Privacy Policy

Version 10 · Last Updated: August 29, 2026

Your privacy matters to us. This Privacy Policy explains what data ProgramU collects, how we use it, who we share it with, and the rights you have over your information. ProgramU is operated by ProgramU LLC, a Wyoming limited liability company. If you have questions, reach out at privacy@programu.app.

1. Who This Policy Applies To

This Privacy Policy applies to all users of the ProgramU mobile application (available on iOS and Android) and the ProgramU website at programu.app. It applies whether you are a current subscriber, a free-tier user, a trial user, or just browsing our website. ProgramU is currently available to residents of the United States only. International expansion is on our roadmap, but at this time we do not knowingly serve users outside the United States. ProgramU is intended for adults 18 years of age and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with their information, please contact privacy@programu.app and we will delete it promptly.

2. Information We Collect

Account Data: • Your email address • Your display name • Your profile photo (if you choose to add one) • Your date of birth (used for age verification only) Identity and Intake Data: • ReflectU intake responses (your description of the life you want, identity vision, patterns to release, ways you want to feel, topics excluded, a chosen name for ReflectU) • BeingU 90-day program inputs (desire, vision, focus, pattern) Journal and Reflection Data: • Freeform Journal entries (available with or without a program), including whether an entry was written in response to a Kaion journal prompt and, if so, the prompt text • Daily Identity Check-Ins • 7PM Identity Reflection entries • Living Proof wins • BeingU journal entries • Long-form program reflections • Sleep practice records ReflectU Chat history and metadata: If you use ReflectU Chat (a conversational AI that reflects your own thoughts back to you to help you find clarity), we store: • The text of your messages and the assistant's responses, in conversation threads tied to your account • Thread metadata: timestamps, message counts, themes extracted by our summarizer, and rolling summaries used to keep the mirror coherent across turns • A snapshot of your recent ProgramU activity (last 7 days of journals/reflections, recent wins, recent sessions) refreshed every 24 hours per active thread, used to ground the assistant's reflection in what is actually happening for you We NEVER log message content to error-reporting tools (Sentry) or operational logs. Only metadata (thread id, message length, latency, token usage, filter triggers) is recorded for cost and safety analytics. ProgramU Time Capsule content: The text of letters you write to your future self, any photos you attach (up to 3 per letter), and the scheduled delivery date you choose. Letters are stored until their delivery date, at which point they are emailed to you at the address on your account. A delivered letter remains stored in your account until you seal a new one (which replaces it) or delete your account. CollectiveU Participation Data: If you join a CollectiveU group session, aggregate live participant counts are stored without user identifiers. Separately, your own account records that you played a CollectiveU session (a per-account play count and timestamp, live or replay) — the same kind of listening history described under Usage Data below. Other participants never see this, and it is never combined with the aggregate counts. Voice Recordings (Optional): If you opt into our Voice Clone feature, your voice sample is transmitted from your device to Inworld AI and is not stored on ProgramU servers. We retain only the resulting voice model identifier. See Section 4 for details. Usage Data: • Listening history and play counts • App activity timestamps (such as when you last opened the app) • Feature-usage counters (for example, which onboarding steps you complete or which home-screen actions you tap), stored as daily per-account counts • Generated session metadata • In-app preferences • Progress through the 90-day BeingU program Device Information: We collect app version and operating system platform (iOS, Android, or web) at consent time for audit purposes. We do NOT collect: device model, IP address, advertising identifiers, precise location, or device fingerprinting data. Subscription and payment information: When you subscribe to a paid tier, payment processing depends on the platform: • On iOS: Apple In-App Purchase (Apple handles your payment details; ProgramU receives only your subscription status and transaction identifier) • On Android: Google Play Billing (Google handles your payment details; ProgramU receives only your subscription status and transaction identifier) • On the web app: Stripe (Stripe handles your payment details — credit card, debit card, Apple Pay, Google Pay, or other supported methods; ProgramU receives only your subscription status, transaction identifier, and the email address associated with the transaction) For iOS and Android subscriptions, your subscription state is also mirrored to RevenueCat for unified entitlement management. RevenueCat receives your user ID and subscription state; it does not receive your payment card details. Web app subscriptions purchased through Stripe are NOT routed through RevenueCat — ProgramU records your entitlement directly from Stripe.

