Feelvu

Privacy Policy

Last updated: September 11, 2026

What changed on 6 September 2026. Three things worth reading if you were here before. Every company that receives anything is now listed by name, with what they get and where they are — there are seven, and only the database is in Seoul. There is a new section for people in the United States about consumer health data. And until that date the check-in event carried the feeling you had picked to Google Analytics; it no longer does, and if you want the record of it removed from Google’s side too, write to us and we will ask.

Feelvu is published by Geniart Bytelabs Pte. Ltd.. Feelvu helps you track emotional check-ins, journal reflections, and wellness patterns. Your emotional data belongs to you.

What We Collect

We may collect account information, emotional check-ins, selected context tags, journal entries, cloud progress, notification preferences, and app settings.

You can optionally add basic profile details — an age range and gender — in Settings. These are always optional, are never required to use Feelvu, and you can change or remove them at any time.

If you choose to connect CozyFlow, Feelvu may receive limited hormone and wellness context such as life stage, cycle phase when available, PMS window, context date, confidence level, and derived sleep, movement, food, stress, and body signals. Feelvu does not receive raw CozyFlow logs and does not require gender to enable this feature.

How We Use Data

We use your data to show your check-in history, emotional patterns, cloud growth, reminders, exports, and optional hormone-aware and body-rhythm wellness insights.

Feelvu is not a medical device and does not diagnose, treat, cure, or prevent any disease or medical condition.

CozyFlow Connection

CozyFlow connection is optional. We only use hormone and derived daily wellness context after you choose to connect CozyFlow. You can disconnect it at any time from your Feelvu settings.

When disconnected, Feelvu stops using CozyFlow context for future insights. You can export your Feelvu data from settings.

Sleep and Recovery From a Watch

If your phone holds health data from a watch or band, Feelvu can read sleep and recovery from it to fill in part of your check-in for you. That reading happens on your phone and stays in Feelvu unless you say otherwise.

Sending it on to another app is a separate choice, off unless you turn it on, and listed on its own in Settings rather than bundled with anything else. It is off even if you have already connected that app for something else. Turning it on sends a short reading — how long you slept, how broken it was, and whether your body looked recovered — and never the underlying measurements, timestamps, or anything a heart rate could be reconstructed from.

Turn it off and the sending stops. What was already sent lives in the app that received it, and that app has its own way to delete it.

Health readings are never sent to advertising, analytics, attribution, or session-replay services. Not in a reduced form, and not for measuring how Feelvu is doing.

People You Choose to Reach

Feelvu lets you name people you can reach when it is hard to say something out loud — to ask for a little space, or for a hand. Adding someone means giving us their email address so we can send them your request. Nothing is sent to anyone until you add them and they accept.

We send them as little as we can. A request tells them that you asked for them and where to open it. It does not carry your emotion, your journal, your notes, or anything about how you have been doing. Those stay behind your sign-in. Accepting your invite does not turn on any sharing from their side. That is a separate choice only they can make.

You can mute, block, or remove anyone at any time, and every request expires on its own. If someone added your email and you did not want that, ignore the message and nothing further is sent.

Team Workshops at Your Company

If your team runs a Feelvu workshop, your own check-ins and your emotion type stay private to you. Your employer never sees them.

That is how it is built, not only how we promise to behave. When you check in, your phone works out which of four working states to add to the team cloud and sends only that word. The feeling you picked and your type are never sent, so there is no record of them for anyone to ask us for later.

The only thing your team sees is an ask you wrote and chose to share — a sentence like “when a deadline changes, tell me what to stop doing first” — and you decide whether to share it at all, and can change or remove it afterwards.

The company gets a team-level read: which patterns came up, which asks were used, and one habit to try next. It contains no names, no individual check-ins, no scores, and no rankings. Where a team is smaller than five people, the breakdown is withheld entirely rather than shown in a way that would point at somebody.

A percentage also waits for enough people. If fewer than five have checked in, or fewer than half the team, the report shows the shape of the week instead of numbers — because at that point one person is most of the number, and a share that size is a name.

