Privacy Policy
Privacy Policy
Version: v1.3 Effective Date: 2026-04-18
Controller/Operator: PSYCHEBEACON L.L.C.
Address: 235 Grand St., Apt.2504, Jersey City, NJ, USA
Privacy Contact: psychebeacon@gmail.com
1. Categories We Collect
- Account: email/username, language/region, age bracket (18+ check).
- Device & Logs: model, OS, crash/perf logs, IP, timestamps.
- Physiological/Health (sensitive): heart rate, HRV, sleep, steps, activity, emotion/stress inferences.
- Optional Health Profile (voluntary): weight, height, age, disease/history (incl. mental and other), current medications, adverse effects/side effects, appointments/follow-ups (for medication/appointment reminders).
- Usage: feature frequency, interactions, error codes, latency.
- Communications: support/feedback emails/messages.
- Tree Hole & journaling: titles and body text you enter; optional status/activity icons, emotion and topic tags, intensity, the local calendar day and coarse time-of-day / timezone offset at write time; optional weather summary (e.g., city label, weather code, temperature); sync state, version and device model/platform; your choice whether to allow anonymous aggregate statistics ("resonance"); on-device emotion suggestion metadata (e.g., suggested tag, confidence, rules engine version) as structured fields—we do not send Tree Hole body text to third-party LLM APIs under the current implementation (on-device heuristics).
- Billing & digital entitlements: hashed or summarized transaction identifiers, subscription SKUs, subscription status and term, questionnaire quota/consumption records, entitlement check timestamps; we do not store full payment card numbers in app logs (card data is handled by the app stores).
- Questionnaire reviews (if applicable): star/text reviews you submit and the language (zh/en) you select at submission, for display and analytics.
2. Purposes & Legal/Notice at Collection
- Provide & maintain: account, sync, visualization, trends & alerts (incl. medication/appointment reminders), whisper sync/backup, paid questionnaire delivery and reports.
- Security/abuse prevention: anomaly detection, intrusion prevention, risk control, detection of abusive refunds or anomalous answering patterns.
- Billing & performance of contract: purchase verification, grant/revocation of digital entitlements, quota consumption and reconciliation.
- Compliance: consent records, audit, incident reporting, regulatory duties.
- Product improvement (aggregated): where you opt in (e.g., resonance), de-identified or aggregated statistics to improve the product; we do not use Tree Hole raw text for ad profiling or sell it to third parties.
- Beta research & model training (beta only): statistics, training/evaluation on de-identified/anonymous data (see "Beta Program" consent); Tree Hole raw text, per-item paid questionnaire responses and store receipt tokens are not used as inputs for that research purpose unless we provide prominent notice and obtain any additional consent required.
- U.S./California Notice at Collection: categories listed in §1; purposes above; retention in §6; we do not sell personal information; if we ever "share" (e.g., cross-context behavioral ads), we will provide Do Not Sell/Share and Limit Use of Sensitive PI links and update this Policy; we may honor GPC signals where applicable.
- China notice: processing sensitive PI and transfers abroad require separate consent; see the separate Consents and §3.
U.S./California "Notice at Collection": We will inform you of information categories, processing purposes, whether we sell/share, and retention periods at or before collection per 11 CCR §7012; when adding new categories or purposes incompatible with original purposes, we will inform you again and seek re-consent where necessary. We do not sell personal information; if "sharing" (cross-context behavioral advertising) occurs in the future, we will provide "Do Not Sell/Share" entry points. On web platforms, we recognize and respect GPC/Universal Opt-Out Mechanism (UOOM) signals.
3. Cross-Border Transfers
Primary hosting/processing is in the United States (e.g., Azure). Cross-border processing is necessary to provide the App.
No consent, no use / withdrawal disables Service: registering or continuing to use constitutes consent; Mainland China users provide separate consent; declining/withdrawing means we cannot provide the App (export/delete options offered).
Safeguards include encryption, access control, minimization and audit. For China users we plan to rely on SCC filing or Security Assessment; beta stage—no filing/approval number yet; updates will follow and re-consent obtained if required.
4. Sharing & Processors
We share or engage processors only as necessary: cloud hosting (e.g., Microsoft Azure), authentication, crash/performance analytics, notifications/email delivery, mobile app stores and their payment processors (Apple, Google, to complete in-app purchases and refund notifications), and other processors bound by contractual DP terms and purpose limits.
Third-Party Service Provider List: You can view service provider categories, typical supplier names, data processing purposes, and last update dates through Me → Privacy & Security → Terms Management → Service Providers or by visiting our website. For a complete list, please email psychebeacon@gmail.com.
5. De-identification/Anonymization & Models
For research/optimization we use de-identified/anonymous data. Upon withdrawal, we stop using your future data for research/training; already-trained model parameters are not rolled back.
6. Retention & Deletion
- Account & core usage: account life + 12 months.
- Physiological details & optional profile: minimal-necessary, up to 24 months.
- Tree Hole entries: retained while your account is active to enable sync and recall; after you delete content or delete your account, we delete or anonymize backups within 24 months except where a longer period is required by law or dispute/enforcement processes; aggregate statistical tables may be retained long-term if they do not identify individuals.
- Billing & transaction audit records: kept for the period necessary for tax/accounting and dispute handling, generally up to 36 months unless law requires longer.
- Logs/diagnostics: up to 12 months.
- Legal retention as required. Delete or anonymize at end-of-life. Export/delete via Me → Privacy & Security (e.g. Account Security for export, Account Settings for account deletion) or by email.
7. Your Rights & Choices
Access, rectification, deletion, restriction, portability, and withdrawal. For California: Do Not Sell/Share, Limit Use of Sensitive PI, and GPC (if applicable). In the app, open Me → Privacy & Security (including Terms Management, Service Providers, Account Security, and Account Settings), or email psychebeacon@gmail.com.
U.S. State Residents:
- California (CPRA): Do Not Sell/Share, Limit Use of Sensitive PI, GPC support, right to appeal (may file complaints with California Privacy Protection Agency CPPA)
- Virginia/Colorado/Connecticut/Utah: Access, rectification, deletion, portability, opt-out of targeted advertising/profiling/sale, and right to appeal to state attorneys general
8. Security & Breach Notification
We implement encryption in transit/at rest, least privilege, access control, tiered de-identification and audit. In the U.S., for unsecured personal health record breaches, we will notify individuals (no later than 60 days), regulators, and media where thresholds apply under FTC HBNR (16 CFR Part 318). For China and other regions, we follow local laws and timelines.
Data Breach Notification:
- United States: For unsecured personal health record breaches, we will notify affected individuals and regulatory agencies (FTC) as soon as possible and no later than 60 days after discovery, and fulfill media notification when thresholds are met (per FTC HBNR, 16 CFR Part 318).
- China: We will immediately take remedial measures, assess impact, and notify competent authorities and individuals, subject to applicable laws including the Personal Information Protection Law.
- Other regions: We will follow local legal procedures and timelines for notification and reporting.
9. Children
We do not offer the Service to individuals under 18. If mis-registered, contact psychebeacon@gmail.com to purge.
10. Changes & Re-Consent; Offline Provisional Consent
Material changes will be notified and re-consent sought where required. Offline provisional consent may be used when fetch fails; upon reconnection, records are reconciled; if a material new version exists, re-consent is required.