Tranqui is an app for managing stress and understanding your emotions. You log how you feel and you write things down. That is personal, and this policy explains exactly what happens to it.
We have tried to write this plainly. Where the law forces us to use a term of art, we say what it means. If anything here is unclear, email us at privacidad@apptranqui.com and we will explain it.
1. Who we are
Tranqui is operated by AZEApps LLC, an Illinois limited liability company.
AZEApps LLC
229 West Ash Street, Lombard, IL 60148
Privacy contact: privacidad@apptranqui.com
Website: apptranqui.com
This policy covers the Tranqui mobile app, the apptranqui.com website, and related services. Together we call them "Tranqui" or "the Services". In this policy, "we" and "us" mean AZEApps LLC, and "you" means the person using Tranqui.
Tranqui is for adults. You must be 18 or older to create an account. See Section 13.
2. Notice at collection
California law requires us to tell you what we collect at or before the moment we collect it, rather than burying that information at the end of a long document. So here is the whole picture in one table. Every row is explained in more detail in the sections that follow.
| Category | Examples | Why we collect it | Who we disclose it to | Sold or shared? | Retention |
|---|---|---|---|---|---|
| Identifiers | Email address, account ID, device identifier, IP address, and — only if you granted App Tracking Transparency permission — the advertising identifier Apple assigns to your device | To create and secure your account, to run the app, and to measure which ads bring people to Tranqui | Supabase, Apple, RevenueCat, Purelymail, AppsFlyer, Meta, TikTok, Google | Yes — device identifier, IP address, and the advertising identifier where permitted. Never your email address or account ID | Account identifiers: life of the account, plus 30 days. Device and advertising identifiers: 26 months |
| Account and profile data | Name or display name, age range, notification and language preferences, app settings | To run your account and remember your preferences | Supabase | No | Life of the account, plus 30 days |
| Onboarding responses | The answers you give when you set up your account, about your goals, your preferences, and your current situation | To personalize the content the app offers you | Supabase only, as our database provider | No — never | Life of the account, plus 30 days |
| Journal content | Moods, emotions, and the reflections you write | To show you your own history and to personalize the content the app offers you | Supabase only, as our database provider | No — never | Deleted within 30 days of account deletion |
| Device data | Device model, operating system version, app version | To keep the app working across different devices and operating system versions | Supabase, AppsFlyer, Meta, TikTok, Google. The advertising partners' software transmits these with any network request it makes | Yes | 26 months |
| App usage and lifecycle events | Which screens you open, which features you use, session length, and app lifecycle events: install, open, session, account registration, subscription or trial start, and purchase including value | To understand which features are useful, and to measure which ads bring people to Tranqui | Supabase. AppsFlyer, Meta, TikTok and Google receive the lifecycle events only | Yes — install, open, session, account registration, subscription or trial start, and purchase events only. Which screens you open and which features you use stay with Supabase | 26 months |
| Approximate location | City or region inferred from your IP address. We do not collect precise location | To show region-appropriate content and language, and for fraud prevention | Supabase, AppsFlyer, Meta, TikTok, Google | Yes | 26 months |
| Purchase and subscription data | Whether you are on a free trial or a paid plan, purchase and renewal history, Apple transaction identifiers. We never receive your card number | To give you access to what you paid for, and to measure advertising | Apple, RevenueCat, AppsFlyer, Meta, TikTok, Google | Yes — the fact and value of a purchase only. Never payment details, which we do not have | 7 years, for tax and accounting |
| Support correspondence | Your emails to us and our replies | To answer you and to keep a record of what we told you | Purelymail | No | 3 years |
| Inferences | Patterns we draw from your mood and emotion logs and from your onboarding responses, used to choose which content to show you | To personalize the app | Supabase only | No — never | Life of the account, plus 30 days |
"Sold or shared" is a legal term, not a description of a cash transaction. Under California and several other state privacy laws, letting an advertising partner receive an identifier so it can measure an ad campaign counts as a "sale" or a "share" even though no money changes hands. Section 8 explains this in full, and Section 9 tells you how to opt out.
3. Information we collect
3.1 Information you provide
- Account information. Your email address, and a password if you do not sign in through Apple. A name or display name if you choose to give one.
- Onboarding responses. When you set up your account we ask a few questions about your goals, your preferences, and your current situation. Your answers are used to choose which content the app offers you. Answering is how the app knows where to start; the questions are about you, so we treat the answers with the same protection as journal content. See Section 4.
- Journal content. The moods and emotions you log, and the reflections you write. This is the heart of the app and it gets the strongest protection in this policy. See Section 4.
- Preferences. Notification settings, language, reminder times, and similar choices.
- Support correspondence. Anything you write to us when you ask for help, report a problem, or exercise a privacy right.
We ask for your age range, not your date of birth. The app only needs to know that you are 18 or older, so we do not collect a full birth date — that is one fewer identifier to hold and one fewer thing to lose. We do not ask for your race, religion, national origin, sexual orientation, disability status, or any similar characteristic.
3.2 Information collected automatically
When you use the app, we and our providers automatically collect:
- Device and app information. Device model, operating system version, app version, language and region settings.
- Usage information. Which screens you open, which features you use, how long a session lasts, and app lifecycle events: install, open, session, account registration, subscription or trial start, and purchase.
- Network information. Your IP address, and the approximate city or region it implies. We do not collect GPS or precise location.
- Identifiers. A device identifier and, if you allow it under Apple's App Tracking Transparency prompt, the advertising identifier Apple assigns to your device.
Our website uses only the cookies that are strictly necessary to make it work. It does not carry advertising or analytics cookies.
3.3 Information from third parties
- Apple. If you sign in with Apple, we receive an account identifier and the email address you choose to share, which may be a private relay address. Apple also tells us your subscription status. Apple processes your payment; we never see your card details.
- RevenueCat. Our subscription management provider tells us whether your trial or subscription is active, when it renews, and when it lapses.
- Supabase. Our authentication provider confirms that a sign-in attempt is valid.
- AppsFlyer. Our attribution provider tells us which advertisement or campaign an install came from.
4. Sensitive information and consumer health data
Moods, emotions, the reflections you write in Tranqui, and the answers you give when you set up your account are sensitive personal information. In Washington and Nevada they are also "consumer health data" under state law. We treat them accordingly: they are never sold, never shared with advertising partners, and never used to train any artificial intelligence model.
In practice, that commitment means all of the following:
- No advertising partner ever receives your journal content or your onboarding responses, or anything derived from them. Meta, TikTok, Google, and AppsFlyer receive device identifiers, an IP address, basic device information, and app lifecycle events; Section 8 lists exactly what. They never receive a mood, an emotion, a topic, a word you have written, or an answer you gave when you set up your account, they never receive an inference we have drawn from any of those, and there is no event in Tranqui that would tell them what an entry is about.
- No model is trained on what you write. Not ours, not a vendor's. See Section 6.
- Access inside the company is restricted. See Section 11.
- Deletion is real. When you ask us to delete your account, your journal content and your onboarding responses are deleted within 30 days, and backups containing them are purged on a rolling 90-day cycle. See Section 10.
If you are in Washington or Nevada, you have additional rights over this information under the My Health My Data Act and Nevada SB 370. Those rights, and the specific disclosures those laws require, are set out in our Consumer Health Data Privacy Policy, which is a separate document.
5. How we use your information
We use your information for these purposes, and for no others except the limited disclosures described in Section 7:
- Providing the service. Running the app, storing and displaying your entries, syncing across your devices, and sending the notifications you have asked for.
- Personalizing content. Choosing which exercises, prompts, and educational material to show you, based on the moods and emotions you log and on the answers you gave when you set up your account.
- Managing accounts and subscriptions. Creating and authenticating your account, starting and ending your free trial, keeping your subscription in the right state, and handling renewals and lapses.
- Support. Answering your questions, investigating problems you report, and keeping a record of what we told you.
- Product analytics and improvement. Understanding which features are used and which are ignored, and deciding what to build next. This uses device and usage data, not journal content.
- Security and fraud prevention. Detecting unauthorized access, abuse of free trials, and automated attacks.
- Measuring advertising effectiveness. Understanding which advertisements bring people to Tranqui, so we do not waste money on the ones that do not. This uses device identifiers and app lifecycle events, never journal content. See Section 8.
