Sensa Privacy Policy

Effective Date: 4 August 2026
Last Updated: 4 August 2026
Version: 1.2

1. Who We Are

Sensa is a mobile application for self-reflection and emotional awareness, developed by Mikhail Gigolaev (hereinafter "we", "us", "our"), an individual acting as an independent developer.

Contact Information:

  • Name: Mikhail Gigolaev
  • Address: Tbilisi, Iosif Pilsudski av, 9, 187, Georgia
  • Email for privacy inquiries: privacy.sensa@gigolaev.com

This Privacy Policy describes what data we collect, why, how we protect it, and what rights you have. By using Sensa, you agree to the terms of this Policy.


2. What Data We Collect

We collect the minimum data necessary for the application to function. Your entries remain yours.

2.1 Data You Provide Directly

During registration:

  • Email address (for login and account recovery)
  • Password (stored in encrypted form; we do not have access to it)

When signing in with Apple:

  • Anonymized Apple ID identifier
  • Email (real or Apple's private relay email — at your discretion)
  • Name (if you choose to share it)

When signing in with Google:

  • Google account identifier
  • Account email address
  • Name and profile picture link, if present in the account

While using the application:

  • Journal entries (free-form text, notes, thoughts)
  • Mood data (selected intensity, emotions, life areas)
  • Coping cards (categories created by you: Thoughts, Situations, Self-support, Values)
  • Completed practice sessions (breathing, mindfulness — completion record, duration, selected parameters)
  • Photos attached to entries — these remain on your device, see section 5
  • Entry location, if you attach one — see section 2.5
  • Profile picture (avatar) — this remains on your device, see section 5
  • Application settings (theme, interface language, entry templates, section visibility, reminders)

2.2 Anonymous Mode

If you use Sensa without registration (anonymous mode), we create an anonymous technical identifier for you in Firebase. Your data is stored on this device and in our database under this anonymous identifier, but without any link to an email address or your identity.

2.3 Technical Data

The application collects no technical telemetry. Sensa contains no crash reporting, no performance monitoring, and no usage statistics.

Only two Google Firebase services are used in the application: authentication and the Firestore database. Device model, system version, device identifier, IP address, and error stack traces are neither collected nor stored by us.

One thing outside our control is worth noting: Apple collects anonymized statistics and crash reports on the App Store and TestFlight side and provides them to developers in aggregated form. This happens through the operating system and the app store, not through Sensa's code.

2.4 What We Do Not Collect

We intentionally do not use:

  • Advertising trackers and identifiers
  • Behavioral analytics and usage statistics (Firebase Analytics, Mixpanel and similar)
  • Social SDKs (Facebook, TikTok, Snapchat, etc.)
  • Microphone and audio recording
  • Contacts, calendar, health data
  • Background location tracking
  • Tracking cookies

Voice input. The "Voice" button in the editor opens the system keyboard and explains how to use iOS dictation. The application does not record audio, does not access the microphone, and does not request access to it — Sensa holds no microphone permission at all. Dictation is handled entirely by the operating system.

Camera and photos. Access is requested only at the moment you add a photo to an entry or choose an avatar yourself. The application does not browse your photo library and has no access to it outside that action.

We do not profile you, do not show advertising, and do not transfer your data to third parties for marketing purposes.

2.5 Entry Location

You can attach a location to an entry. This is always a deliberate action on your part — a location is never added automatically.

There are two ways to do it, and they produce different data:

  • Choosing a place from search or from the "Nearby" list — the coordinates of the selected place are saved (a café, a park, a street), not your own
  • Tapping "Current location" — the coordinates of your device and their accuracy are saved

In both cases the entry stores: the place name and its subtitle, latitude and longitude, the date and time it was added, and the method used — so that it is always clear whose coordinates these are. Accuracy is stored only for the current-location case.

Coordinates are requested at reduced accuracy — roughly one hundred metres, not at full satellite-navigation precision.

If you have previously granted location access, Sensa determines your position once when the place picker opens, in order to show a list of nearby places. If access has not been granted, no request is made and the system permission dialog is not shown.

