TwoMins - Privacy Policy
Effective Date: 2026-07-29
Last Updated: 2026-07-29
This Privacy Policy applies to the TwoMins mobile application ("Application") and any related services operated by Sniku ("Service Provider", "we", "us", or "our"). TwoMins is a 2-minute micro-journaling and mood tracking app that helps users capture daily mood, energy, and stress check-ins through quick, lightweight daily entries.
By downloading or using TwoMins, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, please do not use the Application.
For questions or concerns, contact us at: twominsapp@gmail.com
Account Information
When you create an account, we collect your email address and display name. You may sign in using Email and Password or Google Sign-In. Guest mode is also available, allowing you to use the app fully without creating an account. In guest mode, all data remains stored locally on your device only.
Daily Check-In Data
The core of TwoMins is your daily 2-minute check-in. This includes mood scores on a 1 to 5 scale, energy level ratings, stress level ratings, short personal text notes, and any custom tags you choose to add.
Voice Journal Entries
You may optionally record short voice entries as part of your daily check-in. Voice recordings are stored exclusively on your device and are never transmitted anywhere. See Section 4 for full details.
Profile Information
This includes any profile photo and display name preferences you choose to set within the app.
Reflections and Prompts
Any responses to guided reflection prompts or evening reset entries you complete within the app.
Device Information
We collect basic device information including device model, operating system version, and app version to ensure compatibility and stability.
Usage Data
We collect information about how you interact with the app, including which features you use, session duration, and time spent in the app. This helps us improve the experience over time.
Network Information
Your IP address is collected at the time of Firebase authentication to support secure sign-in.
Crash and Diagnostic Data
If the app crashes or encounters an error, Firebase Crashlytics collects crash logs, device model, and OS version to help us identify and fix issues quickly.
We do not collect your location data, contacts, calendar information, or biometric data of any kind. We do not collect raw audio files from your device. We do not collect any data beyond what is described in this Privacy Policy.
We use this information to provide the core features of the app, including mood tracking, journaling, and data organization.
Data Used: Mood scores, journal entries, tags
Legal Basis: Contract / Legitimate Interest
Data Used: Email address, Google credentials
Legal Basis: Contract
This information is used to create and secure your account and allow you to log in safely.
Data Used: Encrypted journal entries, mood scores
Legal Basis: Consent
If you enable cloud backup, your encrypted data is securely stored in the cloud. You can disable this feature at any time.
Data Used: Anonymized mood scores and redacted journal notes
Legal Basis: Consent
If you choose to use AI-powered insights, we process anonymized and privacy-filtered data to generate emotional trends and summaries.
Data Used: Notification preferences
Legal Basis: Consent
We use your notification settings to send reminders. You can turn reminders off at any time in your settings.
Data Used: Crash logs, device information
Legal Basis: Legitimate Interest
We process limited technical data to maintain app performance, fix bugs, and improve stability.
Data Used: IP address, authentication tokens
Legal Basis: Legitimate Interest
We use this information to protect accounts, prevent unauthorized access, and ensure platform security.
We do not use your data for advertising, profiling for third-party marketing, or sale to any third party.
TwoMins uses Google Gemini 1.5 Flash AI to generate weekly and monthly emotional insight reports. These reports identify patterns across your mood, energy, and stress inputs to provide personalized wellness summaries.
Only the following anonymized data is transmitted to Gemini for processing:
Numerical mood scores (1–5 scale)
Numerical energy level scores
Numerical stress level scores
Text journal notes — automatically screened to remove personally identifiable information before transmission
Before any text is sent to Gemini AI, our sanitization system automatically redacts:
Email addresses → [REDACTED_EMAIL]
Phone numbers → [REDACTED_PHONE]
URLs and web links → [REDACTED_URL]
Personal names → [REDACTED_NAME]
Street addresses → [REDACTED_ADDRESS]
Text notes are also truncated to 1,000 characters maximum to prevent excessive data transmission.