- Legal compliance. Meeting tax, accounting, and consumer protection obligations, and responding to lawful requests.
We do not use your information to make automated decisions that produce legal or similarly significant effects about you.
6. Artificial intelligence
Tranqui uses artificial intelligence to write content — exercises, prompts, explanations, and educational material — before that content ever reaches the app. Three commitments follow from that, and they are absolute:
- AI generates static in-app content only. Everything an AI model produced for Tranqui was produced in advance and shipped as part of the app. It is the same for every user.
- AI does not read, process, or respond to anything you write. Your entries, reflections, and moods are never sent to an AI model. There is no chatbot in Tranqui and nothing you write is answered by a machine.
- No user data trains any model. Not a model of ours, and not a third party's. Your content is never used as training data, fine-tuning data, or evaluation data by anyone.
We say this without qualification because it is a design decision, not a policy preference. If we ever build a feature that would require sending your content to an AI model, we would have to change this section first, tell you before it took effect, and ask for your consent.
7. How we disclose your information
We use a small number of service providers to run Tranqui. Each is named below, along with what it receives and why.
| Recipient | What they receive | Purpose |
|---|---|---|
| Supabase | Account data including your age range, your onboarding responses, journal content, subscription status, usage data, device model, operating system version, app version, IP address | Infrastructure, database, and authentication |
| Apple | Payment and subscription data, account identifier, sign-in credentials if you use Sign in with Apple | Billing, subscription management, sign-in |
| RevenueCat | Subscription status, device identifier | Subscription management and entitlement checks |
| Purelymail | Your email address, and the content of support messages you send us | Sending and receiving account and support email |
| AppsFlyer | Device and advertising identifiers, IP address, device model, operating system version, app version, and install, open, session, account registration, subscription or trial start and purchase events including value | Attribution — telling us which campaign an install came from |
| Meta | Device and advertising identifiers, IP address, device model, operating system version, app version, and install, open, session, account registration, subscription or trial start and purchase events including value | Advertising measurement |
| TikTok | Device and advertising identifiers, IP address, device model, operating system version, app version, and install, open, session, account registration, subscription or trial start and purchase events including value | Advertising measurement |
| Device and advertising identifiers, IP address, device model, operating system version, app version, and install, open, session, account registration, subscription or trial start and purchase events including value | Advertising measurement |
The advertising identifier reaches AppsFlyer, Meta, TikTok and Google only if you granted App Tracking Transparency permission. Section 9 explains how to withhold or withdraw it.
No advertising or attribution partner in this table receives your journal entries, moods, reflections, onboarding responses, or anything derived from them, and none receives the record of which screens you open or which features you use inside the app. The only recipient that holds journal content and onboarding responses is Supabase, which stores them for us as our database provider. Our email provider carries whatever you choose to put in an email to us, so please do not paste an entry into a support message unless you need us to see it.
We have not negotiated bespoke data processing agreements with these providers. We are bound by each provider's published data processing terms, which we accepted when we signed up for the service, and which for the major providers incorporate the standard contractual clauses. Those terms govern what each provider may do with the information it receives.
We also disclose information in these circumstances:
- Legal process. When we are required to by a subpoena, court order, warrant, or other lawful demand. We review each request, we disclose only what the request actually requires, and where we are permitted to tell you about it, we will.
- Safety. When we believe in good faith that disclosure is necessary to prevent imminent physical harm to a person, or to investigate suspected fraud or a violation of our Terms.
- Corporate transactions. If Tranqui is involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction. The recipient would remain bound by this policy for information collected before the transfer, and we would notify you before any change to how your information is handled took effect.
8. Advertising, analytics, and "sale" or "sharing"
We advertise Tranqui on Meta, TikTok, and Google. To know whether that advertising works, we need to connect an install to the campaign that produced it. That is what this section is about, and this is the operative disclosure:
We never sell, share, or disclose your journal entries, moods, reflections, or any content you write in Tranqui for advertising purposes.
