← Back to UpgradingYou

Privacy Policy

Effective Date: September 25, 2026

UpgradingYou, LLC, a Delaware limited liability company ("we," "us," or "our") operates the UpgradingYou mobile application and website (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service.

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

1.1a Waitlist Information

If you join the pre-launch waitlist, we collect your email address and the landing-page variant shown to you so we can notify you about availability and evaluate that page. We do not retain the page URL, referring URL, or UTM query parameters with your signup.

1.2 Profile and Onboarding Data

1.3 Activity and Planning Data

1.4 Conversation and AI Data

1.4a Feedback and Support Data

1.4b Appgrade and Safety-Review Data

When you create, use, or share an appgrade (a mini-app), we may collect and store:

When an appgrade is safety-reviewed, its executable code and derived safety context may be sent through OpenRouter to an AI model for hostile-code analysis. The deterministic permission and hard-block checks remain enforced if that AI review is unavailable.

You can also share a snapshot: a frozen page from an appgrade or from a chat, with only the data you chose to include. A snapshot lives at a public link. Anyone with that link can open it, with or without an account. Taps in the snapshot viewer (for example, checking off an ingredient) are not saved.

1.5 Subscription and Payment Data

1.5a Gift Purchases

If you buy a gift subscription for someone else, you may give us that person's email address and first name and a short message to pass along, and we email them a link to claim the gift. We use those details only to deliver the gift and to keep a record of the purchase. A recipient's address is not added to any mailing list, is not used to market to them, and does not create an account for them. If you would rather hand the code over yourself, leave the recipient fields blank and we will send the code to you instead. If someone gifted you a subscription and you would like your address removed from our records, contact us at the address in Section 11.

1.6 Device and Technical Data

1.7 Analytics Data

We use PostHog, a product-analytics service, to understand how people use the Service so we can improve it. On the web, PostHog is disabled unless you explicitly choose “Allow analytics”; declining or leaving the choice unanswered sends nothing to PostHog. In the native app, product analytics is enabled by default. When enabled, PostHog receives:

We do not send the contents of your conversations, memories, habits, health data, or financial data to PostHog. Error diagnostics exist to fix failures, not to profile you: we do not put message, memory, health, or payment content in them, though a technical error message occasionally quotes a fragment of the data that caused it. Analytics data is processed by PostHog on our behalf under its own privacy policy. On the web, you can grant or revoke analytics in Settings at any time; revocation stops collection and clears the browser-side analytics identity and queue.

On the website, we also use Cloudflare Web Analytics to understand aggregate page views and how the site performs. A small script (a "beacon") reports page views, referring pages, and browser performance timings. It does not use cookies or browser storage, does not attach the data to your account, and does not collect conversation, memory, habit, health, or financial contents. Cloudflare receives a visitor IP as part of ordinary web requests and discards it for this purpose rather than using it to identify you. This applies to the website, not the native iOS or Android apps. Processing is governed by Cloudflare's privacy policy. See our Cookie Policy.

1.8 Location (optional)

An appgrade may ask for your current location, for example to log a walk or stamp a journal entry. This is off until you allow it in the system location prompt, and it is one-shot while you are using the app. We do not track you in the background, and timezone (Section 1.2) is not precise location. If that appgrade then includes the location in an AI request, the location may be sent to our AI provider (OpenRouter) as part of that request.

1.9 Health and Fitness Data (Apple Health -- iOS, optional)

On iOS, you may optionally connect Apple Health from the app's Settings. This is off by default and requires your explicit permission through Apple's standard Health access prompt. When enabled, we read the following categories from Apple Health solely to automatically track your activities and show your progress:

We read this data only; we do not write any data back to Apple Health. Rather than storing your individual health samples, we compute a per-day summary on your device (for example, total steps, exercise minutes, workout count, and hours of sleep for a given day) and store that daily summary on our servers so the app can mark matching activities complete and so your assistant can reference your real progress when you ask about it.

We never use Apple Health data for advertising or marketing, and we never sell it or share it with data brokers or third parties for their own purposes. You can stop the sync at any time by turning off the Apple Health toggle in Settings, and you can revoke our access entirely in iOS Settings → Privacy & Security → Health. Health data we have stored is removed when you delete your account.

1.10 Calendar Data (device calendar -- optional)

You may optionally let the app read the calendar on your device (from the app's Settings, or when your assistant offers it during setup). This is off by default and requires your permission through your device's standard calendar access prompt. When enabled, we read your upcoming events (about the next two weeks) from the calendars already on your phone and store a small rolling snapshot on our servers so your assistant can plan around your real commitments.

