Privacy Policy
Effective Date: August 1, 2026 · Last updated: October 3, 2026
BE THE ONE ("we", "us", or "our") operates the BE THE ONE mobile application and the website at bethe.one. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
1. Information We Collect
Account Information: When you create an account, we collect your name, email address, and authentication credentials through Apple Sign-In or Google Sign-In. We store a unique user identifier provided by Firebase Authentication.
Profile Information: You may optionally provide a profile photo, display name, country of residence, and personal preferences during onboarding.
Activity Data: We collect data about your use of the app, including ritual completions, session durations, experience points (XP), streak history, goals, affirmations, and journal entries you create.
Health Data: With your explicit permission, we access Apple HealthKit data (workout duration, active energy) to integrate with your rituals. Health data is stored locally on your device and is never transmitted to our servers or shared with third parties.
AI Conversations: When you use Higher Self, BeTheOne sends your message and only the selected context needed for the conversation to an approved AI provider. Anthropic and OpenAI are the only approved Higher Self providers; Anthropic is currently the only active production route. BeTheOne separately stores conversation history and memories according to its conversation, memory, export, and deletion controls. Higher Self processing is not end-to-end encrypted because BeTheOne and the active provider must process readable request content.
Social Features: If you use community features (feed, likes, comments), your display name, activity summaries, and interactions are visible to other users and stored in our database.
Device and Usage Data: We collect crash reports, performance metrics, and usage analytics to improve the app. Some records use device or account identifiers; these are not all anonymous.
Discipline self-check and email reports / Disziplin-Test
When you request a discipline report, we process your email address and 13 answers to calculate and send the report you requested. Answers remain in your browser until you submit the report form. Our server uses the answers to generate the report but does not store the individual answers or raw score in the report log. Resend processes your recipient address and the generated email, not the individual answers. Report delivery is a requested service; optional newsletter marketing uses your separate consent and email confirmation.
We keep pseudonymous request fingerprints, recipient/IP hashes, timestamps, provider message IDs and delivery-status events for reliability, duplicate prevention and abuse protection. These events do not contain your email address, answers or score and are not sent to advertising analytics or session replay. Operational report records are retained for up to 90 days. If you separately choose the newsletter, your address and consent are stored in our existing subscriber system; you can unsubscribe at any time through the link in newsletter emails. Existing confirmed subscriptions remain unchanged.
Wenn du deinen Bericht anforderst, verarbeiten wir deine E-Mail-Adresse und 13 Antworten für die Berechnung und den Versand. Resend erhält deine Adresse und den erstellten Bericht, nicht die einzelnen Antworten. Wir speichern keine Einzelantworten oder Punktzahlen im Versandprotokoll. Für den Newsletter ist eine zusätzliche Einwilligung und Bestätigung per E-Mail erforderlich; du kannst dich jederzeit abmelden. Pseudonyme Versand- und Missbrauchsschutzdaten werden höchstens 90 Tage aufbewahrt. Fragen oder Löschanfragen: [email protected].
Article workbooks by email / Arbeitshefte per E-Mail
The interactive article worksheets keep your written notes and optional planner date on the current page only. We do not save them to browser storage or send them to our server or analytics. They are not included in the workbook email. Copy and print buttons transfer your notes only when you choose; save them yourself before reloading or closing the page.
Die interaktiven Arbeitsblätter behalten deine schriftlichen Notizen und das freiwillige Planungsdatum nur auf der aktuellen Seite. Wir speichern sie nicht im Browser-Speicher und senden sie weder an unseren Server noch an Analyse-Dienste. Sie sind nicht in der Workbook-E-Mail enthalten. Kopieren und Drucken erfolgt nur auf deine Auswahl; sichere deine Notizen selbst, bevor du die Seite neu lädst oder schließt.
