miracle.fyi Log in →

Privacy Policy

The short version: we collect only what the product needs to work: account information; the text, images, documents, audio, messages, and settings you submit; guest checklist snapshots and progress you intentionally share; the community profile and automatic activity created under the defaults below; limited technical records; and membership or pact payment records. Anyone with a private guest checklist link can view and complete its shared items, so treat the link like a secret. Automatic activity can include a fixed journal-session count or structured exercise progress under your named community profile, but not journal writing or private habit and pact details in the published card. We use OpenAI and Anthropic only for the specific capture, North Star, and automatic numeric exercise-classification features described below. Deliberate Feed posts and replies are never sent to AI. One session cookie. No ad trackers, no analytics scripts, no selling data, and no opting your content into AI model training.

1. Who we are

miracle.fyi is operated by Highway 86 LLC, a Delaware limited liability company. This policy covers the miracle.fyi website, app, Chrome extension, API, MCP server, and messaging integrations. Privacy questions: claycollins@gmail.com.

2. What we collect

  • Account information. When you sign in, our authentication provider (WorkOS) gives us your email address and name and may provide the profile-picture URL supplied by your sign-in provider. That's the account.
  • The content you create. Goals, journal entries, mantras, North Star text and builder answers, to-dos and notes, pact check-ins, Vision images, screenshots and files attached to tasks, vocabulary, and settings. This is the heart of the Service and it exists so you can use it, not so we can mine it.
  • Guest checklist assignments. When you share a task checklist, we store a separate snapshot of the title and checklist item text, the assignee label you enter or the default Guest label, each item's starting and current completion state, completion attribution supplied through the link, activity times, revocation state, and assignment completion state. Miracle's server stores no raw capability token. The token is returned in the private link fragment, which the browser omits from the initial page request and ordinary URL access logs. The guest page keeps it in assignment-scoped session storage for that browser tab so a reload still works. When someone uses the assignment, the guest page sends the token only in an authorization header to authorize that assignment request; Miracle keeps it out of paths, query strings, request bodies, database rows, application logs, and account exports. The database keeps only a non-secret rotation version used with the server's private pepper to validate the link.
  • Pact Community information. Miracle creates an active community profile and enrolls each account in the free One Thing Today pact. By default, the public display name is the sign-in first name and last initial, the handle is a unique generated value, and the avatar is the provider profile picture when WorkOS supplies an approved Google or WorkOS-hosted image URL or generated initials otherwise. The stored provider image URL can refresh when you sign in after the source picture changes. Public pages for group pacts you own reuse the active Community display name, handle, and current avatar. The group commitment and description are public as the page's headline and story. A public pact share page can also show anonymous activity type, time, reply count, and Cheer count. It never shows a member name, avatar, handle, post text, reply text, source record, or payment information in that anonymous preview. Miracle does not collect separate pact marketing, identity, photo-upload, or arbitrary pact-photo URL fields. Legacy pact marketing copy saved before this change may remain stored and appear under a legacy label in your account export until account deletion, but current product and public pages do not use it. We store the handle, display name, generated avatar seed, optional provider image URL, automatic-sharing and audience choices, Community Guidelines acknowledgement records if provided, and moderation status. Automatic community activity can store fixed journal-session counts and structured exercise amounts, types or units, and daily targets. We do not ask for or store a separate date of birth for community access because the Service is limited to adults under the Terms. Community use can add deliberate manual posts and replies. Miracle applies reject-only validation, stores accepted text exactly as submitted, rejects disallowed text instead of rewriting it, and never sends manual Feed text to AI. Community use can also add Cheers, follows, blocks, reports, notifications, and short-lived rate-limit records. Your email address and full last name are not displayed by default, and you may change the public community name and handle.
  • Payment and consent records. If you start a membership trial or explicitly activate a money-backed pact, Stripe processes your card. We store membership status, Stripe customer and subscription references, renewal dates, card brand and last four digits, the exact pact terms hash and version you accepted, acceptance time, one-way hashes of the acceptance IP address and browser signature, obligations, charge attempts, receipts, refunds, disputes, and delivery status for required billing messages. We never store your full card number, which stays with Stripe.
  • Messages and attachments you send to connected capture services. If you connect Telegram, WhatsApp, Slack, Discord, or iMessage through Sendblue, we receive the messages, voice clips, and screenshots you intentionally send to Miracle, plus the account, channel, or phone identifier the service attaches. We do not read unrelated conversations.
