App: Gloam
Provider: ADV IT Solutions SRL ("ADV IT Solutions", "we", "us", "our")
ADV IT Solutions SRL, a company registered in Romania, RO44665006, and is the data controller for the limited personal data processed through Gloam ("the App").
Gloam is a private, on-device voice-journaling app. This policy explains what we do and — just as importantly — what we deliberately don't do with your data. Our guiding principle is simple: your journal belongs to you. Your recordings stay on your device, and nothing about what you say or how you feel is ever sold, shared for advertising, or used to profile you.
1. A one-minute summary
- We don't have accounts. No sign-up, no email, no password. We don't know who you are.
- Your recordings live on your device, in encrypted storage. By default your audio never leaves your phone.
- Two features send data off-device, and only if you turn them on:
- Cloud transcription (optional): your audio is uploaded to our processing service to be turned into text.
- Reflections (optional): the text transcript of an entry is sent to our processing service to generate a written reflection.
- We use privacy-safe analytics to understand how the app is used (e.g. how many people finish onboarding). These events never contain your journal content, transcripts, moods, or anything you said.
- We never sell your data. We never use your journal content for advertising.
2. Data stored on your device (not sent to us)
Everything below stays local to your device and is never transmitted to us in the course of normal use:
- Voice recordings (audio files) and their transcripts.
- Reflections, moods, themes, and insights derived from your entries.
- Voice-tone signals analysed on your device (e.g. how your voice sounded versus the words) — this analysis runs entirely on your phone; the audio used for it never leaves the device.
- Your preferences: reminder time, language, transcription mode, consent toggles, and whether the app lock is on.
This data is stored in an encrypted local database (SQLCipher) with the encryption key held in your device's secure storage (Android Keystore / iOS Keychain). If you enable the optional app lock, access is further gated behind your device biometrics or screen lock. Biometric verification happens on your device through the operating system; we never receive your fingerprint, face data, or PIN.
You can permanently erase all of this at any time via Settings → Delete everything.
3. Data that leaves your device — only with your consent
Gloam works fully offline. Two optional features send data to our backend, and each is off until you turn it on.
3.1 Cloud transcription (optional)
If you choose cloud transcription in Settings, the audio of an entry is
uploaded through our backend to OpenAI (using OpenAI's Whisper whisper-1
speech-to-text model) to be converted into text. If you instead keep
on-device transcription (the private default), your audio is transcribed
locally and never leaves your phone.
- What is sent: the audio recording and, optionally, a language hint (e.g.
en,ro). - Sent to: OpenAI, L.L.C., our speech-to-text processor (https://openai.com/policies/privacy-policy/).
- Purpose: to produce a text transcript of that recording.
- How it's processed: our backend forwards the audio to OpenAI's API and returns the resulting text to your device. Under OpenAI's API terms, submitted audio is not used to train OpenAI's models.
- Retention: the audio is processed only to generate the transcript for that request. We do not use it to build any profile of you and do not retain it on our servers beyond what is necessary to complete the request.
- Consent: cloud transcription is off by default. Choosing "Cloud" in the transcription picker — which names OpenAI and explains what's sent — is how you turn it on; nothing is sent until you do.
3.2 Reflections (optional)
If you enable "Send transcripts for reflection" in Settings, the
text transcript of an entry is sent through our backend to OpenAI (using
OpenAI's gpt-4o-mini model) to generate a short written reflection and a follow-up
question. Your audio is never sent for reflections — only the text.
- What is sent: the text transcript of the entry.
- Sent to: OpenAI, L.L.C., our reflection processor (https://openai.com/policies/privacy-policy/).
- Purpose: to generate a reflection and a gentle follow-up prompt for that entry.
- How it's processed: our backend forwards the transcript to OpenAI's API and returns the resulting reflection to your device. Under OpenAI's API terms, submitted transcripts are not used to train OpenAI's models.
- Retention: the transcript is processed only to generate that reflection. We do not use it for advertising or profiling and do not retain it on our servers beyond what is necessary to complete the request.
- Consent: reflections are off by default. The first time you request one, the app names OpenAI and explains what's sent before asking you to turn the feature on; nothing is sent until you do, and you can turn it off again at any time in Settings.
You can turn either feature off at any time in Settings. When off, no audio or transcript is sent for that purpose.