When you request an article workbook, we use your email address, the selected article and its language to send one email through Resend. Your on-page exercise choices and personal notes are not sent to us. To avoid duplicate emails after an interrupted request, we temporarily retain the recipient address and exact email content in a delivery payload. Payloads are scheduled for removal after 24 hours, request records after seven days, and pseudonymous operational events after 90 days; cleanup runs hourly while the service is running. Operational records include hashed recipient/IP identifiers, request IDs, timestamps, provider message IDs and sending or newsletter-confirmation status.
The form keeps a retry ID and an email digest, not the raw email address, in this browser tab’s session storage. Request, sending-acceptance and error analytics contain the article and language, not your email or exercise choices. A sending-acceptance event does not prove inbox delivery. The workbook does not require newsletter membership. Only if you separately select the newsletter option do we start the existing email-confirmation process; an existing confirmed subscription remains unchanged. Newsletter emails provide an unsubscribe link. Questions or deletion requests: [email protected].
Wenn du ein Arbeitsheft anforderst, verwenden wir deine E-Mail-Adresse, den gewählten Artikel und die Sprache für eine einmalige E-Mail über Resend. Deine Übungsauswahl und persönlichen Notizen werden nicht an uns gesendet. Für sichere Wiederholungsversuche speichern wir die Empfängeradresse und den genauen E-Mail-Inhalt vorübergehend: Diese Versanddaten werden nach 24 Stunden, Anfrageprotokolle nach sieben Tagen und pseudonyme Betriebsereignisse nach 90 Tagen zur Löschung vorgesehen. Die Bereinigung läuft stündlich, solange der Dienst läuft. Dazu gehören gehashte Empfänger- und IP-Kennungen, Anfrage- und Nachrichten-IDs, Zeitpunkte sowie Versand- und Newsletter-Status.
Im Sitzungsspeicher dieses Browser-Tabs bleiben eine Wiederholungs-ID und ein E-Mail-Hash, nicht die lesbare Adresse. Analyseereignisse enthalten Artikel und Sprache, keine E-Mail-Adresse oder Übungsauswahl. Die Annahme zum Versand ist kein Nachweis der Zustellung im Posteingang. Das Arbeitsheft erfordert kein Newsletter-Abo. Nur mit deiner gesonderten Auswahl starten wir die E-Mail-Bestätigung für den Newsletter; bestehende bestätigte Abos bleiben unverändert. Du kannst dich über den Link in Newsletter-E-Mails abmelden.
Website marketing cookies / Marketing-Cookies
If you choose “Allow marketing” in our website cookie settings, we load the Meta Pixel (ID 1644641617172700) to measure page visits, early-access signups and confirmed registrations, and to understand how well our Facebook and Instagram ads work. Meta receives the event, page address, browser/device information, IP address and cookie identifiers, and may associate them with your Meta account. We do not send your signup email, form answers or assessment scores to this pixel. Automatic event detection and automatic advanced matching are disabled in our installation.
The pixel remains off until you opt in. Use “Cookie settings” on our public pages to decline or withdraw permission at any time. We remember your choice for 180 days. With permission, Meta may set its advertising cookies, including _fbp and _fbc. Declining stops our pixel events and removes those first-party cookies. Withdrawal does not erase data already received by Meta. Email/newsletter consent is separate from this optional marketing-cookie choice. Meta Privacy Policy.
Nur mit deiner Auswahl „Marketing erlauben“ laden wir den Meta Pixel zur Messung von Seitenbesuchen sowie abgeschickten und bestätigten Anmeldungen. Meta erhält Ereignis-, Seiten-, Browser-, IP- und Cookie-Daten und kann diese deinem Meta-Konto zuordnen. Wir übermitteln keine E-Mail-Adresse, Formularantworten oder Testergebnisse. Über „Cookie-Einstellungen“ kannst du jederzeit ablehnen oder widerrufen. Deine Auswahl speichern wir 180 Tage. Newsletter-Einwilligung und Marketing-Cookies sind voneinander unabhängig.
