Privacy Policy — Become

Last updated: 2026-06-15 Effective date: 2026-06-05 Contact: privacy@become.app

Become ("Become", "we", "us", "our") is a daily identity-practice app. This policy explains what data the app handles, why we handle it, the legal bases for doing so, and the third parties that process data on our behalf. We try to collect as little as possible, and we do not sell your data.

This policy is written to cover users in both the United States (including California residents under the CCPA/CPRA) and the European Economic Area and United Kingdom (under the GDPR / UK GDPR). The relevant sections below set out the specific rights available in each region.

For the purposes of the GDPR / UK GDPR, Become is the data controller for the personal data described here. You can reach us about any privacy matter at privacy@become.app.

Summary

(via Supabase).

stored in your account so the app can show your history and adapt to you.

Anthropic (the provider of the Claude AI models) for processing as a third-party sub-processor.

reports are scrubbed to avoid carrying your personal content.

— counts, timings, and which screens you use — to understand whether the app actually helps people keep their practice. These events never contain the text of your reflections, Moves, identity statement, or coaching. Analytics is off by default and you can turn it on or off any time in Settings.

Google Play, and subscription status is managed through RevenueCat. We never receive your full payment-card details.

third-party advertising trackers.

Storage modes

Become can run in a local-only mode and a cloud (account) mode.

storage) and is not stored on our servers. The cloud features described in this policy do not apply.

— you sign in with an account and your content is stored in our database so it is available across sessions and devices.

The disclosures below describe cloud mode, which is the default for the hosted service.

What we collect and why

Account data

Authentication is handled by Supabase Auth. Passwords are stored hashed by Supabase; we never see or store your plaintext password.

used to keep you signed in and to associate your content with your account.

App content you create

skipped), and written reflections. This content is stored in our database (Supabase) under your account so the app can display your streak and history and tailor future Moves and coaching. Rows are isolated per user via database row-level security, so one account cannot read another account's data.

AI processing

needed to produce that result (for example your archetype or free-text input, or your recent reflections) is sent to Anthropic, PBC — the provider of the Claude models — which processes it and returns the generated text. We send only what is needed to produce the result. Anthropic acts as our sub-processor for this purpose; please also refer to Anthropic's own privacy and usage terms for how they handle API data.

self-harm or harm to others. When such a signal is detected, the app may show supportive, non-AI-generated information, including a crisis resource such as the 988 Suicide & Crisis Lifeline (a US resource). This is an automated, best-effort feature intended to point you toward help; it is not a monitoring, reporting, or emergency-response service, and Become is not a substitute for professional or emergency care. If you or someone else may be in danger, contact your local emergency services.

Diagnostics and crash reporting

problems. A diagnostic report can include information such as a stack trace, the page or route where the error occurred, a generated error-reference id, basic device/browser type, and a coarse user identifier (your account id).

personal content in error reports. Identity statements, Moves, reflections, and coaching text are redacted, long strings are truncated, and email addresses are reduced (for example to the domain only). No method is perfect, but the pipeline is designed to keep your personal content out of diagnostics.

Product analytics (optional, off by default)

interaction events — small, structured records of how you use Become so we can measure whether the product is helping (for example: that a check-in screen was opened, which status you selected, how long a reflection was in characters, when a coaching line was shown, and that the journey screen was viewed). Each event carries only metadata — counts, durations, timestamps, a local hour, screen names, and enumerated choices.

reflections, identity statement, Moves, or coaching. That content is excluded by design at the point of collection, and a server-side filter strips any such field as a second line of defense before anything is stored.

explicitly opt in. If you have not opted in, no interaction events are sent or stored**, even internally. You can withdraw consent at any time in Settings; we stop collecting from that point.

in the EU), isolated per user by row-level security, and are deleted when you delete your account (see "Data retention"). We only ever analyze them in aggregate (population-level counts and rates with no user identifier); we do not build per-user analytics reports from them.

AI personalization (Tier-2 — separate opt-in, off by default)

Become builds a small practice portrait of you: a handful of structured readings — what seems to motivate you, how established the habit is, how lived the identity is, where you are in the change, and your cadence. It is inferred only from your behavior (when and how often you show up), never from the text you write, and is refreshed about once a day.

coaching — never to add pressure, guilt, or urgency, and never to change what you're asked to do. It is stored in our database (Supabase, EU), readable only by you, and deleted when you delete your account.

meaningfully shape your experience, you can view exactly what was inferred and the logic behind it on your portrait page, contest it ("this doesn't sound right" — which stops it from shaping your coaching), or delete it outright. You can also turn the whole feature off in Settings at any time. No portrait is ever built, and no coaching is personalized, unless you have opted in (it fails closed). Become never infers anything clinical or about your wellbeing, and the portrait is never conditioned on you being low, struggling, or in distress.

