Project Me asks you to be honest about how you feel. That only works if you can trust what happens to what you share. This page says, plainly, what we collect, why, where it lives, and how to get rid of it. Project Me is run by Libni (“we”, “us”), and you can reach us at hello@libni.co.
| What | Why | Where it lives |
|---|---|---|
| Your email, and first name if you give it | To create your account, send your welcome and password emails, tell you about renewals, new practices, and the monthly call | Firebase (Google) and our email/CRM tool |
| Membership status and payment dates (not card details) | To know whether your membership is active, when it renews, and when to send a receipt or a lapse reminder | Firebase, Xendit |
| Your payment method details | To charge your membership. We never see or store these. Xendit handles them under its own privacy policy. | Xendit only |
| Your journal entries | So you can come back to them. Nothing else. | Firebase, under your own account |
| Your saved practices and listening history | To show your “Saved” and “Recent” lists | Firebase, under your own account |
| Basic technical data (browser type, rough region, error logs) | To keep the app working and fix bugs | Netlify, Firebase, Google Cloud |
Journal entries are stored under your own user account, and the database rules only allow your login to read them. Libni cannot open your journal from the Studio. We do not read journals, scan them, use them for marketing, or feed them to any AI system. The only way anyone sees an entry is if you show them.
We don't sell your data, rent it, or share it with advertisers. We don't run ad tracking pixels on the site or in the app.
The app uses Firebase's sign-in cookies and local storage so you stay logged in and so we remember small preferences (like whether you've dismissed the “add to home screen” tip). The website sets no cookies of its own. Xendit's checkout page uses its own cookies under its own policy.
Your account, journal, saves, and history stay as long as you're a member, and for 12 months after your membership ends in case you come back. After that we delete them. Payment and membership records are kept as long as accounting law requires. You can ask us to delete everything sooner at any time.
Under the Philippine Data Privacy Act of 2012 you also have the right to object to processing, to data portability, and to lodge a complaint with the National Privacy Commission. We'd rather hear from you first so we can fix it.
Memberships are for adults (18+). Some practices are labelled “for the kids” and are meant to be played by a parent or guardian for their own children. We don't knowingly collect any information from children.
Sign-in is handled by Firebase Authentication. Database rules restrict every piece of personal data to the account it belongs to, and payment webhooks are verified with a secret token. No system is perfectly secure, so if we ever discover a breach affecting your data we'll tell you promptly and honestly.
If we change this policy in a way that matters, we'll email members before it takes effect. The date at the top always tells you the current version.
Libni · hello@libni.co