Sensa does not track your movements, does not access location in the background, and does not request persistent access — only access while the application is in use.

An attached location can be removed from an entry at any time through the editor.


3. Why We Collect This Data

Email and password / Apple ID — for authentication and account recovery.

Entry content — this is the core function of the application: your personal journal. We store this data so you can revisit your entries, track mood patterns over time, and reflect on yourself.

Photos and avatar — so that an entry can hold more than text, and your profile looks the way you want it to. These files remain on your device.

Entry location — so you can recall the circumstances in which an entry was written. Context often reveals the connection between a state and a situation.

We do not use your data to:

  • Build psychological profiles
  • Analyze your emotional state
  • Share with anyone (including researchers, advertisers, insurance companies)
  • Train artificial intelligence models

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), the following legal bases for processing personal data under the GDPR apply:

  • Performance of a contract (Article 6(1)(b) GDPR) — processing your email, password, and entry content is necessary to provide the functionality of the application that you agreed to upon registration
  • Consent (Article 6(1)(a) GDPR) — for features requiring separate permission: camera and photo library access when adding a photo, location access when attaching a place. You grant each of these permissions separately and can withdraw them in your device settings

We carry out no processing on the basis of legitimate interest: no telemetry is collected, there is no analytics, and no grounds for such processing arise.


5. Where and How Your Data Is Stored

Sensa's data is split into two circuits, and the difference between them is substantial.

5.1 On the device only

This data never leaves your phone: it is not uploaded to the cloud, not synchronised between devices, and not accessible to us under any circumstances.

  • Photos attached to entries
  • Profile picture (avatar)

The files are kept in the application's internal storage, which other applications cannot reach. Deleting Sensa from your device deletes them with it. Opening your journal on another device, you will see the entry text but not its photos.

A dedicated barrier in the code enforces this: before anything is sent to the cloud, all local file paths are stripped from the entry data. The barrier is duplicated at two levels and covered by automated tests.

5.2 On the device and in the cloud

The application works offline: the local copy is primary, the cloud serves as synchronisation and backup. Synchronised data:

  • Entry text, completed templates, mood, emotions, life areas
  • Coping cards
  • History of completed practices
  • Settings, including interface language and reminders
  • Entry location, if you attached one

The cloud part is stored on Google Firebase infrastructure, in the europe-west3 (Frankfurt, Germany) region. This is European Union territory, where the GDPR applies — one of the strictest data protection standards in the world.

Protection:

  • Data transmission from device to server is protected by TLS 1.3 encryption
  • Data at rest on Google's servers is encrypted (encryption at rest)
  • Database access is controlled by Firestore security rules: each user can access only their own data
  • No one, including us, can access your entries without your authorization

Technical processor: Google LLC, acting under a Data Processing Agreement with Firebase. Details: firebase.google.com/support/privacy.


6. Sharing Data with Third Parties

We do not sell and do not share your personal data with third parties for commercial, marketing, or any other purposes.

Two companies provide technical services involved in the operation of the application.

Google LLC (Firebase) — cloud infrastructure for data storage and authentication. Google acts as a data processor on our behalf and is not entitled to use your data for its own purposes. Terms: cloud.google.com/terms/data-processing-addendum. If you signed in with Google, Google also acts as your sign-in provider.

Apple Inc. — involved when you work with entry locations. Three cases:

  • Place search. Your search text and the approximate search area are sent to Apple's mapping service
  • Resolving a name from coordinates. When you tap "Current location", your device coordinates are sent to Apple's geocoder to obtain a readable place name
  • Map in entry view. Map tiles are loaded from Apple's servers

We do not control how Apple handles these requests — they are governed by Apple's privacy policy. The content of your entries, your emotions, your mood, and your email are never sent to Apple. If you never attach a location to your entries, no requests to Apple's services occur at all.

If you signed in with Apple, Apple also acts as your sign-in provider.

We may disclose your data only in the following cases:

  • Legal request from competent state authorities of Georgia or your country of residence
  • Protection of life and safety (e.g., a clear threat of harm to self or others — an extremely rare case)

In the event of such disclosure, we will do our best to notify you in advance, unless prohibited by law.


