Voyage

Privacy Policy

Effective Date: April 28, 2026
Last Updated: April 28, 2026
Operator: Voyage Labs  ·  [email protected]

1 — Who We Are

Voyage Labs operates Voyage ("the App"), a self-encounter iOS application. Our product is built on one principle: the only person who should understand you better from using Voyage is you.

We are not an advertising platform. We do not monetize your data. We do not build behavioral profiles to sell.

2 — What We Collect

Account Information

Conversation and Reflection Data

Voyage does not provide advice, diagnoses, or suggestions. Everything surfaced in the app originates solely from what you have shared.

Usage Data

Device Data

We do not collect: precise location, contacts, photos, or camera access, biometric data, or financial information.

3 — How We Use Your Data

PurposeData Used
Deliver Compass responsesConversation history, past memories, your profile
Extract and store memoriesCompass conversation content
Generate Kaleidoscope narrativesYour stored memories and patterns
Personalize depth and contextStored memories, patterns, realm activity
Maintain your accountAuthentication identifiers, account metadata
Improve app stabilityAnonymized crash reports, usage analytics

We do not use your reflection content for advertising, marketing segmentation, or model training without your explicit opt-in.

Beta Testing — Internal Quality Review

During the current beta period, a small number of session transcripts may be reviewed by our team to evaluate and improve the quality of Compass's responses and memory extraction. This is done to make the product better — not for profiling, advertising, or any other purpose.

If you would prefer your sessions not be reviewed by our team, email [email protected] and we will exclude your account from manual review. Aggregate usage metrics (session count, extraction accuracy) will still be tracked, but your conversation content will not be read by any person on our team.

4 — How We Process Your Data

We believe you deserve to understand exactly what happens to your words.

At rest: All your data — memories, conversations, patterns, narratives — is encrypted at rest in our database (AES-256, managed by Supabase). We hold the encryption keys, not you. This is the same model used by Day One, Notion, and most privacy-respecting consumer apps.

In transit: All communication between the app and our servers uses TLS 1.3. No plaintext is ever transmitted over the network.

During processing: When you send a message to Compass or generate a Kaleidoscope, your content is briefly decrypted in server memory to process your request. This is transient — it is never logged, never written to disk, and clears when the request completes.

Honest statement: We technically have the ability to read your data to operate the product. We choose not to, and our infrastructure is designed to minimize that exposure. We do not log conversation content. We do not have employees reviewing your reflections — except as described in the beta clause above, with opt-out available.

5 — Third Parties We Share Data With

We share data with a small number of service providers necessary to operate Voyage. We do not sell your data to anyone.

Anthropic (Claude API)

Your Compass conversations and memory content are sent to Anthropic's Claude API to generate responses and extract memories. Anthropic processes this data under their own privacy policy: anthropic.com/privacy. Voyage operates under Anthropic's API usage policies, which prohibit using submitted data to train models without consent.

Supabase

Our database and backend infrastructure provider. Your data is stored in Supabase's infrastructure (AWS-backed, US region by default). Supabase manages encryption at rest and secure access controls.

Apple / Google

Used for authentication only. We receive a unique user identifier and, if provided by the platform, an email address for account recovery. We are passwordless — we do not receive or store any password from Apple, Google, or you directly.

We do not share your data with advertisers, data brokers, or analytics platforms that build cross-app profiles.

6 — Sensitive Data

Voyage is designed for deep personal reflection. Your conversations may contain sensitive information — mental health, relationships, family, career struggles, grief, or personal identity.

We treat all reflection content as sensitive by default. We apply the highest level of care in how it is stored, processed, and protected. We never use this content to infer health or psychological status for advertising or third-party profiling.

If you are in crisis or need immediate mental health support, please contact a qualified professional or emergency service. Voyage is not a clinical tool and is not a substitute for professional care.

7 — Age Requirement

Voyage is intended for users aged 18 and older. We require age verification during onboarding and do not knowingly permit users under 18 to create an account.

If you believe a user under 18 has created an account, contact us at [email protected] and we will delete the account and associated data promptly.

8 — Data Retention

Data TypeRetention
Active account dataRetained while your account is active
Memories and patternsRetained until you delete them or your account
Conversation historyRetained until you delete it or your account
Anonymized usage analyticsUp to 24 months
Account metadata30 days after account deletion (for fraud prevention)

When you delete your account, your personal reflection data — memories, conversations, patterns, narratives — is permanently deleted within 30 days. This cannot be undone.

9 — Your Rights

You have the right to:

To exercise any of these rights, email [email protected]. We will respond within 30 days.

10 — California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

To submit a CCPA request: [email protected]

11 — European Users (GDPR)

If you are located in the European Economic Area, UK, or Switzerland, you have rights under GDPR including the right to access, rectify, erase, restrict processing, data portability, and lodge a complaint with your local supervisory authority.

Our legal basis for processing:

Data transfers outside the EEA are covered by standard contractual clauses with our service providers.

12 — Security

We take reasonable technical and organizational measures to protect your data. These include encryption at rest and in transit, strict access controls, no plaintext logging of sensitive content, and regular security review.

No system is perfectly secure. If we become aware of a breach that affects your personal data, we will notify you in accordance with applicable law.

13 — Changes to This Policy

We will notify you of material changes via in-app notification or email at least 14 days before the changes take effect. Continued use after that date constitutes acceptance.

14 — Contact

Voyage Labs
[email protected]
voyageapp.app