trueform

Privacy & security.

What we store, what’s encrypted, and when AI reads your writing.

Your privacy, in plain language

Your writing is encrypted before it is saved. AI receives readable text when you use features that interpret your reflections or respond to you. This page explains that distinction and the controls available to you.

AI interpretation is part of Trueform. We explain it and ask for your explicit agreement before you begin. You can withdraw consent in Account; new reflections and AI requests then pause while existing history, export and deletion remain available. You can always disagree with an AI suggestion.

Please avoid identifying other people or adding intimate details you do not need to record. If you are under 18, a trusted adult can help you understand these choices. You never need to send us your password or private diary to ask for help.

What’s protected in storage

Your browser encrypts private writing before saving it. It decrypts that writing when you open it with an unlocked account.

InformationHow it’s stored
Reflections and summariesPrivate text, summaries and titles are encrypted. Recording dates remain readable.
Insights, assessments and Journey momentsTheir private text is encrypted. Record identifiers, links and operational information are kept so the app can load and update them.
Your ConstellationTopic names, descriptions and the meaning of relationships are encrypted, along with selected onboarding answers and earlier map text. Technical information remains readable and account-linked: record identifiers, which stars connect, categories, scores, resonance responses and dates.
Supporting evidenceCaptured passages, evidence text and review explanations are encrypted.
Feedback you submitReadable by Adam Humphrey to investigate problems and improve Trueform. Only the text and questionnaire answers you submit, your account identifier and submission date are stored. Your diary and map are not attached, and feedback is not sent to AI.
Account detailsSign-in details, account identifiers and session information are processed by the account and hosting services.

Existing accounts convert earlier map content when you next unlock them in the updated app. Until conversion completes, that content retains its earlier storage format. Backups made before conversion can retain earlier readable fields until their retention period ends.

Trueform does not encrypt every piece of information. We do not describe the service as fully zero-knowledge.

When AI receives readable text

After you agree to AI processing, saving a reflection sends its readable text through Trueform’s server to OpenAI to suggest themes and connections. Guided reflection sends the messages you submit during that conversation to generate replies. Your initial onboarding map is built from the options you select; that step does not send your answers to an AI provider.

With your AI agreement in place, when you request new Insights, a node assessment or a review of earlier Journey moments, your unlocked browser sends the relevant readable map context and saved evidence through Trueform’s server for analysis. That can include passages from your writing and their context.

Encryption protects stored content; it doesn’t hide the readable request from the AI processor. Simply browsing your saved map, Insights or Journey doesn’t start a new AI review.

Which services are involved?

Trueform uses OpenAI for AI processing, Supabase for database and authentication services, Vercel for hosting, and Resend for account emails. Microsoft 365 through GoDaddy handles the support inbox. Their processing and retention terms apply to the information they receive. Deleting something from Trueform does not instantly remove every provider log or backup.

Encryption in Trueform does not change how a provider retains information it has already processed.

Keeping access to your writing

For password-unlocked accounts, your password opens the key used for your private history. Remembered browsers keep protected material that lets them unlock it again.

Some older accounts keep their key only in the original browser. Your Account page shows which applies to you.

Restoring access to an email address is not the same as recovering an encryption key. Without your password, a working remembered browser or another recovery method you previously set up, old encrypted history may remain unreadable.

Encryption also cannot protect an already unlocked screen from someone using your device, or from malicious code running in that browser.

Your data, outside Trueform

You can download an export from Account. It contains readable private information from the account you’ve unlocked. Keep it somewhere secure.

Use Account to delete a password-unlocked account after confirming your current password. You can also remove remembered browsers there. Removal stops future server access; it cannot remotely erase a download or text already visible in another browser.

Account deletion removes the account and its stored reflections, map, Insights and Journey records from the active service. It cannot remove downloads you’ve kept elsewhere. Provider backups and logs follow their own retention schedules.

Why we use information

We use account details and the content you choose to save to provide the service you request. We use limited operational information to secure the service, prevent abuse and handle support requests. AI interpretation and guided conversation rely on your consent, including explicit consent for sensitive information you choose to submit for those purposes.

Use “Withdraw AI consent” in Account to stop future AI requests and pause new reflections. A request already underway may finish. Withdrawal does not undo processing that already happened or remove existing saved results. You can export your information or delete the account.

Your agreement, its version and withdrawal status are recorded. We do not use your writing for advertising or sell it. Trueform has no advertising trackers or public profiles. Essential browser storage supports sign-in, encryption, remembered access, preferences and encrypted drafts.

How long information stays

Your saved account information stays until you remove it or delete your account. Local encrypted writing and setup drafts expire after seven days; expiry is checked when the app next accesses them. Remembered access expires after 30 days unless renewed.

For the public waitlist, submitting the form adds the email address to the list immediately. We keep the address and its consent record until 90 days after the waitlist closes, unless you unsubscribe or ask us to delete them sooner. Short-lived anti-abuse records are deleted after two days. Unsubscribing removes the active waitlist entry immediately; only a non-identifying aggregate unsubscribe event remains.

Short-lived account-action proofs expire within ten minutes. Expired operational records are cleaned up separately. A private account identifier and deletion date is kept for 35 days, then removed by scheduled cleanup, to help prevent a restored backup from recreating a deleted account. They contain no diary text or email address.

Provider logs and backups have separate schedules. OpenAI’s standard API abuse-monitoring retention can include inputs and outputs for up to 30 days, with exceptions for law or preventing harm. We request that completions are not stored as application records; this does not disable abuse monitoring or all temporary processing. See OpenAI’s data controls.

Providers and international processing

Supabase stores the database in London. Vercel hosts the app and account service, and OpenAI processes AI requests after your agreement. Resend sends invitation and recovery emails: it receives the recipient address, message and account link, but no reflections or map content is attached. Resend sends our email from Ireland and stores email and log data in the United States for 30 days on our current plan. We do not enable email-open or click tracking. See Resend’s security and retention information. Microsoft 365 through GoDaddy processes messages you choose to send to support. These providers can process information outside the UK. A UK database location does not make all processing UK-only. Contact us for information about the provider arrangements that apply to your data.

Who operates Trueform

Adam Humphrey operates Trueform in the UK and is responsible for your personal information (the data controller). Contact support@mytrueform.app about your information or a safety concern. Notice updated: 8 October 2026. Core AI agreement v2 is unchanged.

Your rights and getting help

You can ask to access, correct or erase your personal information, restrict processing, receive a portable copy, or object where applicable. Email support@mytrueform.app. We may need a proportionate identity check. We cannot recover a lost encryption key or read material we cannot decrypt.

Children have privacy rights too. We do not automatically give a parent access to a young person’s diary. Requests involving someone else require a careful check of authority and the young person’s interests.

You can complain to the Information Commissioner’s Office. Read the terms of use.