Optional app screen recordings
Where this option is available, you can choose to share masked recordings of selected introductory onboarding screens with Mixpanel to help us find navigation problems. The choice is off by default and separate from coaching, email and website-cookie consent. We sample 10% of eligible sessions and mask text, images, maps and web content. Authentication, personal onboarding answers, Higher Self conversations, journals, private messages, health and payment screens are excluded from recording. We do not record your microphone or camera.
You can withdraw permission in the app’s Settings at any time. This stops new recording; it does not erase recordings already received by Mixpanel. The choice applies to the current account on that device and resets on sign-out. Recordings are linked to your account identifier and processed in our Mixpanel project in the United States. Account-erasure requests include associated Mixpanel data and are processed separately from deletion of live app data. Recording remains disabled until the relevant app release and privacy checks are complete.
Website analytics / Website-Analyse
The same optional marketing-cookie choice also controls Google Analytics 4 (measurement ID G-XRN08DNLLW), Microsoft Clarity (project xmvjuu8slg) and website performance measurements. These shared integrations do not load before you choose “Allow marketing”. On permitted public pages, Google Analytics measures visits and events, including page language and approved campaign parameters; Clarity records session interactions to help us understand how the website is used. Providers may process page, browser/device and cookie data, and receive your IP address through network requests. Our shared loader excludes signup, token, private and assessment pages. Google advertising storage, Google signals and advertising personalization remain disabled even when analytics is allowed.
After a newly completed email confirmation, a single-use, consent-gated server receipt can authorize one Google Analytics sign_up event with the method “email” and page language. The event does not include your email address, subscriber ID, confirmation token, answers or scores. Merely opening or refreshing the success page does not authorize another registration event; Clarity, performance measurements and a Google page-view event do not run on that page. Cookie settings let you decline or withdraw this optional permission, separately from newsletter consent. Your choice is remembered for 180 days. Withdrawal disables these integrations and clears their first-party analytics cookies, including _ga, _ga_*, _gid, _gat*, _clck and _clsk; it does not erase data the providers already received. Clarity can resume on a later page navigation after renewed consent.
Dieselbe freiwillige Auswahl für Marketing-Cookies steuert auch Google Analytics 4 (Mess-ID G-XRN08DNLLW), Microsoft Clarity (Projekt xmvjuu8slg) und die Messung der Website-Leistung. Diese gemeinsamen Integrationen laden erst nach deiner Auswahl „Marketing erlauben“. Auf freigegebenen öffentlichen Seiten misst Google Analytics Besuche und Ereignisse einschließlich Seitensprache und zulässiger Kampagnenparameter; Clarity zeichnet Sitzungsinteraktionen auf, um die Nutzung der Website zu verstehen. Die Anbieter können Seiten-, Browser-/Geräte- und Cookie-Daten verarbeiten und erhalten über Netzwerkanfragen deine IP-Adresse. Unser gemeinsamer Loader schließt Anmelde-, Token-, private und Testseiten aus. Google-Werbespeicherung, Google signals und personalisierte Werbung bleiben auch bei erlaubter Analyse deaktiviert.
Nach einer neu abgeschlossenen E-Mail-Bestätigung kann eine einmal verwendbare, einwilligungsabhängige Serverbestätigung ein Google-Analytics-Ereignis sign_up mit der Methode „email“ und der Seitensprache auslösen. Es enthält keine E-Mail-Adresse, Abonnenten-ID, Bestätigungstoken, Antworten oder Punktzahlen. Das bloße Öffnen oder Neuladen der Erfolgsseite erlaubt kein weiteres Registrierungsereignis; Clarity, Leistungsmessungen und ein Google-Seitenaufruf laufen dort nicht. Über die Cookie-Einstellungen kannst du diese freiwillige Erlaubnis unabhängig von der Newsletter-Einwilligung ablehnen oder widerrufen. Deine Auswahl wird 180 Tage gespeichert. Ein Widerruf deaktiviert diese Integrationen und entfernt ihre eigenen Analyse-Cookies, darunter _ga, _ga_*, _gid, _gat*, _clck und _clsk; bereits bei den Anbietern eingegangene Daten werden dadurch nicht gelöscht. Clarity kann nach erneuter Einwilligung bei einer späteren Seitennavigation wieder starten.
