Trail Worm LLC (“Company,” “we,” “our,” or “us”) operates the Marcus AI: Habit Tracker mobile application (“Marcus AI”) and related services (the “Service”). This Privacy Policy explains what information we collect, what we do with it, who we share it with, how long we keep it, and what choices you have.
By using the Service, you agree to the collection and use of information described here. If you do not agree, please do not use the Service.
This document is part of a three-document set. Please read it together with our Terms of Service and our AI Safety & Chatbot Disclaimer, both available in-app and at the same locations as this Policy.
1. Information We Collect
1.1 Information You Provide
When you create an account or use the Service, you may voluntarily provide:
- Account information. Email address, password (stored only as a hash by Firebase Authentication), and the authentication provider you use (email/password, Google, or Apple).
- Habit data. Habit names, goals (optional), scheduled days, reminder times, optional notes, and check-in records.
- Chat content. Messages, prompts, and text you submit to the AI chatbot, including any AI action proposals you accept, edit, or dismiss.
- Voice recordings. Audio you record for speech-to-text transcription. Audio is sent to OpenAI Whisper for transcription only and is not stored on our servers after the transcription completes (see §3).
- Settings and preferences. Notification preferences, theme preference, AI-action permission toggle, philosopher selection.
- Feedback and support. Any communications you send to us about the Service.
1.2 Chat Content, Conversation State, and AI Memory
When you interact with the AI chatbot, we collect and maintain:
- Your messages and the AI’s generated responses.
- Conversation metadata (titles, timestamps, archive status, message counts, last-message previews, conversation summaries, key-topic lists).
- An “AI memory” — a server-managed store of up to 50 personal facts the AI infers about you across conversations (used to provide continuity).
- A “stable identity” profile — values, motivations, recurring goals, and habit patterns the AI infers about you.
- The state of any AI action proposals (proposed habit, proposed edit, log-checkin) and your response to them.
Chat message content, conversation titles and summaries, key topics, the stable identity profile, and the memory facts are all encrypted at rest in our database using AES-256-GCM (see §4).
Important: You should avoid submitting health records, financial account numbers, government identifiers, passwords, or personal information about other individuals within chatbot conversations.
1.3 Onboarding Data
If you complete the in-app onboarding flow, we collect:
- The goal you select (such as “Build morning routine” or “Reduce stress”).
- The time-context information you provide.
- The philosopher you choose for the introductory chat.
- The transcript of your onboarding chat (limited to a 4-turn cap).
- The list of philosophers we recommend based on your selections, and whether you’ve seen the post-purchase recommended-unlock notification.
This information is used to personalize the experience and the philosophers we recommend, and is stored in a per-user onboarding record alongside your account data.
1.4 Automatically Collected Information
When you use the Service, certain information is collected automatically:
- Device information. Device type, operating system and version, app version, device model.
- Usage data. Feature interactions, screen views, session duration, app foreground/background events.
- Analytics events. Tagged events linked to your account (such as habit creation, check-ins, AI action responses, paywall views, conversation archives). The content of your habits and conversations is never included in analytics events.
- Error data. Crash reports, error messages, and stack traces, with content fields scrubbed before transmission (see §5).
- Timezone. Your device’s timezone, used for accurate habit scheduling, streak computation, and free-tier daily-quota windows.
- Push notification token. Stored locally on your device for the local notification scheduler. We do not transmit your push token to a third-party push server.
- Advertising identifier (optional). If you allow it, our Meta advertising SDK accesses your device’s advertising identifier — the iOS Advertising Identifier (IDFA), only if you permit tracking through the App Tracking Transparency prompt, or the Google Advertising ID (AAID) on Android — to measure the performance of our own app-install advertising. It is not used to build cross-context advertising profiles or to deliver third-party targeted ads inside the Service. See §5 (Meta) and §1.8.
- Background refresh (iOS only, optional). If you install the daily-quote widget on iOS, the operating system may briefly wake the app while it is otherwise suspended so the widget can fetch the next day’s quote. We use Apple’s standard
BGAppRefreshTaskAPI for this; the task runs only with iOS’s permission and only opportunistically. During the refresh, the app makes a single authenticated call to our Cloud Functions to request the day’s quote. For most philosophers the quote is served from a pre-curated public-domain corpus on our servers without contacting OpenAI; for the one philosopher whose quotes are AI-generated (Siddhartha Gautama), the refresh path calls OpenAI on the same terms described in §3. You can disable widget background refresh at any time by removing the widget, or by toggling “Background App Refresh” off for Marcus AI in iOS Settings.