3. Third-Party Services (Sub-Processors)

We use the following third-party sub-processors to operate ProgramU. Each processes only the data necessary for its function: • Firebase (Google Cloud): Authentication, Firestore database, Cloud Functions, Cloud Run, Firebase Storage, Cloud Logging. Stores your account data, journal entries, session metadata, voice clone identifiers, generated session scripts, and operational telemetry. Data is encrypted at rest (AES-256, Google-managed keys) and in transit (TLS). Region: us-central1. • Cloudflare R2: Object storage for generated session audio files (.mp3). Files are stored at user-scoped paths and encrypted at rest with provider-managed keys. Audio files are served via Cloudflare's public CDN URLs. • Anthropic: AI text generation for session scripts, BeingU phase content, refined focus, suggested resources, and ReflectU post-call summaries. For session/script generation, Anthropic receives the system prompt, your relevant intake context, and your focus text on each request. For ReflectU summaries, Anthropic receives the transcript of a completed ReflectU conversation so it can generate the short summary, themes, and energy reading saved with that call. Anthropic does NOT power ReflectU's live voice or text conversation (see the Google and Inworld entries below). Anthropic does not train on our API traffic — we have not opted into training usage and have confirmed this is the default for our enterprise API access. Per Anthropic's enterprise API terms, request/response data may be retained for up to 30 days for abuse-detection purposes unless otherwise contracted. • Google (Google AI Studio / Gemini): AI text generation that powers ReflectU's live conversational responses (both voice and text). For each turn of a ReflectU conversation, Google's Gemini model receives the persona instructions, your conversation history, and your message (your transcribed speech, in voice mode) so it can generate ReflectU's reply. Requests reach Google through Inworld's routing infrastructure (see the Inworld entry). Google processes this data per its API terms; we do not use this data to train any model. • Inworld: ReflectU speech-to-text (STT), text-to-speech (TTS), and AI model routing, plus voice synthesis for generated sessions. For generated sessions, Inworld receives the session script text and the voice ID to synthesize. For ReflectU live voice conversations, Inworld transcribes your spoken audio (STT), routes the conversation to an AI model for the response, and synthesizes the reply back into speech (TTS). Inworld acts as a ROUTER for the conversational AI step: ProgramU's preference is Google's Gemini model, but if that model is unavailable or fails, Inworld's routing infrastructure may automatically route the request to a comparable third-party AI model or provider, which is outside ProgramU's direct control. If you create a voice clone, your voice sample is transmitted directly to Inworld to generate your voice model; we do not store the raw recording on our servers (see §4 for voice clone details). Inworld processes only what is needed to transcribe, route, generate, and synthesize your audio. • Apple App Store and Google Play Store: In-app purchase processing for iOS and Android subscriptions, respectively. Each handles your payment details per their own privacy policies and terms. • Stripe: Payment processing for web app subscriptions. Stripe handles your payment card details, transaction processing, and receipt delivery. Stripe receives your email address and a user identifier to associate the transaction with your ProgramU account. Stripe's privacy policy and PCI compliance govern your payment data on their systems. • RevenueCat: Unified subscription entitlement management for iOS and Android subscriptions only. Receives your user ID, platform (iOS/Android), subscription tier, plan duration, and transaction identifier. Does not receive your payment card details. Web app subscriptions are not processed through RevenueCat. • Apple Sign-In and Google Sign-In: Optional authentication providers. Used only if you choose to sign in via Apple or Google instead of email/password. Each provider processes your authentication credentials per their own privacy policies. • Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM): Push notification delivery for iOS and Android, respectively. Receive your device push token and the notification payload to deliver notifications to your device. • Expo Push Service: ProgramU's push notification orchestration layer. When the server schedules a notification (e.g., BeingU phase ready, CollectiveU session start), the notification payload and your Expo push token are sent to Expo's push service, which forwards to APNs or FCM for delivery to your device. Notification content does not include sensitive personal data such as journal text or session content. • Resend: Transactional email delivery. Sends account-related emails (verification, password reset, account deletion confirmation, ProgramU Time Capsule letter delivery on scheduled dates). Receives your email address and the email content at the time of send. • Sentry: Error and crash reporting. Receives your user ID, application stack traces, and operational breadcrumbs. Personal content (journal entries, intake answers, session focus, voice data) is filtered out of error reports before transmission. Sentry retains reports per its default retention policy (~90 days). • PostHog (ProgramU website and web app only): Product analytics and session replay for the web experience — page views, feature-usage events, and session recordings to help us understand and improve the website and web app. Limited to United States visitors; PostHog is not loaded and no session recording occurs for visitors in the EU or UK. PostHog does not receive your journal entries, session content, voice data, or payment details. The ProgramU mobile apps use no analytics SDK. • Vercel Analytics and Speed Insights (ProgramU website only): Privacy-friendly, aggregate web traffic and performance metrics. Collects anonymized page-view and performance data to monitor site health; does not use cross-site tracking cookies and does not identify individual users. What we do NOT send to sub-processors: • We do NOT send your email address, display name, payment card details, or device identifiers to Anthropic, Google, Inworld, or Sentry beyond what is described above. • Voice clone records at Inworld are tagged with an opaque random handle, not your account identifier. • We do NOT use any third-party advertising networks or behavioral advertising pixels. The ProgramU mobile apps use no analytics SDKs; the ProgramU website uses first-party product analytics (PostHog, Vercel Analytics) limited to United States visitors, as described above — never to track you across other companies' apps or websites.

