Rize (“Rize”, “we”, “us”, or “our”) is a mental health and wellness application that supports mood tracking, journaling, meditation, breathing exercises, personalized wellness plans, AI-assisted wellness conversations, optional social and community features, and related tools. This Privacy Policy explains what information we collect, how we use it, who we share it with, how long we keep it, and the choices and rights you have.
We collect the categories of information below so the app can function, personalize your experience, keep the service reliable and secure, and support optional features you choose to use.
| Category | Examples | Where it is stored / processed |
|---|---|---|
| Account & identity | Email address, display name, user ID, authentication tokens, optional profile photo | Supabase Auth, the profiles table, and Supabase
Storage (for profile photos you upload) |
| Onboarding & wellness preferences | Answers from the onboarding flow (for example goals, coping preferences, core values, and future-self letter content) | Stored on your device in an encrypted local database and secure app storage. Selected excerpts may be sent to our AI orchestrator only to personalize greetings and wellness conversations. |
| Health & fitness | Daily wellness check-ins, mood and PIES dimension ratings, optional check-in notes | Stored on your device in an encrypted local database. Only
activity type and timestamp metadata sync to Supabase via
user_activity; check-in bodies and notes do not leave
your device. |
| User content — journal | Journal entries and journal prompts you view or write | Stored on your device in an encrypted local database. Only journal activity metadata (such as that a journal session occurred) may sync to Supabase; entry text does not leave your device. |
| User content — wellness plans | Personalized plans, goals, and progress you create in the app | Stored on your device in an encrypted local database. Plan names may be generated through our AI orchestrator when you use that feature. |
| AI chat & conversation data | Messages you send to the in-app wellness Guide, conversation memories, summaries, and favorited chats | Stored on your device in an encrypted local database. Messages are transmitted to our AI orchestrator, which forwards them to a third-party large language model (LLM) provider to generate responses. Chat content is not stored in Supabase application tables. |
| Voice input (conversation mode) | Speech converted to text on your device when you use voice chat | Processed on-device using platform speech recognition. We receive the resulting text transcript only; raw audio recordings are not uploaded or stored by us. |
| Text-to-speech | Guide responses you choose to hear spoken aloud | Text is sent to our AI orchestrator, which uses a third-party text-to-speech provider to generate audio returned to your device. |
| Social & friends | Friend connections, friend requests, and friend challenge participation | Supabase database tables such as friends and related
challenge tables |
| Community content | Posts, comments, reactions, and photos you choose to share in community features | Supabase database and storage |
| Moderation & safety | Reports you submit about community content and accounts you block | Supabase tables such as content_reports and
user_blocks |
| Activity metadata | Practice type (for example meditation, breathing, journal, check-in), timestamps, and optional duration | Stored locally and synced to Supabase user_activity
for achievements, streaks, and optional social sharing you initiate |
| Device & usage | Operating system, device type, app version, sign-in timestamps, login method, and login success/failure status | Supabase user_login_activity on sign-in; device/app
version may also be sent with Guide chat requests and recorded in
server operational logs |
| Diagnostics | Crash reports, performance data, and technical error information | Sentry (when enabled in the build). Personal wellness content is scrubbed before upload where possible. |
| Product analytics | App usage events (for example app opens, screens viewed, and that a check-in, meditation, breathing, journal, or Guide chat session occurred), device type, operating system, and app version. Analytics events carry activity metadata only — journal text, chat message content, and check-in notes are not sent to analytics. | PostHog, hosted in the European Union. Events are linked to a pseudonymous user ID, not your name or email. IP addresses are discarded at ingestion and not stored. |
| Session replay (beta period only) | Visual recordings of the app screens you view and your interactions with them, used to find usability problems and bugs. Because these are images of your screen, wellness content displayed on screen may be visible in a recording. | PostHog, hosted in the European Union. Recordings are linked to a pseudonymous user ID and automatically deleted after 30 days. Session replay is enabled only during the beta testing phase and will be turned off for the public release. |
| Server operational logs | Technical logs of API requests and responses, which may include chat message content and session identifiers used for reliability, abuse prevention, and internal administration | Our AI orchestrator’s operational logging system. In production privacy mode, these logs are not linked to your account user ID, but may still contain session identifiers and message content for a limited retention period. |
We do not sell your personal information. We do not use your health or wellness data for advertising, and we do not use your data for cross-app tracking.
We share data only with service providers that help us operate the app, or when required by law:
We may also disclose information if required by law, to respond to lawful requests, or to protect the rights, safety, and security of our users and our service.
Your most sensitive wellness content — including journal entries, mood and check-in details, chat history, onboarding answers, and wellness plans — is stored primarily on your device in an encrypted local database (SQLCipher). App preferences and some onboarding progress may also be stored in secure on-device storage.
Deleting the app from your device removes local data unless you have cloud-backed account data still stored on our servers (for example community posts or your account profile).
All network traffic between the app and our servers uses encryption in transit (HTTPS/TLS). Sensitive local data is encrypted at rest on your device. Access to server-side data is protected by authentication and row-level security policies. No method of transmission or storage is completely secure, but we work to protect your information using industry-standard safeguards.
Rize is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at contact@rizeapp.ca and we will take steps to delete it.
We may update this Privacy Policy from time to time. We will revise the “Last Updated” date above when we do. Material changes may also be communicated through the app or by other reasonable means where appropriate.
If you have any questions about this Privacy Policy or your data, contact us at contact@rizeapp.ca.
Account deletion instructions: https://auth.rizeapp.ca/account-deletion/