Privacy Policy

Last updated: 8 August 2026

BecomingMe (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal information when you use our mobile application and website (collectively, the “Service”). It is written to meet the requirements of the EU General Data Protection Regulation (“GDPR”) and applicable Spanish data-protection law. Please read it carefully. By using BecomingMe, you agree to the practices described here.

Questions? Email us at info@becomingme.co.


0. Who is responsible for your data

The data controller is Katrin Kurz, trading as BecomingMe, registered as an autónoma in Spain. Contact: info@becomingme.co. If you would like our postal address for a formal data-subject request, email us and we will provide it.

We do not currently have a statutory obligation to appoint a Data Protection Officer. If you have a concern you cannot resolve with us directly, you may lodge a complaint with the Spanish data-protection authority, Agencia Española de Protección de Datos (aepd.es), or with your local supervisory authority in the EU/UK.


1. What We Collect

Account information

When you create an account we collect your first name, email address, and a password. Your password is never stored in plain text; it is hashed by our authentication provider.

Community profile

If you complete the Community section of the app, you may provide optional information such as your location, profession, languages, a profile photo, a bio, and answers to community prompt questions. This information is visible to other authenticated members of the app.

Photos you add

You can add photos in two places: images on your Vision Board, and a photo of yourself carrying out your daily embodiment challenge, which then appears on your private Evidence wall. These photos are stored privately, in your own account. Only you can see them. We do not share them, we do not use them for advertising, and we do not run face recognition, tagging, or any other automated analysis on them. You can replace any photo at any time, and deleting your account deletes the photos with it.

Self-development data

The core of BecomingMe is personal growth work. We store the responses you provide throughout the app, including:

This data is private to you and is never sold or shared with third parties for marketing purposes.

Subscription and payment information

We store your subscription status, plan type, and subscription period so the app can grant you access. Payment processing is handled entirely by Apple (via the App Store) or Stripe (via our website). We never store your credit-card number, CVV, or full payment details Apple and Stripe handle all payment data under their own privacy policies.

Push notification tokens

If you grant permission for push notifications, your device push token is sent to OneSignal (see Third Parties below) so we can send you reminders and updates.

Analytics and crash data

To understand how the app is used and to keep it reliable, we collect product-analytics events (which screens you visit, which buttons you tap, and session recordings with all text inputs and images masked) via PostHog, and uncaught error reports via Sentry. When you are signed in, these events are linked to your account (via your user ID and email) so we can measure things like whether features actually help people return and make progress. We never send the contents of your reflections, identity statements, or questionnaire answers to these tools only structured event names, screen names, durations, counts, and error codes.

Analytics is enabled by default under our legitimate interest in improving and stabilising the Service (see Section 2), and is disclosed to you when you create your account. You can turn it off at any time in Settings → Privacy in the app doing so stops your activity being linked to you and opts you out of further collection.

Support and feedback

When you submit a support ticket or feedback form, we store your message and the email you provide so we can respond.

Technical data

We log which AI-powered features you use (counted, not the content) for rate-limiting purposes this prevents misuse and keeps the service fast and available for everyone.


2. Legal Basis for Processing (GDPR Art. 6)

Under EU law we must have a lawful basis for each category of processing. Ours are:

CategoryLegal basis
Creating and maintaining your account; providing the Service; processing paymentsPerformance of a contract (Art. 6(1)(b))
Generating your AI insights, summaries, vectors, and challengesPerformance of a contract (Art. 6(1)(b))
Storing your self-development data and syncing across devicesPerformance of a contract (Art. 6(1)(b))
Sending transactional emails (trial-ending, receipts, security)Performance of a contract (Art. 6(1)(b))
Running the free web experience at becomingme.co/become before you have an account: holding your email address and the answers you give, and generating your identity statement and challenges from themSteps taken at your request before entering into a contract (Art. 6(1)(b))
Transcribing voice notes you record in the free web experienceSteps taken at your request before entering into a contract (Art. 6(1)(b)) you choose to use the microphone, and typing is always available instead
Sending the follow-up email sequence after you complete the free web experienceYour consent (Art. 6(1)(a)) given when you enter your email to begin, withdrawable by unsubscribing from any of those emails
Push notificationsYour consent (Art. 6(1)(a)) granted via your OS permission prompt
Product analytics and session replay (PostHog) and crash reports (Sentry)Our legitimate interests (Art. 6(1)(f)) improving and stabilising the Service; enabled by default and disclosed at signup, with an opt-out at any time in Settings → Privacy
Community features (your profile shown to other members)Your consent (Art. 6(1)(a)) by completing the optional Community section
Detecting and preventing abuse; rate-limiting AI calls; security loggingOur legitimate interests (Art. 6(1)(f)) keeping the Service safe and available
Complying with tax, accounting, and consumer-law obligationsCompliance with a legal obligation (Art. 6(1)(c))

Special categories of data (GDPR Art. 9)

Some of the free text you write in BecomingMe, such as your reflections, identity statements, patterns, and your daily mood and emotion entries, can reveal special categories of personal data. In particular, it can reveal information about your mental and emotional wellbeing and your religious or philosophical beliefs. We process this data solely to provide your personalised transformation experience, and only on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you give before you share anything.

