Legal
Privacy Policy
Short version: your data never leaves your phone.
Last updated: 21 August 2026
BareMind is a fully offline app. It stores everything you enter — mood logs, sleep, journal entries, health data — on your device only. Nothing is transmitted to any server. There are no accounts, no analytics, and no third-party SDKs that collect personal data. The website has no signup of any kind.
What data BareMind stores
All of the following is stored locally on your device using the browser's IndexedDB and localStorage. It never leaves your device. On both Android and iOS, sensitive entries are encrypted at rest (AES-256-GCM) using a key kept in the device's secure hardware storage (Android Keystore / iOS Keychain). Some structured numeric values (e.g. step counts, sleep duration) are stored unencrypted inside the app's private, OS-sandboxed storage.
- Mood logs — mood rating, emotions, context tags, optional text note
- Sleep — on iOS you log sleep manually (duration and a quality rating). On Android you can optionally record overnight: microphone audio is processed on-device to detect movement and classify sleep stages. Raw audio is never stored; only derived metrics (stage timeline, RMS values, score) are saved.
- Voice journal entries (Android only) — audio is transcribed on-device using a locally downloaded speech model. The recording and its transcript are both saved, encrypted, on the device so you can play the entry back; deleting the entry deletes both. There is no microphone feature on iOS.
- Health & activity data — if you enable it, BareMind reads step count and sleep, read-only, from Apple Health (HealthKit) on iOS or Health Connect on Android. This data is stored locally and never shared or written back.
- Written journal entries — anything you type in the journal, and the weekly and monthly reflections.
- Thought records — CBT reframes (the situation, the thought, the pattern you picked, the kinder version) and worry-tree entries.
- Gratitude, goals and values — gratitude notes, your three active goals and their logs, the values bullseye, earned badges.
- Safety plan and coping cards — if you write one. This is treated as sensitive and encrypted like the rest.
- Exposure ladder — the items you list and how each attempt went, if you use it.
- Practice sessions — which breathing, meditation, grounding or stretch practice you ran, and for how long.
- Day factors — the tags you attach to a day (sleep, exercise, caffeine, alcohol, connection and so on), plus water and step counts.
- Screen time (Android, optional) — if you turn it on, daily app-usage totals read on-device.
- Settings and preferences — sleep window, daily goals, reminder times, theme, language. Stored in localStorage.
- Cycle data — menstrual cycle entries, if logged.
- Pain and headache logs — if logged.
What BareMind does not do
- Does not transmit any personal data to any server
- Does not require an account or email address
- Does not use analytics, crash reporting, or advertising SDKs
- Does not share data with third parties
- Does not use cloud backup or sync of its own — see the note on your phone's own backup below
- Does not sell data
Device permissions
BareMind requests the following permissions. Each is used only for the stated purpose and data stays on-device.
- Microphone (Android only) — used for optional sleep tracking (movement detection via ambient sound analysis) and voice journal transcription. Audio is processed locally; sleep audio is never stored, and voice-journal recordings are stored only on the device, encrypted. iOS does not request microphone access.
- Notifications — used to send bedtime reminders and mood check-in prompts. Notification content is generated locally.
- Apple Health / Health Connect — used to read step count and sleep, read-only, if you choose to enable it (HealthKit on iOS, Health Connect on Android). BareMind only reads; it never writes back.
- Activity recognition (Android) — used to count your daily steps on-device.
- Usage access (Android, optional) — if you enable screen-time tracking, BareMind reads app-usage stats on-device only.
- Alarms & reminders (Android) — exact-alarm and start-on-boot permissions, used only so a reminder or the smart wake-up fires at the time you set, and survives a restart. Scheduled on-device.
- Foreground service (Android) — keeps overnight sleep analysis and voice recording running while the screen is off, with the standing notification Android requires. On-device only.
- Internet (Android) — declared for exactly one thing: downloading the speech model described below. Nothing else in the app opens a connection.
- Biometric unlock (optional) — Face ID / Touch ID (iOS) or fingerprint / face (Android) used only to unlock the app; the biometric is handled by the OS and never seen, stored, or transmitted by BareMind.
