Privacy Policy — Good Parts.
Feeling Mindful Labs ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how your personal information is collected, used, and disclosed when you use Good Parts.
Last updated:
This policy describes how Good Parts handles your information. Reading this policy or using the app does not by itself grant consent to optional sharing. The optional ChatGPT connection is currently unavailable.
For health-related journal information, read our separate Consumer Health Data Privacy Policy, including withdrawal, access, deletion and appeal instructions.
Definitions
- Company: Feeling Mindful Labs LLC, (United States)
- Device: Any internet-connected device such as a phone, tablet, or computer used to access Good Parts
- Personal Data: Any information that allows for the identification of a natural person
- Service: The Good Parts application and related services
What Information Do We Collect?
We collect the following information when you use Good Parts:
- Name and email address (account registration)
- Voice recordings (journal entries — uploaded for transcription, then deleted)
- Journal transcriptions and AI-generated parts analysis
- Journal-derived moods, themes, people, insights, and personalized reflection prompts
- Subscription and purchase history
- Device information (model, OS version)
- Crash and diagnostic data
Device Permissions
Good Parts may request access to the following device features:
- Microphone — for voice journal recording
- Push Notifications — for reminders and updates
- Face ID / biometrics — for the optional app lock (processed entirely on-device; never leaves your device)
You can manage these permissions at any time in your device's Settings.
How Do We Use Your Information?
- To provide and maintain Good Parts's core functionality
- To personalize your experience based on your preferences and data
- To improve Good Parts based on usage patterns and feedback
- To process transactions (if applicable)
- To communicate updates, security alerts, and support messages
Service Providers and Other Recipients
Last reviewed: . The services below receive information for the features you use. Optional services such as sign-in providers receive data when you choose them.
- Supabase: Account identifiers, sign-in information, journal text and derived parts, people, moods, themes, insights and prompts; recordings uploaded for transcription. Authentication, database and file storage, and backend functions. Supabase keeps daily database backups for 7 days.
- Google Cloud and Firebase: Journal processing payloads and service diagnostics on Google Cloud; account and journal data in app versions using the Firebase backend. Google Cloud hosts the processing worker. Firebase provides authentication and storage for the legacy backend. Google Cloud keeps audit logs for up to 400 days.
- Apple and Google sign-in; Apple Push Notification service: Sign-in requests and account identifiers when you choose the corresponding sign-in option. On iPhone, while an entry is processing: the Live Activity push token for its Lock Screen card and the card's final status ("Your entry is ready", "Your entries are ready", "Your entry needs attention" or "Your entries need attention"), sent from our server directly to Apple. Authenticate your account through Supabase, and end the Lock Screen progress card when processing finishes.
- RevenueCat, Stripe, Apple App Store and Google Play: Account/customer identifiers, purchase and subscription information, and device and IP information. For a web purchase, your email address and the payment details you enter at checkout. Subscription management and payment processing through your chosen purchase channel. Web purchases use RevenueCat Web Billing, with Stripe processing the payment. When you delete your account, our server deletes your RevenueCat customer record through RevenueCat's API. Stripe, Apple and Google keep their own payment and purchase records under their terms, and deleting your account does not cancel an App Store or Google Play subscription; a web subscription is cancelled when the RevenueCat customer is deleted.
- Sentry: Crash reports, error details, performance traces and profiles from a sample of app sessions, device and app information, diagnostic context, and your pseudonymous account ID. Identify and fix errors in the app and processing worker. Before a report is sent, the app and worker remove fields that can hold journal content. Session replay and screenshots are off. Sentry may use non-identifying service data to improve its products.
