Privacy Policy
This policy explains how Irina Kogai (“we”, “us” or “our”), operating Henka from the Australian Capital Territory, Australia, handles information in connection with the Henka mobile app. Our contact details are in Contact.
1. Information handled and why
Henka does not require an email address or a named app account for journey tracking. It uses persistent installation and purchase identifiers. These are pseudonymous identifiers: they can link records to an installation or customer and should not be treated as fully anonymous information.
| Category | Information and source | Use and destination |
|---|---|---|
| Journey content | Information you enter or save: inspiration names and context, admiration text, selected qualities, practices and schedules, energy levels, completion dates, reflections, checkpoint answers, assessments, history, drafts and settings. | Stored in the app’s local database to provide your journeys and progress. The app does not synchronise this database to our servers. Selected creation fields leave the device when you request AI, as described below. |
| AI requests and results | Your chosen creation fields and the suggestions produced in response. The exact fields differ between quality discovery and practice generation. | Cloudflare processes the request; OpenAI generates the suggestions. Results return to your device and can become part of your saved draft or journey. |
| Trial and AI access | A generated app user identifier, an installation credential, a trial start timestamp if a trial was started, and monthly paid AI usage counts. | The credential is sent to our Cloudflare service; the access database stores its hash, the identifier and trial timestamp. Paid AI counters use the original RevenueCat customer identifier. These records authenticate requests and enforce access and allowances. |
| Purchases and restoration | App customer identifiers, store receipt or transaction information, product and purchase history, entitlement status, and device/app/network information used by the purchase service. Information comes from your device, the store and RevenueCat. | Apple or Google processes the payment. RevenueCat validates purchases, restores access and supplies purchase reporting. Our backend checks RevenueCat when paid AI access needs verification. The app does not ask you to enter full payment card details. |
| Network and service information | IP addresses, request timing and routing information, request outcomes and technical request metadata generated when your device connects to a service. | Service delivery, security and abuse prevention. Cloudflare uses the connecting IP address for request rate limits. |
| Communications | If you contact us: the contact details, message, purchase reference or attachments you choose to provide. | To answer the request, investigate a problem or handle a privacy or consumer complaint. Do not send payment card numbers, installation credentials or unnecessary sensitive information. |
After the user explicitly connects online services through the billing notice, a configured native build can initialise RevenueCat and check access when the app opens or returns to the foreground. Before connection, the new implementation does not configure the billing SDK. This can happen before a purchase and independently of using AI. RevenueCat can derive a country from an IP address; that is different from the app requesting precise device location.
The reviewed app has no advertising feature or separate behavioural analytics SDK. RevenueCat’s purchase reporting is a form of analytics. The app does not request photos, contacts, microphone recordings, precise location or health-platform records for the features described here.
2. Optional AI processing
Manual journey creation and local daily tracking do not require an AI request, subject to your trial or purchased access. When you request AI:
- Quality discovery sends the inspiration name, any inspiration context, admiration text and selected admiration hints, and the chosen journey duration.
- Practice generation sends the names and descriptions of selected qualities and the chosen journey duration. The app does not transmit optional time/preferences text; such fields are rejected at its request boundary until covered by a revised disclosure.
These requests pass through our Cloudflare service to OpenAI. Our app also sends its access identifier and credential to Cloudflare to authorise AI; the backend does not forward those access credentials or the user’s connecting IP address to OpenAI in the AI request. OpenAI receives the creation text, which may itself identify you or someone else if you include identifying details.
The app does not automatically attach daily completions, energy check-in history, private reflections, checkpoint answers or saved journey history to AI requests. If you copy any of that information into a creation field, it will be included with that field. Avoid unnecessary names, confidential information, health details or sensitive information about yourself or other people.
Our AI request code does not save prompts or results in the backend access database or deliberately log their text. It requests that OpenAI not store a retrievable response. This does not mean zero retention. OpenAI states that API data is not used for model training by default unless the API customer opts in; its default abuse-monitoring retention is up to 30 days, with longer retention possible for legal or harm-prevention reasons. See OpenAI’s API data controls. Model-dependent prompt caching may also retain encrypted application state; account settings and model behaviour must be verified. store:false is not a zero-retention approval.
You can avoid future AI submissions by using manual creation. Stopping future requests does not recall information already processed. For requests about previously submitted information, use Contact.
3. Service providers and other disclosures
The app uses Cloudflare for the AI proxy, access database and traffic protection; OpenAI for AI generation; and RevenueCat for purchase validation, customer access records and purchase reporting. Apple and Google handle their stores, store accounts and payments. Your device or backup provider may separately process device backups according to your settings.
Providers’ roles depend on the service and applicable contracts. Store account and payment processing is also governed by the relevant store’s own terms and privacy information. Provider policies do not replace our obligations for information we are responsible for handling.
