Privacy Policy
Last updated: July 23, 2026
Paradigm is a wellness and self-reflection app. This policy explains what information Paradigm collects, how it is used, and what controls users have.
Information We Collect
Paradigm may collect account details, authentication identifiers, onboarding answers, identity profile details, session requests, check-ins, post-session reflections, generated session scripts, generated audio metadata, session completions, proof actions, Shadow Profile notes, dream entries, Attention Shield preferences, beta feedback, purchase entitlement status, and basic product analytics.
When someone requests Android closed-beta access or joins the iOS waitlist, Paradigm collects the submitted email address, selected list, optional response to “What are you becoming?”, consent record, verification and enrollment status, referrer, lightweight campaign parameters, and a one-way hash derived from basic request metadata to reduce duplicate or abusive signups.
If a user chooses voice input, audio may be processed for transcription and session personalization. If a user explicitly creates a custom voice feature, Paradigm may send consent and voice sample recordings to the selected voice provider to create a voice for that user's own sessions.
How We Use Information
Paradigm uses information to personalize rituals, remember user preferences, generate audio, maintain streaks and session passes, support Attention Shield behavior, provide support, improve reliability, understand whether the product is working, and send early access or launch updates to people who requested them.
Closed Beta Enrollment
For Android closed-beta applicants, Paradigm verifies the submitted email, adds eligible verified addresses to a restricted Google Play tester group, sends the official Google Play opt-in link, records delivery and retry events, and removes tester-group access when a tester leaves or access is revoked. Supabase stores the enrollment record; Resend processes service emails; Google Workspace and Google Play process tester access. Verification tokens are stored only as one-way hashes and expire after 24 hours. Rate-limit attempt hashes are deleted after 30 days.
AI Providers
Paradigm may send relevant session prompts, onboarding turns, voice transcription requests, or consented voice samples to AI providers for text generation, text-to-speech, speech-to-text, and voice features. Paradigm aims to send only the information needed to provide the requested feature.
Payments
Purchases are processed by app store billing and RevenueCat. Paradigm stores entitlement status, product identifiers, expiration data, and webhook event metadata so the app can unlock Base, Plus, or Sovereign access.
Analytics And Error Monitoring
Paradigm may record compact app events such as session generation requested, session ready, session completed, feedback submitted, billing refresh, and sign-out. Paradigm may use services such as Sentry to collect crash reports and error context.
On closed-beta web pages, and only after a visitor permits advertising measurement, Paradigm uses the TikTok Pixel and Events API to understand whether a TikTok advertisement led to a page visit or completed beta application. A completed-application event may be sent from both the browser and Paradigm's server with the same random event identifier so TikTok can deduplicate it. TikTok may receive standard browser and event information, timestamps, referring and campaign information, advertising cookies, page metadata, page interactions and performance information, and a securely hashed version of an email entered in the beta form through Automatic Advanced Matching. TikTok may use matched events for attribution, campaign optimization, and audience matching subject to its settings and the visitor's TikTok settings. Paradigm does not intentionally send TikTok the applicant's optional intention response, private ritual content, voice data, reflections, or other in-app content. Visitors can decline or change this choice from the Privacy choices control on a beta page.
Attention Shield
Light Shield uses app usage data when the user grants permission. Full Shield uses Android Accessibility permission to redirect selected apps during user-created shield windows. Paradigm does not read messages, passwords, private app contents, or notifications.
User Controls
Users can export data, clear offline audio, sign out, leave the closed beta from the management link in a beta email, and request account deletion from Settings. Leaving the beta stops beta service emails and queues removal from the Google Play tester group. Deleting an account removes profile data, generated sessions, session history, saved reflections, and generated audio associated with the account, subject to provider, security, legal, and billing records that may need to be retained.
Contact
For privacy questions, contact paradigm.csupport@proton.me.