In the mobile app, you give that consent on a separate, dedicated consent screen during sign-up. In the free web experience at becomingme.co/start, you give it on the second screen, before you have answered anything personal, by pressing a button labelled “Yes, use my answers to build my plan”. Directly above that button, and on screen the whole time it is, we tell you that this covers your answers including the personal ones and link to this policy. Pressing it is the consent; there is no pre-selected box and nothing is agreed to by simply continuing or by staying on the page. In both cases the consent is specific, and it is optional in the sense that you are free to close the page instead.

You can withdraw this consent at any time by deleting your account, which erases this data (see Section 8 on retention). If you used the free web experience without creating an account, email support@becomingme.co and we will erase what we hold.


3. AI-Powered Features

BecomingMe uses artificial intelligence to deliver personalised insights and recommendations. This section explains exactly what data is sent to AI providers and for what purpose.

Anthropic (Claude)

We use Anthropic's Claude AI models to power the following features:

Data sent to Anthropic is used only to generate the response shown to you. We do not use your data to train Anthropic's models. Anthropic's privacy policy applies: anthropic.com/privacy.

OpenAI

We use OpenAI's embedding model (text-embedding-3-small) to convert your profile into a semantic vector. This vector is used internally to personalise content recommendations and if you opt into the Community to help surface members with similar goals.

We also use OpenAI's text-to-speech model to read your personalised visualisation aloud. To do that, the text of that visualisation which is built from your identity statement, your life vision and your intention for the day is sent to OpenAI and returned as audio. It is used only to produce the recording you then listen to.

We also use OpenAI's Whisper speech-to-text model to transcribe voice notes you record on this website, so you can speak your answers instead of typing them. See Speaking instead of typing below for exactly how the audio is handled.

We do not use your data to train OpenAI models. OpenAI's privacy policy applies: openai.com/policies/privacy-policy.

Speaking instead of typing

Several places let you speak your answer rather than type it. How the audio is handled depends on where you are, and the difference matters, so we set both out in full.

In the mobile app. The transcription is done by your device's own operating system, not by us. Where your device supports offline recognition for your language it happens entirely on your phone and the audio never leaves it. Otherwise your device sends the audio to Apple (on iPhone and iPad) or Google (on Android) to transcribe, exactly as it would for any other dictation on that device. BecomingMe never receives, stores, or has access to the audio.

On this website. In our web experience at becomingme.co/become, tapping the microphone records a short audio clip in your browser and sends it to our own server, which forwards it to OpenAI to be transcribed by their Whisper speech-to-text model. The text comes back to the page so you can read and edit it before continuing. The audio is used only to produce that text. It is held in memory for the seconds the transcription takes, is never written to our database or file storage, and is discarded as soon as the text is returned. We do not use your audio or the resulting text to train OpenAI's models.

In both cases, only the resulting text is saved, and only if you keep it. The microphone is never used unless you deliberately tap it, and typing is available on every field. If you would rather no audio were sent anywhere, type your answer instead of using the microphone.


4. How We Use Your Data

We do not sell your personal data, and we do not run any advertising or tracking cookies on becomingme.co. We send nothing about you to any advertising network. Nothing you share inside the experience is used to target ads, here or anywhere else. Full detail in Section 7.


5. Third-Party Services (Processors)

We work with the following carefully selected providers, who act as processors of your data on our behalf. Each handles your data under their own privacy policy and an EU-compliant data-processing agreement.

ProviderPurposeRegion
SupabaseSecure database (Postgres), authentication, file storage, edge functions.EU (Frankfurt)
AnthropicAI analysis Self & Life Analysis, Next Level Self, action recommendations, daily challenges.USA (under SCCs)
OpenAISemantic embeddings for personalisation and community matching; text-to-speech for your personalised visualisation (the text of that visualisation is sent to be read aloud); and Whisper speech-to-text for voice notes you record on this website (the audio is transcribed and then discarded, never stored).USA (under SCCs)
ElevenLabsText-to-speech for our shared, pre-recorded guided audio. It only ever receives our own script text, never anything you write and nothing personal to you.USA (under SCCs)
Apple App StoreIn-app subscription purchases and payment processing.EU + USA
StripeWeb-based subscription payments (if you subscribe via becomingme.co).EU + USA (under SCCs)
OneSignalPush notification delivery (device tokens only never message contents).USA (under SCCs)
ResendTransactional email delivery (trial-ending reminders, receipts).EU/USA (under SCCs)
PostHog (EU Cloud)Product analytics and session replay with all free-text inputs masked.EU (Frankfurt)
Sentry (EU)Application crash and error reporting (PII-redacted).EU (Frankfurt)
CloudflareWebsite hosting (Cloudflare Pages), CDN for media files, and Turnstile bot protection on our sign-up flow. Processes your IP address and basic device signals to serve pages and block automated abuse.Global edge network
Apple / Google (speech)Speech-to-text in the mobile app when you choose to speak instead of type. Your device transcribes on-device where it can; otherwise the audio is transcribed by Apple (iOS) or Google (Android) as part of the operating system. We never receive or store the audio, only the resulting text. Voice notes recorded on this website are handled differently, by OpenAI Whisper (see above).USA / global
Backblaze B2Storage of audio visualisations and instructional videos.EU (Amsterdam)

6. International Data Transfers

Wherever possible we choose EU-hosted providers (Supabase, PostHog, Sentry, Backblaze, Cloudflare). For providers based in the United States (Anthropic, OpenAI, ElevenLabs, Stripe, Apple, OneSignal, Resend), data may be transferred outside the European Economic Area. Each such transfer is protected by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, by the provider's certification under the EU–US Data Privacy Framework.

