LEGAL

Privacy Policy

Effective date: August 4, 2026 · Last updated: August 4, 2026

Template notice. This Privacy Policy is a working draft prepared from CymaTones' current tech stack and product surfaces. It is not a substitute for review by qualified legal counsel. Have this document reviewed for your jurisdiction, product specifics, and any regulated data types before relying on it as your published policy.

CymaTones LLC ("CymaTones," "we," "us," or "our") values your privacy. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have regarding your personal information when you use CymaTones — including our website, mobile applications, and TV applications (collectively, the "Service").

Simple summary: We collect what we need to run the Service — your account info, your listening/session activity, your scans, your journal + scrapbook + voice-affirmation content, and payment details. We don't sell your data. Payments are processed by Stripe (we never store card numbers). Your private user content (voice recordings, journal entries, uploaded photos) stays inside your account with owner-only access, is never shared with third parties for marketing, and is never used to train external AI models.
Wellness note. CymaTones provides frequency/wellness content and community tools. It is not a medical device, diagnostic tool, or treatment. See our Terms of Service for the full wellness disclaimer.

1. What We Collect

Information You Provide

CategoryExamples
Account informationName, email address, password (hashed), profile preferences
Birth data (optional)Birth date, time, and location for Cosmos personalized readings
Payment informationProcessed by Stripe — we receive transaction metadata (amount, product, status, last-four digits) but never store full card numbers
Voice affirmation recordingsAudio files you record inside the Affirmations feature (Sanctuary → Affirmations). Stored in a private, owner-only storage bucket. Never shared. Never used to train AI models.
Journal entriesText, page themes, and scrapbook layouts you create in the garden Journal — stored per user, owner-only.
Scrapbook imagesPhotos you upload for your journal scrapbook (private, owner-only bucket).
Bioscan dataVoice, tongue, nails, face, and vision scans: derived spectrums and calculated scores. See §5 for exactly what is / is not retained.
Symptom selectionsYour Symptoms Selector inputs (duration, intensity) used to build a Custom Playlist.
Garden stateYour garden layout, plants, decor, character avatar, and daily-ritual activity.
User community contentPublic gardens, shared playlists, community shop listings, keepsakes — visible per your chosen visibility settings.
Support communicationMessages you send us, support request attachments.

Information Collected Automatically

CategoryExamples
Usage dataWhich tracks you play, duration listened, features used, scan count, pages visited.
Device & browser dataIP address, browser type, device type, operating system, user agent. On mobile/TV apps, device identifiers provided by the platform.
Technical logsError reports, API request logs, security audit events.
Cookies & similar techSession cookies, anonymous scan identifiers, timezone cookie, preferences (see §7).

2. How We Use Information

We use your information to:

  • Provide the Service: create your account, stream frequency tracks, run scans, generate reports, and deliver features you request across web, mobile, and TV apps.
  • Personalize your experience: tailor Custom Intelligence dashboards, Cosmos readings, and Custom Playlists based on your preferences and history.
  • Process payments: handle subscriptions, one-time purchases, refunds, and billing communications via Stripe.
  • Communicate with you: send service announcements, billing receipts, scan-completion notifications, and support responses via Resend.
  • Improve the Service: analyze aggregate usage patterns to identify bugs, optimize features, and develop new offerings.
  • Security and fraud prevention: detect and prevent abuse, enforce our Terms, comply with law.
  • Legal compliance: meet legal, regulatory, and contractual obligations.

We do not use your personal information to train external AI models, nor do we sell or rent your personal information to third parties for their marketing.

3. How We Share Information

We share information only as follows:

  • Service providers (subprocessors): trusted third parties that help us operate the Service (see §4).
  • Legal requirements: when required by law, court order, or to protect CymaTones' rights, users, or the public.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, with advance notice where practicable.
  • With your consent: when you explicitly ask us to share information (e.g., publishing a public garden or a shared playlist).

We do not sell your personal information.

