Privacy Policy.
Odyssey is built on the belief that a reflective practice should be private. This Privacy Policy explains what information we collect when you use the Odyssey iOS app (the "App") and the odyssey.app website (the "Site"), how we use it, who we share it with, and the rights you have over it.
The short version. We collect the minimum data needed to give you an account, take payment, and improve the App. Your journal entries stay on your device and are never transmitted to our servers. We don't sell your data. You can request a copy or deletion of your data at any time.
01Who we are
The data controller responsible for your personal information is Odyssey Commerce LLC, a limited liability company formed under the laws of the State of Wyoming, United States, with its registered office at 1603 Capitol Ave Ste 415, Cheyenne, WY 82001 ("Odyssey", "we", "us", or "our").
For privacy questions, requests, or to exercise the rights described below, contact our privacy team at support@odyssey-store.com.
02What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, hashed password, unique account ID, sign-in timestamps. If you register with Sign in with Apple, we receive the account identifier Apple provides and the email address you choose to share (which may be an Apple private relay address); we do not receive your Apple password. | You, when you create an account (directly or via Sign in with Apple). |
| Subscription data | Subscription status, plan, renewal dates, country, anonymous purchase receipt identifiers. We do not see or store full card details. | Apple (App Store IAP) or Stripe (web purchases). |
| Product analytics | Pseudonymous event data: which lessons were opened, session length, device model, operating-system version, app version, approximate region (country-level). | Automatically, via PostHog. |
| Camera feed (Panic flow) | When you start the in-app Panic flow, the App opens a live camera feed as a real-time grounding and distraction aid. The feed is shown to you on-screen only. No photo or video is recorded, saved, or transmitted, and the feed is not visible to us or any third party. | You, only when you open the Panic flow. |
| Diagnostic logs | Crash reports and error messages — non-personal device + app state at the time of a crash. | Automatically, when an error occurs. |
| Support correspondence | The content of any email you send us and our reply. | You. |
| Journal entries | Stored locally on your device only. Not transmitted to our servers; not visible to us, our staff, or any third party. | You. |
We do not collect: precise location, contacts, your photo library, health-app data, advertising identifiers, or biometric data. The live camera feed used in the Panic flow is processed on your device in real time and is never recorded or stored.
03How we use your information
We use personal information to:
- Provide the Service — authenticate you, deliver lessons, sync your subscription status across devices;
- Process payments — verify in-app purchases with Apple and process web subscriptions via Stripe;
- Improve the App — understand which content users find useful, fix bugs, and prioritise new features (via PostHog and crash reports);
- Communicate with you — respond to support requests, send essential service messages (e.g. password resets, subscription receipts);
- Comply with the law — meet our legal, tax, and regulatory obligations.
We do not use your information for advertising and we do not sell or rent personal information to third parties.
04Legal bases (EU / UK customers)
If you are located in the European Economic Area or the United Kingdom, the EU General Data Protection Regulation ("GDPR") and UK GDPR apply to our handling of your data. We rely on the following legal grounds:
- Performance of a contract — to give you the Service you signed up for (account, subscriptions).
- Legitimate interests — to keep the App secure, prevent abuse, and understand product usage at an aggregate level. You can object to processing on this basis (see Section 8).
- Consent — where required by law (e.g. for certain analytics or marketing communications). You can withdraw consent at any time.
- Legal obligation — where we must process data to comply with a law that applies to us.
05Who we share data with
We share personal information only with the service providers we need to run Odyssey. Each provider acts as our operator/processor under a contract that requires it to protect your data and use it only on our instructions.
| Provider | What they do | Where data is processed |
|---|---|---|
| Apple Inc. | App Store distribution, in-app subscription billing, anonymous purchase receipts. | USA and global. Apple privacy |
| Supabase, Inc. | Account authentication and storage of account/subscription metadata. | USA (and the specific region we have selected). Supabase privacy |
| PostHog, Inc. | Pseudonymous product analytics. | USA / EU. PostHog privacy |
| Superwall, Inc. | Manages and displays subscription paywalls and free-trial offers, and records pseudonymous events about which paywall you saw and whether you subscribed. | USA. Superwall privacy |
| Stripe, Inc. | Payment processing for web subscriptions. | USA and global. Stripe privacy |
We may also disclose information if we are legally required to do so (e.g. in response to a valid court order or regulatory request), or if necessary to protect our rights, your safety, or the safety of others.
