Privacy Policy
Last updated: 21 July 2026
BecomingMe (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal information when you use our mobile application and website (collectively, the “Service”). It is written to meet the requirements of the EU General Data Protection Regulation (“GDPR”) and applicable Spanish data-protection law. Please read it carefully. By using BecomingMe, you agree to the practices described here.
Questions? Email us at info@becomingme.co.
0. Who is responsible for your data
The data controller is Katrin Kurz, trading as BecomingMe, registered as an autónoma in Spain. Contact: info@becomingme.co. If you would like our postal address for a formal data-subject request, email us and we will provide it.
We do not currently have a statutory obligation to appoint a Data Protection Officer. If you have a concern you cannot resolve with us directly, you may lodge a complaint with the Spanish data-protection authority, Agencia Española de Protección de Datos (aepd.es), or with your local supervisory authority in the EU/UK.
1. What We Collect
Account information
When you create an account we collect your first name, email address, and a password. Your password is never stored in plain text; it is hashed by our authentication provider.
Community profile
If you complete the Community section of the app, you may provide optional information such as your location, profession, languages, a profile photo, a bio, and answers to community prompt questions. This information is visible to other authenticated members of the app.
Self-development data
The core of BecomingMe is personal growth work. We store the responses you provide throughout the app, including:
- Your Self & Life Analysis questionnaire answers and clarity score
- Your Life Vision focus areas, visions, and goals
- Your Next Level Self patterns (old beliefs, emotions, habits; new targets; KPIs)
- Your Effective Action plans and daily actions
- Your Daily Alignment sessions mood, visualisation notes, embodiment challenges, reflections, and alignment scores
- Your weekly streak data
- A numerical “user vector” (a mathematical embedding derived from your free-text answers) used to personalise content recommendations inside the app
This data is private to you and is never sold or shared with third parties for marketing purposes.
Subscription and payment information
We store your subscription status, plan type, and subscription period so the app can grant you access. Payment processing is handled entirely by Apple (via the App Store) or Stripe (via our website). We never store your credit-card number, CVV, or full payment details Apple and Stripe handle all payment data under their own privacy policies.
Push notification tokens
If you grant permission for push notifications, your device push token is sent to OneSignal (see Third Parties below) so we can send you reminders and updates.
Analytics and crash data
To understand how the app is used and to keep it reliable, we collect product-analytics events (which screens you visit, which buttons you tap, and session recordings with all text inputs and images masked) via PostHog, and uncaught error reports via Sentry. When you are signed in, these events are linked to your account (via your user ID and email) so we can measure things like whether features actually help people return and make progress. We never send the contents of your reflections, identity statements, or questionnaire answers to these tools only structured event names, screen names, durations, counts, and error codes.
Analytics is enabled by default under our legitimate interest in improving and stabilising the Service (see Section 2), and is disclosed to you when you create your account. You can turn it off at any time in Settings → Privacy in the app doing so stops your activity being linked to you and opts you out of further collection.
Support and feedback
When you submit a support ticket or feedback form, we store your message and the email you provide so we can respond.
Technical data
We log which AI-powered features you use (counted, not the content) for rate-limiting purposes this prevents misuse and keeps the service fast and available for everyone.
2. Legal Basis for Processing (GDPR Art. 6)
Under EU law we must have a lawful basis for each category of processing. Ours are:
| Category | Legal basis |
|---|---|
| Creating and maintaining your account; providing the Service; processing payments | Performance of a contract (Art. 6(1)(b)) |
| Generating your AI insights, summaries, vectors, and challenges | Performance of a contract (Art. 6(1)(b)) |
| Storing your self-development data and syncing across devices | Performance of a contract (Art. 6(1)(b)) |
| Sending transactional emails (trial-ending, receipts, security) | Performance of a contract (Art. 6(1)(b)) |
| Push notifications | Your consent (Art. 6(1)(a)) granted via your OS permission prompt |
| Product analytics and session replay (PostHog) and crash reports (Sentry) | Our legitimate interests (Art. 6(1)(f)) improving and stabilising the Service; enabled by default and disclosed at signup, with an opt-out at any time in Settings → Privacy |
| Community features (your profile shown to other members) | Your consent (Art. 6(1)(a)) by completing the optional Community section |
| Detecting and preventing abuse; rate-limiting AI calls; security logging | Our legitimate interests (Art. 6(1)(f)) keeping the Service safe and available |
| Complying with tax, accounting, and consumer-law obligations | Compliance with a legal obligation (Art. 6(1)(c)) |
Special categories of data (GDPR Art. 9)
Some of the free text you write in BecomingMe, such as your reflections, identity statements, patterns, and your daily mood and emotion entries, can reveal special categories of personal data. In particular, it can reveal information about your mental and emotional wellbeing and your religious or philosophical beliefs. We process this data solely to provide your personalised transformation experience, and only on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you give during sign-up on a separate, dedicated consent screen before you share anything. You can withdraw this consent at any time by deleting your account, which erases this data (see Section 8 on retention).
3. AI-Powered Features
BecomingMe uses artificial intelligence to deliver personalised insights and recommendations. This section explains exactly what data is sent to AI providers and for what purpose.
Anthropic (Claude)
We use Anthropic's Claude AI models to power the following features:
- Self & Life Analysis summary your questionnaire answers are sent to generate a personalised written insight across five dimensions of your life
- Next Level Self pattern candidates your 10 NLS questionnaire answers are used to identify the patterns holding you back and generate a set of pattern cards for you to review
- Action recommendations your goals are used to generate specific, practical action steps
- Onboarding action plan your life focus area, goal, identity statement, and biggest block are used to generate your first personalised action steps
- Daily embodiment challenges your overall profile is used to generate three tailored daily challenges during your Daily Alignment
- New pattern suggestions when you confirm a limiting pattern, Claude suggests an empowering new belief, emotion, and habit for the other side
Data sent to Anthropic is used only to generate the response shown to you. We do not use your data to train Anthropic's models. Anthropic's privacy policy applies: anthropic.com/privacy.
