Consumer Health Data Privacy Notice
Last updated August 24, 2026
Why this notice exists
Sayward is a private journaling and conversation-preparation app, not health care, therapy, diagnosis, treatment, relationship or mental-health assessment, monitoring, or crisis support. Even so, journal entries about mental load, closeness, physical connection, conflict, and relationship patterns can reveal highly sensitive information about wellbeing and intimacy. This notice treats that information broadly as “consumer health data” so you can see what happens to it.
This notice supplements the Privacy Policy. If the two differ, contact us before relying on either one.
Data we collect
What you write and choose about the week
This can include optional appreciation, labels you select about what you are carrying, support you want, feelings about the relationship, closeness and physical-connection choices, and whether meal or schedule answers differ.
What you notice, bring, and decide
This can include a private Felt Moment journal entry, a user-requested AI drafting conversation, final wording you approve, topics and private points, sharing choices, meeting state, agreements, decisions, and joint meeting receipts.
AI drafts and reflections you request
This can include suggested wording, topic angles, optional solo or paired private reflections, and possible private themes drafted from final Felt Moment wording you approved. These are AI drafts, not diagnoses, assessments, or findings.
Account, device, purchase, and service data
Your first name or nickname, email, account and relationship-chapter identifiers, subscription status, device token, app events, IP address, diagnostic data, and a purpose-limited one-way trial code derived from your normalized email can become sensitive when linked to use of Sayward or to relationship content. Sayward does not currently collect precise location, contacts, or biometric identifiers, and the current app does not record audio.
Metadata only, unless this notice changes
If you report an AI reflection, Sayward stores your account, the product surface, an opaque output receipt when available, the model and prompt version, the fixed reason you chose, and moderation status. The report form has no excerpt or comment field and does not store the reflection or your source words.
Where the data comes from
- You, when you write, choose an answer, request AI help, pair an account, enable a reminder, contact support, or make a privacy request.
- A partner you pair with, but only for material they choose to share and joint records from a relationship chapter in which you both participated.
- Your use of the app and device, such as service state, security events, subscription state, and diagnostics when those features are enabled.
- Service providers, such as a store or AI provider returning the result of an action you requested.
Why we collect and use it
- To create and authenticate your account.
- To provide private solo reflection and the sealed paired-meeting flow.
- To show only the material you or an original participant chose for a shared meeting or joint record.
- To perform a specific AI action you request, including a paired reflection only after both people independently opt in.
- To manage subscriptions and entitlements, including preventing account deletion and same-email registration from resetting the two-use trial.
- To send reminders and service-state notifications if you enable them and push is configured.
- To protect accounts, enforce limits, diagnose failures, provide support, respond to privacy requests, and investigate incidents.
- To meet legal obligations that counsel determines apply.
Who can receive it
Authorized operators can access account and structural service data for support, security, and operations. Sayward’s server can decrypt selected sensitive writing when it is needed to provide an authorized feature. Operators should not read relationship prose unless you ask for support that requires it or a narrowly scoped incident investigation makes it strictly necessary.
A partner can receive the appreciation and closeness answer you sealed, topics and final Felt Moment wording you chose to bring, and joint agreements and meeting receipts. They do not receive your raw Felt Moment event, its AI drafting conversation, private patterns, or material you keep private. A new partner cannot access an earlier relationship chapter.
Railway hosts Sayward’s web app, API, and PostgreSQL database. The account and relationship data Sayward stores, including metadata-only AI safety reports, therefore pass through or reside in that infrastructure.
Felt Moment help sends the event, current draft, and drafting conversation. A solo week reflection sends your own weekly answers. Topic help sends the topic and points you submit. A private pattern reflection sends final Felt Moment wording you approved from your current relationship chapter—not raw notes, draft conversations, or earlier chapters.
After a paired meeting is complete, nothing is sent for a paired week reflection unless both people independently opt in. If both do, Anthropic receives both first names, each person’s closeness answer, labels each person selected about what they were carrying, final Felt Moment wording shared at the meeting, and whether meal or schedule answers differed. It does not receive written Prep answers, raw or private Moments, or draft conversations. Each person gets a separate private reflection.
Anthropic states that API content is not used to train its models and may retain API data for a limited safety-monitoring period under its API terms. An AI result can be incomplete or wrong.
