Privacy Policy
Last updated: 11 June 2026
Operated by: Cabin's independent developer, based in India ("we", "us", "I")
This policy explains what data Cabin collects from you, why, who can see it, and how to delete it.
1. Who we are
Cabin is a conversational AI app made for emotional support and reflection. It is not a medical, mental-health, or therapy service. Cabin is operated by an independent developer based in India, not (yet) a registered company. You can reach me at [email protected].
2. What we collect
2.1 Data you give us
- Phone number: to send you a one-time code (OTP) to sign in. Verification is handled by Google Firebase Authentication.
- Chat messages: what you write in Cabin, and the AI's replies.
- Onboarding answers: language preference, mood preference, what brings you to Cabin (free text).
- Preferences: theme, sound mode, ambient music on/off, proactive check-ins on/off.
2.2 Data we collect automatically
- Device push token: issued by Apple/Google to deliver Cabin's notifications to your device.
- Device metadata: OS name and version, app version, device model, locale. Used to debug crashes and tailor the experience.
- Crash and error reports: when the app crashes, we collect a stack trace, the device metadata above, and a Cabin-generated anonymous identifier. We do NOT include your chat messages in crash reports.
- Usage analytics: which screens you visit, which features you use, and aggregate counts (e.g., messages sent per day). Identified by an anonymous Cabin user identifier, NOT by phone number or message content.
- Advertising identifiers: if the app shows ads, the ad network (Google AdMob) may receive a device advertising ID. You can reset or limit this in your device settings.
2.3 What we do NOT collect
- We do not collect your contacts, photos, location, or microphone audio.
- We do not read SMS messages outside the OTP flow.
- We do not ask for your real name, email, or address. Your phone number is the only personal identifier we hold for you.
3. Why we collect it
- Provide the service: sign you in, deliver replies, send the check-in pushes you opted into.
- Personalize: remember your name, mood preferences, conversation context.
- Improve: diagnose crashes, fix bugs, understand which features people use.
- Protect: detect abuse (e.g., automated abuse, attempts to extract training data), keep the service running.
- Legal compliance: respond to lawful requests where applicable.
We do NOT use your chat content to train AI models. AI replies are generated by third-party large-language-model providers (see §4) on a per-request basis; the providers we use do not retain prompts for training under our agreements.
4. Who can see your data
| Recipient | What they see | Why |
| ------------------------------------------------------------------------------------- | ------------------------------------------------ | --------------------------- |
| Google Firebase | Phone number + OTP delivery metadata | Authentication |
| AWS (Amazon Web Services) | All app data at rest (encrypted) | Database + storage |
| Expo (push delivery) | Push token + push body | Sending notifications |
| Google FCM / Apple APNs | Push token + push body | Final notification delivery |
| Large-language-model provider (OpenAI) | Your chat messages (per request) | Generating AI replies |
| Sentry | Crash stacks + device metadata, NO chat content | Error tracking |
| PostHog | Anonymous user ID + event names, NO chat content | Product analytics |
| Google AdMob (if ads are on) | Advertising ID + device info | Ad serving |
| Cloudflare | Web hosting traffic (IP, headers) | Web app delivery |
We do not sell your data. We do not share it for cross-product behavioral advertising.
5. Where it lives and how long we keep it
- Primary storage: AWS (RDS) in the Mumbai region (ap-south-1).
- Chat messages + memory: kept until you delete your account or use "Forget this conversation" / "Delete memory" in-app.
- Crash reports: kept by Sentry for the standard Sentry retention period (typically 30 days).
- Analytics events: kept by PostHog per their default retention (typically 1 year for aggregate).
- Account-level data (phone, prefs, push tokens): kept while your account is active. When you delete your account, all of this is removed from our databases within 30 days.
6. Your rights
- Access: request a copy of your data via Settings → Export my data (uses the existing `/memory/export` flow).
- Correction: edit preferences and onboarding answers from Settings.
- Deletion: Settings → Delete my account permanently removes your data within 30 days.
- Withdraw consent: Settings → Proactive check-ins off (stops pushes), Sound / Mood toggles off, sign out anytime.
- EU / UK users: in addition, you have the right to object to processing and to data portability. Contact us at [email protected].
- India users: under the DPDP Act, you may also nominate a representative and lodge a complaint with the Data Protection Board.
7. Children
Cabin is not intended for users under 18. We do not knowingly collect data from under-18s. If you believe an under-18 has created an account, contact us and we will remove it.
8. Security
Data at rest in AWS is encrypted. Transport is TLS. Backend access is restricted to authorized personnel; we use secret stores (not plaintext files) for production credentials. No system is perfectly secure; we will notify you of any breach affecting your data per applicable law.
9. Changes
We may update this policy. Material changes will be announced in-app at least 14 days before they take effect. The latest version always lives at https://master.cabinapp.pages.dev/legal/privacy.
10. Contact
For privacy questions or to exercise your rights: [email protected].