4. Biometric and Sensitive Data

ProgramU offers an optional Voice Clone feature that creates a personalized text-to-speech voice for your sessions. We treat your voice as biometric data subject to heightened protection. Voice Clone Data Handling. If you choose to create a voice clone (available with Full Access), here is exactly how your voice sample is handled: 1. You record a short voice sample directly in the ProgramU app or web app. 2. The sample is transmitted directly from your device to Inworld AI to create your voice model. The transmission is encrypted in transit via TLS. 3. We do NOT store your raw voice recording on ProgramU servers at any point. The recording exists in transit only — never written to Firebase Storage, never persisted in any ProgramU database. 4. Inworld generates your voice model from the sample and returns a voice model identifier. Only the model identifier is stored in your ProgramU account (under your user profile in Firestore). 5. Your voice model lives at Inworld. Inworld stores it under an opaque random handle that contains no link to your ProgramU account identifier. 6. Subsequent session synthesis uses your voice model identifier to request audio from Inworld for that session's script. The voice model itself never leaves Inworld. Your Biometric Consent: Voice Clone is strictly opt-in. Before any recording occurs, ProgramU presents a dedicated biometric consent screen that provides: • Explicit, informed, unambiguous consent — you must affirmatively agree before we record. We do not infer consent from continued app usage, default-on settings, or pre-checked boxes. • Specific purpose disclosure — we tell you exactly what your voice will be used for. • Storage and retention disclosure — exactly what is stored where, and what triggers deletion. • Right to withdraw — you can withdraw consent any time by deleting your voice clone. • Risk disclosure — we disclose that synthetic voice generation has inherent risks, including the theoretical possibility of misuse if your voice model were compromised. Your consent is recorded with a timestamp, the consent version, and the platform you signed up from. Right to withdraw voice clone consent: You can delete your voice clone at any time from Profile → My Voice Clone. This permanently removes the voice model from Inworld and clears the model identifier from your ProgramU account. Existing audio files generated with the voice clone before deletion remain in your account unless you separately delete them. You may also revoke consent by deleting your account or by emailing privacy@programu.app.

5. How AI Data Processing Works

When you generate a session: 1. Your session topic and relevant intake context leave your device and are sent to Anthropic Claude for script generation. 2. The generated script is sent to Inworld AI for voice synthesis. 3. The final MP3 audio is uploaded to Cloudflare R2 and linked to your account. AI training and your data: • Anthropic (session script text generation, and ReflectU post-call summaries): Anthropic does not train on ProgramU's API traffic. We have not opted into training usage, and Anthropic's enterprise API defaults exclude our traffic from training datasets. • Google (Gemini — ReflectU live conversational responses): Google processes your ReflectU conversation turns to generate ReflectU's replies. We do not use this data to train any model, and we process it under Google's API terms. See Section 14 for the full ReflectU data flow, including how Inworld's routing may fall back to a comparable model if Gemini is unavailable. • Inworld (ReflectU speech-to-text, text-to-speech, AI routing, and session voice synthesis): Inworld processes your voice sample, session scripts, spoken audio, and conversation text to perform transcription, routing, and synthesis tasks. Inworld's product policy governs whether and how it may use this data for service improvement. We have requested that Inworld not use our customer data for model training; you may contact privacy@programu.app for the most current status of this arrangement. • We never use your journal entries, intake answers, session focus text, voice recordings, ReflectU conversations, or any other personal content to train any AI model that we or any third party operates. AI-generated content can contain errors or imperfections. ProgramU filters block obvious safety issues, but AI is not perfect. Use your own judgment when applying any session to your life.