4. Subprocessors

We work with the following trusted partners to operate CymaTones:

PartnerPurposeData Shared
SupabaseDatabase, authentication, and file storageAccount, session, listening, scan, journal, affirmation, scrapbook, and garden data
StripePayment processing (subscriptions + one-time purchases)Name, email, billing address, payment method — full card numbers never touch our servers
VercelWeb hosting and edge computeHTTP request logs, deployment data
ResendTransactional and marketing email deliveryEmail address, message content, delivery/open events
AnthropicAI-enhanced scan reports (server-side generation)Scan spectrum data and Symptoms picker inputs — not retained by Anthropic for training per its enterprise terms
Cloudflare WorkersVoice-scan proxy to Anthropic (bioscan pipeline)Voice-scan audio segment during the request, not persisted
TikTok Live listener (self-hosted on Render.com)Ingests public TikTok Live gift + chat events for the streaming gardenPublic TikTok display names + gift metadata for connected creator accounts only
Google Play (Android app store)Distribution + billing for the Android mobile app (if published)Install/uninstall telemetry, in-app purchase data per Google Play terms
Amazon Appstore (Fire TV app store)Distribution + billing for the Fire TV / TV appInstall/uninstall telemetry, in-app purchase data per Amazon terms

Each partner is bound by a data processing agreement or equivalent contractual protection. We review partners periodically to ensure they meet our privacy and security standards.

5. Voice, Audio & Scan Data

CymaVoice scan (bioscan)

Your voice-scan audio is processed live and not persisted. A short voice segment is captured, analyzed (via our Cloudflare Worker + Anthropic pipeline for enhanced reports), and used to produce a numerical frequency spectrum + scores — then the audio is discarded. We store the derived values, not the raw waveform.

What we do store from bioscans:

  • The derived numerical frequency spectrum
  • Calculated harmony scores and TCM-based analysis
  • Scan date, payment status, and the generated report content

What we do not store from bioscans:

  • Raw audio files from your scan
  • Waveform data that could be played back to reconstruct your voice

Vision, Tongue, Face, and Nails scanners follow the same principle: images are processed for analysis and only the derived scores / report content are retained.

Voice affirmation recordings (Sanctuary)

Separately from bioscans, the Voice Affirmations feature (Sanctuary → Affirmations) lets you record audio clips of your own affirmations. These recordings are stored on our servers because you replay them yourself. Storage rules:

  • Stored in a private, owner-only Supabase Storage bucket (owner-only enforced by row-level security).
  • Streamed back to you via short-lived signed URLs; no public URLs are ever generated.
  • Never shared with third parties, never used for marketing, never used to train AI models.
  • You can delete a recording at any time from the Affirmations page; deletion removes the audio file from storage.

Scrapbook image uploads (Journal)

Photos you upload for your journal scrapbook follow the same owner-only pattern: private Supabase Storage bucket, RLS-gated signed-URL access, no public URLs, no third-party sharing.

6. AI Processing

CymaTones uses AI (currently Anthropic Claude) to enhance scan reports and generate personalized interpretations. When you complete a scan:

  1. Your scan data (derived spectrum values, scores, and demographic context if provided) is sent to Anthropic via secure API.
  2. Anthropic processes the data and returns an enhanced analysis.
  3. Per Anthropic's enterprise terms, your data is not used to train Anthropic's models.
  4. Results are stored on CymaTones servers for you to access.

You may opt out of AI-enhanced analysis by contacting us; in that case, you will receive the local (non-AI) version of your report.

7. Cookies & Local Storage

We use cookies and similar technologies to operate the Service. Types we use:

  • Essential cookies: required for login, session maintenance, and security (cannot be disabled).
  • Preference cookies: remember settings like volume, visual mode, and your timezone (cymatones-tz) so times render correctly.
  • Anonymous scan cookies: on public pages, we set a 30-day cyma_anon cookie to associate your scans with your device if you are not logged in.

You can control cookies through your browser settings. Disabling essential cookies will break Service functionality.

Local storage: On public pages, we use your browser's local storage to save your scan history so you can return and review past results. This data stays on your device and is not transmitted to us unless you create an account.

8. Analytics & Tracking

As of the "Last updated" date above, CymaTones does not run third-party analytics, Google Analytics, Facebook Pixel, or advertising trackers on the Service. Basic infrastructure telemetry (request logs, error rates) is collected by Vercel and Supabase for uptime + security purposes only. If we add analytics in the future, we will update this section.

