Privacy Policy for "Future You"
Effective Date: January 5, 2025
Last Updated: August 9, 2026
Future You is operated by FutureYou Tech, Brisbane, Queensland, Australia ("we", "us", "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Future You mobile app ("App") and the futureyou.me website ("Website"). Please read it carefully. By using Future You, you agree to the collection and use of information in accordance with this policy.
This Privacy Policy applies to all users worldwide and includes specific provisions for users in the European Union (GDPR), the United Kingdom (UK GDPR), California (CCPA/CPRA), and Australia (Privacy Act 1988).
You can reach us about anything in this policy at support@futureyou.me.
1. Information We Collect
We collect information to provide and improve our services. The categories of information we collect include:
1.1 Information You Provide Directly
- Account Information: Name, email address, username, password, and profile details such as your profile picture, bio, and any social or web links you choose to add.
- User Content: Goals, steps and habits, journals, posts, comments, photos, messages, and other content you create, share, or interact with on the App.
- Communications: Information you provide when you contact us for support or feedback. Please send only what is needed to resolve your request - see Section 1.6 before sharing sensitive details.
1.2 Information from Your Activities
- Interaction Data: Your direct activities within the App, such as likes, comments, shares, follows, and goal interactions.
1.3 Usage Analytics and Session Recordings
- Analytics Data: We collect information about how you interact with the App, including screens viewed, buttons tapped, navigation patterns, and feature usage to help us improve the App.
- Session Recordings: We may record app sessions to diagnose problems and understand how the App is used. Sessions are sampled automatically rather than chosen by us. A recording captures what was shown on your screen and how you moved through the App, which can include text you have entered. Password fields are obscured as you type and appear obscured in recordings. Recording is on by default and you stay in control of it: you can turn it off at any time in Settings → Data & Privacy → App Insights, and if you would prefer that nothing you write is ever captured, turning it off is how to do that.
- Technical Data: Device type, operating system version, app version, and performance metrics.
1.4 Information from Third-Party Services
- OAuth Providers: When you sign in using Google or Apple, we receive your email address, name, and profile picture from these services.
1.5 Payment and Subscription Information
We collect limited subscription information to provide PRO features:
- Subscription status (active, expired, cancelled)
- Subscription tier (monthly, yearly, or free)
- Purchase event dates and subscription changes
- Anonymised receipt verification data
We do NOT collect or store: credit card numbers, billing addresses, or payment method details. All payment information is processed exclusively by Apple Inc. (App Store) or Google LLC (Google Play).
1.6 Sensitive Information You Choose to Share
Future You is a goal-tracking and journaling app, so what you write may reveal sensitive details - about health or mental health, sexual or reproductive matters, relationships, religious or political beliefs - in your goals, journals, posts, comments, or messages to our support team.
- We never require it. No feature of the App asks you for health or other sensitive information, and you can use every part of the App without providing any.
- Please keep it out of support messages. Our support channels handle accounts, billing, technical issues, and safety reports. They are not a confidential clinical, counselling, or legal record, and they are not monitored continuously. Send only what is needed to resolve your request.
- How it is handled. Anything you write is handled as User Content under this policy. It receives the same security measures and retention rules as all other content (Sections 7 and 9), and goes through the same automated processing described in Sections 3 and 16, including search indexing, automated safety screening, and personalisation. We do not sell it and we do not use it for advertising.
- You stay in control. You can delete any goal, journal, or message at any time. Deleting your account removes your content, subject to the retention periods in Section 9.
- Safety exception. Where we believe in good faith that there is a risk to life or safety, or where the law requires it, we may disclose relevant information to emergency services or other appropriate authorities, as described in Section 5.
2. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide you with the App and its features, as outlined in our Terms of Service.
- Legitimate Interests: Processing necessary for our legitimate interests, such as improving the App, ensuring security, and preventing fraud, provided these interests are not overridden by your rights.
- Consent: Where you have given explicit consent for specific processing activities, such as receiving marketing communications.
- Legal Obligations: Processing necessary to comply with applicable laws and regulations.
- Vital Interests: Where processing or disclosure is necessary to prevent death or serious harm to you or another person, as described in Section 5.
- Contract Performance (Subscriptions): Processing subscription data through RevenueCat is necessary to provide PRO features you have purchased and to verify your entitlements.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and Maintain the App: To create and manage your account, enable social features, and deliver the services you request.
- Personalize Your Experience: To customize content, recommendations, and features based on your preferences and usage.
