Before the legal version, here's the short version. Everything below this section is more detail on the same five points.
The rest of this policy fills in the detail.
This Privacy Policy is published by Innermap LLC, a Florida limited liability company ("Inner Map," "we," "us," or "our"). We operate the Inner Map mobile application available on the Apple App Store and Google Play, and any related services.
You can reach us at:
This policy applies to the Inner Map mobile application and any services we provide directly through it. It explains what data we collect, how we use it, who we share it with, how long we keep it, and what rights you have.
This policy does not cover third-party services we link to (for example, crisis hotline websites). When you visit those, their own policies apply.
By using Inner Map, you agree to the practices described in this Privacy Policy.
Inner Map is intended only for users 18 years of age or older. We do not knowingly collect data from anyone under 18. During signup, you confirm that you are 18 or older.
If you believe a minor has provided us with personal information, please contact privacy@my-inner-map.com and we will promptly delete the account and any associated data.
We've designed Inner Map to collect the minimum information needed to make the app work. Specifically:
We may receive information from third parties only in these specific cases:
To make our minimization commitments explicit:
If we ever begin collecting any of the above, we will update this policy and notify you in-app before the change takes effect.
We use the information described above for these specific purposes, and no others:
| What we use | Why | Legal basis (for EU/UK users) |
|---|---|---|
| Account identifier | To recognize you across sessions and tie your map to your account | Contract performance |
| Sign-in identity & email (optional) | To sign you in, link your account across devices, help you recover it, and deliver relationship invites | Contract performance (sign-in); consent (invites) |
| Display name (optional) | To personalize the experience and surface to a connected partner | Consent |
| Conversation content | To generate AI replies and maintain session context | Contract performance |
| Inner-experience map data | To persist your work across sessions | Contract performance |
| Private journal entries | Stored locally on your device to enable journaling | Contract performance (no server processing) |
| Shared journal entries | Stored on our servers, provided to the AI as context, and analyzed for optional map suggestions you approve — when you choose to share an entry | Contract performance |
| Usage counters | To enforce rate limits and prevent abuse | Legitimate interest in service stability |
| Product usage events | To understand which features are used and improve the app (via PostHog; never includes your content) | Legitimate interest in service improvement |
| Device type / OS / version | For crash diagnostics and compatibility | Legitimate interest in service quality |
| Approximate timezone | For time-of-day features | Contract performance |
| Device push token (opt-in) | To deliver the notifications you turn on — the notification itself never contains your content | Consent |
We do not use your information for:
Product analytics. We use PostHog to understand how the app is used — which features people open, and when sessions happen — so we can improve it. These are usage events only: we never send PostHog the content of your conversations, journal entries, messages, or the parts and beliefs on your map. PostHog is not used for advertising, and it does not track you across other apps or websites.
Crash reporting. We use Sentry to capture crash and error reports so we can find and fix problems. These contain technical diagnostics only — the error type, a stack trace, and your device model and OS version. They are configured to exclude your content: no conversations, journal entries, messages, or map data, and no network request contents. Sentry is not used for advertising.
Inner Map uses these third-party providers to power its AI and voice features:
Your text-based conversations are sent to Anthropic's API to generate AI replies. Per Anthropic's API terms:
We use OpenAI for three things: transcribing your voice notes into text, generating spoken audio (such as the “hear this spoken” feature), and creating the embeddings that power the app's memory. Embeddings are numeric representations of text that let the app find and recall relevant past context; to build them, the text of your chat messages, the AI's replies, session summaries, and any journal entries you have shared is sent to OpenAI's embeddings API. (Journal entries you keep private are never sent — see below.) Per OpenAI's API terms for paid tiers:
The live voice feature (Map Voice) turns your speech into text and speaks a reply back. To do this, the audio of what you say is sent to a speech-to-text provider (Cartesia), and the text of the reply is sent to a text-to-speech provider (ElevenLabs) to generate the audio you hear. These providers process that audio or text to perform the conversion; the reply itself is written by Anthropic as described above. We do not use these providers for advertising.
When you mark a journal entry as shared, its text is included in the context sent to Anthropic (for chat) so the AI can draw on it — handled exactly like your conversation content above: not used to train any model, and not retained by Anthropic beyond its standard operational window. A shared entry is also analyzed by AI to see whether it suggests anything worth adding to your inner map; any such suggestion is sent to your in-app inbox for you to accept, edit, or decline, and nothing is added to your map automatically. (Shared entries are also embedded for memory, as described under OpenAI above.) Journal entries you keep private are never transmitted to Anthropic, OpenAI, or any other third party — they are not analyzed, embedded, or sent anywhere.
Beyond the AI providers above, a small number of services help us run Inner Map:
Each of these providers processes data only to supply its service to us, under agreements that prohibit any other use.
The encryption key is generated on your device at first launch and stored in your phone's secure keystore (Apple Keychain on iOS, Android Keystore on Android). The key never leaves your device. We do not have access to it. We cannot decrypt your private journal entries even if compelled to do so. (Entries you choose to share with the AI are stored on our servers instead — see the "On our servers" section below.)
All server-side data is stored on Railway's managed PostgreSQL with encryption at rest (AES-256). All communication between your device and our servers uses TLS (HTTPS/WSS) encryption in transit.