The device-calendar snapshot includes only each event's title, start and end times, all-day flag, location, and the name of the calendar it came from. This device integration does not read or store event notes, attendee lists, or links, and never writes to your calendar. Turning the toggle off in Settings stops the sync and removes the stored snapshot; you can also revoke access in your device's privacy settings. Calendar data is deleted when you delete your account.

1.11 Gmail and Google Calendar (optional private preview)

If you connect Google in Settings, you authorize read-only access separately from signing in to UpgradingYou. To answer your requests, the assistant can search your Gmail mailbox, including older and archived messages, read message bodies and conversations, and list and read Google Calendar events. This can include email senders, recipients, subjects, dates, labels, text and attachment metadata, and calendar names, event titles, descriptions, times, locations and source links. The current integration does not download attachment content, send or modify mail, mark messages read, or create, change or delete events.

For requests judged to concern Gmail, a quick-context step may retrieve candidate email subjects, rank their relevance, and read the top matching messages before the assistant answers. Evidence searches may also read and rank candidate message passages. This processing uses TypeSafe's Jev model, directly or through OpenRouter; relevant Google content is also sent through the app's configured AI providers to generate your response. This is inference to provide your requested assistance, not model training.

We store encrypted access and refresh tokens so you can keep using this connection. We retrieve Google data on demand rather than maintaining a whole-mailbox mirror. Retrieved tool content and answers may be saved in your chat history under Section 5's retention rules. Disconnecting removes our stored tokens and pending connection requests and stops future access; it does not erase existing conversations. You can delete individual conversations in the app, or delete your account to remove all saved conversations and the connection itself, and you can revoke the Google authorization in your Google Account permissions.

Saved answers containing Google information may also become personalized memory facts, summaries, recaps and search embeddings (numeric representations), so the assistant can recall relevant context and help with your plans. These derived records are stored with your account and processed by the relevant AI and hosting providers listed below. They follow the retention and deletion rules in Sections 5 and 6; disconnecting Google alone does not delete them. If you choose voice or sharing features, relevant saved content may also be included in the output you request.

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including their Limited Use requirements. These restrictions also apply to derived, aggregated and anonymized Google data. We do not use Google user data for advertising or retain or use it to develop, improve, or train generalized or non-personalized AI/ML models. Google data is used to provide the user-facing assistance you request.

2. How We Use Your Information

We use the information we collect to:

3. How We Share Your Information

We do not sell your personal information. We share data with third-party service providers only as necessary to operate the Service. We contractually require processors that receive personal data from us to provide the same or equivalent privacy and security protections described in this policy:

Provider Purpose Data Shared
Supabase Authentication and database hosting All account and user-generated data, including encrypted Google connection tokens, saved retrieved content and personalized derived memories
OpenRouter AI chat processing, text-to-speech, embeddings and appgrade safety review (routes to AI providers) Chat messages, conversation history, memory context, relevant connected Google content and derived context, appgrade executable code, and derived safety context
TypeSafe Jev relevance ranking and structured judgments, directly or through OpenRouter Relevant query and application context, including candidate Gmail subjects and message passages for email retrieval
OpenAI AI processing through OpenRouter; direct fallback for memory search embeddings Relevant inference text; text used to create or search personalized memory embeddings
Groq Speech-to-text transcription Audio recordings from voice input
Brave Search Web search during AI conversations Search queries generated in conversation context
RevenueCat Subscription and in-app purchase management User ID, subscription status, product identifiers
Resend Transactional email delivery Email address, email content (e.g., password reset)
Kit Mailing list for the founding-members community Email address and first name of founding members, with a tag marking that group
Expo Push notifications and over-the-air updates Push tokens, notification content
Google OAuth authentication; real-time voice mode (Gemini); Google Play billing on Android OAuth tokens; voice-mode audio, personalized assistant context and resulting transcripts; purchase and subscription status
PostHog Product analytics to understand and improve feature usage Product events and feature usage, account user identifier, device platform
Instagram / Meta Only if you choose to add a snapshot to an Instagram Story The picture of the snapshot and the public snapshot link, handed to Instagram on your device. We do not send your account or notebook to Meta.
Apple OAuth authentication; App Store billing OAuth identity tokens; subscription status
Stripe Payment processing, subscription management, and refunds for web subscriptions Email address and subscription, transaction, dispute, and refund status (card details are handled by Stripe, not by us)
Stripe Connect Creator payouts, identity checks, and tax forms Identity and bank or debit details go to Stripe. We receive payout status and tax-reporting state, not full account numbers
Cloudflare Web hosting, bounded waitlist storage, and real-time voice relay Web request data; waitlist email address; voice-mode audio relayed in real time (not stored)
Cloudflare Web Analytics Aggregate website usage and page-performance metrics Page views, referring pages, and browser performance timings. No cookies, no account identifier, and no conversation or notebook contents. Cloudflare discards the visitor IP after routing and does not use it to identify you.
YouTube Show and play videos linked in assistant messages (privacy-enhanced player, loaded when the message is shown) Your IP address and ordinary browser/request data when the player loads; cookies or storage only once you play the video

