ResonUp

Trust

The limits, written down.

Privacy, security and AI limits are product decisions at ResonUp, not marketing positions. That is what makes them specific enough to write down. Below is the whole of it.

01Commitments

Four things we hold to.

02Privacy

What we collect, and what we do with it.

The Privacy Center shows a plain-language map of every category of data ResonUp holds and the reason it holds it. There is no second, quieter collection running behind it.

  • A collected-data map written in plain language, not a schema dump.
  • Journal entries are private by default; sharing is a decision you make one entry at a time.
  • AI reflection is consented per entry. Nothing is submitted to a model on its own initiative.
  • Data export is available on every plan, including the free one.
  • We collect what a feature needs in order to work, and then we stop.
Read the full Privacy Policy

03Advertising

No advertising, no behavioural tracking.

There is no advertising network inside ResonUp and no behavioural profile assembled from what you write. Reflection data is never used for targeting — not by us and not by anyone else — and it is not for sale.

This is a structural decision rather than a current setting. An advertising business would require us to read what you write, which is the one thing the product is built not to do.

04Security

The minimums, as release gates.

These are not aspirations. A build that does not meet them does not ship.

In the product

  • TLS 1.2 or higher in transit, with TLS 1.3 preferred.
  • Server-side encryption of journal, Vault and voice-transcript content (AES-256-GCM), with the keys held on our own server, apart from the data. This is not end-to-end encryption, and we do not describe it as such.
  • Operator access needs a password, a one-time code and an allow-listed network; changes need a second person’s approval; every access is written to a tamper-evident audit log. No operator role can read journal, Vault or voice content.
  • Journal and Vault contents are never written to logs, and personal data is redacted.
  • Static and dynamic scanning, dependency and secret scanning, and an external penetration test before release.

Around the product

  • Short-lived access tokens, rotating refresh tokens, and revocation that takes effect server-side.
  • Secrets are kept on the server and never in the source repository; credentials on your device live in the iOS Keychain or the Android Keystore.
  • Rate limiting, abuse protection, app-integrity checks (App Attest and Play Integrity) and idempotent writes.
  • Backups are overwritten in rotation, so data you delete leaves them within 35 days at most.
  • A written incident-response plan, a breach decision tree and an audit trail.

05AI transparency

What Reson Intelligence does, and does not.

Every AI feature in ResonUp is a task with a defined input and a defined output. There is no assistant sitting in the background with a view of everything you have written.

What it does

  • Composes a session from the intention you set and the time you have.
  • Drafts an affirmation you can rewrite, keep or discard.
  • Reframes a sentence you deliberately hand to it.
  • Summarizes a period you asked it to look at, from entries you selected.

What it will not do

  • It does not read your journal on its own. Every entry it sees, you sent.
  • It does not diagnose, assess or comment on a health condition.
  • It gives no financial or investment guidance of any kind.
  • It makes no prediction about your future and states no certainty it does not have.
What the AI is for

06Safety

If a conversation turns serious.

When a message suggests a crisis, ResonUp stops its ordinary motivational response. It says plainly that it is not an emergency service, and it points to the emergency and crisis resources where you are, and to someone you trust. It does not assess you and it does not diagnose. The same rule applies to content inside a Circle.

ResonUp is not an emergency service. In an emergency, contact the emergency services where you are.

07Control

Your controls.

All of them in the app, on every plan, and none behind a support request.

How to delete your account

08This website

How this page behaves.

A trust page that describes the app and says nothing about the page you are reading is not a trust page. So: the site you are on now follows the same rules.

  • No third-party analytics. There is no Google Analytics here, and no equivalent.
  • No advertising pixels, no conversion tags, no cross-site identifiers.
  • Typefaces are served from this domain, so reading this page tells a third party nothing.
  • One first-party cookie, which remembers the language you chose. It does nothing else.
  • No embedded players, widgets or chat boxes loading code from somewhere else.

09Contact

Reporting something.

Two addresses, both monitored, both answered by a person.

Privacy and data requests

Access, export, correction and deletion requests, and anything else about how your data is handled.

Security reports

If you believe you have found a vulnerability, write to us before publishing it. We will confirm receipt, keep you informed, and will not pursue anyone who reports in good faith.