Privacy Policy

Effective Date: September 18, 2026

1. Introduction

Welcome to Pharus, operated by House Lawlez LLC ("House Lawlez," "we," "us," or "our"). This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use:

  • The Pharus iOS app, published on the Apple App Store by House Lawlez LLC
  • The Pharus Android app, published on Google Play by House Lawlez LLC (package name com.houselawlez.purpose)
  • The Pharus website and data platform at purpose.houselawlez.com, which serves as the app's home page, its account and data back end, and an administrative console

The mobile app was previously named Purpose; you may still see that name in older screenshots, permission prompts, and the Android package name. Together, the app and website are referred to as the "Services." By using any of our Services, you agree to the collection and use of information in accordance with this Privacy Policy.

In short: Pharus is a purpose journaling app. We collect the reflections, purpose ratings, and media you choose to record, the account details needed to sign you in, and limited product analytics. We do not sell your data, we show no advertising, and we do not share your personal data with other companies except the service providers that run the Services on our behalf.

2. Information We Collect

2.1 Account Information

When you create an account or sign in, we collect:

  • Username (login)
  • Email address
  • First and last name
  • Profile picture URL (if provided by your identity provider) or an avatar you upload in the app
  • Language preference
  • A unique user ID assigned by our identity provider

Authentication is managed through Auth0 (Okta, Inc.), a third-party identity provider. We do not store your password. When you sign in, Auth0 verifies your identity and provides us with a signed identity token. Please refer to Auth0's Privacy Policy for details on how they handle your credentials.

Sign in with Google. If you choose to sign in with your Google Account, Google shares your basic profile with us: your name, email address, profile picture, and a unique Google account identifier. We request only the openid, email, and profile scopes. We use this information solely to create your Pharus account, sign you in, and display your name and avatar inside the Services. We do not request or receive access to Gmail, Google Drive, Google Calendar, Contacts, or any other Google service. Pharus's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Sign in with Apple. If you choose to sign in with your Apple ID, Apple shares your name (on first sign-in only) and either your email address or an Apple-generated private relay address, together with a unique Apple user identifier. We use it for the same purposes described above.

2.2 Purpose and Wellness Data

The core function of our Services is to help you track, reflect on, and understand your sense of purpose. We collect:

  • Purpose level ratings — a numeric score (1–100) representing your self-reported sense of purpose
  • Mood indicators — optional mood labels you associate with your entries
  • Journal reflections — free-text notes, markdown-formatted reflections, and other written content you choose to record
  • Breathing session data — the duration and pattern of guided breathing sessions you complete and, only if you grant the optional Apple Health or Health Connect permission, the heart rate and heart rate variability samples your device recorded during that session. These samples are saved with the breathing log and synchronized with it.
  • Explore activity — which Explore Cards you view, complete, and upvote, so the feed can avoid repeating them
  • Intake questionnaire responses — answers you provide during onboarding to personalize your experience
  • Timestamps — the date and time each entry is created

This information is deeply personal. We treat all purpose and wellness data with the highest level of care and confidentiality. It is never used for advertising or sold to anyone.

2.3 Media Content

Our mobile apps offer multiple journaling modes. Depending on the mode you choose, you may create and store the following types of media:

Journal Mode Media Type Details
Photo Images (JPEG, PNG) Captured using your device camera or selected from your library
Video Video recordings (MOV, MP4) Captured using your device camera with optional trimming
Voice Memo Audio recordings (M4A/AAC) Recorded using your device microphone
Drawing Images (PNG) Created using the in-app drawing canvas (Apple Pencil supported on iOS)
Text Markdown text Written reflections with rich formatting

Media is stored on your device and, when you are signed in, uploaded to private cloud storage attached to your account (see Section 5) so it can be restored on a new device and, only if you choose, shared with a Crew. Media you share is visible only to the people you share it with; nothing you record is public by default.

2.4 Community and Social Content

Pharus includes optional social features. If you use them, we collect the content you contribute:

  • Purpose Crews — the name, description, tags, and cover image of a Crew you create; your membership, role, and optional job title; join requests and the reasons given for approving or denying them
  • Messages — chat messages, replies, upvotes, and reports you submit inside a Crew or in the global Crew chat
  • Shared reflections — a purpose log (including its text and media) that you deliberately share into a Crew
  • Explore Card comments — comments, upvotes, downvotes, and reports on Explore Cards
  • Community Projects — projects you create, the external payment links you attach, and contributions you self-report (an optional amount and note). Pharus never processes payments; contributions are made through the external service you choose.
  • Guest profiles — if you join a Crew before creating an account, we mint an anonymous guest token and store the display name you enter. It is merged into your account if you later sign up.

