Legal
Privacy Policy
Last updated: 1 March 2026
Our commitment
Your recovery data is deeply personal. Renovyn is built on a simple principle: your data belongs to you. We will never sell or monetise your personal information. We share it only with the service providers we need in order to run Renovyn, listed below, and only so they can do that job.
Health data under UK GDPR (Article 9)
Addiction recovery data is classified as special category health data under UK GDPR Article 9. We process this data only with your explicit consent, provided when you create an account and configure your addiction profiles. You can withdraw this consent at any time by deleting your account.
What we collect
- Account information: email address, display name, and authentication credentials.
- Recovery data: addiction profiles, daily check-in responses, streak information, and journal entries.
- Location data: danger zone coordinates and proximity alerts. Location data is processed on-device where possible and only transmitted when required for geofencing functionality.
- Financial data: if you use the debt tracker, we store aggregate debt amounts and payoff progress. We never access bank account details directly unless you opt in to open banking integration.
- Usage analytics: pseudonymous usage patterns, such as which screens are opened, tied to a random identifier rather than to your name. They are not fully anonymous: with effort they could be linked back to a device or an account, so we treat them as personal data. Analytics only run if you allow them.
Data minimisation
We collect only what is necessary to provide the service. We do not require your real name. We do not track browsing activity outside the app. We do not build advertising profiles. We do not offer end-to-end encryption: your journal is stored in a form our systems can read, and we would rather tell you that than let you assume otherwise.
Accountability partners
When you add an accountability partner, they receive traffic-light status signals (green, amber, red) based on your check-in patterns. Partners never see your journal entries, specific check-in answers, danger zone locations, or financial data. This is accountability, not surveillance.
Journal privacy
Journal entries (text and audio) travel over an encrypted connection and are stored on our backend provider's infrastructure. They are never shared with accountability partners and never used for analytics. They are not end-to-end encrypted, so a small number of authorised staff can technically reach them. We limit that access to running the service, investigating abuse, and meeting legal obligations. If you delete a journal entry we remove it from our live systems, and copies in routine backups rotate out within 30 days.
Location data
Danger zone geofencing requires location access. We process proximity calculations on your device whenever possible. When server-side processing is required (e.g., for partner alerts), we use only the minimum data needed: whether you are near a zone, not your continuous location. You can disable location features at any time without losing other functionality.
Data retention and deletion
You can export your data at any time (Pro plan). You can delete your account at any time. Deletion removes your account and the personal data we hold about you, including uploaded files, voice recordings and voice-companion transcripts, from our live systems, and copies in routine backups rotate out within 30 days. A small number of records are kept where they are somebody else's data or where the law requires it, for example community content you created that others rely on, and administrative audit logs.
Third parties
A small number of specialist providers process data on our behalf so that Renovyn works. We describe them by what they do rather than by name:
- Hosting and storage: where your account and everything in it lives
- Identity: checks that a sign-in is really you, and nothing more
- Payments: a regulated payment provider. Your card details go to them directly; we never receive or store your full card number
- Email delivery: sends the messages you ask us for, such as sign-in links and receipts
Each provider is contractually bound to process your data only as instructed by us, in compliance with UK GDPR. We do not publish which companies they are. If you want the named list, ask privacy@renovyn.io and we will send it to you.
Your rights
Under UK GDPR, you have the right to: access your data, rectify inaccurate data, erase your data, restrict processing, data portability, object to processing, and withdraw consent. To exercise any of these rights, contact privacy@renovyn.io.
Contact
For privacy-related enquiries, email privacy@renovyn.io. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.