PRIVACY
Privacy policy
Effective September 3, 2026
What Jessalyn is
Jessalyn is a reflection and wellness app. This policy explains the information the app processes when you use passkeys, write or speak with Jessalyn, connect health data, share an approximate location, or manage a subscription.
Information we process
Account and passkey information
Jessalyn creates an opaque account identifier and stores the public credential information needed to verify your passkey, including a credential identifier, public key, security counter, device type, backup status, and any passkey name you choose. Jessalyn does not create an email identity or store a password for your account.
Journal and consultation content
We process the text you submit in consultations, journals, intentions, messages, feedback, and related settings. Consultation transcripts and generated responses are stored so the service can preserve your history, recall relevant context, and provide the features you request.
Voice
During a voice consultation, microphone audio is streamed to Cloudflare Workers AI for speech-to-text processing. The resulting transcript is processed by models reached through OpenRouter to generate a response, and response text is sent to Cloudflare Workers AI for text-to-speech. Jessalyn stores the transcript, but does not intentionally store the raw microphone recording after the live request. Those providers process data under their own terms and our account settings and agreements.
HealthKit and Health Connect
If you opt in and grant system permission, Jessalyn reads only the health and fitness categories you select, such as sleep, steps, active energy, exercise, workouts, resting heart rate, or mindfulness. Raw HealthKit and Health Connect samples remain on your device. The app calculates daily aggregates and sends those summaries, their date, source, and time zone to your Jessalyn account. Relevant bounded summaries may be included as context when you ask Jessalyn for a consultation. We do not use health data for advertising or sell it.
Approximate location
If you opt in, the app obtains a low-accuracy device location to derive an approximate area and time zone. Jessalyn’s servers receive the approximate area and time zone, not the latitude or longitude. This setting can be used as local context in a consultation.
Subscriptions and diagnostics
RevenueCat receives your opaque Jessalyn account identifier and subscription activity to provide plan access. Apple or Google handles payment details; Jessalyn receives purchase status, product, store, environment, renewal, and expiration information. The app may also send crash and operational diagnostics to Sentry, with screenshots, session replay, and default personally identifying information disabled.
How information is used and disclosed
We use information to:
- authenticate your account and protect access;
- provide consultations, journals, messages, health context, and other app features;
- operate subscriptions, exports, deletion, and support;
- maintain reliability, diagnose failures, and prevent abuse; and
- comply with law and enforce our terms.
Service providers process information on our behalf: Cloudflare hosts the application and provides speech processing, OpenRouter and routed model providers generate responses, RevenueCat manages subscription state, and Sentry receives configured diagnostics. When a consultation uses web search, a generated search query is sent to Brave Search. Apple and Google provide device, health, location, passkey, and store services. We may also disclose information when legally required or as part of a business transfer, subject to applicable safeguards.
Retention
- Passkey challenges expire after about five minutes and login sessions after 30 days.
- Raw microphone audio is used for the live request and is not intentionally retained by Jessalyn.
- Uploaded health summaries are pruned after three years or removed when you delete them.
- Generated export files expire after 24 hours.
- Most account content remains until you delete it or ask us to handle a deletion request.
- Subscription and security records may be retained as needed for accounting, fraud prevention, disputes, or legal obligations.
Providers may retain information under their own policies and our configured service terms. Deletion from active systems may not immediately remove limited records that must be kept for security, legal, or transaction-integrity purposes.
Your choices
In the app, open Settings → Data & privacy to export available user-authored content or delete stored app content. You can disconnect or delete imported health data in Health settings, turn approximate location off, revoke operating-system permissions, and manage passkeys separately. An export file is available for a limited time.
Deleting app content does not automatically remove passkey or transaction records. ContactSupport for account-level access, correction, or deletion requests that are not available in the app.
Security and health-care status
Jessalyn uses access controls and encrypted network transport, but no system can guarantee absolute security. Jessalyn is a consumer wellness service, not medical care, and should not be used for emergencies.
Changes and contact
We may update this policy as the service or legal requirements change. We will post the new effective date here and provide additional notice when required. Send questions throughSupport.