We do share device and app-usage identifiers with advertising and attribution partners — Meta, TikTok, Google, and AppsFlyer — so we can measure which advertisements bring people to Tranqui. Under the California Consumer Privacy Act and several other state privacy laws, that sharing is treated as a "sale" or a "share," even though we receive no money for it and no content you write is ever included.
You can opt out at any time.
To be concrete about what those partners receive: a device identifier; an advertising identifier, but only where you granted App Tracking Transparency permission; an IP address; the device model, operating system version and app version that their software transmits with any network request; and app lifecycle events — install, open, session, account registration, subscription or trial start, and purchase including its value. Because an IP address implies a rough location, those partners can infer the city or region you opened the app from; they cannot get closer than that, because we do not collect precise location at all.
They do not receive your email address, your name, your journal entries, the moods or emotions you log, the reflections you write, the topics you write about, any inference we have drawn from any of it, or any event that identifies the topic or emotional content of anything you view or write in the app. There is no such event in Tranqui.
We verify the exact set of events these partners receive against the app's SDK configuration, and we update this section if it changes.
We have never sold personal information for money, and we do not intend to. We do not sell or share the personal information of anyone we know to be under 16, and because Tranqui is an 18-and-over service, we do not knowingly have any such users at all.
To opt out, email privacidad@apptranqui.com or use the Your Privacy Choices page. A person reads and honors those requests. Declining Apple's App Tracking Transparency prompt stops the advertising identifier being shared at all, and takes effect immediately, but it is narrower than a full opt-out and does not replace one. Section 9 sets out every route in full.
9. Your privacy choices
Opt out of sale and sharing. You can opt out of the advertising-related sharing described in Section 8 at any time, by emailing privacidad@apptranqui.com or using the Your Privacy Choices page. A person reads every such request and applies it. You do not need an account, and we will not ask you to create one. Opting out does not reduce the features available to you or change the price you pay.
Global Privacy Control. Global Privacy Control is a signal that browsers and browser extensions send; mobile apps do not send it. On our website there is nothing for the signal to switch off, and we would rather explain that than describe machinery we have not built: the site loads no advertising scripts and no analytics scripts, sets no advertising or analytics cookies, and sells and shares nothing. A Global Privacy Control signal arriving here therefore has nothing to stop. We do not ask you to confirm the signal and we do not override it, and if we ever add anything to the website that would count as a sale or a share, we will honor the signal and say so here before that happens. The app cannot send or receive the signal, so on mobile the full opt-out runs through the email address above or the Your Privacy Choices page. Declining App Tracking Transparency, described just below, is a narrower control: it stops the advertising identifier reaching our partners, but the other information listed in Section 8 keeps flowing until you opt out. The two are not equivalent, and we would rather say so than let you assume otherwise.
App Tracking Transparency. The first time you open Tranqui, iOS asks whether you will allow us to track you across other companies' apps and websites. If you decline, Apple withholds the advertising identifier from us and our partners, and we do not attempt to work around that in any way. Declining affects the advertising identifier only; the rest of what Section 8 lists keeps flowing until you opt out through one of the routes above. You can change your answer at any time in Settings > Privacy & Security > Tracking.
Device-level advertising controls on iOS. Two settings are worth knowing about:
- Settings > Privacy & Security > Tracking. Turn off "Allow Apps to Request to Track" to deny the advertising identifier to every app on your device at once, including ours.
- Settings > Privacy & Security > Apple Advertising. Turn off "Personalized Ads" to stop Apple from using your App Store activity to target advertising.
Notifications. You can turn off Tranqui's notifications at any time in Settings > Notifications > Tranqui on your device. We will still send you essential messages about your account, your subscription, and this policy.
Authorized agents. You may use an authorized agent to submit a request on your behalf. We will ask the agent for proof of your authorization, and we may ask you to confirm it directly.
10. How long we keep your information
We keep information for the periods below. "As long as necessary" is what most privacy policies say, and it commits to nothing, so we have written down actual numbers.
| Data | Retention |
|---|---|
| Account data, including your onboarding responses | Life of the account, plus 30 days |
| Journal entries, moods, reflections | Deleted within 30 days of account deletion |
| Billing and tax records | 7 years (legal requirement) |
| Analytics and usage data | 26 months |
| Support correspondence | 3 years |
| Backups | Purged on a rolling 90-day cycle |
When you ask us to delete your account, we begin deletion immediately and finish within 30 days. Backups are not individually editable, so deleted content can persist in a backup until that backup ages out, which takes no more than 90 days. During that window the backup is encrypted and is not used for any purpose except restoring the service after a failure.
