Sublimi ("we," "our," "us") builds a private AI-personalized subliminal app for iOS. This Privacy Policy explains what we collect, why, how we use it, who we share it with, and the rights you have. We follow GDPR, CCPA, and Apple's App Store privacy requirements. We aim to collect as little data as we can while still making a delightful product.
The short version: we don't sell your data. We don't train AI on your desires. Your photos stay on your phone. Your audio is generated for you and only you.
1. Information we collect
1.1 Information you give us
- Account: name, email, sign-in provider (Apple ID, Google, or email).
- Profile preferences: chosen pillars, voice, language, mascot.
- Generation prompts: the desire text you type to generate a track. Stored encrypted at rest, used only to generate your track and improve your suggestions. Never used to train external models.
- Voice clone samples (Yearly/Lifetime only): a 90-second audio recording you choose to upload to clone your voice via ElevenLabs. You can delete the clone at any time, which permanently removes the sample from our systems and from ElevenLabs.
- Support correspondence: if you email us at hello@sublimi.app.
1.2 Information collected automatically
- Device info: iOS version, device model, app version, time-zone, language.
- Usage events: screens viewed, tracks generated, listening sessions (duration only — never the audio content). Sent to PostHog with anonymized identifiers.
- Diagnostics: crashes and errors via Sentry, scrubbed of personal identifiers.
- Subscription state: active plan, renewal date, transaction IDs (from RevenueCat / Apple).
1.3 Information we do not collect
- Photos: the "before/after" feature stores photos in your device's local sandbox only. They never leave your phone.
- Microphone audio beyond the voice-clone sample you explicitly upload.
- Contacts, calendars, location, health data, or any data outside of what is listed in §1.1 and §1.2.
- Behavioural ad-tracking identifiers (no IDFA collection, no cross-app tracking).
2. How we use your information
- To generate your subliminal tracks (write affirmations, voice them, mix them).
- To deliver your subscription benefits and process your purchases.
- To personalize your experience: surface relevant tracks, build your streak, suggest pillars.
- To debug crashes, monitor performance, and prevent abuse.
- To send you transactional emails (receipts, important account or service notices).
- To comply with legal obligations.
We do not use your prompts, photos, or generated audio to train third-party AI models. Our prompt → Claude → ElevenLabs pipeline is configured with the no-training option enabled where it is supported by the vendor.
3. Legal bases (GDPR)
- Performance of contract: generating your audio, running your subscription.
- Legitimate interests: diagnostics, fraud prevention, product improvement using anonymized analytics.
- Consent: for voice cloning, push notifications, and any optional analytics. You can withdraw at any time in app settings.
- Legal obligation: tax records, requests by lawful authorities.
4. Service providers
We share data only with vendors who help us run the product, under strict data processing agreements:
- Apple — auth, in-app purchases, push (APNs).
- Supabase — encrypted account & subscription database (EU and US regions).
- Cloudflare R2 — encrypted audio storage.
- Anthropic (Claude API) — affirmation writing. Prompts processed under their commercial no-training terms.
- ElevenLabs — voice synthesis and voice cloning. Voice samples auto-deleted from their systems on your request.
- RevenueCat — subscription state.
- PostHog — anonymized product analytics, EU-hosted.
- Sentry — anonymized crash diagnostics.
- Vercel — hosting for the website you're reading.
We do not sell or rent your personal information to anyone. We do not share your information for cross-context behavioural advertising.
5. International transfers
We are based in Canada. If you are in the EEA, UK, or Switzerland, your data may be transferred to and processed in countries outside of your home country, including Canada and the United States. Where required, we rely on Standard Contractual Clauses and equivalent safeguards.
6. Retention
- Account data: while your account is active, plus up to 90 days after deletion to settle billing and abuse review.
- Generation prompts and audio: while your account is active. Auto-deleted on account deletion.
- Voice clone samples: until you delete the clone, or up to 30 days after the last use, whichever comes first.
- Diagnostics: 30 days.
- Anonymized analytics: up to 24 months in aggregated form.
7. Your rights
You have the right to:
- Access the personal data we hold about you.
- Correct data that's wrong.
- Delete your account and all associated data, directly in the app under Profile → Settings → Delete account.
- Export your data in a portable JSON format.
- Object to or restrict certain processing.
- Withdraw consent at any time without affecting prior processing.
- Lodge a complaint with your local data protection authority.
To exercise any of these, email privacy@sublimi.app. We respond within 30 days.
8. Children
Sublimi is rated 17+ and is not intended for children under 13 (or under 16 in the EEA). We do not knowingly collect data from children. If you believe a child has used Sublimi, contact us and we will delete the account.
9. Security
Data in transit is protected with TLS 1.2+. Data at rest is encrypted (AES-256). Access to production systems is gated by SSO + 2FA, with audited least-privilege roles. We run automated dependency and secret-leak scans. Despite our efforts, no system is perfectly secure — please use a unique, strong password and enable 2FA on your Apple ID.
10. Cookies and similar technologies
11. California (CCPA/CPRA) disclosures
California residents have the right to know, delete, correct, and limit the use of sensitive personal information, and to opt out of "sale" or "sharing" of personal information. We do not sell or share personal information. To submit a request, email privacy@sublimi.app from the address on your account, or use the in-app Delete Account flow.
12. Changes to this policy
If we change this policy materially, we will notify you in-app and via email before the changes take effect. The "Last updated" date at the top of this page always reflects the current version.
13. Contact
Sublimi · 1 King St W, Toronto, ON, Canada
Email: privacy@sublimi.app
For EU/UK data subject requests: dpo@sublimi.app