1. Who is responsible
Sanct is provided by Alperen Öztürk through Ophelin (“we,” “us,” or “our”). For privacy questions or requests, contact support@ophelin.com.
This policy applies to the Sanct iOS app, its Ophelin-hosted backend, and the Sanct support and legal pages.
2. Information stored on your device
Sanct uses Apple’s local app-storage technologies to save the information needed for your experience. Depending on the features you use, this may include:
- profile details such as name, age, gender, relationship status, and job status;
- selected moods, chat sessions, journal entries, and message history;
- generated summaries, observations, feedback, and progress history;
- usage limits, a local subscription-status mirror, and consumable credit balances;
- notification preferences and other app settings.
This local history is not a cloud account and is not designed to sync across devices. Deleting the app normally removes its local data. Sanct also provides local export and deletion controls in Settings. Some reset actions may intentionally keep your profile or purchase status; the confirmation shown in the app describes the action’s scope.
3. Information processed for AI features
Chat
When you send a chat message, Sanct sends the conversation messages,
your selected mood, and optional personalization context to
https://ophelin.com/api/stillmind/chat. Personalization
context may contain your name, age, gender, relationship status, job
status, and whether the app considers you a Basic or Premium user.
This information is used to generate the response you requested.
Session Summary
When Sanct analyzes a completed session, it sends the session and
message identifiers, message history, start time, end time, starting
mood, and locale to
https://ophelin.com/api/stillmind/summarize. The Summary
request does not include your profile, purchase entitlement, ending
mood, Relief Rating, corrections, or selected follow-up actions.
Service operation
Ophelin’s backend forwards the AI request content to OpenAI to produce the requested response. The Sanct handlers do not write chat content, profile fields, raw local identifiers, moods, or generated insights to their application logs. They do record limited operational metadata such as a request ID, endpoint contract, status, timing and size buckets, model name, cache state, and message counts.
Summary requests use a short-lived, best-effort in-memory replay cache inside a running server process for up to 24 hours. This reduces accidental duplicate analysis but is not a durable user database. Infrastructure providers may process technical information such as IP address, timestamps, and security logs as part of operating the service.
4. Purchases and subscriptions
Purchases are processed by Apple’s App Store. Sanct uses RevenueCat to load products, complete purchases, restore subscriptions, and determine active entitlements. Apple and RevenueCat may process purchase receipts, product identifiers, transaction information, device or app identifiers, and a pseudonymous customer identifier. We do not receive your full payment-card details.
Consumable chat or analysis balances are maintained locally in the app. They may not restore after local data deletion, app deletion, or moving to another device.
5. Notifications, diagnostics, and support
- Notifications: Sanct requests iOS notification permission only when you choose to enable reminders. You can change permission in iOS Settings.
- Diagnostics: The current Sanct app does not include third-party advertising or Firebase Analytics/Crashlytics. Apple may provide diagnostic information according to your device and App Store settings.
- Support: If you email us, we process your email address, message, and any information you choose to include so we can answer your request.
6. Service providers
| Provider | Purpose | Information involved |
|---|---|---|
| Apple | App distribution, payments, notifications, platform services | Purchase, device, and platform data under Apple’s policies |
| RevenueCat | Purchase and entitlement management | Pseudonymous identifiers, receipts, products, entitlements |
| OpenAI | Generate requested chat and Summary output | The AI request content described in Section 3 |
| Cloudflare | Host, deliver, secure, and operate the Ophelin backend | Request content in transit and ordinary technical metadata |
These providers operate under their own privacy terms and may process information outside your country. Where required, we rely on appropriate contractual or legal transfer mechanisms.
7. Why we process information
Depending on where you live, our legal bases include performing the service you request, your consent, our legitimate interests in securing and improving the service, and compliance with legal obligations. You choose whether to submit reflection content. Because a conversation may reveal health-related or other sensitive information, only submit information you are comfortable having processed for the requested AI feature.
We do not sell your personal information.
8. Retention and deletion
- Local app records remain until you delete them, reset applicable data, or uninstall Sanct.
- The Sanct backend does not maintain a user account or permanent transcript database.
- Limited operational logs are retained according to our infrastructure configuration and security needs.
- Apple, RevenueCat, OpenAI, and Cloudflare retain information according to their terms and legal obligations.
- Support correspondence is kept as long as reasonably necessary to handle the request and meet legal obligations.
To request help with information controlled by Ophelin, email support@ophelin.com. Deleting Ophelin-controlled data cannot erase records that Apple must retain or data controlled independently by another provider.
9. Your privacy rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent. You may also complain to your local data-protection authority. We may need enough information to verify and respond to your request.
10. Security and children
We use HTTPS for network requests and limit the information sent by each feature. No security system can guarantee absolute protection, so avoid entering information that is unnecessary for your reflection.
Sanct is not directed to children under 13. If local law requires a higher age for consenting to data processing, use Sanct only with the involvement of a parent or legal guardian. Contact us if you believe a child submitted information improperly.
11. Changes and contact
We may update this policy as the app, providers, or legal requirements change. The date at the top identifies the current version. Material changes may also be communicated in the app where appropriate.
Privacy contact
Alperen Öztürk / Ophelin
support@ophelin.com