Paradigm · Legal

Privacy Policy

What the Paradigm app collects, why it is needed, who processes it, and the choices you have.

ApexForm Life Pty Ltd (ABN 11 698 784 904) ("ApexForm Life", "we", "us" or "our") operates the Paradigm mobile application and related services. This policy explains what information Paradigm collects, why we use it, the services that process it, how automated processing is used, how long information is kept, and the choices available to you. Paradigm is available only to adults aged 18 or older.

Effective 19 August 2026. Updated 23 September 2026.

This policy covers the Paradigm app. The ApexForm Life website privacy policy separately explains cookies and analytics used on other website pages. This app-specific legal page does not load marketing analytics.

1. Information we collect

Account information

We collect the email address used for passwordless sign-in, or the identifier and email address (if Apple supplies one) associated with Sign in with Apple. We create an internal account identifier so your history and subscription can be restored across devices. If you use Sign in with Apple, we retain an encrypted provider credential only to maintain and revoke that sign-in connection, including when you delete your account.

Age confirmation

We store the date and time when you confirm that you are 18 or older. We do not ask for or store your date of birth.

Voice and reflection content

When you choose to make a capture, we collect the recording you submit. We also store the resulting transcript, AI-assisted results, your responses to readings, and related capture history. Paradigm uses the words and broad vocal features in the recording to offer a possible self-reflection reading and may suggest an optional reflective action.

Depending on what you submit and what is inferred, this content may include sensitive personal information or health information. Please record only what you are comfortable submitting for the processing described below.

Please do not record another person. If your reflection includes personal information about someone else, only submit it when you are permitted to do so. Do not include their sensitive information unless they have agreed and you are allowed to provide it. Paradigm processes any such information only as part of the capture you asked us to handle, under the same retention and deletion rules described in this policy.

If you believe information about you was submitted by a Paradigm user, email support@apexformlife.com with the subject Paradigm Privacy. Do not send a recording, transcript, or other sensitive details in ordinary email; describe the concern minimally and we will explain a secure next step. We will not confirm or disclose another user's account or content without an appropriate basis.

The raw capture recording is stored in active object storage for processing. When processing completes or fails, Paradigm attempts to delete the active raw-audio object, records successful deletion, and retries failed attempts. An upload that never becomes a capture is eligible for deletion after 24 hours. The resulting transcript, generated results, responses to readings, and related capture history remain stored with your Paradigm account as described below.

Purchase information

We receive subscription status, product and transaction identifiers, and purchase history needed to unlock paid features. Apple or the relevant payment provider processes payment credentials. We do not receive or store your full payment-card details.

Technical and security information

We and our infrastructure providers process limited technical information needed to deliver and secure the service, such as request timestamps, IP address, app and platform information, authentication events, response status, and operational error logs.

App feedback reports

When you choose Send feedback, we collect your selected category and the message you write. The form shows the optional technical details included, such as the screen, app build and device or system details; you can turn those details off. The request is associated with your current account or app installation for security and support, even when optional details are off.

App feedback reports are held separately from your reflections and responses to readings, and are not used to generate readings. Support staff with approved access can read your report. Our internal task service receives a report reference and limited technical triage details, not your original message or account identity.

Support communications

If you contact us, we receive the contact details and content you include in the message.

2. Information stored on your device

Some self-reflection inputs, programme progress, reminder settings, preferences, and your adult confirmation are normally stored locally on your device. They may be included in a device backup if your Apple or device backup settings allow it.

If you enable reminders, Paradigm schedules them locally through your device's notification system. Paradigm does not obtain an Expo push token or send reflection content to a push-notification service. Reminder text is deliberately generic, but it may appear on your lock screen depending on your device settings. You can disable reminders in Paradigm or control notification previews in your device settings.

Raw recordings in active object storage follow the processing and deletion-retry lifecycle described above. Transcripts, generated results, and related account history are stored with your Paradigm account as described below.

3. AI processing and your permission

Before each recording, Paradigm asks for your explicit permission to collect the recording and send it to OpenAI. If you agree, OpenAI processes the audio and resulting transcript, and Paradigm uses the audio, transcript, and information inferred from them to create and store the self-reflection reading you request. Depending on what you say, this may include sensitive personal information or health information.

OpenAI processes this information for ApexForm Life. You can choose Not now; no recording begins and nothing is sent. You can also stop using voice capture at any time.

For each new capture accepted by the current service, we retain the version of this notice and the server date and time when the capture request carried your Agree and record choice. This limited receipt is stored with the capture, is included in an access copy, and is deleted when that capture or your account is deleted. Older beta captures created before this receipt was introduced may not contain one; we do not backfill them with a consent event that did not occur.

Under OpenAI's current API data controls, data submitted through its API is not used to train OpenAI models by default. The audio-transcription feature Paradigm uses is listed with no standard abuse-monitoring or application-state retention. Text-generation requests may have abuse-monitoring records retained for up to 30 days, subject to documented exceptions and any different contractual controls that apply.