Relevant information: Cloudflare privacy, OpenAI API data controls, RevenueCat privacy, Apple privacy, and Google privacy.
We may disclose information where required by applicable law or valid legal process, or where lawfully necessary to protect people, investigate abuse or establish, exercise or defend legal claims. Such disclosures must be limited to what is appropriate for the purpose. This is not permission for unrestricted sharing.
4. Processing in other countries
The providers named above operate internationally, including in the United States. Information sent to online services may be processed outside the country where you live. Local device storage does not mean that optional AI, purchase processing or device backups remain in your country.
5. Retention, backups and deletion
On your device. Saved local records remain in app storage unless changed through an available feature or the app’s local storage is removed. Trial expiry does not erase your journey information. Settings includes a separately confirmed local-journey erasure control. It preserves trial/purchase and legal/request evidence; local erasure does not restart the trial. There is no general local-journey export feature in this build. Removing local app data using your operating system’s controls can permanently remove that device’s records. Offloading or archiving an app may preserve its data.
Backups. Operating-system or third-party backups may include app data depending on your settings. Removing local data does not necessarily remove existing backups, and restoring a backup may restore app records. Manage backups with the relevant provider. Henka does not provide its own cloud backup or journey synchronisation service.
Access records. The local implementation includes bounded retention tooling; scheduled execution is disabled until operational adoption and provider verification. Resetting a monthly allowance alone does not delete historical counters. The cleanup procedure expires old counters 30 days after their UTC month ends and checks current purchase entitlement before removing due unpaid trial/unused installation records. Paid dormant bindings require review to preserve restoration. Uninstalling the app does not send a server deletion request.
Providers. OpenAI retention is described in section 2. Cloudflare infrastructure records, RevenueCat customer and purchase records, and Apple/Google records have their own applicable retention arrangements. These are not all subject to OpenAI’s 30-day default. Confirm provider retention and deletion arrangements before relying on a specific deletion date.
Requests. Email story@createdbyira.com to request access, correction or deletion of information for which we are responsible. We may need proportionate information to locate the relevant installation or transaction and verify the request. A receipt alone may not identify an unlinked trial installation. Do not send your installation credential or unrelated identity documents. We cannot remotely read or erase a local-only journey database through the current app.
Deleting service records can affect verification or restoration until access is re-established. It does not itself cancel a store transaction or remove statutory purchase rights. Any information retained despite a valid deletion request must have a lawful basis; we will explain an applicable exception and the relevant retention criteria.
6. Security
The app requires HTTPS for production AI and access requests, and the access database stores a hash of the installation credential rather than the credential itself. The local database is held within app storage. The reviewed configuration does not enable separate application-level database encryption.
Local storage is not the same as end-to-end encrypted cloud storage. Keep your device, backups and store account secure. No transmission or storage system is guaranteed to prevent every loss or unauthorised access; this does not reduce any security or notification duty imposed on us by law.
7. Choices, rights and complaints
You may use manual creation instead of AI and manage device backup settings independently. Online purchase and AI features need the information necessary to provide those features. The app can retain local progress after the trial ends even when editing and new tracking are locked.
Depending on applicable law, you may have rights to access, correct, erase or obtain a portable copy of personal information, restrict processing, withdraw consent, complain to a regulator, or appeal a request decision. The scope of each right and any lawful exceptions depend on your location and the processing involved.
Right to object: where applicable law gives you a right to object to processing based on legitimate interests, you may exercise it through Contact. Where processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing.
Contact us with your request or complaint. We will review it, seek only reasonably necessary clarification or verification, and respond within the applicable legal deadline. If we cannot fulfil a request, we will explain the reason and any available review or complaint route. You do not need to waive a legal right to make a request.
Where the relevant law applies, you may complain to the Office of the Australian Information Commissioner, the UK Information Commissioner’s Office, your competent EEA data protection authority, or another local privacy regulator. This does not require first giving up any right to complain directly.
8. Regional legal grounds and automated processing
AI generates optional suggestions from the creation information you submit. You choose which suggestions to use. Separately, automated access checks use trial dates, purchase entitlement and usage counts to allow or deny features or AI requests. If access appears incorrect, contact us for review. This policy does not describe AI suggestions as a professional assessment of you.
9. Age eligibility
Henka is intended for adults aged 18 or older. People under 18 are not eligible to use the service. If you believe a person under 18 has submitted personal information to our online services, contact story@createdbyira.com so we can investigate and take appropriate action.
10. Changes to this policy
We will update the policy when our information practices change and show the effective date. Material changes will be brought to users’ attention through an appropriate notice. If a new use requires consent or another legal step, we will take that step before beginning it. A policy update does not by itself give us permission to use previously collected information for an incompatible purpose.