We may keep aggregate statistics that cannot identify you or be linked back to you — for example, the total number of accounts created in a month. We may also keep the minimum record needed to show that you asked us to delete your data, or that you opted out, so that we can honor that choice.
11. Security
We protect your information with the following measures:
- Encryption in transit. All traffic between the app and our servers uses TLS. There is no unencrypted fallback.
- Encryption at rest. Your data, including journal content, is encrypted on the disks where it is stored.
- Row-level access control. Our database enforces, at the database level, that an account can read only its own entries. This is not left to application code to get right.
- Restricted internal access. A small number of people have administrative access to production systems. Journal content is not routinely accessible to staff, and we do not read entries except where it is strictly necessary to resolve a support request that you have made and cannot be resolved another way, or where the law requires it.
- Authentication. Passwords are stored hashed, never in plain text. Administrative accounts require multi-factor authentication.
- Vendor terms. Every provider named in Section 7 is bound by its published data processing terms, which we accepted when we signed up and which restrict what it may do with the information it receives. We have not negotiated bespoke agreements with any of them.
We want to be straight with you about the limits of this. Tranqui does not use end-to-end encryption: because your entries sync across your devices and are recoverable if you lose a device, we hold the keys, which means we are technically capable of reading them. We choose not to, and we restrict who could — but no system is completely secure, and anyone who tells you otherwise is selling something.
If you believe you have found a vulnerability in Tranqui, please tell us at privacidad@apptranqui.com. We will acknowledge your report within five business days. We will not pursue legal action against anyone who reports a vulnerability to us in good faith and does not access or destroy other people's data.
12. International data transfers
We operate from the United States and process personal data on servers located in the United States. If you use Tranqui from Latin America or anywhere else outside the United States, your information is transferred to and processed in the United States, where privacy laws differ from those in your country.
We rely on the following safeguards for those transfers:
- The published data processing terms of every provider named in Section 7, which we accepted when we signed up for each service and which require them to protect the information they receive. For the major providers those terms incorporate the standard contractual clauses, or the equivalent mechanism recognized by your country's law. We have not negotiated bespoke agreements with any provider.
- The same technical measures described in Section 11, regardless of where the data sits.
Where the law of your country requires your consent for an international transfer, using Tranqui after being shown this policy constitutes that consent, and you may withdraw it by asking us to delete your account.
13. Children
Tranqui is for adults only. You must be 18 or older to create an account or use the Services.
We ask you to select an age range when you sign up. We do not verify it — we rely on your answer, and we do not collect identity documents or a date of birth in order to check it. Asking is how we keep the service to adults; it is not age verification and we do not describe it as such.
We do not knowingly collect personal information from anyone under 18. If we learn that we have, we delete the account and its contents promptly. If you believe a person under 18 has an account with us, email privacidad@apptranqui.com and we will act on it.
14. Your rights
Wherever you live, you have the following rights over your information. Some of them are guaranteed to you by law and some are not, depending on your state or country — we extend all of them to everyone, because operating two standards is a good way to get one of them wrong.
- Access. Ask what personal information we hold about you and get a copy.
- Correct. Ask us to fix information that is inaccurate.
- Delete. Ask us to delete your account and everything in it. Email us and we will do it on the schedule in Section 10.
- Portability. Get your information in a structured, machine-readable format that you can take elsewhere.
- Opt out. Opt out of the sale and sharing described in Section 8, and of targeted advertising.
- Withdraw consent. Withdraw any consent you have given, at any time. Withdrawing consent does not undo processing we carried out before you withdrew it.
- Non-discrimination. Exercise any of these rights without being charged a different price, given a lower level of service, or penalized in any way. We do not offer financial incentives in exchange for your personal information.
How to exercise them. Email privacidad@apptranqui.com, or write to the postal address in Section 19. Tell us which right you want to exercise. You do not need to use any particular wording. Use one of those two addresses rather than the website's contact form; a person reads them and acts on what arrives.
