Back to app

How We Protect You

Not a legal document. A promise.

🔐

We can't read your feelings

Your journal entries, mood triggers, coping methods, and AI responses are encrypted with AES-256-GCM before they're stored — the same encryption banks use. If someone broke into our database, all they'd see is scrambled text. Even our own engineers can't read your content.

👁️‍🗨️

Zero trackers. Zero ads. Zero exceptions.

No Google Analytics. No Facebook Pixel. No ad SDKs. No third-party tracking scripts of any kind. We don't know which page you stared at the longest, and we don't want to. Your healing journey is yours alone.

🙈

Use it without signing up

You don't need to give us your email, name, or anything to start. Your data stays on your device. When you're ready, you can create an account to sync across devices — but that's entirely your choice.

🗑️

Delete means gone

No 30-day waiting period. No "we keep backups" excuse. When you delete a mood entry, it's permanently removed from our database. When you delete your account, everything goes. We have no reason to keep what you don't want kept.

🤖

AI doesn't remember you

When Peacemind generates a response for you, your text is sent to the AI, processed, and immediately discarded. The AI doesn't store, learn from, or remember your conversations. Every response starts fresh. Your words only live in your encrypted records.

💚

How we stay alive

Peacemind is free, forever. We don't sell your data. Won't. Ever. We sustain ourselves through optional premium features like cross-app insights. The core healing features — mood tracking, breathing, journaling — will always be free for everyone.

📖

Don't trust our words — read our code

Peacemind is open source. Every line of code is public. Anyone can verify that our encryption is real, that there are no hidden trackers, and that your data goes exactly where we say it does. Transparency isn't just a policy — it's in the code.

View source code →
🛡️

Under the hood

  • ✓ AES-256-GCM encryption on all sensitive fields
  • ✓ Row-level security (you can only see your own data)
  • ✓ All API calls server-side (no database access from client)
  • ✓ Rate limiting on all endpoints
  • ✓ Automated security audits on every code change
  • ✓ HTTPS everywhere — encrypted in transit
  • ✓ Zero third-party tracking scripts

We do this not because the law requires it. We do it because you're trusting us with your most vulnerable moments — your anxieties, your tears, your 2am thoughts. That trust deserves to be taken seriously.

Questions about security? Reach us at healingmindspace@proton.me