3.3 Protection at this third party
OpenAI processes the data described above only to fulfil your request (transcription or reflection, respectively), under contractual terms that prohibit using it to train OpenAI's models and require it to protect the data with safeguards equivalent to those described in this policy. We selected OpenAI on that basis and review its published privacy and API-use terms before relying on it.
4. Analytics and app operation
To keep Gloam reliable and understand how it's used (including to measure the effectiveness of our own advertising), we use a small set of Google/Firebase services:
- Firebase Analytics — privacy-safe, engagement-only usage measurement. We record events such as app opens, session starts, completing onboarding, and viewing or tapping the upgrade screen. These events never include your journal content, transcripts, moods, recordings, or anything you said or felt. Analytics also processes standard mobile identifiers and approximate, coarse data (e.g. device model, OS version, app version, and a resettable analytics/advertising identifier) to attribute app installs to our marketing campaigns.
- Firebase App Check — verifies that requests to our backend come from a genuine, untampered instance of the app, to prevent abuse. It uses a device-attestation token and does not identify you.
- Firebase Remote Config — lets us adjust app configuration (such as feature flags) without an update. It does not collect journal content.
- Superwall — presents and A/B-tests our subscription upgrade screens. It receives non-identifying event and device information to decide which upgrade screen to show and to measure conversion. It does not receive your journal content.
These providers process data as described in their own privacy policies:
- Google / Firebase: https://firebase.google.com/support/privacy
- Superwall: https://superwall.com/privacy
5. Subscriptions and payments
Gloam offers an optional Gloam PRO subscription. Purchases are handled entirely by the app store (e.g. Google Play). We do not receive or store your payment card details. The app store shares with us only the information needed to grant your entitlement (e.g. whether an active subscription exists). Please refer to your app store's privacy policy for how it processes payments.
6. Notifications
If you enable daily reminders (or the app schedules periodic report nudges), these are local notifications generated on your device using your chosen time and time zone. They are not sent through a server and involve no message about your journal content.
7. What we do NOT do
- We do not create user accounts or ask for your name, email, or phone number.
- We do not sell your personal data.
- We do not use your journal content, transcripts, moods, or recordings for advertising or profiling.
- We do not track your mental-health state or share "health"-style data with third parties. Any mood or tone signal you see is derived and stored on your device.
8. Legal bases for processing (GDPR)
Where the GDPR applies, we rely on:
- Consent (Art. 6(1)(a)) — for optional cloud transcription, reflections, and analytics where required. You can withdraw consent at any time in Settings or your device settings.
- Legitimate interests (Art. 6(1)(f)) — for security/anti-abuse (App Check) and keeping the app functioning correctly, balanced against your rights.
- Contract (Art. 6(1)(b)) — to provide the PRO features you purchase.
9. Your rights
Under the GDPR and Romanian data-protection law, you have the rights to access, rectify, erase, restrict, and port your personal data, and to object to certain processing. Because most of your data is stored only on your device:
- Access & portability: your entries are on your device; export/erase controls are in the app.
- Erasure: use Settings → Delete everything to permanently remove all local data. Uninstalling the app also removes on-device data.
- Analytics opt-out: you can reset or limit ad/analytics identifiers via your device settings, and disable optional features in Gloam's Settings.
To exercise any right regarding data we act as controller for, or to ask a question, contact us at advitsolutionsro@gmail.com. You also have the right to lodge a complaint with the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP) — https://www.dataprotection.ro.
10. International transfers
Some of our service providers (e.g. Google/Firebase and the AI/transcription providers used by our backend) may process data on servers outside the European Economic Area. Where that happens, transfers are protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
11. Data retention
- On-device data is retained until you delete it (in-app deletion or uninstalling the app).
- Optional cloud transcription / reflection requests are processed transiently to fulfil the request and are not retained by us for profiling.
- Analytics data is retained per Firebase's default / configured retention settings.
12. Children
Gloam is not directed to children. You must be at least 16 years old (or the minimum age of digital consent in your country) to use the App. We do not knowingly collect data from children under this age.
13. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app. Continued use of the App after changes take effect means you accept the revised policy.
14. Contact
ADV IT Solutions SRL
Email: advitsolutionsro@gmail.com
Romania