We've designed Inner Map with security-by-design and privacy-by-design principles. Specific measures include:
We periodically review our security practices internally. As Inner Map grows, we plan to engage external auditors for formal annual reviews.
No system is perfectly secure. We can't promise we'll never have an incident, but we can promise we'll handle one transparently and quickly.
We keep your data only as long as we have a reason to.
When you delete your account, your data is removed from our active systems immediately and from backups within 30 days.
You have the following rights regarding your data:
You can request a copy of the data we hold about you on our servers. The app has a built-in export function: Settings → Privacy → Export My Data. The export is delivered as a JSON file via your phone's share sheet (so you can save it to Files, send it to yourself via email, etc.).
The export contains your content and activity: your account and settings, conversations, inner-experience map, shared journal entries, session summaries, and usage counters. A few purely operational records are not included in the file — sign-in identity records, notification tokens, in-app inbox cards, feedback you've submitted, and the numeric memory embeddings derived from your content. If you'd like a copy of those too, email privacy@my-inner-map.com and we'll provide them. Everything — in the export file or not — is permanently removed when you delete your account.
You can delete your entire account from within the app: Settings → Privacy → Delete My Account. This removes your data from our active systems immediately. It cascades to all related records — sessions, parts, journal entries (including any you shared with the AI) and their embeddings, sign-in identity, notification tokens, your in-app inbox, feedback, and relationship data — and triggers your device to clear local encrypted storage.
Deletion is permanent. We cannot restore an account once deleted.
If something we've stored is wrong (an email address typo, for example), you can correct it via Settings, or by contacting privacy@my-inner-map.com.
If you've consented to specific uses of your data (for example, notifications you've turned on, or an email you provided for relationship invites), you can withdraw that consent at any time by turning the feature off or removing the relevant data in Settings. Turning notifications off deletes your push token from our servers.
The export function described above gives you a machine-readable copy of your data so you can move it elsewhere if you choose.
If you object to any specific processing we do (beyond what's necessary to run the app), please contact privacy@my-inner-map.com and we'll discuss what we can do.
The fastest way is in-app: Settings → Privacy has export and deletion buttons that handle most requests instantly.
For anything not handled in-app, email privacy@my-inner-map.com. We aim to respond within 7 business days, and complete your request within 30 days at the latest.
If you don't think we've handled your request appropriately, you have the right to lodge a complaint with your local data protection authority.
Inner Map is a reflection tool, not therapy. The AI is not a licensed mental health professional. It cannot diagnose, treat, or replace clinical care.
If you are in crisis or considering harm to yourself or others, please reach out to:
The Inner Map AI is configured to recognize crisis indicators and surface these resources during conversations. But the AI is not a crisis intervention service. Please reach out to a human if you need help.
Inner Map is not HIPAA-covered. We are not a healthcare provider, we do not bill insurance, and we do not have a clinical relationship with you. While we treat your data with care comparable to clinical privacy standards, we are not a "covered entity" under HIPAA.
Inner Map is not intended for users under 18. We do not knowingly collect personal data from anyone under 18.
If you are a parent or guardian and believe your child has provided personal information to Inner Map, contact privacy@my-inner-map.com and we will delete the account and associated data.
Different countries have different age thresholds for digital consent. Regardless of local law, Inner Map's product policy is 18+ only.
Inner Map is available worldwide. Our servers are located in the United States.
If you access Inner Map from outside the United States, your data will be transferred to and processed in the United States. We treat all users' data according to the same privacy standards described in this policy, regardless of where you live.
For users in the European Economic Area, the United Kingdom, Switzerland, or other regions with strict data protection laws, we apply GDPR-equivalent protections globally. See the EU/UK-specific section below for details on your rights under GDPR.
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
To exercise these rights, use the in-app tools or contact privacy@my-inner-map.com.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the EU General Data Protection Regulation (GDPR), UK GDPR, and Swiss Federal Act on Data Protection:
Legal bases for processing: We process your data based on (1) the performance of our contract with you (delivering the app's core functionality), (2) your explicit consent (for optional features like the relationship invite system), and (3) our legitimate interest in maintaining service stability and security (for usage counters, rate limiting, and crash diagnostics).
Data Protection Officer: Inner Map has designated a contact for privacy matters at privacy@my-inner-map.com. You can also write to Innermap LLC, 7100 Camino Real, Ste 302, Office 42, Boca Raton, FL 33433, United States.
Right to lodge a complaint: If you believe we have not handled your data appropriately, you have the right to lodge a complaint with your local data protection authority.
International transfers: Your data is transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) and equivalent safeguards to ensure your data receives equivalent protection.
We will respect your privacy rights to the fullest extent possible. There are a few cases where we may not be able to fully honor a request:
If we cannot fulfill a request, we will tell you why and offer an alternative where possible.
We may update this Privacy Policy from time to time. When we do:
We encourage you to review this policy periodically.
For privacy questions, data subject requests, or concerns about how we handle your information:
privacy@my-inner-map.com
For general support:
support@my-inner-map.com
For legal and compliance matters:
legal@my-inner-map.com
For everything else:
hello@my-inner-map.com
By mail:
Innermap LLC
7100 Camino Real, Ste 302, Office 42
Boca Raton, FL 33433
United States
This privacy policy was written in plain language because privacy matters and policies should be readable. If anything here is unclear, please ask — privacy@my-inner-map.com.