Wren

Privacy policy

Effective 30 September 2026. Last updated 30 September 2026.

Wren is an iPhone app for people living with bipolar. It keeps a record of your days: check-ins, sleep, symptoms, medication and conversations with Wren. That is health information, and this policy says exactly what Wren collects, where it goes and how you delete it.

Wren is made by Blue Door Labs Ltd (company number 17489967), registered office: 212a Great West Road, Hounslow, England, TW5 9AW (“we”). You can reach us about anything in this policy at hello@wrenbipolar.com.

The short version

What Wren collects

Your account

You sign in with Apple. Apple gives us a stable identifier for you, which is how we know it is you next time. We ask Apple for your name only, and you can change or clear the name Wren uses in Settings. We do not ask Apple for your email address and do not store one. When you sign in, Apple also gives us a sign-in token for you; we keep the latest one, use it for nothing else, and hand it back to Apple when you delete your account so that Apple ends Wren’s access to your Apple sign-in. We also keep your time zone, so that each day in your record starts and ends where you are.

Your record

Everything you put into Wren, whether you tap it in, set it from the widget or tell Wren in a conversation:

From Apple Health, if you allow it

Each kind of Health data is its own switch, and nothing is read until you turn one on. The phone works out one finished fact from Health and sends only that:

With each fact we keep Health’s own identifiers for the samples it came from, and for a workout the app that recorded it, so the same night or workout is never filed twice and a deletion in Health can be followed. Health data you connect becomes part of your record, including what Wren can read when you talk to it (see below).

History you bring from another app

If you import a backup from eMoods, Bearable, Daylio or Moodistory, the file is read on your phone. Only the resulting entries are sent to Wren, along with which app they came from, so that importing the same file twice cannot duplicate them.

Conversations with Wren

We keep what you write to Wren, what Wren writes back, and the parts of your record Wren looked up to answer, so the conversation is there when you come back to it.

Notifications

If you allow notifications, we keep your device’s push token, an identifier for this installation of the app, a key your phone uses to unlock message previews, your notification choices, and a list of the notifications we have sent you.

Errors and crashes

Wren sends technical error and crash reports to PostHog in the United States so we can find and fix faults. Before sending, Wren replaces error messages with fixed wording and removes personal and health details, account and device identifiers, notes, conversation content and application state. Reports retain technical code locations and binary information needed to diagnose a fault. Error reports are not linked to your account. Product analytics and masked session recordings are described separately below. PostHog receives the network connection needed to deliver a report; IP addresses are discarded from stored events, and geolocation enrichment and person profiles are disabled.

Product analytics and masked session recordings

Wren sends information about how its features are used to PostHog in the United States: which features are opened, whether an operation starts or finishes, exercise and game starts and ends, notification opens and widget interactions. This helps us understand which parts of Wren are useful and where a flow gets stuck. Each account has a random analytics identifier, shared across its devices. PostHog creates an analytics profile under that identifier; we do not add personal or health information to that profile. The identifier is linked to your account inside Wren, but we do not send your name, email address or Apple sign-in identifier to PostHog.

Analytics excludes the contents of your record, conversations and notes, health answers, medication details, episode judgements, day-card variants and calming ratings. A successful operation tells us that it happened, not the answer you gave. We also send masked session recordings. In this version all screen content and touch coordinates are removed before transmission; recordings retain only a neutral viewport and timing. Technical error recording remains separate.

This collection runs while you use a signed-in account and has no in-app opt-in switch. Our basis for this processing is our legitimate interests in understanding use of the app and improving its reliability and flows, with the content exclusions and masking described above.

PostHog’s published event retention window is one year on its free plan and seven years on paid plans; this window limits queries and is not a promise of automatic deletion. Recordings have a separate 30-day retention period; they may take a short additional time to disappear after expiry. We keep account-linked analytics until it is erased following an account deletion or a valid erasure request; technical reports are not linked to an account.

Contact us using the details in this policy about access, objections or deletion. Signing out stops new account-linked collection on that device; it does not by itself erase previously collected analytics.