- Communicate with You: To send service-related announcements, respond to inquiries, and provide customer support.
- Improve the App: To analyze usage patterns, troubleshoot issues, and develop new features.
- Ensure Security: To detect, prevent, and address fraud, abuse, and security issues.
- Comply with Legal Obligations: To fulfill our legal requirements and respond to lawful requests from authorities.
4. Third-Party Service Providers
We use trusted third-party service providers to help us operate and improve the App. These providers have access to your personal data only to perform specific tasks on our behalf and are obligated to protect your information.
| Provider | Purpose | Data Location |
|---|---|---|
| Supabase | Database, authentication, file storage | United States |
| Cloudflare | Hosting, CDN, security | Global (edge locations) |
| OpenAI | Receives content you write. Automated goal screening, content safety scoring, writing suggestions, and personalisation | United States |
| Google (Gemini API) | Receives content you write. Generates the search embeddings that power goal and journal search | United States |
| Firebase (Google) | Push notifications (FCM) | United States |
| PostHog | Receives content you write. Product analytics and session recordings, which capture on-screen content (Section 1.3) | United States |
| Resend | Sending transactional email (verification, reminders, notifications) | United States |
| Telegram | Receives content you write. Operational alerts to our support and moderation channel, which can include account identifiers and extracts of content | Global |
| Unsplash | Stock imagery. Receives photo identifiers only, no personal data | United States |
| RevenueCat | Subscription management, purchase verification | United States |
| Apple Inc. (App Store) | Payment processing (iOS) | United States |
| Google LLC (Google Play) | Payment processing (Android) | United States |
Providers marked "Receives content you write" are sent the text of your goals, journal entries, or on-screen activity so that a feature can work. The others receive identifiers and technical data only.
We also use Google ML Kit to detect the language of what you write. This runs entirely on your device and the text never leaves it.
Each provider maintains their own privacy policy and security measures. We encourage you to review their privacy practices.
RevenueCat acts as a data processor to manage subscription state and verify purchases with Apple and Google. RevenueCat processes anonymous user identifiers, subscription status, purchase receipts, and device identifiers. RevenueCat does not collect your name, email, credit card numbers, or billing address. RevenueCat is SOC 2 Type II certified with a GDPR Data Processing Addendum. See RevenueCat Privacy Policy.
5. Sharing Your Information
We share your information only in the following circumstances:
- With Other Users: Content you share, along with your profile information, is visible to other users according to the visibility you set. Each goal can be set to public, followers only, or private, and new goals are public unless you change this. You can change a goal's visibility at any time. Please check the visibility setting before writing anything you would not want others to read.
- With Service Providers: As described in Section 4, we share data with third-party providers who assist in operating the App.
- For Legal Reasons: We may disclose your information if required by law, court order, or government request, or to protect our rights, property, or safety.
- To Protect Life or Safety: Where we believe in good faith that disclosure is necessary to prevent death or serious harm to you or another person, we may share relevant information with emergency services, law enforcement, or child protection authorities. Under the GDPR this relies on the vital interests of a natural person (Article 6(1)(d)), and where you are physically or legally incapable of giving consent, Article 9(2)(c).
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred to the successor entity.
WE DO NOT SELL, RENT, OR TRADE YOUR PERSONAL INFORMATION TO THIRD PARTIES FOR THEIR MARKETING PURPOSES.
We have not sold personal information in the preceding twelve (12) months and do not intend to do so.
6. Local Storage, Cookies and Session Management
In the App, we store only essential data on your device:
- Authentication Tokens: Securely stored using your device's secure storage (iOS Keychain / Android Keystore) to keep you signed in.
- App Preferences: Your settings and preferences to personalize your experience.
- Cached Content: Temporary data to improve app performance and reduce loading times.
- Analytics Preferences: Your choice regarding analytics data collection.
We do not use:
- Advertising or marketing trackers
- Third-party tracking pixels
- Cross-app tracking technologies
You can clear locally stored data by logging out of the App or clearing the App's data in your device settings.
6.1 Cookies on the Website
The futureyou.me website uses cookies for one purpose: keeping you signed in. These are essential authentication cookies set by our authentication provider and are required for the site to work. We do not use advertising cookies, marketing cookies, or cross-site tracking on the Website. You can clear them through your browser settings, which will sign you out.
