Your journal is yours.
reThinked is operated by reThinked ("reThinked", "we", "us"), based in Malaysia. We are the data controller for the personal data described in this policy. This policy explains what we collect, why, who processes it, and the rights you have. It is written to comply with Malaysia's Personal Data Protection Act 2010 (PDPA), as amended, and other applicable data protection laws. A Bahasa Malaysia version is available at rethinked.my/privasi — you may rely on either.
This Privacy Policy is part of our Terms of Service.
- ✓Your journal is yours. Your decisions, reflections, habits and photos belong to you, and they are private by default.
- ✓No ads. No selling. No third-party tracking. We do not sell personal data, show advertising, or embed any third-party analytics or ad-tracking SDKs in the app.
- ✓AI runs on your content, for you. AI features send the relevant content to our AI providers (Anthropic; OpenAI for voice transcription) to generate your reflections and recaps. Under both providers' API terms, your content is not used to train their models.
- ✓Health data is read-only, never written, never used for advertising.
- ✓You control what's shared. Location is off by default; community posts, buddy sharing and public links only happen when you choose them — and this policy tells you exactly who sees what.
- ✓Questions or requests: rethinked.my@gmail.com (mark data-protection requests "PDPA Request").
Who we are
reThinked is a private decision journal and habit companion. Our servers and database are hosted in Malaysia. You can reach us at rethinked.my@gmail.com, Malaysia.
What we collect
Obligatory vs voluntary. Your email address, password, display name and date of birth are obligatory — we cannot create or operate your account without them. Everything else in this section is voluntary: if you choose not to provide it, the related feature simply won't be available and the rest of the app keeps working.
Account information. Email address, display name, a unique @nickname, an optional avatar photo, your password (stored only as a salted hash), date of birth (used for our age check), timezone, and your sign-in identifiers if you use Sign in with Apple. A phone number is optional — it is required only if you want to use community posting or habit sharing. Your phone number is set once; changing it requires a request that we review (this protects sharing features from impersonation).
Your journal. Everything you choose to write: decision entries (what happened, what you chose, alternatives, reasoning, reflections, lessons), regret and pressure scores, emotions, categories and tags, money and time costs, context (when / where / who), notes, calculations, calendar tasks, and follow-ups. This is the heart of the product and the most personal data we hold — we treat all of it as private to your account unless you explicitly share it (see §7–8). Journal content can reveal information about your emotional or mental state; we process it only as this policy describes, on the basis of the consent you give at sign-up.
Assistant conversations. If you chat with the in-app assistant, your conversation — including the results of tools you allow it to use (which can include your location, if you grant the assistant location access) — is stored with the related plan.
Photos. Images you attach to entries or set as your avatar are uploaded to and stored on our servers. Photo metadata (EXIF), including the capture time and any GPS coordinates embedded by your camera, is preserved — we use it to place entries on your timeline and map. If you don't want a photo's embedded location stored, remove it before uploading or disable location capture in your camera settings. Photos are served only through unguessable signed links issued to your account or, for entries you've shared, to viewers of those shares.
Voice recordings. If you speak a decision instead of typing it, the audio is uploaded for transcription, processed in memory, and not retained on our servers after the transcription is produced. The audio is processed by our transcription provider (§9). Only the resulting text is stored, as part of your entry.
Location. Precise location is attached to a journal entry only when you switch the location toggle on for that entry — it is off by default. We also reverse-geocode coordinates into a readable place name. Separately, if you choose a radius-based community feed, your approximate location is used to scope what you see and is attached to posts you publish (§7).
Apple Health data (with your explicit consent). If you connect Apple Health, we read — read-only, never write — sleep, mindfulness, steps, workouts (including distance), active energy, and heart rate. See §5 for exactly what is stored and how to remove it.
Habits. Your habits, schedules and reminders, check-ins, session timing, moods and effort ratings, your written session reflections, and the AI-generated recaps of your sessions.
Music. If you attach a song, we store the Spotify track metadata (track, artist, album art and preview links) with your entry — never your Spotify account.
Community and sharing data. Posts you publish to the community (with your chosen visibility), reactions, friendships, habit shares, buddy pairings, comparison consents, and fitness-challenge comments. See §7.
Device and technical data. A push-notification token for your device (if you allow notifications), your device sessions (device name, platform, last active time — you can review and revoke these in the app), and authentication tokens. Like most services, our servers also record technical logs — IP address, request time, user agent — for security and troubleshooting; this applies to app traffic and to visitors of public share pages.
Purchase data. Your subscription tier and entitlement state, managed through Apple and RevenueCat. We never see or store your card details — Apple processes all payments.
Usage data. First-party logs of AI feature usage (model, token counts, cost — used for your credit balance and our cost accounting) and first-party product telemetry events. We use no third-party analytics, no crash-tracking SDKs, and no advertising identifiers.
AI-derived content. The reflections, recaps, diaries, journey narratives, observed patterns and decision profiles the app generates from your content. These are part of your account data and are private to you like everything else.
