BackToMe ("we", "us") is a self-help companion for people going through a breakup who want to maintain no contact and heal. For any privacy question or request, contact us at admin@codeapps.dev.
| Data | Where it lives | Leaves your device? |
|---|---|---|
| Journal entries & check-ins | On device (local database) | No |
| The Vault (unsent messages) | On device, AES-256 encrypted | Never — by design |
| Day counter, Healing Score, panic events, achievements | On device; optionally synced pseudonymously (see §4) | Only if cloud sync is active |
| Trusted contacts (up to 3) | On device | No |
| AI Companion chat messages | On device; message content is processed by our AI provider to generate replies | Yes, to generate each reply (§5) |
| Payment details | Handled entirely by Apple / Google | We never see them |
| Usage analytics | Aggregated, pseudonymous | Yes, if enabled (§6) |
Your journal, daily mood check-ins, no-contact day counter, Healing Score, panic-mode sessions, program progress, achievements, notification preferences and trusted contacts are stored in a local database on your phone. Your trusted contacts are read from your address book only when you pick them, are stored locally, and are never uploaded.
Messages you write in the Vault are encrypted on your device with AES-256-GCM before they touch storage. The encryption key is kept in your phone's secure keystore (iOS Keychain / Android Keystore). Vault content is never sent anywhere, never synced, and never readable by us. When you "release" a message it is permanently deleted.
To protect your progress across reinstalls, the app can sync your tracker events (day counter, score changes, check-in dates) and your onboarding quiz answers to our cloud database (Google Firebase), tied to an anonymous account ID — a random identifier not linked to your name, email or phone number. We never ask for your name or email. Journal text and Vault content are not part of this sync.
Subscriptions and one-time purchases are processed entirely by Apple's App Store or Google Play. We never receive your card number, billing address or any payment credentials. Your entitlement (premium yes/no) is stored on your device and can be restored through the store.
On-device data stays until you delete it or uninstall the app. Cloud-synced tracker events persist until you delete your data in-app. All network traffic uses TLS encryption; the Vault additionally uses AES-256-GCM at rest. No method of storage is 100% secure, but we designed BackToMe so the most sensitive data never leaves your hands at all.
BackToMe is not directed at children under 13 (or the higher minimum age of digital consent in your country), and we do not knowingly collect data from them. If you believe a child has used the app, contact us and we'll delete any associated data.
Our cloud providers (Google Firebase, Anthropic) may process data in the United States and other countries. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses implemented by those providers.
BackToMe is a self-help wellness tool. It does not provide medical or mental-health diagnosis or treatment. If you're struggling, please reach out to a qualified professional — and if you're in immediate danger, contact your local emergency number right away.
If we make material changes we'll update this page, adjust the effective date, and notify you in the app before the changes take effect.