Voice recordings or audio files of any kind
Your name or email address
Your Firebase User ID or device identifiers
Raw unfiltered personal text
Any data from users who have disabled AI features
First Use: Before generating your first AI report, an in-app consent dialog clearly explains what data will be processed
Opt-Out: AI Insights can be disabled at any time via Profile → Settings → AI Features & Insights
When Disabled: All your data remains 100% on-device; no data is sent to Gemini
Re-Enable: You can re-enable AI features at any time from the same Settings toggle
Consent Withdrawal: Disabling the toggle constitutes withdrawal of consent for AI processing
Data transmitted to Gemini AI is subject to Google's AI terms:
https://ai.google.dev/gemini-api/terms
TwoMins allows you to record personal 2-minute voice journal entries. Audio data is handled with the highest level of privacy:
All voice recordings are stored exclusively in your device's private internal application storage (sandboxed filesystem)
Audio files use your device's private filesDir — inaccessible to other apps
Voice recordings and audio files are never:
Uploaded to Firebase Firestore or any cloud server
Sent to Google Gemini or any AI service
Transmitted to the Service Provider
Accessible to any third party under any circumstances
Real-time voice transcription uses Android's on-device speech recognition only. No audio is sent to external servers for transcription.
Your voice recordings are permanently deleted when:
You manually delete a voice entry within the app
You use "Clear All Data" in Profile Settings
You delete your account (see Section 8)
You uninstall the Application from your device
TwoMins processes daily check-in information including mood scores, energy ratings, stress levels, and personal text notes. While this is not medical or clinical data, we recognise it is personal in nature and apply the following protections.
All check-in and mood tracking data is stored in an encrypted local database on your device using Room Database. This data never leaves your device unless you explicitly choose to enable cloud backup.
Cloud backup is entirely optional and is not enabled by default. If you choose to enable cloud backup, your journal entries and check-in scores are encrypted using AES-256-GCM encryption with a hardware-backed Android Keystore key before any data is transmitted. Encrypted data is then uploaded to Firebase Firestore. The Service Provider cannot read your encrypted entries because only your device holds the decryption key. You can disable cloud backup at any time via Profile Settings.
Only anonymized numerical scores and PII-redacted text notes are processed by Gemini AI for insight generation. Please refer to Section 3 for complete details on what is and is not shared with AI.
Processing of your check-in and mood tracking data is based on your explicit consent, which you provide by creating journal entries and enabling optional features such as cloud backup and AI Insights. You may withdraw consent at any time as described in Section 9.
We implement multiple layers of technical and organizational security measures to protect your data.
Method: AES‑256‑GCM encryption using Android Keystore
Scope: On‑device database
All data stored locally on your device is encrypted using industry‑standard AES‑256‑GCM encryption. Encryption keys are securely managed using the Android Keystore system.
Method: AES‑256‑GCM client‑side encryption
Scope: Before upload to Firebase Firestore
When cloud backup is enabled, your data is encrypted on your device before being transmitted to cloud storage.
Method: TLS 1.3
Scope: All network communication
All data transmitted between your device and our servers is protected using TLS 1.3 encryption.
Method: AES‑256 encryption (Google Cloud managed)
Scope: Firebase Firestore servers
Data stored in Firebase Firestore is encrypted at rest using Google Cloud’s AES‑256 encryption standards.
Method: PII redaction and anonymization
Scope: Gemini API calls
Before any data is processed for AI insights, personally identifiable information (PII) is removed or anonymized to protect your privacy.
Method: Private app sandboxing
Scope: Device filesystem
Audio recordings are stored within the app’s private sandboxed storage area and are not accessible by other applications.
Encryption keys are stored in the Android Hardware KeyStore — a secure hardware enclave on your device. Keys never leave the secure hardware environment and cannot be extracted by any software, including TwoMins itself.
The Application communicates with external services using encrypted HTTPS connections. API credentials are never hardcoded in the Application and are restricted by package name and SHA certificate fingerprint.
While we implement industry-standard security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security but are committed to protecting your data using best available practices.
