AI Babu
InnerGrove Terms
← Back to app
← InnerGrove

Privacy Policy

InnerGrove (by AI Babu) · Last updated 6 August 2026

1. Overview 2. What stays on your device 3. Health & fitness data 4. Information that leaves your device 5. Advertising & consent 6. Purchases & subscriptions 7. Children 8. Security 9. Deleting your data 10. Changes 11. Contact

1. Overview

InnerGrove is a local, privacy-first companion and mental wellness journal published by AI Babu ("we", "us"). It is designed around a strict zero-data profile architecture. This policy explains what information the app processes, what limited information leaves your device, and the choices you have.

The short version: your journal reflections, CBT thought restructuring logs, habit lists, meal logs, and companion chats are processed and stored entirely on your device and are not uploaded to us. The AI companion runs locally on your phone — your writing is never sent to us or to any AI provider for processing, because there is nothing to send it to. There are no user sign-ups, accounts, or profiles, making your local records unlinkable to you.

What does leave your device is limited to: the one-time language-model download, advertising data handled by Google AdMob, subscription validation, and — only if you switch them on — the optional anonymised CBT sharing and geographic matching features described in section 4. None of these ever include your journal entries or your companion chats.

InnerGrove was previously published as "Santuary AI". Only the name has changed; the app, its data handling, and this policy's commitments are otherwise the same.

2. What stays on your device

The following categories of data are processed and stored 100% locally on your device (using encrypted database models) and are never transmitted to us or stored on our servers:

  • Journal entry titles, text contents, and voice recordings;
  • CBT thought records, including descriptions of stressful situations, negative thoughts, and cognitive reframings;
  • Mood entries, average scores, and mapped emotional triggers;
  • Nutrition details, food lists, calories, and macronutrient parameters;
  • Habit trackers, routine lists, resisted urges, and slip trigger logs;
  • Chat histories and conversation transcripts with the local AI companion.

This data remains in the app's local sandbox storage on your device. You can secure this data behind device biometrics (Face ID or passcode) in settings. All local database records are deleted when you delete the app or wipe the vault from the settings page — see section 9 for the exact steps and for what is and is not removed.

3. Health & fitness data

With your permission, InnerGrove reads active energy burned from your device's system health store — Apple Health on iOS and Health Connect on Android — so that it can be shown alongside the meals and moods you log yourself.

  • Access is read-only. The app never writes anything back to Apple Health or Health Connect.
  • The only value read is active energy burned. No workouts, heart rate, sleep, weight, or clinical records are requested.
  • The value is read on your device and used on your device. It is never uploaded to us, never shared with any third party, and never used for advertising or matching.
  • It is displayed in the Food & Energy section of your local analytics and is not written to our servers, because there are no servers holding your journal data.

You can grant or revoke this access at any time in your operating system's health settings — iOS Settings → Health → Data Access & Devices, or the Health Connect settings on Android. The app works without it: the calories-burned figure simply shows no value, and nothing else changes.

4. Information that leaves your device

a) App store and model downloads

To run the companion offline, the app downloads a language model file during initialization. The download is processed by standard content-delivery networks, which may log technical indicators (like IP address and network details) for request delivery and security. This is not used to identify you.

b) Optional "Share Anonymized Journeys" feature

If you choose to opt-in to the Share Anonymized Journeys feature, the app securely transmits your sanitized CBT coping records (specifically the situation description, negative thought, cognitive distortion categories, and reframed thoughts) to our server database. To protect your privacy:

  • All personal identifying tokens (such as specific names, numbers, or emails) are programmatically removed prior to upload.
  • Because InnerGrove does not use user accounts, sign-ups, or profile configurations, these shared records are completely unlinkable to your identity.
  • This data is contributed solely to help other users facing similar struggles find matching reframing examples (Community Coping Echoes).

c) Optional Geographic matched insights

If you opt in to the Geographic Matching feature, the app performs a coarse IP-address-based lookup to prioritise showing matching anonymous reframing logs from users in your region. This lookup is made over an encrypted (HTTPS) connection to a third-party geolocation provider — currently ipwho.is, falling back to geojs.io if it is unavailable — which receives your IP address in order to return an approximate location. Each provider handles that request under its own privacy policy.