  • Chrome extension captures. Miracle Capture sends data only after you choose a capture action. Browser tab and Area of browser tab send the screenshot and the source page URL. Screen or app window opens Chrome's own source picker, takes one still frame from the source you select, immediately stops the stream, and sends that frame with no page URL. Area of screen asks Chrome for one monitor, hides Miracle's controller, copies one still locally, stops the stream, restores the controller, and lets you select a rectangle. Nothing uploads until you click Send selected area. Only the selected pixels are encoded and sent with no page URL; the full still remains in memory on your device and is cleared when it is no longer needed. If you separately enable the optional Gmail integration, Chrome grants the extension persistent host access on mail.google.com so its message-level controls remain available while you navigate Gmail. Before a capture click, the extension checks only whether the active tab is on the Gmail origin and reads no message fields. It reads and sends only the exact expanded message whose Miracle button or popup Send this email button you click, including its subject, sender, recipients, displayed sent time, plain-text body, stable message hint, and Gmail permalink. Miracle Capture does not scan your inbox, read collapsed messages, capture in the background, or send a page, screen, or message before an explicit click. The selected list destination is a separate setting and is never inferred from screenshot or email content.
  • Chrome extension credentials and settings. The extension stores your default destination and limited account label in its local extension storage. It stores a short-lived OAuth access token in session storage and a rotating refresh token in local extension storage restricted to trusted extension contexts. Gmail and page-selection scripts never receive either token. Disconnect confirms that Miracle revoked the complete token family before removing local credentials. If confirmation fails, the extension keeps the connection active and offers retry instead of falsely claiming that sign-out succeeded. Anyone with access to your unlocked Chrome profile may still be able to operate installed extensions, so protect the device and Chrome profile.
  • Chrome Web Store Limited Use. Miracle Capture's use of information received from Chrome and Gmail complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. We use this information only to provide or improve the extension's single disclosed purpose, related security and reliability, or as otherwise permitted by those requirements.
  • Voice recordings, transcripts, and vocabulary. Server-backed voice capture processes the audio you submit. Voice-to-do capture can also use your saved preferred spellings as recognition context. Miracle holds the audio only in memory during the request and does not write it to its storage. A voice-to-do transcript and organized draft may remain for up to 24 hours. The final reviewed item, or the item a connected bot creates immediately because it cannot offer a review screen, is saved as product content. Journal or mantra dictation saves the text you approve, not the audio recording.
  • PDF source documents. When you choose a PDF through task capture, Miracle validates the real file, records its filename, byte and page counts, and stores an application-encrypted copy in private object storage. Anthropic processes the complete PDF to propose editable tasks and a bounded private search index. Nothing becomes a to-do until you approve it.
  • Forwarded-email attachments. When you deliberately forward an email to your Miracle inbox, Miracle receives every user-visible attachment contained in that signed message. It excludes inline signature graphics and other related body resources unless they are explicit attachments. Miracle records bounded filename, type, size, order, processing status, and page count where applicable, then application-encrypts each accepted file in private object storage and attaches it to the resulting task. Safely readable PDFs, validated raster images, and bounded text-family files are sent to Anthropic with the subject, body, and your forwarding note to identify the requested action and relevant facts. Unsupported, corrupt, encrypted, archived, executable, macro-enabled, SVG, and other opaque files remain private forced downloads but are not sent to Anthropic, executed, unpacked, or rendered inline. The Gmail feature in Miracle Capture does not import Gmail attachments.
  • AI-derived content. When you choose an AI-assisted feature, or when an eligible numeric goal reaches the automatic exercise classifier described below, we receive and save the useful result, such as a screenshot transcription, a structured title and checklist, a cleaned capture, a North Star sentence or field, or a validated exercise decision and neutral labels. A long typed to-do submitted for organization, including its full source text and organized preview, may remain in a short-lived preview row for up to 24 hours. It does not become a to-do until you approve it. The provider inputs and the different retention rules are detailed below.
  • Automatic sync recovery copies. If two devices change the same field before they have synchronized, Miracle applies the changes in server order and briefly keeps the displaced prior value so an overwritten edit can be recovered. The copy contains only the affected field value and limited operational metadata needed to identify the account, target, and change.
  • Device recovery drafts. If an older whole-account sync candidate or a locally invalid target cannot be replayed safely, Miracle can quarantine that exact unsent draft in this browser's IndexedDB instead of sending it or blocking later changes. Eligible drafts remain copyable from Sync recovery for up to 30 days. Drafts that cannot be tied to the current immutable account stay hidden and are never replayed.
  • Browser reminder subscriptions. If you turn on browser alerts for task reminders and generic guest-checklist completion notices, we store a private per-device push endpoint, the public encryption key and authentication secret issued by that browser, a random installation identifier, limited browser information, and delivery status. Scheduled task reminders also use job records needed to retry or deduplicate their delivery. Guest-checklist notices are best-effort and do not include the shared task title, checklist item text, assignee label, or share link. We do not create a browser push subscription or request notification permission on page load.
  • Technical basics. Standard server logs (IP address, request path, timestamp) kept briefly for security and debugging, and one first-party session cookie that keeps you signed in.

