You Are Not to Blame

Privacy Policy — You Are Not to Blame

You Are Not to Blame · app

Last updated: 2026-10-11

1. Introduction

This Privacy Policy ("Policy") describes how Bravery Academy ("we," "us," or "our") collects, uses, stores, and protects information in connection with the "You Are Not to Blame" mobile application ("App"). By installing, accessing, or using the App, you ("User," "you," or "your") acknowledge that you have read, understood, and agree to be bound by this Policy in its entirety.

If you do not agree to this Policy, you must immediately uninstall the App and cease all use.

2. Data Controller

The data controller responsible for your personal data is:

Bravery Academy
Email: hey@bravery.academy

For privacy-related inquiries, please contact us at the address above.

3. Information We Collect

3.1. Information You Provide Directly

The App collects the following categories of information that you voluntarily enter during use:

  • Session responses: text you type during the 12-step Responsibility Pie technique (descriptions of situations, thoughts, feelings, action plans).
  • Responsibility percentages: numerical values you assign to responsibility factors.
  • Mood self-assessments: numerical ratings you provide before and after practice sessions.
  • Vault password: a password you create to encrypt your session data. We do not store or have access to your password.
  • Preferences: language selection, notification settings, diagnostics consent.

3.2. Information Collected Automatically

  • Crash reports and diagnostics: if you have enabled diagnostics, anonymized crash data may be collected via Sentry for stability improvement purposes.
  • Purchase information: transaction identifiers processed through App Store / Google Play and RevenueCat for entitlement verification. We do not receive or store your payment card details.

3.3. Information We Do NOT Collect

  • We do not collect your name, email address, phone number, or physical address.
  • We do not collect device identifiers for advertising purposes.
  • We do not collect location data.
  • We do not create user accounts or require registration.
  • We do not collect biometric data.

4. How We Use Your Information

All session data (text responses, percentages, mood ratings, action plan items) is stored exclusively on your device in an encrypted vault. We use your information solely for the following purposes:

  • To provide core App functionality (the 12-step Responsibility Pie technique).
  • To encrypt and protect your session data locally on your device.
  • To process in-app purchases and verify premium entitlements.
  • To send local push notifications (daily reminders) if you enable them.
  • To improve App stability through anonymized crash reports (only with your explicit consent).

We do not sell, rent, lease, or trade your personal information to any third party for any purpose whatsoever.

5. Data Storage and Security

5.1. Local-Only Architecture

All personal session data is stored exclusively on your device. We do not operate servers that store your session content. There is no cloud backup, cloud sync, or remote storage of your practice data.

5.2. Encryption

Your session data is encrypted in a password-protected local vault. On supported native builds, new vault data uses Argon2id key derivation with AES-GCM authenticated encryption. Older vault data and fallback runtimes may use the previous PBKDF2/AES-CBC vault format with integrity protection. The vault password is never transmitted or stored in plaintext.

5.3. Secure Storage

Sensitive metadata (encryption salt and password verifier) is stored in the operating system's secure keychain (Android Keystore). General encrypted session data is stored in the application's sandboxed local storage.

5.4. Limitations

While we implement industry-standard security measures, no method of electronic storage is 100% secure. You are solely responsible for maintaining the confidentiality of your vault password and the physical security of your device. We disclaim all liability for unauthorized access resulting from your failure to protect your password or device.

5.5. Copies you choose to export

JSON session export and encrypted backup and restore are available without Pro. JSON and PDF files are not encrypted; anyone with access can read them. Encrypted backups use the vault password in use when the copy was created. Changing your vault password later does not update existing copies. You choose the destination through the system share sheet; it may be another app or a cloud provider. The app removes its temporary export files after sharing, but cannot remove copies saved elsewhere. Restoring adds sessions and skips existing IDs; notification schedules are not restored.

6. Local guidance and AI

The first release does not send session content to an AI server or Google Gemini. Remote AI is disabled in the production app. Any available local guidance is generated on your device without a network request. Enabling a remote service in a future release requires an updated privacy notice and a separate consent flow.

7. Third-Party Services

The App integrates the following third-party services:

7.1. App Store / Google Play Billing / RevenueCat
Purpose: processing in-app purchases and verifying premium entitlements.
Data shared: anonymous transaction identifiers.
Privacy policy: https://www.revenuecat.com/privacy

7.2. The first release does not send session content to an AI server or Google Gemini. Remote AI is disabled in the production app. Any available local guidance is generated on your device without a network request. Enabling a remote service in a future release requires an updated privacy notice and a separate consent flow.

7.3. Sentry
Purpose: crash reporting and stability diagnostics (only with your consent).
Data shared: anonymized crash reports, stack traces, device model, OS version.
Privacy policy: https://sentry.io/privacy

7.4. Expo Notifications
Purpose: local push notification scheduling.
Data shared: none (notifications are scheduled locally on-device).

We are not responsible for the privacy practices of third-party services. You are encouraged to review their respective privacy policies.

8. Data Retention and Deletion

8.1. Session Data

Your session data remains on your device until you delete it. You may delete individual sessions through the App's history screen, or delete all data by clearing the vault.

8.2. Uninstallation

Uninstalling the App permanently deletes all locally stored data, including encrypted sessions, vault metadata, and preferences. This action is irreversible.

8.3. Remote AI

No session content is transmitted to remote AI in this release.

8.4. Diagnostics

Local diagnostic files can be cleared through the app. If you opted into remote Sentry diagnostics, turning it off stops new reports; it does not erase reports already received. For deletion of previously sent reports and the applicable retention period, contact hey@bravery.academy.

9. Children's Privacy

The App is not directed at children under the age of 18 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. By using this App, you confirm that you meet the minimum age requirement in your jurisdiction.

If you believe a child has used the App, please contact us, and we will take appropriate steps.

10. Your Rights

10.1. General Rights

Depending on your jurisdiction, you may have the following rights:

  • Right of access: to know what personal data we process.
  • Right of deletion: to request deletion of your personal data.
  • Right to data portability: to receive your data in a structured format.
  • Right to withdraw consent: to withdraw consent at any time.
  • Right to object: to object to certain processing activities.

10.2. How to Exercise Your Rights

Because all personal data is stored locally on your device and we do not maintain copies, you exercise most rights directly through the App:

  • Access: view your session data by unlocking the vault.
  • Deletion: delete individual sessions or clear the entire vault.
  • Portability: export all sessions, including drafts and planned actions, as JSON or an encrypted backup in Settings. Restore encrypted backups there without Pro.
  • Withdraw consent: disable diagnostics at any time.

For any additional requests, contact us at hey@bravery.academy.

10.3. European Economic Area (EEA) / GDPR

If you are located in the EEA, our legal basis for processing is:

  • Consent (Article 6(1)(a)) for diagnostics.
  • Contract performance (Article 6(1)(b)) for core App functionality.
  • Legitimate interests (Article 6(1)(f)) for purchase verification.

You have the right to lodge a complaint with your local data protection authority.

10.4. California (CCPA/CPRA)

We do not sell or share personal information as defined under the CCPA/CPRA. We do not use personal information for cross-context behavioral advertising.

11. International Data Transfers

The first release does not send session content to an AI server or Google Gemini. Remote AI is disabled in the production app. Any available local guidance is generated on your device without a network request. Enabling a remote service in a future release requires an updated privacy notice and a separate consent flow.

12. Changes to This Policy

We reserve the right to update this Policy at any time. Changes will be reflected by updating the "Last updated" date. Continued use of the App after changes constitutes your acceptance of the revised Policy.

For material changes that significantly affect your rights, we will provide notice within the App before the changes take effect. If you do not agree with the updated Policy, you must uninstall the App.

13. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy, please contact:

Bravery Academy
Email: hey@bravery.academy

We will make commercially reasonable efforts to respond within 30 days.