IP-based geolocation is only accurate to the city or region, and we further round the returned coordinates to two decimal places before storing or using them, so they identify a general area rather than a neighbourhood or address. No GPS or fine-location permission is requested at any point, and this feature is off unless you turn it on.

5. Advertising & consent

The free tier of the app is supported by ads served through Google AdMob. Google's Mobile Ads SDK may process mobile advertising identifiers, coarse network parameters, ad impressions, and interaction data to serve ads. You can manage your ad consent and parameters in your device's operating system settings.

6. Purchases & subscriptions

If you purchase a Pro subscription, the transaction is handled entirely by Apple (App Store) or Google (Play Store). We never see or store your payment details. We use RevenueCat as our subscription gateway to verify and activate Pro privileges. RevenueCat processes transaction status and device/receipt identifiers under its own privacy policy. We use it solely to grant you access to Pro features — unlimited AI reflections, the spoken companion voice, the full CBT and EMDR toolkit, weekly insights and complete history, encrypted backup and export, removal of ads, and premium themes and avatars.

Pro does not change how your data is handled. Every Pro feature runs on your device exactly as the free ones do; paying does not send us anything more, and not paying does not send us anything less.

7. Children

InnerGrove does not collect or request any personal identifiers. It is not designed to solicit information from children under the age of 13. If you believe any personal data was shared, please contact us.

8. Security

We recommend enabling biometric locks (Face ID or Touch ID) in the app settings to protect your local data vault from unauthorized access. Your database is encrypted using device-level security protocols.

9. Deleting your data

InnerGrove (by AI Babu) has no accounts and no server-side copy of your journal, so there is no request form to fill in and nobody to ask. You delete your data yourself, from inside the app, and it is gone immediately.

To delete everything InnerGrove has stored:

  1. Open InnerGrove and unlock your vault.
  2. Go to Settings.
  3. Scroll to the Security & Data section.
  4. Tap Wipe Encrypted Vault.
  5. Confirm at the warning dialog by tapping Wipe Data.

Uninstalling the app has the same effect: the encrypted database lives in the app's private storage and is removed with it.

What this deletes. Everything you created, permanently and irreversibly: journal entries, AI companion conversations, CBT and EMDR records, mood history, habits, meal and nutrition logs, goals, insights, voice recordings and their transcripts, any health values read from Health Connect or Apple Health, and your app settings and passcode. The records are shredded rather than merely unlinked, and there is no undo and no recovery.

What this does not delete, because it was never in the vault and is not ours to remove:

  • Your purchase record. Your Pro subscription is held by Google Play or the Apple App Store, and its status is mirrored by RevenueCat. Manage or cancel a subscription in your store account; those records are retained by Google, Apple and RevenueCat under their own policies and retention schedules.
  • Crash reports. If the app has crashed, an anonymous diagnostic report may have been sent to Google Firebase Crashlytics. These contain no journal content — see section 4 — and are retained by Google under Firebase's own retention schedule.
  • Advertising identifiers. Ad requests made by the free tier are handled by Google AdMob. Reset or limit your advertising ID in your device's system settings.
  • Backups you exported yourself. If you created a password-encrypted backup file and saved or shared it, that file is yours and stays wherever you put it. Delete it from that location if you no longer want it.

If you have questions about deletion, contact us at hello@aibabu.tech.

10. Changes

We may update this Privacy Policy as features evolve. We will revise the "Last updated" date at the top of this policy and notify you in-app where appropriate.

11. Contact

If you have questions, contact the AI Babu team at hello@aibabu.tech.

← Back to InnerGrove  ·  Terms of Use

© 2026 AI Babu aibabu.tech