Legal
Privacy Policy
Version 1.4.0 · Last updated 20 July 2026 · Effective 20 July 2026
This Privacy Policy explains how Embody(“Embody”, “we”, “us”, “our”) collects, uses, shares, and protects your personal information when you use the Embody mobile application and the website at myembodyapp.com(together, the “Service”).
Embody is operated by Rahul Patil, a sole proprietor based in India (“the Operator”). For the EU/UK GDPR, the Operator is the data controller. For India’s Digital Personal Data Protection Act, 2023 (DPDP Act), the Operator is the Data Fiduciary. Questions or rights requests: admin@myembodyapp.com.
Plain-language summary. Embody is a wellbeing app for daily affirmations, rituals, tarot and Vedic wisdom, and sounds. We collect the account details you give us (such as your name, email or phone, and optional profile information like date of birth and the topics you care about), plus a small amount of technical and usage data needed to run the app. We store data on your device and in our secure cloud database. We do not sell your personal data, and we do not use it for third-party advertising. You can access, correct, export, or delete your data at any time.
1. Who this policy applies to
The Service is intended for users aged 13 and over (or the higher minimum age required in your country — for example 16 in much of the EU). Embody is not directed to children under 13, and we do not knowingly collect personal data from children under 13. The “Kids” and “Pregnancy” experiences are features designed for an adult to use — for example, a parent reading affirmations with a child, or an expecting parent. See Section 11 (Children).
2. Information we collect
2.1 Information you provide
| Category | Examples | Why we collect it |
|---|---|---|
| Account & identity | Name, email and/or phone; the sign-in method you choose (email, phone, Google, Apple, Facebook). | To create and secure your account and sign you in. |
| Profile details (optional) | Date of birth, gender, “important dates” you add, member-since year. | To personalise content and reminders. Optional — you can skip or remove them. |
| Preferences | Affirmation categories you select (which may include pregnancy, spiritual growth, Vedic wisdom, etc.), angel-hour settings, reminder schedules, Kids/Pregnancy mode. | To tailor affirmations, rituals, and reminders. See Section 3 on sensitive data. |
| Content you create | Custom angel-hour messages and text you write; items you “save”. | To deliver your reminders and saved library. |
| Support requests | Your message, and any screenshot or recording you choose to attach. | To answer your support request. |
| Referrals | A referral code if you were referred, or one you share. | To run the referral programme. |
2.2 Information collected automatically
| Category | Examples | Notes |
|---|---|---|
| Device & technical | Device type, OS, app version, language, time zone, push token (if notifications enabled). | Needed to run the app and deliver notifications. |
| Usage | Streak counts, last-opened timestamps, and (if analytics enabled) events such as viewing the paywall or sharing a referral. | Helps us understand and improve the app. See Section 5. |
| Approximate location (if analytics enabled) | A coarse, city/country-level location our analytics provider derives from your IP address when it receives an event. We never collect precise (GPS) location. | Used only for aggregate, regional product insights (e.g. comparing feature usage between countries). See Section 5. |
| Notification delivery log | A short-lived server record of the notifications we send you (type, scheduled time, delivery status). | Prevents duplicate sends and powers your in-app rituals tracker; deleted automatically after about 30 days. |
2.3 Information from third parties
If you sign in with Google, Apple, or Facebook, that provider sends us basic profile information — typically your name and email — to create your account. We do not receive your social-media password. Apple may provide a private relay email if you choose to hide your address. We do not buy personal data from data brokers, and we do not receive advertising profiles about you.
3. Sensitive / special-category data
Some choices you make can reveal sensitive information. Selecting the Pregnancy experience may indicate a health-related condition, and selecting categories such as Vedic wisdom or spiritual growthmay reveal religious or philosophical beliefs. Under the GDPR these are “special categories” of data.
- We collect this information only because you chose those features, and use it only to personalise your in-app experience.
- Where the law requires (e.g. the EU/UK), we rely on your explicit consent, which you give by selecting these optional features. You can withdraw consent anytime by deselecting the category or deleting your account.
- Embody is a wellbeing product, not a medical service. We do not collect clinical data (due dates, trimesters, diagnoses, medical history) and do not use your data to make decisions about your health. See the medical disclaimer in our Terms of Service.
4. How we use your information (and our legal bases)
We use your information to:
- Provide the Service — create your account, sign you in, deliver content, reminders, and your saved library, and sync across devices. Basis: contract / providing the service you consented to.
- Personalise your experience — tailor content to your choices. Basis: consent (optional/sensitive personalisation) and legitimate interests.
- Send notifications you enable. Basis: consent.
- Provide support and run referrals. Basis: contract / legitimate interests.
- Operate, secure, and improve the Service, including basic product analytics. Basis: legitimate interests.
- Process subscription payments (handled by Apple/Google — Section 6). Basis: contract.
- Comply with law and enforce our Terms. Basis: legal obligation / legitimate interests.
We do notuse your personal data for automated decision-making with legal or similarly significant effects, and we do not sell or “share” it for cross-context behavioural advertising.
5. Analytics
If enabled, we use a product-analytics service (hosted in the United States — see Section 9 on international transfers) to understand how features are used — for example, whether the paywall is viewed or a free trial converts. We keep analytics privacy-friendly and event-based: we track a small, hand-picked set of milestone events (such as completing a daily affirmation or starting a trial), not detailed clickstream or session-by-session behaviour, and we do not use advertising identifiers (IDFA/AAID) or track you across other apps or websites. When analytics are enabled, the analytics service also derives an approximate (city/country-level) location from your IP address at the time an event is received; we use this only for aggregate regional insights (for example, comparing feature usage between countries) and never collect precise (GPS) location. When you are signed in, analytics events are associated with your account identifier and account email address (and, if you have set one, your display name), so that we can recognise the same account across sessions and devices, distinguish our own internal test accounts from real users, and — if you contact support — connect your report to what actually happened. We rely on our legitimate interestin understanding and improving the Service for this processing, having weighed it against your privacy interests — you can object at any time by turning analytics off in the app’s Settings.
6. Payments and subscriptions
Embody may offer optional paid subscriptions (“Embody Premium”). When offered, purchases are processed by the Apple App Store or Google Play, not by us. We do not collect or store your full payment-card details. Apple/Google share limited information needed to confirm and manage your subscription (such as purchase and renewal status), governed by their own privacy policies. We use a subscription-management service acting on our behalf to link your purchase to your account and keep your premium status in sync across your devices; it receives your account identifier and subscription status, never your payment details.
7. How we share information
We share personal data only with service providers (“processors”) that help us run Embody, and only as needed. Each provider processes data solely on our instructions, under a data-processing agreement, and only for the purpose shown:
| Category of provider | What they do for us | Data involved |
|---|---|---|
| Cloud hosting & database | Authentication, database, file storage | Account, profile, preferences, saved items, custom messages, support attachments, push tokens |
| Push-notification delivery | Deliver the notifications you enable | Push tokens, device data, notification content |
| Product analytics (if enabled) | Feature-usage analytics | Usage events, account identifier and email address (display name, if set), device data, IP-derived approximate location (city/country) |
| Email & SMS delivery | Account and support emails; one-time passcodes | Email address / phone number, message content |
| Subscription management | Link your purchase to your account; keep premium status in sync | Account identifier, purchase/renewal status |
| Google / Apple / Meta | Social sign-in (only if you choose it) | OAuth identity (name, email) |
| Apple App Store / Google Play | Subscription billing (when offered) | Purchase/renewal status |
A current list of the specific service providers we use is available on request at admin@myembodyapp.com.
We may also disclose information to comply with law or valid legal process; to protect the rights, safety, and security of users, the public, or Embody; and in connection with a business transfer (e.g. merger or acquisition), in which case we will notify you. We do not sell your personal data.
8. Where your data is stored
- On your device: most settings and content are stored locally so the app works smoothly; sign-in session tokens are kept in your device’s secure storage.
- In the cloud: with an account, your data syncs to our cloud database, protected by row-level security so that only you can access your records.
9. International data transfers
Embody is operated from India and uses providers that may process data in the EU, the United States, and other countries. When we transfer personal data across borders, we rely on appropriate safeguards required by law — for example the EU Standard Contractual Clausesfor EU/UK transfers, and equivalent measures under India’s DPDP Act. Contact us for more information.
10. Data retention, account and data deletion
- Account & profile data: retained until you delete your account.
- Support tickets & attachments: retained as long as needed to resolve your request; attachment links expire automatically (signed URLs valid ~30 days).
- Notification delivery logs: deleted automatically after about 30 days.
- Analytics data: retained in aggregated/pseudonymous form for a limited period.
- Backups & legal records: residual copies may persist in backups for a limited time and where law requires retention.
Account and data deletion
You can delete your account at any time (Profile → Delete account, or by emailing admin@myembodyapp.com). When you do, we permanently delete or anonymise your profile, preferences, saved items, custom messages, reminders, notification history, and support attachments within a reasonable period (typically 30 days, plus a short lag for encrypted backups).
We retain one minimal deletion record — your email address (stored in a protected, hashed form, not as readable text), your account identifier, and your subscription/free-trial history — for up to 12 months after deletion. We keep this record only to: (a) prevent misuse of free trials, referral rewards, and promotional offers; (b) comply with legal, tax, and accounting obligations; and (c) establish, exercise, or defend legal claims. It is never used for marketing or any other purpose, and it is deleted automatically when the retention period ends. Purchases you made are also retained by Apple/Google under their own policies.
11. Children
Embody is intended for users 13 and older (or older where required). We present an age check during onboarding and do not knowingly collect personal data from children under 13. The Kids mode provides gentle affirmations intended to be used by an adult with a child; it is not an account for a child to register and use independently, and it does not ask a child for personal information. If you believe a child under 13 has provided us personal data, contact admin@myembodyapp.com and we will delete it.
12. Your privacy rights
Depending on where you live, you have some or all of the following rights. We honour these requests regardless of where you live, to the extent practicable.
Everyone:
- Access the personal data we hold about you.
- Correct inaccurate data (you can edit most profile fields in the app).
- Delete your data and account (Profile → Delete account, or by email).
- Export a copy of your data (portability).
- Withdraw consent or object to processing (e.g. turn off notifications/analytics or deselect sensitive categories).
EU/UK (GDPR) additionally: restrict or object to certain processing; lodge a complaint with your local data protection authority.
California (CCPA/CPRA) additionally: know, delete, and correct; opt out of “sale”/“sharing” — note we do not sell or share your personal information; non-discrimination for exercising your rights.
India (DPDP Act) additionally: access and correction/erasure; grievance redressal (contact us first; if unresolved, you may approach the Data Protection Board of India); nominate another person to exercise your rights in the event of death or incapacity.
To exercise any right, email admin@myembodyapp.com. We verify your request and respond within the timeframe required by law (generally within 30 days).
13. Security
We protect your data with measures including encryption in transit (HTTPS/TLS), encrypted device storage for session tokens, and server-side row-level security so users can access only their own records. No method of transmission or storage is 100% secure, but we work to protect your information and review our practices regularly. If a breach affects your personal data, we will notify you and the relevant authorities as required by law.
14. Cookies and similar technologies
The Embody app does not use advertising cookies. Our website (myembodyapp.com) may use a small number of essential and (if enabled) analytics cookies. Where required, we will request consent and provide controls via a cookie banner.
15. Third-party links
The Service may contain links to third-party websites or services (for example, when you share an affirmation card). Their privacy practices are governed by their own policies, and we are not responsible for them.
16. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, provide a more prominent notice (such as an in-app message). Your continued use of the Service after changes take effect means you accept the updated policy.
17. Contact us
Operator: Rahul Patil (sole proprietor), India
Email: admin@myembodyapp.com
Website: myembodyapp.com