privacy
the short version: we collect the minimum to run your practice, we never sell it, and you can delete all of it yourself.
last updated 31 August 2026
what we collect
- Your email, to sign you in. If you choose a password it's handled entirely by our authentication provider using standard hashing — we never see it, and our own database has no password column.
- What you save — sessions you keep, recently played sessions, and any affirmation lines you write.
- Felt-sense check-ins — the optional 1–5 rating before and after a session. Skipping is a fully supported choice, not a degraded one.
- Practice history — that you completed a session and which pillar it belonged to. This is what powers your own progress view.
- Voice recordings and journal entries, if you make them — stored privately, reachable only through short-lived signed links we generate per play.
- Minimal technical data — IP address and basic browser information, for security and to diagnose errors. We use one functional cookie to keep you signed in. No advertising, no tracking pixels, no third-party analytics.
- A count of sessions, if you use Retune without an account — we store a random identifier in your browser and a count of how many sessions were started and finished. That is the whole record: no content, no email, no IP address kept against it, and nothing that identifies you. It exists so we can tell whether the app is useful to people who haven't signed up. Clearing your browser data erases it.
what we never do
- We never sell or rent your personal data, to anyone, for any reason.
- We never use your voice to train shared or general-purpose models.
- We never share your recordings or journal entries with anyone, including other users.
- We don't track your location, contacts or camera. Microphone access happens only when you start a recording yourself.
who processes it for us
Only the providers needed to run the service, each under their own data-processing terms:
- Supabase — database, sign-in, and private file storage.
- Vercel — hosting.
- OpenAI — turning affirmation text into speech.
- Stripe — payments. We never receive your card details.
- Sentry — error reports when something breaks. Not analytics, and never your practice content.
- Resend — delivering feedback you send us.
why we're allowed to (UK/EU users)
- Running your account and saving your practice — performing the contract you asked for.
- Voice recordings and the journal — your explicit consent, withdrawable by deleting them.
- Security and abuse prevention — legitimate interest, limited to what keeps the service safe.
- Payments — performing the contract.
how long we keep it
- Delete a recording or journal entry yourself, any time. It's immediate and permanent — the audio and anything generated from it go together, with no grace period.
- Delete your whole account from your account settings. It removes your profile, saved sessions, recents, check-ins, practice history and all voice data in one action, and cancels any membership. We keep only what the law requires, such as financial records of completed payments.
- Recents age out automatically past the most recent eight.
- Otherwise we keep your practice data while your account is active — it exists to show your own history back to you.
your rights
Wherever you are, you can access a copy of your data, correct it, export your saved sessions, or delete everything. In the UK/EU you can also restrict or object to certain processing, ask for portability, and complain to the Information Commissioner's Office if you think we've mishandled something.
To exercise any of these, email hello@retune.fm — though deletion you can simply do yourself.
children
Retune isn't directed at anyone under 16, and we don't knowingly collect their data. If we learn we have, we'll delete it.
security
Encryption in transit, access controls scoped so each account can only reach its own rows, and private-only storage for anything sensitive — voice and journal audio isn't reachable by guessing a URL, because every access needs a short-lived signed link generated per request. No system is perfectly secure, but the design limits what could go wrong.
changes
If we change this materially we'll let you know before it takes effect, rather than quietly editing the page.