Privacy Policy
Effective Date: April 2026
Data Controller:
MIRAIKA, INC.
File Number: 75584571
Registered Office: 2115 W Farwell Ave, Chicago, IL 60645, USA
Last Updated: July 6, 2026
MIRAIKA, INC. ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our InsideX mobile application and related services.
1. Information We Collect
We collect information to provide personalised audio recommendations and improve the App.
Guest Usage (No Account)
You may use InsideX without creating an account ("Guest Mode"). In Guest Mode, we collect:
Stored Locally on Your Device:
- Onboarding Selections: Your wellness focus areas, current mood, and preferred listening time — stored only in your device's local storage, never transmitted to our servers
- Policy Acceptance Record: Which Privacy Policy and Terms versions you accepted, along with the acceptance date
- Listening Preferences: Favourites, recently played sessions, and playlist selections
Transmitted to Our Servers:
- Anonymised Analytics: App usage events via Firebase Analytics
- Crash Reports: Anonymous crash data via Firebase Crashlytics (no user identifier)
- Subscription Data: Anonymous purchase identifiers managed by RevenueCat (if a purchase is made)
- Technical Data: IP address (for security, abuse prevention, and to deliver audio content), device type, OS version, app version
We do not collect any personal information (such as name, email, or profile data) from Guest users. If you later create an account, any purchases made in Guest Mode will be migrated to your new account, along with your local onboarding selections.
Personal Information (Registered Users)
- Account Data: Email address, name, password. If you sign in with Apple or Google, we receive your email address and display name from the respective identity provider. If you use Apple's "Hide My Email" feature, Apple generates a unique relay email address (e.g., xyz@privaterelay.appleid.com) and we store this relay address — we do not receive your real Apple ID email.
- Profile Data: Gender (from onboarding), display name
- Preferences: Wellness focus areas you select during onboarding
Email Password Security
When you create an account using email and password, we handle your password with the following security measures:
- During account creation, your password is encrypted server-side using AES-256-CBC encryption before being temporarily processed for OTP verification
- After verification, the encrypted password is securely stored on your device using platform-native secure storage (iOS Keychain or Android Keystore)
- This locally-stored credential is used solely for automatic sign-in to maintain your session across app launches
- We never store your password as plaintext at any point — neither on our servers nor on your device
Wellness Personalisation Data
This information is provided voluntarily by you during onboarding and is used solely to personalise your audio wellness experience.
- Wellness Focus Areas: The areas you choose to explore during onboarding (typically 1–3 selections from a set of curated themes)
- Current Mood: A single mood state you select during onboarding to help us suggest sessions matching your current emotional state
- Preferred Listening Time: Your preference for when you typically listen (morning, day, evening, or no fixed time) — used to highlight time-appropriate sessions
- Gender: Used to filter relevant wellness content and session recommendations
- Onboarding Completion Status: Timestamps indicating when you started and completed the onboarding process
We do not sell or share your wellness data with third-party advertisers or data brokers. InsideX is a wellness app and does not provide medical advice, diagnosis, or treatment.
Usage and Activity Data
- Listening History: A detailed record of each session you start, including session identifier, start time, pause and resume events, total listening duration, completion status, and date. Used to track progress, calculate streaks, and improve recommendations.
- User Interactions: Your favourite sessions, completed sessions, playlist contents, and recent sessions (last 10), total listening minutes, first session date
- Account Status: Subscription tier (free, lite, or standard), trial status, subscription expiry date
Notification Preferences
If you customise your notification settings, we store your preferences (such as daily reminder times, streak alerts, and notification toggles) securely in our database and associated with your account, so they sync across your devices.
Push Notifications and Device Identification
When you grant notification permissions, we collect:
- Firebase Cloud Messaging (FCM) Token: A unique device-level identifier used to deliver push notifications. Securely stored in our database and associated with your account.
- Platform Information: iOS or Android, to send platform-appropriate notifications
- Login Timestamp: To enforce our single-device session policy (see Section 5)
You can disable push notifications at any time through your device settings.
