WhyMe Privacy Policy
- Version:
- 2.0.0
- Last updated:
- July 28, 2026
- Effective date:
- July 28, 2026
- Contact:
- support@derbywife.com
- Company / legal owner:
- Michel Pierre Suárez Medel / Derby Wife
- Address:
- Bosque del Centenario 30, Fraccionamiento La Herradura, Huixquilucan de Degollado, Municipality of Huixquilucan, State of Mexico, Postal Code 52784, Mexico
This Policy applies to the WhyMe mobile application, its account and synchronization features, related web pages, and the technical services needed to operate it. WhyMe is a personal organization and self-expression tool and is intended only for persons 18 years of age or older.
1. Data controller
Michel Pierre Suárez Medel, an individual operating under the trade name Derby Wife (“Derby Wife,” “WhyMe,” “we,” or the “Controller”), with the address shown above, is responsible for personal data processed in connection with the WhyMe mobile application and related services.
Privacy, support, and data-rights contact: support@derbywife.com. Website: https://www.derbywife.com
2. Scope and nature of the service
This Policy applies to the WhyMe mobile application, its account and synchronization features, related web pages, and the technical services needed to operate it.
WhyMe is a personal organization and self-expression tool that lets users create a profile, customize an avatar, and organize satellites, whys or reasons, and reminders. WhyMe is not a medical, psychological, psychiatric, therapeutic, emergency, or professional advisory service.
WhyMe is intended only for persons 18 years of age or older.
3.1 Account, authentication, and password recovery
We process data needed to operate, protect, and provide the features the user chooses to use. We may process:
- Email address.
- Internal user identifier.
- Account creation date, email confirmation, sessions, and authentication events.
- Account status and security records needed to prevent abuse or unauthorized access.
- Name or display name, only when voluntarily provided.
- Adult-age declaration and accepted legal version.
- Authentication is managed through Supabase Auth. Passwords are stored using cryptographic hashing; Derby Wife does not receive or have access to passwords in readable plain text.
- When a user requests a password reset, Supabase Auth sends an email with a recovery link or flow that may expire. The user is responsible for maintaining access to the associated email. Derby Wife will never ask a user to send a password by email.
3.2 Profile and personalization
- Profile information voluntarily provided by the user.
- Avatar configuration, traits, colors, clothing, backgrounds, accessories, and effects.
- Language, theme, interface, and settings preferences.
- Free or Premium access status.
3.3 User-created content
- Satellites, titles, categories, goals, people, projects, or represented concepts.
- Whys or reasons, notes, emotions, importance levels, favorites, energy, visual position, archived status, and related settings.
- Reminders and their times or recurrence.
- Images or memories only if the installed version offers that feature and the user chooses to use it.
- Users decide what content to enter. Because text may reveal private or sensitive information, users should not enter diagnoses, medical records, passwords, bank information, official documents, intimate information, or third-party personal data without authorization.
3.5 Technical and security data
Depending on actual application and provider operation, we may process:
- IP address and technical data associated with a request.
- Device type, operating system, app version, language, time zone, or regional settings.
- Session, authentication, or user identifiers needed to operate the account and associate purchases.
- Technical and security logs for server requests, access attempts, and essential operational errors.
- WhyMe does not use advertising, advertising identifiers, cross-app tracking, Firebase Analytics, Crashlytics, Sentry, PostHog, or any other analytics or crash-reporting SDK in this release.
3.6 Notifications and reminders
WhyMe may use local reminders when enabled by the user. These reminders are scheduled on the device. This release does not use remote push notifications and does not send a push token to a server.
3.7 Artificial intelligence
The artificial intelligence or Anthropic reflection feature is not enabled in this release. WhyMe does not currently send satellites, reasons, notes, images, or other user content to Anthropic.
If an AI feature is enabled in the future, this Policy and, where applicable, the Google Play declaration will be updated before user content is sent to an AI provider.
4. Sources of data
- Directly from users when they register, create content, or configure the app.
- From the device and application during technical operation.
- From Google Play and RevenueCat regarding purchases and Premium entitlements.
- From providers acting on Derby Wife's behalf for infrastructure, authentication, storage, and technical support.
- We do not buy personal databases. We do not sell, rent, or trade personal data.
5. Purposes of processing
- Create, confirm, authenticate, and manage accounts.
- Enable sign-in and secure password recovery.
- Save and synchronize profiles, avatars, satellites, whys, reminders, preferences, and images where available.
- Provide free and Premium features.
- Validate, associate, restore, and protect purchases.
- Provide support and respond to privacy and account-deletion requests.
- Prevent fraud, abuse, unauthorized access, and security risks.
- Maintain technical availability, diagnose operational incidents, and comply with law.