We may also disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, safety, or property of UpgradingYou, our users, or others.

3.1 Information Visible to Other Users

Some features let you connect with friends (your "village") and share content. Sharing is opt-in. Nothing below is visible to other people unless you choose to share it or join someone's village.

You can update your profile or stop sharing at any time, although people you have already shared with may retain what was previously shared with them. Public snapshot links stay reachable until the snapshot is removed.

3.2 Creator referrals

If you arrive through a creator's referral link, we store the referral code and a timestamp in your browser (see the Cookie Policy) for 30 days, and we may associate your signup with that creator so they can be paid a commission on a web subscription. Creators see aggregate counts only. They never see your identity. This program is optional and not always offered.

4. AI-Specific Disclosures

On iOS and Android, we ask for your explicit permission in the app before sending personal data to a third-party AI service. The permission screen identifies the recipients and the categories of data below. If you choose “Sign out,” the app does not send your personal data for AI processing. Your accepted disclosure version and the time of your choice are stored on your profile so our servers can enforce that boundary. On the website, the same processing is covered by this Privacy Policy.

The Service uses artificial intelligence extensively. You should be aware that:

For supported OpenRouter requests, we require routes that deny provider data collection and support zero-data-retention processing. OpenRouter may still keep limited request metadata, such as timestamps, model choice, token counts, and cost, as described in its privacy documentation; it does not receive permission to use your prompts for model training from UpgradingYou.

5. Data Retention

6. Your Rights and Choices

6.1 Account Deletion

You can permanently delete your account and associated personal data directly within the app, under Settings. From your side, deletion takes effect when you confirm it. We then remove account data from our systems and instruct our processors to delete it, which we complete within 30 days, except for the limited anti-fraud and billing records described in Section 5 or where retention is required by law. You may also request deletion by contacting us at the email below. Note that deleting your account does not automatically cancel any subscription billed through the Apple App Store or Google Play. You must cancel that separately in your Apple ID subscription settings or in your Google Play subscription settings. Web subscriptions billed by Stripe can be cancelled through the billing controls in Settings.

A waitlist signup may exist without an account. Contact us from the waitlisted address if you want that signup removed.

6.2 Data Export

You have the right to receive a copy of your personal data. While a self-service in-app export feature is in development, you may request a machine-readable copy of your data at any time by contacting us at the email below, and we will provide it within 30 days.

6.3 Notification and Email Preferences

You can control which notifications you receive and their frequency through the app's settings.

Check-in emails about your account (Section 2) carry an unsubscribe link, and your mail app's one-click unsubscribe works too. Either one stops every check-in email straight away. Account emails, such as password resets, billing notices, and gift delivery, are part of running your account and continue regardless. If you are on our founding-members list at Kit, unsubscribing from those emails is done through the link at the bottom of any of them, and it is separate from the setting above.

6.4 If you live outside the United States

UpgradingYou, LLC is a United States company. If you use the Service from another country, including in Europe or California, you can still email us to ask for a copy of your data, to correct it, or to delete it. We will respond within 30 days. We do not sell personal information.

6.5 California

We do not sell personal information. If you are a California resident, you can email us to ask what we have collected about you or to request deletion, the same way anyone else can.

7. Data Security

We implement reasonable technical and organizational measures to protect your personal data, including:

No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

8. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly. If you believe a child under 13 has provided us with personal data, please contact us at the email below.

Users between 13 and 17 may use the Service only with the consent and involvement of a parent or legal guardian (see our Terms of Service). If the law where you live sets a higher minimum age, you must meet that age.

9. International Data Transfers

We are based in the United States. If you use the Service from another country, your information is processed in the United States, including by the providers listed in Section 3. Those countries may have different data protection laws than your own.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Effective Date" above. Your continued use of the Service after changes are posted constitutes acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Email: [email protected]

Terms of Service Cookie & Storage Policy