What Wren does not collect

Wren does not collect your location, contacts, photos, browsing history or advertising identifier.

How we use it

We use your information only to run Wren for you: to keep and show your record, to draw your charts and the page for your appointments, to answer you in conversation, to send the notifications you have switched on, and to keep your account secure. Product analytics and masked session recordings help us understand feature use and improve flows, as described above. We do not use it for advertising or marketing, we do not sell it or rent it, and we do not use it to build a profile of you for anyone else.

Health data from Apple Health is never used for advertising or data mining, never sold, and never shared with anyone except the service providers below, who handle it only to run Wren for you.

Conversations and AI

Wren’s side of a conversation is written by an AI model from OpenAI. Wren is not a person, a doctor or a therapist, and what it says can be wrong.

During onboarding, Wren asks for your permission before sending personal or health information to OpenAI.

If you give permission, when you write to Wren, and when Wren writes to you first (the daily check-in message, or to say an export is ready), we send OpenAI:

OpenAI processes this as our service provider to produce Wren’s reply. OpenAI does not use API data to train its models by default. OpenAI may keep API content in abuse-monitoring logs for up to 30 days, or longer where legally required. Wren uses the Responses API, which also stores responses for at least 30 days by default. We do not claim zero data retention. Deleting your Wren account does not immediately remove these provider-held copies.

OpenAI also processes conversation text to make it searchable by meaning, and helps summarise conversations and update Wren’s memories and overview. These can contain health information.

Voice recordings you make in the chat are sent to Modulate (United States) only to turn speech into text. Modulate does not store these recordings by default. The text goes into your editable draft.

Episodes, patterns and memories

Wren uses TypeSafe AI’s Jev model to assess episodes and patterns in your record, how item names should read, and proposed conversation summaries, memories and overview changes. It sends the relevant record values or text and questions for that assessment, which can include health information, your name, proposed summary text, recent conversation turns, Wren’s wake-up notes and phrases for your monthly Wrapped recap. TypeSafe’s published policy says it does not train or fine-tune models on these inputs. Its service is hosted in the United States; its policy does not give a fixed retention period.

Who else handles your information

We use these service providers, each only to run Wren:

WhoWhat they doWhat they handle
Convex, Inc.Hosts Wren’s database and server in the United States (Northern Virginia)Everything described above
OpenAIWrites replies, summaries and memories, and makes conversations searchableThe conversation, context and record information described under Conversations and AI
Modulate, Inc.Turns voice recordings into text (United States)The voice recording you make in the chat
TypeSafe AI, Inc.Assesses episodes, patterns, summaries and memories (United States)The relevant health record and text described above
PostHog, Inc.Product analytics, masked recordings, and error and crash diagnosis (United States)The limited usage events, neutral recordings and scrubbed technical reports described above
AppleSign in with Apple, notifications, Apple Health on your phone, and App Store subscriptionsYour Apple sign-in, notification delivery and subscription payments; Apple handles your payment details

We share nothing with anyone else, except where the law requires it (for example a valid court order), to protect someone’s safety in an emergency, or, if Wren is ever transferred to another organisation, with that organisation under the same promises as this policy.

Notifications on your lock screen

What a notification says on your lock screen is always a plain line such as “I’ve left you a message.” Discreet previews are on unless you turn them off. If you turn them off, your phone shows Wren’s actual message instead, which may mention something from your record. That message travels to your phone encrypted, with a key made on your phone and shared only with Wren’s server.

Where it is kept and how it is protected

Your record is stored with Convex in the United States (Northern Virginia) and travels between your phone and Wren over encrypted connections. Convex encrypts customer data at rest using AES-256. Your sign-in is kept in your iPhone’s Keychain on that device only. Authorised people at Blue Door Labs Ltd who operate and support Wren can access stored records when needed to resolve a problem, keep the service secure, fulfil a rights request or comply with the law. Your record is not monitored for medical care or emergencies.

These providers can process your information outside the UK, including in the United States. Overseas transfers must have the safeguards required by UK data protection law, such as an applicable adequacy decision or approved contractual safeguards. Contact us for information about the safeguards for your data.

