Version 2026-09-23Applies wherever you liveLast updated 23 September 2026

Privacy Policy

Version 2026-09-23 · Last updated: 23 September 2026 · App bundle: com.axiome.app

Axiome tracks your journals, goals, habits, reading, workouts and sleep, with optional AI assistance. This policy explains what we collect, why, where it goes, how long we keep it, and what you can do about it. It covers the Axiome app and this website.

Axiome is run by Emilian Popescu, an individual developer at Padurii 15, Cluj-Napoca, Romania. That person is the data controller for everything in this policy and the person responsible for privacy under every law named below. Write to [email protected] about anything here.

The short version

We never sell your data, we show no ads, and we never use your content to train our own models. Your account lives with Supabase in the European Union. Content leaves our systems only when you use a feature that needs it, and this page names every company it goes to.

Selling and ads

None

No data is sold or shared for advertising. There are no advertising SDKs and the advertising identifier is switched off.

No sale, no ads
Storage

European Union

Your account and content are stored with Supabase in Frankfurt, and each account can only read its own rows.

Supabase, Frankfurt
Your control

Export and delete

Download everything from the app, turn analytics off, and delete your account without writing to anyone.

Profile → Privacy
§ 01

What we collect

Your account. Your email address and the name you give us. If you sign in with Google, we also receive the name, email address and profile picture URL in your Google sign-in token; the app shows an icon you choose rather than that picture.

What you create. Journal entries, vault notes and ideas, goals, activity and habit logs, books and reading notes, glossary terms, workouts, sleep logs, coach conversations, and any images you attach. Some of this is health data: sleep, workouts, and anything about your body or mind that you write down. The Health data policy covers it in more detail, and we only process it with your explicit consent.

Voice. If you use the microphone in the coach, the recording is sent for transcription and the text comes back to you. The recording itself is never stored.

Records we keep to run the service. Which AI features you used and when, the ratings you give generated text (thumbs up or down, and the reason if you add one), your subscription status, and which version of these documents you accepted and when.

Usage and crash data from Firebase, described in section 8, unless you turn it off.

Messages you send us. If you email us, we keep the conversation so we can help you.

We do not collect your location, contacts, calendar contents, or files other than the images you pick. We never sell your data, and we never use your content to train our own models.

§ 02

Why we use it, and on what legal basis

Several laws (the EU and UK GDPR, Brazil's LGPD and others) require us to name a legal basis for each use. These are ours:

To provide the app you signed up for — your account, storing and showing your content, the AI features you ask for, voice transcription, sharing links you create, subscriptions. Basis: performing our contract with you.
To process health data — Basis: your explicit consent, which you give separately when you sign up, and can withdraw at any time (section 14). It is the core of what the app does, so without it the account cannot continue.
To keep the service secure and working — rate limits, abuse prevention, fixing failures, backups. Basis: our legitimate interest in running a safe, reliable service.
To understand which features are used and fix crashes (Firebase). Basis: our legitimate interest in improving the app, and you can switch it off at any time. Where local law requires consent for this, we rely on consent.
To send account emails — confirming your address, resetting your password. Basis: performing our contract.
To sync with Google Calendar and to analyse this website — Basis: your consent, which you give when you connect the calendar or accept the cookie banner.
To meet legal obligations — for example answering a lawful request from an authority, or keeping records of your consents. Basis: legal obligation.

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. AI features generate text for you to read; they do not decide anything about your account.

§ 03

AI features send content to third parties

Read this first

Your content leaves our systems when you use AI

When you use an AI feature, the relevant content leaves our systems and is processed by an AI provider in the United States.

We send it from our servers to Google (Gemini) or to Groq, depending on the feature. Voice recordings go to Groq's Whisper speech model and are discarded as soon as the text comes back. See Google's privacy policy and Groq's privacy policy.

Your email address and account identifiers are never sent. The coach, the goal features, the morning brief, the deeper read and the weekly reflection include your first name, your timezone and your app preferences, so the assistant can address you by name and get your dates right; everything else is the content the feature needs.

Both providers act on our behalf under their business API terms, which do not let them use this content to train their models. They may keep it for a short time to detect abuse, under their own retention rules. If you would rather nothing left our systems, do not use the AI features — the rest of the app works without them.

Everything the coach and the other AI features write is generated by AI, and the app labels it that way. It can be wrong; the Terms explain its limits.

Google (Gemini)United States

The coach, goals, the vault and the life graph.

