HerIdentity Privacy Policy
Effective and last updated: September 10, 2026
HerIdentity is an identity practice that helps users reflect, make aligned decisions, and build evidence of self-trust. This Privacy Policy explains what information HerIdentity collects, how it is used and shared, and the choices available to users. Reading this policy or accepting the Terms of Use does not grant consent for Personalized AI Coach.
1. Age requirement
HerIdentity is intended for people age 13 and older. We do not knowingly collect personal information from children under 13. If we learn that information from a child under 13 was collected, contact us so we can investigate and delete it as required.
2. Information we collect
We collect information that users provide, create, or generate while using HerIdentity:
- Account information: name, email address, authentication information, account identifiers, and settings.
- Identity Pattern Assessment: assessment answers, results, selected secondary pattern, Current Focus, and assessment history.
- Journal and reflection content: journal entries and written reflections a user chooses to create. HerIdentity does not currently collect voice recordings.
- Daily practice information: Daily Identity Decisions, commitments, follow-through, Evidence entries, progress information, and related reflections.
- Identity Declaration: the life a user is creating, identity choices, values and standards, refusals, and boundaries.
- Method and Decision Filter: story titles, story content, mapped pattern names, reframes, and decision-filter responses.
- Coach information: Guided Coach and Personalized AI Coach messages and responses.
- Sisterhood information: content and interactions a user chooses to share in Sisterhood features.
- Subscription information: product, transaction, entitlement, renewal, and purchase-status information needed to recognize HerLab access. HerIdentity does not receive full payment-card details.
- Technical and support information: device, browser, app version, request, error, security, and diagnostic information needed to operate and protect the service, plus messages and attachments a user sends to Support.
3. How we collect and use information
Information is collected when a user creates or signs in to an account, completes forms or assessments, writes practice content, uses app features, makes a purchase, or contacts Support. Technical information is generated when the app communicates with HerIdentity services.
We use this information to:
- Provide, synchronize, personalize, and secure the HerIdentity experience.
- Preserve a user's practice history and display requested progress or Current Focus information.
- Authenticate accounts, prevent abuse, diagnose errors, and maintain service reliability.
- Recognize HerLab subscription access and respond to purchase or account questions.
- Respond to support, privacy, access, and deletion requests.
- Comply with legal obligations and enforce applicable terms.
HerIdentity does not sell personal information or use private practice activity for advertising or cross-context behavioral tracking. Service providers receive information only as needed for the functions described here. Supabase supports authentication and app data storage; Apple may process native purchases; RevenueCat processes subscription and entitlement status; Replit supports application hosting, private file storage, and the managed AI integration; and OpenAI receives only the consented AI information described below.
Google Sign-In is optional. If a user chooses it, Google processes the OAuth sign-in and provides authentication identity information, such as the user’s email address and provider account identifier, to Supabase and HerIdentity. HerIdentity does not send private practice content to Google.
The Identity Pattern Assessment is hosted by Interact. Interact sends HerIdentity only the email entered for the assessment and the final Primary Pattern result tag so the result can be matched to the user’s account. Raw assessment answers are not sent to HerIdentity through this result-delivery connection.
4. Personalized AI Coach data sharing
Personalized AI Coach is HerIdentity's only feature that sends personal data to an external artificial-intelligence service. Guided Coach runs locally on the user’s device, and HerLab’s website assistant runs locally in the browser; neither sends content to an external AI provider. Personalized AI Coach is optional. Before HerIdentity sends any data for this feature, the app presents a separate disclosure and asks the user to choose Allow AI Processing. Opening Coach, accepting the Terms of Use, or accepting this Privacy Policy does not grant that permission.
HerIdentity uses OpenAI, L.L.C., accessed through Replit, Inc.'s managed OpenAI integration, to generate the personalized Coach response requested by the user. The shared information is associated with the authenticated HerIdentity user so the service can assemble the correct consented context, but HerIdentity excludes the user's name and email address from the AI provider payload. The information is used for app functionality, not advertising or tracking.
After the user grants the current disclosure, HerIdentity may send:
- The current Coach message.
- Up to 12 earlier Coach messages and assistant replies created after the current consent.
