Reflune - Privacy Policy

Last updated: 3 August 2026

Reflune is a private journaling app. We built it privacy-first. This policy explains what happens to your data.

Your journal entries

Your entries are stored only on your device. We do not have a server that keeps a copy, and we cannot read them. There is no account and no sign-up.

You can delete a single entry from your list of entries, and Settings carries a Delete everything control that removes every entry, the streak built from them, and the settings you chose along the way: your answers about how you journal, your reminder and your cloud reflection setting. Removing Reflune from your device takes your entries with it. Because no copy of them exists anywhere else, deleting on your device is the whole of deletion: there is nothing left to request from us or from anyone else.

Reflune can also ask for Face ID, Touch ID or your device passcode before it opens. That is a lock in front of the app; your entries stay stored on your device exactly as they are either way.

AI reflections

Nothing you write leaves your device unless you ask for a reflection on an entry you wrote, by tapping Reflect, or Go deeper to continue that exchange. Those taps are the only thing that ever sends anything. There is no background upload, nothing is sent when the app opens, and nothing is sent on a timer.

What is sent. The text of that one entry. If you go deeper, the earlier turns of that same exchange go with it, so the reply can build on what you already said. Your answers about why you journal and how you want a reflection to sound travel with it, as two short preference codes rather than anything you typed. Two pseudonymous technical identifiers travel in separate request headers: a random installation identifier and the anonymous app user identifier generated by RevenueCat. They are used for abuse prevention, free-use accounting and a live Plus entitlement check. No name, account, location or contact data is sent. Pseudonymising these identifiers does not mean they are uncollected.

Who processes it. The request goes to a Cloudflare Worker operated for Reflune, which forwards the journal text to the Vercel AI Gateway, which routes it to Anthropic, where the reply is written. Those three organisations are the only parties that handle the text, and they handle it only for as long as it takes to answer you. RevenueCat receives its anonymous app user identifier for the entitlement lookup and does not receive the journal text from Reflune.

What is kept. Every AI request carries a zero data retention instruction, and that is enforced per request rather than merely asked for: the Gateway routes only through providers under a zero-retention agreement, and where none is available the request fails instead of falling back to one that would keep a copy. The Worker writes no log or database copy of your journal text. Nothing you write is used to train AI models. Separately, Cloudflare keeps a free-use state keyed by the installation identifier. Its lifetime-grace marker is retained indefinitely so the same installation cannot receive two additional supposedly lifetime mirrors after inactivity. Its UTC daily bucket rolls over by day, and installation and IP rate-window state expires after 60 seconds. If a reflection cannot be produced under these rules, none comes back, and Reflune says so on the screen and tells you why. Your entry is saved and your writing is unaffected either way.

Reset and deletion. Delete everything removes journal, streak and recovery data from the app, and it also clears the answer you gave about cloud reflections, so the next one asks you again. It does not alter RevenueCat purchase history or reset server abuse and free-use state. Removing and reinstalling the app is not promised to reset identifiers stored by iOS. The indefinitely retained lifetime marker has no automatic inactivity expiry; daily and rate state can roll over or expire without restoring the two lifetime mirrors.

Third parties. Cloudflare, Vercel AI Gateway, Anthropic and RevenueCat process only the data and purpose described above on Reflune's behalf and are bound to provide the same level of protection. We do not permit them to sell it or use the journal text for training or advertising.

Changing your mind. Reflune asks you before the first cloud reflection, and nothing is sent unless you say yes. Your answer is remembered, and Reflune does not ask again on its own. If you say no, nothing is sent. Your entry is saved either way, and no reflection comes back until you change your answer. You can change your answer at any time, in either direction, in Settings under Cloud reflections.

Subscriptions

Reflune Plus is sold through Apple. Payments and billing are handled by Apple; we never see your payment details.

Purchase status is handled by RevenueCat, under an anonymous identifier that RevenueCat generates for the installed app. Reflune sends that identifier to RevenueCat before a deep cloud reflection and before a paid mirror can bypass free limits. It is used to unlock paid features, restore purchases and verify entitlement, and can therefore relate to purchase history. It is not linked by Reflune to a name, an account or contact detail, because Reflune has none of those.

What we don't do

No advertising, no tracking, no analytics that identify you, no selling of data, no third-party trackers.

Contact

Questions about your privacy? Email privacy@reflune.app.