Privacy, in the present.
Effective July 7, 2026
This policy explains how now handles information when you use the app and its image-generation service.
Information on your device
Vision titles, statements, feelings, aligned actions, reflections, reminder settings, and generated images are stored locally on your device. Widget content is stored in the app's private shared container. now does not provide user accounts or server-side cross-device syncing. Deleting a vision removes that local vision and its reminders; deleting the app removes its local app data, subject to how your device and backups operate.
Image generation and Stability AI
When you request a visualization, now sends the scene prompt, an enhanced version of that prompt, and generation settings through our API to Stability AI. Stability AI processes that material to produce an image, and the generated image passes through our API to your device. Do not include information you do not want an external image provider to process.
Our API does not intentionally store prompts or generated image files after the request finishes. Stability AI's retention of prompts and outputs, and whether material may be used for service or model improvement, can depend on the provider product, current provider terms, and settings on our provider account. Those practices are controlled by Stability AI and can change. Review Stability AI's Privacy Policy and Terms of Use for its current description.
Data categories and purposes
| Category | Purpose | Our retention |
|---|---|---|
| Prompts, enhanced prompts, generation settings, and generated output | Fulfill the image request and return the result | Held in API memory only for the request; not intentionally persisted by our API |
| Random installation identifier | Enforce usage limits and calculate bounded-dataset analytics uniqueness and cohorts | The raw identifier is validated in request memory and is not placed in Redis; analytics records expire with their dataset, no later than 400 days after it starts |
| Network address | Abuse, burst, and monthly limit enforcement | The raw address is used in request memory and converted to an HMAC pseudonym before Redis storage |
| Allowlisted product events and milestone occurrence dates | Measure onboarding, activation, retention, feature use, and subscription conversion | Event, cohort, intersection, and uniqueness records: no later than the dataset reset, at most 400 days after the dataset starts; analytics rate-limit records: up to 1 hour |
| Optional creative source ID | Measure aggregate onboarding, activation, retention, paywall, and purchase outcomes by acquisition creative | The first valid source is retained with pseudonymous analytics state and aggregate counters until the dataset reset, at most 400 days after it starts |
| Generation-limit pseudonyms and counters | Enforce device and network quotas | Monthly counters expire at the start of the next UTC calendar month; burst counters expire after 60 seconds; in-flight counters expire after the provider timeout plus 15 seconds |
| Hosting and security metadata | Deliver, secure, and diagnose the API | Our application does not intentionally log prompts, images, installation identifiers, or network addresses. Vercel may process and retain platform request, function, and security logs under the hosting plan's current settings and terms; that platform-controlled period is not set by this API |
Pseudonymous identifiers
The installation identifier and network address are not placed in Redis keys in raw form. They are transformed with HMAC-SHA-256 and purpose-scoped secret keys held by the service. Analytics also applies an independently pseudonymized network limit so changing an installation identifier does not bypass all ingestion controls. These values reduce direct exposure but remain pseudonymous data, not guaranteed anonymous data.
Analytics
Analytics accepts only fixed event names such as onboarding started, first ritual completed, a D1/D7/D30 return, paywall viewed, or a purchase outcome. If the app was opened from one of our acquisition links, requests may also contain the link's compact creative source ID. The app saves only the first valid source and does not derive it from vision content. Activation and retention events also include the non-sensitive local calendar date when the milestone occurred, formatted as YYYY-MM-DD, so delayed delivery does not change the cohort. Activation, retention, and paywall conversion rates use server-recorded prerequisite intersections and age-eligible activation cohorts rather than dividing unrelated event totals. It does not include vision text, prompts, feelings, actions, notification content, generated images, product prices, Apple transaction identifiers, or raw device identifiers. Protected reports contain aggregate counts and rates, including aggregate creative breakdowns, never individual identifiers.
Notifications
Reminder scheduling uses Apple's local notification system. Personal vision text is hidden on the Lock Screen unless you explicitly enable it.
Sharing, advertising, and tracking
We do not sell personal data, serve targeted advertising, or use this service to track you across other companies' apps or websites. Information is disclosed to service providers needed to operate image generation, hosting, and abuse controls, including Stability AI, Vercel, and Upstash.
Your choices, withdrawal, and deletion
You can use core vision and ritual features without requesting an image and can disable notifications in the app or system settings. Where processing is based on consent, you may withdraw that consent for future processing by stopping the optional feature and contacting us. Withdrawal does not affect processing already completed.
To ask about access or deletion of server-side pseudonymous records, contact support@nowritual.com with the request and, if you choose, the installation identifier shown by the app and an approximate date range. We will use that information only to locate and handle the request. Some aggregate counts cannot be linked back to an installation and cannot be selectively removed. For information held independently by Stability AI or a hosting provider, we will assess and route a request where applicable. You can remove local content from within the app or by deleting the app.
Children
now is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Contact
Privacy and support requests can be sent to support@nowritual.com. You can also visit the support page.