Privacy policy
Return to You — "Return" for short, here and everywhere in the app — is built by an independent developer. Return has no account system and runs no advertising or analytics. This page describes exactly what the app does with information, and it is written to match what the app actually does — if you ever find a gap between the two, that is a bug, and you can write to support@returntoyou.app.
The short version
- No account — there is nothing to sign up for and no profile to delete.
- No ads, no trackers, no cookies — including on this website.
- Your conversation with Return resets on its own each day.
- Your name, intentions, journal, and API key are encrypted on your device.
- Check-in timing stays on your phone unless you choose to share it.
What Return's servers collect
Nothing about you. Return has no account system, no analytics, and no advertising, and nothing you write is ever stored on a Return server. Three features contact a Return server — each is optional, each is anonymous, and you can turn any of them off:
Invite-code AI access
If you use a Return invite code instead of your own API key, your requests pass through Return's server (api.returntoyou.app) on the way to Anthropic. That server records only anonymous metadata — a one-way hash of your invite code, a count of tokens used, and basic request metadata (the model asked for and the response status) — so the shared budget stays fair. It never logs or stores the content of your messages, and the request body is never written down.
The shared pause lines
Return checks about once a week for the shared set of written pause lines. The set is not written fresh each week and it is not written for you — it accumulates, gathering new lines as they are written and reviewed, and everyone using Return draws from the same one. With an API key or invite code this check is on by default; with no key, Return stays fully offline unless you turn it on. Either way the request carries no account, no identifier, and nothing about you — it is an anonymous download of writing, not an exchange. Turning it off deletes the downloaded lines from your phone.
Sending diagnostics
If something goes wrong and you choose to send a diagnostic report, the app uploads a short technical record — the app version, a recent error log, and the state of Return's background service, plus basic device info (make, model, Android version, language, region). It also carries a summary of how you have been using Return — how many pauses you held or waved past, how your wind-down has been moving, and the app's own reading of whether it is being leaned on. Counts and rates only, never a word of what was said. This technical record carries no conversation content. You can see the entire report before you send it. The record on the server is kept for at most 90 days. Nothing here is sent unless you send it — there is no automatic reporting, and a crash on its own uploads nothing. Of the reports you do choose to send, those about a crash are also emailed to the developer so they are not missed; that copy lands in an ordinary mailbox and is not covered by the 90 days. A report whose wording suggests distress sends only a notice that one arrived — the writing itself stays in the 90-day record and is read there.
Feedback is separate: if you choose to flag a line and send a note about it, you can also choose to attach a few lines of that conversation so the note makes sense. When you attach them, those lines are sent and kept the same way — you see exactly what goes, and nothing is attached unless you add it.
What is sent to the AI when you use it
When you use a check-in or reflection, Return sends to Anthropic's servers: that you opened one of the apps you chose (never which app, and never what kind of app — the pause has to be about something happening, and that is the whole of what is said about it), a rough part of the day (never the clock time of your visits, and never how long you were in an app), the country the phone is in (never anything finer — it exists so crisis lines match where you are), your name if you added one, your intention if you have written one, and the sleep care you chose, if you set one. During the evening wind-down, the unplug time you chose is included. And when a check-in follows a recent conversation, a line you wrote earlier may ride along so the thread can continue.
This goes to Anthropic either directly under your own API key, or, if you are using an invite code, through Return's server under Return's key (metadata-only, as above). In both cases Anthropic handles it under Anthropic's privacy terms. Nothing is sent when AI features are off.
What stays on your device
- Your API key — stored in the Android Keystore.
- Your name and written intentions — encrypted.
- Your journal — encrypted entry by entry, so the plain text never touches storage, and behind your device lock if you switch that on. It is never sent anywhere, and the AI cannot read it: no part of Return that talks to Anthropic is permitted to touch the journal, and a test in the build fails if that ever stops being true.
- Your conversation — reset automatically each day, and clearable at any time.
- Local check-in timing — kept on the phone and deletable in Settings.
One thing worth saying out loud: Return does keep a small local timer — it is how the app knows when to offer a pause and when a visit has ended, and part of how it notices its pauses becoming less needed. That timing is part of how Return works, and it stays on your phone unless you choose to send a diagnostic report — which carries a summary of it, as described above.
Deleting your data
Settings → Privacy and data holds a reset that removes your conversation, intentions, chosen apps and settings. Your journal has its own delete on the same screen, and your key stays unless you remove it — both spared on purpose, both listed on the data deletion page. Uninstalling removes everything at once — which is why the same screen can save a backup: a single file, sealed with a passphrase you choose, written wherever you point it. You can also let Return write one automatically, about once a day — for that it keeps your passphrase on the phone, so it can seal the file while you are not there. Return never sends the file, stores it, or holds a copy. If the folder you pick syncs to a cloud service, your journal goes there too, and where that file goes afterwards is yours to decide. Because Return has no account, there is nothing tied to you on a server to delete, and Google Play's account-deletion requirement does not apply — no account can exist in the first place. The small server-side exceptions — a diagnostic report or a flagged line you chose to send, or an invite code's anonymous usage hash — and how to have either removed are on the data deletion page.
Children
Return is not directed at children and is intended for adults.
Where this applies
Return is made in Québec and follows Québec's Law 25 and Canada's PIPEDA. Because the app collects no personal information by default and sets no cookies, there is no cookie banner — the absence is the compliance. Visitors from the EU and elsewhere are covered by the same simple fact: nothing about you is collected unless you turn on one of the optional features above.
Changes
If this policy changes, the effective date at the top changes with it, and the previous wording stays in the site's version history.
← Return homeContact: support@returntoyou.app · Français