7. How Long We Store Your Data

Your data is stored for as long as your account exists. You may delete it at any time from within the application.

When an account is deleted:

  • Local data is wiped from the device immediately — including photos attached to entries and your avatar
  • Deleting the account triggers a server function that removes your entire section of the database, together with entries, coping cards, practice history, and settings

When a single entry is deleted, the photos attached to it are deleted as well.

When you sign out, local data — including photos and avatar — is also wiped from the device. The cloud copy is retained and returns on your next sign-in.

Firebase backups may contain your data for up to 30 days after deletion — this is a technical feature of Google's infrastructure. After this period, the data is fully deleted.

One separate case — moving from anonymous mode to an account. If you used Sensa without registration and then created an account, your entries are transferred into it. The previous anonymous technical identifier is not deleted automatically, and the database section linked to it may persist. It contains neither your email nor your name and is not connected to anything, but if you want it removed, write to us and we will delete it manually.


8. Your Rights

You have full control over your data. Under the GDPR and the Law of Georgia on Personal Data Protection, you have the right to:

  • Access — find out what data we hold about you (most of it is visible directly in the application)
  • Rectification — correct or complete any data (this can be done in the application)
  • Erasure ("right to be forgotten") — delete your account and all associated data through the application settings
  • Data Portability — receive a copy of your entries in a machine-readable format (JSON). To request, write to privacy.sensa@gigolaev.com
  • Restriction of Processing — request temporary suspension of processing
  • Object to Processing — opt out of processing based on legitimate interest
  • Withdraw Consent — withdraw previously given consent at any time (this does not affect the legitimacy of data processed prior to withdrawal)

To exercise any of these rights, write to privacy.sensa@gigolaev.com. We will respond within 30 days.

Complaints:

If you believe we have violated your rights, you may file a complaint with:

  • The Personal Data Protection Service of Georgia — personaldata.ge
  • The data protection supervisory authority of your country (for EU users)

9. Children

Sensa is not intended for children under 16 years of age. We do not knowingly collect personal data from minors. If you are a parent or legal guardian and discover that your child has registered with Sensa without your consent — please contact us, and we will delete the account.


10. Data Security

We apply technical and organizational measures to protect your data:

  • Encryption in transit (TLS 1.3)
  • Encryption at rest (Google Firebase encryption at rest)
  • Two-factor authentication for the developer
  • Firestore security rules restricting access exclusively to the data owner
  • Minimization of data collected
  • Regular updates of dependencies and security patches

Despite all measures, no system is absolutely secure. In the event of a security incident that may affect your data, we will notify you within 72 hours of detection — as required by GDPR.


11. Sensa Is Not a Medical Product

Sensa is a tool for self-reflection and emotional self-regulation. Sensa is not a medical device, does not diagnose, does not prescribe treatment, and does not replace psychotherapy, medical, or psychiatric care.

If you are experiencing acute emotional distress, suicidal thoughts, or a crisis — please contact a psychotherapist, psychiatrist, or family doctor. In life-threatening situations, call your regional emergency service.

In the "Settings → Help" section within the application you will find emergency service numbers for your country.


12. Changes to This Policy

We may update this Policy from time to time. We will notify you of any material changes:

  • Through a push notification or banner in the application
  • By email, to the address provided at registration

The last update date is always shown at the beginning of the document. Continued use of the application after the Policy is updated means acceptance of the new version.


13. Governing Law and Dispute Resolution

This Policy is governed by the laws of Georgia. All disputes are resolved in the courts of Georgia at the location of the data controller.

For users in the European Union, the provisions of the GDPR additionally apply. You have the right to contact the data protection supervisory authority in your country of residence.


14. Contact

For any questions regarding privacy and data processing:

Email: privacy.sensa@gigolaev.com

Mailing Address: Mikhail Gigolaev, Tbilisi, Iosif Pilsudski av, 9, 187, Georgia

We respond to inquiries within 30 days of receipt.


This Privacy Policy is available in Russian, English and Georgian. All three versions are equally authentic. In case of any discrepancy between the versions, the version in the language in which you accessed the document prevails.