Partfully
Effective date: August 1, 2026
Partfully is a product of CBH Labs LLC, a California limited liability company ("CBH Labs," "we," "our," or "us"). This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using the Partfully application ("App") or website (collectively, the "Service"), you agree to the practices described here.
Partfully uses Firebase Authentication. What we receive depends on how you sign in:
The Service stores the following in Google Cloud Firestore under your user account:
Firestore security rules restrict each of these documents to your own account. Other users cannot read them.
During live voice sessions, your microphone audio is streamed in real time to OpenAI over a direct encrypted connection from your device. We do not record or store your audio. It is processed to generate spoken responses and a live text transcript. That transcript is saved to your journal only if you choose to save the session.
Subscriptions are managed by RevenueCat, using your Firebase user identifier as the account key. On iOS and Android, RevenueCat communicates with Apple's App Store or Google Play; on the web, a payment processor handles checkout. We receive your subscription status, entitlements, and purchase events. We never receive your card number or billing details.
Analytics are off until you accept the consent prompt, and you can turn them off again at any time from Settings → Privacy → Product analytics.
When analytics are on, we use PostHog to record feature-usage events (for example, session starts, page views, and paywall interactions) along with technical metadata such as browser type and app version. These events are associated with your Firebase user identifier. Automatic capture is disabled, and all on-screen text and element attributes are masked, so PostHog does not receive the content of your sessions, transcripts, parts, or notes. PostHog also receives error reports when the App crashes or hits an unexpected condition.
Google Analytics for Firebase is initialized under the same consent and the same opt-out. We do not send it any custom events and do not use it to identify individual users.
On iOS, after you sign in, the App asks permission to send notifications. If you grant it, Apple issues a device token to the App. We do not currently store that token on our servers and we do not send push notifications. You can revoke the permission at any time in your device settings. If we begin sending notifications, we will update this policy first.
If you have an email address on your account, we send transactional messages (welcome, subscription confirmations and failures, account deletion confirmation, and free-session notices) and periodic lifecycle messages (a weekly digest for subscribers, a reminder if you have not finished the intro course, and a win-back note if you have been inactive). Every message includes an unsubscribe link, and your preferences are stored on your account.
Our servers run on Google Cloud. Standard request logs, error logs, and IP addresses are processed by Google's infrastructure for operating, securing, and debugging the Service. We apply per-account rate limits to sensitive endpoints. On the web, Firebase App Check with Google reCAPTCHA Enterprise checks that requests come from the real app. On iOS, App Check uses Apple App Attest to verify authentic app installations.
CBH Labs relies on the following service providers to operate Partfully. Each processes limited data as described below:
| Service | Purpose | Data Shared |
|---|---|---|
| Firebase Authentication (Google) | User sign-in (Google, Apple, email/password, anonymous) | Name, email, user ID, password credential (varies by sign-in method) |
| Apple & Google identity services | "Sign in with Apple" and "Sign in with Google" | OAuth tokens; the identity you choose to share |
| Cloud Firestore (Google) | Data storage | All user-created content listed above |
| Google Cloud & Firebase Hosting | Application hosting and backend API | Request and error logs, IP address |
| OpenAI Realtime API | Live voice sessions | Real-time audio stream and session transcript; the optional guide context from your journal (not stored by us) |
| Google Gemini | Text chat, session summaries and notes, journey insights, parts extraction, guided-meditation audio | Session text, transcript excerpts, your parts and personal notes when generating a guide brief |
| RevenueCat | Subscription management | Firebase user ID, purchase receipts and entitlements |
| Apple App Store / Google Play | In-app purchase and billing | Purchase and subscription data (handled under their own policies) |
| Stripe (via RevenueCat, web only) | Payment processing for web subscriptions | Payment details you enter at checkout — these go to Stripe, not to us |
| PostHog | Product analytics and error reporting (only after consent) | Firebase user ID, feature-usage events, error reports (text masking enabled; no session content) |
| Google Analytics for Firebase | Basic app usage measurement (only after consent) | Automatic SDK measurement data; no custom events are sent |
| Resend | Email delivery | Email address, email content |
| Google reCAPTCHA Enterprise | App Check / abuse detection (web only) | Browser signals, IP address |
| Apple Push Notification service | Notification permission on iOS | Device token issued to the App; not stored by us |
| ElevenLabs & Leonardo AI | Producing course narration and artwork before release | No user data. These run in our build tooling on scripted content, not on anything you create |
Each service is subject to its own privacy policy. We encourage you to review them.
