Last updated 12 September 2026
This Privacy Notice for Mihai Ruscanu (doing business as Self: Read to Rise) ("we," "us," or "our") describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:
- Download and use our mobile application (Self: Read to Rise), or any other application of ours that links to this Privacy Notice
- Use Self: Read to Rise. Self: Read to Rise is a mobile app that turns ideas from books into small, concrete actions. Users browse a feed of principles distilled from non-fiction books, choose one to act on, and mark it complete, building a record of their progress over time — statistics, milestones, and shareable proof cards. Users sign in with Apple or Google, or use the app as a guest. Onboarding asks them to choose focus areas, a goal, obstacles, and how much time they have per day, from fixed lists. The app uses AI to rewrite an action to fit the user's chosen goal, to write their completion and share text, and — once enough actions are completed — to produce a written analysis of patterns across them. Subscribers to the paid tier, Self+, can also photograph a highlighted passage in their own physical book; the app extracts the text from the photograph and generates an action from it.
- Engage with us in other related ways, including any marketing or events
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at hey@selfreadrise.com.
Summary of key points
This summary provides key points from our Privacy Notice, but you can find out more details about any of these topics by clicking the link following each key point or by using our table of contents below to find the section you are looking for.
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use. Learn more about personal information you disclose to us.
Do we process any sensitive personal information? Some of the information may be considered "special" or "sensitive" in certain jurisdictions, for example your racial or ethnic origins, sexual orientation, and religious beliefs. We do not process sensitive personal information.
Do we collect any information from third parties? We receive your name and email address from Apple or Google when you sign in with them, and your subscription status from our subscription provider. We do not collect information from public databases, marketing partners, or data brokers. Learn more about information collected from other sources.
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent. We process your information only when we have a valid legal reason to do so. Learn more about how we process your information.
In what situations and with which parties do we share personal information? We may share information in specific situations and with specific third parties. Learn more about when and with whom we share your personal information.
How do we keep your information safe? We have adequate organizational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Learn more about how we keep your information safe.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information. Learn more about your privacy rights.
How do you exercise your rights? The easiest way is in the app — see Deleting your information, and what remains — or by emailing hey@selfreadrise.com. We will consider and act upon any request in accordance with applicable data protection laws.
Table of contents
- What information do we collect?
- How do we process your information?
- What legal bases do we rely on to process your personal information?
- When and with whom do we share your personal information?
- Do we offer artificial intelligence-based products?
- How do we handle your social logins?
- Is your information transferred internationally?
- How long do we keep your information?
- How do we keep your information safe?
- Do we collect information from minors?
- What are your privacy rights?
- Controls for Do-Not-Track features
- How Self stores and uses your information
- Analytics and crash reporting
- Deleting your information, and what remains
- Do we make updates to this notice?
- How can you contact us about this notice?
- How can you review, update, or delete the data we collect from you?
1. What information do we collect?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you register on the Services, when you participate in activities on the Services, or otherwise when you contact us.
Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following:
- names
- email addresses
- focus areas, goals, obstacles, and available time selected during onboarding
- photographs of book pages, and the text extracted from them, which you can edit before saving
- book titles and authors you search for
- the actions you save, their completion status, and your completion reactions
Sensitive Information. We do not process sensitive information.
Payment Data. Payments for Self+ are taken by Apple (App Store) or Google (Google Play), who act as merchant of record. We never see or receive your card number, security code, or billing address. Our subscription provider, RevenueCat, tells us whether your Self+ subscription is active, which plan it is (monthly, annual or lifetime, derived from the store product identifier) and when it expires. We record these on your account, together with the time we last verified them, linked to your account identifier. The RevenueCat software inside the app also receives the purchase record for your account — product identifiers and purchase dates — which the app uses only to work out which plan you are on. Purchase notifications from RevenueCat can include the price, currency, and country of a transaction; we read only the account identifiers from them and do not store the rest. You may find these providers' privacy notices here: Apple, RevenueCat and Google.
Sign-in Data. You can register with us using your existing Apple or Google account. If you choose to register in this way, we receive limited profile information from that provider, as described in the section called "How do we handle your social logins?" below.
