Privacy Policy
Last updated 16 September 2026
This policy explains what the InnerMy app and the InnerMy website collect, why, and what you can do about it.
Who we are
InnerMy is made by MB „Sylvia labs“, a company registered in Lithuania (company code 307285042, VAT LT100018725314), with its registered office at J. Savickio g. 4-7, LT-01108 Vilnius, Lithuania. We are the data controller for the personal data described in this policy. You can reach us at support@innermy.com.
The short version
We collect what is needed to run your account and save your progress: your login details, the goals you pick, and which sessions you listen to. We also receive anonymous crash reports and usage statistics. We do not sell data and we do not show ads. You can delete your account and all of its data from inside the app.
Data we collect
Account information
When you create an account we store your email address and a securely hashed password, or the identifier provided by the sign-in service you chose (such as Apple or Google). We use this to log you in, keep your progress, and contact you about your account.
Your activity in the app
- The goals you select and the answers you give in the recommendation questionnaire.
- Which programs and sessions you open, how much of each session you listened to, and your listening time and completed sessions.
- Settings such as reminders and language.
We store this so the app can recommend programs, resume sessions where you stopped, and show your progress on any device you log in from.
Health-related information
Some questionnaire answers and goals can reveal information about your health or lifestyle, for example a habit you want to change. This is treated as sensitive data. We process it only with your explicit consent, which you give when you answer the questionnaire, and only to recommend and deliver programs. It is never used for advertising, never sold, and never shared with employers, insurers, or data brokers. You can withdraw consent at any time by deleting your account, which removes these answers.
Purchases
Subscriptions and purchases are processed by the Apple App Store or Google Play. They hold your payment details. We receive a confirmation of what you bought and whether your subscription is active, so we can unlock paid content. We never see card numbers.
Technical data
- Crash reports: device model, operating system version, app version, and a technical trace of the error.
- Usage statistics: aggregated, anonymous counts such as how many people open the app on a given day and which screens are used most.
- Device identifier: Firebase assigns your installation of the app a random identifier so that crash reports and statistics from the same device can be grouped. It is not linked to your name or email address and is reset when you reinstall the app.
Support messages
If you email us, we keep the conversation for as long as needed to help you and delete it within 90 days of the last message.
What we do not collect
We do not collect your location, contacts, photos, microphone or camera data, or health records. We do not use advertising identifiers and we do not show third-party ads.
Why we are allowed to use your data
Under the General Data Protection Regulation (GDPR) we rely on: performance of our contract with you (running the app and your account), our legitimate interest in keeping the app secure and working (crash reports and statistics), your consent where we ask for it (notifications, marketing emails), and legal obligations (tax and accounting records for purchases).
Who we share data with
We share data only with service providers that help us run the app. They act on our instructions, may not use your data for their own purposes, and are bound by data processing agreements. At present these are:
- Firebase (Google LLC) for authentication, secure storage of your account and progress data, crash reporting (Firebase Crashlytics), and anonymous usage statistics (Google Analytics for Firebase). Firebase processes this data on our behalf under the Firebase Data Processing Terms.
- Apple and Google for sign-in, purchases, and app distribution, under their own privacy policies.
Google LLC is located in the United States and is certified under the EU-US Data Privacy Framework; transfers are additionally covered by standard contractual clauses approved by the European Commission. We do not sell personal data and we do not share it with advertisers.
We may also disclose data if required by law, or to protect the rights and safety of users or the company. If the company is sold or merged, your data may transfer to the new owner under the same protections, and we will tell you before that happens.
Emails and notifications
We send emails about your account when needed, for example to confirm a purchase or a deletion request. We send news or offers only if you opt in, and every such email has an unsubscribe link. Push notifications are sent only if you allow them, and you can turn them off in your phone's settings at any time.
How long we keep data
Account and activity data are kept while your account exists. When you delete your account, they are removed from our systems within 30 days, except records we must keep for legal reasons (such as purchase records) and anonymous statistics that cannot identify you. Crash reports are kept for up to 12 months.
Your rights
You have the right to access, correct, delete, or restrict the processing of your personal data, to receive it in a portable format, to object to processing based on legitimate interest, and to withdraw consent at any time without affecting earlier processing. Most of this you can do yourself in the app: edit your profile, or delete your account under Profile. For anything else, email support@innermy.com and we will respond within 30 days. You can also complain to your data protection authority; in Lithuania that is the State Data Protection Inspectorate (VDAI).
Residents of California and other US states with privacy laws have similar rights, including the right to know what is collected and the right to delete it. We do not sell or share personal information as those terms are defined in the California Consumer Privacy Act.
Deleting your account
See Delete your account for step-by-step instructions.
Children
InnerMy is not directed at children. You must be at least 16 years old, or the age of digital consent in your country if higher, to create an account. If you believe a child has given us personal data, contact us and we will delete it.
Security
Data is sent over encrypted connections (TLS) and stored by Firebase with encryption at rest, with access limited to the people who need it to operate the service. Passwords are handled by Firebase Authentication and are never stored in plain text. No system is perfectly secure, so please use a strong, unique password.
This website
The InnerMy website does not use cookies, analytics scripts, tracking pixels, or third-party fonts or scripts; nothing on it is loaded from another domain. Our hosting provider keeps standard server logs (IP address, browser type, pages requested) for security purposes for up to 30 days.
Changes to this policy
If we change this policy in a meaningful way we will update the date at the top and, for significant changes, show a notice in the app. Continued use after a change means you accept the updated policy.
Contact
MB „Sylvia labs“
J. Savickio g. 4-7, LT-01108 Vilnius, Lithuania
support@innermy.com