A Stoic philosophy companion
Last updated: September 8, 2026
This privacy policy describes how the Ataraxia mobile application (“Ataraxia”, “the app”, “we”) handles your information.
Ataraxia collects anonymous product analytics so we can tell which passages actually help people and which do not. This is on by default and can be switched off at any time under Settings → Data → “Anonymous usage”, which stops collection immediately.
This changed in version 1.2.2 (September 2026). Analytics used to be off unless you switched it on. Almost nobody found the setting, which left us unable to tell which passages were worth keeping. So the default was reversed, and it was turned on for existing installs — except where someone had already switched it off, which we left alone. Anyone whose setting we changed is told so in the app, with the setting one tap away.
While it is on:
If you purchase Inner Citadel, the subscription:
We run adverts (Apple Search Ads, Google Ads) and publish tagged links on social platforms. To know which of those are worth paying for, the app records which campaign led to your install, stored against the same anonymous app-user id described above.
apple_search_ads or organic_tiktok), not a profile of you. It is written once, at install, and never changed afterwards.The following is saved only on your device using standard secure storage provided by your operating system (iOS keychain / Android encrypted preferences). We never see or transmit it:
If you uninstall the app, this data is deleted. If your operating system creates a device backup (e.g., iCloud Backup, Google Drive backup), that backup belongs to Apple or Google — not to us — and is governed by their respective privacy policies.
Ataraxia includes optional features that send specific data to third-party AI services only when you actively trigger them. We do not send anything in the background.
How these requests are routed. These requests pass through our own proxy server (hosted on Expo’s EAS Hosting) before reaching the AI provider. The proxy exists so our API credentials are never shipped inside the app; it is a stateless relay that forwards your request to the provider and returns the response. It does not store your audio, your text, or any profile of you.
When you record audio using the in-app microphone, your recorded audio is sent — via our proxy — to OpenAI’s transcription API (“Whisper”) and the transcribed text is returned. The audio is not stored by us or by the proxy. Per OpenAI’s published policy, audio submitted via API is not used to train their models and is retained only briefly for abuse monitoring. https://openai.com/policies/privacy-policy
When you tap play to hear a passage read aloud, the text of that passage is sent — via our proxy — to OpenAI’s text-to-speech API, which returns audio that the app plays. The passage text is transient and is not stored by us or by the proxy. The same OpenAI policy applies. https://openai.com/policies/privacy-policy
When you complete a “What troubles you” reflection, the transcribed text of your reflection is sent — via our proxy — to Anthropic’s Claude API for emotion classification, which returns an emotion label. Per Anthropic’s published policy, API inputs are not used to train their models and are retained only as required for compliance and abuse monitoring. https://www.anthropic.com/legal/privacy
When you write or speak what troubles you and ask the Stoics for a reply, the words you wrote are sent — once, via our proxy — to Anthropic’s Claude API, together with a small set of passages from Ataraxia’s own catalogue for the reply to draw on. What comes back is the letter you read.
Three things are worth stating plainly:
You can use the whole app without ever writing a letter.
To keep the app stable, Ataraxia reports crashes and technical errors to Sentry, hosted in the EU. These reports contain only diagnostic technical data — the type of error, a stack trace, the app version, and the device model / OS version. They never include the text you write (reflections, journal entries) or any personal identifier. Crash reports are used solely to find and fix bugs. https://sentry.io/privacy/
| Service | Purpose | Privacy policy |
|---|---|---|
| Apple App Store / TestFlight | iOS distribution + payments | https://www.apple.com/legal/privacy/ |
| Google Play | Android distribution + payments | https://policies.google.com/privacy |
| RevenueCat | Subscription management + install attribution (anonymous app-user id) | https://www.revenuecat.com/privacy |
| PostHog (EU) | Anonymous product analytics — on by default, switchable off in Settings | https://posthog.com/privacy |
| Sentry (EU) | Crash + error reporting (diagnostic data only, no text you write) | https://sentry.io/privacy/ |
| OpenAI | Voice transcription + audio readings (only when you trigger them) | https://openai.com/policies/privacy-policy |
| Anthropic | Emotion classification, and letters from a Stoic (only when you ask for one) | https://www.anthropic.com/legal/privacy |
| Expo / EAS Update | Over-the-air JavaScript updates (no user data sent) | https://expo.dev/privacy |
| Expo / EAS Hosting | Hosts our stateless AI proxy that relays your triggered AI requests (stores no user data) | https://expo.dev/privacy |
Ataraxia is not directed at children under 13. We do not knowingly collect any data from children under 13.
If this policy changes, we will update the “Last updated” date at the top. Material changes (such as introducing a new third-party service) will be highlighted in the app’s release notes.
Questions about this privacy policy, or to request deletion of any data: