Skip to content
Privacy

Consumer Health Data Privacy Policy.

GoodParts · Feeling Mindful Labs LLC

Last updated: October 2, 2026

This policy describes our handling of consumer health data under Washington’s My Health My Data Act. Reading a policy or continuing to use GoodParts does not itself provide consent for additional collection or sharing.

Health data we collect and why

  • Recordings, journal text and reflections you submit, which may describe mental or physical health, symptoms, emotions, relationships, treatment, medications, or reproductive or sexual health. We use them to provide the transcription, journaling and reflection features you request.
  • Inferences from that content: parts, moods, themes, people, relationship context, insights, embeddings and personalized prompts. We use these to organise your journal, retrieve relevant entries and provide requested analysis and reflections.
  • Account identifiers and subscription information linked to your journal. These associate records with your account and determine access to the service. Identifiers, diagnostic information and service requests may reveal use of a health-related service.

We do not sell consumer health data or share it for targeted advertising. We do not use journal content to train AI models. We do not collect precise location to identify visits to health care facilities.

Where the data comes from

Sources include you and your device; information inferred by GoodParts and its processing providers; Apple or Google when you choose their sign-in services; and subscription and payment services. The ChatGPT connector is currently unavailable, so no data comes from ChatGPT.

Recipients, categories and purposes

We use hosting, storage, authentication, transcription, inference, billing, notification delivery, app update, diagnostics and product analytics providers to deliver the features you request. The inventory below describes the data and purposes for each recipient. A provider’s inclusion does not mean every user’s journal is sent to it.

Inventory last reviewed: .

Supabase
Account identifiers, sign-in information, journal text and derived parts, people, moods, themes, insights and prompts; recordings uploaded for transcription. Authentication, database and file storage, and backend functions. Supabase keeps daily database backups for 7 days.
Google Cloud and Firebase
Journal processing payloads and service diagnostics on Google Cloud; account and journal data in app versions using the Firebase backend. Google Cloud hosts the processing worker. Firebase provides authentication and storage for the legacy backend. Google Cloud keeps audit logs for up to 400 days.
Apple and Google sign-in; Apple Push Notification service
Sign-in requests and account identifiers when you choose the corresponding sign-in option. On iPhone, while an entry is processing: the Live Activity push token for its Lock Screen card and the card's final status ("Your entry is ready", "Your entries are ready", "Your entry needs attention" or "Your entries need attention"), sent from our server directly to Apple. Authenticate your account through Supabase, and end the Lock Screen progress card when processing finishes.
RevenueCat, Stripe, Apple App Store and Google Play
Account/customer identifiers, purchase and subscription information, and device and IP information. For a web purchase, your email address and the payment details you enter at checkout. Subscription management and payment processing through your chosen purchase channel. Web purchases use RevenueCat Web Billing, with Stripe processing the payment. When you delete your account, our server deletes your RevenueCat customer record through RevenueCat's API. Stripe, Apple and Google keep their own payment and purchase records under their terms, and deleting your account does not cancel an App Store or Google Play subscription; a web subscription is cancelled when the RevenueCat customer is deleted.
Sentry
Crash reports, error details, performance traces and profiles from a sample of app sessions, device and app information, diagnostic context, and your pseudonymous account ID. Identify and fix errors in the app and processing worker. Before a report is sent, the app and worker remove fields that can hold journal content. Session replay and screenshots are off. Sentry may use non-identifying service data to improve its products.
PostHog
A pseudonymous analytics ID: a random identifier for your account that is not derived from your account ID or email. Today PostHog receives it only in the deletion request our server sends when you delete your account; no released version of the app sends analytics to PostHog. If a future version does, its events will carry that ID, device and app information and a fixed list of usage events, and never journal content, recordings or session replays. Product analytics, to understand which features work, once the app enables it. The app's analytics turn off PostHog's IP-based location lookup, and before any version sends analytics we will set our PostHog project to discard IP addresses. When you delete your account, our server asks PostHog to delete the person and events recorded under your analytics ID; PostHog completes the deletion on its own schedule. Using a mental-health journaling app can itself be health data; see the Consumer Health Data Privacy Policy.
Expo
When the app registers for notifications: your device's Apple or Google push token, an app installation identifier and the app's identifiers, to issue an Expo push token. For each notification: that push token, the time it is sent, and its generic text ("Your entry is ready. Open GoodParts to see it." or "We couldn't finish your entry. Open GoodParts to try again.") with a completed or failed outcome. Notifications carry no journal content or entry identifiers. When the app checks for updates: the app's version, platform and update channel, and an installation identifier. Your IP address reaches Expo with each request. Deliver entry notifications (ready or couldn't finish) to your device through Apple Push Notification service or Firebase Cloud Messaging, and deliver app updates.
AssemblyAI
Voice recordings you submit for cloud transcription, and the resulting transcripts. Convert recordings to text using AssemblyAI's EU processing endpoint. Our uploaded copy is deleted after submission for transcription (best-effort). Once the transcript is back, we ask AssemblyAI to delete the transcript and its audio; that request is best-effort, and audio from a request that fails before a transcript is created stays until AssemblyAI's own retention period ends. Account metadata and logs may be processed in the US. Our account is opted out of AssemblyAI's model-training program.
Vercel
Website requests, such as the pages you visit, your IP address and browser information, and sign-in requests when you use the web upgrade page. No journal content passes through Vercel while the ChatGPT connector is unavailable. Host the website. The ChatGPT connector also runs on Vercel and is currently unavailable: while it is off, its endpoints refuse every request without reading your journal.
Amazon Web Services (Amazon Bedrock, US East)
Journal text you record or save, and context derived from your journal (your parts, people, summaries and earlier insights), for background journal analysis, such as cleaning transcripts, summaries, detecting parts, people and relationships, reflections, prompt suggestions and synthesis. For embeddings used to search and connect your journal: whole journal transcripts (cleaned where available), part names and descriptions, and people's names and relationships. Search phrases from the ChatGPT connector, when it is available; part quotes used to suggest part names; recall questions you ask and the journal excerpts used to answer them. Run AI models in the AWS US East (N. Virginia) region, us-east-1: background journal analysis (DeepSeek V3.2, Qwen3 Next and GLM-5), embeddings (Amazon Titan Text Embeddings V2), and part-name suggestions and recall answers (DeepSeek V3.2). Background journal analysis, embeddings, search, part-name suggestions and recall answers all go to Amazon Bedrock directly, with no intermediary. Our AWS account sets Amazon Bedrock's data retention mode to none, under which Bedrock refuses any model that would need to store prompts or outputs, and model invocation logging is off, so our AWS account keeps no copy of them. AWS states that Amazon Bedrock does not use prompts or outputs to train models or share them with model providers.
OpenAI ChatGPT
Nothing while the ChatGPT connector is unavailable. When it is available: the journal results requested through the connector after you allow access, including a specific entry’s transcript when requested. Respond to your requests in ChatGPT. This optional connection is separate from the AI processing on Amazon Bedrock described above; ChatGPT retention follows your OpenAI account or workspace settings and OpenAI’s policies.