OpenAI
We use OpenAI's embedding model (text-embedding-3-small) to convert your profile into a semantic vector. This vector is used internally to personalise content recommendations and if you opt into the Community to help surface members with similar goals. We do not use your data to train OpenAI models. OpenAI's privacy policy applies: openai.com/policies/privacy-policy.
4. How We Use Your Data
- To provide and personalise the BecomingMe app experience
- To sync your data across your devices
- To generate personalised AI insights, recommendations, and challenges
- To process and manage your subscription
- To send push notification reminders (only with your permission)
- To send transactional emails (e.g. trial-ending reminders) to the email address on your account
- To respond to support requests
- To detect and prevent abuse or policy violations
- To improve the reliability and performance of the Service
We do not sell your personal data. We do not use your data for advertising. We do not run third-party advertising or marketing cookies on becomingme.co.
5. Third-Party Services (Processors)
We work with the following carefully selected providers, who act as processors of your data on our behalf. Each handles your data under their own privacy policy and an EU-compliant data-processing agreement.
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Secure database (Postgres), authentication, file storage, edge functions. | EU (Frankfurt) |
| Anthropic | AI analysis Self & Life Analysis, Next Level Self, action recommendations, daily challenges. | USA (under SCCs) |
| OpenAI | Semantic embeddings for personalisation and community matching. | USA (under SCCs) |
| Apple App Store | In-app subscription purchases and payment processing. | EU + USA |
| Stripe | Web-based subscription payments (if you subscribe via becomingme.co). | EU + USA (under SCCs) |
| OneSignal | Push notification delivery (device tokens only never message contents). | USA (under SCCs) |
| Resend | Transactional email delivery (trial-ending reminders, receipts). | EU/USA (under SCCs) |
| PostHog (EU Cloud) | Product analytics and session replay with all free-text inputs masked. | EU (Frankfurt) |
| Sentry (EU) | Application crash and error reporting (PII-redacted). | EU (Frankfurt) |
| Cloudflare | Website hosting (Cloudflare Pages) and CDN for media files. | Global edge network |
| Backblaze B2 | Storage of audio visualisations and instructional videos. | EU (Amsterdam) |
6. International Data Transfers
Wherever possible we choose EU-hosted providers (Supabase, PostHog, Sentry, Backblaze, Cloudflare). For providers based in the United States (Anthropic, OpenAI, Stripe, Apple, OneSignal, Resend), data may be transferred outside the European Economic Area. Each such transfer is protected by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, by the provider's certification under the EU–US Data Privacy Framework.
You can request a copy of the safeguards in place for any specific transfer by emailing info@becomingme.co.
7. Cookies and Similar Technologies (Website)
The becomingme.co website uses strictly necessary cookies only small files set by Stripe during the secure-checkout flow to prevent fraud and complete payment. We do not run any marketing, advertising, or third-party analytics cookies on the website. Because we only use strictly necessary cookies, no cookie banner is required under the ePrivacy Directive.
Inside the mobile app, the analytics and crash-reporting SDKs (PostHog and Sentry) are enabled by default to help us improve and stabilise the Service, and can be disabled at any time in Settings → Privacy.
8. Data Retention
| Data | Retention period |
|---|---|
| Account and self-development data | For as long as your account is active. Deleted within 30 days of account deletion. |
| Subscription and billing records | Up to 6 years after the last transaction, to comply with Spanish tax and accounting law (Art. 30 Código de Comercio). |
| Support tickets and feedback | Up to 24 months after the issue is resolved. |
| Crash reports (Sentry) | 90 days. |
| Product analytics events (PostHog) | 12 months. |
| Server logs and rate-limit counters | 30 days. |
| Anonymised, aggregated statistics | Indefinitely (no personal data). |
If you delete your account (via Settings → Account → Delete Account in the app), we process the deletion within 24 hours and permanently remove your personal data from our systems within 30 days, except where we are required by law to retain specific records (e.g. billing records, as above).
9. Your Rights Under GDPR
You have the right to:
- Access request a copy of the personal data we hold about you.
- Rectification correct inaccurate or incomplete data; most fields are directly editable in Settings → Account.
- Erasure (“right to be forgotten”) delete your account in-app, or email us.
- Portability receive your data in a structured, machine-readable format; email us.
- Restriction ask us to pause processing while a dispute is resolved.
- Objection object to processing based on our legitimate interests.
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal. You withdraw consent for your sensitive reflections (special categories, Art. 9) by deleting your account, and for community features or push notifications in the app. Analytics runs under our legitimate interest, so you opt out of it in Settings → Privacy or object to it under the right above.
- Lodge a complaint with the Spanish supervisory authority (AEPD) or your local EU/UK supervisory authority.
To exercise any right, email info@becomingme.co. We respond within one month, as required by Art. 12(3) GDPR (extendable by a further two months for complex requests, with notice).
10. Security
All data is transmitted over encrypted HTTPS connections. Your account data in Supabase is protected by Row-Level Security policies, which mean each user can only access their own data not other users' data. Secret API keys (Anthropic, OpenAI, Stripe) never leave our secure server environment and are never included in the app itself. Webhooks from Apple and Stripe are signature-verified before being processed.
11. Children's Privacy
BecomingMe is intended only for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal data, please contact us at info@becomingme.co and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top. For material changes, we will notify you via email or an in-app notification at least 14 days before the change takes effect.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:
BecomingMe Katrin Kurz (autónoma, Spain)
Email: info@becomingme.co
Website: becomingme.co