2. How We Use Your Information
- To provide, maintain, and improve the app and its features
- To personalize your experience (AI coaching, ritual suggestions, gamification)
- To sync your progress across devices
- To send account and community service email, including generic friend accountability alerts, enabled at registration and switchable off in app Settings or through the unsubscribe link in each message
- To send push notifications you have opted into (reminders, streaks)
- To analyze usage patterns and fix bugs (including analytics linked to pseudonymous identifiers)
- To enforce our Terms of Service and moderate community content
3. Third-Party Services
We use the following third-party services that may process your data:
- Amazon Web Services (AWS) — API hosting, app databases, file storage, encrypted backups and operational logs.
- Resend — Account and service email delivery, including delivery, bounce and suppression records.
- Firebase (Google) — Authentication, cloud database (Firestore), crash reporting (Crashlytics), analytics, and push notifications (Cloud Messaging). Firebase Privacy Policy
- Mixpanel — Product analytics and session replay to understand how users interact with the app. We do not collect advertising identifiers (IDFA). Mixpanel Privacy Policy
- Anthropic and OpenAI — The only approved AI providers for Higher Self. Anthropic is the current production route; OpenAI is an inactive evaluation candidate. BeTheOne does not enable provider use of Higher Self API data for model training or provider-managed conversation storage. OpenAI Higher Self requests use
store: false. Under standard API terms, provider API content may be retained for up to 30 days, with limited safety, legal, abuse-prevention, and feedback exceptions. Anthropic retention details · OpenAI data controls · How Higher Self works - Apple HealthKit — Health data integration, accessed only with your explicit permission and processed entirely on-device.
4. Data Storage and Security
The iOS app stores data locally using Apple's SwiftData framework. Account data is also stored in AWS DynamoDB and S3; Firebase provides authentication and holds some older or shared records. Data is encrypted in transit and at rest. Authentication tokens are stored in the iOS Keychain with the kSecAttrAccessibleWhenUnlockedThisDeviceOnly protection class.
We implement Firebase App Check to prevent unauthorized API access and use HTTPS for all network communication.
5. Account deletion, inactivity and retention
Delete your account
In the iOS app, open Settings > Delete Account. You can also sign in on the web and choose Delete Account in Settings, without reinstalling the app. Use the same Apple or Google account you registered with. We ask you to confirm the deletion and may require a fresh sign-in. If you cannot access your account, email [email protected]. We will verify ownership before deleting it; do not send your password.
After confirmation, deletion starts immediately. There is no cooling-off period or account recovery after deletion begins. Access and new writes are blocked while the service removes your account. Most live app data is removed during that request. Interrupted work is retried automatically; if you see an error, deletion may already be in progress. Contact support if it has not finished within 24 hours.
Deletion removes your authentication account, linked app identities, profile, progress, saved app content, uploaded files, notification tokens, and your authored or received community records from our live app stores. Export anything you need before confirming. Some shared records, such as a redeemed invitation, are kept without your identifying fields to prevent reuse. Removing your account does not remove copies another person already downloaded or messages delivered outside BeTheOne.
We remove personal records rather than merely hiding your profile. Analytics that still contain a user identifier are pseudonymous, not anonymous, and require separate erasure. Truly anonymous totals may remain. Requests to erase identified data held by analytics providers are tracked separately from live app deletion; Mixpanel states that its deletion processing can take up to 30 days. Google Analytics acknowledges requests separately and applies its own deletion schedule.