Some providers’ own terms let them use limited information about our use of their service for their own purposes: Sentry may use non-identifying service data to improve its products; AssemblyAI and Expo may keep and use de-identified or aggregated data; RevenueCat may analyse customer data and data derived from it for its other offerings; and Vercel controls the service-generated data, such as request logs and IP addresses, that its platform creates.

We do not share consumer health data with corporate affiliates. You may request the actual third parties and affiliates that received your data and an email address or online contact mechanism for each.

Collection and optional sharing

We collect and process the data needed for the journaling features you request. Where consent is required, we ask before collection or sharing, explain the data, purposes and recipient categories, and obtain sharing consent separately from collection consent. A policy change does not authorize a new purpose or category of health data.

The optional ChatGPT connector is currently unavailable. While it is off, it refuses every request without reading your journal, and we share no consumer health data with OpenAI through it. We will update this policy, and ask for your separate authorization, before it becomes available again.

Access, withdrawal, deletion and appeals

Contact privacy@feelingmindful.com to confirm whether we collect or share your health data, access it and its recipient list, withdraw consent to future collection or sharing, or request deletion. State which right you want to exercise and the account involved. Do not email journal content, passwords or authentication codes. We will use reasonable measures to authenticate your request and will not require a new account.

You can also export your journal or delete your GoodParts account in the app’s Settings. Your GoodParts account is a Feeling Mindful account that our other apps can share, so deleting it also deletes anything saved to this account in BecomingOne, Shanks Awareness Training or Simple Rituals, if you signed in to them with it. Data one of those apps keeps in its own storage, such as the current cloud sync in BecomingOne and Simple Rituals, is not affected: delete it from inside that app or email privacy@feelingmindful.com. If you connected GoodParts to ChatGPT before the connector was turned off, you can remove that connection in ChatGPT settings. Disconnection and withdrawal do not themselves erase existing records or ChatGPT conversations. Use the respective deletion controls or contact us for help with a health-data deletion request.

If you use GoodParts without signing in, your account is anonymous. We delete an anonymous account and its health data after 12 months without use (opening GoodParts or another Feeling Mindful app with that account while online, or signing in). That deletion works the same way as an account deletion, including asking the recipients that hold the data to delete it. Signing in with Apple, Google or email, or opening the app at least once every 12 months, keeps it.

Each Feeling Mindful app that uses your account keeps its own consent and withdrawal. In GoodParts, Settings › Privacy & data lets you withdraw consent to future collection, or to optional sharing, for GoodParts; this does not change BecomingOne, Shanks Awareness Training or Simple Rituals. Those apps do not have their own withdrawal controls yet: to withdraw for one of them, email privacy@feelingmindful.com and name the app, and that withdrawal does not change GoodParts. A withdrawal made in GoodParts’ settings takes effect as soon as it is recorded. To withdraw for every app at once, email privacy@feelingmindful.com; a request that does not name an app is applied to all of them, including data an app keeps in its own storage. Sending an email does not instantly change your app settings: until we confirm the request has been applied, stop submitting new entries. Withdrawing stops future collection or sharing and may make the affected features unavailable; it does not delete existing records or cancel a paid subscription. Manage subscriptions through the purchase channel.

We respond without undue delay and within 45 days of receiving your request; authentication does not extend that deadline. If reasonably necessary, we may extend by another 45 days and explain the reason within the initial period. Deletion includes asking the recipients that hold the data to delete it, with these exceptions: payment and purchase records held by Stripe and the app stores are kept under those recipients’ own terms (we delete the RevenueCat customer record), and error reports already sent to Sentry are kept until Sentry’s retention period ends. Archived and backup copies are deleted within the applicable period, no later than six months after authentication. Our database provider’s daily backups are kept for 7 days. We do not treat deletion from active systems alone as completion.

If we refuse a request, we explain why and how to appeal. To appeal, email the same address with “Privacy appeal” in the subject. We provide a written decision within 45 days. If denied, you may submit a complaint to the Washington Attorney General. We do not unlawfully discriminate against you for exercising these rights.