Content you post to a Crew is visible to the other members of that Crew, and content you post in global chat is visible to every Crew member. Your username may be shown alongside it. Moderators, Crew leaders, and our administrators can review reported content.

2.5 Device and Push Notification Tokens

To deliver push notifications, we collect:

  • Apple Push Notification service (APNs) tokens from iOS devices
  • Firebase Cloud Messaging (FCM) tokens from Android devices

These tokens are unique device identifiers used solely for sending you notifications. They do not reveal your identity, location, or any personal content. You can disable push notifications at any time through your device settings.

2.6 Subscriptions and Purchases

Pharus is free to download and offers an optional premium subscription purchased through the Apple App Store or Google Play. Apple or Google processes the payment; we never see your payment card or billing address. We receive and store the subscription status needed to unlock premium features: the product identifier, purchase and expiration dates, renewal state, and an obfuscated transaction identifier. You manage and cancel subscriptions through your App Store or Google Play account.

2.7 Support, Mailing List, and Deletion Requests

  • Support requests — the name, email address, and message you send through our contact form or by email
  • Mailing list — the email address you enter to receive Pharus updates; every message includes an unsubscribe option
  • Account deletion requests — the email address, optional name and note, and the IP address and browser user agent of a request submitted on our public account deletion page, kept as a record that the request was honored

2.8 Audit and System Data

In accordance with our compliance architecture, we automatically record audit metadata for data operations. This includes who created or modified a record (username), when the action occurred (timestamp), and what data was changed. Moderation actions inside Crews are recorded in an audit log that includes the acting moderator, the target, and the reason given. This audit trail exists for data integrity, security monitoring, and regulatory compliance. It is not used for behavioral profiling or advertising.

2.9 Product Analytics and Diagnostics

We collect in-app analytics and diagnostic information to improve our products. This data includes:

  • Event names and properties — for example, that a user opened a screen, created a log entry, or tapped a specific control. Event properties never include the contents of your journal reflections, mood text, or media.
  • A pseudonymous identifier — once you sign in, your account login is used as your identifier so we can stitch a session's events together.
  • Device and client metadata — OS, OS version, app version, device model, locale, and other standard properties.
  • Crash logs and diagnostics — crash reports and performance data provided through Apple's and Google's standard platform reporting and through our analytics provider, so we can find and fix defects.
  • Approximate location derived from IP address — our analytics provider infers a country, region, and city from the IP address that reaches its ingest endpoint. We do not request or store GPS, Wi-Fi, or cell-tower location. The inferred location is approximate and can be inaccurate, particularly for users on cellular carriers, corporate networks, or privacy relays such as iCloud Private Relay.
  • Web session recordings — on the website only, we record a sampled portion of user sessions (page interactions, clicks, scrolls) so we can diagnose usability issues. Sensitive form inputs are masked by redaction rules.

Mixpanel acts as a data processor on our behalf and is contractually prohibited from selling this data or using it for advertising. See Mixpanel's Privacy Policy for additional detail. You can ask us to delete your Mixpanel profile by contacting us at the address in Section 15 or by checking the corresponding box on our account deletion page.

2.10 Information We Do Not Collect

We want to be explicit about what we do not collect:

  • No advertising identifiers — we do not collect IDFA, GAID, or any advertising-related device identifiers
  • No precise location data — we do not request or store GPS, Wi-Fi, or cell-tower location information. We collect only the coarse IP-based geolocation described in Section 2.9.
  • No contacts or address book data
  • No health data beyond breathing sessions — the optional Apple Health or Health Connect integration reads only heart rate and heart rate variability while a guided breathing session is running, and writes that session back as a mindfulness or exercise session. We never read your other health records, and we never read heart data outside a session.
  • No payment card details
  • No cross-site or cross-app advertising tracking
  • No sale of personal data — we do not sell your personal data to any third party

3. Device Permissions

Our mobile apps request the following device permissions. Each is optional and used only for the stated purpose:

3.1 Camera

  • Platforms: iOS, Android
  • Purpose: To capture photos and videos as part of your journal reflections, and to choose an avatar or Crew cover image
  • When requested: Only when you select the Photo or Video journal mode or choose to take a picture
  • Android permission: android.permission.CAMERA (runtime-requested)

Camera access is never activated in the background. We only access the camera when you explicitly initiate a capture action.

