CBT Cards / Privacy

Privacy policy

This page separates private reflection content from technical service data, and separates both from app-store disclosure labels. Those are different things and should not be collapsed into one slogan.

Implementation-policy audit: · Public store metadata rechecked: · Store reconciliation: open

Scope and verification status

This policy describes the CBT Cards mobile app using the implementation audit that informed the policy on 14 July 2026. Public Apple App Store and Google Play metadata was separately rechecked on 19 August 2026. Store privacy labels are publisher disclosures, not a substitute for inspecting the shipped application, SDK configuration, consent flow, and store-console answers.

The public store metadata currently contains statements that do not line up cleanly with one another. CBT Cards therefore records the discrepancy instead of silently choosing whichever statement is more convenient. The external reconciliation remains open until the current iOS and Android builds and store-console answers are verified together.

Reflection content kept on the device

The app stores settings, card state, notes, diary entries, check-ins, reminders, activity history, and supported tool entries locally using Hive. The application attempts to use a key from device secure storage to encrypt supported Hive boxes. A PIN lock can also be enabled in the app.

Diary entries, check-in text, notes, and attached photos are reflection content. They are not the same category as technical identifiers, crash diagnostics, performance telemetry, or aggregate usage events. Reflection content remains local unless you deliberately use a feature that exports, shares, or backs up supported data.

Accounts and direct identifiers

The app does not require a CBT Cards account for its core features. It does not ask for your name or email to use cards, diary entries, or check-ins. The app may open your email client if you choose to contact support.

Technical services, diagnostics, and analytics

Public website. Optional aggregate Google Analytics loads only after explicit consent. Worksheet text and private reflection content are not sent to website analytics. You can decline analytics or clear the saved choice in browser storage.

The audited app implementation includes Firebase Analytics, Firebase Crashlytics, Firebase Performance, Firebase Cloud Messaging, and Firestore. Analytics and Crashlytics collection can be controlled with the in-app analytics-consent setting. When enabled or otherwise used by the application, Firebase services may process technical device, diagnostic, performance, identifier, or usage data according to their configuration and provider terms.

Firestore is used for a shared card-popularity counter. The app sends a card identifier and increments a counter; the audited behavior does not send diary text with that counter. This distinction matters: a store category about identifiers or app activity does not, by itself, mean that private journal or check-in contents are uploaded.

Current store disclosure reconciliation

Apple App Store. The separately verified public mobile release history rechecked on 19 August 2026 reaches Version 3.1 CBT IN ACTION. Apple's App Privacy section lists Identifiers under data used for tracking and Usage Data as data not linked to identity. Marketing text on the public listing uses broader tracking-free privacy wording. Those public statements require reconciliation against the current iOS source/build, Firebase configuration, any advertising or attribution SDK behavior, ATT/IDFA usage, and the answers stored in App Store Connect. See the mobile release history for the release-version source of truth.

Google Play. The public listing was last shown as updated on 9 March 2026 when rechecked. Its Data Safety section says the app may share App activity and App info and performance with third parties, while a separate field indicates that collection is absent. Marketing text on the listing also uses broader tracking-free privacy wording. The exact Android build/version and Play Console answers still need to be checked against the shipped implementation.

These store observations describe disclosure categories around technical and usage data. They should not be reinterpreted as evidence that diary entries, check-ins, or note contents are shared. Conversely, the local-content design should not be stretched into an absolute claim about all technical telemetry.

Official store pages: Apple App Store · Google Play. The repository verification checklist is documented in MOBILE_PRIVACY_AUDIT.md.

Backups, exports, and sharing

You can export supported app data to a file and use platform sharing. The app also provides an optional Google Drive backup feature that requires you to sign in and explicitly initiate the backup. Google processes data used for that feature under its own terms. The developer does not operate a separate CBT Cards account database for the app's core reflection features.

Permissions

The app may request camera or photo access if you choose to attach photos to entries, notification permission for reminders, and network access for optional online services. Photos attached through the app are stored locally unless you choose to include them in a backup or share them using your device.

Retention and deletion

Local information remains on your device until you delete it in the app, clear app data, or uninstall the app. Backups and exported files are controlled by you in their destination. You may turn analytics consent off in Settings; service data already processed by a provider is governed by that provider's retention rules and the app's configured integration.

What still has to be verified

Before the store-reconciliation task can be closed, CBT Cards needs a build-level review of the current iOS and Android application source, Firebase/SDK configuration, consent initialization, any identifier or attribution access, and the exact privacy/Data Safety answers in App Store Connect and Play Console. The verified app commit/build and store-answer update date should then be recorded together.

Children

CBT Cards is not directed to children under the age required by local law to consent to data processing. Do not use the app on behalf of a child without appropriate supervision.

Your questions

For privacy questions, use the current options on the support page. Do not send private journal contents or other sensitive reflection text when reporting a support or privacy issue.