6.2 Analytics Services
We use PostHog for product analytics and session replay to understand how users interact with the App and to improve our services. PostHog may collect:
- Usage patterns and navigation flows, linked to your account
- Session recordings, which capture on-screen content as described in Section 1.3
- Device and app technical information
- Feature usage and interaction data
- Your email address and username, so that sessions can be linked to your account
This data is processed based on our legitimate interests (GDPR Article 6(1)(f)) to understand how the App is used and to fix problems. PostHog processes it in the United States. You can opt out of analytics and session recording at any time in Settings → Data & Privacy → App Insights. In rare cases, we may temporarily enable analytics to help diagnose and fix errors or crashes you are experiencing.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Passwords are hashed by our authentication provider and are never stored in readable form
- Row-level database security, so that each account can only read the data it is entitled to
- Access controls limiting who on our side can view your data
- Credentials and API keys held in dedicated secret storage, never in our source code
- Location metadata is stripped from photos when they are processed for upload
- Secure cloud infrastructure with established providers
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.
YOU ARE RESPONSIBLE FOR MAINTAINING THE CONFIDENTIALITY OF YOUR ACCOUNT CREDENTIALS AND FOR ANY ACTIVITY THAT OCCURS UNDER YOUR ACCOUNT.
8. Data Breach Notification
In the event of a data breach that affects your personal information, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of a notifiable breach, as required by GDPR Article 33.
- Notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms (GDPR Article 34). In Australia we follow the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), assessing a suspected breach within 30 days and notifying affected individuals and the Information Commissioner as soon as practicable.
- Provide details about the nature of the breach, the types of data affected, and the potential consequences.
- Describe the measures we are taking to address the breach and mitigate any harm.
- Offer guidance on steps you can take to protect yourself.
We will notify you via the email address associated with your account and, where appropriate, through in-app notifications.
9. Data Retention
We retain your personal data for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
Retention Periods
- Account Data: Retained for the duration of your account's active status, plus a reasonable period afterward to comply with legal obligations.
- User Content: Retained until you delete it or your account is terminated.
- Backup Data: May be retained in encrypted backups for up to 30 days after deletion from live systems.
- Abandoned Sign-Ups: If you create an account but never choose a username or create any content, the account and its data are deleted automatically 30 days after sign-up.
- Deletion Archive: A deleted account is snapshotted into a private archive that only support staff can access, so that we can verify a deletion was carried out correctly and resolve any dispute about it. We are introducing automatic deletion of these archives 90 days after the account is deleted.
- Data Exports: A data export you request is deleted automatically when its download link expires.
Subscription and Purchase Data
Your subscription records are held in your account and are deleted with it. Purchases are made through Apple and Google, who keep their own transaction records under their own policies and retention periods, including for tax purposes. We do not hold your payment details at any point.
When data retention periods expire, we securely delete or anonymize your data in accordance with our data handling procedures.
You can request deletion of your data at any time. See our Account Deletion Instructions for more details.
10. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal data. We honor all applicable privacy rights regardless of your location.
Rights Available to All Users
- Access: Request information about the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data (use our Account Deletion feature).
- Data Portability: Request a copy of your data in a structured, commonly used format.
- Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
To exercise these rights, contact us at support@futureyou.me. Response times, and the limits of email delivery, are described in Section 20.
We may retain certain subscription and payment records where required by Australian tax law (5-year retention), necessary for fraud prevention, or required by Apple or Google for payment dispute resolution.
11. Additional Rights for EU/EEA Users (GDPR)
If you are located in the European Union, European Economic Area, or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR):
- Right to Restriction: Request restriction of processing of your personal data in certain circumstances.
- Right to Object: Object to processing of your personal data based on legitimate interests.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
International Data Transfers
Your data may be transferred to and processed in countries outside the EEA, including Australia and the United States, where our service providers are located. When we transfer your data outside the EEA, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the European Commission
- Transfers to countries with adequate data protection laws
- Binding corporate rules where applicable
Data Protection Officer
As a small business, we are not required to appoint a Data Protection Officer. However, you may contact us with any privacy concerns at support@futureyou.me.
12. Additional Rights for California Users (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Categories of Personal Information Collected
- Identifiers: Name, email address, username.
- Personal Information (Cal. Civ. Code § 1798.80): Name, email address.
- Internet Activity: Your direct interactions such as likes, comments, shares, and follows.
- Inferences: Preferences and interests derived from your usage.
Your CCPA Rights
- Right to Know: Request disclosure of the personal information we collect, use, and share.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out of Sale: We do not sell personal information, so this right does not apply.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
"DO NOT SELL OR SHARE MY PERSONAL INFORMATION": We do not sell or share your personal information for cross-context behavioral advertising. We have not sold or shared personal information in the preceding twelve (12) months.