Identity verification. Before we act on an access, correction, deletion, or portability request, we need to be confident that you are who you say you are — releasing someone's journal to an impostor would be a far worse privacy failure than any this policy is trying to prevent. Normally we verify you by confirming that you control the email address on the account. If a request is unusually broad or the account holds a lot of information, we may ask for more. We will not ask for more information than the verification actually needs, and we will not use anything you send for verification for any other purpose.
Response times. We acknowledge requests within 10 business days and respond substantively within 45 days. If a request is complex, we may extend that by a further 45 days, and we will tell you before the first 45 days are up. Opt-out requests are handled within 15 business days and usually much faster.
Appeals. If we refuse a request, we will tell you why in writing. You may appeal by replying to that message or by writing to privacidad@apptranqui.com with the word "appeal" in the subject line. We will review the decision afresh rather than restate it, and we will respond within 45 days with our conclusion and the reasons for it. If we deny your appeal, we will tell you how to complain to your state attorney general or data protection authority.
15. United States state privacy rights
15.1 California
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the rights described in Section 14 and a few more. The table below sets out the statutory categories of personal information and what we do with each.
| Statutory category | Examples in Tranqui | Collected | Disclosed for a business purpose | Sold or shared |
|---|---|---|---|---|
| A. Identifiers | Email address, account ID, device identifier, IP address, and the advertising identifier where you granted App Tracking Transparency permission | Yes | Yes | Yes — device identifier, IP address, and the advertising identifier where permitted. Never your email address or account ID |
| B. California Customer Records categories | Name or display name, email address. Payment card details are handled by Apple and never reach us | Yes | Yes | No |
| C. Protected classification characteristics | An age range, collected to confirm you are 18 or older. We do not collect a date of birth, race, religion, national origin, sexual orientation, disability status, or similar characteristics | Age range only | Yes, to Supabase only | No |
| D. Commercial information | Subscription plan, trial status, purchase and renewal history | Yes | Yes | Yes — the fact and value of a purchase only |
| E. Biometric information | None | No | No | No |
| F. Internet or other electronic network activity | Screens viewed, features used, session length, device model, operating system version, app version, and app lifecycle events | Yes | Yes | Yes — device model, operating system version, app version, and install, open, session, account registration, subscription or trial start and purchase events only. Which screens you open and which features you use are never shared |
| G. Geolocation data | Approximate city or region inferred from IP address. We do not collect precise location | Approximate only | Yes | Yes |
| H. Audio, electronic, visual, or similar information | None. Tranqui does not record audio or video | No | No | No |
| I. Professional or employment information | None | No | No | No |
| J. Non-public education information | None | No | No | No |
| K. Inferences | Patterns drawn from your mood and emotion logs, and the profile formed by the goals, preferences, and current situation you describe when you set up your account, used to choose which content to show you | Yes | Yes, to Supabase only | No — never |
| L. Sensitive personal information | Your journal entries, moods, emotions, and reflections, and the goals and current situation you describe when you set up your account, all of which concern your mental health, and your account log-in credentials | Yes | Journal content and onboarding responses to Supabase only. Log-in credentials to Supabase, or to Apple if you use Sign in with Apple | No — never |
Sources and purposes. We collect these categories from you directly, automatically from your device, and from the third parties named in Section 3.3. We collect them for the purposes in Section 5 and disclose them to the recipients in Section 7.
Right to limit the use of sensitive personal information. California lets you direct a business to limit its use of sensitive personal information to what is necessary to provide the service you asked for.
Your journal content and your onboarding responses are used to run Tranqui and to choose which content the app shows you, and for nothing else. To do that we draw patterns from your mood and emotion logs and from what you told us when you set up your account. Those patterns never leave Supabase, are never used for advertising, are never disclosed to any advertising partner, and are never sold or shared.
If you would rather we did not draw them at all, email us and we will limit our use of your journal content and your onboarding responses to storing them and displaying them back to you. The effect is that the app stops personalizing which exercises and prompts it offers and shows the same content to you as to everyone else. Nothing else about your account changes and the price is the same.
