PERSONAL MEANS SOMETHING HERE
Your privacy, in plain words.
What Týr stores, who can access it, and the choices you have.
Last updated 24 September 2026
Your web account
The client account area uses the same Firebase account and access rules as the Android app. It connects to Firebase Authentication, Firestore, Cloud Functions and Google reCAPTCHA Enterprise for App Check. Google sign-in opens a Google authentication window. reCAPTCHA processes browser and connection information to detect abuse and may use browser storage for this purpose. Google’s Privacy Policy and Terms of Service apply to reCAPTCHA. Public brochure pages do not load these services.
Sign-in state is stored for the browser tab session. Care records and unfinished writing are held in memory and are cleared on sign-out or page closure; this web area does not enable a persistent offline care-data cache. Downloaded exports, safety plans, calendars and provider browser data are separate copies that you control. Use your device security and sign out on shared devices.
Web clients can manage sessions, open Razorpay-hosted payment links, read shared notes, complete homework, and use their journal, check-ins, tools, questionnaires and safety plan. Sharing and practitioner access follow the same rules described below. The website does not receive card credentials.
Who this notice is from
Týr — Trust your Recovery is an online practice and Android companion. Questions about privacy or your records can be sent to talk02pallavi@gmail.com.
This notice covers this website and the app. The public pages present information. The web account area and Android app use the same Firebase backend to support your care.
When you visit this website
The public brochure pages do not use advertising trackers, analytics scripts, tracking cookies, remote fonts, or embedded third-party videos. The interactive preview uses sample content. Its choices stay in the page’s memory and are reset when you close the preview; they are not saved or sent.
The hosting provider processes the connection information needed to deliver the website, such as IP address, requested page, browser information, and access time. Following an email link opens your email app. If you send a message, your email provider and the practice’s email provider process it.
When you use the Android app
The app stores your sign-in and profile details, an optional profile photo, appointments, session notes, homework, questionnaire responses and scores, session credits and payment records, and the wellbeing records you choose to create. Wellbeing records include check-ins, journal entries, tool entries, and your safety plan.
Account and care records are stored in the practice’s Firebase services and protected by authentication and access rules. Firebase encrypts stored data and network traffic. The app also maintains a Firestore cache on your device for offline access. This is not a claim of end-to-end encryption or storage only on your device.
You can use your Google account photo or upload a profile photo. Uploads are reduced to a small avatar, with original image metadata removed, and stored on your private user profile. Your selection remains until you change or remove it; account deletion removes the profile. Google photos are loaded from the account’s image provider.
Client journal drafts are encrypted on your device and kept separately for each signed-in account. They are excluded from Android backups and app exports, and draft saving never sends your writing to your practitioner. Returning to a draft does not restore a new sharing choice; sharing still requires the app’s explicit Save and consent controls. Signing out keeps that account’s draft on the device. Discarding a draft, successfully deleting wellbeing data or your account in the app, or clearing app data removes the relevant device draft; uninstalling also removes device drafts.
Unshared practitioner note drafts are encrypted on the practitioner’s device and excluded from device backups and client exports. They are cleared after successful sharing or when the app’s data is removed. Account deletion does not automatically erase these device copies; contact the practice about any local records that remain.
Who can see what
| Information | Access in the app |
|---|---|
| Mood check-ins and safety plan | You. Practitioner access is denied by the app’s server rules. |
| Journal and tool entries | You, plus the assigned practitioner for entries shared with that practitioner and care episode. |
| Sessions, clinical notes, homework, questionnaires, and plan records | You and the assigned practitioner, subject to record authorship, care episode and sharing permissions. An admin practitioner can see limited operational session details and manage assignments; admins can also review practitioners’ assigned clients and shared session notes in a separate read-only view. This does not include client reflections, private check-ins, safety plans, or unshared journal/tool entries. |
| Another client’s records | Not available to your account. |
A change of practitioner requires renewed sharing consent for the new care episode. Turning off sharing removes the practitioner’s future access through the app to that journal or tool entry. It cannot retract a copy already lawfully exported or information already discussed in a session. These access controls describe app roles; they do not mean the cloud service operator has no administrative responsibilities or technical access.
Services used to run the app
- Firebase Authentication, Firestore, and Cloud Functions provide sign-in, storage, access control, scheduling, and secure account operations. App Check helps validate requests.
- Google Calendar and Google Meet support appointment events and unique meeting links. Appointment metadata is processed for that purpose. The app does not add the client as a Calendar guest.
- Razorpay provides the hosted checkout for session packages purchased through the web account or Android app. Payment identifiers and credit records are kept by the backend. The app and website do not ask you to enter card details into their own forms. Payment is completed through Razorpay’s hosted checkout.
- Firebase Crashlytics is enabled in release builds to collect crash diagnostics. Diagnostics can include app and device information and technical error details. The website does not use Crashlytics.
Choices, exports, and your device
Use the app’s sharing switches, app lock, and screenshot protection as appropriate for your device. Reminders are managed on the device. Signing out is not a promise of secure erasure of the offline cache.
You can export a readable JSON copy from the app. Keep it somewhere private: anyone who can open the exported file can read it. An export reads records over a period of time and is not an atomic snapshot of every record at one instant.
Delete wellbeing data removes check-ins, journals, tool entries, and the safety plan, while retaining sessions, clinical notes, homework, questionnaires, and the credit/payment ledger. Close and delete account is a separate, broader action. See account deletion.
Retention and deletion
Account and care records are retained while your account remains open to support your care history and ongoing use. You may request account deletion at any time. There is currently no automatic deletion after a fixed period of inactivity.
Our operational target is to complete an accepted, identity-verified account-deletion request within 30 days. App access closes when the deletion operation is accepted. Appointment and payment cleanup may delay completion; we will explain any delay or specific legal reason for retaining a record. The 30-day target is not a promise that every provider backup has been erased.
A limited record of the deleted account identifier and deletion status remains for the life of this backend to prevent late requests from recreating deleted records. Unresolved payment-review references remain until the issue is resolved and their further retention is reviewed; they have no automatic expiry. These records do not contain therapy notes.
Google states that Firebase Authentication removes deleted-user data from its live and backup systems within 180 days after deletion is initiated, Crashlytics retains crash data and associated identifiers for 90 days before starting removal, and Firebase Hosting retains IP data for a few months. Calendar, payment-provider records, emails, device caches and exported files have separate retention and deletion arrangements.
Provider retention information
See Google’s Firebase privacy information for the provider retention periods described above.
Questions or corrections
Contact talk02pallavi@gmail.com to ask about access, correction, sharing, retention, or deletion. Keep the initial message limited to your account email and the type of request; do not send your password or therapy journal.