Mobile app privacy policy

Effective 11 October 2026

This policy explains how Reloov processes personal data when you use the mobile app. Reloov is designed to keep most private content on your device and to send data off-device only when a feature requires it.

Who is responsible for your data

The data controller is Reloov’s operator, identified in the “Operator and agreement” section of the Terms of Use. Registered office: Boulevard Bischoffsheim 39/4, 1000 Brussels, Belgium. RPM Bruxelles / RPR Brussel. Enterprise number 0775.602.102. VAT BE 0775.602.102.

Privacy contact: [email protected].

Who Reloov is for

Reloov is intended only for adults aged 18 or older. We do not knowingly provide the app to children or knowingly collect their personal data.

Data we process

The data involved depends on the features you choose to use. You do not have to use Chat, attach an image, dictate text, or complete a Test.

  • Account data: Firebase authentication identifier, email address, display name, profile photo, and sign-in provider. Language and app preferences remain local unless a feature expressly states otherwise.

  • Local app data: journal entries, Chat history, Test answers and results, Journey progress, moods, saved affirmations, counters, and preferences stored in the app database on your device.

  • Chat request data: your current message, deliberately selected context, language and optional image. The server supplies recent exchanges and short summaries for continuity. A Firebase identity token authenticates the request to the Reloov API.

  • Dictation data: audio is transcribed using Apple’s on-device speech technology. Reloov keeps the resulting text only when you save or send it; it does not intentionally upload or retain the voice recording.

  • Technical and support data: limited security, request, error, device, and timestamp information needed to authenticate requests, prevent abuse, diagnose failures, or answer a support request.

  • Purchase data, if paid features are offered: product, entitlement, renewal, and transaction status supplied by Apple or Google. Reloov does not receive your full payment-card details.

Local-first storage

Your journal, visible Chat history, Test answers and results, progress, moods and most preferences stay on your device. They do not form a public profile. Chat also uses the limited server context described below; the app does not synchronise full history between devices.

Deleting local data removes this content from the current app installation. It does not necessarily erase copies contained in device or operating-system backups controlled by Apple or Google; those copies follow your backup settings and the provider’s retention rules, and restoring a backup may restore app data.

Sensitive and intimate information

Relationship reflections may reveal information about your emotional life, health, sexuality, beliefs, or other intimate matters. Where this is special-category data under GDPR Article 9, we process it only with your explicit consent. Chat asks for that consent before the first message is sent off-device.

You can withdraw AI-processing consent at any time from the Privacy screen. Withdrawal prevents new Chat requests until you expressly consent again; it does not delete your local Chat history or affect processing already completed lawfully. You may separately delete the relevant local content or your account. Do not use Reloov as a medical or therapy record.

Why we process data and our legal bases

  • To create and secure your account and provide the features you request: performance of our contract with you.

  • To process intimate information in Chat or other chosen features: your explicit consent.

  • To protect Reloov, prevent abuse, troubleshoot, and maintain reliability: our legitimate interests, balanced against your rights.

  • To manage purchases, accounting, tax, legal requests, and disputes: performance of a contract and compliance with legal obligations.

  • To answer support or privacy requests: performance of our contract, legitimate interests, or legal obligations, depending on the request.

How Chat and AI processing work

Reloov clearly identifies Chat as an AI experience. The app sends your current message, selected context, language, optional image and Firebase identity token to the Reloov API. The token authenticates the request and is not sent to the AI model. The server adds recent exchanges and memory summaries, then sends the necessary content to Reloov’s AI provider to generate a reply.

Your visible Chat history stays in the app’s local database. The server retains only the eight latest completed exchanges (messages, replies, selected context and photo identifiers, without image files) and two short AI summaries. Reloov does not use your private Chat, journal, Tests or images to train a general-purpose AI model.

Clearing Chat removes local messages and photos, saved server exchanges and both AI summaries. It does not reset subscription credits or usage. Account deletion removes that context immediately before deleting the identity; a content-free security marker blocks already issued tokens for about one day. Subscription period dates, allowance and usage totals remain while the account exists and are removed with that marker after account deletion.

Cloudflare AI Search may process the current message, a short extract of the preceding user message and the selected topic to retrieve reference passages. These queries are not added to the documentary index. Only relevant passages go to the response model; photos, authentication tokens and full memory summaries are not part of the search query.

AI responses may be inaccurate or inappropriate. Reloov does not use AI to make decisions that produce legal or similarly significant effects about you.

Images and speech

An image you attach to Chat is stored locally with your conversation and sent with that request. Only attach images you have the right to use, and avoid images that identify another person unless you have a lawful reason and their permission.

Speech-to-text is designed to run on the device. Reloov uses the transcription as ordinary text; it does not intentionally send or save an audio file. Operating-system services remain governed by Apple’s or Google’s terms and privacy settings.

Who receives data

We disclose data only when needed for the service you request, security, support, a transaction, or the law. Categories of recipients may include:

  • Google Firebase provides authentication and issues authentication tokens; Apple or Google also receives data when you choose its sign-in service.

  • The Reloov API receives the authentication token and Chat request. Hosting, network, security, and AI processors receive the data needed for their respective role.

  • Apple App Store or Google Play for purchases, subscription status, cancellations, and refunds where paid features are offered.

  • Professional advisers, courts, regulators, or public authorities when legally required or necessary to establish, exercise, or defend legal claims.

No sale and no advertising use

We do not sell your personal data. We do not use your private journal, Chat, Test answers, or attached images for targeted advertising or to build an advertising profile.

International transfers

Some authentication, infrastructure, store, or AI providers may process data outside the European Economic Area. The applicable safeguard depends on the provider and processing location. Where Chapter V GDPR requires a transfer mechanism, Reloov uses an applicable adequacy decision or contractual safeguards such as Standard Contractual Clauses. You may contact us for information about the safeguard applicable to current processing.

How long data is kept

  • Local content remains on your device until you delete it, delete local data, or remove the app.

  • Firebase account data remains while your account exists. In-app account deletion asks Firebase to delete the active identity. Firebase may retain limited backup, fraud-prevention, or security records under its published retention rules, while Reloov removes its subscription-period usage records with the security marker after about one day, except for records required by law.

  • AI request data and technical or security records may be retained by Reloov and its processors only for the time needed to generate and secure the response, investigate a specific failure or abuse, or comply with law. The exact period may vary by data category and processor; we do not claim that every provider operates with immediate or zero retention.

  • Transaction and accounting records may be retained for the period required by Belgian tax, accounting, payment-dispute, and consumer law.

  • Support and rights-request records are kept as long as needed to resolve the request and document compliance.

Your controls and GDPR rights

Local-only content is controlled directly through the app. Because Reloov does not possess that content, we cannot retrieve, correct, export, or restore it for you. For personal data held by Reloov or its processors, and subject to GDPR conditions, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests.

Send requests to [email protected] from the email linked to your account. We may verify your identity and normally respond within one month. You may complain to the Belgian Data Protection Authority at dataprotectionauthority.be or to the authority in your country of residence.

Security

We use measures designed to protect data, including authenticated requests, encryption in transit, access controls, local app sandboxing, data minimization, and provider review. No device or online service can guarantee absolute security. Protect your device passcode and account credentials.

Changes and contact

We may update this policy when the app, providers, or law changes. Material changes will be communicated in the app or by another reasonable method before they take effect where required.

Questions and privacy requests: [email protected]. Reloov, Boulevard Bischoffsheim 39/4, 1000 Brussels, Belgium.