3.2 Microphone

  • Platforms: iOS, Android
  • Purpose: To record voice memos as part of your journal reflections
  • When requested: Only when you select the Voice Memo journal mode
  • Android permission: android.permission.RECORD_AUDIO (runtime-requested)

Microphone access is never activated in the background. Audio recording begins only when you tap the record button and stops when you tap stop.

3.3 Notifications

  • Platforms: iOS, Android
  • Purpose: To deliver the reminders and Crew updates you opt into
  • When requested: When you first enable reminders; you can revoke it at any time in system settings

3.4 Health (optional)

  • Platforms: iOS (Apple Health), Android (Health Connect)
  • Purpose: To save completed breathing sessions to your health app and to read heart rate and heart rate variability during a session so the breathing log can show how your body responded
  • When requested: Only when you start a guided breathing session; breathing works fully without it

3.5 Internet

  • Platforms: iOS, Android, Web
  • Purpose: To synchronize your data with the Pharus platform, authenticate your account, and receive push notifications

4. How We Use Your Information

We use the information we collect for the following purposes:

  • App functionality — displaying your purpose logs, journal entries, trends, insights, Crews, and Explore content
  • Account management and authentication — creating your account, verifying your identity, and protecting your account
  • Data synchronization — persisting your entries from mobile clients to the Pharus platform so your data is available across devices and survives a lost phone
  • Personalization — tailoring insights, reminders, and Explore Cards to your own entries and intake answers
  • Developer communications — sending reminders and updates you have opted into, and replying to your support requests
  • Research and insights — generating aggregated, de-identified analytics about purpose and well-being trends (individual-level data is never shared externally)
  • Fraud prevention, security, and compliance — rate limiting, abuse and moderation handling, and maintaining audit trails for data integrity and regulatory requirements
  • Analytics and service improvement — understanding usage patterns and diagnosing defects to improve the experience

We do not use your data for advertising, behavioral profiling, or sale to third parties. These purposes match the data safety disclosures published on our Google Play listing.

5. Data Storage and Security

5.1 Server-Side Storage

Your account and purpose data are stored in a PostgreSQL database hosted on Heroku in the United States. Media files (photos, videos, voice memos, drawings, avatars, and Crew cover images) are stored in a private Amazon Web Services (S3) bucket. Nothing in that bucket is publicly listable; the app downloads media through short-lived, signed links issued only to the account that owns the media or to the members it was shared with. All data transmissions between your device and our servers are encrypted in transit using TLS (HTTPS), and stored data is encrypted at rest by our hosting providers.

5.2 On-Device Storage (iOS)

  • OAuth tokens are stored in the iOS Keychain, which is hardware-encrypted and protected by the device passcode
  • Journal entries are stored locally as encrypted JSON in the Keychain
  • Media files are stored in the app's private Documents directory, which is sandboxed and inaccessible to other applications
  • Onboarding preferences and voyage records are stored in UserDefaults (app-local, non-sensitive configuration)

5.3 On-Device Storage (Android)

  • OAuth tokens are stored in EncryptedSharedPreferences, protected by AES-256 encryption backed by the Android Keystore
  • Journal entries are stored in app-internal storage
  • Media files are stored in the app's private internal storage directory, sandboxed from other applications
  • Onboarding preferences and voyage records are stored in app-scoped SharedPreferences

5.4 Security Measures

We implement the following security measures to protect your data:

  • TLS encryption for all data in transit
  • Hardware-backed encryption for sensitive on-device storage (Keychain on iOS, Android Keystore)
  • OAuth 2.0 with PKCE for authentication flows
  • Stateless JWT-based session management (no server-side session storage)
  • CSRF protection with a dual-token pattern
  • Content Security Policy headers
  • Role-based access control (RBAC) for administrative functions
  • Rate limiting on public endpoints
  • Data audit trails for all record operations

Our platform is architected in anticipation of SOC 2 Type 2 and HIPAA compliance standards.

6. Data Synchronization

When you use the Pharus iOS or Android app while signed in, your purpose logs, journal entries, media, and associated metadata are synchronized to the Pharus platform via our REST API. This synchronization ensures that:

  • Your data is backed up on our servers and not lost if your device is lost or damaged
  • You can access your data across multiple devices
  • Aggregated research insights can be generated from de-identified data

The Harbor voyage archive and a few playful in-app records are intentionally kept only on your device and are not synchronized.

