the privacy policy
Short, because there's not much to hide.
Where your data lives. Your sessions, your settings, and the AI's running memory of you are stored on your device — in your browser or on your phone. 5 Minutes of Chaos does not require an account and we don't keep a database of your journals. You can export everything as a file, or erase everything, whenever you want, from inside the app.
What travels, and when. A local-only journal entry never leaves your phone. When you use the included preview, only that session's words are sent over an encrypted connection to our server and then OpenAI; no earlier entry, memory, parked worry, or voice measurement is included. With Full Chaos, a requested reflection may also include the running memory you control, parked worries, recent session references, and on-device voice measurements. The reflection and the updated memory come back to your device. We do not store, log, or read your session content in a journal database, and we set OpenAI's store flag to off on every call, so they don't keep it as retrievable data either.
Your choice. During onboarding, you choose whether to allow thoughtful reflection processing. You can change that choice later under You → Privacy & lock. When it is off, every new entry stays on your phone and no reflection request is sent to us or OpenAI.
Current-client session prep. If you already work with Sean, the iPhone app can make a PDF from journal pages you select for an upcoming session. The PDF is made on your phone. It is not uploaded to us automatically: you preview the choices, decide separately whether AI-assisted preparation is allowed, and send the email yourself through your own mail app. If you send it, we receive the selected journal text, your name, session date, optional discussion note, and the email address you send from. We use that material only to prepare for and conduct your coaching session, according to the choice written in your email. Email may not be encrypted, and this inbox is not monitored for urgent support. You may ask us to delete a packet at any time.
Retries, limits, and app integrity. To stop one lost network reply from charging for a second AI call, our server keeps the completed response in an encrypted retry cache for up to seven days; it does not cache the transcript. This lets a requested reflection finish after a crash, lost signal, or offline weekend without creating another AI response. We also keep non-journal security records: a random installation ID, an App Attest public key and counter, one-way-hashed subscription and quota identifiers, and usage totals. On devices that cannot use App Attest, a one-way hash of the IP address may be kept for the day to enforce a tighter abuse limit. These records protect the service and are not used for advertising, profiling, or analytics.
The part we can't promise yet. OpenAI keeps a separate copy of API requests for up to thirty days for abuse monitoring, and the store flag does not turn that off — only an approved zero-retention agreement does. We are applying for one. Until it's granted, your session text sits in OpenAI's abuse-monitoring logs for up to thirty days, and we'd rather tell you that than let you assume otherwise. Nobody trains on it: API data isn't used to train OpenAI's models, and we don't use your words to train anything. See their API data policies.
Voice. The iPhone app uses a verified local recording plus private on-device speech recognition. On current iPhones, the completed recording gets a second long-form on-device transcription pass before the journal entry continues. If the recorder itself ever stops, the session clock stops instead of pretending it is still capturing you. On the web, your browser's speech service handles transcription per your browser vendor's policies. Audio reaches our service only when you separately approve secure transcript rescue as described below.
What the microphone hears. Speech recognition picks up whatever is nearby — a television, someone else in the room, a call on speakerphone. The app cannot tell voices apart and does not try to guess, so anything it hears is written down as though you said it. If something lands in a transcript that wasn't you, you can correct the words or keep that session out of your reviews. Either way it stays in your log, and nothing is quietly reinterpreted on your behalf.
Keeping the audio. In the iPhone app you can switch on "Keep the audio" to save each spoken session's recording. It is off unless you turn it on and these saved files stay on your device. Delete them one at a time with the session, or all at once from Privacy. Keeping recordings does not itself permit an upload.
The safety net. During a spoken session the iPhone app holds the audio on your device until the completed file has been transcribed and your words are safely written down, then deletes it. If transcription fails mid-session — it has happened — the audio stays on your phone so the app can automatically recover your words instead of re-living them. You may retry privately on the device. You may also separately approve secure transcript rescue; then only that rescue recording passes through our authenticated server to OpenAI's transcription API. We do not write the audio to server storage or logs. OpenAI does not retain application state for the transcription endpoint, but its default abuse-monitoring logs may retain API content for up to thirty days. The local rescue hold is released when the words are recovered or when you let it go.
How you sounded. When a session is spoken, the app measures a handful of numbers about the delivery on your device — how much of the window you filled, how often you paused, whether you got quieter by the end. Those numbers travel with your words to write the reflection. The audio they were derived from does not, except for a rescue you explicitly approve.
What we don't do. No ads, no trackers, no analytics tied to your identity, no selling data, no "anonymized insights" hustle. The subscription is the business model. That's the whole point of it.
Payments. Subscriptions are handled by Apple through your Apple Account. We never see your payment details. The app sends Apple's signed subscription proof to our server so we can verify Full Chaos; we validate it and keep only a one-way-hashed identifier for quotas and cost limits.
One-tap problem reports. When you choose Report This Problem, the app sends only a random report ID, feature and error code, time, app/build and iOS versions, device model, connectivity state, and an optional note you write. It never includes a transcript, journal entry, title, memory, photo, or audio. Reports are kept for up to thirty days to investigate the problem and are rate-limited to prevent abuse.
If you contact support. We receive the email address and information you choose to send us. We use it only to answer you and investigate the problem. The app reminds you not to include journal words unless you deliberately want us to read them.
Questions? Say hi: chaos.audditude.com/support. This policy covers the 5 Minutes of Chaos web and iOS apps, by Audditude.