Privacy Policy
Version 2026-07-01. This is the version identifier recorded against your consent choice.
The short version: we collect what we need to run the product and to find out which parts of it help. We do not collect the contents of your journal into any analytics system, and we do not send health information to advertising platforms.
What we collect
Things you give us
- Your email address and password. The password is stored as an Argon2id hash and cannot be read back, by us or by anyone with a copy of the database.
- Your content — habits, completions, sleep records, moods and journal entries. This is yours. It is used to draw your screens and compute your statistics, and for nothing else.
- Your timezone and display name, so that “today” means your today and we can address you properly.
Things we observe
- Which pages and features you use, as a stream of named events — a page view, a habit created, a report opened. Never the content of what you wrote.
- How you arrived: the campaign parameters in the link you followed, the site that referred you, and a first-party identifier that lets us connect the visit to the signup.
- Coarse technical context: browser and operating system as broad categories (“Chrome”, “iOS”), country and city, and screen width. We do not store your IP address — only a keyed hash of it, used for rate limiting and for noticing that a session moved.
- Performance measurements from your own session, so we can tell which pages are slow for real people rather than in a lab.
What we never do
- Send journal text anywhere. It is excluded from our analytics pipeline by design — the event recorded when you write carries a word count and nothing else.
- Forward mood or sleep data to Meta, Google or any advertising platform. Their policies may permit some of it; we do not do it.
- Sell your data, or share it with data brokers.
- Use your content to train a machine learning model.
Who else sees anything
Two advertising platforms receive a limited set of conversion events, and only if you have consented to marketing cookies:
- Meta receives the fact that a signup, trial or subscription happened, plus a hashed (irreversible) form of your email address so it can match the conversion to an ad click.
- Google Analytics receives page views and conversions against an opaque identifier. Advertising features are switched off unless you have consented to them.
Our infrastructure providers — Vercel for hosting, Neon for the database, Resend for email — process data on our behalf under contract and do not use it for their own purposes.
How long we keep it
- Your content: until you delete it, or until you delete your account.
- Analytics events: 24 months, then dropped. Aggregate figures computed from them are kept, but they can no longer be traced to anyone.
- Security logs: retained longer, and containing only an account identifier and a hashed address — no readable personal data.
What you can do
- Get a copy of everything. One click in Settings produces a JSON file with every habit, entry, record and consent decision. No support ticket, no waiting period.
- Delete your account. Your content is removed. Analytics events are stripped of every identifier rather than deleted, so aggregate history stays correct without any of it pointing back to you. There is a 30-day window in which signing back in cancels the deletion, because it is irreversible and people change their minds.
- Change your mind about tracking at any time, from cookie preferences. The product works identically with all of it declined.
- Object, restrict, or complain. If you are in the EEA or UK you can lodge a complaint with your national data protection authority, and you do not have to contact us first.
Legal bases
For your content and account: performance of the contract. For security logging and abuse prevention: legitimate interests. For analytics and advertising cookies: consent, which you can withdraw as easily as you gave it.
Contact
privacy@crescendo.app. We answer data requests within 30 days, and usually much sooner.