Privacy
Document under review before the public app launch. Conditions for minors and legal documentation of sensitive data processing and international transfers remain under review.
Who is responsible for your data
BRIDG LABS LTDA is responsible for Sentuni. This policy describes the iPhone app, the account service and this website. Sentuni helps you record experiences, organize emotions and reflect on your days.
Account and journal
Access requires Sign in with Apple. We use an account identifier, protected credentials, authentication dates and session information, without requesting your name or email from Apple. The journal uses iOS file protection and separate storage per account. The app excludes journal files from automatic system backups. Clues for recognizing emotions are processed on your device; your stories are not sent to an artificial intelligence service.
Optional copy and providers
In Settings → My account, you choose whether to inspect, save, recover or delete a journal copy. Uploading is manual and optional, separate from signing in. There is no automatic synchronization; you can use the journal and Sentuni Plus without uploading a copy. Cloudflare hosts the service and stores this copy. Transfers use HTTPS and data is encrypted on the server. This is not end-to-end encryption: the service holds the key to recover your data. Cloudflare infrastructure may process data outside Brazil.
Your control
In Settings → My account, Save copy to account replaces the remote copy; Recover copy on this iPhone replaces local entries. Delete account copy keeps the journal on your device. Delete my account removes the account, revokes Apple authorization and deletes associated data on this iPhone when the operation completes. If an error occurs, follow the message and retry. Delete all check-ins in Settings affects only the local journal, not the remote copy. Signing out does not delete entries. Other devices must recognize deletion or revocation to clear their local copies.
Purchases and technical data
Apple processes payments and RevenueCat verifies purchases, subscriptions and restorations. RevenueCat receives a random in-app purchase identifier, product information and transaction data needed to confirm access. It does not receive your journal or your Sentuni account name or email. We do not receive card numbers or banking details. Deleting a Sentuni account does not cancel an App Store subscription; manage it in Apple settings. With your permission, PostHog receives usage events, such as navigation and opening the offer, and Sentry receives technical error diagnostics. We use random identifiers and limited technical information, without names, emails, stories, emotions, intensities or PDFs. We do not record screens. You can separately accept or decline analytics and diagnostics, and withdraw permission in app settings or website privacy preferences. Declining does not limit the journal or Plus. These services receive technical connection metadata and may process data outside Brazil. We do not use advertising or sell your journal.
What you record and why
You choose which emotions, intensities, dates, situations, thoughts, sensations, actions and notes to include. These entries may reveal sensitive information about your health and personal life. They are used for the journal, worksheets, calendar and reports you request. Avoid including other people’s information that is not necessary for your reflection.
Reports you choose to share
The PDF is generated in the app using the period and entries you select. You choose whether to include details, intensities, stories and observations, review the PDF and choose a recipient or save location through the iOS share sheet. Generating a report does not send your journal to our server. Once shared, the copy is controlled by the recipient or service you chose. Deleting data in Sentuni does not delete external files.
How long data is kept
The local journal remains until deleted on the device. The account remains until deletion; the remote copy remains until replaced or deleted. Sessions expire after 30 days. Temporary authentication, security and deletion-confirmation identifiers have individual expiration periods and are cleaned up during subsequent requests. Provider recovery backups may retain earlier versions for up to 30 days, depending on the plan. These versions are not an ordinary recovery option for deleted accounts.
Your rights
Under applicable law, you may request confirmation and access, correction, information about sharing, portability as provided by law, anonymization, restriction or deletion, as well as withdraw consent or challenge unlawful processing. You may also contact Brazil’s ANPD. These rights are free and do not require Sentuni Plus; the paid report is an additional presentation tool for your sessions.
Language and privacy on this website
The website uses your browser’s language preferences to open an available version. When you click a flag, only that preference is saved in your browser’s local storage until you replace it or clear site data. We do not request GPS location or query external location services. Images show examples from the app; this website does not receive your journal entries.
Contact
For support and privacy requests, email suporte@sentuni.com. The address uses Cloudflare forwarding to the operator’s support inbox. Do not include stories, PDFs or sensitive data in your first message; describe only the technical problem.