Each clause below has its own 👍/✏️/❓ — mark it, add a one-line note if you want, then hit "Copy my feedback" and paste it back to Claude in chat. Saved in this browser as you go; nothing here is shared automatically between your browser and Isabel's, so each of you copies and sends your own.
↓ Jump straight to the complete, ready-to-paste Privacy Policy & Terms & Conditions — or read the clause-by-clause reasoning below first.
Every clause below quotes that live text exactly, so you can search-and-replace directly on Squarespace. old = what's live today (false, outdated, or just too generic) · new = the proposed replacement, this document. Two items have nothing live to quote — they're gaps, not errors — marked "missing today" instead.
"We may collect anonymized, aggregated information about how the App is used (e.g., session starts, navigation events, audio plays). This helps us improve app performance and user experience."
This wasn't in the earlier draft — found re-checking the whole document against this rejection. What's actually collected is individual, per-event data (every check-in, every audio play, every screen view) tied to a persistent per-account identifier via Segment, forwarded to Amplitude — not "anonymized, aggregated" in any technical sense. It also silently omits that emotional check-in content and subscription events are collected too (covered separately below and in §2C). And even once corrected, "linked to your account" on its own isn't specific enough — say plainly that the link is a non-identifying reference, not your name or email.
"We collect information about how you use the App — including which screens you visit, which audio sessions you play, and check-in activity — tied to a persistent but non-identifying reference to your account, never your name or email. This helps us personalise your experience and understand how the App is used. Exactly which provider receives which of this, and what each one does with it, is described in full in the Third-Party Services section below."
"We do not collect health data, journal entries, or personal reflections at this stage. If this changes in future versions, we will update this Policy and seek additional consent."
Journaling, reflections, and check-in notes are a current, live feature — not something planned for later. This is the clearest of the four false statements, and the one most likely to have triggered the rejection on its own.
"Allin collects what you enter during check-ins and reflection — how you're feeling, what's on your mind, and any notes or journal entries you choose to write. This is sensitive, personal information, and we treat it accordingly.
We encrypt and detach your personal details from what you share, so no third party we work with ever receives your sensitive content linked to who you are — see Third-Party Services, below, for exactly who gets what. What you write is never used for analytics or advertising, and it's included in full when you delete your account (see Your Rights, below).
Your reflections and journal entries are not read by anyone at Allin, and nothing automated analyses them either — they exist solely so you can look back on your own journal. If we ever do study reflection content to help improve Allin, we will only ever look at broad, collective patterns across many people's entries — never by reading what any one person specifically wrote."
"Sign-in data is retained only for as long as your account is active. Basic usage analytics may be stored in aggregated form. We use industry-standard safeguards, such as encrypted storage and access controls, to protect any information processed."
Not false, exactly — deceptively generic. "Encrypted storage and access controls" was true only in the trivial infrastructure sense (Supabase encrypts its disks) when this was written in September. It's now true in a much more specific, meaningful way that's actually worth telling users about, rather than leaving them with the same boilerplate a policy template would have said before any of this was built.
"We've put a lot of care into separating your identity from what you share. Your account details (email, sign-in) are never stored directly alongside your check-ins, journal entries, or beliefs plan — they're only connected through an internal reference used purely for that purpose, and the most sensitive parts of what you write are also encrypted as an extra layer of protection.
We built it this way so that even in the worst case — if someone gained unauthorised access to our systems — what you've shared couldn't be easily traced back to you personally. That separation carries through to how we work with outside providers too: whichever one holds your email or account details is never the same one that holds your check-in content or notes, and none of them ever gets both together (see Third-Party Services, below, for exactly who gets what). It also means deletion is clean: when you delete your account, there's one clear thread to pull, and everything connected to it goes with it completely.
One honest note: we can still reconnect your account to your data ourselves, when you ask us to — for example, to show you or delete everything we hold about you (see Your Rights, below)."
Granular, independent consent (reminders / analytics / advertising, not one bundled toggle) is built and shipping in v2.3. A privacy policy that stays silent about real consent controls a user already has, in-app, is itself a form of the same problem this whole document exists to fix — not false, but incomplete in a way that undersells the actual care taken.