3. What we don't do

  • No advertising, and no third-party ad or analytics trackers anywhere on the site.
  • We never sell or rent your personal information.
  • We do not use your content to train AI models, and we do not opt it into model-training programs offered by OpenAI or Anthropic.
  • No cookies beyond the single session cookie that signs you in.

4. How we use your information

We use information only to operate the features you request and the account defaults disclosed in this policy:

  • Store, display, sync, export, and delete your product content.
  • Create the guest-checklist snapshot you request, let anyone holding its private capability link mark snapshot items complete, show that progress to you, let you revoke access, and keep completion of the source task under your signed-in control.
  • Keep a short-lived recovery copy when one synchronized edit displaces another edit to the same field.
  • Transcribe server-backed audio; turn voice transcripts, longer typed entries, screenshots, PDFs, forwarded emails and their safely readable attachments, and a Gmail message explicitly captured through Miracle Capture into reviewable to-dos; clean and file messages sent to connected capture services; and compose, polish, or rebuild North Star text.
  • Authenticate Miracle Capture with a capture-only OAuth permission, remember the extension's default destination, process only the browser view, selected page area, selected screen or window, or open Gmail message you explicitly capture, and open your Miracle account when you use its shortcut.
  • Return requested information to an AI assistant or other MCP client you connect, limited by the access scopes you approve, and apply changes that client asks Miracle to make on your behalf.
  • Resurface tasks in the app and, when you explicitly enable a channel, send task reminders through browser push or a connected Telegram account. A reminder does not change the task's due date, active section, or deferred lifecycle.
  • Verify membership access, evaluate pact days, enforce explicit billing consent and future-only effective dates, process and reconcile authorized charges, refunds, and disputes, and show shared-pact activity to that pact's members.
  • Operate Pact Community under the account defaults: create the first-name-and-last-initial identity, unique handle, and available provider avatar; reuse the active Community display name, handle, and avatar on public pages for group pacts you own; publish the group commitment and description there as the headline and story; publish fixed generic completions; publish detached fixed journal-session counts and structured exercise progress to the followers or global account audience unless you turn sharing off or select pact-only; classify eligible numeric goal definitions for safe exercise; apply reject-only validation to deliberate Feed posts and replies, then store accepted text exactly as submitted without AI processing; keep the source habit or pact and private-pact relationship out of detached activity; narrow other private-pact activity to that pact; support follows, Cheers, and flat replies; enforce rate limits; honor blocks; review reports; and apply the Community Guidelines.
  • Send required transactional messages, send product updates only if you separately subscribed, secure and debug the Service, prevent abuse, and comply with law.

