Privacy Policy
Last updated 24 July 2026
Balm is built so that what you write never leaves your phone. There is no account to create and nothing to sync. This policy explains exactly what stays on your device, the little that Balm does send, and who processes it.
At a glance
- No account, no sign-up, no email address required.
- Your thought records and check-ins are stored only on your device. We cannot read them.
- Balm sends anonymous usage events and crash reports — fixed labels, counts and yes/no flags, never a word of what you wrote.
- No advertising, no cross-app tracking, and nothing is sold or shared with brokers.
1. Who we are
Balm is published by Vladislavs Petkuns ("we", "us"), an independent developer. For the limited data described in section 3 we are the data controller under the EU/UK General Data Protection Regulation. You can reach us at balm.mobapp@gmail.com.
2. What stays on your device
Everything you create in Balm is written to the app's private storage on your phone:
- Thought records — the situation, your automatic thoughts, the emotions and their intensity, the evidence for and against, and your balanced response.
- Check-ins — the emotion you picked and when.
- Your settings — reminder times, language, theme and onboarding answers.
- Your app-lock PIN — held in the operating system's secure store (iOS Keychain / Android Keystore), not in the app's database.
This data is never uploaded. Balm has no backend server and no account system, so there is nowhere for it to go — no one else, including us, can read it. Removing the app removes it with it.
One thing worth knowing: if you have device backups switched on, your phone's own backup (iCloud Backup or Google's Android backup) may include Balm's data along with the rest of your apps. That backup is handled by Apple or Google under their terms and encryption, not by us. You can exclude it in your device's backup settings.
3. What Balm sends
Two things leave the app, and neither one contains anything you wrote.
Anonymous usage events
So we can see where the app confuses people and what is worth building next, Balm records events such as a thought record was started, onboarding finished, or the paywall was opened. The details attached to these events are limited by design to fixed labels from a predefined list, whole-number counts, and yes/no flags — for example which goal you tapped during onboarding (chosen from a fixed set), which emotion type a check-in used (also a fixed set), a step number, or whether a prompt was accepted. Free text is never attached to an event. The words in your records, including the situation and thoughts you describe, are never sent anywhere.
Crash reports
When Balm crashes, a diagnostic report is sent so the bug can be found and fixed. It contains the technical stack trace, your device model, operating system version and the app version — not your content.
What the analytics tools collect automatically
The same events are sent to two analytics providers — Google Firebase and PostHog — which we use to understand different things: Firebase for stability and store reporting, PostHog for which parts of the app people actually complete. Both receive the identical, content-free events described above; neither receives anything extra.
Each adds some standard information of its own: a randomly generated identifier for your app installation, device model, operating system version, language, and an approximate country derived from your IP address. These identifiers are not your name, email or advertising ID, and they are not linked to any account — reinstalling Balm generates new ones and disconnects future events from earlier ones. Alongside each event we also send three labels describing this installation: whether Premium is unlocked, your chosen theme, and your chosen app language.
PostHog processes this data on servers in the European Union. Balm does not use PostHog's session recording, which would capture what is on your screen — it is switched off in the app's configuration, not merely unused. Balm also fetches configuration values from Firebase Remote Config, which involves sending that same identifier and device information in order to receive a response.
Our lawful basis for this limited processing is legitimate interest — specifically, keeping the app working and understanding where it fails. Balm does not show ads, does not use an advertising identifier, does not ask for App Tracking Transparency permission, and does not track you across other apps or websites.
Balm does not currently include an in-app switch to turn usage analytics off. If you would rather we did not process your usage events, write to balm.mobapp@gmail.com — see section 7 on your right to object.
4. Purchases
Balm Premium is a one-time purchase. Payment is handled entirely by the app store you bought it from — Apple's App Store or Google Play — and we never see your card details, billing address or store account credentials.
RevenueCat processes the purchase receipt on our behalf so that Balm knows Premium is unlocked and can restore it if you reinstall or switch devices. RevenueCat receives an anonymous app user identifier and the receipt information from the store. Neither Apple, Google nor RevenueCat receives your thought records.
5. Who processes data for us
We use a small number of established providers. None of them receives the content you write in Balm.
| Provider | What it receives | Their policy |
|---|---|---|
| Google Firebase | Anonymous usage events, crash diagnostics, app instance identifier, device and configuration data (Analytics, Crashlytics, Remote Config). | firebase.google.com/support/privacy |
| PostHog | The same anonymous usage events, an anonymous device identifier, and the Premium / theme / language labels. Processed in the European Union. No session recording. | posthog.com/privacy |
| RevenueCat | Purchase receipts and an anonymous app user identifier. | revenuecat.com/privacy |
| Apple | Payment and purchase handling for App Store purchases; device backups if you have them switched on. | apple.com/legal/privacy |
| Google Play | Payment and purchase handling for Google Play purchases. | policies.google.com/privacy |
These providers operate internationally and may process the data described above outside your own country, including in the United States, under the safeguards set out in their respective privacy policies and data processing terms.
6. Keeping and deleting data
On your device: your records stay until you remove them. You can delete a single record at any time, erase everything at once from Settings → Delete all data, or uninstall the app — all three take effect immediately and cannot be undone by us, because we never had a copy.
Usage events and crash reports: retained by Google for the retention period configured on our Firebase project, after which they expire automatically. Crash reports are kept only as long as they are useful for fixing the underlying bug.
You can take your writing with you at any time: Settings → Export as CSV is always free, and Premium adds a formatted PDF report you can hand to a therapist.
7. Your rights
Because Balm holds no account and keeps your writing only on your device, the requests you would normally have to make to a company are things you can do yourself, instantly and without asking: read your data, export it, or delete all of it.
For the limited usage and crash data covered in section 3, and depending on where you live, you have the right to access it, correct it, have it erased, restrict or object to its processing, and receive it in a portable form. To exercise any of these, email balm.mobapp@gmail.com. Please note an honest limitation: these events are not linked to your name, email or any account, so in most cases we have no way to identify which events came from your device. Reinstalling Balm resets the identifier and disconnects future events from earlier ones.
If you are in the EU, EEA or UK, you also have the right to lodge a complaint with your local data protection authority.
California residents: we do not sell or share personal information as those terms are defined under the CCPA/CPRA, we do not use it for cross-context behavioural advertising, and we do not offer financial incentives in exchange for it.
8. Children
Balm is not directed at children. We do not knowingly collect personal information from children under 13 (or under 16 in countries where that is the applicable age). If you believe a child has provided us with information, contact us and we will delete it.
9. Security
Your records live in the app's private storage, which the operating system isolates from other apps. Your app-lock PIN is stored in the device's hardware-backed secure store, and the optional app lock keeps Balm behind Face ID, Touch ID or your PIN. The usage and crash data described above travels over encrypted connections. No system is perfectly secure, but because your writing never leaves the device, there is no server of ours to breach.
10. Changes to this policy
If this policy changes, the updated version will appear on this page with a new date at the top. Where a change materially affects how your data is handled, we will also note it in the app's release notes.
11. Contact
Questions about privacy, or about anything in this policy, go to balm.mobapp@gmail.com. We aim to reply within a few business days.