1. About this policy
Floatback is a product of Wired Different Labs LLC, doing business as Floatback ("Floatback," "we," "us," or "our"). It's a self-guided wellness tool that uses techniques informed by EMDR research. It is not therapy and does not create a therapist-client relationship. See our Terms of Service for more. This policy explains what we collect, how we use it, who else sees it, and the rights you have over it.
2. The sensitivity of what you share
Floatback is built to hold emotionally sensitive material: trauma narratives, body sensations, distress ratings, and beliefs you carry about yourself. That is a different category of data than "what pages you visited on a website." We recognize that, and we design for it.
- We collect only what the app actually needs to help you.
- We do not sell your data. Ever.
- We do not use it for advertising. Ever.
- We do not share it with data brokers, insurers, employers, family, or any third party other than the vendors we rely on to run the service (listed below in section 8).
- You can delete everything at any time from Settings.
If there are things you do not want to write down, for any reason, it is okay to skip them. The app is meant to be useful without demanding full disclosure.
3. What we collect
- Account information: your email address, optional display name, and app preferences.
- Conversation content: everything you write during mapping conversations and guided sessions with the AI companion, including your messages and the companion's replies.
- Voice input (optional): if you tap the microphone to speak instead of type, the app records that audio in your browser and sends it to a transcription service (OpenAI's Whisper) to turn it into text. We then use the text exactly as if you had typed it. We do not keep the audio recording once it has been transcribed. Voice is always optional (you can type instead), and there's a daily limit on how much you can transcribe. See section 6 for what the transcription service receives.
- Session data: distress ratings you give (a number from 0–10), the negative and positive beliefs you identify (as the text you wrote), body sensations you describe, target memories or situations you choose to work with, and your progress through a session's phases.
- Your map: the AI-generated "map" of themes, beliefs, and emotional threads drawn from what you share.
- AI-generated profile notes: over time, the companion writes short summaries about you to keep continuity across sessions: things like a sketch of your "parts," your typical body sensations, the emotional vocabulary you use, your relationship-attachment patterns, and the coaching style that's worked for you. These are summaries the AI builds from your sessions; you don't write them directly. They live on your profile, are exported and deleted alongside everything else, and are covered by the same "you can ignore what doesn't fit" caveat as the map (see section 7).
- Life-log and mood entries: optional observations and check-ins you record between sessions.
- Feedback you send us: anything you submit through the in-app feedback form: the message itself, the type of feedback you chose (general, bug, feature request, or compliment), an optional star rating, whether you've allowed us to follow up with you, and basic technical context (the page you were on and your browser's user-agent string) to help us investigate bug reports. Feedback is deleted along with the rest of your data when you delete your account.
- No usage analytics: we do not track which features you use or how you move through the app. Floatback runs no third-party analytics or tracking tools of any kind.
- Crash and error reports: when something breaks, we collect a technical error report (what went wrong, where in the app, and your account ID so we can connect related reports) through an error-logging service (BetterStack), so we can find and fix bugs. These reports are designed to capture technical details only: the diagnostic context we attach is automatically stripped of the free-text fields you write, and we never include your email.
- Subscription and billing information: if you start a paid plan, we keep the subscription and account details we need to grant access and renew it: your Stripe customer ID, current plan and status, trial end date, and any cohort flags (for example, the founding-member 50%-off discount). Payment method details, billing address, and similar payment-card information are collected by Stripe directly at checkout. We never see or store them.
- Email-delivery records: we keep a small log of the transactional emails we send you (welcome notes, billing notifications, trial reminders): the template that was sent, the time, and whether delivery succeeded. We use it to debug delivery problems and to avoid sending you the same email twice. You can opt out of non-essential email categories from Settings.
- Connection metadata: when your browser talks to our servers, our hosting provider sees standard request information like your IP address and user-agent string. We use this only for security, abuse prevention, and short-term debugging. We don't build a tracking profile from it, and we don't store it against your account.
- Waitlist signups: if you give us your email address before you have an account (for example, by joining a launch waitlist), we keep your email and the date you signed up so we can contact you when access opens. To be removed, email us using the address on our website.
4. How your data is stored
Your data is stored in Supabase (PostgreSQL), encrypted in transit (TLS) and at rest. Each user's data is isolated at the database level using row-level security: your account can only read and write its own rows. Access to the production database is restricted to a small number of operators who need it to run the service.
People don't read your content. We have not built any feature that lets someone on our team read through your conversations, your map, or the things you write. The app's servers process your data automatically to make features work, for example sending your message to the AI so it can reply, but a person isn't browsing it. If you ever ask us for help with your account and we'd need to look at something, we'll ask for your explicit permission first, and only look at what's needed to sort out your request.
5. Cookies, local storage, and tracking
The app stores a small amount of data in your browser to keep you signed in, remember your preferences, and keep the app working. We do not use analytics or advertising cookies, and we do not track you across other websites.
- Browser storage (localStorage): your sign-in session, theme choice, cookie-consent acknowledgement, and last-route memory live in your browser's local storage, not on our servers. Clearing your browser data will sign you out and reset these preferences.
- A small functional cookie: remembers whether the sidebar is open or collapsed so it stays the way you left it between visits.
- Consent banner: our cookie notice is a first-party banner built into the app; it does not load a third-party consent manager. Your acknowledgement is stored locally under the key
cookie_consent_v1 and can be reset from Settings.
Most browsers let you block or delete cookies and local storage. Blocking them will sign you out and may affect how the app looks and behaves.
6. What we send to outside services to power the app
A few features only work by sending data to specialized outside providers. We send each one only what it needs to do its job, over an encrypted connection. Here is exactly what goes where.
The primary AI companion (Anthropic).
The AI companion is primarily powered by Anthropic's Claude API. When Anthropic generates a companion response, the app sends it the following:
- The full conversation history for that session: your messages and the companion's previous replies.
- Relevant session state for guided sessions: the target experience you've chosen, the emotions and body sensations you've described, the beliefs you're working with (sent as the text you wrote, not as numeric ratings), and your current distress rating (a number from 0–10).
- Therapeutic context the app has built up about you from past sessions, for example your "parts" map, notes about grounding techniques that have helped, or patterns we've noticed. Sent as a condensed text summary alongside each session payload.
- In exploration chat, if the companion searches your history to remember something, the relevant map items, life-log entries, or past-conversation excerpts returned by that search.
- In the separate mapping conversation (the onboarding / exploration chat, not guided sessions), we also send your preferred name if you've set one, so the companion can address you by it. Guided-session requests do not include your preferred name.
Transmission is over TLS. Anthropic receives this data to generate the response and then returns the response to our servers, which we then show to you and store in our database (so you can see your history).
Anthropic also powers background AI work that helps organize what you share. This includes extracting structured information from a conversation, generating or updating your map, categorizing text you capture, generating a session title, and creating narrative or loop summaries. For each task, Anthropic receives the input used to perform it. Depending on the task, that can include a conversation transcript or excerpt, capture text, map or session context, or existing AI-generated notes.
Retention and training at Anthropic.
- Anthropic's default API policy is that customer inputs and outputs may be retained for up to 30 days for abuse monitoring and then deleted. We use Anthropic under this default policy.
- Anthropic does not train its models on API inputs or outputs by default, and we have not opted in to any training-data program.
- We are evaluating moving Floatback to Anthropic's Zero Data Retention (ZDR) configuration, under which Anthropic stores API inputs and outputs only long enough to generate the response and then deletes them. We are not yet on ZDR. If we move to ZDR we will update this policy.
For the most current statement of Anthropic's API data practices, see Anthropic's own privacy and usage policies.
Voice transcription and some AI work (OpenAI).
If you use voice input, the app sends your audio recording to OpenAI's Whisper API, which converts it to text and returns the text to us.
An authorized admin can select OpenAI's GPT-5.6 for companion chat. OpenAI can also be used as a disaster fallback when Anthropic cannot complete an AI request. For a companion reply, OpenAI receives the conversation and relevant context needed to generate it. That context can include map items, life-log entries, or past-conversation excerpts that Explore retrieved.
The same fallback can be used for background AI work, including extracting structured information from a transcript, generating or updating your map, categorizing capture text, generating a session title, and creating narrative or loop summaries. OpenAI receives the input supplied for the particular task. Depending on the task, that can include a full conversation transcript or an excerpt, capture text, map or session context, retrieved history, or existing AI-generated notes.
Under OpenAI's default API data-use terms, OpenAI states that it does not use data submitted through its API to train its models unless the customer opts in. Under its default retention controls, OpenAI may retain abuse-monitoring logs for up to 30 days. Eligible API customers may use Zero Data Retention or modified-retention controls, while legal requirements or a legal hold can require data to be kept longer. We do not store the audio recording ourselves once we have the transcript. For OpenAI's current API data practices, see OpenAI's own policies.
Meaning matching and guidance retrieval (Cohere).
Floatback uses Cohere's embeddings API to recognize related material. To build and refresh the meaning-search index, the app sends bounded text from map entities and life-log entries. To keep your map from filling up with near-duplicates, it can also send short map-item labels or descriptions.
When you use meaning search, or Explore searches your map to remember something, the app sends the query used for that search to Cohere. On ordinary Explore turns, the app can also send a bounded excerpt made from up to three recent messages you wrote so it can find relevant guidance from Floatback's library. That recent-message excerpt is capped at 2,048 characters and does not include the companion's replies.
Cohere returns numerical embeddings that let Floatback compare meaning. Floatback does not send full conversation histories to Cohere in these requests, and the current guided-session flow does not send its transcript to Cohere. The bounded map, life-log, search, and recent-message text can still be sensitive. For Cohere's data-use and retention practices, see Cohere's own policy.
7. AI-generated reflections, maps, and summaries
The companion generates reflections, observations, belief summaries, and a "map" of your themes. Who owns these is a genuinely nuanced question, and we want to be upfront about how we treat them:
- You own the content you share. Your messages, ratings, beliefs, and descriptions are yours.
- AI-generated content built from your inputs is treated as yours for the purposes of this policy. You can export it with the rest of your data, and deleting your account deletes it.
- Do not treat AI-generated content as authoritative. The companion can misread, overreach, or invent a reflection that doesn't fit. It is not a clinical assessment, and the map is not a diagnosis. You are always the authority on your own experience. We encourage you to keep what resonates and ignore what doesn't.
- We retain a non-exclusive, internal license to use anonymous, aggregated usage information (e.g. "how often users complete a session") to improve the product. We do not use your conversation content, ratings, or map to train or fine-tune AI models.
8. Vendors and who else sees your data
Running Floatback requires a small number of trusted third-party service providers. We only share what each vendor needs to perform its function:
- Supabase: database, authentication, and hosting for edge functions. Stores your account and your data.
- Anthropic: the Claude API, for generating companion responses and performing background AI work such as transcript extraction, map generation and updates, capture categorization, titles, and narrative or loop summaries. Receives the conversation content, map or session context, capture text, retrieved history, or AI-generated notes supplied for the task, as described in section 6.
- Stripe: payments, subscription management, and the customer billing portal. Receives your email address and a reference to your account so it can keep your subscription tied to you. Stripe also collects your payment method, billing address, and similar payment details directly from you at checkout; those go to Stripe, not to us.
- Resend: sends transactional emails from us (welcome messages, billing notifications, trial reminders). Receives your email address and the contents of the message we're sending you.
- OpenAI: voice transcription through Whisper, plus companion responses and background AI work through GPT-5.6 when selected by an authorized admin or used as the disaster fallback after Anthropic fails. Depending on the feature, receives your audio or the conversation, capture, map, session, retrieved-history, or AI-generated-note context supplied for the task, as described in section 6.
- Cohere: embedding-based meaning matching and guidance retrieval. Receives bounded text from map entities and life-log entries for indexing, short map-item text for duplicate matching, meaning-search queries, and bounded excerpts from recent user messages on ordinary Explore turns, as described in section 6.
- BetterStack: error and crash logging. Receives technical error reports (what broke, where, and your account ID), scrubbed of the free text you write, so we can find and fix bugs.
We do not sell your data, share it with advertisers or data brokers, or provide it to insurers, employers, family members, or anyone else without a legal obligation to do so.
9. Third-party links
The app and our website may link to other sites, for example, crisis hotlines, research articles, or external resources. We're not responsible for the privacy practices of those sites. A link from us is not an endorsement of how another site handles your data. Please check their policies before sharing anything with them.
10. Keeping your account secure
You can sign in to Floatback with a password or with a magic link we email to you. Either way, your account is only as secure as the credential that unlocks it, so please:
- If you use a password: don't share it, don't reuse it from other services, and consider a password manager.
- If you use a magic link: your email account is the key. Keep it protected with a strong, unique password and, ideally, two-factor authentication.
- On a shared or public device, sign out when you're done.
- We will never ask for your password, a magic-link code, or for you to forward a sign-in email. If you get a message claiming to be from us asking for any of those, treat it as phishing and don't respond.
- If you suspect someone else may have access to your account or your email, change your credentials and contact us.
No internet service can promise perfect security, but we apply industry-standard practices (encryption in transit and at rest, row-level isolation, and limited operator access) to protect your account and the data it contains.
11. Retention and deletion
By default we keep your data for as long as your account is active. You also have direct control over how long sessions stick around:
- Choose a retention window. From Settings, you can ask us to automatically delete guided-session data older than 30 days, older than 1 year, a custom number of days you set yourself, or keep it indefinitely (the default). A daily background job removes sessions that fall outside the window you've chosen.
- What the retention window deletes. Expired sessions and the conversation transcripts attached to them. The cross-session knowledge built up from your work (your threads, present triggers, memories, mood entries, mapping conversations, and your map) is intentionally preserved so the app stays useful between sessions. If you want all of that gone too, use "Delete Account."
- Delete a single session at any time from your session history, or delete your entire accountfrom the Settings page.
When you delete your account:
- Your profile, sessions, conversations, map, mood entries, ratings, feedback, AI-generated profile notes, email-delivery records, and your sign-in record (email and login history) are all removed from our live database.
- Backups containing your data may persist for a short period under our hosting provider's standard backup-rotation window before being overwritten.
- Anything that already left for an outside service as part of past use, whether Anthropic (companion or background AI payloads), OpenAI (voice, companion, or background AI payloads), or Cohere (map and life-log text, meaning-search queries, or bounded recent-message excerpts), is subject to that provider's own retention policy (see sections 6 and 8).
- The technical error reports held by our error-logging provider (BetterStack) contain only metadata and your account ID (never the text you write or your email) and age out automatically on a short retention schedule.
- If you have an active paid subscription, we cancel it at Stripe right away (you won't be billed again) and delete your customer record there, which removes your saved payment method from our processor. Past charge history is retained by Stripe under their own policies for tax and legal reasons.
If Wired Different Labs LLC is acquired or merges with another company, your data may transfer to the new entity as part of that transaction. If that happens, we will tell you, and the new entity will be bound by this policy (or one at least as protective) for the data they receive.
12. Disclosure required by law
In rare cases we may access, preserve, or disclose your information when we have a good-faith belief that doing so is necessary to:
- comply with a law, subpoena, court order, or other legal process;
- enforce our Terms of Service or this Privacy Policy;
- investigate or prevent fraud, abuse, or a security issue;
- protect the rights, safety, or property of you, us, or others.
Because of the sensitive nature of what people share with Floatback, we will push back on overly broad or improper requests and will only disclose what we're legally required to provide. Where the law permits, we will notify you before complying.
13. Your rights
- Access & export: download all your data as a JSON file from Settings.
- Deletion: delete an individual session from your session history, or your entire account from Settings.
- Correction: update your profile information at any time.
- Withdrawal of consent: you can stop using the app at any time. Signing out does not delete your data; deleting your account does.
- Email preferences: from Settings you can turn off our non-essential emails: account & welcome notes and occasional product nudges. Billing emails (a payment receipt, a failed-payment notice, or a cancellation confirmation) are always sent, because they're essential to keeping your account and subscription working.
If you are in the EU/UK, you have additional rights under GDPR/UK GDPR, including the right to restrict processing, to data portability, and to lodge a complaint with your local data protection authority. If you are a California resident, you have rights under the CCPA/CPRA, including the right to know what we collect and to request deletion. Contact us using the details in section 16 to exercise these rights.
14. If something goes wrong
We take reasonable technical and organizational measures to protect your data, but no system is perfectly secure. In the event of a data breach that affects your personal information:
- We will notify affected users without undue delay, by email and/or an in-app notice, and within 72 hours of becoming aware of the breach where that is practicable.
- Where required by law, we will notify the relevant supervisory authority (for example, a data protection authority under GDPR) within 72 hours of becoming aware of the breach, consistent with applicable statutory deadlines.
- Our notification will describe, to the extent we know it, what happened, what data was affected, what we are doing about it, and what you can do to protect yourself.
15. Children's privacy
Floatback is not intended for users under the age of 18. We do not knowingly collect data from minors. If you believe a minor has created an account, please contact us so we can remove it.
16. Changes to this policy, and how to contact us
We may update this privacy policy from time to time. When we make material changes, such as changes to what we collect, who we share it with, or how long we keep it, you will be asked to re-agree to the updated policy the next time you open the app.
If you have questions about this policy or how your data is handled, please use the feedback form in the app or email us at the address listed on our website.