Reconnect Privacy Policy
Last updated: August 2, 2026
Reconnect helps you take small real-world actions that fit your day. This policy explains what we collect, why, and the choices you have. We collect the minimum needed to make the app work, and we never sell your data, share it for advertising, or use third-party analytics trackers.
Reconnect is a wellbeing tool, not a medical or crisis service. The brain-science explanations in the app are educational and are not medical advice, diagnosis, or treatment. If you are in distress or thinking about harming yourself, please contact a crisis line such as the 988 Suicide & Crisis Lifeline (US, call or text 988) or your local emergency number.
What we collect
- Account email. Used to create your account and sign you in, through our authentication provider (Supabase).
- A user ID. A random identifier that links your saved progress to your account.
- A rotating Device ID. Reconnect creates a random install identifier for first-party analytics and diagnostics. It is not an Apple hardware identifier or advertising ID, is never used for cross-company tracking, and rotates at guest-to-account, account-to-account, invalid-session, and sign-out boundaries so different accounts sharing one installation are not joined.
- Your in-app activity. Plans you complete, completion times, plans you skip or swap, XP and streak counts, the interests and comfort level you choose, optional personality selections, optional short reflections you save with a completed plan, and your optional weekly yes/not-yet answer about whether a Reconnect rep helped you interact with someone. A saved reflection stays with that rep in Activity History and, when you are signed in, syncs with your account so it can survive reinstall. Reconnect can use a small positive topic signal from it to tune future suggestions on your device. The reflection text is never included in product analytics. The editor asks you not to include names or sensitive details.
- First-party product usage events. Reconnect records product interaction events on our own server for app opens; onboarding steps; plans shown, accepted, swapped, skipped, and completed; optional post-plan felt and prediction/outcome answers; legacy reminder-offer choices from earlier app versions; and the optional weekly connection answer. These events use the rotating Device ID. A signed-in request carries your Supabase bearer credential; our backend ignores any user ID nominated by the client and links the event only to the account Supabase verifies from that credential. Anonymous beacon events remain anonymous. Events can include limited structured values such as plan level/category and the answer option you selected. They do not include your name, email, precise location, calendar details, plan free text, people/place nicknames, or the monthly loneliness check-in. Analytics events are retained for 90 days and then removed by a private daily cleanup job.
- Bounded diagnostics. If the app encounters a JavaScript error, it can send our backend a redacted message, source path, line/column, redacted stack, page path, app build, platform, timestamp, and rotating Device ID. A signed-in report may be linked only to the Supabase user verified from its bearer credential so account deletion can remove it. Reports exclude authorization headers, request bodies, precise location, calendar content, names, and email. They are retained for 30 days and then removed by the same private cleanup contract.
- Abuse-prevention counters. To enforce hourly request limits, our backend converts the request IP into a secret-keyed, endpoint-specific digest and stores only that digest, a counter, and its expiry in a private database table. The raw IP is not stored in the counter, the digest is not used for analytics or profiling, and an expired row no longer affects enforcement. Expired rows are removed in bounded cleanup batches during later limiter traffic, so the final expired rows can remain until another limited request runs. Routine application logs record the request method, path without its query string, status, timing, and a random request ID; they omit IP addresses, URL query values, authorization headers, and request bodies.
- Optional monthly loneliness check-in. If you answer the three monthly questions, the scores and snooze date are stored only on that device. They are never synced to your account, sent to analytics, or uploaded to Reconnect's server.
- Optional first and last name. Only if you enter them in your profile.
- Optional nicknames for people and places you add. If you use the "See anyone familiar?" or "your spot" features, the short labels you write (for example, "the barista" or "the Tuesday class") are stored with your synced progress so they survive reinstalls. They are labels you author yourself; we never read your contacts, never match you with anyone, and you can rename or remove them at any time from the Journey screen.
- Approximate location, only when you allow it. Used while the app is open to find nearby places for a plan. Reconnect keeps the full device coordinate in local device state, rounds it to two decimal places before sending a nearby-place or reverse-geocode request, and sends only that coarser coordinate to our backend and Google Places. It is not included in your synced progress or analytics. If you instead type a city or ZIP, account state keeps only the exact text you entered and, when returned, a validated Google place ID. Google's formatted label and resolved coordinates remain session-only and are freshly resolved.