"When you first use Allin, you choose independently whether to allow: reminder notifications, product/usage analytics, and advertising attribution. These are three separate choices, not one bundled setting — you can turn any of them on or off at any time in Settings → Privacy. Turning off analytics stops any further usage data described in this policy from being collected from that point forward."
"To exercise these rights, contact us at info@join-allin.com. We will respond within a reasonable timeframe (and within legal requirements)."
Not false, but incomplete in a way that materially undersells what's actually available: this reads as though every request means emailing and waiting, when in-app self-service deletion is built and confirmed live, and reaches further than just our own database. The earlier draft flagged this as "worth adding a line once it's confirmed live" — it's now confirmed, so this promotes it from a suggestion to the actual replacement text.
"You can delete your account and all associated data at any time directly in the app (Settings → Delete Account) — no need to contact us. This immediately and permanently deletes your check-ins, beliefs plan, journal entries, and account details from our database. As part of the same request, we also ask our analytics provider (Amplitude) and our email provider (Customer.io) to delete your data. We're still working to extend this to every provider we use (Segment does not currently offer us a way to do this) — say so plainly rather than imply full coverage.
For any other rights — access, correction, objection, or a question about a specific provider — contact us at info@join-allin.com and we will respond within a reasonable timeframe (and within legal requirements)."
"If we engage third-party processors (e.g., analytics, AI providers, cloud hosting), they will only act under our instructions and with safeguards required by law. Currently, Allin does not actively share personal data with third parties. If future integrations (e.g., analytics, push notifications, subscriptions) require third-party services, we will update this Policy and provide details of the processors used."
Found re-checking the whole document, not in the earlier draft: the entire section is written in hypothetical future tense ("if we engage," "if future integrations require") for processors that are live today — Segment, Amplitude, Customer.io, Meta, RevenueCat, Supabase, and Anthropic all already receive data. The "does not actively share" sentence is the specific line the earlier draft caught; the surrounding tense needs the same fix so the two don't contradict each other once one is corrected and the other isn't. Beyond tense: every bullet now says specifically how what it receives is protected or limited, not just what it is — a name and a purpose alone leaves out exactly the detail ("is it anonymised? does it get my email?") that makes this read as thought-through rather than a compliance list.
"Allin uses a small number of trusted providers to run the app and talk to you — each gets only what it needs to do its job, never more:
• Segment routes basic usage events (like which screen you're on) to the providers below — it doesn't use the data itself.
• Amplitude helps us see how people use Allin, using a reference to your account that's kept separate from your name or email — never the actual words you write.
• Customer.io sends you account and product emails, using your email address only for that, and only if you haven't opted out.
• Meta gets limited ad-attribution data (like whether you installed after clicking one of our ads), only if you've consented to tracking — never anything you've written.
• RevenueCat and Apple process your subscription — nothing more.
• Supabase is our database provider — where the protections described in Data Retention & Security, above, apply.
• Anthropic is the one provider that sees the actual words you write, because interpreting them is its job: matching you to a session, screening for crisis language, composing your plan. Never used for advertising or to build a profile of you, and never used to train its models. Don't publish this exact bullet until a signed DPA with Anthropic is in place — see the table at the bottom.
We don't sell your data, and we don't share it for anything beyond running and improving Allin."
"If personalization or recommendations are provided using automated decision-making or AI, we will explain this clearly in-app. If any processing involves storage or services outside your region, we will ensure that adequate safeguards are in place (e.g., Standard Contractual Clauses under GDPR)."
Also found re-checking the whole document. First sentence is a live, unmet promise: Anthropic-powered recommendations and plan composition are live today, and none of it is explained in-app — there's no in-app AI disclosure screen at all right now. Second sentence conditionally references safeguards ("if... we will ensure") for something that's already happening — Supabase is US-hosted today, so this needs to be a factual present-tense statement, not a future conditional, and it needs a real legal answer for what safeguard mechanism is actually in place, not just an assumed one.
"Some of what Allin shows you — including your matched audio session and your personalised beliefs plan — is generated with the help of AI (Anthropic). We use this to interpret what you've written, never to make decisions that have a legal or similarly significant effect on you.