5. Who we share it with

Only service providers that operate the product, only with what they need:

  • WorkOS and an available profile-image host: WorkOS handles sign-in and may supply the name and profile-picture URL provided by Google or another identity provider. Community and public group-pact pages may show the same current provider avatar. The viewer's browser requests it directly only from an approved Google or WorkOS content-delivery host. The image request suppresses the Miracle page address, but the image host receives ordinary connection information such as the viewer's IP address, browser information, and request time. Miracle does not derive a Gravatar hash from your email address or query Gravatar.
  • Stripe: payments and pact-leader payouts.
  • Railway: hosting, object storage, and our database.
  • Resend: email delivery.
  • Telegram, Meta (WhatsApp), Slack, Discord, and Sendblue (iMessage relay): only if you connect that capture service. The service handles messages, account or phone identifiers, and attachments you route through it under its own privacy terms.
  • Cloudflare: an email you forward to Miracle transits Cloudflare's email routing before it reaches us.
  • Your browser's push service: if you enable browser alerts, Miracle sends an end-to-end encrypted notification to the private endpoint issued by Safari or an installed iOS web app (Apple Push Notification service), Chrome (Google Firebase Cloud Messaging), Firefox (Mozilla Push Service), or the equivalent service selected by your browser. That provider receives the routing endpoint and delivery metadata under its own privacy terms. Task-reminder text is encrypted in transit for the subscribed browser. A guest-checklist completion alert is generic and omits the shared title, checklist item text, assignee label, and share link so those details do not appear on a lock screen.
  • OpenAI: server-backed voice capture sends the full audio recording to OpenAI for transcription. Voice-to-do capture also sends your saved preferred spellings as recognition context; common-error spellings are applied by Miracle afterward and are not sent. Journal or mantra audio is sent without vocabulary context. A full typed message sent through Telegram, WhatsApp, Slack, Discord, or iMessage is sent to OpenAI to remove capture-command framing and choose Inbox, Today, or In Progress. Ordinary typed to-dos entered in the Miracle web app are not sent to OpenAI.
  • Anthropic: voice-to-do capture sends the corrected transcript, but not the audio, to Anthropic's Claude to create a title, checklist, notes, and due date. When a typed web to-do is at least 24 words, at least 160 characters, or contains multiple nonempty lines, Miracle sends the full typed text to Anthropic to propose a title, up to 20 checklist items, and a due date. Shorter one-line typed tasks are saved without AI organization. Forwarded-email capture sends the subject, email body, any note you add, sanitized filenames, and the complete contents of every safely readable user-visible attachment. Miracle validates PDFs, normalizes supported raster images, and bounds decoded text before sending it. It does not send unsupported, corrupt, encrypted, archived, executable, macro-enabled, SVG, or other opaque attachments. Claude can return only a bounded title, checklist, due date, and factual attachment summaries. It receives no routing, messaging, URL-fetching, storage, command, or other execution tool, and Miracle treats every instruction found inside an email or file as untrusted content rather than authority. A Gmail message you explicitly capture through Miracle Capture sends its subject and body, plus any available sender, recipient, sent-time, and source-link context, but that extension path does not import Gmail attachments. Screenshot-to-do capture sends the full screenshot image, including a browser, window, screen, or cropped area you explicitly choose through Miracle Capture, to transcribe visible text and extract a task; ordinary Vision board uploads are not sent. PDF capture sends the complete PDF and its filename to propose up to 20 editable tasks and produce a private search index; the selected list destination is controlled by Miracle and is not taken from the email, screenshot, document, or model. North Star tools can send your net-worth or identity answer, money manner, place, relationships, health or longevity, feelings, purpose, selected people or feeling values, and the saved North Star sentence to compose alternate wording, polish a list, or rebuild editable fields. Miracle does not send deliberate Feed posts or replies to Anthropic or another AI provider. Those manual submissions use reject-only validation and, when accepted, are stored exactly as submitted. For a numeric goal eligible for followers or global automatic sharing, Miracle automatically sends only the NFKC-normalized goal title, capped at 240 characters, and unit, capped at 40 characters, when an eligible definition is new or changes so Anthropic can decide whether it is safe physical exercise and return neutral singular and plural labels. Progress sets reuse that saved decision and never invoke the classifier; a transient provider or delivery failure may retry the same definition. The title can come from a private habit or pact, but the raw title never publishes. Local filters reject profanity, sexual anatomy, obvious personal information such as contact details, threats, self-harm, and bidirectional or hidden formatting before the call. Miracle never sends this classifier a member identity; pact id, type, visibility, description, or membership; target, progress, history, schedule, notes, rules, stake, payment data, or journal content. Miracle claims a new provider call only while at least one member of the goal is eligible for followers or global automatic sharing. Choosing Off or pact-only removes that member's eligibility and prevents a detached card for that member. A shared pact may still be classified for another eligible member, and an already in-flight provider request may finish. Unsafe or uncertain input or output, provider failure, or a missing Anthropic key fails closed without blocking the goal or progress. Miracle retains only the current validated decision and neutral labels with the pact until its definition changes or the pact is deleted, not the raw model response. Per-day Feed-safe label, term, and action snapshots expire with the 180-day automatic-activity window. Fixed automatic completions and journal-session counts still do not use AI, task text, or journal writing.
  • An AI assistant or other MCP client you connect: after you authorize ChatGPT, Claude, or another compatible client, Miracle returns only the information requested under the access scopes you approved. Depending on that request, this can include to-dos and notes, pacts and money summaries, Goal Grid data, journal entries, Vision data, North Star fields, birth-date or Time on Earth data, and other scoped product content. The client can also send authorized changes back to Miracle. The assistant's provider processes that data under its own privacy terms; Miracle does not send MCP data until an authenticated client requests it.