Model: Gemini API

GroqUnited States

Book insights, the glossary, journal analysis, gym insights, quotes, weekly summaries, and voice transcription (Whisper).

Model: Groq API

§ 04

Goal research runs a web search

When you create a goal or ask for a goal health check, we send your goal statement to Gemini with Google Search switched on. Google searches the web using your goal text and returns pages it cites in the brief. That means the wording of your goal reaches Google's search infrastructure, not only its AI models. Goals are often personal — a health target, a debt, a relationship — so treat the statement as the part of a goal that travels furthest.

Kept for fourteen days

14 days

The brief is cached against your account for fourteen days so the same goal is not researched twice, then discarded.

§ 05

Google Calendar, if you connect it

Calendar sync is off until you turn it on, and connecting it asks Google for a separate permission. Once connected, any habit or activity you mark for sync has its title, description, time, duration and repeat pattern written into your Google Calendar, and updated or deleted there when you change it here. We only write to your calendar; we never read your other events. Those events live in your Google account under Google's privacy policy, and anyone you share that calendar with can read them. Disconnecting stops further syncing; events already created stay until you delete them.

§ 06

Content your phone loads from other sites

Some images are fetched by your phone directly, which means those sites see your IP address, the approximate location it implies, and which file you asked for. Book covers come from Open Library (covers.openlibrary.org), so Open Library can see which books are on your shelf as you browse it. Exercise photos come from the jsDelivr CDN (cdn.jsdelivr.net), which sees which exercises you open. We send these sites nothing else about you.

Book search goes through our servers to Open Library's search API, so your device is not exposed for the search itself, only for the covers that come back.

§ 07

Sharing creates a public link

If you share an entry, we generate a link containing a random token. Anyone holding that link can read that entry without signing in — the link is the only credential. Nothing else in your account becomes reachable through it. You can revoke a share at any time, which makes the link stop working.

§ 08

Usage data and crash reports

We use Firebase Analytics and Firebase Crashlytics, both run by Google, to see which parts of the app are used and when it crashes. They receive event names such as "login" or "trial accepted", a few plain values with them, your account identifier, the app version, your device model and operating system, and, for a crash, the technical trace of where it happened. They never receive anything you write.

Advertising identifier collection is switched off, there are no advertising SDKs, and nothing in the app profiles you for advertising. You can turn this off at any time under Profile → Privacy → Share usage data and crash reports. Firebase keeps analytics events for up to 14 months and crash reports for 90 days. See Firebase's privacy documentation.

§ 09

Payments

Subscriptions are sold through Google Play and managed with RevenueCat, whose SDK runs inside the app. It sends RevenueCat your Axiome account identifier with the device and app information it needs to attach a purchase to your account, and returns your subscription status, renewal date and a customer identifier. Google handles payment; we never see or store your card details.

§ 10

Your device

Reminders are scheduled on your device — we run no push server and collect no push tokens. Biometric unlock is handled entirely by your device; we never receive your fingerprint or face data. The camera and photos are used only when you add an image, and only images you pick are uploaded. The microphone is used only while you hold the record button. Data the app keeps on your phone for offline use is encrypted.

§ 11

Who receives your data

These companies process data on our behalf, only for the purposes above, under contracts that require them to protect it. None of them may sell it or use it for their own advertising.

Supabase (database, file storage, our servers) — everything in your account. Stored in Frankfurt, Germany.
Google — Gemini for AI features, Google Search for goal research, Firebase for usage data and crashes, Google Play for purchases, Google Sign-In and Google Calendar if you use them.
Groq — AI features and voice transcription.
RevenueCat — subscription status.
Resend — delivering account emails.
Open Library and jsDelivr — see section 6.
Amazon Web Services, PostHog and Tally — for this website only; see section 19.

We disclose data to anyone else only if the law requires it — a valid court order, for example — and we will tell you unless the law forbids it. If Axiome is ever transferred to someone else, your data goes with it only under this policy, and we will tell you first.

§ 12

International transfers

Your account is stored in the European Union. Some recipients are in the United States: Google, Groq, RevenueCat, Resend, PostHog's parent company and Amazon Web Services. When data goes from the EU, the UK or Switzerland to the United States, it is protected by the EU–US Data Privacy Framework (and its UK and Swiss extensions) where the recipient is certified, and otherwise by the European Commission's Standard Contractual Clauses, with the UK addendum for UK data. You can ask us for a copy of the safeguards.