One exception, included because it matters for your safety: if what you write suggests you may be at risk, our systems — including this AI screening — are designed to detect that so we can direct you to appropriate support resources (such as crisis text and phone lines for your region). This is the one case where automated screening actively changes what you see next, and it exists solely to get you help faster.
Some of our service providers, including our database provider (Supabase) and our AI provider (Anthropic), are located outside the UK/EEA. Needs Marie/legal to confirm the actual transfer-safeguard mechanism in place (SCCs or otherwise) before this sentence is finalised — don't just restate the old conditional language as if it were confirmed."
Separate product gap, not just a copy fix: the live policy's promise to "explain this clearly in-app" is a real commitment worth keeping, not just removing. Worth a short in-app AI-disclosure note (e.g. on the plan/recommendation screen) as its own small piece of work — flagging here so it doesn't get lost once the policy wording itself is fixed.
"Users may submit personal notes, reflections, or other content in future versions of the App."
Same class of issue as the privacy policy: journaling, reflections, and notes are a current, live feature (the reflection step after every session), not something planned for later. The legal text was written before this shipped and never updated.
"You may submit personal notes, reflections, or other content while using the App. By submitting content, you grant Allin a non-exclusive, worldwide, royalty-free license to use, store, and process it in order to provide and improve the service."
"The App may rely on third-party services (such as Apple Sign-In, analytics, and subscription management)."
Lower severity than everything above — this is a general disclosure clause, not an affirmative false claim, and hedged with "may." Worth aligning to the same named provider list as the privacy policy once that's updated, so the two documents agree with each other rather than one being specific and one vague.
"The App relies on third-party services, including Apple Sign-In, Segment, Amplitude, Customer.io, Meta, RevenueCat, Supabase, and Anthropic — see our Privacy Policy for what each one does."
Checked every remaining clause in both documents against current reality. These are accurate today and need no change — listed explicitly so nothing looks like it silently vanished when the sections above are edited.
| Clause | Where | Why it's fine as-is |
|---|---|---|
| Medical disclaimer ("not intended to diagnose, treat, cure, or prevent") | Terms, Key Disclaimers | Still true — Allin is a wellness app, not a medical device. No change. |
| Crisis-line guidance (999/911, "not medical advice") | Terms, Key Disclaimers | Still true, and now backed by more crisis-safety work in-app (UK Shout 85258 added, two routing bugs fixed) than when this was written — the policy undersells current safety work if anything. |
| Subscription auto-renewal, Apple refund policy | Terms, Subscriptions | Matches how RevenueCat/StoreKit actually works today. No change. |
| "AI-generated outputs may not always be accurate or appropriate" | Terms, Liability | Already correctly hedged — this is the one place in either document that already acknowledges AI is involved, even though the Privacy Policy currently doesn't. |
| Liability limitation, "as is" / "as available" | Terms, Liability | Standard, unaffected by anything found this session. No change. |
| Governing law — England & Wales | Terms, Governing Law | Unaffected. No change. |
| Age requirement — 16+, parental consent under 18 | Terms, top; Privacy Policy §5 | Now more true than when written — an age gate (self-declared birthdate, hard-block under-16) was decided and built 2026-08-24, so this is an enforced fact now, not just a stated policy. |
| Sign-in data (Apple ID, name if shared, email) | Privacy Policy §2A | Matches the current Apple Sign-In implementation exactly. No change. |
| Age gate mechanism | Privacy Policy §5 | Verified specific: a self-declared birthdate at signup, hard-block under-16 — and only the pass/fail result is stored, never the birthdate itself (data minimisation). Existing "not directed at children under 16" wording already covers this; no wording change needed, just noting the mechanism is real and specific now. |
| Item | Status |
|---|---|
| Signed DPA with Anthropic | Open — needed before the Anthropic bullet in §6 can be published as final wording, not the bracketed placeholder |
| Transfer-safeguard mechanism (§7) confirmed for real | Open — needs Marie/legal to say what's actually in place, not restate the old assumption |
| In-app AI-disclosure note | Not started — a small product item, not a copy fix; keeps the live promise in §7 rather than just deleting it |
| Isabel + Marie sign-off on all replacement copy above | Pending — standard rule, this is user-facing legal copy |
| Publish to Squarespace | Needs you/Isabel — no Squarespace access from here |
| Amplitude no longer receives email | Done — fixed 2026-08-16, re-verified against AnalyticsClient.swift directly, already reflected in §6's replacement text above |
| Age gate (16+, hard-block under-16) | Done — decided + built 2026-08-24, already reflected in the "kept as-is" table above |
Everything above, assembled into the two complete documents. Sections not mentioned above are carried over word-for-word from the live pages — nothing invented, nothing paraphrased. Two spots are held back with a clear callout rather than published as final wording — search for "HOLD" if you want to jump straight to them.
This Privacy Policy explains how Allin ("we," "our," or "us") collects, uses, and protects information when you use our mobile application (the "App").
At this stage, Allin processes minimal personal data. The App is designed with user privacy as a priority, and we avoid unnecessary collection or storage of sensitive information.
We comply with applicable data protection regulations, including the General Data Protection Regulation (GDPR) where relevant.
A. Sign-In Information
If you sign in using Apple, we may receive a unique identifier, your name (if shared), and your email address. This is used solely for authentication and account setup.
B. Usage Data
We collect information about how you use the App — including which screens you visit, which audio sessions you play, and check-in activity — tied to a persistent but non-identifying reference to your account, never your name or email. This helps us personalise your experience and understand how the App is used. Exactly which provider receives which of this, and what each one does with it, is described in full in Third-Party Services, below.
C. Check-ins & Reflections
Allin collects what you enter during check-ins and reflection — how you're feeling, what's on your mind, and any notes or journal entries you choose to write. This is sensitive, personal information, and we treat it accordingly.
We encrypt and detach your personal details from what you share, so no third party we work with ever receives your sensitive content linked to who you are — see Third-Party Services, below, for exactly who gets what. What you write is never used for analytics or advertising, and it's included in full when you delete your account (see Your Rights, below).
Your reflections and journal entries are not read by anyone at Allin, and nothing automated analyses them either — they exist solely so you can look back on your own journal. If we ever do study reflection content to help improve Allin, we will only ever look at broad, collective patterns across many people's entries — never by reading what any one person specifically wrote.
We've put a lot of care into separating your identity from what you share. Your account details (email, sign-in) are never stored directly alongside your check-ins, journal entries, or beliefs plan — they're only connected through an internal reference used purely for that purpose, and the most sensitive parts of what you write are also encrypted as an extra layer of protection.
We built it this way so that even in the worst case — if someone gained unauthorised access to our systems — what you've shared couldn't be easily traced back to you personally. That separation carries through to how we work with outside providers too: whichever one holds your email or account details is never the same one that holds your check-in content or notes, and none of them ever gets both together (see Third-Party Services, below, for exactly who gets what). It also means deletion is clean: when you delete your account, there's one clear thread to pull, and everything connected to it goes with it completely.
One honest note: we can still reconnect your account to your data ourselves, when you ask us to — for example, to show you or delete everything we hold about you (see Your Rights, below).
When you first use Allin, you choose independently whether to allow: reminder notifications, product/usage analytics, and advertising attribution. These are three separate choices, not one bundled setting — you can turn any of them on or off at any time in Settings → Privacy. Turning off analytics stops any further usage data described in this policy from being collected from that point forward.
Depending on your location, you may have the right to:
You can delete your account and all associated data at any time directly in the app (Settings → Delete Account) — no need to contact us. This immediately and permanently deletes your check-ins, beliefs plan, journal entries, and account details from our database, and we ask our other service providers to delete your data where they're able to do so.
For any other rights, or a question about a specific provider, contact us at info@join-allin.com and we will respond within a reasonable timeframe (and within legal requirements).
Allin is not directed at children under the age of 16. We do not knowingly collect or process data from children. If we learn that a child's information has been inadvertently collected, we will delete it promptly.
Allin uses a small number of trusted providers to run the app and talk to you — each gets only what it needs to do its job, never more:
We don't sell your data, and we don't share it for anything beyond running and improving Allin.