Application Data. If you use our application(s), we also may collect the following information if you choose to provide us with access or permission:
- Mobile Device Access. We may request access or permission to certain features of your mobile device: your camera, your photo library, and notifications. If you wish to change our access or permissions, you may do so in your device's settings.
- Mobile Device Data. If you turn on product analytics (see section 14), our analytics provider's software records your device model and manufacturer, operating system and version, app version and build, language, time zone, and screen size, and assigns its own pseudonymous identifier to your installation of the app. Our crash-reporting provider's software records similar technical details about your device, assigns its own persistent identifier to your installation of the app, and sends a report whenever the app hits an error or records a diagnostic event — not only when it crashes — as well as tracking app sessions. This runs whether or not you have turned product analytics on (see section 14). We do not read any hardware or advertising identifier from your device, and we do not collect your mobile carrier or phone network.
- Reminders. If you allow notifications, the app schedules reminders on your device. We do not send push notifications from our servers; reminders are scheduled and delivered by your device (see section 13). If you have turned product analytics on, the app records when you tap a reminder and when one arrives while the app is open; it cannot see a reminder delivered while the app is closed. You can turn reminders off in your device's settings.
This information is primarily needed to maintain the security and operation of our application(s), for troubleshooting, and for our internal analytics and reporting purposes.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
Information automatically collected
In Short: Some information — such as your Internet Protocol (IP) address and/or device characteristics — is collected automatically when you use our Services.
We automatically collect certain information when you visit, use, or navigate the Services. This information does not by itself include your name or contact details, but once you are signed in it is linked to your account identifier. It may include device and usage information, such as your IP address, device characteristics, operating system, language, the page that referred you to our website, approximate country, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.
The information we collect includes:
- Log and Usage Data. Log and usage data is service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use our Services and which we record in log files. This log data may include your IP address, device information, information about your activity in the Services (such as which features your account used and when, and whether a request was refused by a usage limit), the pages you viewed on our website, and server-side error records. Crash reports from the app itself go to our crash-reporting provider rather than into our server logs (see section 14). Server logs are deleted 30 days after they are written.
- Device Data. We collect device data such as your device model, operating system, app version, language, time zone, and screen size, and — on our website — your browser type. We do not collect your Internet service provider or mobile carrier.
- Location Data. Approximate location (country or city) derived by our analytics provider from your IP address, if you have turned product analytics on. We never collect precise location and never use GPS.
Google API. Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Information collected from other sources
In Short: We receive limited information from Apple, Google, and our subscription provider.
When you sign in with Apple or Google, we receive your name (where the provider supplies it), your email address, and which provider you used. If you use Apple's Hide My Email, we receive the relay address Apple creates for you, not your real one. From our subscription provider, RevenueCat, we receive whether your Self+ subscription is active, which plan it is and when it expires; the time we last verified this is recorded by us.
We do not obtain information about you from public databases, marketing partners, affiliate programs, data brokers, or social media platforms, and we do not collect information for targeted advertising.
2. How do we process your information?
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.
We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
- To facilitate account creation and authentication and otherwise manage user accounts. We may process your information so you can create and log in to your account, as well as keep your account in working order. (Retention period: Until you delete your account. There is no automatic expiry and we do not delete inactive accounts. When you delete your account we keep a record containing only your account identifier for at least two hours, removed by a nightly clean-up and so ordinarily within a day, to stop a session still open on another device writing new data into the account we have just erased.)
- To deliver and facilitate delivery of services to the user. We may process your information to provide you with the requested service. (Retention period: Until you delete your account, or until you delete the individual item — you can delete any single saved action at any time. Text extracted from a photograph of a book page is kept with that action until you delete it; a temporary copy on our servers, used to avoid charging twice for the same request, expires about 24 hours after the request and is then removed automatically, ordinarily within the following day. The photograph itself is never stored.)
- To respond to user inquiries/offer support to users. We may process your information to respond to your inquiries and solve any potential issues you might have with the requested service. (Retention period: Correspondence is kept in our support mailbox for as long as needed to resolve your inquiry, and for a reasonable period afterwards in case you follow up.)