If you live outside the EU — for example in Brazil, Argentina, Japan, Korea, India or Australia — your data is transferred to the EU and to the United States as described here. The details some laws ask for are:

Supabase Inc. · Germany (EU) · everything in your account · continuously while you use the app, over encrypted connections · to store and serve your data · until your account is deleted.
Google LLC · United States · the content an AI feature or goal research needs, your first name, timezone and preferences; usage events and crash traces unless you turn them off · each time you use the feature, or as you use the app · to generate responses and keep the app stable · as in section 3 and section 8.
Groq, Inc. · United States · the content an AI feature needs; voice recordings · each time you use the feature · to generate responses and transcribe speech · discarded after processing, subject to short abuse-monitoring retention.
RevenueCat, Inc. · United States · account identifier and purchase records · when you buy and when the app checks your plan · to manage subscriptions · until your account is deleted.
Resend, Inc. · United States · your email address and the email · when we send an account email · to deliver it · per Resend's retention.

You can refuse these transfers by not using the features that cause them — AI features, voice input, goal research — or by switching off usage data. Storage, subscriptions and account emails are needed to provide the app at all.

§ 13

How long we keep it

Your content and account — while your account exists. You can delete any item yourself at any time.

After you delete your account — sign-in is blocked immediately and everything is erased thirty days later. The delay lets you change your mind by emailing us. Encrypted backups roll over on their normal schedule afterwards and are never restored except to recover from a disaster.

AI usage records, ratings and consent records — while your account exists, then deleted with it.

Goal research briefs — fourteen days. Voice recordings — not kept at all.

Firebase — analytics up to 14 months, crash reports 90 days.

Emails you send us — up to two years after the conversation ends, unless you ask us to delete them sooner.

Copies already sent to the AI providers, to Google Search or to your Google Calendar follow those providers' retention rules.

§ 14

Your rights

Wherever you live, you can:

Access your data and learn how it is used — ask us, or use Download my data in the app.
Correct it — edit it in the app, or ask us.
Delete it — item by item, or your whole account from Profile → Delete Account.
Take it with you — the download is a machine-readable file.
Object to or restrict processing based on our legitimate interests, including analytics.
Withdraw consent — for health data, Google Calendar, or website analytics — at any time, without affecting what was done before. Withdrawing health-data consent means we cannot keep your account, so we will delete it.
Appeal a refusal: if we decline a request, reply to our answer and a second review will be made. If you are still unhappy you can complain to the authority named for your region below.
Not be treated differently for using any of these rights. We never charge for a request.

Write to [email protected] from the address on your account, so we know the request is yours. We answer within one month, sooner where your local law requires (for example, 15 days in Brazil), and tell you if we need longer. You may use an authorised agent; we will ask the agent for proof of your permission.

§ 15

Europe: EU, EEA, UK and Switzerland

The GDPR, the UK GDPR and the Swiss Federal Act on Data Protection apply. The legal bases are in section 2 and the transfer safeguards in section 12. Our lead supervisory authority is Romania's ANSPDCP (dataprotection.ro), but you can complain to the authority where you live or work — in the UK the ICO (ico.org.uk), in Switzerland the FDPIC (edoeb.admin.ch).

§ 16

United States

This section is our notice under the California Consumer Privacy Act (as amended by the CPRA) and the comprehensive privacy laws of other states, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Nebraska and Rhode Island.

Categories we collect (past 12 months): identifiers (email, name, account ID); customer records; commercial information (subscription status); internet or electronic activity (app usage events, crash data); audio (voice recordings, transcribed and discarded); sensitive personal information (health data, account login); and the content you write. Sources: you, your device, and Google Sign-In. Purposes: section 2. Retention: section 13.
We do not sell or share personal information, as those words are defined in California law, and have not in the past 12 months. We do not use it for targeted advertising or profiling with legal or similar effects.
Sensitive personal information is used only to provide the service you asked for, so there is nothing to limit.
Global Privacy Control: this website treats a browser's Global Privacy Control signal as an opt-out and does not load analytics. The app sends nothing that could be sold or shared.
Your rights: know, access, correct, delete, portability, opt out, and non-discrimination (section 14), plus an appeal. If we deny your appeal, you can contact your state Attorney General.
Consumer health data under Washington's My Health My Data Act, Nevada's SB 370 and Connecticut law is covered by our Health data policy.
Axiome is not directed at children and we do not knowingly collect data from anyone under 18.
§ 17