6. How We Use Your Information

We use your information to: • Provide the core ProgramU service (generate your sessions, sync your library, deliver your subscription) • Personalize your experience (tailor session content to your identity vision) • Process payments (via Apple, Google, Stripe, and RevenueCat) • Send transactional emails (account verification, account deletion confirmation, ProgramU Time Capsule letter delivery, etc.) • Catch and diagnose errors (via Sentry) • Comply with legal obligations • Detect and prevent fraud or abuse of the service We do NOT use your information to: • Show you ads or sell ad space • Train AI models • Sell, rent, or trade your personal data to anyone • Build profiles of you for advertising • Track you across apps or websites Your responsibility when using ProgramU sessions: ProgramU sessions — including subliminal, meditation, hypnosis, EFT tapping, BeingU programs, ReflectU sessions, and CollectiveU sessions — are designed to produce states of relaxation, focus, identity-level reflection, suggestibility, and (in the case of hypnosis sessions) trance. These states can affect your alertness, attention, and awareness. You agree to use ProgramU sessions only in environments where altered states of attention will not endanger you or others. Specifically: • Do not listen to ProgramU sessions while driving, operating machinery, exercising in any environment requiring full attention, or performing any task that requires alertness. • Hypnosis sessions induce a trance-like state. Use only when seated or lying down in a safe environment. • Sleep hypnosis sessions are designed to guide you into sleep and do not include an awakening sequence. Use only when you are ready to sleep. • You are responsible for choosing when and where to engage with sessions. ProgramU is not liable for any consequence resulting from your use of sessions in inappropriate contexts. By using ProgramU, you acknowledge that you have read, understood, and accepted this responsibility. AI-generated content: All ProgramU sessions, BeingU phase content, ReflectU outputs, and refined focus text are AI-generated. AI systems can produce errors, unintended outputs, and content that may not perfectly match your input. ProgramU continuously refines its AI models, prompts, and safety filters — content generated today may differ from content generated tomorrow as the system improves. You acknowledge that AI-generated content is inherent to the service and not a defect. Use your judgment. If a session, paragraph, or AI output does not feel right for you, skip it and try a different one. Your judgment is the final filter on any AI output. Legal disclosures: we may disclose information where required by law or legal process; to enforce our Terms of Service; to respond to a payment dispute with records of the subscription and acceptance; or to protect the rights, property, or safety of ProgramU LLC, our users, or the public.

7. Data Security

Your data is stored using Google Firebase and Cloudflare R2, both of which employ industry-standard security practices, including: • TLS encryption for all data transmitted between your device and our servers • AES-256 encryption for data stored at rest • Firebase Security Rules that restrict access to authenticated users and authorized system processes We minimize logging of personal content and scrub sensitive data from error reports before they leave your device. No system is perfectly secure, and we cannot guarantee absolute security. But we apply modern best practices and continuously work to improve our safeguards.

8. Your Rights

Access and Correction: • Update your profile information at any time within the app • Request a copy of your personal data by emailing privacy@programu.app Deletion: You can permanently delete your account and all associated data at any time: • In the app: Profile → Privacy & Security → Delete Account • By email: privacy@programu.app Account deletion permanently wipes: • All journal entries, intake responses, and session history • Your voice clone model (deleted from Inworld AI) • Your generated audio files on Cloudflare R2 • Your RevenueCat subscriber record • Your Firebase Auth account • Your user root document and all subcollections Most deletion processes complete within 24 hours. In rare cases, full deletion may take up to 30 days. Data Portability: Upon request to privacy@programu.app, we will provide a copy of your personal data in a portable, machine-readable format. Right to Object: You have the right to object to certain processing activities. Contact privacy@programu.app to exercise this right.