How we use your data
We use personal data to: (a) provide the service — store and render your journal, habits and journeys; (b) generate your AI reflections, recaps and insights; (c) operate sharing features you opt into; (d) send notifications you enable and transactional email (verification codes, password resets); (e) keep your account secure and prevent abuse; (f) meter AI usage against your credit allowance; (g) improve the product using first-party usage data; and (h) comply with legal obligations.
We do not sell personal data. We do not use your data for advertising, and no data is shared with advertisers or data brokers.
AI processing
reThinked's reflections, recaps, diaries, journey narratives, observer insights and similar features are AI-generated. To produce them, the relevant content is sent to our AI providers:
- Anthropic (Claude models) — journal text and context, habit session notes, health-derived session summaries (§5), files you upload to the plan analyzer (screened for safety and, for documents, text-extracted), and plan-research queries (for the research feature, Anthropic also performs web searches on our behalf based on your plan's content).
- OpenAI — voice recordings, for speech-to-text transcription.
Under both providers' API terms, content sent through their APIs is not used to train their models.
You consent to this processing when you create your account — we ask explicitly at sign-up. Because reflections are generated from what you log, content you enter is processed by AI as described; you can delete any item at any time (deletion works as described in §11), and you can ask us to limit AI processing of your account at rethinked.my@gmail.com — without it, AI-dependent features (reflections, recaps, journeys) won't be generated.
AI outputs can be wrong. They are reflections for your own thinking — not medical, psychological, legal or financial advice. See the Terms of Service §6 for the full disclaimer.
Apple Health and fitness data
Health data is sensitive personal data under the PDPA, so it gets its own rules:
- We process Apple Health data only with your explicit consent, which we ask for in the app before connecting — separately from the iOS Health permission dialog. You can withdraw it at any time by disconnecting.
- We request read-only access, and only to: sleep, mindfulness, steps, workouts (including distance), active energy, and heart rate. We never write anything to Apple Health, and we never store your health data in iCloud.
- What we store on our servers: (a) workout summaries linked to your habit sessions — type, duration, distance, calories, steps, average heart rate; (b) daily wellbeing snapshots — sleep hours and quality, mindful minutes, daylight minutes, mood; (c) wellbeing context saved with a decision entry (e.g. that night's sleep, that day's mood); and (d) statistical correlations the app computes between your wellbeing and your decisions.
- Health-derived summaries are included in the content sent to our AI provider to write your session recaps (§4).
- We never use Apple Health data for advertising or marketing, and never disclose it to advertisers, data brokers or insurers.
- If you share a habit with a Buddy, your session recaps (which can include fitness stats) are visible to that Buddy only while your "share reflections" toggle is on (§7).
- Removing health data: disconnect Health in the app (stops new reads) and revoke reThinked's access in iOS Settings → Health. Deleting a session or entry removes its linked workout summary or wellbeing context. Daily snapshots and computed correlations are removed when you delete your account, or earlier on request to rethinked.my@gmail.com.
Location
- Per-entry location is opt-in, off by default — it is captured only when you switch it on while logging.
- Photos can carry their own GPS metadata (§2).
- Community region scoping uses your country (from your phone number or profile) and, only if you pick a radius mode, your approximate coordinates.
- You can edit or remove an entry's location, and change your community feed mode, at any time.
Community, sharing and Buddies
Everything in this section happens only when you choose to share. Before you do, know exactly who will see what:
- Community posts. When you share a piece of wisdom from a decision, you pick its visibility: Share with everyone (the default) — shown to users in your region with your @nickname and avatar; Anonymous — shown to users in your region with no name and no avatar; Friends only — shown only to your friends, with your name and avatar. A snapshot of your region (and, if you use a radius-based feed, your approximate coordinates) is attached at post time. Photos attached to the underlying decision appear with the post — remember a photo can identify you even when your name doesn't.
- Finding people. To share a habit directly, users search by @nickname or phone number — so someone who already knows your phone number or nickname can find your profile name for sharing purposes. (Friend discovery can be turned off in settings.)
- Buddies. Adopting a shared habit pairs you with the sharer. Buddies always see each other's streaks, progress, and when the other is currently in a session. Your written session reflections and AI session recaps are visible to your Buddy only while your "share reflections" toggle is on (you can turn it off any time).
- Challenges and comments. Fitness-challenge participants see each other's progress and comments.
- Content you publish to other users may be seen, screenshotted, or remembered by them — share what you're comfortable sharing.
Public share links
You can publish an individual decision/journal entry to the web at rethinked.my/j/<link>:
- This is opt-in, per entry. Nothing is public unless you tap Share.
- The link is a long, unguessable token, but anyone who has the link can view the page — no login needed. The public page shows the entry's narrative (what happened, your choice, reasoning, reflection, lesson), your verdict and note, category and emotion, the context you entered — including place name, time, and the people you mentioned — pressure and regret scores, money/time costs, any link you attached, any attached song, and its photos. It does not show your name, account, or GPS coordinates — though a place name or photo you attached can itself reveal a location or identity.
- Turning sharing off makes the link stop working. If you share the same entry again later, the same link becomes active again — so treat a link you've sent as something its holders may regain access to if you re-share. Copies, screenshots or caches made by others while the page was public are outside our control.