13. Australian Privacy Act Compliance
Future You is operated from Brisbane, Queensland, Australia. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
- We collect personal information only by lawful and fair means.
- We take reasonable steps to ensure the accuracy of personal information.
- We protect personal information from misuse, interference, and loss.
- We provide access to personal information upon request.
- We allow individuals to request correction of their personal information.
If you have a complaint, please tell us first. Email support@futureyou.me with the details and we will look into it. Most concerns are resolved this way, and it gives us the chance to put things right.
If you are not satisfied with our response, you may then contact the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
14. Children's Privacy
Future You is not intended for users under 16 years of age. We do not knowingly collect personal information from children under 16.
If you are under 16, please do not use the App or provide any personal information. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at support@futureyou.me.
If we learn that we have collected personal information from a child under 16 without verifiable parental consent, we will take steps to delete that information promptly.
15. International Data Transfers
Future You is operated from Australia and our services are provided globally. By using the App from outside Australia, you acknowledge and agree that:
- Your personal data is stored primarily in the United States, where our database and file storage are hosted with Supabase.
- Your data is also processed in other countries where our service providers operate (see Section 4). Most of them are based in the United States.
- Future You is operated from Brisbane, Australia, and our team accesses your data from there.
- Data protection laws in these countries may differ from those in your country of residence.
- You consent to such transfers as necessary to provide you with the App's services.
We take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy, regardless of where it is processed.
16. Automated Decision-Making and Personalization
Feed Personalization
Future You uses automated systems to personalize your experience, including:
- Customizing your feed based on your interests, likes, and interactions
- Suggesting goals and content that may be relevant to you
- Ordering content to show you what we believe you'll find most valuable
- Building a short internal profile of your interests and focus from the content you create, so that these suggestions improve over time
This personalization is designed to enhance your experience and does not have legal or similarly significant effects on you. It is never used to decide your account status, suspend you, or restrict your access to features. You can influence these recommendations through your interactions within the App.
Automated Content Screening
Some content checks happen automatically, before any person sees your content:
- When you create a goal, its text is checked automatically and the goal is rejected if it contains threats, hate speech, instructions for self-harm, sexual content involving minors, or plans to commit crimes. Everyday language, dark humour, self-criticism, and recovery goals such as "quit drinking" are allowed.
- After you post a goal or journal, it is scored automatically for safety, spam, and quality. Content scoring above our threshold is hidden from other users and flagged for review.
These checks are automated. A person reviews every flagged item afterwards and can restore it. If you believe a decision was wrong, contact us at support@futureyou.me and a person will look at it.
Decisions to suspend or terminate an account are always made by a person, never automatically.
17. Limitation of Liability
While we implement reasonable security measures to protect your personal information, we cannot guarantee absolute security. To the maximum extent permitted by applicable law:
WE SHALL NOT BE LIABLE FOR ANY UNAUTHORIZED ACCESS TO, ALTERATION OF, OR DISCLOSURE OF YOUR PERSONAL INFORMATION, OR FOR ANY DATA BREACH, EXCEPT WHERE CAUSED BY OUR GROSS NEGLIGENCE OR WILLFUL MISCONDUCT.
Some jurisdictions do not allow the exclusion or limitation of liability for certain damages. In such jurisdictions, our liability is limited to the greatest extent permitted by law.
This limitation of liability is in addition to, and does not limit, any limitation of liability set forth in our Terms of Service.
18. Third-Party Links
The App may contain links to third-party websites, services, or applications that are not operated by us. This Privacy Policy does not apply to those third-party services.
We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party services. We encourage you to review the privacy policy of every site or service you visit.
19. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes, we will:
- Update the "Last Updated" date at the top of this page.
- For material changes, we may provide additional notice through the App.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
20. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Operated by: FutureYou Tech
Email: support@futureyou.me
Location: Brisbane, Queensland, Australia
Where you exercise a privacy right under Sections 10 to 13, we respond within 30 days in the ordinary course. If a request is complex, or you have made several, we may need longer and will tell you if that happens.
Our replies are sent by email, and email is not perfectly reliable - messages are sometimes filtered into spam or junk folders, or delayed by the receiving provider. If you have not heard from us when you expected to, please check those folders and then write to us again, and we will follow it up. Delivery of an email is not something we are able to guarantee.
General support enquiries are handled as described in Section 7A of our Terms of Service.