Privacy Policy
Last updated: August 2026
What we collect
If you create an account, Supabase Auth stores your verified email address. We store the default intensity and boundaries you choose, plus roadmaps you deliberately save. We also collect information you voluntarily provide through the waitlist or suggestion form. We record anonymous usage events (page views, button clicks) through a self-hosted analytics tool (Umami) that uses no cookies and stores no personally identifiable information.
Why we collect it
Supabase provides authentication and database storage. Resend delivers generic one-time authentication codes. Cloudflare Turnstile helps prevent automated abuse. Anonymous analytics help us improve the product; email addresses, codes, boundaries, and saved-plan identifiers are not sent to analytics.
We do not sell your data
Your email address and usage data are never sold, rented, or shared with third parties for marketing purposes.
Local storage
We use browser storage to remember age confirmation and anonymous intensity. If a signed-out visitor chooses Save plan, the three content identifiers and intensity are held temporarily in session storage until sign-in completes. Authentication uses secure session cookies.
Data deletion
Account holders can permanently delete their account, preferences, and saved roadmaps from Account settings. Waitlist and suggestion deletion requests can be submitted through the site's suggestion form.
Changes
We may update this policy from time to time. Changes will be posted on this page with an updated date.