1.5 Audit Log Data
When certain security-sensitive events happen on your account, we record an audit-log entry. The events that produce an audit row are:
- Resetting your AI memory (event type: memory_reset).
- A subscription status change reported by RevenueCat (event type: subscription_change).
- An account deletion request (event type: account_deletion, written both before and after the deletion).
Each audit entry contains: the user identifier, the IP address that initiated the request (best-effort, capped at 64 characters), the user-agent string (capped at 512 characters), the event type, a timestamp, and event-specific metadata. Audit log entries are retained for 180 days and then automatically deleted by a daily scheduled job.
After account deletion the user identifier in remaining audit entries is no longer linked to any active account; the entry persists for the remainder of the 180-day window as a compliance record consistent with GDPR Recital 26 (data that can no longer reasonably be used to identify a person is not personal data).
1.6 Server-Side Operational Data
To operate the Service safely and reliably, we maintain:
- Rate-limit counters. Per-user, per-endpoint request counts in a rolling ~1-hour window. These are deleted as the window rolls forward.
- Free-tier usage counters. Per-user daily counts of how many free chat messages you’ve sent on which local-day. Used to enforce the 3-messages/3-days quota. Stored while your account is active.
- Conversation count. Per-user counts of your active and archived conversations, used to enforce the 500-active and 2,000-total caps. Stored while your account is active.
- Token-usage and cost data. Per-user counters of OpenAI tokens consumed and estimated cost in cents per month. Used to enforce a hard monthly cost ceiling that protects the Service from runaway usage.
1.7 Device Attestation (Firebase App Check)
We use Firebase App Check to verify that requests to our Cloud Functions originate from a real, unmodified installation of our app. On iOS this uses Apple’s App Attest service; on Android it uses Google Play Integrity. The attestation tokens we receive are short-lived and contain no identifying information about you. Apple and Google may receive device-integrity signals from your device as part of their own service operation, governed by their privacy policies; we do not transmit habit content, chat content, or any account identifiers to Apple or Google as part of attestation.
App Check is currently in monitor mode while we verify rollout; enforcement will be enabled after a stable verification rate is observed.
1.8 Information We Do Not Collect
- We do not collect precise geolocation data.
- We do not access your contacts, photos, or camera.
- We do not collect biometric data.
- We do not collect data for targeted advertising and we do not “share” personal information for cross-context behavioral advertising under the California Consumer Privacy Act. The limited advertising-measurement processing described in §5 (Meta) is for measuring the performance of our own app-install advertising, is subject to your App Tracking Transparency choice on iOS, and is not used to build cross-context advertising profiles or to deliver third-party targeted ads inside the Service.
2. How We Use Your Information
We use collected information for the following purposes:
- Providing the Service. Operating the app, generating AI chatbot responses, managing habits and streaks, processing voice transcription, scheduling local notifications, completing subscription purchases, and routing support requests.
- Personalization. Maintaining AI conversation memory, the stable-identity profile, and per-philosopher conversation context to provide relevant and consistent AI interactions; recommending philosophers based on your onboarding selections.
- Security and integrity. Detecting and preventing misuse, fraud, abuse of the AI safety protocols, and unauthorized access; rate-limiting requests; enforcing free-tier quotas and conversation caps; running content moderation on chat messages.
- Service improvement. Analyzing aggregated usage patterns and AI-performance metadata to improve features and reliability. We do not use the content of your habits or conversations for product analytics (see §5).
- Communications. Responding to your support requests; sending Service-related notifications such as habit reminders (which are scheduled locally on your device).
- Legal compliance. Fulfilling legal obligations, responding to lawful requests from authorities, enforcing our Terms of Service, and maintaining audit records of security-sensitive events.
We do not use your personal information for targeted advertising.
3. AI Processing — What We Send to OpenAI
The AI chatbot is powered by OpenAI. When you use the chatbot, the following information is transmitted to OpenAI to generate responses:
- Your chat messages in the current conversation, plus the most recent ~16 messages of conversation history.
- Brief summaries of your most recent conversations (the last 5), so the philosopher can maintain continuity.
- Habit context relevant to the conversation, in plaintext: habit names, goals, scheduled days, reminder times, current and longest streaks, and recent check-in records.
- Up to 50 personal facts (“memory facts”) that the AI has inferred about you over time.
- A stable identity profile of values, motivations, and goals the AI has inferred.
- The selected philosopher persona and the active conversation topic.
Additional, narrower OpenAI calls are made for:
- Voice transcription. Voice recordings are sent to OpenAI Whisper. We do not store the audio on our servers after transcription completes.
- Content moderation. Your chat input and the AI’s output are checked against the OpenAI Moderation API to enforce safety rules. Moderation scores and categories are stored on our servers in a moderation-log collection (not shared with third parties beyond OpenAI itself) for safety and audit purposes.
- Embeddings. When the AI proposes a new habit, we ask OpenAI to compute an embedding of the habit name and goal so we can detect duplicates against your existing habits.
- Title generation and conversation summarization. A small model (gpt-4o-mini) is asked to produce 20-character conversation titles and short summaries of completed conversations.
OpenAI’s commitments, as published by OpenAI at the time of writing:
- API inputs and outputs are not used to train OpenAI’s models.
- API data may be retained by OpenAI for up to 30 days for abuse and misuse monitoring, after which it is deleted.
Encryption nuance. Habit content (names, goals, notes) and chat content are encrypted at rest in our Firestore database (see §4). They are sent plaintext to OpenAI as part of conversation context. The encryption guarantee protects against database breach; it does not prevent OpenAI from receiving your habit and chat content as the API needs that content to generate a useful response.
Your consent. When you accept these legal documents at signup, you expressly consent to the OpenAI transmission described in this section. You can use the habit-tracking features of the Service without ever using the chatbot. If you do not consent to OpenAI transmission, do not use the chatbot.
For more on OpenAI’s data practices, please refer to OpenAI’s published Privacy Policy and API Data Usage Policy.
4. Encryption and Local Caching
We implement client-side, field-level encryption (AES-256-GCM) to protect sensitive user data at rest in our database. Encrypted fields include:
- Habit names, goals, and notes.
- Chat message content.
- Conversation titles, last-message previews, summaries, and key topics.
- AI memory facts and the stable identity profile.
- Memory buckets used by the AI memory system (habits, philosophy, reflections, preferences).
Each user has a unique data-encryption key (DEK), itself encrypted at rest under a master key-encryption key (KEK) stored as a Firebase Functions secret. Encryption and decryption occur on your device or on our Cloud Functions server before data is written to or after it is read from Firestore.
Encryption in transit. All connections between your device and our servers, and between our servers and our subprocessors, use TLS.
On-device cache. The Firebase SDK maintains an offline cache of Firestore data on your device (in a SQLite database) for performance and offline use. This cache contains decrypted copies of the data your account has read. The cache is protected by your operating system’s standard file-protection mechanisms (iOS Keychain / Data Protection; Android Keystore-backed file protection). Uninstalling the app removes the cache.
Home-screen widget cache. If you install one of our optional home-screen widgets (today’s habits, a streak summary, the daily quote, or the habit-consistency heatmap), the app additionally writes a small snapshot of the data the widget needs to a separate on-device location that the widget process can read: an iOS App Group container (group.com.trailworm.marcusai.widgets) on iOS, or an Android EncryptedSharedPreferences store (AES-256-GCM under a key held in the Android Keystore) on Android. The snapshot contains your habit names and today’s check-in counts in decrypted form, your current and longest streaks, per-day check-in history used by the heatmap widget, the day’s quote text and attribution, and (on iOS only) a small authentication envelope — your user ID and short-lived Firebase auth tokens — that the iOS widget background-refresh task uses to fetch the next day’s quote. The widget snapshot is local-only — nothing in it is transmitted to a third party — and is wiped when you sign out of the app or uninstall it.
5. Third-Party Service Providers (Subprocessors)
We rely on the following subprocessors. Each is bound by data-protection terms that limit their use of your data to operating the Service on our behalf.