- PostHog: A pseudonymous analytics ID: a random identifier for your account that is not derived from your account ID or email. Today PostHog receives it only in the deletion request our server sends when you delete your account; no released version of the app sends analytics to PostHog. If a future version does, its events will carry that ID, device and app information and a fixed list of usage events, and never journal content, recordings or session replays. Product analytics, to understand which features work, once the app enables it. The app's analytics turn off PostHog's IP-based location lookup, and before any version sends analytics we will set our PostHog project to discard IP addresses. When you delete your account, our server asks PostHog to delete the person and events recorded under your analytics ID; PostHog completes the deletion on its own schedule. Using a mental-health journaling app can itself be health data; see the Consumer Health Data Privacy Policy.
- Expo: When the app registers for notifications: your device's Apple or Google push token, an app installation identifier and the app's identifiers, to issue an Expo push token. For each notification: that push token, the time it is sent, and its generic text ("Your entry is ready. Open GoodParts to see it." or "We couldn't finish your entry. Open GoodParts to try again.") with a completed or failed outcome. Notifications carry no journal content or entry identifiers. When the app checks for updates: the app's version, platform and update channel, and an installation identifier. Your IP address reaches Expo with each request. Deliver entry notifications (ready or couldn't finish) to your device through Apple Push Notification service or Firebase Cloud Messaging, and deliver app updates.
- AssemblyAI: Voice recordings you submit for cloud transcription, and the resulting transcripts. Convert recordings to text using AssemblyAI's EU processing endpoint. Our uploaded copy is deleted after submission for transcription (best-effort). Once the transcript is back, we ask AssemblyAI to delete the transcript and its audio; that request is best-effort, and audio from a request that fails before a transcript is created stays until AssemblyAI's own retention period ends. Account metadata and logs may be processed in the US. Our account is opted out of AssemblyAI's model-training program.
- Vercel: Website requests, such as the pages you visit, your IP address and browser information, and sign-in requests when you use the web upgrade page. No journal content passes through Vercel while the ChatGPT connector is unavailable. Host the website. The ChatGPT connector also runs on Vercel and is currently unavailable: while it is off, its endpoints refuse every request without reading your journal.
- Amazon Web Services (Amazon Bedrock, US East): Journal text you record or save, and context derived from your journal (your parts, people, summaries and earlier insights), for background journal analysis, such as cleaning transcripts, summaries, detecting parts, people and relationships, reflections, prompt suggestions and synthesis. For embeddings used to search and connect your journal: whole journal transcripts (cleaned where available), part names and descriptions, and people's names and relationships. Search phrases from the ChatGPT connector, when it is available; part quotes used to suggest part names; recall questions you ask and the journal excerpts used to answer them. Run AI models in the AWS US East (N. Virginia) region, us-east-1: background journal analysis (DeepSeek V3.2, Qwen3 Next and GLM-5), embeddings (Amazon Titan Text Embeddings V2), and part-name suggestions and recall answers (DeepSeek V3.2). Background journal analysis, embeddings, search, part-name suggestions and recall answers all go to Amazon Bedrock directly, with no intermediary. Our AWS account sets Amazon Bedrock's data retention mode to none, under which Bedrock refuses any model that would need to store prompts or outputs, and model invocation logging is off, so our AWS account keeps no copy of them. AWS states that Amazon Bedrock does not use prompts or outputs to train models or share them with model providers.
- OpenAI ChatGPT: Nothing while the ChatGPT connector is unavailable. When it is available: the journal results requested through the connector after you allow access, including a specific entry’s transcript when requested. Respond to your requests in ChatGPT. This optional connection is separate from the AI processing on Amazon Bedrock described above; ChatGPT retention follows your OpenAI account or workspace settings and OpenAI’s policies.
Each third-party service has its own privacy policy governing the use of your information.
ChatGPT Integration
Connecting Good Parts to ChatGPT is currently unavailable. While it is off, the connector refuses every request without reading your journal, and Good Parts shares no journal information with ChatGPT or OpenAI. We will update this policy before the connection becomes available again.
Sensitive Journal Content
Journal content may reveal emotional, relationship, mental-health, or other sensitive personal information. Good Parts processes this content only as needed to provide the journaling and reflection features you choose.