You can request a copy of the safeguards in place for any specific transfer by emailing info@becomingme.co.


7. Cookies and Similar Technologies (Website)

We never sell or share your data with advertisers. There are no advertising or tracking cookies on this website at all, which is why we do not show you a cookie banner. Everything below is either strictly necessary to deliver the pages you asked for, or has been deliberately configured to store nothing on your device.

Strictly necessary (always on). These are needed to deliver the pages and features you ask for, so they do not require your consent: your sign-in session, the answers you enter during sign-up (kept in your own browser until you create an account), the campaign tag from the link you arrived through (kept only for the current browser tab, so we can record which channel a sign-up came from), cookies set by Stripe during secure checkout to prevent fraud, and Cloudflare Turnstile, which protects our sign-up endpoint from automated abuse.

Analytics (nothing stored on your device). We use PostHog to understand how people move through the site. We have deliberately configured it so that it stores nothing at all on your device: the random identifier that groups your page views into one visit is held in the page's temporary memory and is gone the moment you close the tab. We cannot recognise you on a later visit, and you are counted as a new visitor every time you come back. This runs for everyone and never depends on your answer to the banner, because how people move through the site is how we find what is broken on it.

Advertising. None. We do not run an advertising pixel and we set no advertising cookies. No _fbp, no _fbc, nothing from Meta or any other ad network. Because there is nothing non-essential stored on your device, there is nothing for you to consent to and no banner to answer. If that ever changes we will ask you first, before anything is set.

IP addresses. Your IP address is unavoidably processed whenever you load this site, because it is how the page reaches you. Cloudflare processes it to serve pages and to block automated abuse, and PostHog receives it, where it is used for coarse country-level location and then discarded. We do not use IP addresses to build advertising profiles.

Inside the mobile app, the analytics and crash-reporting SDKs (PostHog and Sentry) are enabled by default to help us improve and stabilise the Service, and can be disabled at any time in Settings → Privacy.


8. Data Retention

DataRetention period
Account and self-development dataFor as long as your account is active. Deleted within 30 days of account deletion.
Subscription and billing recordsUp to 6 years after the last transaction, to comply with Spanish tax and accounting law (Art. 30 Código de Comercio).
Email address of a deleted accountKept indefinitely in our subscription record, on its own, to prevent repeated sign-ups for the free trial. See the note below the table.
Support tickets and feedbackUp to 24 months after the issue is resolved.
Crash reports (Sentry)90 days.
Product analytics events (PostHog)12 months.
Server logs and rate-limit counters30 days.
Anonymised, aggregated statisticsIndefinitely (no personal data).

If you delete your account (via Settings → Account → Delete Account in the app), we process the deletion within 24 hours and permanently remove your personal data from our systems within 30 days. Everything you wrote goes: your vision, goals, identity statements, reflections, analyses, community profile and uploaded images are all erased and cannot be recovered by us or by you.

Two things are deliberately kept. The first is billing records, which Spanish tax and accounting law requires us to retain (see the table above). The second is your email address, which stays in our subscription record after the rest of the account is gone. It is kept on its own, with no remaining link to anything you wrote, and it is used for one purpose only: to recognise that this address has already had a free trial, so the trial cannot be claimed over and over by deleting and re-registering. We rely on our legitimate interest in preventing abuse of the free trial (Art. 6(1)(f) GDPR) for this, and we do not use it to contact you. If you want that record removed as well, email info@becomingme.co and we will erase it, on the understanding that you would then be eligible for a further free trial.


9. Your Rights Under GDPR

You have the right to:

To exercise any right, email info@becomingme.co. We respond within one month, as required by Art. 12(3) GDPR (extendable by a further two months for complex requests, with notice).


10. Security

All data is transmitted over encrypted HTTPS connections. Your account data in Supabase is protected by Row-Level Security policies, which mean each user can only access their own data not other users' data. Secret API keys (Anthropic, OpenAI, Stripe) never leave our secure server environment and are never included in the app itself. Webhooks from Apple and Stripe are signature-verified before being processed.


11. Children's Privacy

BecomingMe is intended only for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal data, please contact us at info@becomingme.co and we will delete it promptly.


12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top. For material changes, we will notify you via email or an in-app notification at least 14 days before the change takes effect.


13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:

BecomingMe Katrin Kurz (autónoma, Spain)
Email: info@becomingme.co
Website: becomingme.co