What we collect
Your account. Your email address and the name you give us. If you sign in with Google, we also receive the name, email address and profile picture URL in your Google sign-in token; the app shows an icon you choose rather than that picture.
What you create. Journal entries, vault notes and ideas, goals, activity and habit logs, books and reading notes, glossary terms, workouts, sleep logs, coach conversations, and any images you attach. Some of this is health data: sleep, workouts, and anything about your body or mind that you write down. The Health data policy covers it in more detail, and we only process it with your explicit consent.
Voice. If you use the microphone in the coach, the recording is sent for transcription and the text comes back to you. The recording itself is never stored.
Records we keep to run the service. Which AI features you used and when, the ratings you give generated text (thumbs up or down, and the reason if you add one), your subscription status, and which version of these documents you accepted and when.
Usage and crash data from Firebase, described in section 8, unless you turn it off.
Messages you send us. If you email us, we keep the conversation so we can help you.
We do not collect your location, contacts, calendar contents, or files other than the images you pick. We never sell your data, and we never use your content to train our own models.
Why we use it, and on what legal basis
Several laws (the EU and UK GDPR, Brazil's LGPD and others) require us to name a legal basis for each use. These are ours:
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. AI features generate text for you to read; they do not decide anything about your account.
AI features send content to third parties
Your content leaves our systems when you use AI
When you use an AI feature, the relevant content leaves our systems and is processed by an AI provider in the United States.
We send it from our servers to Google (Gemini) or to Groq, depending on the feature. Voice recordings go to Groq's Whisper speech model and are discarded as soon as the text comes back. See Google's privacy policy and Groq's privacy policy.
Your email address and account identifiers are never sent. The coach, the goal features, the morning brief, the deeper read and the weekly reflection include your first name, your timezone and your app preferences, so the assistant can address you by name and get your dates right; everything else is the content the feature needs.
Both providers act on our behalf under their business API terms, which do not let them use this content to train their models. They may keep it for a short time to detect abuse, under their own retention rules. If you would rather nothing left our systems, do not use the AI features — the rest of the app works without them.
Everything the coach and the other AI features write is generated by AI, and the app labels it that way. It can be wrong; the Terms explain its limits.
The coach, goals, the vault and the life graph.
Model: Gemini API
Book insights, the glossary, journal analysis, gym insights, quotes, weekly summaries, and voice transcription (Whisper).
Model: Groq API
Goal research runs a web search
When you create a goal or ask for a goal health check, we send your goal statement to Gemini with Google Search switched on. Google searches the web using your goal text and returns pages it cites in the brief. That means the wording of your goal reaches Google's search infrastructure, not only its AI models. Goals are often personal — a health target, a debt, a relationship — so treat the statement as the part of a goal that travels furthest.
Kept for fourteen days
14 daysThe brief is cached against your account for fourteen days so the same goal is not researched twice, then discarded.
Google Calendar, if you connect it
Calendar sync is off until you turn it on, and connecting it asks Google for a separate permission. Once connected, any habit or activity you mark for sync has its title, description, time, duration and repeat pattern written into your Google Calendar, and updated or deleted there when you change it here. We only write to your calendar; we never read your other events. Those events live in your Google account under Google's privacy policy, and anyone you share that calendar with can read them. Disconnecting stops further syncing; events already created stay until you delete them.
Content your phone loads from other sites
Some images are fetched by your phone directly, which means those sites see your IP address, the approximate location it implies, and which file you asked for. Book covers come from Open Library (covers.openlibrary.org), so Open Library can see which books are on your shelf as you browse it. Exercise photos come from the jsDelivr CDN (cdn.jsdelivr.net), which sees which exercises you open. We send these sites nothing else about you.
Book search goes through our servers to Open Library's search API, so your device is not exposed for the search itself, only for the covers that come back.
Sharing creates a public link
If you share an entry, we generate a link containing a random token. Anyone holding that link can read that entry without signing in — the link is the only credential. Nothing else in your account becomes reachable through it. You can revoke a share at any time, which makes the link stop working.
Usage data and crash reports
We use Firebase Analytics and Firebase Crashlytics, both run by Google, to see which parts of the app are used and when it crashes. They receive event names such as "login" or "trial accepted", a few plain values with them, your account identifier, the app version, your device model and operating system, and, for a crash, the technical trace of where it happened. They never receive anything you write.
Advertising identifier collection is switched off, there are no advertising SDKs, and nothing in the app profiles you for advertising. You can turn this off at any time under Profile → Privacy → Share usage data and crash reports. Firebase keeps analytics events for up to 14 months and crash reports for 90 days. See Firebase's privacy documentation.