Subscription and payment data

are handled entirely by the app store you bought it through — the Apple App Store or Google Play — under their respective terms and privacy policies. We do not** receive or store your full payment-card number or billing address.

purchase, renewal, or expiration occurs, RevenueCat sends us the subscription status (such as the product identifier, whether the entitlement is active, and an expiration date) linked to your account id, so the app can unlock or lock paid features. We store this entitlement status in our database (Supabase).

Technical data

is processed transiently by our hosting and infrastructure providers to deliver the service, maintain security, and protect against abuse.

How the app is delivered

The Android app is a native shell (built with Capacitor) that loads the Become web app over an encrypted HTTPS connection. The same data practices described in this policy apply whether you use Become on the web or through the mobile app.

Legal bases for processing (GDPR / UK GDPR)

If you are in the EEA or UK, we rely on the following legal bases under Article 6 of the GDPR:

to provide the core features you ask for, including authentication, storing your content, generating statements/Moves/coaching, and managing subscription access.

abuse, and diagnose and fix errors (crash and error reporting). We balance these interests against your rights and freedoms.

may withdraw consent at any time without affecting prior processing.

to comply with applicable law.

With your separate, opt-in consent (see "AI personalization"), Become builds a behavioral practice portrait and uses it to adapt the tone of your coaching. This is automated processing that can meaningfully shape your experience, so you have the right to meaningful information about its logic, to contest it, and to obtain human review — all available from your portrait page and by contacting privacy@become.app. We do not use your personal data for any other automated decision-making that produces legal or similarly significant effects about you. AI generation produces coaching content in response to your input; it does not make decisions about your rights or access (other than reflecting your subscription status).

Third-party processors / sub-processors

We share data only with service providers that help us run Become. Each acts under contract and processes data on our behalf:

password, account identifiers, and the app content stored under your account.

statement, Moves, and coaching.

coarse account identifier.

linked to your account id. (Payment processing itself is handled by the Apple App Store / Google Play.)

request/connection data such as IP address.

Some of these providers may store or process data outside your country (see "International data transfers"). We do not sell personal data and do not use it for third-party advertising.

Data retention

active. It is deleted when you delete your account or make a verified deletion request (see "Your rights").

can correctly grant or restrict paid features.

active and are deleted when you delete your account, alongside your other account data. Your practice portrait, if any, is deleted when you delete it, when you withdraw the personalization opt-in, or when you delete your account.

and is then deleted in line with our error-reporting provider's retention settings.

obligations, resolve disputes, or enforce our agreements.

Your rights

To exercise any right described below, contact us at privacy@become.app. We will respond within the timeframe required by applicable law. We may need to verify your identity (for example, by confirming control of your account email) before acting on a request.

For everyone

You can request to access, correct, export, or delete your personal data, and you can delete your account.

For residents of the European Economic Area and the United Kingdom (GDPR / UK GDPR)

You have the right to:

machine-readable format.

You also have the right to lodge a complaint with a supervisory authority — your local EU data protection authority, or the UK Information Commissioner's Office (ICO) in the United Kingdom. We would appreciate the chance to address your concern first.

For California residents (CCPA / CPRA)

If you are a California resident, you have the right to:

have collected, the sources, the purposes, and the categories of third parties to whom it is disclosed.

exceptions.

or share your personal information** as those terms are defined under the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes that would require an opt-out.

to provide the service you requested.

of these rights.

You may exercise these rights yourself or through an authorized agent. We do not knowingly sell or share the personal information of consumers, including minors.

International data transfers

Become is operated for a global audience, and our service providers may store or process data in countries other than your own, including the United States. Where we or our processors transfer personal data out of the EEA or the UK, we rely on appropriate safeguards recognized under the GDPR / UK GDPR — such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or an adequacy decision — to protect that data.

Security

We use encryption in transit (HTTPS) for data moving between your device and our services, rely on our processors' security controls (including hashed password storage and per-user database row-level security), and apply the principle of collecting as little personal data as practical. No method of transmission or storage is perfectly secure, but we take reasonable measures to protect your data.

Children's privacy

Become is not directed to children. We do not knowingly collect personal data from children under 13 (or under the minimum age of digital consent in your country, which may be up to 16 in parts of the EEA). If you believe a child has provided us personal data, contact us at privacy@become.app and we will delete it.

Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide an additional notice in the app. Your continued use of Become after an update means you accept the revised policy.

Governing law

This policy is governed by applicable data-protection law in the jurisdictions where our users are located. Nothing in this policy limits any non-waivable rights you may have under the laws of your country or state of residence, including under the GDPR / UK GDPR for users in Europe and the CCPA/CPRA for California residents.

Contact

Questions, concerns, or privacy requests: privacy@become.app.

This policy is provided in good faith to describe our actual data practices. It is not legal advice.