Canada, Latin America

Under local law you also have the following:

Canada (PIPEDA, and Quebec's Law 25): the person in charge of protecting personal information is Emilian Popescu, reachable at [email protected]. You can complain to the Office of the Privacy Commissioner of Canada, or in Quebec to the Commission d'accès à l'information.
Brazil (LGPD): our data protection officer (encarregado) is Emilian Popescu, at [email protected]. You have every right in Article 18 LGPD, including confirmation that we process your data, anonymisation, and information about who we share it with. You can petition the ANPD.
Argentina (Law 25,326): you can access your data free of charge every six months unless you show a legitimate interest in more frequent access. La AGENCIA DE ACCESO A LA INFORMACIÓN PÚBLICA, en su carácter de Órgano de Control de la Ley N° 25.326, tiene la atribución de atender las denuncias y reclamos que interpongan quienes resulten afectados en sus derechos por incumplimiento de las normas vigentes en materia de protección de datos personales.
Mexico (LFPDPPP): you can exercise your ARCO rights (access, rectification, cancellation, opposition) and revoke consent by writing to us; we answer within 20 business days.
Colombia (Law 1581), Chile (Law 19,628 and Law 21,719), Peru (Law 29733) and other countries in the region: you can know, update, correct and delete your data and revoke consent, and complain to your national data protection authority (in Colombia, the Superintendencia de Industria y Comercio).
§ 18

Asia-Pacific

Under local law you also have the following:

Japan (APPI): data goes to the EU and to the United States (section 12). Japan's Personal Information Protection Commission recognises the EU's protection as equivalent to Japan's. The United States has no comprehensive federal privacy law; the recipients there are bound by contract to protect your data as described in this policy. You can ask us to disclose, correct, stop using or delete your data.
South Korea (PIPA): section 12 lists every overseas transfer — the items, country, timing and method, recipient, purpose and retention. When data reaches the end of its retention it is permanently deleted from the database; files are deleted from storage. You can refuse the transfers as described there. You can complain to the Personal Information Protection Commission.
India (DPDP Act 2023): our grievance officer is Emilian Popescu, at [email protected]; we answer grievances within 90 days at most. You can nominate someone to exercise your rights if you die or become unable to, and complain to the Data Protection Board of India.
Singapore (PDPA), Philippines (Data Privacy Act), Thailand (PDPA), Malaysia (PDPA), Indonesia (PDP Law), Vietnam, Hong Kong (PDPO) and Taiwan (PDPA): you can access and correct your data and withdraw consent, and complain to your national authority.
Australia (Privacy Act 1988) and New Zealand (Privacy Act 2020): you can access and correct your data, and complain to the OAIC or to the New Zealand Privacy Commissioner if we do not resolve your complaint within 30 days.
Axiome is not offered in mainland China.
§ 19

This website

This website is hosted on Amazon Web Services (CloudFront and S3). Like any web server it sees your IP address and browser details, and keeps them in access logs for security.

Analytics. If you accept the cookie banner, we use PostHog, hosted in the EU, to count page views and clicks on the download buttons. It sets a cookie and uses browser storage to recognise a returning visitor. Nothing loads until you accept, and a browser that sends Global Privacy Control is treated as a refusal. You can change your mind under Cookie settings at the bottom of every page.

The waitlist. If you join the waitlist, the form is provided by Tally (Belgium, EU), which receives what you type — usually your email address. We use it only to tell you when Axiome is available, and delete it when you ask or when the waitlist closes.

The site uses no other cookies, no advertising and no tracking pixels.

§ 20

Security

Data travels over encrypted connections and is encrypted at rest. Access is enforced by the database itself, so one account cannot read another's data, and uploaded images sit in a private bucket only your account can read. If a breach puts your data at risk, we will tell you and the authorities as the law requires — within 72 hours for European authorities.

§ 21

Age

Axiome is for adults and is not directed at anyone under 18. We do not knowingly collect data from under-18s. If you believe someone under 18 has an account, tell us and we will delete it.

§ 22

Changes

If we change this policy materially, the app asks you to read and accept the new version before you continue. Each version is numbered by its date, and we record which one you accepted.

§ 23

Contact

Emilian Popescu, Padurii 15, Cluj-Napoca, Romania. [email protected] · phone number on request

Emilian Popescu

Data controller

Padurii 15, Cluj-Napoca, Romania