You can leave and take your asks with you. One button on the team page removes you and pulls every sentence you wrote off the board in the same step. Your past check-ins stay, because they are single words with no name attached and are already part of a report somebody read; they are deleted on the same schedule as everyone else’s.

Team data does not last forever. Your company picks how long check-ins and confirmations are kept when the space is opened — three months, six months, or thirteen months — and they are deleted after that. The asks the team wrote are the team’s own words and stay until the space is closed. The same page will show you everything the space holds about you, at any time.

The four working states in the report are our estimate of how a day like that tends to go at work. They are not a measurement of anyone, and the report says how often people agreed the wording matched their own day.

We do not read feelings out of your work. Nothing is inferred from chat, email, calendar or meeting recordings. Everything Feelvu knows is something a person chose and typed.

If you write to us about running a workshop, we keep your name, email and what you told us so we can reply. No account is created. Write to sooyeon@mycozyleaf.com to have it deleted.

Checking In at a Cafe or Shop

Some cafes and shops put a Feelvu code on a table or a counter. Scanning it opens a check-in that suggests something on their menu. You do not need an account and you are not asked for one.

The shop never receives your check-in. What you felt, the context tags you picked, and anything else about you are not sent to them and are not part of what we record about the visit. If you do not have an account, that check-in stays in your own browser — up to 120 of them, and clearing your browser data removes them. If you do have one, it is saved to your own history like any other check-in, and that is the only place it goes.

What we do record is which menu item was suggested, whether it was tapped, and which printed code it came from. If you were signed in, that record is linked to your account, so deleting your account deletes it too. If you were not, it is linked to a code this browser made up, and if you later create an account we attach those earlier visits to it — so that they can be deleted with everything else rather than staying behind under a name nobody can look up.

None of that record contains what you felt. A shop can ask us for a monthly summary of the counts. It contains no feelings, no identifiers, and no rows about individuals.

Show where you checked in is off until you turn it on, in Settings. Turned on, Feelvu shows the cafe or shop beside the check-ins you made by scanning their code, including ones from before you turned it on. It uses only which printed code was scanned — Feelvu never asks your phone for your location. Nothing about this is sent to the shop, and turning it off stops the place being shown. Nothing else in Feelvu uses where you were.

Advertising and Analytics

We do not sell your emotional, menstrual, reproductive health, or mental wellness data. We do not share health-related events with advertising platforms, and your journal entries are not used to train AI models. We may use service providers for hosting, authentication, security, notifications, account support, and core app operations.

Where AI Is Used

One feature sends text to an outside model: the card that helps with a stuck piece of work. When you write what you are stuck on, that sentence goes to a model provider, along with any names you typed in the “people” field, the planner tasks you attached, the deadline, and the one word you picked for how you feel. Nothing else in Feelvu does this.

Your check-ins, your journal, your body rhythm, your patterns and your history never go to a model. Neither does anything a workshop collects. The twelve feelings, the readings, the partner suggestions and the workshop clusters are worked out by rules on our own servers, and the stuck-work card is written by rules too — the model only rewrites the card the rules already produced, so with the model unavailable you get the same card.

We do not send your name, your email, or your account id. The providers we may route to are Google (Gemini), Groq and OpenRouter. If you would rather nothing was sent, do not use the stuck-work card — the rest of Feelvu is unaffected.

Analytics are not loaded until the age gate has passed. We do not use advertising identifiers, ad SDKs, or personalised advertising in Feelvu.

When you make an account we record one word for how you found Feelvu — for example “instagram”, “search”, or “direct”. We do not keep the link you arrived from, so what you searched for and which page you came from stay on your device. It is written once, it is never used to target anything at you, and deleting your account deletes it.

If you are in the United States

Several states now have their own law for what they call consumer health data, and it is written broadly enough to cover almost everything Feelvu holds: how you felt, what you wrote about it, anything about a cycle, and anything we work out from those. Washington’s My Health My Data Act is the strictest of them, so this section is written to it and applies to everyone.

We do not sell it. Not for money, not for anything else of value, and there is no version of Feelvu where that changes without you being asked first, separately, in words that say what is being asked.

We do not share it for advertising. No advertising identifiers, no ad SDKs, no audience matching. The companies listed above are the only ones that receive anything, and each entry says what.

