Celuna Privacy Policy

Last updated: September 24, 2026

Your personal content stays on your device by default. If you consent and enable Settings > Account sync on both devices, your intentions, journals, Vision Board images, voice notes, profile, progress, favorites and listening history are transferred between devices using the same Celuna account. This content is stored on Cloudflare infrastructure under your technical account identity. HTTPS protects transfer; this feature does not provide end-to-end encryption. Your local encryption key is not uploaded. Operating-system automatic backup is separate from this sync feature.

1. Who we are

Celuna is a mobile app that turns manifestation and personal-growth practices into a daily habit, operated by Ebru Yıldız under the Celuna Labs brand. For the purposes of this policy, the data controller is Ebru Yıldız (Celuna Labs). This policy explains what data is processed, and how, while you use the app; for privacy questions or a formal data request, you can reach us at support.celuna@gmail.com.

2. Data stored locally on your device

Your personal content stays on your device by default. If you consent and enable Settings > Account sync on both devices, your intentions, journals, Vision Board images, voice notes, profile, progress, favorites and listening history are transferred between devices using the same Celuna account. This content is stored on Cloudflare infrastructure under your technical account identity. HTTPS protects transfer; this feature does not provide end-to-end encryption. Your local encryption key is not uploaded. Operating-system automatic backup is separate from this sync feature.

3. Device permissions

• Microphone: used only when you start a recording, to capture voice manifests/intentions and your own voice in the Mirror Technique.
• Speech recognition: to convert what you say in the Mirror Technique into text (via the system speech-recognition service on iOS); on Android, the Manifest Intention step's speak-to-write feature also uses the device's own speech recognition service. This recognition runs through that operating system's OWN infrastructure (Google on Android, Apple on iOS) — depending on your device/settings, it may happen entirely on-device, or it may be sent to that OS vendor's own servers for processing. Either way, this audio/text never reaches Celuna's own servers and is never stored by Celuna — but "doesn't go to Celuna" does not mean "never leaves the device"; this is the general behavior of Google's/Apple's own OS-level service, and details can be found in that provider's own privacy policy.
• Notifications: to send your Ritual Hour reminders.
• Photos: when you add an image to your Vision Board, the operating system's own photo picker opens; Celuna is never granted persistent access to your whole photo library — only the photo you select is passed to the app.

Your personal content stays on your device by default. If you consent and enable Settings > Account sync on both devices, your intentions, journals, Vision Board images, voice notes, profile, progress, favorites and listening history are transferred between devices using the same Celuna account. This content is stored on Cloudflare infrastructure under your technical account identity. HTTPS protects transfer; this feature does not provide end-to-end encryption. Your local encryption key is not uploaded. Operating-system automatic backup is separate from this sync feature.

4. Identity and security infrastructure

Firebase Authentication creates the app account identity. Linking Google or Apple lets you recover the same identity and Premium status on another device; transferring personal content separately requires enabling account sync. Firestore retains only the minimal technical profile record; synced personal content uses separate Cloudflare storage. Requests verify Firebase identity. When available, an App Check token is evaluated as an additional security signal; its absence alone does not block access. Anonymous accounts cannot use personal cloud sync.

Email sign-in is also supported. Firebase Authentication processes your email address and password for authentication; the password is not included in personal-content sync. Email accounts require verification. Your profile uses the name you choose in the questions; your Google or Apple name is not copied automatically.

5. Subscription and payment data

Celuna's premium subscriptions are processed through the Apple App Store / Google Play and RevenueCat. Your card/payment details never reach us — Apple/Google handle this directly. To verify your subscription status, the anonymous/technical identity described in Section 4 is shared with RevenueCat, which matches it to your subscription status (active/inactive, plan type). Your name, email, or payment details are never shared with RevenueCat.

6. Free previews and Premium audio/media delivery

Cloudflare delivers published audio to your device. Free previews verify Firebase identity; full Premium content also verifies RevenueCat entitlement and a valid device registration. One Premium account allows at most two devices. Downloaded catalogue audio uses account-separated local caches. Your own images and voice notes are uploaded only through separately enabled account sync.

7. Content sharing

When you share a frequency, atmosphere, voice manifest, or a custom mix you created from within the app, the resulting link carries only the content TYPE and a stable content ID (and, for a custom mix, the Hz and atmosphere you chose) — your identity, account, or any other personal information is NEVER added to the link. This link opens via celuna.net and, if the app is already installed, opens the matching content screen directly.

If the app is NOT yet installed and the link routes you through Google Play, Play's Install Referrer mechanism may pass this content target to the app once, at install time (see Section 9) — the app keeps it only on your device, never links it to your identity in any way, uses it once to open the right screen on first launch, and then deletes it.

8. Crash reporting (Firebase Crashlytics)

If the app crashes unexpectedly or encounters an error, an automatic technical diagnostic report is sent via Google's Firebase Crashlytics service. This report includes technical details such as where in the code the error occurred, and is not linked by Celuna to your Celuna account or personal content. However, as with any crash-reporting service, Google/Firebase may also process standard technical/device identifiers alongside this report — such as a Firebase installation ID, device model, OS version, and app version. None of your personal content — intentions, voice notes, gratitude entries, or profile information — is ever included in these reports; Crashlytics is used only to help us understand and fix why the app crashed. This data is processed by Google; see Google's privacy policy for details. Per Google's own published retention policy, Crashlytics crash reports (along with their associated technical identifiers) start being removed from Google's live and backup systems after approximately 90 days (source: firebase.google.com/support/privacy).

