Privacy Policy
Last updated 6 August 2026
ffeeling exists so you can understand how you really feel. That only works if you trust us with honest entries, so we collect as little as possible, never sell your data, and never show your private notes to your employer. This policy explains what we collect, why, how long we keep it, and the rights you have wherever in the world you live.
1. Who is responsible for your data
For your individual ffeeling account, the ffeeling team is the data controller (the 'business' under US state laws). You can contact us through the contact page on this site for any privacy question or request.
Where you join through an employer's business subscription, that organisation is a controller for the aggregated, anonymised wellbeing insights it receives, and we process member data as described below. Your individual check-ins, scores and context notes remain yours: administrators only ever see organisation-level aggregates and never see your notes.
2. What we collect
Account information: your email address, display name, hashed password (or the identifier from a sign-in provider you choose), your plan, and — for business members — your organisation membership and whether you chose to stay anonymous.
Wellbeing entries you create: your daily feeling selection and score, the life areas or factors you attribute it to, any free-text context notes, and your energy-level logs. In many countries this counts as sensitive or special-category data about your health, so we treat it with extra care.
Preferences and settings: your custom feeling scale, its words and colours, your reminder time and time zone, and your notification or reminder subscriptions.
Technical and security data: IP address, device and browser type, approximate region derived from IP, timestamps, and error or security logs. We use this to keep accounts safe and to fix faults.
Communications: messages you send us through the contact form or by email, and our replies.
Payment information: if you subscribe, our payment provider processes your card details. We never see or store full card numbers — we receive only the subscription status, plan, amount, and a reference.
We do not buy personal data from data brokers, and we do not build advertising profiles about you.
3. Why we use it, and our legal bases
To provide the Service — creating your account, saving your check-ins, generating charts, reports and calendars. Legal basis: performance of our contract with you.
To process sensitive wellbeing entries. Legal basis: your explicit consent, which you give by choosing to record how you feel, and which you can withdraw at any time by stopping check-ins, deleting entries, or closing your account.
To send reminders you have asked for at the time you set. Legal basis: performance of our contract and, where required, your consent.
To keep the Service secure, prevent abuse and debug problems. Legal basis: our legitimate interests in a safe, working service, and our legal obligations.
To handle billing, tax and accounting. Legal basis: contract and legal obligation.
To reply to your messages and provide support. Legal basis: contract and legitimate interests.
To improve the Service using aggregated, anonymised statistics that cannot identify you, and — only if you accept optional cookies — basic product analytics. Legal basis: legitimate interests and, for optional cookies, your consent.
We do not use your data for automated decision-making that has legal or similarly significant effects on you, and we do not profile you for advertising.
4. Anonymity in a workplace setting
When you join through an employer link you can choose to stay anonymous. Your display name is then not shown in anything your organisation sees.
Administrators receive organisation-level aggregates only: overall averages, trends over time, and which life areas are driving feelings across the group. They never receive your individual check-in history, and never receive your context notes.
Where a group is small enough that an aggregate could reveal an individual, we apply minimum-threshold suppression so figures are withheld rather than shown. Attempting to re-identify an individual from aggregated data is prohibited by our Terms.
5. Cookies and similar technologies
We use a small number of strictly necessary cookies and browser-storage items to keep you signed in and to remember your cookie choice. Everything else is optional and only runs if you accept.
If you reject optional cookies, the Service still works fully — we simply clear and stop using non-essential storage. Full detail, including how to change your mind, is in our Cookie Policy.
6. Who we share data with
We share personal data only with service providers who help us run ffeeling, under contracts that limit them to our instructions:
- cloud hosting, database, authentication and file-storage providers
- email delivery and push-notification providers, so reminders and account emails reach you
- payment and subscription providers for billing
- error-monitoring and security tooling
We may also disclose data where we are legally required to, to establish or defend legal claims, or to protect the rights and safety of users — and, if our business is reorganised or acquired, to the successor under equivalent protections.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
7. International transfers
ffeeling is available worldwide, so your data may be processed in countries other than your own, including the United Kingdom, the European Economic Area and the United States.
Where data leaves the UK or EEA, we rely on an adequacy decision where one exists, or otherwise on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with technical measures such as encryption in transit and at rest.
You can contact us for information about the safeguards that apply to a specific transfer.
8. How long we keep it
We keep your account and wellbeing entries for as long as your account is open — that is the point of the product, since long-range reflection needs history.
If you delete an entry, it is removed from your account immediately and purged from backups within 30 days.
If you close your account, we delete or irreversibly anonymise your personal data within 30 days, except where we must keep limited records longer for tax, accounting, fraud-prevention or legal-claim purposes — typically up to six or seven years for billing records.
Anonymised aggregate statistics that can no longer identify you may be retained indefinitely.
9. How we protect it
Data is encrypted in transit and at rest. Access to production systems is limited to those who need it, protected by strong authentication, and logged.
Row-level access rules in our database are designed so one user cannot read another user's entries, and so administrators cannot reach individual member records.
No system is perfectly secure. If a breach affects your rights, we will notify you and the relevant regulators within the timeframes the law requires.
10. Your rights
Wherever you live, you can ask us to:
- access a copy of the personal data we hold about you, in a portable format
- correct anything inaccurate or incomplete
- delete your data and close your account
- restrict or object to certain processing
- withdraw consent you have given, including for sensitive wellbeing data and optional cookies
- opt out of marketing at any time
If you are in the EEA, UK or Switzerland, these rights come from GDPR and UK GDPR, and you may complain to your local supervisory authority — in the UK, the Information Commissioner's Office.
If you are in California, you also have the right to know, delete, correct and limit the use of sensitive personal information, plus the right not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA.
If you are in Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act), Japan (APPI), South Africa (POPIA) or another jurisdiction with equivalent laws, we honour the corresponding rights.
You can exercise most rights directly in the app — export via the report download, edit in settings, delete your account in settings. For anything else, contact us. We respond within 30 days (or one month), and will tell you if we need longer. We do not charge for reasonable requests, and we may need to verify your identity first.
11. Children
The Service is for adults aged 18 and over. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it and the associated data.
12. Changes to this policy
We will post any updated policy here with a new 'last updated' date. Where changes materially affect how we use your data, we will notify you in the app or by email before they take effect, and seek fresh consent where the law requires it.