- To fulfill and manage your Self+ subscription. We may process your information to verify and manage your subscription. (Retention period: Until you delete your account. We store only whether your Self+ subscription is active, when we last verified it, and when it expires — no payment or billing details. Apple, Google and our subscription provider keep their own transaction records under their own retention periods, which we do not control.)
- To protect our Services. We may process your information as part of our efforts to keep our Services safe and secure, including fraud monitoring and prevention. (Retention period: Usage counters that enforce daily limits are kept until you delete your account and carry no separate expiry. Server logs recording which features an account used are deleted automatically 30 days after they are written; deleting your account does not remove them sooner, but they expire on that schedule.)
- To save or protect an individual's vital interest. We may process your information when necessary to save or protect an individual's vital interest, such as to prevent harm.
- Personalising your idea feed. We use the focus areas, obstacles, and available time you selected during onboarding to decide which ideas to show you and in what order. (Retention period: Until you delete your account.)
- Generating AI-written actions and insights. We use your onboarding answers, your saved actions, and the text of any book passage you capture to generate a tailored action, to write your completion and share text, and — when you request it — to produce a written analysis of patterns across the actions you have completed. (Retention period: Until you delete your account.)
- Reading text from a photographed book page. When you photograph a highlighted passage in one of your own books, we extract the text from the image so you can edit it and create an action from it. The photograph itself is never stored. (Retention period: The photograph is not retained. The extracted text is kept until you delete the action or your account, along with a one-way hash of the passage used to count how many actions have been generated from it; a short-lived server copy of the text, used to avoid charging twice for the same request, expires after about 24 hours and is then removed automatically.)
- To diagnose crashes and errors. When the app crashes or hits an error, we receive a report containing your account identifier and technical details about the device and the failure. These reports never include your highlights or your goals. On iOS, the short trail of recent activity attached to a report can include the address of a recent book-search request, which contains the book title. This is separate from product analytics and is not covered by the analytics choice in Settings. (Retention period: Retained by our crash-reporting provider under its own retention settings.)
- To prevent the free personalisation offer from being claimed more than once. When a registered account is deleted and our records show — or cannot rule out — that its one free personalised action was used, we keep a one-way (SHA-256) hash of its email address. Guest accounts leave no hash. The hash cannot be read back as your address, but it is derived from it, so we treat it as personal information. (Retention period: 12 months after account deletion.)
3. What legal bases do we rely on to process your personal information?
In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e., legal basis) to do so under applicable law, like with your consent, to comply with laws, to provide you with services to enter into or fulfill our contractual obligations, to protect your rights, or to fulfill our legitimate business interests.
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. As such, we may rely on the following legal bases to process your personal information:
- Consent. We may process your information if you have given us permission (i.e., consent) to use your personal information for a specific purpose. You can withdraw your consent at any time. Learn more about withdrawing your consent.
- Performance of a Contract. We may process your personal information when we believe it is necessary to fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
- Legitimate Interests. We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms. For example, we may process your personal information for some of the purposes described in order to:
- Diagnose problems and/or prevent fraudulent activities
- Find and fix faults that would otherwise stop the app working for you and for other users
- Stop the single free personalised action being claimed repeatedly by deleting an account and registering the same address again
- Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.
- Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
4. When and with whom do we share your personal information?
In Short: We may share information in specific situations described in this section and/or with the following third parties.
Vendors, Consultants, and Other Third-Party Service Providers. We may share your data with third-party vendors, service providers, contractors, or agents ("third parties") who perform services for us or on our behalf and require access to such information to do that work. We have contracts in place with our third parties, which are designed to help safeguard your personal information. This means that they cannot do anything with your personal information unless we have instructed them to do it. They will also not share your personal information with any organization apart from us. They also commit to protect the data they hold on our behalf and to retain it for the period we instruct.