Shine the Light. California Civil Code Section 1798.83 lets you request a list of the personal information we disclosed to third parties for those third parties' own direct marketing purposes in the previous calendar year. We do not make such disclosures. If that ever changes, you may make a request once per year by emailing privacidad@apptranqui.com.
Response commitment. We respond to verified California requests within 45 days, extendable once by a further 45 days where the request is complex, and we will tell you before the first period runs out if we need the extension.
Complaints. You may complain to the California Privacy Protection Agency or the California Attorney General.
15.2 Other states
In every state listed below you have the right to confirm whether we process your personal data, to access it, to obtain a portable copy, to delete it, to correct it, and to opt out of targeted advertising and of the sale of your data. We honor all of those rights for every user in every state, including where a state's own law does not require one of them. Use the contact routes in Section 14.
The "Notable differences" column highlights a selection of provisions that vary between these states. It is not an exhaustive statement of any state's law, and a provision left out of one row does not mean that state lacks it — most of these statutes require sensitive-data consent and require universal opt-out signals to be honored. We treat your journal content as consent-based for every user, wherever they live. On universal opt-out signals, Section 9 gives the full account: our website sells and shares nothing, so a signal arriving there has nothing to switch off, and mobile apps do not send such a signal at all — which is why the email opt-out described in Section 9 is open to every user wherever they live, and covers everything Section 8 describes.
| State | Law | Notable differences |
|---|---|---|
| Virginia | Consumer Data Protection Act | Consent required before processing sensitive data. Appeal process required |
| Colorado | Colorado Privacy Act | Universal opt-out signals such as Global Privacy Control must be honored. Consent required for sensitive data. Appeal process required |
| Connecticut | Connecticut Data Privacy Act | Universal opt-out signals must be honored. Consent required for sensitive data. Appeal process required |
| Utah | Utah Consumer Privacy Act | State law provides no correction right and no appeal process. We give you both anyway |
| Texas | Texas Data Privacy and Security Act | Universal opt-out signals must be honored. Consent required for sensitive data. Appeal process required |
| Oregon | Oregon Consumer Privacy Act | You may request a list of the specific third parties to whom we disclosed your personal data. Appeal process required |
| Montana | Montana Consumer Data Privacy Act | Universal opt-out signals must be honored. Appeal process required |
| Delaware | Delaware Personal Data Privacy Act | You may request the categories of third parties to whom we disclosed your personal data. Appeal process required |
| Iowa | Iowa Consumer Data Protection Act | State law provides no correction right and no appeal process. We give you both anyway |
| Nebraska | Nebraska Data Privacy Act | Consent required for sensitive data. Appeal process required |
| New Hampshire | New Hampshire Data Privacy Act | Universal opt-out signals must be honored. Appeal process required |
| New Jersey | New Jersey Data Privacy Act | Universal opt-out signals must be honored. Consent required for sensitive data. Appeal process required |
| Maryland | Maryland Online Data Privacy Act | Selling sensitive data is prohibited outright, and data collection must be reasonably necessary. We do not sell sensitive data anywhere |
| Minnesota | Minnesota Consumer Data Privacy Act | You may request a list of the specific third parties to whom we disclosed your personal data, and question the result of any profiling. Appeal process required |
| Rhode Island | Data Transparency and Personal Privacy Protection Act | The third parties to whom personal data may be sold must be named in the privacy policy. Section 7 names all of ours |
| Kentucky | Consumer Data Protection Act | Consent required for sensitive data. Appeal process required |
| Indiana | Consumer Data Protection Act | You may ask for a copy or a representative summary of your personal data. Appeal process required |
| Tennessee | Tennessee Information Protection Act | Consent required for sensitive data. Appeal process required |
Sensitive data consent. Several of these states require your consent before a company processes sensitive data, which includes information about mental health. You give that consent when you answer the questions at sign-up, log a mood, or write a reflection, and you can withdraw it at any time by emailing us to delete your journal content or your whole account. We do not use that data for advertising in any state, whether or not the state requires consent.
Appeals. Most of these states require us to offer an appeal if we refuse a privacy request. We offer it to everyone. The process is in Section 14.