- Calendar free/busy windows, only if you connect Google Calendar. We read only when you are free or busy, so we can suggest plan times that fit. We never read event titles, descriptions, attendees, or any other calendar details. To keep the optional connection working, our backend stores the Google OAuth credentials, expiry, scope, and connection metadata in a service-role-only Supabase table; those credentials are never returned to the app. OAuth state is high-entropy, server-held, and one-use. After Google's callback, the app receives only an opaque handle that expires after five minutes and can be finalized only by the authenticated account that started the connection.
- Sign in with Apple authorization, only if you use Apple sign-in. Supabase can return Apple's provider refresh credential during sign-in. The app holds it in memory only and hands it once to Reconnect's authenticated backend, where it is validated against the verified Supabase Apple identity and stored service-role-only solely so account deletion can revoke the Apple authorization. It is never used for analytics, personalization, advertising, or tracking.
- Local reminder permission, only if you allow it in the iOS app. Used on your device to remind you about a plan. Reconnect does not upload or store a push notification token.
What we do NOT collect
The current iOS version does not include Apple Health access. We do not collect health or fitness data, receive monthly loneliness check-in answers off your device, or collect financial information, contacts, photos, browsing or search history, audio, or advertising identifiers. Reconnect has no dedicated sensitive-information fields; please do not put names or sensitive details in the optional reflection. Product usage analytics do not include precise GPS location, name, email, contacts, people/place nicknames, calendar details, plan free text, or written-reflection text. We do not use third-party advertising or analytics trackers, and we do not sell data or share it with data brokers.
Third-party services
We use a small number of services to run the app. Places, Calendar, and coarse IP-region lookups are routed through our backend. Authentication and synced-state requests go directly from the app to Reconnect's Supabase project over encrypted HTTPS:
- Supabase stores your account, synced progress (including optional reflections when you are signed in), Reconnect's first-party product usage events, optional Google Calendar OAuth credentials and connection metadata in a service-role-only table, and secret-keyed abuse-prevention counters with expiry timestamps. Reflection text is part of synced progress, not analytics. Analytics events are sent from Reconnect to Reconnect's own backend, not through a third-party analytics SDK.
- Google Calendar provides your free/busy windows (only with the limited
calendar.freebusy permission) if you connect it.
- Google Places receives a search term (such as "coffee shop") and either a device coordinate rounded to two decimal places or a manually selected city to return nearby spots. Reconnect stores only the city or ZIP text you entered and, when available, Google's place ID; provider-returned coordinates, formatted labels, venue results, photo resource names, and photo bytes are not durably stored. The backend requests current venue and photo data on demand and streams validated, bounded raster photo bytes through a same-origin endpoint. The app never receives the Google API key or direct Google photo URL. Google Maps content is subject to the Google Maps Platform Terms and Google Privacy Policy.
- Apple WeatherKit receives a device coordinate rounded to two decimal places on iOS to return short-lived current weather context. Reconnect uses it only to decide which suggestion fits the day, and never shows you weather. The response stays on that device, is never synced to your account or sent to analytics, can influence recommendations for 45 minutes, and is purged from durable device state after 90 minutes.
- ipwho.is and ipapi.co are tried in that order for coarse first-party analytics location. The selected provider receives the request IP for the lookup. Reconnect stores the resulting country/region, not the IP address; its bounded lookup cache uses a secret-keyed digest instead of the raw IP.
Reconnect's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
How your data is used
To run the app, sign you in, sync your progress across devices, personalize plan suggestions, find nearby places, fit plans to your schedule, measure whether people can move from a shown plan to a completed real-world action, and understand whether those actions lead to human interaction. That is the whole list.
Deleting your data
You can delete your account at any time from Profile, then Account, then Delete account. For Apple sign-in accounts, Reconnect first attempts to revoke the Apple authorization using the server-only credential. One service-role-only database transaction then permanently removes the verified account's linked analytics and client-error reports, Apple revocation credential, authentication identity, synced progress, and Google Calendar credentials and connection metadata. If a legacy Apple account has no usable credential or Apple revocation fails, Reconnect still deletes its own data and shows Apple's manual permission-removal steps. You can also email us to request deletion.
Children
Reconnect is not directed at children under 13, and we do not knowingly collect data from them.
Changes
If we change this policy, we will update the date at the top of this page.
Contact
Questions about privacy or your data: rewire.social.app@gmail.com.