9. Invite/referral feature and post-install content target

For installs made through Google Play, Celuna may save an invite code and/or a shared content target (see Section 7) on your device at install time (Google Play Install Referrer). It is used once and, until then, stays only on your device.

If you use the invite feature, Celuna sends your technical account ID (Firebase user ID) and the invite code to Celuna’s own server (a Cloudflare Worker and D1 database) to create your invite code, record that you were invited, check whether the invite qualifies, and keep count of qualifying invites and rewards. These records are stored under the technical account ID and contain no name, email address or personal content. When a reward is earned, Celuna’s server asks RevenueCat to grant a free Premium period to the account, and RevenueCat sends subscription events (a webhook) to Celuna’s server so that a reward is not granted or paused incorrectly. Deleting these records is described in Section 11.

10. Third-party sharing

We do not sell your data, share it with ad networks, or include any advertising or user-tracking/analytics SDK in the app. Data is shared only with the following service providers, only as needed to perform their function:

• Google Firebase (Authentication, Firestore, App Check, Crashlytics) — for identity verification, minimal account records, security checks, and crash reporting
• RevenueCat — for subscription/purchase status verification
• Apple App Store / Google Play — for payment processing
• Cloudflare — for secure delivery of premium audio content, optional account sync, invite/referral records and device registration

Your personal content stays on your device by default. If you consent and enable Settings > Account sync on both devices, your intentions, journals, Vision Board images, voice notes, profile, progress, favorites and listening history are transferred between devices using the same Celuna account. This content is stored on Cloudflare infrastructure under your technical account identity. HTTPS protects transfer; this feature does not provide end-to-end encryption. Your local encryption key is not uploaded. Operating-system automatic backup is separate from this sync feature.

11. Deleting your account

You can permanently delete your account via Settings > "Delete My Account & Data." This deletes:

• Your Firebase Authentication identity record
• Your minimal Firestore profile record (users/{id})
• Your subscriber record at RevenueCat
• All local content and cache on your device (intentions, voice notes, journals, Vision Board, preferences)

Our deletion request to RevenueCat permanently deletes your subscriber record and purchase history from RevenueCat's live systems; per RevenueCat's own API documentation, this operation runs asynchronously and cannot be undone. RevenueCat processes this data on our behalf as a data processor, under our Terms of Service/Data Processing Agreement (DPA) with them. After a deletion request, some copies may persist briefly in RevenueCat's systems per their standard backup/archival practices; no specific number of days or years is published for that, so we don't state a duration here (source: revenuecat.com/dpa). Crashlytics crash reports are never matched to your account (see Section 8), so they are not part of account deletion — they are removed on their own once the ~90-day-later removal process described there begins.

IMPORTANT: deleting your Celuna account does NOT automatically cancel an active subscription billed through Google Play or the App Store. To stop a subscription from renewing, you must cancel it separately through the relevant store (Google Play: app → Menu → Payments & subscriptions; App Store: iOS Settings → your name → Subscriptions). You can also request deletion without the app installed via support.celuna@gmail.com.

Turning sync off stops transfers on this device without deleting cloud content. Clearing local data disables sync and erases local copies on this device; it does not erase the other device or cloud copies. Re-enabling sync for the same account may download cloud records again. Delete My Account & Data deletes synced cloud records and attachments before deleting the account identity. Signing out does not delete your account, subscription or cloud data. Cloud records remain until you delete the account or the relevant records.

When you delete an individual record, its old image or audio attachment may remain in cloud storage until the account is deleted. Sync attachments are limited to 20 MB per file and 100 MB total per account.

Deleting your account also deletes the following from Celuna’s server:
• your invite code, the invites you sent and your reward records
• your synced personal content and attachments (if you used account sync)
• the one-way, app-scoped technical device identifiers registered for the two-device Premium limit

Two technical records can remain after deletion. Neither contains your name, email address, profile or personal content. First: if you were invited and your invite had already counted, a record of that count can remain so that the inviter’s earned count does not fall. Your account identifier in that record is replaced by a random marker; the record stays tied to the inviter’s account only and is removed when the inviter deletes theirs.

Second: a one-way technical hash of your account ID, together with the timestamps of the deletion, is kept so that a deleted account cannot be processed again and to guard against invite abuse. The code sets no automatic expiry, so it is kept for as long as Celuna operates its invite security and abuse protection. The original account ID is cleared from this record once the deletion has been confirmed with RevenueCat.

12. Children's privacy

Celuna is not directed at users under 13 and does not knowingly collect data from them.

13. Worldwide distribution and international users

Firebase, RevenueCat and Cloudflare use global infrastructure. Servers processing your data, including personal content when you enable sync, may be in a different country from yours. For access, correction, deletion or other privacy requests, contact support.celuna@gmail.com.

14. Your control over your data

Turning sync off stops transfers on this device without deleting cloud content. Clearing local data disables sync and erases local copies on this device; it does not erase the other device or cloud copies. Re-enabling sync for the same account may download cloud records again. Delete My Account & Data deletes synced cloud records and attachments before deleting the account identity. Signing out does not delete your account, subscription or cloud data. Cloud records remain until you delete the account or the relevant records.

When you delete an individual record, its old image or audio attachment may remain in cloud storage until the account is deleted. Sync attachments are limited to 20 MB per file and 100 MB total per account.

15. Changes to this policy

If this policy is updated, the current version will be published on this page and the date above will change.