Reports about AI results are sent to Sayward, not Anthropic, and contain no reflection or source-word excerpt.
They receive purchase, store-account, entitlement, and app-customer identifiers needed for mobile subscriptions. Sayward does not send relationship prose to them. They may still know that a store account obtained or subscribed to Sayward.
Sentry receives a narrow structural error record used to diagnose failures: exception class or type, release and environment, a known app route, backend code-file and line locations, and web numeric line and column locations. Sayward removes user identity, request data, breadcrumbs and page labels, exception messages, source context, email, authentication values, and relationship writing; the web boundary also removes filenames, function names, and unknown fields. Session replay and performance traces are disabled.
For mobile reminders and service-state notices, these services receive a device token and notification title, body, and type. Notifications do not include relationship prose, but a device lock screen may display the notice.
An inbound email provider receives the routing headers and text of an email before sending it to Sayward. The feature is disabled when no provider authentication is configured. The active provider must be confirmed before production.
Current implementation has no affiliate that receives consumer health data. Sayward does not disclose consumer health data to data brokers or advertisers.
No sale or targeted advertising
Sayward does not sell consumer health data, exchange it for money or other valuable consideration, or use it for targeted advertising. It has no advertising SDK. Because those uses do not occur, an opt-out signal does not change them.
AI is a choice, not a background scan
Opening Sayward does not give Anthropic ongoing access to your account. Each AI path requires a named action. A paired week reflection additionally requires both people to choose it after the meeting is complete; the first person can withdraw before the second person opts in. Once information has already been sent for a requested result, withdrawing cannot undo that completed transmission, but it stops a waiting paired request and can stop future optional use.
Your access, export, correction, deletion, and withdrawal choices
Email privacy@sayward.app with the subject “Consumer health data request.” Say what you want us to do; do not put relationship prose, a password, or a partner’s information in the email. We may ask you to authenticate through your existing Sayward account or email. You do not need to create a new account.
- Access and export: ask whether Sayward holds consumer health data about you, for a copy in a portable format, and for a list of recipients. Sayward has an authenticated machine-readable JSON export; we will verify the account before providing or directing you to it.
- Correction: update information available in the app or tell us what account information you believe is inaccurate.
- Delete: use Settings → Account → Delete my account, or ask us to delete particular consumer health data. Account deletion removes your account and private or authored content. Joint meeting and agreement receipts may remain available to another original participant. To prevent the two-use trial from resetting, Sayward retains the former numeric account ID, meeting week and completion time, and a keyed one-way code derived from the normalized email. It contains no relationship writing or plaintext email, but can match a later registration using the same email. We will assess any broader statutory deletion request separately and notify applicable processors where required.
- Withdraw: use “Withdraw my choice” while a paired AI reflection is waiting, turn off optional features where available, or email us to withdraw consent for future optional collection or disclosure. Some processing is necessary to provide an account or a feature you ask for; stopping it may mean that feature cannot operate.
How requests and appeals are handled
We will confirm receipt and respond without undue delay. Where a 45-day legal response period applies, we will respond within 45 days after receiving the request. If reasonably necessary and legally permitted, we may extend once for up to 45 additional days; we will tell you within the first period and explain why. Where applicable law permits delayed deletion from archived or backup systems, that work may continue for the permitted period. Sayward does not currently charge for privacy requests.
If we refuse or limit a request, email privacy@sayward.app with the subject “Appeal — consumer health data request.” A person who did not make the original decision should review the appeal. Where law requires it, we will answer the appeal within 45 days and explain how to contact the appropriate regulator if the appeal is denied.
Retention and deletion limits
Sayward stores active-account content to provide the reflection and meeting history you request; the current implementation does not set one fixed expiration date for all active-account content. When a shared Felt Moment is revealed, its raw event and AI drafting conversation are deleted and only the final wording you approved remains. The non-content trial receipt and keyed email-derived code currently remain for once-ever trial enforcement; a time limit and request-handling rule for that exception must be approved before production. Service providers keep data under their own terms and configured retention. Retention settings and processor contracts require counsel and operator review before production.
Changes and contact
We will update this notice before collecting a new category of consumer health data or using disclosed data for a materially new purpose. Where consent is required, a notice update alone will not replace it.
Sayward is operated by KLMN Studio LLC. Questions, requests, and appeals: privacy@sayward.app.