Disconnecting ChatGPT and Deleting Data
If you connected Good Parts to ChatGPT before the connection was turned off, you can remove it in ChatGPT settings. Disconnecting does not delete information already included in your ChatGPT conversations or your original Good Parts data. Manage or delete ChatGPT conversations through ChatGPT, and export or delete Good Parts data through Good Parts settings or our data deletion request page. OpenAI processes information received by ChatGPT under its own privacy policy and your ChatGPT account or workspace settings. Those policies and settings govern how long OpenAI retains that information; the retention controls on our own AI processing do not apply to your ChatGPT conversations. Deleting your Good Parts account does not delete OpenAI's copy.
Data Sharing
We do not sell your personal information. We may share data with third-party service providers solely to operate Good Parts (e.g., authentication, cloud storage, crash reporting). We may also disclose information if required by law.
Data Retention
We retain your information only as long as necessary to provide Good Parts and fulfill the purposes described in this policy. When you delete your account, we remove your personal data from our active systems within 30 days, and backup copies within six months. Our database provider, Supabase, keeps daily backups for 7 days, so database backups holding your data roll off within 7 days of its removal from the active database. Service providers listed above keep their own copies under their own retention periods. When you delete your account we delete your RevenueCat customer record; Stripe and the app stores keep their payment and purchase records under their terms.
If you use Good Parts without signing in, your account is anonymous: no email, phone, Apple or Google sign-in is attached to it. We delete an anonymous account, together with its journal and everything else saved to it, after 12 months without use. Use means opening Good Parts, or another Feeling Mindful app with the same account, while connected to the internet, or signing in. Deletion works the same way as deleting your account yourself, as described above: we remove the data from our active systems, ask the service providers that hold it to delete their copies, and backups roll off on the same schedule. To keep your journal, open the app at least once every 12 months, or sign in with Apple, Google or email, after which the account is no longer anonymous. We do not delete an account that has an active subscription or an open privacy request.
Your Good Parts account is a Feeling Mindful account that our other apps can share: BecomingOne, Shanks Awareness Training and Simple Rituals. If you signed in to them with it, deleting it also deletes whatever those apps saved to this account, not only your Good Parts journal. Data one of those apps keeps in its own storage, such as the current cloud sync in BecomingOne and Simple Rituals, is not affected: delete it from inside that app or email privacy@feelingmindful.com.
Data Security
We implement industry-standard security measures to protect your information, including encryption in transit (TLS) and at rest. However, no method of electronic storage is 100% secure, and we cannot guarantee absolute security.
Your Rights
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate personal data
- Deletion: Request deletion of your personal data
- Portability: Request transfer of your data to another service
To exercise any of these rights, contact us at privacy@feelingmindful.com or use our data deletion request page.
Children's Privacy
Good Parts is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will remove it.
Not Medical or Mental Health Advice
Good Parts is a wellness and self-reflection tool. It is not therapy, medical care, or a substitute for professional mental health treatment, and nothing in the app constitutes medical advice. If you are in crisis, call or text 988 (in the US) or contact your local emergency services.
App Stores
Good Parts is distributed through the Apple App Store and/or Google Play. The terms and privacy policies of Apple and Google also apply to your use of the app. We are solely responsible for Good Parts and its content — Apple and Google have no obligation to provide maintenance or support.
In-App Purchases
Good Parts may offer subscriptions through the Apple App Store, Google Play, or RevenueCat Web Billing, with Stripe as its payment processor. Manage cancellations and refund requests through the channel where you purchased. Deleting your account does not cancel an App Store or Google Play subscription; a web subscription is cancelled when we delete your RevenueCat customer record. We do not receive your full payment card number.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the app or by email. A policy update does not itself authorize new uses or sharing that require your consent.
Governing Law
This policy does not limit the privacy rights or remedies available to you under applicable state or federal law.
Contact Us
If you have questions about this Privacy Policy, contact us at: privacy@feelingmindful.com