Technical Information
- Authentication: Firebase Auth tokens and user identifier
- Device Data: Device type, OS version, app version, locale
- Analytics: Anonymised app usage via Firebase Analytics
- Crash and Performance Data: Anonymous crash reports via Firebase Crashlytics, including build version, app locale, and subscription tier (free or premium — not personally identifiable). We do NOT include user identifiers in crash reports.
- App Integrity: Firebase App Check uses platform-native attestation (Apple App Attest / Google Play Integrity) to verify that requests originate from a legitimate copy of our app. This involves a device-level integrity token but does not identify you personally.
- Email Verification Status: Whether your email address has been verified, and the verification date
- Timestamps: Account creation, last active date
Consent Records
We maintain an audit trail of your consent decisions to comply with GDPR Article 7(1). This record includes:
- The Privacy Policy version you accepted
- The Terms of Service version you accepted
- The date and time of each acceptance
- The method of acceptance (account signup, policy update prompt, or guest mode confirmation)
- Marketing consent preferences (if applicable)
- Age confirmation (self-declaration that user is 18 or older)
This audit history is retained for the life of your account and removed when your account is deleted, except where retention is required by law.
2. How We Collect Information
- Directly from You: When you create an account, complete the onboarding quiz, select preferences, or contact support
- Through Social Sign-In: When you sign in with Apple or Google, we receive your name and email address (or relay email) from the respective identity provider. We do not receive or store your Apple ID password or Google account password.
- Automatically: Through Firebase services when you use the App
- Third-Party Services: Firebase (Google) for authentication, database, analytics, push notifications, and crash reporting; RevenueCat for subscription management
3. How We Use Your Information
Service Delivery
- Provide access to audio sessions
- Track your progress and listening history
- Maintain your favourites and playlists
- Enforce access tiers (free users access demo sessions only; premium users access all content)
Personalisation
We use an on-device recommendation engine to suggest sessions and content that match your profile. The engine considers:
- Your selected wellness focus areas
- Your current mood (if provided)
- Your preferred listening time (if provided)
- Your gender (for content filtering)
- Sessions you have already played (to avoid repetition)
- General popularity of sessions in our catalog
The recommendation engine runs locally on your device. These signals are used solely to rank and order session suggestions — they are not used for advertising, profiling for third parties, or automated decision-making with legal effects on you.
You can withdraw your personalisation consent at any time via Settings → Withdraw Privacy Consent.
Communication
- Send OTP verification codes
- Welcome emails and service updates
- Subscription-related emails (trial started, payment failed, plan changed, subscription expired)
- Marketing (only with explicit consent)
Service Improvement
- Analyse anonymised usage patterns
- Fix bugs and technical issues
- Develop new features
Security and Compliance
- Prevent fraud and unauthorised access
- Enforce single-device session policy
- Verify app integrity via Firebase App Check
- Enforce Terms of Service
- Comply with legal obligations
4. Data Storage and Service Providers
Firebase (Google)
- Purpose: Authentication, database (Firestore), file storage, analytics, crash reporting, push notifications, app integrity (App Check)
- Location: europe-west region
- Security: Industry-standard encryption (in transit and at rest)
RevenueCat
- Purpose: Subscription management and in-app purchase validation
- Data Processed: Anonymous purchase receipts, subscription status, anonymous user identifier
- Privacy: https://www.revenuecat.com/privacy
Email Services
- Purpose: OTP verification, account notifications, subscription emails, newsletters (with consent)
- Data Shared: Email address, name, language preference
All service providers are GDPR-compliant.
5. Single-Device Session Policy
For security and licensing reasons, your account can be active on only one device at a time. When you sign in on a new device:
- Your previous device receives a logout notification
- The previous device's session is terminated automatically
- Only the new device retains active access
This policy applies only to registered users. Guest Mode is device-bound and does not sync across devices.
6. Data Sharing
We do not sell your personal data. We share data only:
- With authorised personnel — a limited number of our own staff and administrators who may access your data on a strict need-to-know basis, under confidentiality obligations and access controls, to operate the service, provide support, and ensure security
- With service providers (Firebase, RevenueCat, email services) under contracts that limit their use of your data to providing services to us
- For legal requirements
- In case of business transfers (with notice)
- With your explicit consent
- As aggregated, anonymised insights
We do not show advertisements and do not use third-party tracking pixels.
7. Data Security
We implement:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest (Firebase security)
- AES-256-CBC encryption for password handling during account creation
- Platform-native secure storage for credentials on your device (iOS Keychain / Android Keystore)
- AES-256 encryption for downloaded audio files stored on your device
- Access controls and authentication
- Regular security audits
Report breaches to: support@insidexapp.com
8. Data Retention
- Active Accounts: Data retained while account is active
- Guest Users: Anonymised purchase data retained by RevenueCat; local data remains on your device until you uninstall the app or clear local storage
- Inactive Accounts: Deleted after 24 months of inactivity
- Deleted Accounts: Data removed within 30 days
- Analytics: Anonymised after 14 months
- Crash Reports: Retained by Firebase Crashlytics for up to 90 days
- Consent Audit Trail: Retained for the life of your account, then deleted with your account
- OTP Verification Codes: Automatically deleted within 1 hour of generation
- Legal Obligations: Some data retained as required by law
9. Account Deletion
You can delete your account and all associated data directly within the app.
How to Delete Your Account
- Open the app → Settings → scroll to bottom → Delete Account
- Confirm your password to verify your identity (for social login users, a confirmation dialogue is shown instead)
- Your account and all data will be permanently deleted immediately
What Gets Deleted
- Your account credentials and profile information
- Listening history, preferences, and wellness personalisation data
- Favourites, playlists, and progress data
- Notification preferences
- Consent audit trail
- Active device session information
- All personal data stored in our systems
Important
- This action is permanent and cannot be undone
- If you have an active subscription, please cancel it through your device settings (Apple App Store or Google Play Store) before deleting your account to avoid further charges
- Some data may be retained for legal compliance purposes as described in our Data Retention section
You can also request deletion via email at support@insidexapp.com
10. Your Rights (GDPR)
You have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Restrict processing
- Object to processing
- Data portability
- Withdraw consent at any time (via Settings → Withdraw Privacy Consent, or by contacting us)
Contact: support@insidexapp.com (response within 30 days)
Depending on where you live, you may lodge a complaint with your data protection authority: in the EU/EEA, your national authority (edpb.europa.eu); in the UK, the Information Commissioner's Office (ico.org.uk); in California, the California Privacy Protection Agency (cppa.ca.gov) or the California Attorney General; or, in the United States, the Federal Trade Commission (ftc.gov).
11. International Data Transfers
Data is stored in UK/EU (Firebase europe-west region). As MIRAIKA, INC. operates from the United States, your data may also be accessed from or transferred to the U.S. Transfers outside the EEA are protected by:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions
- GDPR safeguards
12. Age Restriction
The Services are for users aged 18 and older only. Age verification is performed through self-declaration during account creation, social sign-in, or entry into Guest Mode. We do not knowingly collect data from anyone under 18. If we discover such data, we delete it immediately.
Parents: Contact support@insidexapp.com if you believe we have your child's data.
13. Cookies and Tracking
The App uses:
- Essential cookies for authentication
- Firebase Analytics (anonymised; can be limited via device-level controls)
- No third-party advertising or tracking pixels
14. Changes to This Policy
We may update this Privacy Policy from time to time. We classify updates into three tiers:
- Major Changes (e.g., new categories of data collection, new third-party sharing): We will show you an in-app re-consent prompt before your next use. You must accept the updated policy to continue using the app's personalised features.
- Minor Changes (e.g., clarifications, new optional features): You will be notified in-app, but continued use constitutes acceptance.
- Editorial Changes (typo or wording fixes): No notice required.
We maintain a version history of all changes. You can review the current version and effective date at the top of this page.
15. Contact Information
Data Controller: MIRAIKA, INC.
File Number: 75584571
2115 W Farwell Ave, Chicago, IL 60645, USA
General Inquiries: hello@insidexapp.com
Support: support@insidexapp.com
Phone: +1 224 373 3143
Automated Emails: noreply@insidexapp.com
(Please do not reply to emails from this address)
This policy complies with the EU GDPR, UK GDPR, applicable US state privacy laws (including the California CCPA/CPRA), Apple App Store guidelines, and Privacy Manifest requirements.