9. Mobile & TV Applications

CymaTones is offered as a website, a mobile application (subject to release), and a TV application (subject to release · currently targeted at Fire TV via the Amazon Appstore).

  • On mobile and TV, the platform (Google Play, Apple App Store, Amazon Appstore) may collect its own device identifiers, install/uninstall telemetry, and — for in-app purchases — payment information per that platform's terms.
  • The audio/frequency streaming, listening history, scanners, journal, and affirmations all follow the same privacy rules as on the web — private data stays owner-only.
  • Microphone access on mobile/TV apps is only used for scan/affirmation features you explicitly initiate. It is never listened to in the background.

10. Data Retention

Data TypeRetention Period
Account dataWhile your account is active + up to 90 days after deletion request
Scan resultsWhile your account is active (unless deleted by you)
Voice affirmation recordingsWhile your account is active (unless you delete individual recordings)
Journal + scrapbook contentWhile your account is active
Playback / session logsUp to 24 months, then aggregated/anonymized
Payment records7 years (tax and accounting law)
Support communications3 years
Anonymous scan data (public)6 months, then deleted
Security audit logs12 months

11. Security

We take security seriously:

  • Passwords are stored hashed via Supabase Auth (bcrypt-derived).
  • Connections to the Service are encrypted via HTTPS/TLS.
  • Database access uses row-level security (RLS) — you only see your own data.
  • Private user content (voice affirmations, scrapbook images) is served only via short-lived signed URLs.
  • Payment handling is delegated to Stripe, a PCI-DSS Level 1 certified processor.
  • Webhook signatures are verified with HMAC to prevent tampering.
  • Access to internal admin tools requires a dedicated founder role with audit logging.

No method of transmission or storage is 100% secure. If we become aware of a data breach affecting your information, we will notify you as required by law.

12. Your Rights

You have the right to:

  • Access your personal information.
  • Correct inaccurate information.
  • Delete your account and associated data.
  • Export your data in a machine-readable format.
  • Opt out of marketing communications (transactional emails continue for active accounts).
  • Withdraw consent for optional processing (e.g., AI enhancement).

To exercise any of these rights, email support@cymatones.com. We'll respond within 30 days.

13. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act give you additional rights:

  • Right to know what personal information we collect, use, and share.
  • Right to delete personal information.
  • Right to correct inaccurate personal information.
  • Right to opt out of the "sale" or "sharing" of personal information (we do not sell; we do not share for cross-context behavioral advertising).
  • Right to limit the use of sensitive personal information.
  • Right to non-discrimination for exercising your rights.

To exercise California rights, contact support@cymatones.com. We may need to verify your identity before fulfilling the request.

Shine the Light

California Civil Code § 1798.83 allows California residents to request certain information about our disclosure of personal information to third parties for direct marketing. We do not disclose personal information to third parties for their direct marketing.

14. EU/UK Users (GDPR/UK GDPR)

If you are in the European Economic Area or United Kingdom, the GDPR gives you rights including access, correction, deletion, restriction, portability, and objection to processing of your personal information.

Legal bases for processing:

  • Contract: to provide the Service you signed up for.
  • Consent: for optional features like Cosmos birth data or marketing emails.
  • Legitimate interests: for service improvement, security, and fraud prevention.
  • Legal obligation: for tax, accounting, and compliance.

You may contact a supervisory authority in your country if you believe we have violated data protection law. We would appreciate the opportunity to resolve your concern first — please contact support@cymatones.com.

International Transfers

Our servers are primarily located in the United States. By using the Service, you consent to the transfer of your information to the United States and other countries where our service providers operate. We use standard contractual clauses or equivalent safeguards for transfers from the EEA/UK where required.

15. Children's Privacy

CymaTones is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 13 (per COPPA in the U.S.) or under 16 (per GDPR in the EU/UK). If you believe a child has provided us personal information, please contact support@cymatones.com and we will take steps to delete it.

16. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top. For material changes, we will notify you via email and/or an in-app notice at least 30 days before the changes take effect where required by law.

17. Contact

Questions about this Privacy Policy or how we handle your information?

© 2026 CymaTones LLC. All rights reserved.