Legal

Privacy Policy

Effective date: July 24, 2026 · Governing law: State of Georgia, USA

1. Overview

The Inner Renewal (“we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy explains what personal information we collect when you use our digital wellness membership platform (“Platform”), how we use it, and the choices you have.

By using the Platform, you consent to the data practices described in this policy. If you do not agree, please do not use the Platform.

2. Information We Collect

2.1 Information you provide directly

  • Account information— your name, email address, and password when you register
  • Profile information— display name, optional profile photo, and membership preferences
  • Onboarding responses— your wellness intention, current emotional state, and practice preferences collected during initial setup to personalize your experience
  • Journal entries— text content you write in the private digital journal feature
  • Mood logs— the mood label, intensity rating, and optional notes you record in Mood Check-In
  • Reflection responses— written responses to guided reflection prompts
  • Contact messages— name, email, subject, and message when you submit a contact form
  • Payment information— billing details submitted during checkout, processed securely by Stripe, Inc. We do not store full card numbers on our servers

2.2 Information collected automatically

  • Session and listening data— which audio sessions you start, complete, and save as favorites; session duration and pathway progress
  • Progress data— wellness plan completion, activity patterns, and insight calculations
  • Email engagement— whether you open or click links in emails we send (where applicable, via Resend)
  • Technical log data— IP address, browser type, device type, operating system, and pages visited, collected by our hosting provider Vercel for security and operational purposes
  • Authentication tokens— session tokens stored in HTTP-only cookies to keep you signed in, managed by Supabase Auth

2.3 Sensitive wellness data

Journal entries, mood logs, and reflection responses may contain information about your emotional health, mental state, and personal experiences. We treat this data as sensitive. It is:

  • Stored encrypted at rest via Supabase (PostgreSQL with row-level security policies)
  • Not shared with, sold to, or disclosed to any third party for advertising, marketing, or profiling purposes
  • Accessible only to you through your authenticated account, and to our engineering team under strict need-to-know access controls solely for technical support purposes

3. How We Use Your Information

  • To operate the Platform— authenticate your account, display your journal, calculate your progress insights, and deliver your personalized wellness plan
  • To personalize your experience— use onboarding responses and mood data to suggest relevant sessions and generate wellness plans tailored to you
  • To process payments— pass billing information to Stripe to charge your subscription
  • To communicate with you— send transactional emails (confirmations, receipts, password resets) and, with your consent, wellness newsletters and product updates
  • To provide support— respond to messages submitted via the contact form
  • To improve the Platform— use aggregated, de-identified usage data to understand which features are most helpful and improve the experience for all members
  • To ensure security— detect and prevent fraud, abuse, and security incidents
  • To comply with legal obligations— fulfill legal and regulatory requirements applicable in the State of Georgia and other applicable jurisdictions

We do not sell, rent, or trade your personal data to third parties. We do not use your wellness content (journals, mood logs, reflections) to train AI models or for any purpose other than providing the Platform services to you.

4. Third-Party Service Providers

We share data with the following trusted providers solely to operate the Platform. Each provider is bound by data processing agreements and their own privacy policies.

ProviderPurposeData Shared
SupabaseDatabase, authentication, and file storageAll user data stored on the Platform
Stripe, Inc.Payment processingName, email, billing details
ResendTransactional and marketing email deliveryName, email address
VercelHosting and infrastructureServer access logs, IP addresses

5. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Platform. If you delete your account:

  • Your profile, journal entries, mood logs, and wellness data will be deleted within 30 days
  • Payment records may be retained for up to 7 years to comply with financial and tax regulations
  • Support correspondence may be retained for up to 3 years
  • Aggregated, de-identified usage data may be retained indefinitely for Platform improvement

6. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Correction — request correction of inaccurate or incomplete data
  • Deletion — request deletion of your personal data (“right to be forgotten”)
  • Portability — request your data in a portable, machine-readable format
  • Opt-out of marketing— unsubscribe from marketing emails at any time via the unsubscribe link in any email, or by updating your email preferences in account settings
  • Withdraw consent— where processing is based on consent, withdraw it at any time

To exercise any of these rights, contact us at hello@theinnerrenewal.com. We will respond within 30 days. We may need to verify your identity before processing certain requests.

7. Cookies and Local Storage

We use strictly necessary session cookies for authentication managed by Supabase Auth. We use browser localStorage for UI preferences such as sidebar state and dismissed prompts. We do not use advertising cookies, third-party tracking cookies, or analytics cookies that profile you across other websites. See our Cookie Policy for full details.

8. Data Security

We implement industry-standard security measures to protect your data, including TLS/HTTPS encryption for all data in transit, encryption at rest via Supabase, row-level security (RLS) policies ensuring each user can only access their own data, and strict access controls limiting staff access to personal data. No method of electronic storage is 100% secure. In the event of a data breach that affects your rights, we will notify you and applicable authorities as required by law.

9. Children's Privacy

The Platform is intended for individuals aged 18 and older. We do not knowingly collect personal information from anyone under 18. If we learn we have inadvertently collected data from a minor, we will delete it promptly. Please contact us at hello@theinnerrenewal.com if you believe this has occurred.

10. International Users

The Platform is operated from the United States and is subject to U.S. law. If you access the Platform from outside the United States, your data will be transferred to and processed in the United States. By using the Platform, you consent to this transfer. We take steps to ensure your data receives an adequate level of protection wherever it is processed.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to your registered email address at least 14 days before taking effect. The “Effective date” at the top of this page reflects the most recent update. Your continued use of the Platform after that date constitutes acceptance of the updated policy.

12. Contact Us

For questions, requests, or concerns about this Privacy Policy or how we handle your data, please contact:

The Inner Renewal

Email: hello@theinnerrenewal.com