On-device iPhone exception. When the installed iPhone app successfully uses its native on-device mantra recognition path, the audio and preferred terms stay on the device and are not sent to OpenAI or Anthropic. If that native path is unavailable and you use the server-backed recorder, the OpenAI disclosure above applies. This exception does not cover iPhone voice-to-do capture, which is server-backed.

How the AI providers handle content. Miracle uses commercial APIs and does not opt submitted content into provider model training. Under the providers' published defaults as of this policy's effective date, OpenAI says API data is not used to train its models unless the customer explicitly opts in. OpenAI lists no abuse-monitoring or application-state retention for its audio-transcription endpoint, while its text Chat Completions endpoint can retain customer content in abuse-monitoring logs for up to 30 days. Anthropic says commercial API inputs and outputs are not used to train its models by default and are automatically deleted from its backend within 30 days. Both providers describe exceptions for legal requirements and misuse or policy enforcement, and an account-specific agreement can change retention. Provider retention is separate from Miracle's own retention below.

What other members can see. Automatic completion sharing and the global feed are the account defaults. A private pact post is visible only to active members of that pact. A followers post is visible to accounts that follow the community profile. A global post can appear in the global feed. The audience for a deliberate post or reply sees the exact text you submitted. Detached journal and exercise cards use the followers or global account audience and are not published when the account audience is pact-only. Their audience can see the community handle, display name, provider picture or generated initials, fixed journal-session count, or structured exercise amount, exercise type or unit, and daily target, plus replies and Cheer count. A detached exercise card never identifies the source habit or pact, even when progress originated inside a private pact. Blocks remove visibility and interaction between the two profiles. Miracle does not place private task text, journal writing, North Star language, habit or pact titles, pact identity or membership, notes, attachments, exact dollar amounts, payment records, or stake charges into an automatic card.

