The Become Company
Privacy Policy
Last updated 12 August 2026
Become is a personal growth, journalling and identity practice operated by The Become Company, founded and run by Niamh Dee. This policy explains what we collect, why we collect it, and what you can ask us to do with it.
What you write inside Become is personal. We treat it that way. We do not sell your information, and we only share the content you write with service providers when it is necessary to provide the features you use, such as generating your Coach messages.
Who we are
The Become Company operates Become and is responsible for how your personal information is processed. Niamh Dee is the founder and the person responsible for how your data is handled. You can reach us at niamh@thebecomeapp.com.
What we collect
- Account information. Your email address, and your name if you sign in with Google or provide one. If you sign in with Google we receive your basic profile details, never your Google password.
- Your Identity Profile and check-ins. Your vision, identity statements, Core 5, daily ratings, evidence and written reflections.
- Coach conversations. The messages generated for you and any replies you send.
- Membership information. Your subscription and trial status. Card details are handled by Stripe and never reach our servers.
- Basic technical information. Your time zone, and standard log data such as request timestamps that our hosting and database providers record to keep the service running and secure.
Why we collect it
- To create and secure your account and sign you in.
- To save your Identity Profile and check-ins so they are there tomorrow and on your other devices.
- To generate your Coach messages.
- To manage trials, memberships and payments.
- To send you the emails you signed up for, including your welcome sequence and reminders at a sensible hour in your own time zone.
We rely on the contract with you to run the service, your consent for marketing emails, and our legitimate interest in keeping Become secure and working.
How your journal and coaching data is handled
Your Identity Profile, check-ins and reflections are stored against your account and are accessible through your signed-in account. When you use AI-powered features, relevant content is sent to our AI service providers as described below. Before you create an account, your work is kept locally in your own browser.
To provide AI-powered features such as Coach messages and Core 5 suggestions, relevant parts of your Identity Profile and recent check-ins are sent, for that single request, to the AI gateway provided by our hosting platform, which passes the request to a Google Gemini model. We do not use your content to train any model ourselves, and we do not sell or publish it. Coach messages are guidance for personal reflection, not therapy, medical, legal or financial advice.
We do not read your journal entries as a matter of course. We may access account data only where it is necessary to fix a fault you have reported or to meet a legal obligation.
Third parties we use
- Google Sign-In. Optional authentication. We receive your email address and basic profile.
- Supabase. Database and authentication. This is where your account and entries are stored.
- Stripe. Payments, subscriptions and trials. Stripe processes your card details directly.
- Kit. Email delivery for the welcome sequence and reminders. Kit receives your email address, your first name, a reminder date and time calculated from your browser time zone, and lifecycle tags such as whether you have completed a check-in.
- Lovable AI gateway and Google Gemini models. Used to generate Coach messages and Core 5 suggestions from the content you have written.
- Lovable. Hosting and infrastructure used to serve the site and run the application.
These providers process personal information as necessary to provide the services described above. Their own privacy policies and terms may also apply to their processing.
Where your data is processed
Our providers are global businesses, so your information may be processed outside your own country, including in the United States. Stripe states that it may transfer personal data to countries other than your own, including the United States and India. Google states that it maintains servers around the world and that your information may be processed on servers outside the country where you live, and Google's data processing terms allow customer data to be processed in any country where Google or its subprocessors maintain facilities, which covers the Gemini models used for AI features. Lovable is based in the United States and may transfer personal data to the United States or other jurisdictions. Kit is based in the United States. Supabase hosts each project in a single primary region within a broader area, and does not guarantee a specific country unless a specific region is chosen.
We do not publish a closed list of countries, because these providers do not publish one either. Where transfers happen out of the EEA, the UK or Switzerland, we rely on the transfer safeguards those providers publish for their own services, such as standard contractual clauses, the UK addendum and, where applicable, their certification under the EU to US and Swiss to US Data Privacy Framework.
Data retention
We keep your account and entries for as long as your account exists, because the value of Become is in looking back over time. If you ask us to delete your account, we remove your Identity Profile, check-ins and Coach history from the live database. Copies may persist for a short time in our providers' routine backups until those backups age out. Billing records held by Stripe are kept under Stripe's own retention practices. We do not currently operate a fixed retention schedule beyond this.
Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to certain processing, ask for it in a portable format, and withdraw consent for marketing at any time. Every marketing email includes an unsubscribe link. To exercise any of these rights, email us. We aim to respond within 30 days.
Security
Access to your entries is restricted to your own signed-in account through row level security rules on our database. Data is encrypted in transit over HTTPS. No service can promise perfect security, but we take this seriously and keep our dependencies current.
Children
Become is not intended for anyone under 16. We do not knowingly collect information from children.
Changes to this policy
If we change this policy we will update the date at the top, and tell you by email if the change is significant.
Contact
The Become Company, attention Niamh Dee. Email niamh@thebecomeapp.com.