legal

Privacy Policy — DRAFT

⚠️ DRAFT — NOT LEGAL ADVICE. Do not publish until an attorney reviews it. This is founder homework (per docs/legal/README.md): a customized starting draft that reflects the platform's actual data practices so counsel edits rather than starts from a blank page. [BRACKETED] items need a decision or verification. The voice-biometric section ties to LEGACY_VOICE_CONSENT_COUNSEL_BRIEF.md.

Effective date: [DATE] · Operator: Point Seven Studio LLC ([STATE OF FORMATION]) · Contact: [privacy@…]

This Privacy Policy explains how Point Seven Studio LLC ("we," "us") collects, uses, and shares information across our services, including HiveJournal (hivejournal.com), Graphene (graphene.fm), write.cafe, Lovio (lovio.io), DreamPro (dreampro.io), and EmberKiln (collectively, the "Services"). It applies to all of them; where a specific brand differs, we say so.

1. Who this applies to & age

The Services are intended for users 18 and older [CONFIRM age threshold with counsel — journaling/voice data + COPPA argue for 18+; if 13+ is allowed on any surface, a separate parental-consent flow is required]. Child-directed offerings (e.g., a future "DreamPro Junior") are not live and will have their own COPPA-compliant flow before launch.

2. Information we collect

You give us:

  • Account data — email, name, password (hashed), and profile details; or, if you sign in with Google, your Google account identifiers.
  • Your content — journal entries, notes, stories, comments, and other text you create. Journal content is personal and often sensitive, and we treat it accordingly.
  • Voice recordings & voice clones — audio you record (voice notes, consent recordings, and reading samples used to create a synthetic "clone" of your voice). See §5 — this is biometric data.
  • Wellness inputs — mood, tone, satisfaction, sleep, habit/goal, and check-in data you choose to enter. This is self-reported wellbeing data, not medical data (see §6 and the Terms).
  • Payment info — handled by our processor (Stripe); we do not store full card numbers.
  • Communications — messages you send us and your email preferences.

Collected automatically:

  • Usage/analytics events, device and browser data, IP address, and cookies/identifiers (see §8).

From third parties you connect:

  • If you link an integration (e.g., Spotify), we receive data from that service per your authorization.

3. How we use information

To provide, operate, personalize, and improve the Services; to generate AI features you request (§4); to process payments and creator payouts; to communicate with you; to maintain safety, security, and integrity; to comply with law; and for analytics to understand and improve the product.

4. AI processing of your content

Core features use large language models and other AI to process content you provide or request — for example, generating stories (Odessa), summaries, narration, coaching prompts, and companion (JQ) responses. To do this we send relevant content to AI providers, currently OpenAI and Anthropic, acting as our processors. [CONFIRM: under these providers' API terms, submitted content is not used to train their models; state that commitment here once verified.] AI output can be inaccurate or unexpected and is not professional, medical, legal, or financial advice.

5. Voice & biometric data (please read)

Creating a voice "clone" involves a voiceprint, which may be a biometric identifier under laws such as the Illinois Biometric Information Privacy Act (BIPA), Texas CUBI, and Washington law. [This entire section is counsel-gated — align it with LEGACY_VOICE_CONSENT_COUNSEL_BRIEF.md and finalize the retention schedule + written-consent language before publishing.]

  • What we collect: the audio samples you provide and a synthetic voice model generated from them by our vendor, ElevenLabs, acting as our processor.
  • Consent: we create a voice clone only with your explicit, recorded consent, and only to speak your own content back to you (and, where you set it up, to deliver your own recordings to people you choose). We do not use your voice to narrate anyone else's content. [Facilitated/eldercare "subject-consents / facilitator-operates" flows are governed separately — see the consent design + counsel brief — and are not live.]
  • Retention & destruction: [STATE the specific retention period + destruction schedule required by BIPA-class law.]
  • No sale / no profit-from-biometrics: we do not sell your biometric data or otherwise profit from it beyond providing the Service.
  • Your control: you can retire/delete your voice clone at any time, which removes it from active use [confirm downstream deletion at ElevenLabs + our storage timeline].

6. Wellness data is not medical data

Mood, coaching (DreamPro), and reflective features are wellbeing tools, not medical or clinical services, and we are not a HIPAA-covered entity for consumer use of the Services. Any provider-facing feature (e.g., Throughline) operates on metadata-only, consent-based sharing and is described separately. [Confirm HIPAA-scope posture with counsel; keep the family/consumer as the contracting party.]

7. How we share information

We do not sell your personal information. We share it with:

  • Service providers / subprocessors who process data on our behalf, currently: Supabase (database, storage, auth), Stripe (payments), OpenAI and Anthropic (AI processing), ElevenLabs (voice synthesis/cloning), Replicate (image/video generation), PostHog and Google Analytics (analytics), Meta (advertising pixel), Resend (email), Cloudflare Turnstile (bot protection), Vercel and Railway (hosting), and print/fulfillment + social partners (Gelato, Lulu, YouTube, Bluesky) where you use those features. [Verify this list is current + complete before publishing; consider a maintained subprocessor page.]
  • Other users, only for content you choose to make public or share.
  • Legal / safety recipients when required by law or to protect rights and safety.
  • Business transfers (e.g., a merger or acquisition), subject to this Policy.

8. Cookies, analytics & advertising

We use cookies and similar technologies for authentication, preferences, analytics (PostHog, Google Analytics), and advertising measurement (Meta Pixel). [Add a cookie banner / consent management where required (EU/UK, and "Do Not Sell/Share" for CA); describe opt-outs.]

9. Your rights & choices

Depending on where you live (e.g., California/CCPA-CPRA, EU/UK GDPR), you may have rights to access, correct, delete, and export your data, to opt out of certain sharing/targeted advertising, and to withdraw consent. You can also delete your account and retire your voice clone in-product. To exercise rights, contact [privacy@…]. We will not discriminate against you for exercising them.

10. Data retention

We keep information for as long as your account is active and as needed to provide the Services, then delete or de-identify it within [RETENTION PERIODS], except where longer retention is required by law. Voice/biometric retention follows §5.

11. Security

We use reasonable technical and organizational measures (encryption in transit, access controls, hosted-provider safeguards). No system is perfectly secure. [Add breach-notification commitment consistent with state law.]

12. International transfers

We operate in the United States; if you access the Services from elsewhere, your data is processed in the US and other countries where our providers operate. [Add GDPR transfer mechanism if serving EU/UK.]

13. Changes

We may update this Policy; material changes will be notified via the Services or email, and the "Effective date" will change.

14. Contact

Point Seven Studio LLC — [address][privacy@…].


Implementation notes (remove before publishing)

  • Publish as: /privacy (host-aware so each brand's footer links to it) after counsel review.
  • Depends on: the voice-biometric section is only as good as the consent model + counsel answers (brief); don't publish §5 ahead of that.
  • Keep in sync: if you add a subprocessor (§7) or a new data type, update this + the Terms.
PRIVACY POLICY DRAFT — Docs | HiveJournal