Payments
Subscriptions are sold through Google Play and managed with RevenueCat, whose SDK runs inside the app. It sends RevenueCat your Axiome account identifier with the device and app information it needs to attach a purchase to your account, and returns your subscription status, renewal date and a customer identifier. Google handles payment; we never see or store your card details.
Your device
Reminders are scheduled on your device — we run no push server and collect no push tokens. Biometric unlock is handled entirely by your device; we never receive your fingerprint or face data. The camera and photos are used only when you add an image, and only images you pick are uploaded. The microphone is used only while you hold the record button. Data the app keeps on your phone for offline use is encrypted.
Who receives your data
These companies process data on our behalf, only for the purposes above, under contracts that require them to protect it. None of them may sell it or use it for their own advertising.
We disclose data to anyone else only if the law requires it — a valid court order, for example — and we will tell you unless the law forbids it. If Axiome is ever transferred to someone else, your data goes with it only under this policy, and we will tell you first.
International transfers
Your account is stored in the European Union. Some recipients are in the United States: Google, Groq, RevenueCat, Resend, PostHog's parent company and Amazon Web Services. When data goes from the EU, the UK or Switzerland to the United States, it is protected by the EU–US Data Privacy Framework (and its UK and Swiss extensions) where the recipient is certified, and otherwise by the European Commission's Standard Contractual Clauses, with the UK addendum for UK data. You can ask us for a copy of the safeguards.
If you live outside the EU — for example in Brazil, Argentina, Japan, Korea, India or Australia — your data is transferred to the EU and to the United States as described here. The details some laws ask for are:
You can refuse these transfers by not using the features that cause them — AI features, voice input, goal research — or by switching off usage data. Storage, subscriptions and account emails are needed to provide the app at all.
How long we keep it
Your content and account — while your account exists. You can delete any item yourself at any time.
After you delete your account — sign-in is blocked immediately and everything is erased thirty days later. The delay lets you change your mind by emailing us. Encrypted backups roll over on their normal schedule afterwards and are never restored except to recover from a disaster.
AI usage records, ratings and consent records — while your account exists, then deleted with it.
Goal research briefs — fourteen days. Voice recordings — not kept at all.
Firebase — analytics up to 14 months, crash reports 90 days.
Emails you send us — up to two years after the conversation ends, unless you ask us to delete them sooner.
Copies already sent to the AI providers, to Google Search or to your Google Calendar follow those providers' retention rules.
Your rights
Wherever you live, you can:
Write to [email protected] from the address on your account, so we know the request is yours. We answer within one month, sooner where your local law requires (for example, 15 days in Brazil), and tell you if we need longer. You may use an authorised agent; we will ask the agent for proof of your permission.
Europe: EU, EEA, UK and Switzerland
The GDPR, the UK GDPR and the Swiss Federal Act on Data Protection apply. The legal bases are in section 2 and the transfer safeguards in section 12. Our lead supervisory authority is Romania's ANSPDCP (dataprotection.ro), but you can complain to the authority where you live or work — in the UK the ICO (ico.org.uk), in Switzerland the FDPIC (edoeb.admin.ch).
United States
This section is our notice under the California Consumer Privacy Act (as amended by the CPRA) and the comprehensive privacy laws of other states, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Nebraska and Rhode Island.
Canada, Latin America
Under local law you also have the following:
Asia-Pacific
Under local law you also have the following:
This website
This website is hosted on Amazon Web Services (CloudFront and S3). Like any web server it sees your IP address and browser details, and keeps them in access logs for security.
Analytics. If you accept the cookie banner, we use PostHog, hosted in the EU, to count page views and clicks on the download buttons. It sets a cookie and uses browser storage to recognise a returning visitor. Nothing loads until you accept, and a browser that sends Global Privacy Control is treated as a refusal. You can change your mind under Cookie settings at the bottom of every page.
The waitlist. If you join the waitlist, the form is provided by Tally (Belgium, EU), which receives what you type — usually your email address. We use it only to tell you when Axiome is available, and delete it when you ask or when the waitlist closes.
The site uses no other cookies, no advertising and no tracking pixels.
Security
Data travels over encrypted connections and is encrypted at rest. Access is enforced by the database itself, so one account cannot read another's data, and uploaded images sit in a private bucket only your account can read. If a breach puts your data at risk, we will tell you and the authorities as the law requires — within 72 hours for European authorities.
Age
Axiome is for adults and is not directed at anyone under 18. We do not knowingly collect data from under-18s. If you believe someone under 18 has an account, tell us and we will delete it.
Changes
If we change this policy materially, the app asks you to read and accept the new version before you continue. Each version is numbered by its date, and we record which one you accepted.
Contact
Emilian Popescu, Padurii 15, Cluj-Napoca, Romania. [email protected] · phone number on request