Privacy

Sign-in is an email address and a six-digit code. There is no password anywhere, so there is nothing to leak and nothing to reset. We store your address, and the sign-in records any login system keeps — device, IP address, timestamps. Nothing else identifies anyone.

Affirmations, sets, journal entries, and list items are private. Root sees email addresses and row counts, never content. The root panel has no code path that reads it — the rule that says so fails the build if any file under it so much as names a table your writing is in.

No ads, no data sold. Vercel Web Analytics counts page views and visitors; it sets no cookies, and the value it uses to tell one visitor from another is a hash that is regenerated daily and cannot be tied back to a person or matched against a later day.

Your writing never leaves this app. There is no analytics vendor that sees it, no AI service that reads it, no third party of any kind that receives it. Everything you write goes to our database and comes back to your screen. The only thing that ever goes out is your email address, to Resend, the service that sends your sign-in code — and it is sent nothing else.

Resend also holds the mailing list, if you signed up for it on the About page. That is the same address and a separate choice: nothing is stored until you click the link in the confirmation email, every message has an unsubscribe link, and nothing you write is ever part of it. You can be on the list without an account and have an account without being on the list.

Every query the app makes runs on our own servers, scoped to your account. That is a promise about our code — not, as it would be with database-level rules, a guarantee enforced by the database itself. It is checked on every build by a rule that fails the build if a single query forgets it, and by a test that signs in as one account and asserts it cannot see another’s rows.

A passkey stores a public key and an identifier here. The private key never leaves your device and is never sent to us, and no fingerprint or face data reaches the app at all — that check happens on your device, and the app is only told it succeeded.

Delete the account and every row goes with it, in one transaction — your writing, your preferences, and your sign-in record. Immediately and permanently, with no copy kept by the app. As with any hosted database, the provider keeps short-term point-in-time history of the database as a whole.

Wallpapers are drawn and saved on your device. No image is uploaded.

Run remembers where you got to — which line you were on, and in a counted run how many are left. That is all it keeps. There is no history of runs, nothing is added up, and no record exists of which days you practiced or whether you did.

A set in a link travels in the part of the address after the #, and browsers never send that part to a server. The affirmations in a link you share reach nobody’s server, no proxy and no access log.

Who this is

Operated by an individual in Europe. The point of contact for anything about your data is springapp@outlook.com.

How long the sign-in record is kept

Sessions are deleted when they expire, when you sign out, and when you sign out other devices; nothing about a sign-in outlives the account.