The third parties we may share personal information with are as follows:
- AI Service Providers: Anthropic
- Allow Users to Connect to Their Third-Party Accounts: Google account and Apple account
- Cloud Computing Services: Google Cloud Platform
- Functionality and Infrastructure Optimization: Cloud Firestore and Cloud Functions for Firebase
- Invoice and Billing: RevenueCat, Apple App Store and Google Play Store
- User Account Registration and Authentication: Google Sign-In, Firebase Authentication and Sign in with Apple
- Web and Mobile Analytics: PostHog
- Website Hosting: Firebase Hosting
- Crash Reporting: Sentry
- Book information and cover images: Apple iTunes Search API
- Email and support correspondence: Microsoft 365 (hosts our hey@selfreadrise.com mailbox, and so processes any request you send us)
We also may need to share your personal information in the following situations:
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
5. Do we offer artificial intelligence-based products?
In Short: We offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies.
As part of our Services, we offer products, features, or tools powered by artificial intelligence, machine learning, or similar technologies (collectively, "AI Products"). These tools are designed to enhance your experience and provide you with innovative solutions. The terms in this Privacy Notice govern your use of the AI Products within our Services.
Use of AI Technologies
We provide the AI Products through one third-party service provider ("AI Service Provider"), Anthropic. As outlined in this Privacy Notice, the content you submit and the output generated for you will be processed by these AI Service Providers to enable your use of our AI Products, for purposes outlined in "What legal bases do we rely on to process your personal information?" We never send your name, email address, or account identifier to an AI Service Provider. You must not use the AI Products in any way that violates the terms or policies of any AI Service Provider.
Our AI Products
Our AI Products are designed for the following functions:
- AI insights
- Text analysis
- Natural language processing
- AI applications
- Image analysis
How We Process Your Data Using AI
Personal information processed using our AI Products is handled in line with this Privacy Notice and the terms under which we use Anthropic's API.
How to Opt Out
Our AI features are optional. You can use the app fully — browsing ideas, saving actions, completing them, and tracking your progress — without any AI processing of your information. Personalised actions, capturing a passage from your own book, and Growth Insights each require a deliberate action from you. Two follow-on steps then happen automatically once you have chosen one: when you complete a personalised action, we generate its completion and share text; and a Growth Insight you have asked for is translated into the app's other language, either straight away or the next time you open the Growth Insights screen.
6. How do we handle your social logins?
In Short: You can sign in with your Apple or Google account. If you do, we receive limited profile information from that provider.
Our Services offer you the ability to register and log in using your Apple or Google account. Where you choose to do this, we receive your name and email address (Apple supplies these only the first time you authorise the app with your Apple ID, so either may be absent — for example if you deleted your account and signed up again), and which provider you used. We do not ask for, read or store your contacts, friends list or profile picture. Our sign-in service, Firebase Authentication, does hold the account identifier Apple or Google issues for you and, for Google, the profile-picture link included in the sign-in token; we do not use either. Sign in with Apple is available on iOS; on Android you can sign in with Google or continue as a guest.
We will use the information we receive only for the purposes that are described in this Privacy Notice or that are otherwise made clear to you on the relevant Services. Please note that we do not control, and are not responsible for, other uses of your personal information by Apple or Google. We recommend that you review their privacy notices to understand how they collect, use, and share your personal information, and how you can set your privacy preferences on their sites and apps.
7. Is your information transferred internationally?
In Short: We may transfer, store, and process your information in countries other than your own.
Our servers are located in the United States. Regardless of your location, please be aware that your information may be transferred to, stored by, and processed by us in our facilities and in the facilities of the third parties with whom we may share your personal information (see "When and with whom do we share your personal information?" above), including facilities in the United States, and other countries.
If you are a resident in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, then these countries may not necessarily have data protection laws or other similar laws as comprehensive as those in your country. However, we will take all necessary measures to protect your personal information in accordance with this Privacy Notice and applicable law.
European Commission's Standard Contractual Clauses:
We have implemented measures to protect your personal information, including by using the European Commission's Standard Contractual Clauses for transfers of personal information between us and our third-party providers. These clauses require all recipients to protect all personal information that they process originating from the EEA or UK in accordance with European data protection laws and regulations. Our Standard Contractual Clauses can be provided upon request. We have implemented similar appropriate safeguards with our third-party service providers and partners and further details can be provided upon request.