TwoMins uses the following third-party services. Each has their own Privacy Policy governing their data handling:
Purpose: User account creation, Email/Password and Google Sign-In
Data Shared: Email address, display name, authentication tokens
Purpose: Optional encrypted cloud backup of journal data
Data Shared: AES-256 encrypted journal entries, mood scores, and timestamps
Note: Data is encrypted before upload — Firebase cannot read your entries
Purpose: Weekly and monthly emotional insight report generation
Data Shared: Anonymized numerical scores and PII-redacted text notes only
Note: Audio, names, emails, and user IDs are never shared
Purpose: Crash reporting and app stability monitoring
Data Shared: Crash logs, device model, OS version, app version
Purpose: App distribution, updates, and Android platform services
The Service Provider does not sell, rent, or trade your personal data to any third party for commercial purposes.
TwoMins provides complete account and data deletion directly within the app:
Open Profile → Settings
Select "Delete Account & Data"
Re-authenticate to confirm your identity
All data is permanently and immediately deleted:
When you request account deletion, we permanently remove your data as described below:
Action: Permanently deleted
Your Firebase Authentication account and associated login credentials are permanently removed.
Action: Permanently deleted
All documents stored in Firebase Firestore related to your account are permanently erased.
Action: All tables cleared
All locally stored data within the app’s Room database is fully deleted from your device.
Action: Recursively deleted
All stored audio recordings and related files are permanently removed from your device storage.
Action: Permanently wiped
Temporary and cached files are deleted to prevent data remnants.
Action: Completely cleared
All saved app settings and preferences are reset and removed.
This process is immediate and irreversible.
Before deleting your account, you can export a complete backup of your journal data via Profile → Export Data (JSON format).
You may also request deletion by contacting twominsapp@gmail.com Email requests will be processed within 30 days as required by applicable law.
Individual journal entries, voice recordings, and check-in logs can be deleted at any time from within the app without deleting your entire account.
Depending on your location, you may have the following rights regarding your personal data:
Access: Request a copy of your personal data
Correction: Request correction of inaccurate data
Deletion: Request deletion of your personal data (see Section 8)
Export: Download your data in JSON format via Profile → Export Data
Opt-Out: Disable AI features, cloud backup, or notifications at any time in Settings
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the right to:
Data portability — receive your data in a structured, machine-readable format
Restriction of processing — request we limit how we use your data
Object to processing — object to processing based on legitimate interests
Withdraw consent — at any time, without affecting prior processing
Lodge a complaint — with your local data protection supervisory authority
If you are a California resident, you have the right to:
Know what personal information is collected about you
Know whether your personal information is sold or disclosed and to whom
Opt out of the sale or sharing of personal information
Request deletion of your personal information
Non-discrimination for exercising your CCPA/CPRA rights
We do not sell personal information. To exercise your California rights, contact: twominsapp@gmail.com
To exercise any of the above rights, contact us at twominsapp@gmail.com. We will respond within the timeframe required by applicable law (generally 30 days, extendable to 60 days where permitted).
TwoMins requests the following device permissions:
Our app requests certain permissions only when necessary to provide specific features. We request permissions contextually and only when you use the related feature.
Purpose: Voice journal recording
When Requested: Only when you tap “Start Recording” in the Voice Journal feature
This permission allows the app to record audio entries for your journal. Recording does not occur without your active action.
Purpose: Daily check‑in and reflection reminders
When Requested: During reminder setup
This permission allows us to send optional reminders. You can disable notifications at any time in your device settings.
Purpose: Firebase authentication, optional cloud backup, and Gemini AI insights
When Requested: At app launch
This permission enables secure communication with authentication services and optional cloud features.
Purpose: Precise daily reminder scheduling
When Requested: When reminders are configured
This allows reminders to trigger at the exact time you select.
Purpose: Profile photo selection from your gallery
When Requested: When you change your profile photo
This permission allows you to select an image from your device gallery. The app does not scan or access other media files.
