Raven
Privacy Policy
Last updated 7/10/2026 · Version 4
Privacy Policy
Last updated: 10 July 2026
This Privacy Policy explains how Raven ("we", "our", or "us") collects, uses, and protects your information when you use the Raven app ("the App"). Please read it carefully.
1. Who We Are
Raven is a personal AI diary application operated by CodePulse. If you have questions about this policy, contact us at businesscodepulse@gmail.com.
2. What Data We Collect and How We Collect It
We collect data in two ways: directly from you (what you type, record, or attach in the App) and automatically derived (information our systems or AI providers extract from what you write, as described below).
Account Data (provided by you at sign-in)
- Your name and email address (via Google or Apple Sign-In)
- A unique identifier from your sign-in provider (Google ID or Apple ID)
- Your device push notification token (if you opt in)
Diary Entries (provided by you)
- Entry text
- Mood you select
- Images you attach
- Voice recordings you make (transcribed to text, then discarded)
- Time capsule messages you write to your future self
- Timestamps
AI-Generated Data (derived from your entries, stored in your account)
- AI reflections, conversation responses, and weekly letters written for you
- AI-generated image descriptions
- Voice transcriptions
- Memory summaries of your past entries
- Mood scores and wellbeing insight records
- Names of people detected in your entries
- Commitments and intentions extracted from your entries
Usage-Derived Data
- Your usual writing time, derived from entry timestamps, used only to schedule notifications at a convenient hour
Wellbeing Data (provided by you)
- Mood check-in responses and notes
Subscription Data
- Your subscription status, trial period, and expiry date (managed via RevenueCat — we do not store your payment card details)
Technical Data
- Device type and operating system (for crash reporting and compatibility)
- App usage logs (errors only — we do not log reading behaviour)
Product Analytics
- Anonymised onboarding and funnel milestones (e.g. sign-up completed, first entry created, subscription started), linked to your account ID only — never to your diary content
3. How We Use Your Data
| Purpose | Legal basis |
|---|---|
| Providing the diary and storage features | Contract performance |
| Generating AI responses, reflections, letters, and insights from your entries | Your explicit consent (given during onboarding, see Section 5) |
| Sending push notifications you have opted into | Consent |
| Processing your subscription and billing | Contract performance |
| Understanding onboarding and feature adoption (product analytics) | Legitimate interest |
| Diagnosing technical errors | Legitimate interest |
| Complying with legal obligations | Legal obligation |
We do not use your diary entries for advertising, profiling for commercial purposes, or to train AI models.
4. The Vault — Special Protection
Entries you mark as Vault entries are stored in your account but are never included in any AI processing context. They are not sent to any AI provider, not used in reflections, not compressed into memory summaries, and not included in semantic search. This is enforced at the data layer, not just the user interface.
5. AI Processing & Third-Party AI Providers
Your permission comes first
The App asks for your explicit consent during onboarding before any of your content is shared with an AI provider. You cannot complete sign-up without making this choice, and the App does not send your diary content to AI providers without it.
What is sent, and to whom
To deliver AI reflections, conversation, weekly letters, and analysis features, the following content is sent to AI providers: the text of your entries, relevant context from your past entries (summaries and related entries), images you attach, and your first name. Depending on your settings, this is sent to one of:
- Anthropic (Claude) — anthropic.com/privacy
- OpenAI (GPT models) — openai.com/privacy
- Google (Gemini) — policies.google.com/privacy
Voice notes: regardless of which AI provider you select, voice recordings are sent to OpenAI (Whisper) for transcription. The audio is used only to produce the transcript returned to you.
Protection of your data by these providers
Only the minimum content needed to generate a response is sent. Vault entries are never sent. We share data with these providers only under agreements that require them to protect your data to a standard equal to the protections in this policy: they act as data processors on our behalf, may not use your content to train their models, may not use it for advertising, and may not retain it beyond what is required to return a response to you.
6. Other Third Parties
| Service | Purpose | Privacy Policy |
|---|---|---|
| Google Sign-In | Authentication | policies.google.com/privacy |
| Apple Sign-In | Authentication | apple.com/legal/privacy |
| RevenueCat | Subscription management | revenuecat.com/privacy |
| AWS S3 / Cloudflare R2 | Image storage | Processed under our data processing agreements |
| Expo / React Native | Push notification delivery | expo.dev/privacy |
| OnRamp | Onboarding & product analytics (funnel milestones, account ID — no diary content, no session recording) | getonramp.dev |
All third parties listed here process data under agreements that provide protection equal to this policy.
7. Data Retention
- Active accounts: Your data is retained for as long as your account exists.
- Deleted accounts: All personal data is permanently deleted within 30 days of account deletion.
- Subscription lapse: Your entries remain readable even if your subscription lapses. We do not delete data due to inactivity.
8. Your Rights
Depending on your location, you may have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — ask us to correct inaccurate data
- Deletion — delete your account and all associated data yourself, directly in the App: Settings → Delete account. This permanently deletes your account, entries, images, and all derived data — no email or phone call required. You may also request deletion by contacting us.
- Export — export your diary entries in JSON or text format directly from the App (Settings → Data → Export)
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — turn off push notifications at any time in your device settings
To exercise any of these rights, contact us at businesscodepulse@gmail.com. We will respond within 30 days.
California residents (CCPA): We do not sell your personal information. You have the right to know what data we collect and to request deletion.
UK & EEA residents (UK GDPR / GDPR): Your data is processed on the legal bases set out in Section 3. You have the right to lodge a complaint with your local supervisory authority.
9. Children
Raven is not intended for users under the age of 13 (or 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has created an account, please contact us and we will delete it promptly.
10. Security
We use industry-standard security measures including:
- Encrypted connections (TLS) for all data in transit
- Encrypted storage for sensitive data at rest
- Access controls limiting who can access production data
No method of transmission or storage is 100% secure. If you become aware of a security concern, please contact us at businesscodepulse@gmail.com.
11. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via a notice in the App. Continued use after the effective date constitutes acceptance of the updated policy.
12. Contact
CodePulse
Email: businesscodepulse@gmail.com