7. Third-Party Services

We use the following third-party services to operate Pharus:

Service Provider Purpose Data Shared
Auth0 Okta, Inc. User authentication (OAuth 2.0 / OIDC) Email, name, profile picture
Sign in with Google Google LLC Optional sign-in method Google returns your basic profile to us; we send Google nothing but the sign-in request
Sign in with Apple Apple Inc. Optional sign-in method Apple returns your name and (relay) email to us; we send Apple nothing but the sign-in request
Firebase Cloud Messaging Google LLC Push notifications to Android devices FCM device token, notification content
Apple Push Notification service Apple Inc. Push notifications to iOS devices APNs device token, notification content
App Store and Google Play billing Apple Inc. / Google LLC Premium subscription purchases Apple or Google send us subscription status; we receive no payment details
Heroku Salesforce, Inc. Application hosting and database All server-side account and purpose data resides on Heroku infrastructure
Amazon S3 Amazon Web Services, Inc. Private media storage Photos, videos, voice memos, drawings, avatars, and Crew cover images
Mixpanel Mixpanel, Inc. Product analytics and (web only) sampled session replay Pseudonymous user ID (your login), email, display name, event names and properties, device/client metadata, IP-derived approximate location

Each of these providers processes data on our behalf under its own terms and receives only the minimum data necessary to perform its function.

8. How We Share Information

We do not sell, rent, or trade your personal information. We share personal data only:

  • With the service providers listed in Section 7, who process it on our behalf and may not use it for their own purposes
  • With other Pharus users, only for content you deliberately post to a Crew, global chat, an Explore Card, or a Community Project
  • With law enforcement or regulators when required by law, subpoena, or court order, or to protect the rights, safety, or property of our users or the public
  • With a successor entity if House Lawlez is involved in a merger, acquisition, or asset sale, in which case this policy continues to apply

Aggregated, de-identified statistics that cannot reasonably be linked to you may be published or shared for purpose research.

9. Cookies and Web Technologies

The Pharus website uses the following cookies and web technologies:

  • CSRF token cookie — a security cookie used to prevent cross-site request forgery attacks. This is a technical cookie required for secure operation and does not track you.
  • OAuth session tokens — used to maintain your authenticated session. These are removed when you sign out.
  • Analytics cookies — set by Mixpanel to recognize the same browser across visits, as described in Section 2.9.

We do not use advertising cookies, social media tracking pixels, or any form of cross-site tracking. We do not participate in real-time bidding or ad exchanges.

10. Data Retention and Deletion

We retain your data as follows:

  • Account data — retained for as long as your account is active
  • Purpose logs, journal entries, and media — retained for as long as your account is active, unless you delete individual entries
  • Crew messages and comments — retained while the Crew or card exists; messages you delete are removed from view immediately
  • Audit records — retained in accordance with our compliance requirements (minimum 7 years for certain regulated data)
  • Push notification tokens — retained until you uninstall the app or revoke notification permissions
  • Analytics data — retained by Mixpanel under its standard retention period, or until you ask us to delete your profile

You can delete your account from inside the app (Profile → Delete Account) or, if you have uninstalled the app, by submitting the form on our account deletion page. We delete or anonymize your personal data within 30 days, except for audit records required by law or regulatory obligations. The deletion page lists exactly what is deleted and what is retained.

11. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you
  • Correction — request that we correct inaccurate data
  • Deletion — request that we delete your personal data
  • Portability — request a machine-readable export of your data
  • Restriction — request that we limit how we process your data
  • Objection — object to specific types of processing
  • Withdraw consent — revoke previously granted consent at any time, including by disconnecting your Google Account from Pharus at myaccount.google.com/permissions

To exercise any of these rights, please contact us at contact@houselawlez.com. We will respond to your request within 30 days.

12. Children's Privacy

Our Services are not directed to children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, please contact us immediately at contact@houselawlez.com and we will promptly delete the information.

13. International Data Transfers

Our servers are located in the United States. If you access our Services from outside the United States, your information may be transferred to, stored, and processed in the United States. By using our Services, you consent to such transfer. We take appropriate safeguards to ensure your data is treated securely and in accordance with this Privacy Policy regardless of where it is processed.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Effective Date" at the top of this page. For significant changes, we will provide prominent notice through the Services (such as an in-app notification or a banner on the website). Your continued use of the Services after any changes constitutes acceptance of the updated policy.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

We are committed to resolving any concerns about your privacy and our collection or use of your personal data.

Pharus

Data Platform