Permission principles:
Permissions are requested only at the point of relevant action — never pre-emptively
Core journaling features work without microphone or cloud permissions
All permissions can be revoked at any time via Android Settings
We retain your data only for as long as necessary to provide the app’s services or comply with legal obligations. Retention periods vary depending on the type of data:
Retention Period: Until deleted by you or the app is uninstalled
Your journal entries remain stored locally on your device unless you manually delete them or remove the app.
Retention Period: Until account deletion or backup is disabled
If cloud backup is enabled, your encrypted data is stored until you delete your account or disable the backup feature.
Retention Period: Until account deletion
Your authentication details are retained as long as your account remains active.
Retention Period: Until manually deleted or account deleted
Audio files remain stored locally until you delete them or remove your account.
Retention Period: Up to 90 days
Technical crash reports are retained temporarily to help diagnose and fix stability issues.
Retention Period: Up to 24 months
Aggregated and anonymized analytics data may be retained to improve app functionality and user experience.
Retention Policy: Not retained by TwoMins
TwoMins does not store AI prompts. Processing and retention are governed by Google’s AI and Gemini API terms and policies.
Upon account deletion, all personal data is removed immediately from our systems. The Service Provider does not retain copies of your personal journal data beyond what is necessary to provide the service.
The Service Provider and its third-party service providers (Firebase, Google Gemini) may process your data in countries outside your country of residence, including outside the European Economic Area (EEA).
Where applicable law requires safeguards for international transfers, we rely on:
Standard Contractual Clauses (SCCs) approved by the European Commission
Adequacy decisions recognized by applicable regulatory authorities
Google's Data Processing Terms which include appropriate transfer mechanisms
For more information about Google's international transfer safeguards:
https://privacy.google.com/businesses/gdprcontrollerterms
TwoMins is not intended for children under 16 years of age, or such higher age as required by applicable law in your jurisdiction.
The Service Provider does not knowingly collect personally identifiable information from children under 16. If you are a parent or guardian and believe your child has provided personal information to TwoMins, please contact us immediately at twominsapp@gmail.com and we will promptly delete such information from our systems.
Where parental or guardian consent is required under applicable law (such as COPPA in the United States for users under 13), the Application is not intended for use without that consent.
The Application itself does not use browser cookies. Third-party SDKs integrated into TwoMins (Firebase, Crashlytics) may use device identifiers and similar technologies to support functionality, analytics, and service delivery.
Where required by applicable law, the Service Provider will obtain consent before using non-essential tracking technologies.
In the event of a data breach that affects your personal data, the Service Provider will:
Notify affected users in accordance with applicable legal requirements
Inform relevant supervisory authorities where legally required (e.g., within 72 hours under GDPR)
Provide information about the nature of the breach and steps taken to address it
Communicate recommended actions you can take to protect yourself
Notifications will be sent to the email address associated with your account.
The Service Provider may update this Privacy Policy from time to time to reflect changes in the Application, legal requirements, or industry practices.
For material changes, we will:
Post the updated policy with a new effective date
Notify you via in-app notification or email where required by law
Where required, seek your consent before changes take effect
Previous versions of this Privacy Policy are available upon request by contacting twominsapp@gmail.com
Continued use of the Application after the effective date of any changes constitutes acceptance of the updated policy, to the extent permitted by applicable law.
Where processing is based on consent, you provide that consent by:
Creating an account and using TwoMins features
Enabling optional features such as cloud backup or AI Insights
Agreeing to the in-app AI consent dialog before first use of Gemini features
You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. To withdraw consent:
AI Features: Toggle off via Profile → Settings → AI Features & Insights
Cloud Backup: Toggle off via Profile → Settings → Cloud Backup
Notifications: Toggle off via Profile → Settings → Reminders
Full withdrawal: Delete your account via Profile → Settings → Delete Account & Data
For any questions, concerns, or requests regarding this Privacy Policy or your personal data:
Service Provider: Sniku
Email: twominsapp@gmail.com
Response Time: Within 30 days of receipt
For urgent data protection matters or to report a suspected data breach, please mark your email subject line as "URGENT — Data Protection" for priority handling.
This Privacy Policy is effective as of 2026-07-29
TwoMins — Your 2-minute daily journing companion