Privacy Policy

Last updated 27 August 2026

The short version: we collect as little as we can, we never ask what you took, and we never sell, share, or train models on anything you write in the app. The rest of this page explains that properly.

1.What we collect

When you buy a membership: your email address, and the billing details Stripe needs to take payment. Stripe holds your card data. We receive only a token, the last four digits, and whether the payment succeeded.

When you use the app: what you tap in the check-in, what you save, what you write in the optional free-text fields, and the timing of your sessions. This is the most personal data in the product and it is treated accordingly.

Basic analytics about how the website and app are used, so we can tell which parts help and which do not.

2.What we never collect

We never ask what you drank or took. There is no field for it anywhere in the app, in any form, including as an optional or anonymised question. This is a design decision, not a setting.

We do not collect precise location, contacts, photos, or health data from other apps or devices.

3.How your entries are protected

Your saved entries, spirals, and practices are stored against your account with row-level security, meaning the database itself refuses to return one person’s rows to anyone else.

They are never exposed in any shared, social, aggregate, or leaderboard feature, because no such feature exists.

They are never used to train machine learning models, ours or anyone else’s, and they are never sold or shared with advertisers or data brokers.

Every session in the app works with no network connection. Entries sync in the background when you are online, and syncing is never a condition of using anything.

4.Why we are allowed to hold it

To provide the product you have paid for, which is our contractual basis. To meet legal obligations such as tax records. And, for basic analytics, our legitimate interest in understanding whether the product works, balanced against your privacy.

Where the law requires consent, for example for non-essential analytics in the UK and EU, we ask for it and you can withdraw it at any time.

5.Who we share it with

Stripe, for payments. Supabase, for database hosting. Our email provider, so we can send you what you bought and tell you about renewals. Our analytics provider. Each processes data only on our instructions.

We will disclose data if the law genuinely requires it. We will not hand over your entries because someone asked politely.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in US state privacy laws.

6.How long we keep it

Your account data for as long as you have an account, and then up to 90 days after you delete it, so an accidental deletion can be undone. Payment and tax records for as long as the law requires, usually six to seven years.

7.Your rights

Wherever you live, you can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Email hello@afters.app and we will action it within 30 days.

If you are in the UK or EU you also have rights to restrict or object to processing, and to data portability, and you can complain to your data protection authority. In the UK that is the ICO.

If you are in California or another US state with a privacy law, you have rights to know, delete, and correct, and a right not to be discriminated against for exercising them.

8.Children

AFTERS is for adults. We do not knowingly collect data from anyone under 18. If you believe a child has given us data, email us and we will delete it.

9.Changes and contact

If we change this policy in a way that materially affects you, we will email you before it takes effect.

Questions, requests, or complaints: hello@afters.app.