- Document consent, acceptance of terms, purchases, refunds, disputes, or compliance.
- We do not use private user content for personalized advertising, AI model training, or sale of profiles.
6. Legal grounds and user control
Processing may be necessary to perform the user relationship, comply with legal obligations, protect service security, or act on consent where legally required. Users may:
- Edit or delete content in the app.
- Disable local reminders.
- Withdraw optional permissions through the operating system.
- Request access, correction, deletion, or objection.
- Delete an account in the app or initiate a request on the web.
7. Providers and processors
To operate WhyMe we rely on the following providers, who may process data in Mexico, the United States, or other countries where they operate:
Supabase, Inc. — Active — Authentication, database, storage, and server functions (email, user ID, profile, content, sessions, files, technical logs).
Google Play / Google Play Billing — Active — Distribution and purchase processing (Google account and transaction data managed by Google; WhyMe receives only what is needed to validate access).
RevenueCat, Inc. — Active — Validation, restoration, and Premium entitlement management (user ID, product, purchase history, transaction, and entitlement).
Expo / EAS — Technical infrastructure — Build, technical distribution, or updates (strictly necessary technical metadata).
Anthropic, PBC — Inactive — Future AI feature; receives no WhyMe content in this release.
Derby Wife seeks to limit processing to what is necessary and to use providers acting under applicable instructions, contracts, and safeguards. For Google Play Data Safety purposes, transmissions to Supabase and RevenueCat are treated as service-provider processing when they act solely on Derby Wife's behalf. If a future integration uses data for independent or advertising purposes, the relevant disclosures will be updated.
8. Restoring a purchase
Users may use the Restore Purchase feature available in WhyMe. Restoration attempts to re-sync the purchase from the same Google Play account and retrieve the RevenueCat status. It may depend on using the same Google Play account, the purchase not having been refunded/revoked/invalidated, Google Play and RevenueCat availability, correct WhyMe–RevenueCat association, and project transfer/restore settings.
Deleting the app or signing out does not by itself erase Google Play purchase history. Deleting the WhyMe account is not a refund.
9. Retention
- Account, profile, and content: while the account is active or until deleted by the user.
- Passwords: only as a hash managed by Supabase Auth while the account exists.
- Security records: for a reasonable period needed to investigate abuse, incidents, or unauthorized access.
- Purchases and entitlement: as needed to validate or restore Premium, handle refunds or disputes, prevent fraud, and comply with legal obligations.
- Privacy and deletion requests: as needed to document compliance.
- Blocked data or legal-defense records: for the applicable limitation period, with restricted access and no ordinary use.
- When an account is deleted, data is deleted or de-identified except for minimum information that must be retained for law, security, fraud prevention, accounting, support, purchases, disputes, or legal defense. Backups may require a reasonable additional period to be overwritten and will remain protected and unavailable for ordinary use.
10. Security
- Encryption in transit through HTTPS/TLS.
- Secure authentication and session management.
- Per-user access policies and Supabase Row Level Security.
- Private storage and time-limited file URLs where applicable.
- Separation of secrets from client code.
- Administrative access controls and deletion procedures.
- No system is completely secure. If a breach significantly affects individual rights, we will act under applicable law.
11. Data rights and privacy requests (ARCO)
Users may request access, correction, deletion, or objection (ARCO) by emailing support@derbywife.com. The request should include: name and account email; the right being exercised; a clear description; a method for receiving a response; and reasonable information to verify identity. Do not send passwords; we may request proportionate additional verification to protect the account.
For users in Mexico, we will communicate our determination within the applicable legal period, which may be up to twenty business days, and, if approved, implement it within the following fifteen business days. Those periods may be extended once where legally permitted and justified.
12. Account deletion
Users may initiate deletion in the app (Settings > Account > Delete account) or on the web at https://www.derbywife.com/whyme/account-deletion. Deletion includes, as applicable: the Supabase Auth account, profile and operational email, avatar and visual settings, satellites, whys, notes, favorites, positions and energy, reminders, images or memories (if any), preferences, sessions, and associated data, and the identifiable RevenueCat customer record (except for minimum legitimate retention or a temporary hold required by law, dispute handling, or fraud prevention).
Google Play may retain purchase records under its own policies. Deleting a WhyMe account does not uninstall the app, does not automatically create a refund, does not necessarily erase Google Play transaction history, and may require a new account and use of Restore Purchase to attempt to recover Premium later.
13. Minors
WhyMe is intended for adults aged 18 or older. We do not authorize minor accounts. If we learn that a minor created an account, we may suspend it and delete related data after reasonable verification.
15. Contact
Michel Pierre Suárez Medel / Derby Wife — support@derbywife.com — address as shown above.
