Effective Date: September 18, 2026
Welcome to Pharus, operated by House Lawlez LLC ("House Lawlez," "we," "us," or "our"). This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use:
com.houselawlez.purpose)
purpose.houselawlez.com, which serves as the app's home
page, its account and data back end, and an administrative console
The mobile app was previously named Purpose; you may still see that name in older screenshots, permission prompts, and the Android package name. Together, the app and website are referred to as the "Services." By using any of our Services, you agree to the collection and use of information in accordance with this Privacy Policy.
In short: Pharus is a purpose journaling app. We collect the reflections, purpose ratings, and media you choose to record, the account details needed to sign you in, and limited product analytics. We do not sell your data, we show no advertising, and we do not share your personal data with other companies except the service providers that run the Services on our behalf.
When you create an account or sign in, we collect:
Authentication is managed through Auth0 (Okta, Inc.), a third-party identity provider. We do not store your password. When you sign in, Auth0 verifies your identity and provides us with a signed identity token. Please refer to Auth0's Privacy Policy for details on how they handle your credentials.
Sign in with Google. If you choose to sign in with your Google Account, Google shares your basic profile with us:
your name, email address, profile picture, and a unique Google account identifier. We request only the openid,
email, and profile scopes. We use this information solely to create your Pharus account, sign you in, and
display your name and avatar inside the Services. We do not request or receive access to Gmail, Google Drive, Google Calendar,
Contacts, or any other Google service. Pharus's use of information received from Google APIs adheres to the
Google API Services User Data Policy, including the Limited Use requirements.
Sign in with Apple. If you choose to sign in with your Apple ID, Apple shares your name (on first sign-in only) and either your email address or an Apple-generated private relay address, together with a unique Apple user identifier. We use it for the same purposes described above.
The core function of our Services is to help you track, reflect on, and understand your sense of purpose. We collect:
This information is deeply personal. We treat all purpose and wellness data with the highest level of care and confidentiality. It is never used for advertising or sold to anyone.
Our mobile apps offer multiple journaling modes. Depending on the mode you choose, you may create and store the following types of media:
| Journal Mode | Media Type | Details |
|---|---|---|
| Photo | Images (JPEG, PNG) | Captured using your device camera or selected from your library |
| Video | Video recordings (MOV, MP4) | Captured using your device camera with optional trimming |
| Voice Memo | Audio recordings (M4A/AAC) | Recorded using your device microphone |
| Drawing | Images (PNG) | Created using the in-app drawing canvas (Apple Pencil supported on iOS) |
| Text | Markdown text | Written reflections with rich formatting |
Media is stored on your device and, when you are signed in, uploaded to private cloud storage attached to your account (see Section 5) so it can be restored on a new device and, only if you choose, shared with a Crew. Media you share is visible only to the people you share it with; nothing you record is public by default.
Pharus includes optional social features. If you use them, we collect the content you contribute:
Content you post to a Crew is visible to the other members of that Crew, and content you post in global chat is visible to every Crew member. Your username may be shown alongside it. Moderators, Crew leaders, and our administrators can review reported content.
To deliver push notifications, we collect:
These tokens are unique device identifiers used solely for sending you notifications. They do not reveal your identity, location, or any personal content. You can disable push notifications at any time through your device settings.
Pharus is free to download and offers an optional premium subscription purchased through the Apple App Store or Google Play. Apple or Google processes the payment; we never see your payment card or billing address. We receive and store the subscription status needed to unlock premium features: the product identifier, purchase and expiration dates, renewal state, and an obfuscated transaction identifier. You manage and cancel subscriptions through your App Store or Google Play account.
In accordance with our compliance architecture, we automatically record audit metadata for data operations. This includes who created or modified a record (username), when the action occurred (timestamp), and what data was changed. Moderation actions inside Crews are recorded in an audit log that includes the acting moderator, the target, and the reason given. This audit trail exists for data integrity, security monitoring, and regulatory compliance. It is not used for behavioral profiling or advertising.
We collect in-app analytics and diagnostic information to improve our products. This data includes:
Mixpanel acts as a data processor on our behalf and is contractually prohibited from selling this data or using it for advertising. See Mixpanel's Privacy Policy for additional detail. You can ask us to delete your Mixpanel profile by contacting us at the address in Section 15 or by checking the corresponding box on our account deletion page.