9. Data Retention

How Long We Keep Your Data: Your data is retained for as long as your account remains active. We do not have automatic scheduled deletion of inactive accounts — your data remains accessible to you until you delete your account or contact us to do so. What Gets Deleted When You Delete Your Account: • Firebase Auth account → deleted • Firestore user document and all subcollections → deleted • Firebase Storage files under your user path → deleted • Cloudflare R2 generated audio files → deleted • Inworld AI voice model → deleted • RevenueCat subscriber record → deleted After account deletion, data may persist briefly at the following sub-processors, governed by their own retention policies: • Firestore automatic backups (managed by Google Cloud): up to 35 days • Firestore Point-In-Time Recovery (PITR): 7-day rolling window for disaster recovery • Firebase Cloud Functions logs (server-side operational logs): ~30 days, retained by Google Cloud Logging • Cloud Run worker logs (BeingU generation): ~30 days, retained by Google Cloud Logging • Cloudflare R2 audit logs: per Cloudflare's default retention policy • RevenueCat historical purchase records: retained per payment processor compliance requirements (typically 7 years for tax and audit compliance) • Stripe historical transaction records: retained per payment processor compliance requirements (typically 7 years for tax and audit compliance) • Apple App Store and Google Play Store: transaction history is retained at the Apple ID or Google Account level, governed by Apple's and Google's privacy policies • Resend transactional email send history: typically 30 days to 1 year per Resend's platform retention • Sentry error reports: tied to your account UID at the time of error; retained per Sentry's default policy (~90 days). Sentry error reports are NOT retroactively deleted when your ProgramU account is deleted. • Inworld voice model: deleted from Inworld when you delete your voice clone or your account • Anthropic API request/response data: per Anthropic's enterprise API terms, up to ~30 days for abuse-detection purposes ReflectU Chat retention: • Conversation threads are retained indefinitely while your account is active. You can review, switch between, or implicitly archive past threads via the chat interface. • When you delete your account, all ReflectU Chat threads and messages are wiped from ProgramU within minutes (subject to the sub-processor timelines above). • Per-thread analytics records (metadata only — never message content) are kept under analytics/reflectuChat for cost and safety analysis; they are tied to a one-way hash of your user id, not to your account record. ProgramU itself wipes your account data (Firestore, Firebase Storage, R2) at the time of deletion request, typically within minutes. Sub-processor retention timelines above are outside ProgramU's direct control but are disclosed for transparency. None of this retained data is used to contact you or re-identify you after deletion.

10. Children's Privacy

ProgramU is intended for adults 18 years of age and older. We verify age at onboarding via a date-of-birth gate. ProgramU LLC does not knowingly collect personal information from anyone under 18. If we become aware that we have collected personal data from a person under 18, we will delete that information immediately. If you are a parent or guardian who believes we have collected data from a minor, please contact privacy@programu.app.

11. Geographic Availability

ProgramU LLC is organized in the State of Wyoming, United States. ProgramU is currently available only to residents of the United States. Our servers and sub-processors are based in the United States, and our crisis resources, customer support, and legal protections are designed for U.S. users. We do not knowingly serve users outside the United States. The App Store and Google Play listings restrict ProgramU's availability to the U.S. region. If you access ProgramU from outside the United States, your access may be restricted, and we cannot guarantee compliance with the privacy laws of your country. International expansion to additional countries is on our future roadmap. When we expand to a new region, we will update this Privacy Policy to address the privacy laws of that region. Until then, our compliance and disclosures focus on U.S. federal and state privacy law.

12. California and Other State Residents

Residents of certain U.S. states have additional rights under applicable privacy laws, including: • The right to know what personal information we collect • The right to delete personal information • The right to correct inaccurate personal information • The right to opt out of the sale or sharing of personal information (ProgramU does not sell or share personal information) • The right to limit the use of sensitive personal information • The right to non-discrimination for exercising your privacy rights To exercise any of these rights, email privacy@programu.app with your request. We will respond within the timeframe required by applicable law (typically 45 days). ProgramU LLC does not sell or share personal information for cross-context behavioral advertising.

13. Changes to This Policy

ProgramU LLC may revise this Privacy Policy from time to time. When we make material changes, we will: 1. Post the updated policy on programu.app/privacy-policy.html with a new "Last Updated" date 2. Notify you within the app 3. Require you to review and accept the updated policy before continuing to use ProgramU For minor changes (such as typo fixes or formatting updates), we may update the policy without requiring re-acceptance. The current version of this policy is always the version posted at programu.app/privacy-policy.html.