We share your information with these providers only to operate the Service. We do not sell your personal information and we do not share it for advertising. The Service contains no advertising SDKs and no ad-tracking code.
We use the information we collect to:
CBH Labs does not use your session content, transcripts, or parts data to train, fine-tune, or improve any machine learning model. We do not train models of our own, and we do not supply your content to anyone for model training. Your content is sent to the AI providers named above to generate responses; those providers operate their own systems under their published API terms, which we do not control.
Partfully does not use traditional browser cookies or any advertising cookies. We use browser localStorage on your device for the following purposes:
You can clear all localStorage data at any time through your browser or device settings. Doing so will sign you out and reset your consent and analytics preferences.
We do not delete your data on a schedule. Your account data and user-created content are kept until you delete them — either by deleting individual sessions and parts in the App, or by deleting your account. There is no automatic expiry, and we do not currently purge inactive accounts.
When account deletion completes, the data listed in Section 8 is removed from our live systems. We retain a restricted record of the account identifier, deletion status, and timestamps to prevent delayed requests from recreating deleted data. This record contains no session content, profile information, or provider credentials. Copies may persist for a limited period in the routine backups kept by our infrastructure providers, and in the records our subscription and email providers keep for their own legal and accounting purposes.
We use industry-standard security measures to protect your data, including encrypted connections (TLS/HTTPS), Firebase security rules that restrict access to your own data, and secure server-side API key management. However, no system is perfectly secure, and we cannot guarantee absolute security.
The Service is intended for individuals who are at least 18 years of age. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected data from a person under 18, we will take steps to delete it promptly. If you believe someone under 18 has provided us with personal information, please contact us at [email protected].
You can delete your account yourself: open Settings from the home screen, tap Delete Account, and confirm your identity. Deletion cannot be undone. If cleanup fails, the App asks you to retry rather than reporting success. Completed deletion removes:
Deleting your account does not cancel an active subscription. Cancel that separately through the App Store, Google Play, or the management link in Settings. Records held by our subscription provider and our email provider are retained under their own policies, and analytics events recorded before deletion remain in PostHog under a pseudonymous identifier. Email us if you want those removed too.
If you have been using Partfully without signing in, the in-app delete button is not available. Clearing the app's storage or reinstalling removes your access to that anonymous account; email us if you need the stored data deleted.
Depending on your jurisdiction, you may also have the right to:
To exercise any of these rights, please email [email protected]. We will respond within 30 days.
Your data may be processed in the United States or other countries where our third-party service providers operate. Where required by law (such as for transfers from the European Economic Area), we rely on appropriate safeguards including standard contractual clauses adopted by the European Commission. By using the Service, you acknowledge the transfer of your information to these locations.
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) provides you with additional rights and protections.
We process your personal data under the following legal bases:
In addition to the rights listed in Section 8, you have the right to:
To exercise any GDPR right, please contact us at [email protected]. We will respond within 30 days (extendable by 60 days for complex requests, with notice).
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights regarding your personal information:
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. To exercise your California privacy rights, please contact us at [email protected]. We will respond within 45 days.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the App or by other reasonable means, and we will ask you to re-accept the updated policy before continuing to use the Service. The "Effective date" at the top of this page indicates when the policy was last revised.
The data controller responsible for your personal data is:
CBH Labs LLC
A California limited liability company
Email: [email protected]
If you have questions or concerns about this Privacy Policy, our data practices, or wish to exercise any of your rights, please contact us at the email address above.