Last updated July 27, 2026
Privacy Policy
Sigmund Freud: Psychoanalysis Reimagined is operated by PRETTY GOOD - FZCO, Dubai, U.A.E.
Account and sign-in
Primary access to the room of psychoanalysis uses an email address and a six-digit code. Sign in with Apple and Google are optional alternatives. Supabase Auth maintains the app account. Resend delivers email sign-in codes. Apple and Google provide identity information only when you choose those methods. We may keep your name, email address when supplied, account identifier, and sign-in provider information while your account exists. We use this information for authentication, account security, purchase delivery, and access to your minute balance. We do not use it for advertising or cross-app tracking.
Apple purchases and minute records
The iPhone app offers one analytic hour of up to 50 connected minutes and a five-hour bundle through Apple In-App Purchase. Internal TestFlight purchases use Apple's no-charge Sandbox environment. Production purchase and minute delivery remain disabled until production release verification is complete. Apple handles payment details and displays the approved local price before confirmation. We do not receive your payment-card number. We receive verified store transaction information and store the transaction identifier, product, store environment, purchase time, account assignment, minute credit, current balance, and delivery status. These records prevent duplicate delivery, recover an undelivered purchase, and keep the remaining balance available when you sign in on another device. Sandbox and Production balances are kept separate.
Under the release model, one credited minute opens one connected minute or part of a minute in the room. Listening and silence are included in connected time. The server records each charged minute, the balance after the charge, and the room session timing needed to enforce paid access. Purchased minutes do not expire while the account remains open. The release model provides no free sessions, trial minutes, or complimentary minute balance.
Voice and AI processing
The app does not listen until you choose to begin a paid session and allow microphone access. Live microphone audio is sent to Inworld AI through an encrypted realtime connection. Inworld provides speech recognition and routes response generation to Anthropic's Claude model. The completed generated text is checked by Inworld's moderation service before playback. Only approved text is sent to Inworld TTS-2 speech synthesis and played by the app. Recognized text and relevant historical source context are processed to produce the response.
Source-grounded corpus retrieval is release-gated and is enabled in the current internal TestFlight build. Recognized text, not microphone audio, may be sent through a Supabase gateway to our private Freud source-retrieval service hosted on Fly.io. During a source-grounded request, that service retrieves passages and scholarly annotations from the Freud corpus. It is configured not to store query text or returned source context.
Website delivery
The website serves its fonts and images from ai-sigmund-freud.xyz and does not use third-party font hosting. Netlify hosts and delivers the website. To deliver pages, protect the service, and diagnose requests, Netlify may process information such as an IP address, device and browser information, the requested page, referrer, timestamp, request identifier, response status, and related traffic or security data. The website code does not include advertising trackers or third-party analytics scripts.
Experience video submissions
If you choose to submit a YouTube experience for possible publication, the website collects the YouTube URL, the public display name you choose, your private contact email, your description of the experience, and your permission confirmations. Netlify processes and stores the form submission so we can review it. Nothing is published automatically. If a submission is approved, the chosen display name, edited description, and embedded YouTube video may appear publicly. The contact email is used only for editorial communication and is not displayed. You can request removal of a published experience or deletion of an unpublished submission by contacting support@ai-sigmund-freud.xyz.
Conversation records and audio
The app and our application database do not save microphone audio recordings or generated Freud audio recordings. Microphone audio is streamed to Inworld for live speech recognition. Approved generated audio is streamed to the app, held in memory only as needed for playback and recovery of an interrupted sentence, and discarded when playback or the session ends. Inworld, Anthropic, Supabase, and their infrastructure providers may process conversation content and limited technical, security, usage, and billing metadata under their applicable agreements and privacy terms. Our operational logs are designed to contain technical status and identifiers, not conversation text or audio.
After a completed paid hour, the app can save a verbatim text record made from recognized user speech and Freud replies that finished playing. The transcript is encrypted on the phone before it is stored as ciphertext. Our service also stores the account-specific key in protected, wrapped form and can issue that key to another authenticated device, which is how the same signed-in account can open the transcript across devices. This protects transcripts from ordinary database reads and prevents another app account from retrieving them. It is not end-to-end encryption against PRETTY GOOD - FZCO or its infrastructure providers because the service controls the key-wrapping boundary. We do not use conversation records for advertising or cross-app tracking.
A small working memory is stored so Freud can continue across sessions. It contains compact themes such as named people, emotional tones, dreams, striking words, and open threads rather than a verbatim transcript. After each completed paid hour, the service also stores Freud's compact running view, a factual summary of that hour when there was a substantive conversation, and a factual summary of the day's conversations. A very brief check-in can remain on the calendar without an individual summary. The session and daily summaries appear in the signed-in casebook. These working-memory records and summaries are protected by database access controls, but they are not protected by the transcript's client-side encryption. Deleting the account deletes them from the active application database.
Private Journal
After an ended paid session, the app can ask whether you want a private AI-prepared note. If you agree, only recognized phrases that passed the app's confidence boundary and Freud responses that finished playing are held briefly in app memory and sent through our authenticated Journal service to prepare a draft. Microphone audio and uncertain recognized text are not sent to the Journal draft service. The draft service verifies that the ended paid room belongs to your signed-in account before contacting the generation provider. Draft input and output are not written to our application database or operational logs unless you review the draft and choose Save.
You see and can edit the draft before saving. Choosing Not Now or Discard saves no Journal entry. If you choose Save, the app stores the note you approved, its title, optional themes, images, questions, Freud reflections, any rights-cleared source references, and the server-derived date and connected duration. Saved Journal notes are protected by account access controls, are kept separately between Sandbox and Production, and can be edited, exported, or deleted by the signed-in account. They are not client-side encrypted. A saved note is an AI-prepared personal reflection, not a transcript, diagnosis, clinical assessment, treatment record, or hidden model memory.
How long records remain
Account information, the unspent minute balance, verified purchase-delivery records, the minute ledger, room-session records, encrypted transcripts and their wrapped account key, session and daily summaries, working memory, and Private Journal notes you chose to save remain in the active application database while the account exists. Deleting an associated saved note also deletes that hour's transcript in the current app. Limited operational, security, accounting, refund, or fraud-prevention records may remain only as long as reasonably necessary for those purposes or as required by law. Apple keeps its own purchase history under Apple's policies. Service-provider backup copies may persist for a limited backup cycle before deletion.
Your choices and account deletion
You can decline microphone access, end a session at any time, or avoid beginning another session. Removing the app from your phone does not delete the account. To delete the account, open the information panel in the app and choose Delete Account.
Account deletion removes the app sign-in account and its active sessions, remaining minute balance, Apple purchase-delivery entries, minute-ledger entries, room-session records, encrypted transcripts and wrapped transcript key, session and daily summaries, working memory, Journal preferences, and saved Private Journal notes from the active application database. Any unused minutes are permanently lost and cannot be recovered after deletion. Deleting the account does not cancel or refund a completed Apple consumable purchase and does not delete your Apple or Google account. Apple purchase history, limited provider backups, and records that must be retained by a provider or by law may remain under the applicable retention rules.
AI and historical limitations
The system provides an AI-generated historical and educational interpretation informed by Freud's published work. Outputs can be incomplete or inaccurate. They are not psychotherapy, diagnosis, crisis care, or medical advice.
Contact
Privacy requests and support: support@ai-sigmund-freud.xyz