- OpenAI. AI response generation, voice transcription (Whisper), content moderation, text embeddings, conversation title generation and summarization. Receives chat content, conversation context, habit context, AI memory facts, the stable identity profile, voice audio, and moderation inputs. OpenAI commits not to train on API data and to delete data after up to 30 days.
- Google Firebase / Google Cloud Platform. Authentication (Firebase Auth), database (Firestore), serverless functions (Cloud Functions), device attestation (App Check), Cloud Scheduler for scheduled jobs, and hosting infrastructure. Receives all account, habit, chat, settings, analytics, audit, and operational data. Encrypted-at-rest fields are stored as ciphertext.
- Google Cloud Storage. Holds encrypted daily backups of our Firestore database. Backups are retained for 30 days on a rolling basis and then automatically deleted.
- Apple. When you use Apple Sign-In, Apple verifies your identity and may relay an obfuscated email address (Apple Hide My Email) on your behalf. When you purchase a subscription via the App Store, Apple processes payment and provides a purchase receipt to RevenueCat. Apple App Attest provides device-integrity attestation; we do not send PII to Apple as part of attestation.
- Google. When you use Google Sign-In, Google verifies your identity and shares your email and profile picture (if you grant that scope) with us. When you purchase a subscription via Google Play, Google processes payment and provides a purchase receipt to RevenueCat. Google Play Integrity provides device-integrity attestation; we do not send PII to Google as part of attestation.
- RevenueCat. Subscription and entitlement management. Receives your Firebase user identifier (as the RevenueCat “appUserID”), purchase receipts, subscription status, product identifiers, expiration timestamps, and entitlement state. Sends subscription-change webhooks to our Cloud Functions, which then update the Service.
- PostHog. Product analytics and AI-performance metadata monitoring. Receives event names, screen names, anonymous-then-identified user IDs (your Firebase UID after login), session duration, device model, OS version, app version, philosopher identifier, AI model name, token counts, and estimated cost in cents. Conversation content, habit content, and AI memory content are NOT sent to PostHog. A previous version of the integration used PostHog’s AI wrapper that captured prompt and completion text; that wrapper has been removed and replaced with metadata-only capture.
- Sentry. Crash reporting and error monitoring. Receives error messages, stack traces, device model, OS version, app/bundle version, and your Firebase UID. Content fields are stripped before transmission via an allowlist plus a pre-send scrubber that drops content-shaped keys (habit/conversation/message/content/memory and similar) and truncates long strings.
- Meta Platforms, Inc. (Facebook). Advertising measurement and attribution for our own app-install advertising. Using Meta’s mobile SDK, we share your device’s advertising identifier (the iOS Advertising Identifier (IDFA) on iOS — only if you allow it through the App Tracking Transparency prompt — or the Google Advertising ID on Android) together with a small set of app-event signals: that the app was installed or opened, that an account was registered, and that a subscription was purchased (including the purchase amount and currency). This lets us understand which advertising campaigns lead to installs and subscriptions. We do not send Meta any of your habit, chat, AI-memory, or email content. See §1.8 and the advertising-choices note below.
- Resend. Transactional email delivery for non-authentication Service emails. Receives the recipient’s email address, the message body and subject line, and any subscription metadata included in the email (such as the subscription term, renewal amount and date, and cancellation instructions for an annual-renewal reminder, or the aggregated counts contained in our annual compliance report). Used to send NY General Business Law §527-A annual renewal reminders to annual subscribers, and the annual California Senate Bill 243 §22603 crisis-referral compliance report to our compliance address. Firebase Authentication’s transactional emails (email verification and password reset) continue to be sent through Firebase’s built-in sender and do not pass through Resend.
- Sender.net (operated by Sender UAB). Newsletter delivery for our optional email newsletter — the weekly Marcus AI Stoic letter and occasional product-launch announcements. If you subscribe on our website (trailworm.com or trailworm.com/marcusai), Sender receives the email address you submit, the signup source (which page or form you subscribed from), your newsletter preferences (for example, the weekly letter versus launch news only), and engagement data such as opens, clicks, bounces, and unsubscribes. The newsletter is optional and separate from your Marcus AI account: subscribing is not required to use the Service, and no habit, chat, AI-memory, or account data is sent to Sender. Signups are confirmed by double opt-in, and every email includes an unsubscribe link.