- Public pages embed a Spotify player when a song is attached; Spotify sets its own cookies on that page under its own privacy policy.
Who processes your data
We share personal data only with the service providers below ("processors"), each bound by contractual terms requiring them to protect your data and to use it only to provide their service to us:
| Provider | What they process | Purpose |
|---|---|---|
| Anthropic (US) | Journal/habit text, analyzer files, health-derived summaries (§4–5) | AI reflections, recaps, safety screening |
| OpenAI (US) | Voice recordings | Speech-to-text transcription |
| Apple (US) | Sign in with Apple; purchase/receipt data; push delivery (APNs) | Authentication, payments, notifications |
| RevenueCat (US) | App user ID + subscription state (no journal content) | Subscription management |
| Google (US) | Coordinates/addresses and place queries (Maps); push tokens + notification payloads (Firebase Cloud Messaging); video search queries derived from your plan text (YouTube), where used | Maps, geocoding, push notifications, video suggestions |
| Zoho ZeptoMail (US/India) | Your email address + transactional message content | Verification codes, password resets |
| Spotify (Sweden/US) | Song search queries; your device fetches previews from Spotify's servers | Music attachments |
Optional integrations (only if you connect them, where offered): Google Sign-In, Google Calendar (event titles, times and locations you sync), Gmail (email metadata — subject lines and headers, not message bodies — and drafts the app creates for you) and Google Drive (only files the app creates). If you connect these, Google processes that data under its own terms; you can disconnect at any time in the app, which deletes our stored connection tokens.
Administrators. A small number of administrators can access account and content data, only as needed for support, abuse handling, security and service operation.
We may also disclose personal data where we believe in good faith that disclosure is required by Malaysian law, regulation or legal process, or to protect the rights and safety of users; and, if reThinked is ever part of a business transfer, to the successor under this same policy.
There are no analytics companies, ad networks or data brokers in this list because we use none.
International transfers
Our servers and database are in Malaysia. The processors in §9 operate outside Malaysia (mainly the United States). These transfers are made under section 129 of the PDPA on the basis of your consent, because the transfer is necessary to perform our contract with you, and because we have taken all reasonable precautions and exercised due diligence: each provider is bound by contractual data-protection commitments, and we have assessed their protections against the PDPA's standards.
Retention
- Your content (journal, photos, habits, health data, AI-derived content) is kept until you delete it or delete your account.
- Deletion: when you delete an item or your account, it is removed from our active systems within 30 days, and leaves the backup cycle within 90 days.
- Not retained at all: voice audio after transcription (§2); the bytes of files you upload for AI analysis (only the extracted text/metadata you can see in the app is kept).
- Temporary by design: group discussion rooms (where offered) expire automatically after 7 days; on close, a transcript is emailed to the room's members.
- Operational logs: security and telemetry logs are kept up to 12 months; AI-usage/billing records up to 7 years to meet tax and accounting obligations.
- We may retain specific records longer where Malaysian law requires it.
Security
We protect your data with encryption in transit (TLS), salted-and-hashed passwords, token-based authentication stored in the iOS Keychain, signed photo links, server access controls, and routine backups. Payments are handled entirely by Apple — card data never touches our systems. No method of transmission or storage is 100% secure. If a personal data breach occurs that causes or is likely to cause you significant harm, we will notify the Personal Data Protection Commissioner within 72 hours and notify you without undue delay (and in any event within 7 days of notifying the Commissioner), as the PDPA requires.
Your rights (PDPA)
You have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or outdated data;
- Withdraw consent to processing (this may mean some or all of the service stops working for you; withdrawal doesn't affect processing that already lawfully happened);
- Limit processing of your data, including AI processing (§4);
- Data portability — receive your personal data in a structured, commonly used, machine-readable electronic format, or ask us to transmit it directly to another service provider where technically feasible;
- Delete your data — delete individual items in the app, or delete your entire account (in-app, or by request);
- Object to direct marketing — we currently send none; if we ever do, every message will include an unsubscribe option.
To exercise any right, use the in-app controls or email rethinked.my@gmail.com with the subject "PDPA Request". We respond within 21 days as the PDPA requires. We will never discriminate against you for exercising your rights. If you're unsatisfied, you may complain to Malaysia's Personal Data Protection Commissioner (JPDP).
Children
You must be at least 13 years old to use reThinked. If you are under 18, you may use reThinked only with the involvement and consent of a parent or guardian, who should review this policy and our Terms with you. We check date of birth at sign-up and refuse accounts for anyone under 13. We do not knowingly collect personal data from a child under 13 — if you believe a child under 13 has provided us data, contact rethinked.my@gmail.com and we will delete it. (We may offer a dedicated parent/child experience in future.)
Changes to this policy
We may update this policy as the product evolves. We'll post the updated version with a new "Last updated" date, and for material changes we'll notify you in the app (and by email for significant changes) before they take effect. Previous versions are available on request.
Contact
reThinked · Malaysia
Privacy requests: rethinked.my@gmail.com (subject: "PDPA Request")
General support: rethinked.my@gmail.com