Seen
Privacy Policy
Effective 29 July 2026
Seen is a private journaling and memory-keeping app. Your reflections belong to you. This page explains — in plain English — what we collect, what we do with it, and what rights you have. It is written to comply with Apple's App Store Guideline 5.1.1 and to give you a clear picture of how your data is handled.
1. Who we are
Seen is designed and operated by David Ferraloro. If you have any question about how your data is handled, or you want to exercise any of the rights described below, please write to seenreflectionapp@gmail.com.
2. What data we collect
To use Seen you provide, and we store on your behalf:
- Account details: your email address and a password. Passwords are hashed with bcrypt before they ever touch storage — we never store or transmit your plaintext password.
- Journal entries: the text, mood and date of every reflection you write in the app.
- Photos: images you choose to add. Each photo is stored on our servers linked to your account, together with any written "day note" you add and, when your camera roll has provided it, the location the photo was originally taken (extracted from the photo's EXIF metadata). We do not track your live location.
- Day notes: the short reflections you write about a particular date.
- Anonymous usage events: lightweight interaction events such as app_opened, journal_saved, photo_added. These carry the event name, the platform (iOS/Android/web), the app version, the local date, and a salted, one-way hash of your account identifier — never your email, never your journal text, never your photos. See §7.
On your device we additionally store, using iOS Keychain (SecureStore), your session token and your local App Lock preference (Face ID / passcode). This never leaves your device.
3. What we do with it
We use the data above only to:
- Sign you in and keep your session active on your device.
- Show your journal entries, photos and day notes back to you.
- Generate an optional short reflection about a photo you upload (see §4 for the third-party involved and the strict conditions).
- Understand aggregate usage — how many people open the app, how many entries get written — so we can improve the app.
We do not use your data to build advertising profiles, serve you ads, share with data brokers, or train third-party machine learning models.
4. Third-party processors
When you add a photo, Seen sends that single photo (and only that photo) to OpenAI in order to generate a short reflection. OpenAI processes the image only to produce the response, does not retain it for training under the API terms Seen operates under, and returns text only. If you never add a photo, no data ever leaves the Seen infrastructure for OpenAI.
Our backend runs on managed cloud infrastructure. Data is stored in MongoDB and served over HTTPS. No other third parties (analytics vendors, ad SDKs, crash-reporting SDKs) are integrated into Seen.
5. How long we keep it
Your journal entries, photos and day notes are kept for as long as your account exists. Anonymous usage events are kept indefinitely in aggregate form — they cannot be traced back to you personally because they are keyed on a salted hash and contain no content.
6. Your rights and how to exercise them
You can, at any time, from inside the app:
- See every entry and every photo — that is the app itself.
- Edit or delete individual entries and photos.
- Sign out — this clears your session token from your device but leaves your data on our servers.
- Permanently delete your account. Settings → danger zone → delete account. This purges, immediately and irrecoverably, your user record, every journal entry, every photo, every day note, and every anonymous event associated with you. This is a hard delete — there is no grace period.
If you would prefer to exercise any of these rights by email — for example if you are permanently locked out of your account — write to seenreflectionapp@gmail.com and we will handle the request within 30 days.
7. Anonymous usage events
Seen does not use any third-party analytics SDK. The lightweight interaction events described in §2 are recorded on the Seen backend keyed on a salted one-way hash of your account identifier. The salt is a server-side secret; the hash is not reversible. Events never contain journal text, photo bytes, mood, location or any other content — only the event name, platform, app version, local date and timestamp. You can turn off event recording entirely at any time from Settings → anonymous analytics.
8. Children
Seen is not intended for children under 13, and we do not knowingly collect data from children under 13. If you believe we have, please write to seenreflectionapp@gmail.com.
9. Security
All traffic between the Seen app and our backend is encrypted in transit with HTTPS/TLS. Passwords are stored only as bcrypt hashes. Your session token and App Lock preference are stored inside iOS Keychain (SecureStore) on your device. In-app, Face ID / Touch ID / passcode protection can be enabled at any time from Settings.
No system can guarantee absolute security. If Seen ever suffers a security incident affecting personal data, we will notify affected users by email as soon as practicable.
10. International transfers
If you use Seen outside the country where the backend is hosted, your data will be transferred to and processed in that country. We rely on the same technical and contractual protections regardless of where the data is processed.
11. Changes to this policy
If we materially change how Seen handles your data we will update this page and, when appropriate, notify you in the app. The "Effective" date at the top always reflects when the current version took effect.
12. Contact
Questions, concerns, requests: write to seenreflectionapp@gmail.com. We answer every message.