14. ReflectU AI Conversations (Voice and Text) — Data Flow

ReflectU offers an AI-powered conversation experience, in both voice and text; its persona is named Kaion. This section describes the specific data handling for ReflectU conversations, beyond what is covered in Section 3 (Third-Party Services). The conversational AI behind ReflectU: ReflectU's live conversational responses — for both voice and text — are generated by Google's Gemini model (gemini-2.5-flash), reached through Inworld's routing infrastructure. ProgramU's preference is Gemini; however, because Inworld acts as a ROUTER, if Gemini is unavailable or fails, Inworld's routing infrastructure may automatically route the request to a comparable third-party AI model or provider, which is outside ProgramU's direct control. Anthropic's Claude does NOT power the live ReflectU conversation; Anthropic is used only to generate the short summary, themes, and energy reading saved after a conversation ends (see Section 3). Live voice data flow: When you start a ReflectU voice session, the data flows like this, in real time: 1. Your spoken audio is transmitted to Inworld and transcribed to text (speech-to-text / STT). 2. The transcribed text, along with the persona instructions and conversation history, is sent — via Inworld's router — to Google's Gemini (or, on fallback, a comparable model) to generate ReflectU's reply. 3. The reply text is synthesized back into speech by Inworld (text-to-speech / TTS) and played to you. In text mode, the same Gemini-via-Inworld step generates the reply; the STT and TTS steps do not apply. What Kaion can see about your ProgramU life: When your personalization master toggle is ON, each conversation may include context from your account so Kaion's guidance is grounded in your actual work: your identity intake, your 90-day program status, recent session titles, and your most recent freeform Journal entries (including which of his prompts an entry answered). Turning personalization OFF excludes this personal context (the EducateU article catalog, which is not personal data, may still be included). Journal content shared this way is used only to generate the conversation and is governed by the same provider terms as the rest of the conversation. Your voice and the data flow: Your live-call voice audio is transmitted to Inworld solely so it can be transcribed for the conversation. It is NOT used to create a voiceprint, NOT used to train any model, and is NOT retained by ProgramU — raw call audio exists in transit only between your device and Inworld and is never written to ProgramU servers. (The optional Voice Clone feature, which is a separate opt-in, is governed by Section 4 — Biometric and Sensitive Data.) Google, Inworld, and any fallback provider may process and retain conversation data per their own privacy policies (for Inworld, inworld.ai/privacy). Zero Data Retention status: ProgramU does not currently have a Zero Data Retention (ZDR) agreement with Inworld. This means Inworld — and the AI model provider it routes to (Google, or a comparable fallback provider) — may retain conversation data for some period per their default platform retention policies. ZDR is offered by Inworld only on higher service tiers; we intend to adopt it as we scale, but it is not in place today. You may contact privacy@programu.app for the most current status. Treat all ReflectU conversation content (voice and text) as data that is processed by third parties under Inworld's and the routed model provider's terms. Voice transcript storage in ProgramU: After each ReflectU voice conversation ends, a transcript of the conversation (the text of what was said by both you and the AI) is stored in your ProgramU account under users/{your-uid}/reflectuCalls/{callId}/transcript. This is so you can revisit conversations via the in-app history view. Transcripts include: • The role (user / assistant) of each turn • The text content of each turn • Timestamps and call duration • A short summary, themes, and energy reading generated by our summarizer for each call Deletion: Voice call transcripts are deleted when you delete your ProgramU account (see Section 8 — Your Rights). Per-conversation deletion within an active account is on our roadmap for a future release; for now, the only way to remove a single transcript is to delete your account or contact privacy@programu.app. What is NOT stored: • Raw audio recordings of the conversation are not stored on ProgramU servers. Audio exists in transit only between your device and Inworld AI. • Your voice clone (a separate optional feature) is governed by Section 4 — Biometric and Sensitive Data. Consent flow: Before your first ReflectU voice conversation, ProgramU presents a one-time disclaimer modal explaining the AI nature of the experience and how to access crisis resources. Tapping "I understand — start the call" records your consent (timestamp + version) at users/{your-uid}/preferences/reflectuCall. Subsequent voice calls do not require re-consenting unless the disclaimer version changes.

15. Contact Us

For privacy questions, data requests, or to exercise your rights: • Privacy questions: privacy@programu.app • Data requests: privacy@programu.app • Safety concerns: support@programu.app • General support: support@programu.app Mailing address: ProgramU LLC 30 N Gould St Ste N Sheridan, WY 82801 United States Thanks for trusting us with your work. We take that trust seriously. — The ProgramU Team

By continuing to use ProgramU, you acknowledge that you have read and understood this Privacy Policy.