What analytics receives, and does not. Feelvu uses Google Analytics for counts: which pages get opened, how many people finish a check-in, which export format is used. Until 6 September 2026 the check-in event also carried the feeling you had picked, which should never have left and no longer does. If you were using Feelvu before that date and want the record of it removed from Google’s side too, write to us and we will make the request.

Your rights here. You can ask what consumer health data we hold, get a copy of it, and have it deleted — including from anyone we passed it to. The copy and the deletion are both buttons in Settings; for anything else, write to the address at the bottom. We answer within thirty days and will say so if we need the one extension the law allows. If we ever refuse, you can appeal to the same address and we will explain in writing.

Nobody is required to agree to this to use Feelvu. Withdrawing a consent you gave for an optional feature does not switch off the rest of your account, and we do not price the app differently for it.

Health and Safety

Feelvu is for self-reflection and everyday wellness support. It is not a crisis service, medical service, or replacement for professional care. If you may harm yourself or others, or you are experiencing an emergency, contact local emergency services immediately.

Age Requirement

Feelvu is intended for users who are at least 14 years old. If the law where you live requires parent or guardian consent at an older age, you should use Feelvu only with that consent.

Children under 14 should not use this version of Feelvu on their own. If we learn that we collected personal data from someone under 14 without a parent-supported account flow, we will delete it unless we are legally required to retain limited records.

In South Korea, personal data from a child under 14 requires consent from a legal representative and a check that the consent was given. Someone under 14 cannot make an account on their own here; a parent or legal guardian makes it for them. They can give us a guardian’s email address, and nothing else about them is stored at that point — we hold only that address. The guardian receives the same wording you are reading and agrees at their own address. That tap is the consent, and only then are they asked for one thing: what the child is called. We create the account from that screen, with a generated identifier that cannot receive mail, and show a one-time link the guardian passes to the child. The child has no email address on the account and no password. If the guardian does nothing the request lapses within three days, the row holding their address is deleted, and no account exists. A guardian can withdraw at any time from the same link they were sent: it has a button that deletes the account and everything in it, and what is left is a dated record that consent was given and withdrawn, with their address removed from it.

Security, and who can read what

Two people have now asked the same two questions — is the text encrypted, and can anyone at Feelvu read it — and the old wording here answered neither. Plainly:

Everything travels over an encrypted connection, and what you write is encrypted again before it is stored. Your journal entries, the lines saved from them, your planner tasks, the notes on anything you send a friend, and the standing message you set up for a hard day are all held as ciphertext. Each account has its own key; messages between two people have a key belonging to the message, so both of you can read it. The keys are locked with a secret that is not in the database, so a copy of the database on its own opens nothing.

What is not encrypted is deliberate: the emotion you tapped, the day it was on, the category you picked from a list. Those are what patterns and reports are counted from, and they are not sentences you wrote.

The honest limit: this is not a key only you hold. We can still open your writing, because the app has to be able to — patterns, reports and your data export all read it. What the encryption stops is a leaked or stolen copy of the database, and it makes deleting your account mean more: the key is deleted with it, so even a backup taken before you left cannot be read afterwards.

Other Feelvu users cannot. Every table has row-level security switched on, and a row is readable only by the account that owns it. That is enforced by the database, not by the app asking politely.

A small number of us can. Running the service means somebody has to be able to reach the database to fix it and to answer you when you write in. We do not read entries outside of that, we do not sell them, and we do not use them for advertising.

If you would rather none of it left your phone, use Feelvu without an account. Guest check-ins stay in your browser and are not sent to us while you have no account. If you later make one in the same visit, the check-ins you made just before signing up come across to it; older ones stay put until you are asked and say yes.

No system is perfectly secure, so please use a strong password and contact us if you believe your account or data may be at risk.

Your Choices

You can choose not to use hormone-aware features, disconnect CozyFlow, export your data, and delete or request deletion of your account data from Feelvu settings or our account deletion page.

Deleting your account removes your check-ins, your written notes, your saved cards, your cloud and everything else you wrote, along with the body and training context other apps sent us and your login itself. Where your email address sits inside somebody else’s row — a message they sent you, a contact list you appear on, a conversation you were part of — the row stays with them and your address is replaced, because deleting it would take their side of the conversation with it. Nothing that identifies you is left behind.