8. How long do we keep your information?
In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice unless otherwise required by law.
We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). If you are located in the EU or UK, see section "How do we process your information?" for our retention periods by purpose.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
9. How do we keep your information safe?
In Short: We aim to protect your personal information through a system of organizational and technical security measures.
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.
10. Do we collect information from minors?
In Short: We do not knowingly collect data from or market to children under 18 years of age.
We do not knowingly collect, solicit data from, or market to children under 18 years of age, nor do we knowingly sell such personal information. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent's use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at hey@selfreadrise.com.
11. What are your privacy rights?
In Short: In some regions, such as the European Economic Area (EEA), United Kingdom (UK), and Switzerland, you have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time, depending on your country, province, or state of residence.
In some regions (like the EEA, UK, and Switzerland), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; (iv) if applicable, to data portability; and (v) not to be subject to automated decision-making. In certain circumstances, you may also have the right to object to the processing of your personal information. You can make such a request by contacting us by using the contact details provided in the section "How can you contact us about this notice?" below.
We will consider and act upon any request in accordance with applicable data protection laws.
If you are located in the UK and are unhappy with how we have handled your personal information, you can make a complaint directly to us. This is in addition to the rights you have under the UK General Data Protection Regulation and the Data Protection Act 2018.
How to contact us:
- Email: hey@selfreadrise.com
What happens after you complain
- We will acknowledge your complaint within 30 days of receiving it.
- We will investigate without unjustifiable or excessive delay.
- We will keep you informed of progress and explain the outcome.
If you are not happy with our final response, you can refer your complaint to the Information Commissioner's Office, the UK supervisory authority.
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you also have the right to complain to your Member State data protection authority or UK data protection authority.
If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
Withdrawing your consent: If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time. In the app, you can turn product analytics off at any time: open Profile, tap the gear icon in the top-right corner, then under Settings → Privacy tap "Share usage data". You can also withdraw consent by contacting us using the contact details provided in the section "How can you contact us about this notice?" below.
However, please note that this will not affect the lawfulness of the processing before its withdrawal nor, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.
Account Information
If you would at any time like to review or change the information in your account or terminate your account, you can:
- Contact us using the contact information provided.
- In the app: open Profile, tap the gear icon in the top-right corner, then go to Settings → Account Settings and, under "Danger zone", tap Delete Account. You will confirm twice and sign in again with Apple or Google. Deletion is immediate and cannot be undone. Guests reach the same place, labelled "Delete All My Data". Your onboarding answers can be changed at any time in Settings. Your name and email address come from Apple or Google and cannot be changed in the app; if they change, or are wrong, email us and we will update our copy. If you can no longer sign in, email hey@selfreadrise.com from your account's email address with the subject "Delete My Account". We will confirm the request with the email address on the account before deleting anything.
When you delete your account, we delete it and your information from our live systems immediately; section 15 lists exactly what remains and for how long. We may also retain information where required to comply with applicable legal requirements.
If you have questions or comments about your privacy rights, you may email us at hey@selfreadrise.com.
12. Controls for Do-Not-Track features
Most web browsers include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. Our website honours the DNT signal: if your browser sends it, our website analytics does not run. Our mobile app does not track your activity across other apps or websites, so there is nothing for a DNT setting to apply to there.
13. How Self stores and uses your information
Where your information is stored
Whether you use Self with an account or as a guest, and whether or not you subscribe to Self+, your actions, your progress and any content you create are stored on our servers, hosted by Google (Firebase) in the United States. A copy is cached on your device so the app opens quickly, but the server copy is the one we rely on. If you have an account, uninstalling the app does not delete it or your data — signing in again brings it back. Guest sessions work differently; see "Guest use" below. To delete your data, use Delete Account in the app or contact us (see "Deleting your information, and what remains" below).
Guest use
When you first open Self we create an anonymous account so your progress has somewhere to live, before you decide whether to sign in. A guest account has no name or email address attached, but its actions and progress are stored on our servers like any other account. If you later sign in with Apple or Google, your guest history carries over. If you sign in with an Apple or Google account that already belongs to another Self account, the guest session's data is deleted after you confirm.