- Expo / Expo Application Services (EAS). Build infrastructure for the mobile app. Receives source code and build-time secrets when we compile new releases. Does not receive runtime user data.
Your advertising choices. On iOS, the App Tracking Transparency prompt (shown once after onboarding) controls whether your advertising identifier is shared with Meta; if you decline — or change it later under Settings → Privacy & Security → Tracking — no advertising identifier is used, and only Apple’s aggregated, non-identifying measurement applies. On Android, you can reset or delete your advertising ID, or opt out of ad personalization, under Settings → Privacy → Ads (or Google → Ads). The advertising-measurement processing described above is used only to measure our own app-install advertising; we do not sell your personal information to any party, and we do not share your personal information for cross-context behavioral advertising. We will provide reasonable advance notice (typically 30 days, where required by law) before adding a material new subprocessor that processes personal data.
Data Processing Addenda (DPAs) and Standard Contractual Clauses are available on request from info@trailworm.com.
6. Data Sharing
We do not sell, rent, or trade your personal information to third parties.
We share your information only:
- With the subprocessors listed in §5, solely to operate the Service.
- For legal compliance. We may disclose information if required to comply with applicable law, regulation, or legal process; respond to lawful requests from government or regulatory authorities; protect the rights, property, or safety of the Company, our users, or the public; or enforce our Terms of Service.
- In a business transfer. If the Company is involved in a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
- With your consent. When you give us explicit consent to share with a specific third party.
We honor opt-out signals from the Global Privacy Control (GPC) specification, where they reach us, and we treat them as a “do not sell or share” request under the California Consumer Privacy Act and similar state laws. Because our app does not sell or share personal information for cross-context advertising, the practical effect of GPC on your account is limited; we still record your preference.
7. Data Retention
We retain information for the periods listed below, except where a longer retention period is required by law:
- Account, habit, chat, conversation, settings, AI memory, and onboarding data — retained while your account is active.
- Analytics events — retained while your account is active. After account deletion, aggregated event records may persist with the user identifier no longer linked to any active account (see §8).
- Audit log entries — 180 days, then deleted by a daily scheduled job. Persists past account deletion within the 180-day window in unlinkable form.
- Daily Firestore backups — 30 days, on a rolling basis, then automatically deleted.
- Voice audio — not persisted by us; OpenAI may retain up to 30 days for abuse monitoring.
- Moderation logs — 180 days for safety review.
- Rate-limit counters — rolling ~1-hour window.
- Free-tier usage and conversation counters — while your account is active.
- Token-usage and cost counters — while your account is active.
After account deletion (see §8), the per-user collections listed in this policy are wiped immediately. Backups containing pre-deletion data age out within 30 days. Audit-log entries persist as described above.
8. Your Rights and How to Delete Your Account
8.1 In-App Account Deletion (Primary Path)
You may delete your account at any time directly from within the app:
- Open Settings.
- Scroll to Delete Account.
- Tap the delete button in the confirmation modal.
The same delete-account flow is reachable from the email-verification screen and the terms-acceptance screen, so you can delete an account that has not yet completed onboarding.
When you confirm deletion, the following user-scoped collections are wiped on our servers immediately: habits, habit logs, chat messages, conversations, user philosopher state, user memory, memory facts, user settings, encryption keys, error logs, moderation logs, subscription status, free-tier usage, conversation counts, user usage counters, daily-quote cache, onboarding state, rate-limit windows, and per-user user document. Your Firebase Authentication account is also deleted.
8.2 Email Fallback
If you cannot access in-app deletion, email info@trailworm.com with the subject line “Data Deletion Request” and the email address associated with your account. We will process such requests within 30 days.
8.3 What Survives Deletion
The following data is intentionally retained after account deletion. None of it can be used to identify you because the user identifier is no longer linked to any active account:
- Audit log entries for the deletion event itself, plus any prior audit entries within the 180-day retention window. Required for our compliance and forensic record. (GDPR Recital 26.)
- Aggregated analytics events for the orphaned identifier. We do not actively re-link these to any new account.
- Encrypted backup snapshots taken before deletion will age out automatically within the 30-day backup retention window.
