, or struggle details. Sentry Privacy Policy →
Expo
Push notification delivery. If you enable reminders, your device push token is processed by Expo's notification service to deliver them — nothing else is shared. Expo Privacy Policy →
4. How long we keep your data
Active account data — kept for as long as your account exists.
After account deletion — your data is deleted immediately from our active database. Encrypted backups may retain data for up to 30 days before being purged in the normal backup rotation cycle.
Anonymous analytics — retained for 12 months in aggregated form.
5. Legal basis for processing (EU/UK users)
For users in the European Union or United Kingdom, we process your data on the following legal bases:
Performance of contract (GDPR Art. 6(1)(b)) — account email, authentication, and sobriety data necessary to provide the App's core functionality.
Explicit consent (GDPR Art. 9(2)(a)) — recovery and struggle category data is considered "special category data" under GDPR. By creating an account, you provide explicit consent for us to process this data solely for the purpose of providing you with the recovery support features of the App. You may withdraw consent at any time by deleting your account.
Consent (GDPR Art. 6(1)(a)) — crash reports and usage analytics, which are off by default and processed only if you enable them in Settings. Withdraw at any time by switching them off.
6. Your rights
Regardless of where you live, we honor the following rights:
Access — request a copy of all data we hold about you.
Correction — ask us to correct inaccurate data.
Deletion — delete your account at any time via Settings → Delete Account in the app, or via our web form.
Export — request a machine-readable export of your data (JSON format).
Objection — analytics and crash reporting are off by default, and you can switch them on or off at any time in Settings — no email required.
To exercise any right, email us at support@freeheart.app. We will respond within 30 days.
7. Children
FREE HEART is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child under 13 has created an account, please contact us immediately and we will delete the account.
8. Security
Data protected in transit with TLS
Database protected at rest by Supabase security controls
Row-level security ensures users can only access their own records
Passwords are never stored in plain text — hashed via bcrypt
Two-factor authentication available to all users
Sensitive tokens stored in device Secure Store (not AsyncStorage)
9. Changes to this policy
If we make material changes to this policy, we will notify you via in-app notification and update the "Last updated" date at the top of this page. Continued use of FREE HEART after changes take effect constitutes acceptance of the revised policy.
10. Contact
Questions, requests, or concerns about your privacy:
Data controller: Joseph Santamaria (operating as FREE HEART), Costa Rica.