Feeling It Privacy Policy
Effective date: September 8, 2026
Contact: Feeling It support form
Feeling It is a feelings-wheel and journal app designed to work without a Feeling It account, advertising, cross-app tracking, or a third-party analytics SDK. This policy explains what the app handles, where information goes, and the choices available to you.
Information you choose to create
A journal entry can contain the emotion words you select, intensity, additional emotions, a short note, a need or reflection response, life-context labels, timestamps, and optional place, calendar, or selected people context. The app also stores settings such as appearance, reminders, privacy-lock preference, and whether optional integrations are enabled.
Feeling It stores this information on your device using Apple’s app-storage frameworks. We do not operate an account server that receives your journal, and the app does not include advertising or third-party analytics SDKs.
Optional product analytics
Product analytics is off by default. If you explicitly choose Help improve Feeling It during onboarding or turn on Help Improve Feeling It in Settings > Journal settings, Feeling It sends allowlisted product-interaction events to a public Apple CloudKit database that the developer can access; creator-only client permissions prevent other app users from reading the records. These events use fixed identifiers for screens, controls, selections, coarse workflow outcomes, completed gestures, and foreground-lifecycle changes, such as opening a tab, tapping a fixed control, or whether a non-sensitive operation succeeded. Within each foreground session, they include event order, active milliseconds elapsed since foreground began (excluding time iOS makes the app inactive), a random ephemeral UUID that changes for every foreground session, and the app version and build. Only a session whose foreground end was durably recorded is eligible to upload. An incomplete session left by an exit or relaunch, and the entire session that reaches Safety & Support, is discarded instead. CloudKit adds a batch creation time, and each batch carries an expiry time used by the developer-operated retention process. Because finalized batches normally upload after foreground use and contain relative event timing, those fields can let the developer approximate when an app interaction occurred. Feeling It does not send a client-generated wall-clock time for each event or the date and time you assign to a journal entry.
The client-defined analytics payload does not contain an account identifier or a persistent user, device, or installation identifier. CloudKit requires an authenticated iCloud account for public-database writes and automatically associates each stored record with an account-specific creator identifier in CloudKit system metadata. Because that association can connect multiple product-interaction records from the same iCloud account, Feeling It discloses Product Interaction as linked to the user for the Analytics purpose. It separately discloses the CloudKit creator identifier as linked User ID for the App Functionality purpose because the identifier supports creator-scoped access, account isolation, and withdrawal/deletion. The developer does not use the creator identifier to analyze behavior, discover a person’s real-world identity, combine the events with other datasets, advertise, market, profile, sell information, or track anyone across other companies’ apps or websites.
Solely so deletion retries can target the correct iCloud account and exact uploaded batches, Feeling It stores one-way SHA-256 account hashes and opaque CloudKit batch record names in protected, backup-excluded storage. The raw account identifier is not stored. These local values are never included inside an analytics payload, log, export, or report and reveal no journal content.
Analytics can count a fixed identifier for a reminder-control tap, but it never includes the control’s setting or result. Analytics never includes journal content or stored-entry totals, the feeling names or identifiers you view or choose, intensity values, notes, reflection answers, life-context selections, journal timestamps, the contents or identities of searches or results, safety-language detection, crisis-support screens or answers, Health information or authorization, location or place labels, Calendar information or authorization, the content of notifications, reminder schedule values, notification-permission outcomes, StoreKit purchase or restore actions or results, accessibility settings, biometric information, file contents or names, share destinations, or raw error messages. No entitlement-status value is sent, although use of a tracked feature that is available only with Lifetime Access can indicate that Lifetime Access is available on that device. These exclusions apply even when you consent to product analytics.
We target removal of uploaded analytics within 90 days. Batches carry an 85-day expiry time to leave time for cleanup and retries. This field does not automatically delete a CloudKit record; removal requires the developer’s maintenance process or an in-app deletion request. A CloudKit outage or maintenance-process failure can delay removal beyond the target while the operator retries cleanup. The analytics choice is per device. Turning it off immediately clears unsent events and stops new collection on that device, then requests deletion for its current iCloud account and each locally recorded account the device previously used to upload. CloudKit permits deletion only while the matching account is authenticated. If an account is signed out or CloudKit is temporarily unavailable, the app keeps that account’s deletion request and local hash pending and retries when the same account becomes available; the retention target also applies to these records. Deletion on one device can race with a still-enabled second device on the same iCloud account, which can upload new records after the first device verifies deletion. Turn analytics off separately on every device where you enabled it, then retry deletion if needed. Uninstalling the app does not send a withdrawal request; already uploaded batches remain until an in-app deletion succeeds or maintenance removes them. Analytics is optional and does not affect free or paid functionality.
Optional iCloud sync
Your journal starts on your device. If you purchase Lifetime Access and turn on iCloud sync, Feeling It copies journal records to the private CloudKit database associated with your Apple Account so they can sync among your Apple devices. Apple operates iCloud and handles that information under Apple’s Privacy Policy.
Turning on iCloud is optional. The app checks your iCloud account status only to make the feature work. Turning sync off safely copies the active journal back to on-device storage before switching modes; it does not change Apple’s separate backup or retention practices.
Apple Health
If you enable Apple Health sync, Feeling It can write supported journal entries to the State of Mind category in HealthKit. Feeling It does not read your existing Health history. Health permission is optional, is requested through Apple’s system interface, and can be changed in the Health app or Settings. A local journal save does not depend on a successful Health write.