Some of what Allin shows you — including your matched audio session and your personalised beliefs plan — is generated with the help of AI (Anthropic). We use this to interpret what you've written, never to make decisions that have a legal or similarly significant effect on you.
One exception, included because it matters for your safety: if what you write suggests you may be at risk, our systems — including this AI screening — are designed to detect that so we can direct you to appropriate support resources (such as crisis text and phone lines for your region). This is the one case where automated screening actively changes what you see next, and it exists solely to get you help faster.
Some of our service providers are located outside the UK/EEA.
We may update this Privacy Policy from time to time. Significant changes will be communicated via in-app notice or email (if available).
If you have questions or concerns about this Privacy Policy, please contact us:
Email: info@join-allin.com
Controller: Allin
Service Overview — Allin is a mobile application that guides users through emotional check-ins and personalized audio sessions designed to support emotional regulation and self-reflection.
Availability — The App is currently available on the Apple App Store.
Acceptance — By downloading, accessing, or using Allin, you confirm that you accept and agree to be bound by these Terms of Service and our Privacy Policy. If you do not agree, you must not use the App.
Age Requirement — The App is intended for individuals aged 16 and older.
Parental Consent — If you are under 18, you must have parental or guardian consent to use the App.
Account Registration — You may be required to register using Apple Sign-In. You agree to provide accurate and complete information during registration.
Audio Sessions — The App provides audio content generated and curated by Allin for self-regulation and personal development purposes.
Disclaimer — This App is not intended to diagnose, treat, cure, or prevent any medical condition. If you are in crisis or experiencing suicidal thoughts, call 999 (UK), 911 (US), or your local emergency number immediately. Contact appropriate crisis hotlines in your region.
User Content & Intellectual Property — You may submit personal notes, reflections, or other content while using the App. By submitting content, you grant Allin a non-exclusive, worldwide, royalty-free license to use, store, and process it in order to provide and improve the service. You remain the owner of your content. You agree not to submit unlawful, harmful, or infringing content. We are not responsible for user-generated content and may remove content that breaches these Terms.
Permitted Use — The App and its content are provided for personal, non-commercial use only.
Prohibited Use — You may not: copy, distribute, modify, or reverse engineer the App or its content; use the App in a manner that violates applicable laws or infringes the rights of others; misuse, interfere with, or attempt to disrupt the operation of the App.
The App may offer free and paid subscription plans via Apple's in-app purchase system. Prices, billing cycles, and renewal terms will be displayed within the App and are subject to Apple's standard policies.
Cancellation & Refunds — You can manage or cancel your subscription at any time via your Apple ID account settings. Refunds are handled in accordance with Apple's App Store policies.
Renewals — Subscriptions will automatically renew unless cancelled at least 24 hours before the end of the current period. Refunds are limited to those required by law or Apple's App Store policies.
The App relies on third-party services, including Apple Sign-In, Segment, Amplitude, Customer.io, Meta, RevenueCat, Supabase, and Anthropic — see our Privacy Policy for what each one does. Your use of these services is subject to their respective policies. We are not responsible for the data practices or content of external services.
No Warranty — The App is provided on an "as is" and "as available" basis. We do not warrant that the App will always be error-free or uninterrupted.
Limitation of Liability — To the maximum extent permitted by law, Allin and its operators are not liable for indirect, incidental, or consequential damages, including reliance on audio sessions or data loss.
The App may provide outputs generated by algorithms or artificial intelligence. These outputs may not always be accurate or appropriate. Users remain responsible for their own decisions and actions.
Account Suspension or Termination — We may suspend or terminate accounts that breach these Terms or where necessary for security, legal, or operational reasons. Accounts may also be terminated for unlawful activity, fraud, or non-payment. Upon termination, your right to access the App ends, and we may delete stored data. No refunds will be provided for termination due to breach of these Terms.
We may update these Terms periodically. Significant changes will be communicated via email or an in-app notice. Continued use of the App after changes indicates acceptance of the revised Terms.
For clarity: These Terms are governed by the laws of England and Wales. You agree that courts of England and Wales will have exclusive jurisdiction, except where mandatory consumer protection laws in your country apply.
For questions, support, or rights requests, please contact us:
Email: info@join-allin.com
Controller: Allin