What visitors to a pact share page can see. Anyone with a group pact's public link can see its public title, description, leader identity, terms, member and check-in totals, and an anonymous recent-activity preview when the owner has enabled a public community. Each preview row can state only the activity category, relative time, reply count, and Cheer count. It does not include a member name, avatar, handle, post text, reply text, source record, or payment information. Members-only and disabled communities do not expose activity rows. Joining and signing in are required to see the full Feed, names, post and reply text, or to interact.

What a guest checklist recipient can see and do. Anyone with the private link can see the assignment's copied title, assignee label, checklist item text, and current progress and can check or uncheck delegated snapshot items. Items already completed before sharing stay locked. The link does not expose task notes, attachments, later edits to the source task, the rest of the owner's account, or the owner's sign-in identity. Miracle does not authenticate the recipient or guarantee that the named assignee is the person using the link. Guest progress is private link activity, not Community activity, and cannot complete the owner's source task.

An eligible committed exercise action can create a separate automatic post. Other members can therefore see the amount just completed and the resulting running total for each shared set, such as "Did 10 more push-ups. 20 of 100 done today." Individually completed circles can post separately, while one bulk action that finishes several circles creates one combined post. A retry does not create another post for the same event. Undo removes that event's post, and later visible totals reconcile to the remaining progress. These progress writes reuse the saved exercise classification and do not send the target, progress, or set to Anthropic.

We will also disclose information if the law genuinely requires it. We do not otherwise disclose your information.

6. Where your data lives and how long

Our primary servers, object storage, and database are hosted in the United States. The service providers above may process data in the United States or other locations described in their terms. If you use the Service from elsewhere, you consent to that processing.