- OpenAI-side data, which remains subject to OpenAI’s published retention policy (currently up to 30 days).
8.4 Active Subscriptions Are Not Cancelled
Deleting your account does not cancel any active App Store or Google Play subscription. Apple and Google manage your subscription billing; we have no ability to cancel a store-managed subscription on your behalf.
If you have an active subscription when you delete your account, you must separately cancel through:
- Apple App Store: Settings → Apple ID → Subscriptions → Marcus AI: Habit Tracker → Cancel Subscription.
- Google Play Store: Play Store app → Subscriptions → Marcus AI → Cancel Subscription.
The deletion confirmation dialog will warn you when an active subscription is detected and provide a link to the appropriate store settings.
8.5 Other Privacy Rights (GDPR, CCPA, etc.)
In addition to deletion, you may have other rights under your local privacy law. See §9.
9. Your Privacy Rights
Depending on where you live, you may have additional rights under applicable privacy law.
9.1 European Economic Area, United Kingdom, Switzerland (GDPR / UK GDPR / FADP)
If you are in the EEA, UK, or Switzerland you may have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete personal data.
- Erasure (“right to be forgotten”), subject to legal exceptions.
- Restrict processing of your personal data in certain circumstances.
- Portability of your data in a structured, machine-readable format.
- Object to certain processing activities, including direct marketing.
- Withdraw consent, where processing is based on consent (this will not affect prior lawful processing).
- Lodge a complaint with your local data protection authority.
Legal bases for processing. We process your data based on (a) performance of a contract (providing the Service), (b) our legitimate interests (security, fraud prevention, Service improvement), (c) consent (where specifically obtained, such as the OpenAI processing consent at signup), and (d) legal obligation (compliance with applicable law).
Automated decision-making. We do not use your personal data to make significant automated decisions that produce legal or similarly significant effects. AI chatbot responses are generated by OpenAI but are conversational in nature and are not used to take consequential decisions on your behalf without your confirmation.
9.2 California (CCPA / CPRA, including 2026 amendments)
If you are a California resident you have the right to:
- Know the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the third parties to whom we have disclosed it.
- Delete your personal information.
- Correct inaccurate personal information.
- Opt out of sale or sharing of personal information for cross-context behavioral advertising. We do not sell or share personal information for cross-context behavioral advertising.
- Limit use of sensitive personal information. We do not collect sensitive personal information for purposes that would trigger this right.
- Non-discrimination — we will not discriminate against you for exercising your privacy rights.
Categories of personal information collected in the past 12 months:
- Identifiers: email address, Firebase user ID, and — where you allow it — your device advertising identifier (iOS IDFA / Android AAID; see §5).
- Internet or other electronic activity: usage data, chat content (encrypted at rest), voice recordings (transient).
- Geolocation: timezone only (no precise location).
- Inferences: AI-generated conversation summaries, memory facts, the stable identity profile.
Categories of personal information sold or shared: None.
We design our consent and choice flows for symmetry of choice consistent with California’s 2026 CCPA amendments — dismissing a banner is not consent, and we do not use misleading urgency or visual bias.
9.3 Other US States
Residents of other states with comprehensive privacy laws (including, as of 2026, Colorado, Connecticut, Delaware, Iowa, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia) have generally similar rights — access, correct, delete, portability, opt-out of sale/share/profiling — exercisable through the contact channel below. Where state law requires honoring Global Privacy Control (GPC) signals as a universal opt-out, we do so.
9.4 Exercising Your Rights
Email info@trailworm.com with the subject line “Privacy Rights Request” and a description of your request. We may need to verify your identity (for example, by confirming you can receive email at the address tied to your account) before we proceed. We will respond within the time required by applicable law (typically 30 to 45 days), and may extend the period once where permitted with notice to you. If we deny a request, you may appeal the decision by replying to the response.
For the right to delete specifically, the in-app flow described in §8.1 is the fastest path.
10. International Data Transfers
The Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States and other countries where our subprocessors operate. These countries may have data-protection laws that differ from the laws of your jurisdiction.