Health information is never used for advertising, marketing, profiling, or sale.
Calendar context
Calendar access is optional and requested only if you enable calendar context. Calendar is scanned on-device. Raw notes are never saved. A snapshot you choose becomes part of that journal entry and syncs with your private iCloud journal when iCloud sync is on.
The saved snapshot can include the event identifier, title, start and end time, all-day status, calendar name and color, and an on-device derived notable-moment label. You can leave calendar context out of any entry or disable calendar access in Settings.
Location context
Location access is optional and requested when you choose location context. Feeling It requests a one-time location through Apple’s location service and uses Apple’s geocoding service to turn it into an editable place label. Raw coordinates are not stored in your journal. Only the place label you choose is saved, and it is included in iCloud sync if iCloud sync is on.
People and Contacts
Contacts access is optional. If you enable it, Feeling It looks up names on-device from the contacts you allow it to access. Only names you select are saved with a journal entry. Phone numbers, email addresses, photos, and address-book identifiers are not saved with the entry.
Selected names become part of your journal, including private iCloud sync when you turn it on and journal files you choose to export. They are never included in product analytics. You can remove selected names when editing an entry. Turning Contacts access off stops future lookups; names already saved with entries remain until you remove them or delete those entries.
Reminders, motion, and app lock
- Reminder schedules use Apple’s local-notification service. Feeling It does not run a remote messaging or marketing-notification service.
- Optional device motion adds subtle visual depth to the wheel. Motion samples are not stored or sent by Feeling It.
- If you enable the privacy lock, authentication is performed by iOS with Face ID, Touch ID, or the device passcode. Feeling It does not receive or store biometric data.
Purchases
Lifetime Access is sold through Apple’s In-App Purchase system. Apple processes payment, purchase history, refunds, and Family Sharing eligibility. Feeling It receives StoreKit product and entitlement status so it can unlock features; it does not receive your full payment-card details.
Export, import, and sharing
You can export your journal to a file, import a compatible backup, or share a generated card. Those actions occur only when you choose them. After you hand a file or card to the system share sheet, Files, a cloud-storage provider, or another app, that recipient’s privacy practices apply. Review the destination before sharing sensitive information.
Retention and deletion
On-device journal information remains until you delete individual entries, use Erase my data at the bottom of Settings, or uninstall the app. If you turned on iCloud sync, uninstalling Feeling It removes the app’s on-device data but does not by itself delete journal records already stored in the app’s private iCloud database. To request deletion of both on-device and private iCloud journal records from within the app, use Erase my data before uninstalling; you can also manage app data through your Apple Account. Deleting one entry immediately scrubs its emotion, intensity, notes, reflections, contexts, place, calendar snapshot, selected people, and device Health linkage from Feeling It’s journal. To make that deletion converge across synced devices, Feeling It retains only the entry identifier and its creation, modification, and deletion timestamps as a payload-free deletion marker until you use Erase my data.
If the deleted entry was linked to an Apple Health sample, Feeling It attempts to remove that sample when Health authorization allows and can retain device-local cleanup metadata until a retry succeeds. Erase my data removes Feeling It journal records and deletion markers from this device and requests their removal from the app’s private iCloud database, but it does not delete samples already written to Apple Health. If iCloud cleanup cannot finish, the app keeps iCloud sync disabled and offers a retry so stale records cannot be restored into the journal. The app retains container-specific CloudKit account identifiers in protected local recovery storage to ensure a retry targets the account whose journal was synced. These are opaque identifiers, not your Apple Account email or name; they are not sent to analytics. Cleanup for an earlier account remains pending while a different account is signed in. If an older cleanup request cannot be tied to an account, it remains unresolved instead of deleting from the current account. Copies may remain temporarily in device backups or Apple’s systems under Apple’s retention practices. You can export a copy before deletion.
Because there is no Feeling It account service, we generally cannot identify or retrieve a journal on your behalf. For questions about a privacy request, use the Feeling It support form. Requests involving iCloud, Health, App Store purchases, or Apple backups may also need to be directed to Apple.
Optional product analytics follows the separate 85-day expiry, 90-day operational target, and withdrawal process described above. Disabling analytics clears the device queue immediately and starts deletion attempts for the current iCloud account and every locally recorded uploader account when each matching account is available; journal erasure does not silently re-enable analytics.
Children
Feeling It is not directed to children under 13, and we do not knowingly operate a service that collects personal information from children. App Store age-rating and family controls remain governed by Apple and the device owner.
Safety and medical information
Feeling It is a reflection and emotional-vocabulary aid, not therapy, diagnosis, crisis monitoring, or medical advice. The app does not send journal text to a clinician or emergency service. If you may be in immediate danger, contact local emergency services.
Changes to this policy
If this policy changes materially, the effective date above will be updated and the revised policy will be published at the in-app Privacy Policy link before or with the related app update.
Support
For privacy questions, technical support, or deletion guidance, use the form below. The form is outside the app and uses EmailJS to deliver the name, reply address, and message you choose to submit. EmailJS also processes request metadata and may temporarily log an IP address to prevent abuse, as described in the EmailJS Privacy Policy. Support information is used to respond to your request, prevent abuse, and meet legal obligations; it is not connected to your in-app journal. Please do not include journal entries, Health information, payment information, or other sensitive content in a support message.