If you live in a state not listed here, write to us anyway. We will handle your request the same way.
16. Washington and Nevada consumer health data
Washington's My Health My Data Act and Nevada Senate Bill 370 regulate "consumer health data", which includes the moods, emotions, and reflections you record in Tranqui and the answers you give when you set up your account. Both laws require us to publish a consumer health data privacy policy as a separate, separately linked document, so we have not restated its contents here.
Read the Consumer Health Data Privacy Policy. It sets out what consumer health data we collect, why, who receives it, how long we keep it, your rights over it, and how to withdraw your consent.
The short version, which the full policy states in binding terms: we do not sell your consumer health data, we do not share it with advertising or attribution partners, we do not use it to train artificial intelligence models, and we do not operate a geofence around any health care facility.
17. Latin America
Tranqui is available across Latin America and we have not written those users out of this policy in order to serve a United States launch. If you are in Brazil, Argentina, Mexico, or another Latin American country, everything above applies to you, and so does this section.
17.1 Legal bases for processing
We process your personal data on these legal bases, depending on the purpose:
- Performance of a contract. Running your account and providing the Services you signed up for.
- Consent. Processing the moods, emotions, and reflections you record and the answers you give when you set up your account, which are sensitive data in most Latin American jurisdictions, and sending you marketing messages if you have asked for them.
- Legal obligation. Keeping tax and accounting records, and responding to lawful demands.
- Legitimate interests. Securing the Services, preventing fraud, and understanding how the app is used at an aggregate level. We do not rely on legitimate interests to process journal content or onboarding responses.
17.2 Brazil
Under the Lei Geral de Proteção de Dados (Law 13.709/2018) you may confirm that we process your data, access it, correct it, anonymize or delete it, obtain a portable copy, learn with whom we have shared it, be told what happens if you refuse consent, and revoke consent at any time.
Our data protection officer, the encarregado required by Article 41, can be reached at privacidad@apptranqui.com. You may also complain to the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.
17.3 Argentina
Under Ley 25.326 you have rights of access, rectification, updating, and suppression of your personal data. Write to privacidad@apptranqui.com to exercise them.
As Argentine law requires us to tell you: the data subject has the right to exercise the right of access to their personal data free of charge at intervals of no less than six months, unless a legitimate interest to the contrary is demonstrated, in accordance with Article 14, subsection 3 of Law 25.326. The Agencia de Acceso a la Información Pública (AAIP), as the enforcement authority for Law 25.326, has the power to hear complaints and claims brought by those affected by breaches of personal data protection law.
17.4 Mexico
Under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares you hold the ARCO rights — access, rectification, cancellation, and opposition — and you may revoke your consent or limit the use or disclosure of your data. Send an ARCO request to privacidad@apptranqui.com with your name, a means of contacting you, proof of identity, a clear description of the data concerned, and the right you wish to exercise. We will respond within 20 business days and, if the request is granted, act on it within 15 further business days. You may also complain to the Mexican data protection authority designated under that law.
17.5 Other countries
Chile, Colombia, Peru, Uruguay, Ecuador, Costa Rica, and other countries in the region have their own data protection statutes. Where your local law grants you a right this policy does not mention, you still have it, and we will honor it on the same terms. Write to privacidad@apptranqui.com.
18. Changes to this policy
We update this policy when what we do changes. When we make a material change — a new category of data, a new purpose, a new recipient, or anything that expands what we share — we will tell you before it takes effect, by email to the address on your account, and we will update the "Last updated" date at the top.
We will not apply a material change retroactively to information we have already collected without asking for your consent first. If you do not agree with a change, ask us to delete your account and we will delete your information on the schedule in Section 10.
19. Contact us
AZEApps LLC
229 West Ash Street, Lombard, IL 60148
Privacy and data subject requests: privacidad@apptranqui.com
Security reports: privacidad@apptranqui.com
Website: apptranqui.com
To make a privacy request, email privacidad@apptranqui.com and tell us what you want. You can also write to us at the postal address above. We acknowledge requests within 10 business days and respond within 45 days, as described in Section 14.
To opt out of the sale and sharing of your personal information, email privacidad@apptranqui.com or use the Your Privacy Choices page.