If account deletion is temporarily unavailable in the app, email us and we will process the request manually after verifying account ownership.

Where your data is kept

Feelvu runs on Supabase, and the database is in Seoul, South Korea (AWS ap-northeast-2). If you use Feelvu from Singapore, the EU, or anywhere else, your data is transferred there and held there. We chose one region rather than several so there is one honest answer to this question.

Two things leave that database. Email goes through Resend so that a message can reach your inbox. And the execution rescue feature, and only that feature, sends the words you typed to a language model provider to rewrite a card that was already written by our own rules; nothing you write in your journal, your check-ins, or the message reader is sent to any model.

Everyone who receives anything, and where they are. The database is the only thing in Seoul. Every company below is outside South Korea, which means using Feelvu involves sending data across a border — so here is the whole list rather than a category.

Supabase

Seoul, South Korea

everything you save: your check-ins, what you wrote with them, your account. This is the database itself.

Vercel

the United States, with edge locations worldwide

the request for every page. It serves the app and sees the ordinary things a web server sees — which page, from roughly where, on what browser.

Sentry

the United States

an error when something breaks, with a scrubber in front of it so the text you wrote is not in the report.

Resend

the United States

an email address and the message being sent to it, when Feelvu has to reach an inbox.

Google Analytics

the United States

which pages were opened and a handful of counts — how many things were taken on, which export format, how long a streak ran. Never a feeling, a note, or anything you typed.

Google (Gemini), Groq, OpenRouter

the United States

only what the stuck-work card sends: the sentence about what you are stuck on, names in the people field, the tasks you attached, the deadline, and the one word for how you feel.

Google (sign-in, Calendar, Drive, Gmail drafts)

the United States

nothing unless you connect it. Then: your sign-in, calendar titles and times if you connected Calendar, files the app itself made if you connected Drive, and a draft it writes for you to send yourself. Gmail is draft-only — Feelvu cannot read your mail.

Google Forms

the United States

what you type into one of our forms, if you fill one in. That is the feedback forms, and the beta sign-up, which asks for your email, country and device. It also learns that the feedback page was opened, because one form is shown inside it. Nothing from your check-ins or your account goes with it.

If you would rather nothing went to a model provider, do not use the stuck-work card; the rest of Feelvu is unaffected. If you would rather nothing went anywhere at all, use Feelvu without an account.

How long we keep it

Some things delete themselves. A mood share ends the night you sent it. A support request lasts six hours if you marked it urgent and twenty-four otherwise. A care message lasts three days. Those are not settings; they are how the features work.

Everything else, your check-ins and what you wrote with them, is kept until you delete your account, because the whole point of it is to still be there in three months when you want to see a pattern. Deleting your account deletes it, and deletes the key that opens it, which is what makes a backup taken beforehand unreadable too.

Your rights, and how to use them

You can get a copy of everything held about you from Settings, Export data. It downloads as one file and names anything that could not be read rather than leaving it out. You can correct what you told us from the same screen. You can delete the account, and everything in it, from Settings or from our account deletion page.

Where you gave consent for something optional, hormone-aware features, notifications, a CozyFlow connection, showing where you checked in, you can withdraw it in Settings without losing the rest of your account. Withdrawing stops future use; it does not undo what was already shown to you.

If you are in the EU or the UK, we handle your data to provide a service you asked for and, for the optional parts above, on the consent you gave. If you are in Singapore, the same applies under the Personal Data Protection Act. If you think we have got something wrong, write to us first at the address below; you can also complain to your data protection authority, which in Singapore is the Personal Data Protection Commission and in the EU is the authority for the country you live in.

Legal Requests and Breach Notices

We will respond to lawful requests and required privacy, security, or health data notices according to applicable law.

Contact, and who is responsible

One person is responsible for this, and answers these questions themselves. Access, correction, deletion, withdrawal, or a complaint, all of it goes to geniartbytelabs@gmail.com. We aim to answer within thirty days, which is the longest either the PDPA or the GDPR allows, and usually much sooner.