Last updated: September 2026 · version 1.3

Privacy Policy

1.Introduction

Welcome to inBetween. We are committed to protecting your privacy and handling your personal data transparently. This privacy policy explains how we process information when you use the inBetween app. Our philosophy is simple: your story belongs to you. We only collect what is strictly necessary for the app to function, and we never sell or share your data with third parties for commercial purposes.

2.Data Controller

inBetween, based in the Netherlands. Email: hello@iaminbetween.com

3.What data do we process?

Name: the first name you optionally enter when setting up the app.

Voice recordings: audio files you record yourself, stored as .m4a on your device.

Transcriptions: the text generated from your voice recording.

App settings: language preference, theme, and whether you have completed onboarding.

Audio fragment (temporary): when you choose to transcribe, your recording is sent once to an external API for processing. This file is not retained by us afterwards.

Anonymous usage statistic: at each app start, we send one anonymous signal to our analytics storage (Supabase, in the EU). This contains a randomly generated installation ID (no name, no device ID), your language setting, platform (iOS/Android), app version, the hour of the day, whether you are a returning user, and a country code derived from your device's locale setting (e.g. NL, DE — not GPS location). This signal cannot be traced back to you as a person.

For certain in-app actions, we also send an anonymous event signal containing the same random installation ID and a description of the action: • which language was chosen at first launch • whether onboarding was completed • which question was skipped or recorded (the question text) • which ambient sound was played • whether premium was activated

All signals contain no name, email address or any other personally identifiable information.

Feedback (optional): if you send a message via the feedback button, we process the text you type yourself, together with the type (bug, suggestion or other), your language setting, platform and app version. We do not ask for your name or email address — feedback is anonymous, unless you put personal data in the message yourself.

Special categories of personal data: your recordings and transcriptions may contain sensitive information (for example about health, beliefs or emotions) — but only if you record it yourself. This data stays locally on your device and is only sent to OpenAI when you choose to transcribe or generate a story. By using that feature you give your explicit consent for this (Art. 9(2)(a) GDPR).

4.What we do NOT collect

We collect NO account or login data, NO GPS location data, NO cookies or tracking, NO advertising profiles, NO personally identifiable analytics, NO data from other apps on your device and NO device identifiers (such as IDFA or IMEI). We do collect anonymous, non-traceable usage statistics as described in article 3.

5.Legal basis (GDPR)

We process your data on the basis of:

• Consent (Art. 6(1)(a) GDPR) — you give explicit consent at first use of the app.

• Performance of a contract (Art. 6(1)(b) GDPR) — processing necessary for the core functionality of the app.

• Legitimate interest (Art. 6(1)(f) GDPR) — to keep the app safe and functional.

6.How do we use your data?

• To make the app work: saving and playing recordings, showing transcriptions, saving settings.

• To tailor your questions: the app may decide locally, on your own device, which question to show based on the themes you engage with. This determination never leaves your device.

• To provide AI features: transcription via Whisper and title generation, story writing, read-aloud and suggesting a follow-up question based on your earlier recordings via GPT (both OpenAI). These requests pass through our own secure server, which only relays them and stores nothing.

• We do NOT use your data for advertising, commercial profiling or resale.

7.Storage and security

All personal data — recordings, transcriptions and settings — are stored exclusively on your own device via the local database and your phone's file system. inBetween keeps no copy of your data. Our server only relays AI requests to the AI service and does not store or log any recordings, transcriptions or other content. When you delete the app, all data is automatically erased.

8.Retention period

Data is retained for as long as you use the app. You can delete recordings and transcriptions at any time via the app. When the app is deleted, all data is immediately and permanently erased from your device.

Exception – server data: the anonymous usage statistics and any feedback messages are not stored on your device, but in our EU database (Supabase, Ireland). We keep these for a maximum of 12 months, after which they are automatically deleted. Because this data is anonymous, it does not disappear when you delete the app.

9.Sub-processors and external services

We share data exclusively with the following sub-processors, and only to the extent necessary:

• OpenAI (US) — for audio transcription via Whisper and for generating titles, stories and read-aloud audio via GPT. Your audio file and text fragments are sent once per request and not retained by OpenAI for training after processing. See openai.com/policies.

• Supabase (data in the EU – Ireland) — for storing anonymous usage statistics and feedback messages. The data is physically located on servers in Ireland. Supabase Inc. is a US company, but your data does not leave the EU. See supabase.com/privacy.

• Resend (US) — to deliver your feedback message to us as an email (hello@iaminbetween.com). Resend only processes the content of your feedback message; we do not pass on any name or email address. See resend.com/legal/privacy-policy.

• RevenueCat (US) — for managing your subscription: the purchase confirmation from Apple or Google, a random user ID, and device and platform information. Your payment details go to Apple or Google only; neither RevenueCat nor we ever see them. See revenuecat.com/privacy.

We never sell your data and do not work with data brokers or advertising networks.

10.International transfers

The country behind a service is where that company is legally established — not necessarily where your data is stored. Supabase, for example, is a US company, but your data is physically located in Ireland (EU) and does not leave the EU.

Data is processed outside the EEA (US) for AI processing (OpenAI), the delivery of feedback email (Resend) and the management of subscriptions (RevenueCat). For OpenAI and Resend this happens once, at the moment you choose to transcribe, generate a story or send feedback. For RevenueCat it continues for as long as you have a subscription. We base this transfer on the Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework as safeguards.

11.AI functions and automated decision-making

The AI-generated transcriptions, titles and stories are intended solely for personal use. They have no legal effect and are not intended as diagnosis, advice or treatment. You remain solely responsible for decisions based on the app. AI processing only takes place at your explicit request.

12.Your rights (GDPR)

Under the GDPR you have the right to:

• Access your data • Rectification of incorrect data • Erasure ('right to be forgotten') • Restriction of processing • Object to processing • Data portability • Withdrawal of consent

You can exercise all these rights yourself via the app (delete individual recordings, or erase everything at once via Settings → Data → 'Delete all my data', or delete the app). For questions you can also contact us at hello@iaminbetween.com. We respond to your request within 30 days. You have the right to lodge a complaint with your national data protection authority.

13.Data breaches

If, despite our measures, a data breach occurs, we report it within 72 hours to the Dutch Data Protection Authority when it poses a risk to your rights and freedoms (Art. 33 GDPR). If a breach is likely to result in a high risk, we also inform those affected directly and without undue delay (Art. 34 GDPR).

14.Children's privacy

inBetween is not intended for persons under 16 years of age. We do not knowingly collect data from minors. If you become aware of this, please contact us at hello@iaminbetween.com so we can delete the data.

15.Liability

inBetween is developed with care and continuously improved. The app is intended for personal use and is not a substitute for professional psychological or medical help. Because your data is stored solely on your own device, we recommend keeping your own copy of any important memories you do not store elsewhere.

16.Changes to this policy

We may update this privacy policy from time to time. For significant changes you will be notified via the app. The date at the top of this policy always indicates the most recent version.

17.Governing law

This privacy policy and the processing of your data are governed by Dutch law, alongside the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (UAVG). The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) is the competent supervisory authority. Any disputes arising from this will be submitted to the competent court in the Netherlands.

18.Contact

Questions or comments about this privacy policy?

hello@iaminbetween.com