Privacy Policy
Last updated: 5/10/2026
What we collect
- Account: email address for magic-link sign-in.
- Questionnaire: the answers you provide so we can build your routine.
- Payments: Stripe processes your card; we store the Stripe session ID and amount only.
- Operational: IP addresses are one-way hashed and used only for rate-limiting and abuse prevention.
How we use it
We use your inputs to generate and store your routine, and to improve the service in aggregate. We do not sell personal information.
Who we share it with
- Supabase (database, auth)
- Stripe (payment processing)
- Anthropic (recommendation narratives) — we do not send identifying information
- Upstash (rate-limiting)
Your rights (California)
You can request access, correction, or deletion of your data via your account settings or by emailing privacy@coredose.app. We honor verified deletion requests within 30 days.
Security
We encrypt data in transit and at rest, restrict service-role access to server code, and enforce row-level security on all user tables.
Contact
privacy@coredose.app