If we are ever involved in a merger, acquisition, or asset sale, personal information may be transferred as part of that transaction. We will provide notice before that happens.
06International transfers
We primarily process personal information in the United States. If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with cross-border data-transfer restrictions, your data may be transferred to and stored in the United States. Where required, we rely on safeguards such as Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms recognised under GDPR and the UK GDPR. You can request a copy of the safeguards in place by emailing support@odyssey-store.com.
07How long we keep your data
- Account data — until you delete your account, then up to 30 days for routine backup purges.
- Subscription records — kept for as long as required by applicable US tax and accounting law (typically 3–7 years).
- Analytics events — retained in PostHog for up to 24 months, then aggregated or deleted.
- Crash logs — up to 90 days.
- Support emails — up to 3 years from the last interaction.
- Journal entries — controlled entirely by you on your device. Deleting the App or the entry permanently removes it.
08Your rights
Depending on where you live, you have some or all of the following rights regarding your personal information:
- Access — request a copy of the information we hold about you;
- Correction — ask us to fix information that is inaccurate or incomplete;
- Deletion — ask us to delete your information ("right to erasure");
- Objection / restriction — object to certain processing, including processing based on legitimate interests;
- Withdraw consent — where processing relies on consent;
- Portability — receive a copy of your data in a structured, machine-readable format;
- Lodge a complaint — with the relevant supervisory authority. EU residents may complain to their national data protection authority. UK residents may complain to the ICO. US residents may also contact their state Attorney General's office where applicable.
To exercise any of these rights, email support@odyssey-store.com. We will respond within the timeframe required by applicable law (typically 30–45 days). We may need to verify your identity before acting on a request.
09Security
We take reasonable technical and organisational measures to protect your information, including encryption in transit (TLS), encryption at rest, restricted access to production systems, audit logging, and least-privilege access for staff. No system is perfectly secure; if we ever become aware of a breach that affects you, we will notify you and the relevant regulators in line with applicable US state breach-notification laws and, where applicable, Articles 33–34 of the GDPR.
10Children
Odyssey is not intended for children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, please contact us and we will delete it.
11Cookies and similar technologies (Site only)
The Site uses a small number of strictly necessary cookies (e.g. to support Stripe checkout). It does not set advertising or cross-site tracking cookies. The App does not use cookies. Where applicable law requires consent for non-essential cookies, you will see a notice asking for that consent before they are set.
12California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, "CCPA"), gives you additional rights regarding your personal information. The categories described in Section 2 above ("What we collect") and Section 5 ("Who we share data with") satisfy our CCPA notice-at-collection obligations. Specifically, in the preceding 12 months we have collected the following categories of personal information: identifiers (email address, account ID), commercial information (subscription status), internet or other electronic network activity (pseudonymous analytics events), and inferences drawn from that activity.
As a California resident, you have the right to:
- Know what personal information we have collected about you and how we have used it;
- Delete personal information we hold about you, subject to certain legal exceptions;
- Correct inaccurate personal information we hold about you;
- Opt out of the sale or sharing of your personal information. We do not sell or share your personal information as those terms are defined under the CCPA, including for cross-context behavioural advertising;
- Limit the use and disclosure of sensitive personal information. We do not use sensitive personal information for purposes that would trigger this right under the CCPA;
- Non-discrimination — we will not deny you services, charge different prices, or provide a different level of service because you exercised your CCPA rights.
To exercise any of these rights, email support@odyssey-store.com or use the contact details in Section 14. We may need to verify your identity before fulfilling your request. You may also designate an authorised agent to make a request on your behalf, subject to verification of the agent's authority. We do not knowingly sell or share the personal information of consumers under 16.
13Apple App Tracking Transparency
We do not engage in "tracking" as defined by Apple's App Tracking Transparency framework. We do not link data collected from the App to data collected from third-party apps or websites for advertising purposes, and we do not share data with data brokers.
14Changes to this Policy
We may update this Policy from time to time. If we make a material change, we will provide reasonable advance notice (for example, via the App or by email). The "Last updated" date at the top of this page shows when the current version came into force.
15Contact
For any privacy questions, requests, or complaints, contact our privacy team:
Odyssey Commerce LLC
1603 Capitol Ave Ste 415
Cheyenne, WY 82001
United States
Email: support@odyssey-store.com