  • Product content. We keep it while your account is active or until you delete it. Ask us to delete your account at claycollins@gmail.com and we will remove deletable personal data within 30 days, with copies in encrypted backups aging out on the backup cycle.
  • Voice. Miracle does not retain voice audio after the transcription request. Voice-to-do transcripts and drafts expire within 24 hours; the saved to-do follows the product-content rule.
  • Typed to-do previews. A long typed entry and its organized preview expire within 24 hours. If you approve the preview, the resulting to-do follows the product-content rule.
  • Screenshots and images. An image attached to saved content remains private product content until that content or your account is deleted. An unreferenced image is deleted after a seven-day recovery grace period. Extracted screenshot text saved in a to-do follows the product-content rule.
  • PDF documents. An unsaved PDF preview, its proposed tasks, and its private search index expire within 24 hours. An approved PDF is attached to the resulting tasks and follows the product-content rule. If its last task attachment is removed, Miracle keeps the encrypted document for a seven-day recovery grace period and then deletes it. Raw PDF bytes are encrypted with AES-256-GCM inside the application before private object storage; the service must decrypt them temporarily to send the requested PDF to Anthropic or return it to your authenticated download. A non-content processing meter containing the account, an opaque capture reference, page count, new-or-retry type, and timestamp remains for up to 72 hours so deleting a preview cannot reset the AI processing limit.
  • Forwarded and captured email. Miracle keeps the original email body in a separate, read-only source field. For Gmail, this is the message explicitly sent through Miracle Capture. Miracle automatically removes it after 90 days. Removing it does not erase notes you added or edited. Files from forwarded email are task attachments and follow the product-content rule independently of the temporary source email. Completed inbound-delivery and extension-capture records follow the same 90-day policy. If an accepted message is still retrying at that age, Miracle removes its body and addressing details, retains only a bounded subject and, for an extension capture, its selected list destination, and continues trying to create the task. The extracted to-do fields and attached files remain until you delete them.
  • Sync recovery. A prior field value retained because a later synchronized edit displaced it is used only to recover overwritten work and is automatically deleted after 30 days. Deleting your account data removes these recovery copies as part of that deletion workflow.
  • Device recovery drafts. A quarantined unsent draft remains only in browser storage for up to 30 days and is never sent automatically. Discarding the draft or deleting app content removes drafts tied to that account from the current device.
  • Guest checklist assignments. A shared snapshot and its item progress remain with the source task until you delete the source task or delete your account data. Stopping sharing immediately invalidates the existing capability link but retains the private revoked snapshot and progress for your account; sharing that task again replaces the snapshot and issues a new capability. The account export includes active and revoked snapshots and progress but never includes the link token, server pepper, token rotation version, or other capability-signing material.
  • Browser reminders. An active browser push subscription remains until you turn it off on that device, the browser expires it, or you delete your account data. Expired or disabled subscription records are deleted after 30 days. Terminal task-reminder delivery jobs and their per-channel results are deleted after 90 days; this window prevents duplicate delivery across retries and deployments.
  • Pact Community. Your public display name, handle, avatar seed, optional provider image URL, sharing choices, manual posts, replies, Cheers, follows, and blocks remain until you change or delete the relevant item or delete the account, subject to safety and legal exceptions. Accepted manual posts and replies are stored exactly as submitted. Automatic completion, journal-session, and exercise-progress posts expire after 180 days. Per-day Feed-safe exercise labels, numeric terms, and action records expire with that same automatic-activity window. Miracle no longer creates generalized-result receipts; any legacy single-use receipt expires after 15 minutes. A current validated exercise-classification decision and its neutral labels remain with the pact until the title or unit changes or the pact is deleted; Miracle does not retain the raw model response. Hashed classifier quota buckets and other Community rate-limit buckets are deleted after seven days, and notifications after 90 days. Reports and moderation decisions may remain as long as reasonably needed for safety, appeals, abuse prevention, legal obligations, and defense of claims. Turning automatic sharing off prevents new automatic cards and removes your visible automatic cards. Deleting community activity removes your authored posts, replies, Cheers, any unexpired legacy generalized-result receipts, and retained exercise Feed action and label records. It preserves the profile, follows, and blocks so identity and safety choices do not disappear unexpectedly. Deleting the account removes that remaining community data through relational deletion; reports and safety records may remain with account identifiers minimized where practical.
  • Financial and safety records. Payment, consent, refund, dispute, fraud-prevention, and required-message delivery records are kept as long as reasonably needed for reconciliation, legal obligations, and defense of claims. Deleting a pact removes it from the product but does not erase those records.

7. Your rights

Wherever you live, we honor the basics: you can access and export your data, correct it, turn automatic completion sharing off, delete individual community posts or replies, delete authored community activity from Community settings, revoke guest checklist assignments, request account deletion, and object to processing. The account export includes active and revoked guest checklist snapshots and progress plus your community profile, posts, replies, reactions, follows, blocks, reports, unexpired legacy generalized-result receipts, member-scoped Community interaction rate-limit records, and notifications. It never includes a guest capability token, the server pepper, token rotation metadata, or other capability-signing material. Internal hashed provider-spend buckets and the global spend bucket are not included. Residents of California, the EU/UK, and similar jurisdictions may have formal versions of these rights; email claycollins@gmail.com and we'll handle the request regardless of formality.

8. Security

Data is encrypted in transit, source PDFs and forwarded-email attachments receive additional application-layer encryption at rest, sessions are signed, payment credentials never touch our servers, and access to production systems is limited. Guest checklist links are bearer capabilities: possession grants the limited access described above, so keep them private and revoke any link that may have been forwarded or exposed. No system is perfect; if a breach affects your data, we will tell you promptly and plainly.

9. Children

The Service is for adults 18 and over. We do not knowingly collect information from anyone under 18. If you believe we have, contact us and we will delete it.

10. Changes to this policy

If we change this policy in a way that matters, we will post a notice on our updates page or in the app before it takes effect, and update the date above. We will not quietly weaken it.

11. Contact

Highway 86 LLC · claycollins@gmail.com · or use our contact page.