We want to be explicit about what we do not collect:
Our mobile apps request the following device permissions. Each is optional and used only for the stated purpose:
android.permission.CAMERA (runtime-requested)Camera access is never activated in the background. We only access the camera when you explicitly initiate a capture action.
android.permission.RECORD_AUDIO (runtime-requested)Microphone access is never activated in the background. Audio recording begins only when you tap the record button and stops when you tap stop.
We use the information we collect for the following purposes:
We do not use your data for advertising, behavioral profiling, or sale to third parties. These purposes match the data safety disclosures published on our Google Play listing.
Your account and purpose data are stored in a PostgreSQL database hosted on Heroku in the United States. Media files (photos, videos, voice memos, drawings, avatars, and Crew cover images) are stored in a private Amazon Web Services (S3) bucket. Nothing in that bucket is publicly listable; the app downloads media through short-lived, signed links issued only to the account that owns the media or to the members it was shared with. All data transmissions between your device and our servers are encrypted in transit using TLS (HTTPS), and stored data is encrypted at rest by our hosting providers.
We implement the following security measures to protect your data:
Our platform is architected in anticipation of SOC 2 Type 2 and HIPAA compliance standards.
When you use the Pharus iOS or Android app while signed in, your purpose logs, journal entries, media, and associated metadata are synchronized to the Pharus platform via our REST API. This synchronization ensures that:
The Harbor voyage archive and a few playful in-app records are intentionally kept only on your device and are not synchronized.
We use the following third-party services to operate Pharus:
| Service | Provider | Purpose | Data Shared |
|---|---|---|---|
| Auth0 | Okta, Inc. | User authentication (OAuth 2.0 / OIDC) | Email, name, profile picture |
| Sign in with Google | Google LLC | Optional sign-in method | Google returns your basic profile to us; we send Google nothing but the sign-in request |
| Sign in with Apple | Apple Inc. | Optional sign-in method | Apple returns your name and (relay) email to us; we send Apple nothing but the sign-in request |
| Firebase Cloud Messaging | Google LLC | Push notifications to Android devices | FCM device token, notification content |
| Apple Push Notification service | Apple Inc. | Push notifications to iOS devices | APNs device token, notification content |
| App Store and Google Play billing | Apple Inc. / Google LLC | Premium subscription purchases | Apple or Google send us subscription status; we receive no payment details |
| Heroku | Salesforce, Inc. | Application hosting and database | All server-side account and purpose data resides on Heroku infrastructure |
| Amazon S3 | Amazon Web Services, Inc. | Private media storage | Photos, videos, voice memos, drawings, avatars, and Crew cover images |
| Mixpanel | Mixpanel, Inc. | Product analytics and (web only) sampled session replay | Pseudonymous user ID (your login), email, display name, event names and properties, device/client metadata, IP-derived approximate location |
Each of these providers processes data on our behalf under its own terms and receives only the minimum data necessary to perform its function.
We do not sell, rent, or trade your personal information. We share personal data only:
Aggregated, de-identified statistics that cannot reasonably be linked to you may be published or shared for purpose research.
The Pharus website uses the following cookies and web technologies:
We do not use advertising cookies, social media tracking pixels, or any form of cross-site tracking. We do not participate in real-time bidding or ad exchanges.
We retain your data as follows:
You can delete your account from inside the app (Profile → Delete Account) or, if you have uninstalled the app, by submitting the form on our account deletion page. We delete or anonymize your personal data within 30 days, except for audit records required by law or regulatory obligations. The deletion page lists exactly what is deleted and what is retained.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise any of these rights, please contact us at contact@houselawlez.com. We will respond to your request within 30 days.
Our Services are not directed to children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, please contact us immediately at contact@houselawlez.com and we will promptly delete the information.
Our servers are located in the United States. If you access our Services from outside the United States, your information may be transferred to, stored, and processed in the United States. By using our Services, you consent to such transfer. We take appropriate safeguards to ensure your data is treated securely and in accordance with this Privacy Policy regardless of where it is processed.
We may update this Privacy Policy from time to time. When we do, we will revise the "Effective Date" at the top of this page. For significant changes, we will provide prominent notice through the Services (such as an in-app notification or a banner on the website). Your continued use of the Services after any changes constitutes acceptance of the updated policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
We are committed to resolving any concerns about your privacy and our collection or use of your personal data.
Data Platform