Subscriptions
A current paid subscription or lifetime access prevents automatic deletion for inactivity. Uncertain billing status also blocks automatic deletion until it is checked. You can still explicitly delete a paid account. Deleting an account does not cancel a subscription billed by Apple or another payment provider: manage Apple subscriptions here, or cancel through the provider that bills you, to stop future charges. Deletion does not create a refund. Payment providers may retain transaction records under their own legal obligations.
Taking a break
There is no separate temporary-deactivation mode. Signing out, uninstalling the app, or switching off emails does not delete your account or cancel a subscription. Your data remains subject to the inactivity policy below. Returning before deletion begins keeps the account.
Signup and return reminders
When account service email is enabled, an unfinished signup can receive one completion reminder after at least a day without recorded activity, during the first 14 days. A user who stops using the app can receive up to three return reminders, around days 1, 3 and 7 of that lapse. Returning resets that reminder sequence. These reminders follow consent, suppression, frequency and delivery checks; they do not mean your account is about to be deleted. They are separate from the three deletion warnings below.
Inactive accounts and warning emails
We count an account as inactive after 30 days without recorded use; this label does not restrict access or start deletion. After 12 calendar months of observed inactivity, an eligible unpaid account enters a warning period. We send three warning emails: at least 30 days, 14 days, and 7 days before deletion. Each warning states the earliest deletion date. Delivery delays extend that date; we do not shorten the notice period.
Signing in and using BeTheOne before deletion begins cancels the warning sequence and restarts the inactivity period. Use the same sign-in account, and connect to the internet so activity can reach our service. Opening an email alone does not count. You can ask support to pause deletion while an ownership, export, billing, or deletion request is being resolved.
We do not automatically delete an account when billing or activity cannot be verified, an email address cannot be verified, warnings cannot be delivered, service emails are switched off, or a support hold applies. Those accounts require review. Linked identities also require verified activity and billing coverage. Existing accounts receive a full observation period from this policy's activation; old or missing login history is not used to backdate deletion.
Backups, devices and limited retained records
Deletion from live stores does not instantly rewrite disaster-recovery backups. AWS app-database recovery copies expire within 30 days. Firestore scheduled backups and object-storage recovery copies follow their configured expiry periods. Deleted data must be removed again before a backup is restored to service. Account erasure removes all accessible versions of account-owned uploads; provider soft-delete windows may still apply.
We retain restricted deletion markers so an old device or restored backup cannot recreate a deleted account. Security or abuse reports, payment records, and records needed for a specific legal obligation or dispute are handled separately and limited to that purpose. Support can explain which exception applies to a request. They are not used to restore your profile or send marketing.
Deletion on one device cannot remotely erase an offline device, a personal export, or a device backup you control. The iOS deletion flow clears account-owned local data when it can establish ownership. If a damaged or recovered local archive has uncertain ownership, the app may require support rather than erase another person's data. Uninstall the app and remove personal exports or backups you no longer want.
6. Your Rights
You have the right to:
- Access your data — use the Export Data feature in Settings
- Delete your account and associated data, subject to the limited retention described above — use Delete Account in Settings
- Opt out of analytics — disable analytics in your device settings
- Opt out of account and community service email — turn it off in app Settings or use the unsubscribe link in any message
- Withdraw consent for HealthKit — revoke access in iOS Settings > Health
- Withdraw consent for notifications — disable in iOS Settings
Account and community service email does not include product-education or marketing email. Those categories remain off unless a separate lawful basis and user control are provided.
If you are a resident of the European Economic Area (EEA), you have additional rights under GDPR, including the right to data portability, rectification, and the right to lodge a complaint with a supervisory authority.
If you are a California resident, you have rights under the CCPA, including the right to know what personal information is collected, the right to delete, and the right to opt out of the sale of personal information. We do not sell your personal information.
7. Children's Privacy
Our services are not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected data from a child under 13, please contact us and we will promptly delete it.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the effective date. Your continued use of the app after changes constitutes acceptance of the updated policy.
9. Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
Email: privacy@bethe.one
Website: bethe.one