AI-generated content may be incomplete or incorrect. Paradigm presents the main interpretation for each capture as a possibility and lets you choose Yes, Adjust, Unsure or No. You can later change that response. Only interpretation text you accept with Yes or write yourself using Adjust is eligible to inform later AI-assisted pattern maps or weekly summaries; Unsure, No/not-a-fit and otherwise unconfirmed interpretations are excluded from that downstream synthesis. Paradigm explains the high-level information classes used for a reading, but does not provide a diagnosis, objective score, fact, or assessment of who you are. It is a self-development and reflection tool, not a substitute for professional care.

4. How we use information

Paradigm uses your reflections and personal history to support your own experience. As your history grows, it can help make your experience more relevant to you.

We use information to:

  • create, authenticate, and secure your account;
  • upload, transcribe, and analyse recordings you choose to submit;
  • provide personalised results and account history;
  • remember your responses to readings and improve the relevance of results shown to you;
  • manage subscriptions and feature entitlements;
  • send one-time sign-in codes;
  • answer support requests and review app feedback reports;
  • prevent fraud, abuse, and repeated free-tier resets;
  • troubleshoot failures and maintain the service; and
  • comply with applicable law.

5. Automated processing

Paradigm uses automated systems to transcribe recordings and produce optional interpretations, reflective prompts, suggested practices or small experiments, pattern summaries, and history views. These outputs use information you submit, the words and broad vocal features in a recording where relevant, your responses to readings, and related capture history. They are possibilities for reflection, not facts, diagnoses, objective scores, or professional or medical decisions. You can choose Yes, Adjust, Unsure or No for the main interpretation and can later change that response. Later AI-assisted pattern maps and weekly summaries use only interpretation text that you accepted with Yes or supplied using Adjust; Unsure, No/not-a-fit and otherwise unconfirmed interpretations are excluded.

The Identity Audit automatically converts the answers you choose into local theme summaries, labels and an ordered snapshot. It uses only those self-report answers for that result. It is not an objective measure of identity, health, cause, capacity or future behaviour. You can skip or retake it.

Some AI-assisted features may suggest an optional practice or small self-directed experiment using the direction, obstacle, reflection history and outcome feedback you choose to provide. You decide whether to edit, start, dismiss, stop or respond to a suggestion. A suggestion does not determine medical care, professional support or eligibility for another service.

We also use automated checks involving account identifiers, subscription and purchase status, usage history, authentication events, and security signals. A program may solely grant, continue, restore, limit, or withhold paid-feature access or another free use; permit, delay, or refuse a sign-in or request; or perform a step directly related to a human access or security review. Provider systems may supply purchase, delivery, fraud-prevention, or security results used in those checks. These outcomes can affect access to a Paradigm account or feature, but do not decide medical care, employment, credit, insurance, legal status, or access to another essential service. Contact us if you believe an access or security decision is wrong or you want it reviewed.

Paradigm also checks whether a valid adult-confirmation timestamp is present on this device before allowing normal app access. If it is absent or invalid, the app returns to the 18+ confirmation screen. We do not use that check to estimate your age or collect a birth date.

Automated safeguards review AI-written results for wording outside Paradigm's general-wellness boundaries. They may request a fresh result or withhold generated text rather than show or retain it. If a capture fails without delivering a reading, it should not consume a free reading. These safeguards are not crisis detection or emergency monitoring. You can retry or contact us if you believe a service or access outcome is wrong.

Checks of the words you submit may also withhold a reading and show a fixed message explaining Paradigm's limits and available help. These checks cannot reliably recognise emergencies or assess whether someone is safe. Nobody monitors your recordings or notes for emergencies.

Automated retention and deletion routines use account or capture identifiers, storage or processing status, deletion requests, and retention dates to delete raw recordings, carry out account deletion, remove limited records after approved periods, and prevent an older recovery copy from reactivating data already deleted. They do not assess your reflection content or decide eligibility for care or another service. If an operation cannot be completed safely, it may be retried or paused. Some steps may complete before another step needs a retry or further review. Contact us if you believe a deletion or retention outcome is wrong or incomplete.

6. Service providers and disclosures

We disclose only the information needed to operate Paradigm to service providers and platform operators:

  • Railway — secure cloud hosting and storage;
  • OpenAI — transcription and AI processing;
  • RevenueCat — subscription and purchase-status management;
  • Resend — delivery of passwordless sign-in emails;
  • Notion — internal app-feedback task references and limited triage details, without your original report message or account identity;
  • Apple — Sign in with Apple and App Store purchases;
  • Stripe — if you purchase through a supported website or activate a web subscription; and
  • Rewardful — partner-referral attribution if that feature is enabled on a supported web checkout. Rewardful may receive a referral identifier and related purchase or subscription events through its Stripe connection.

Providers handling personal information only for us are required to use it for the contracted service, service protection, or legal compliance and to maintain appropriate privacy and security protections. Apple and Stripe may also process purchase, payment, device, transaction, fraud-prevention, and account information as independent organisations under their own privacy notices and legal duties. Stripe states that it uses some of this information for payment authentication, fraud and loss prevention, service analytics, and improving the automated models used in its services. Paradigm does not send reflection content, recordings, transcripts, or generated readings to Apple, RevenueCat, Stripe, or Rewardful.