Data deletion
All data is stored on your device. You can delete it at any time:
- In-app — Settings → Clear all data removes all entries and resets the app.
- Via Android — Settings → Apps → BareMind → Storage → Clear Data removes everything including the app's local database.
- Via iOS — offloading or deleting the app from Settings → General → iPhone Storage (or long-press → Delete App) removes all locally stored data.
- Uninstalling the app removes all locally stored data.
Your phone's own backup
BareMind runs no backup or sync of its own. Your phone may still run one, and the two are worth telling apart:
- Android — BareMind opts out of Android/Google backup entirely, so its data is never copied into a Google account backup.
- iOS — if you have iCloud Backup switched on, your device backup can include BareMind's private storage, in the encrypted form described above. That backup belongs to Apple and to you; it never comes to me. You can exclude the app in Settings → your name → iCloud → Manage Storage → Backups.
The encryption key is a separate matter: it is stored device-only and is never placed in iCloud Keychain, so encrypted entries lifted from a backup onto a different phone stay unreadable. To move your data deliberately, use the app's own export in Settings → Data — that file is yours to place where you like.
Voice model download (Android only)
On Android, the voice journal feature uses whisper.cpp, an open-source on-device speech recognition engine, running the open Whisper model. When you first open Voice Journal, the app downloads one speech model file (about 875 MB, shared by every language) from Hugging Face (huggingface.co), a public model repository, and checks it against a fixed checksum. This model download is the only outbound network request BareMind makes, and no personal data is sent during it — Hugging Face sees only what any file download produces (your IP address and the file name). The speech model is the same for everyone and contains nothing about you. On iOS there is no voice journal and no model download — the iOS app makes no outbound network requests at all.
Age & eligibility (children's privacy)
BareMind is intended for users aged 13 and older and is not directed at children under 13. I do not knowingly collect personal information from children under 13; if you are under 13, please do not use this app. If you believe a child under 13 has used the app, contact privacy@baremind.health.
This website (baremind.health)
There is no signup on this site — no waitlist, no newsletter, no account, no form of any kind. The pages send no requests anywhere, load nothing from a third party, and set no cookies. There is no analytics script, no pixel, no embedded font or CDN.
One thing is unavoidable: to serve you a page at all, the web server has to see your request.
- Server logs — like any web server, mine records the IP address, timestamp, requested page and browser user-agent of each request. These are used only to keep the site running and to block automated abuse, are never linked to anything else, are never shared, and are deleted automatically after 14 days.
- Lawful basis — legitimate interest in keeping the site online and defending it against attack. Not consent, because there is nothing here you could consent to.
- Where — a server I rent in Germany (Hetzner). No third-party analytics, hosting-side tracking or CRM is involved.
A launch waitlist used to run here. It was retired on 13 August 2026 and every address it held was deleted from the live file and from every backup. Nothing was kept, and the signup endpoint no longer exists.
Your rights
These rights apply only to the server logs described above — that is the entirety of the personal data I hold. They do not apply to anything inside the app, because that never reaches me and I have no way to retrieve it.
- Access — ask for a copy of what is held about you.
- Rectification — ask for it to be corrected.
- Erasure — ask for it to be deleted.
- Restriction and objection — ask me to stop using it while a question is resolved.
- Portability — ask for it in a machine-readable form.
In practice a log line is only linkable to you if you tell me the IP address and rough time to look for, and after 14 days it is gone regardless. Email privacy@baremind.health for any of these and I answer within 30 days. If you are in the UK, the EU or the EEA and you think your data has been handled badly, you also have the right to complain to your national data protection authority — you do not have to come to me first.
Changes to this policy
If this policy changes materially, the updated version will be posted at this URL with a revised date. Because BareMind has no accounts, I cannot notify you directly — check this page if you want to see the latest version.
Contact & data controller
The app has no data controller, because there is nothing to control. No accounts, no servers, no analytics — what you write stays on your phone. I never receive it, so there is nothing for me to hand over, delete, sell or lose.
For this website's server logs — the only personal data that exists anywhere in BareMind — the data controller is me. BareMind is built and run by one person, in Canada.
I answer data requests within 30 days. Questions about this policy, or to exercise any of the rights above: