Privacy Policy

Last updated: 11 June 2026

Operated by: Cabin's independent developer, based in India ("we", "us", "I")

This policy explains what data Cabin collects from you, why, who can see it, and how to delete it.

1. Who we are

Cabin is a conversational AI app made for emotional support and reflection. It is not a medical, mental-health, or therapy service. Cabin is operated by an independent developer based in India, not (yet) a registered company. You can reach me at [email protected].

2. What we collect

2.1 Data you give us

2.2 Data we collect automatically

2.3 What we do NOT collect

3. Why we collect it

We do NOT use your chat content to train AI models. AI replies are generated by third-party large-language-model providers (see §4) on a per-request basis; the providers we use do not retain prompts for training under our agreements.

4. Who can see your data

| Recipient | What they see | Why |

| ------------------------------------------------------------------------------------- | ------------------------------------------------ | --------------------------- |

| Google Firebase | Phone number + OTP delivery metadata | Authentication |

| AWS (Amazon Web Services) | All app data at rest (encrypted) | Database + storage |

| Expo (push delivery) | Push token + push body | Sending notifications |

| Google FCM / Apple APNs | Push token + push body | Final notification delivery |

| Large-language-model provider (OpenAI) | Your chat messages (per request) | Generating AI replies |

| Sentry | Crash stacks + device metadata, NO chat content | Error tracking |

| PostHog | Anonymous user ID + event names, NO chat content | Product analytics |

| Google AdMob (if ads are on) | Advertising ID + device info | Ad serving |

| Cloudflare | Web hosting traffic (IP, headers) | Web app delivery |

We do not sell your data. We do not share it for cross-product behavioral advertising.

5. Where it lives and how long we keep it

6. Your rights

7. Children

Cabin is not intended for users under 18. We do not knowingly collect data from under-18s. If you believe an under-18 has created an account, contact us and we will remove it.

8. Security

Data at rest in AWS is encrypted. Transport is TLS. Backend access is restricted to authorized personnel; we use secret stores (not plaintext files) for production credentials. No system is perfectly secure; we will notify you of any breach affecting your data per applicable law.

9. Changes

We may update this policy. Material changes will be announced in-app at least 14 days before they take effect. The latest version always lives at https://master.cabinapp.pages.dev/legal/privacy.

10. Contact

For privacy questions or to exercise your rights: [email protected].