We may also disclose information if required by law, to protect a person's safety or rights, or as part of a corporate transaction subject to appropriate confidentiality protections.

7. No advertising, sale, or cross-app tracking

We do not sell personal information. The Paradigm app does not contain third-party advertising and does not use your information to track you across apps or websites owned by other companies. We do not share reflection content with data brokers.

A supported web checkout may, after giving notice and when you choose Subscribe, load Rewardful and store a first-party referral cookie for the configured campaign period. This is used only to attribute a partner referral and purchase, not to monitor your reflection activity.

8. Retention

  • Paradigm attempts to delete raw capture recordings from active object storage after processing completes or fails. Failed deletion attempts are retried, and unattached uploads are eligible for deletion after 24 hours. Temporary or encrypted provider recovery copies may remain until ordinary rotation completes.
  • Transcripts, readings, responses to readings, and derived account history are kept as needed for your chosen features and personal history. In the current app, these records remain stored with your account until you delete the account or deletion is required sooner.
  • The normal active-storage period for app feedback reports is 90 days from submission. Account deletion removes associated reports and queues cleanup of linked task details; that cleanup may need retries or human review. Limited recovery copies and separately justified incident or legal records follow their applicable retention rules.
  • One-time sign-in codes expire after 10 minutes. Sign-in security records, including your email address and a hashed code, are used to prevent abuse and become eligible for cleanup 30 days after creation. Scheduled cleanup and retries can delay physical removal.
  • Temporary caches of review results stop being used when they expire; expiry does not necessarily remove the stored copy immediately.
  • Operational and security logs are kept for the limited period needed to protect and operate the service or investigate an incident.
  • Purchase, tax, dispute, or legal records may be retained where a store, payment provider, or law requires it.

After account deletion, we retain a limited, non-reversible recovery marker used only to prevent an older recovery point from reactivating the deleted account. Recovery markers become eligible for removal 35 days after account deletion; scheduled cleanup and retries can delay physical removal. We may separately retain a limited, non-reversible usage record to prevent repeated free-tier resets and enforce service eligibility, but only for a documented, limited period approved for that purpose. Neither record is linked to recordings, transcripts, or reflection content.

9. Deleting your account and data

You can permanently delete your Paradigm account from Settings → Delete Account. This removes your account and associated recordings, transcripts, generated content, responses to readings, app feedback reports, and active server-side activity records under our control. Cleanup of linked app-feedback task details is queued and may need retries or human review. It also clears the app's local programme data on that device. Where RevenueCat holds the Paradigm customer record used to manage feature access, we request deletion of that customer record as part of the account-deletion flow.

Deleting the app by itself does not delete a signed-in account. Account deletion does not cancel an App Store or other recurring subscription; cancel it separately in the store or payment account where you subscribed. Apple, a payment provider, or another provider may retain transaction, tax, fraud-prevention, suppression, security, or legal records where required or justified. Limited copies may also remain temporarily in encrypted backups or provider recovery systems until their ordinary rotation period ends.

To request access to or deletion of an app feedback report, contact support@apexformlife.com with your report reference. We verify ownership before acting; the reference alone is not proof of identity.

10. Security

We use administrative, technical, and organisational safeguards designed to protect information, including encryption in transit and access controls. No method of electronic storage or transmission is completely secure.

11. International processing

Our providers and their subprocessors may process information outside Australia, including in the United States, Canada, and Ireland, and in other locations identified in their current subprocessor disclosures. Locations can change; contact us for current information. Privacy laws in those countries may differ from those where you live. We assess provider safeguards and remain responsible for handling personal information as required by applicable law.

12. Your choices and rights

You can:

  • decline microphone access;
  • decline third-party AI processing before a recording;
  • choose Yes, Adjust, Unsure or No for an AI-assisted interpretation, and later change that response;
  • manage or cancel your subscription through the store or payment provider where you subscribed, including by contacting support for an existing web purchase; and
  • delete your account in the app.

Depending on where you live, you may also have rights to access, correct, object to processing of, or request a copy of personal information. You may ask us to review a feature-access decision made by automated checks. Email support@apexformlife.com with the subject Paradigm Privacy to make a request. We may need to verify your identity before acting.

13. Adults only

Paradigm is available only to people aged 18 or older. We ask users to confirm they are at least 18 before accessing the app. We do not knowingly permit children to use Paradigm. If you believe a person under 18 has provided information, contact us so we can investigate and delete it where appropriate.

14. Changes to this policy

We may update this policy as Paradigm, our providers, or applicable requirements change. We will update the effective date and provide additional notice where required.

15. Contact and complaints

For privacy questions, requests, or complaints, email support@apexformlife.com with the subject Paradigm Privacy. We will review privacy complaints and respond within a reasonable period. If you are in Australia and remain dissatisfied, you may be able to contact the Office of the Australian Information Commissioner.

Read the Paradigm Terms of Use, Paradigm Support, and, for an iOS app licence, Apple's Standard EULA.