A guest session lives on the device that created it, and it is the only link between you and that data. On Android, uninstalling the app clears the session; on iPhone and iPad it is held in the Apple Keychain and usually survives a reinstall. If the session is lost, the data stays on our servers but nothing connects it to you any more — neither you nor we can reach it, and we cannot restore it or hand it back to you. This is why the app warns that a reinstall can lose a guest session, and why creating an account is the only way to be sure of keeping your progress.
Onboarding answers
During onboarding you choose focus areas, a goal, obstacles and how much time you have, from lists we provide. There is no free-text field, so we never hold anything you wrote in your own words about yourself. We use these choices to order the ideas we show you and, when you ask for a personalised action, we send them to our AI provider to tailor it.
Camera and photos (Self+)
Self+ subscribers can photograph a highlighted passage in their own book, or import a photo from their library. The photograph is sent to our AI provider to extract the text and is not stored by us: no image is ever saved to our servers, and the app deletes its temporary copy from your device as soon as the image has been prepared (if an image is refused as too large, that copy stays in the app's cache until your device clears it). You can edit the extracted text before saving it, and it is kept with the resulting action until you delete it. A copy of the extracted text is held on our servers for about 24 hours to avoid charging twice for the same request, then removed automatically. We also keep a one-way hash of the passage, used to count how many actions have been generated from it, until you delete your account.
What we process about your activity
The actions you save, when they are due, whether you completed them and how you felt about completing them; the book each action came from; any book title or author you search for; the personalised actions and completion text our AI writes for you; and, if you ask for them, Growth Insights, a written analysis of patterns across the actions you have completed. Your streak is calculated from your completed actions each time you open the app and is not stored on our servers; if you have turned product analytics on, the current streak count is included in the analytics event sent when you open the app.
AI processing
Our AI provider is Anthropic, in the United States. We send it only the content needed for each request (a photographed page, extracted text, your onboarding answers, your completed actions, book titles) and never your name, email address or account identifier. AI features run only when you choose them; you can use Self fully without any of them. Two follow-on steps then happen automatically: when you complete a personalised action, the AI writes its completion and share text, and a Growth Insight you asked for is translated into the app's other language.
Book search
When you tap a book's name in the app, its title and author are sent from your device to Apple's public book-search service, together with your IP address, to fetch the cover image; this happens on every plan. Self+ subscribers capturing a passage can also type a book title, and the text they type is sent to the same Apple service to look up the author and cover.
Reminders
Reminders are scheduled on your device by the app. We never send push notifications and are not told when a reminder is delivered; if you have turned product analytics on, the app records when you tap a reminder and when one arrives while the app is open. A reminder can show the text of an action that is due (up to 90 characters) on your lock screen and, when your due actions come from one book, that book's title. For Self+ subscribers, reminders can also mention your chosen focus area or goal, including the evening reminder for overdue actions.
14. Analytics and crash reporting
These are two different things, and only one of them is optional.
Product analytics (off until you turn it on)
We use PostHog, hosted in the European Union, to understand which features are used. Nothing is collected until you tick "Help improve Self" at the end of onboarding, and you can change your mind at any time in Profile, then the gear icon, then Settings, Privacy, "Share usage data". This choice is stored on your device, not on your account. Once you sign in, analytics events are linked to your account identifier, together with your subscription status and sign-in method. Each event also carries your device model, operating system, app version, language, time zone and screen size, and the request reaches PostHog with your IP address, from which it can derive your approximate location. Events record which features you use and how often, together with your current streak length, the daily time band and the number of focus areas and obstacles you chose at onboarding, the category of actions you save, milestones you reach and your subscription plan — and never your reading, your highlights, your goal or any text you write.
Crash reporting (always on)
We use Sentry, on its EU-region service, to receive a report when the app crashes, hits an error or records a diagnostic event, so we can fix it. This runs from the moment the app starts and cannot be switched off in the app; the analytics choice above does not affect it. Reports include your account identifier, an identifier Sentry assigns to your installation of the app, technical details about your device and the error, a short trail of recent activity in the app, and your subscription status (active entitlements, subscription identifiers and expiry date), including the full list of purchased products if restoring a purchase fails. They never include your highlights or your goals; on iOS the activity trail can include the address of a recent book-search request, which contains the book title. Crash reports are retained by Sentry under its own retention period and are not deleted when you delete your account.
Subscription verification
RevenueCat receives your account identifier so we can check whether Self+ is active. This applies to every user, including free and guest accounts.
On our website
selfreadrise.com uses PostHog's EU service to count page views and clicks on app-store and email links, together with the page opened, the site language, the clicked link's text, and your browser and device type. It sets no cookies, discards your IP address and builds no visitor profile. It starts when a page loads, and you can switch it off on this page or by sending a Do Not Track signal.
- PostHog Privacy Policy: https://posthog.com/privacy
- Sentry Privacy Policy: https://sentry.io/privacy/
- RevenueCat Privacy Policy: https://www.revenuecat.com/privacy/
15. Deleting your information, and what remains
In the app
Open Profile, tap the gear icon in the top-right corner, then Settings, Account Settings, and under "Danger zone" tap Delete Account. Guests see "Delete All My Data" in the same place. You confirm twice and sign in again with Apple or Google (guests confirm once). Deletion runs immediately and cannot be undone or cancelled. If the app reports an error part-way through, it finishes the deletion automatically on a later launch while you are still signed in to that account on the same device; if you cannot open the app again, email us and we will complete it.
By email
If you can no longer sign in, email hey@selfreadrise.com from your account's email address with the subject "Delete My Account". We confirm the request with the address on the account before acting on it, and complete it within 30 days.
What deletion removes
Your profile, your actions, your Growth Insights, your captured highlights, the personalised actions we generated for you, our server-side usage records for your account, and your sign-in itself, all from our live systems immediately. We also ask PostHog and RevenueCat to delete their records for your account; we send those requests and cannot guarantee their completion on our side. Deleting your account does not cancel a Self+ subscription. Cancel it in the App Store or Google Play first.
What remains, and for how long
- A record of your account identifier, for at least two hours and until our nightly clean-up removes it (ordinarily the next morning), so that a session still open on another device cannot write into the account just erased.
- If our records show, or cannot rule out, that you had used your one free personalised action, a one-way hash of your email address, for 12 months from the most recent deletion, so the free offer cannot be claimed again by re-registering. It cannot be reversed into your address and is deleted automatically. Guest accounts leave no hash.
- Server logs of which features your account used, which expire 30 days after they are written.
- Crash reports already sent to Sentry, under Sentry's own retention period.
- Content already sent to our AI provider for a request you made — never linked to your name, email address or account identifier — under that provider's own retention period. Deletion does not reach it.
A copy of your information
In the app: Settings, Account Settings, Download All Data — after signing in again if you have an account (guests are not asked to). This gives you, as a JSON file: your profile (empty for guests), your saved actions, the personalised actions we generated for you, your Growth Insights, your captured highlights, and the app data saved on your device — including your onboarding answers and capture counters. Your actions, highlights, personalised actions and insights are read from our servers rather than from the copy on your device, so the file reflects what we actually hold. It does not include our server-side usage records; email us if you want those. You can also delete any single action from its detail screen, and change your onboarding answers at any time in Settings. Your name and email address come from Apple or Google and cannot be changed in the app; if they change, or are wrong, email us and we will update our copy.
Contact
For any request about your information: hey@selfreadrise.com
16. Do we make updates to this notice?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Last updated" date at the top of this Privacy Notice. If we make material changes to this Privacy Notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.
17. How can you contact us about this notice?
If you have questions or comments about this notice, you may email us at hey@selfreadrise.com or contact us by post at:
Mihai Ruscanu
Bucharest
Romania
18. How can you review, update, or delete the data we collect from you?
Based on the applicable laws of your country, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information. These rights may be limited in some circumstances by applicable law. To request to review, update, or delete your personal information, use the in-app controls described in section 15 or email us at hey@selfreadrise.com.