For users in the EEA, UK, or Switzerland. We rely on the EU-US Data Privacy Framework (DPF) for transfers to subprocessors that are DPF-certified (Firebase / Google Cloud is DPF-certified at the time of writing). Where a subprocessor is not DPF-certified, we rely on the European Commission’s Standard Contractual Clauses (SCCs) plus supplementary measures (encryption in transit; field-level encryption at rest for sensitive data) consistent with the Schrems II judgment of the Court of Justice of the European Union. We will adapt our transfer mechanisms if the DPF is invalidated or modified.
By using the Service, you acknowledge the transfer of your information to the United States and other countries as described in this Privacy Policy, to the extent permitted by applicable law.
11. Data Security
We implement reasonable technical and organizational measures to protect your information, including:
- Encryption in transit. TLS for all client-server and server-to-subprocessor connections.
- Encryption at rest. Field-level AES-256-GCM for sensitive content; Firebase-managed encryption for everything else stored in Firestore.
- Key management. A per-user data-encryption key (DEK), encrypted at rest by a master key-encryption key (KEK) held as a Firebase Functions secret.
- Access controls. Access to user data is restricted on the principle of least privilege.
- Authentication. Firebase Authentication with support for email/password, Google, and Apple sign-in. Generic credential-failure messaging prevents account-existence enumeration.
- Server-side write enforcement. Chat messages and conversation records are written exclusively by our Cloud Functions using the Firebase Admin SDK; clients cannot create them directly.
- Per-user data isolation. Firestore security rules enforce that only the authenticated user can read or modify their own data.
- Device attestation. Firebase App Check (App Attest on iOS, Play Integrity on Android) verifies that requests come from an unmodified installation of our app. Currently in monitor mode pending a stable verification rate; enforcement will follow.
- Rate limiting. Per-user, per-endpoint server-side rate limits.
- Content moderation. OpenAI’s Moderation API runs against chat input and output to detect crisis and harmful content.
- Audit logging. Security-sensitive events (memory reset, subscription change, account deletion) are logged with IP and user-agent for 180 days.
- Crash and error reporting. Errors are reported to Sentry with content fields scrubbed (see §5).
No method of electronic transmission or storage is 100% secure. While we use commercially reasonable measures to protect your information, we cannot guarantee absolute security.
If you become aware of a security vulnerability or unauthorized access to your account, please notify us immediately at info@trailworm.com.
12. Local Notifications
The Service may send local push notifications to remind you of scheduled habits and to nudge you in the evening if any habit remains unchecked at 10:00 PM local time.
These notifications are:
- Generated and scheduled locally on your device.
- Not sent through external push notification servers.
- Controllable through your device’s notification settings and through your in-app notification preference.
We do not use push notifications for marketing or advertising.
13. Children’s Privacy
The Service is intended only for adults aged 18 and over. It is not directed to, and we do not knowingly collect personal information from, anyone under the age of 18 — and in no event from children under the age of 13 (consistent with the Children’s Online Privacy Protection Act (“COPPA”)).
If we become aware that we have collected personal information from a person under the age of 18, we will delete that information and terminate the associated account promptly.
If you are a parent or guardian and believe a minor has provided personal information through the Service, please contact us at info@trailworm.com. We will verify and delete such information promptly.
14. Third-Party Links and Services
The Service may contain links to third-party websites or services (for example, the Apple App Store and Google Play Store cancellation flows linked from our Settings screen). We are not responsible for the privacy practices, content, or security of any third-party service. We encourage you to review the privacy policies of any third-party services you access through or in connection with the Service.
15. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to our practices, the Service, or applicable law.
When we make material changes we will:
- Update the “Effective Date” and “Version” at the top of this Privacy Policy.
- Provide notice through the Service or by other appropriate means.
- Where the change is material, present the updated Privacy Policy in the app and require you to affirmatively accept it before continuing to use the Service. Acceptance is tracked separately for the Privacy Policy, the Terms of Service, and the AI Safety & Chatbot Disclaimer.
If you do not agree with the revised Privacy Policy, you may delete your account using the procedure in §8.
16. Contact Information
For questions, concerns, or requests regarding this Privacy Policy or our data practices:
Trail Worm LLC
- Email: info@trailworm.com
- Phone: (732) 501-6165
- Address: 232 South 3rd Avenue, Highland Park, NJ 08904
For GDPR-related inquiries, you may also contact your local data protection authority.