How long we keep it, and deleting it

We keep your record for as long as you have a Wren account. You can delete everything at any time in Settings, under This account, with Delete everything. That removes your account, your whole record, your conversations and your notification settings from Wren, and asks Apple to revoke Wren’s access to your Apple sign-in, using the token described under Your account. Access to the old account ends immediately. Large records and conversation history are deleted by background jobs; they normally finish shortly afterwards, but there is no fixed completion time. If deletion has not completed, contact us so we can investigate. Account deletion also queues a separate request for us to erase the account-linked events and recordings held by PostHog. A separate background process submits that request automatically when our deletion connection is configured; otherwise we handle it. The automatic process submits a first deletion request after a day and a second about seven days after the first is accepted. Recordings uploaded from an offline device after that second request are not covered by these automatic passes; contact us if further erasure is needed. PostHog processes deletion in the background, so submission is not immediate erasure. Older events collected without an analytics profile require separate handling by us and are not reached by profile deletion.

Deleted information may remain in provider backups until those backups expire. Convex’s downloadable manual and daily backups expire after seven days, and weekly backups after 14 days. Other internal recovery copies follow the provider’s recovery and deletion procedures. OpenAI retention is described above; TypeSafe retains data for as long as needed for its service or other stated business purposes, and we can request erasure. We do not use backup copies to keep running a deleted account. Scrubbed technical error reports are not linked to your account and are not removed by account deletion. Deleting your Wren account does not delete anything from Apple Health. Anything you exported yourself, such as a PDF you shared with your doctor, is yours and stays wherever you sent it.

Apple Weather processes the location your phone sends to provide weather. Apple's privacy policy applies to that service. WeatherKit says location is used to provide weather, is not associated with personally identifiable information, and is not tracked between requests.

If you only want Wren to stop reading Health, switch the stream off in Wren’s Settings, or in the iPhone’s Settings under Health. What was already sent stays in your record until you delete it.

Your choices and rights

You can see and correct the entries in your record inside the app, choose which Health data Wren reads, choose which notifications you get, and delete your account. Settings → Take a copy gives you a zip of spreadsheet files containing everything you gave Wren or chose in it, plus Wren’s stored memories, overview sections and episode spans. Credentials, device tokens and internal bookkeeping are left out. Depending on where you live, you may also have the right to ask us for other information we hold about you, to correct or delete it, to object to or restrict how we use it, to withdraw your consent, and to complain to your data protection authority. Write to hello@wrenbipolar.com and we will normally answer within one month. If the law allows extra time for a complex request, we will tell you within that month and explain why.

Blue Door Labs Ltd is the controller of your information. Under UK GDPR, we use account and service information to perform our agreement with you (Article 6(1)(b)), and rely on your explicit consent to process health information (Article 9(2)(a)). We rely on legitimate interests (Article 6(1)(f)) for limited product analytics, fault diagnosis and security, and legal obligations (Article 6(1)(c)) where required. You can withdraw health or AI permission by contacting us, or delete your account in Settings; withdrawal does not undo processing already carried out. Without health permission we cannot provide features that need your health record. You can object to analytics by contacting us. You can complain to the UK Information Commissioner at ico.org.uk or your local regulator.

If Washington’s My Health My Data Act applies to you, the health information we collect, its sources, purposes and the providers we share it with are described above. We do not sell consumer health data. You can ask to confirm whether we hold it, access or delete it, or withdraw consent to its collection or sharing by emailing us; an authorised agent can make a request for you. If we decline a request, reply to appeal our decision. If the appeal is denied, you can complain to the Washington Attorney General.

Children

Wren is for adults. It is not meant for anyone under 18, and we do not knowingly keep a record for anyone under that age. If you think a child has an account, write to us and we will delete it.

Changes to this policy

If we change this policy, we will update the date at the top. If the change is significant, such as a new kind of information or a new service provider, we will tell you in the app before it takes effect.

Contact

Blue Door Labs Ltd (company number 17489967), registered office: 212a Great West Road, Hounslow, England, TW5 9AW. Email hello@wrenbipolar.com.