- The identity declaration, including the life she is creating, who she chooses to be, values and standards, what she refuses to keep performing, and boundaries.
- The latest post-consent Identity Pattern assessment, selected secondary pattern, and Current Focus.
- Up to six recent post-consent mapped Method story titles and pattern names.
- Up to six recent post-consent Evidence entry texts and their Current Focus.
HerIdentity does not send journals, daily decisions or commitments, Witness details, name, email address, payment information, raw quiz answers, unmapped Method stories, or Coach/history/pattern/Evidence records from before the current consent to OpenAI.
HerIdentity checks the current consent before loading eligible context and again immediately before provider dispatch. OpenAI states that business and API data is not used to train its models by default. Standard API abuse-monitoring systems may retain submitted inputs and generated outputs for up to 30 days unless approved shorter-retention or Zero Data Retention controls apply. HerIdentity does not represent that Zero Data Retention is enabled. OpenAI may use automated safety classifiers, and limited retention exceptions may apply for security or legal obligations. Replit states that data sent through its managed AI integrations follows the selected provider's retention policies.
HerIdentity extends its privacy protections to this processing through explicit consent, data minimization, authenticated access controls, encryption in transit, purpose limitation, no advertising/tracking use, OpenAI's business-data training controls, and the retention limits described above.
A user may choose Not Now and continue using HerIdentity's non-AI features and local Guided Coach. Declining does not save or send the drafted message to OpenAI. Consent can later be granted or withdrawn in Settings → Privacy → AI Data Sharing. Withdrawal immediately blocks new Personalized AI Coach transmissions while preserving non-AI access. A materially changed provider or materially changed shared-data category requires a new consent disclosure.
5. Subscriptions and purchases
Apple processes native in-app purchases under its own payment and privacy terms. RevenueCat processes purchase status, product and transaction identifiers, and entitlement information so HerIdentity can recognize HerLab access across supported platforms. HerIdentity does not receive full payment-card numbers from Apple or RevenueCat.
6. Security and retention
HerIdentity uses reasonable administrative and technical safeguards, including authenticated requests, access controls, and encryption in transit, to protect information against unauthorized access, loss, alteration, or disclosure. No method of transmission or storage can be guaranteed completely secure.
Account and practice information is retained while the account is active and as needed to provide the service, resolve disputes, enforce agreements, protect security, or meet legal obligations. Deleted information may remain temporarily in backups or provider systems subject to applicable retention schedules. Personalized AI Coach data is also subject to the OpenAI and Replit practices described above.
7. Your privacy choices and rights
Depending on location and applicable law, users may request access to, correction of, export of, or deletion of personal information, and may object to or restrict certain processing. Users may update account information in the app, manage AI permission in Settings, and contact Support for privacy requests. HerIdentity does not discriminate against users for exercising applicable privacy rights.
HerIdentity may need to verify the requester's identity before completing a request. Some information may be retained when required for security, fraud prevention, legal compliance, or establishing, exercising, or defending legal claims.
8. California privacy rights
California residents may request information about categories and specific pieces of personal information collected, sources, purposes, categories of third parties to whom information is disclosed, and may request correction or deletion where applicable. HerIdentity does not sell personal information or share it for cross-context behavioral advertising. California users may exercise applicable rights by contacting Support and may use an authorized agent where permitted by law.
9. Account deletion and provider requests
Users can start account deletion from the app's account settings. The deletion flow removes the HerIdentity-held profile and practice records covered by that flow and then deletes the associated authentication account. Provider-held information remains subject to the provider's applicable retention and deletion processes.
Contact Support to request access to or deletion of HerIdentity-held information, or to ask for help regarding information processed by OpenAI, Replit, Supabase, Apple, or RevenueCat. We will route or respond to a provider-related request as applicable.
10. Policy updates and contact
We may update this Privacy Policy to reflect changes in the product, providers, or legal requirements. The effective date above identifies the current version. A materially changed AI provider or shared-data category requires a new in-app AI consent disclosure before new transmissions.
For questions or privacy requests, email support@heridentityapp.com.
© 2026 HerIdentity. This Privacy Policy does not change the Terms of Use.
