This policy explains how the Fenix app and the support pages at getfenix.app handle personal data. Fenix is developed by Walid Dawoud. Privacy questions can be sent to privacy@getfenix.app.
1. Account and profile information
Account creation and authentication. When you create an account, we process your email address, full name, a unique user ID, authentication-provider information, and account-security information. If you use Sign in with Apple, Apple provides an email address (which may be an Apple private relay address) and may provide your name the first time you authorize Fenix. If you use an email and password, Supabase handles authentication and stores a cryptographic password hash; Fenix does not receive or store your password in readable form.
Personalization. We store your selected focus domain and whether you completed onboarding in your account metadata so these choices can be restored on another device.
Profile photo. You may optionally upload a profile photo. It is stored in Supabase Storage. The file is available through a public direct URL, so you should treat an uploaded profile photo as public rather than confidential.
2. Practice data stored in your account
When you are signed in, Fenix stores the following data in Supabase so it can be restored and synchronized across devices:
- Meditation sessions: start and completion times, duration, meditation type, and any optional mood or note you add.
- Affirmation practice: your selected affirmation topic and any custom affirmation sentences you save.
- Lesson and exercise progress: assigned lesson and exercise identifiers, the date assigned, commitment and completion status, and related timestamps.
- Daily ritual progress: the date and whether the day's insight and exercise were completed, including their identifiers.
- Insight history: which insights you opened and the associated date.
- Exercise feedback: the feedback choice you submit (such as "too hard" or "helpful"), the relevant lesson and exercise identifiers, the submission time, and non-text exercise attributes used to improve future suggestions.
Supabase row-level security prevents other ordinary user accounts from reading this account data. Authorized service-provider personnel or the developer may access it only when needed to operate, secure, troubleshoot, or comply with legal obligations.
3. Data stored on your device
Fenix stores local copies of some account and practice data to support offline use and reliable synchronization. Pending changes may remain in a local retry queue until they can be sent to Supabase.
Theme and language preferences, notification permission state, scheduled notifications, and most interface preferences are stored on the device. The native app stores its authentication session encrypted at rest, with the encryption key held in the device Keychain or Keystore.
Meditation reminders are scheduled and delivered by the operating system on your device. Fenix does not collect a push-notification token or send reminders through a Fenix server. As described below, analytics events do record when a reminder is enabled or disabled and the selected reminder hour and minute.
4. Product analytics
We use PostHog to understand how Fenix is used and improve the product. Fenix sends events such as:
- opening lessons or insights and sharing an insight quote;
- committing to or completing an exercise;
- submitting an exercise-feedback choice;
- starting, pausing, resuming, cancelling, or completing a meditation, including its type and duration;
- enabling, disabling, or changing the time of a meditation reminder;
- completing onboarding, including the selected focus domain; and
- opening a screen inside the app, recorded as the screen's route name.
Screen names are the app's own route patterns, such as /meditation or /lesson/[lessonSlug]. They record which screen you opened, never which lesson, insight, or affirmation you were reading on it.
These events can include lesson, insight, exercise, and assignment identifiers or slugs, completion state, feedback choice, reminder hour and minute, meditation duration, streak count, screen route name, app version, operating-system and device information, and a PostHog-generated device identifier.
When you are signed in, Fenix identifies your analytics profile with your Supabase user ID, so the events above are linked to your account rather than only to your device. This is what lets us see whether a change actually helps the same person over time, and on more than one device. Fenix does not send PostHog your name, email address, profile photo, meditation-note text, mood value, or custom affirmation text. If you turn Usage Analytics off in Settings, no events and no identification are sent at all.
PostHog and other network providers may receive technical connection information, such as your IP address, as part of delivering their services. Fenix does not request or send precise GPS location.
5. Crash reports and performance data
We use Sentry in production to diagnose crashes, errors, and problems the app recovered from without interrupting you, such as a practice entry that could not reach the server. Sentry may receive stack traces, breadcrumbs, performance timings, app version, operating system, device details, and technical connection information. When you are signed in, crash and error reports also carry your Supabase user ID, so a repeated failure can be traced to one account instead of guessed at. Fenix does not send Sentry your name, email address, passwords, meditation notes, custom affirmations, or profile photos. Technical error context can nevertheless contain incidental information, so access is limited to troubleshooting and security purposes.
6. Camera, photos, microphone, and location
If you choose to add a profile photo, Fenix asks for camera or photo-library access only to take or select that image. Fenix does not use microphone permission and does not request precise or approximate device-location permission.
7. Service providers and disclosures
We use the following providers to operate Fenix:
- Supabase: database hosting, authentication, account management, and file storage.
- Resend: delivery of account confirmation, password-reset, email-change, and security emails.
- PostHog: product analytics described in section 4.
- Sentry: crash reporting and performance monitoring described in section 5.
- Apple: authentication when you choose Sign in with Apple.
- Netlify: hosting for getfenix.app; routine web-server records may include an IP address, browser information, requested page, and timestamp.
- IONOS: email hosting for messages you choose to send to our @getfenix.app contact addresses.
We do not sell personal data, use advertising SDKs, or share data for cross-app advertising or tracking.
8. Retention and account deletion
Account and synchronized practice data are retained while your account exists. You can delete your account inside Fenix. A successful deletion removes your Supabase authentication account, the account-linked database records listed in section 2, and avatar files stored for that account. The app also clears its locally stored authenticated session, Fenix practice data and preferences, pending synchronization queue, in-memory query cache, and scheduled Fenix meditation notifications from that device.
Analytics and crash records are linked to your Fenix account, as described in sections 4 and 5. When you delete your account, Fenix also asks PostHog to delete the analytics profile and recorded events belonging to that account. Crash and error reports held by Sentry are not deleted at that moment; they age out according to Sentry's retention period, and you can ask us to remove them sooner at privacy@getfenix.app. Both providers may retain records longer where their own operational requirements demand it. Support or privacy correspondence may be retained as needed to respond, maintain security records, and meet legal obligations. Provider backups and security logs may persist for a limited period before deletion or rotation.
9. Your choices and rights
You can edit your name and email, change your password, remove your profile photo, manage notification permission in device settings, and delete your account from within the app. Depending on where you live, you may also have rights to access, correct, export, restrict, object to processing of, or delete your personal data. Contact privacy@getfenix.app to make a request.
10. Children
Fenix is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided personal data, contact privacy@getfenix.app.
11. Changes and contact
If we materially change how we handle personal data, we will update this page and its effective date.
Privacy questions and requests: privacy@getfenix.app.