Privacy — draft
What we collect, and why, in plain language.
Ninety is built for one of the more sensitive moments in someone's life, and this page is written to match that, not to bury it in boilerplate.
What we collect
Account basics (email, country, language). Your intake answers (relationship situation, attachment patterns, mood screen). Messages you send the AI coach, and its replies. Your weekly check-in scores. Vault (Write-Don't-Send) letters. Streak and usage activity, like when you confirm no-contact or complete a lesson.
Why we collect it
To run the coaching itself: personalizing the protocol, the coach's tone, and pacing to your actual situation. To keep you safe: a crisis flag is logged (never the message content itself) if our safety classifier detects risk. To run the weekly trend charts and phase pacing you see in your own account. Nothing here is used for advertising, and we don't sell data to anyone.
Who processes it
Supabase (EU, Frankfurt) hosts the database behind Row Level Security, so only your own account can ever read your own rows. Anthropic PBC (United States) processes your coach messages and vault letters to generate the AI's replies, under a data processing agreement — that content is sent to their API for that single purpose and isn't used by us for anything else. Resend sends transactional email. Stripe processes payment; Ninety never sees or stores your card details directly. [Founder: confirm current DPA status with each vendor before publishing.]
International transfers
Because Anthropic's API is US-based, coach and vault content crosses into the US for the moment it takes to generate a reply, under standard contractual safeguards. If you'd rather avoid that entirely, you can still use Ninety's daily protocol and progress tracking without ever messaging the coach or writing a vault letter.
How long we keep it
Your data stays while your account is active. If you delete your account, we delete your rows within 30 days, except the minimum needed to satisfy legal or financial recordkeeping (for example, payment records Stripe requires us to retain).
Your rights
Under GDPR and similar laws, you can access, correct, export, or delete your data, and object to or restrict some processing. Export and delete are available directly from Settings; for anything else, contact us at [support email].
Security
Data is encrypted in transit and at rest via Supabase's infrastructure. Access to any individual's data is restricted by Row Level Security at the database level, not just application logic.
No ad tracking
Ninety runs no ad-network trackers and no ad pixels of any kind. We use PostHog (EU-hosted, self-managed) for basic product analytics, server-side only: things like whether onboarding was completed, which coach mode a message used, or a check-in was submitted. It never receives your email, your name, your coach messages, your vault letters, or your actual check-in scores, only that an event of that kind happened, tagged to an internal account ID.
Children
Ninety is for adults 18 and older. We don't knowingly collect data from anyone younger.
Changes to this policy
We'll update this page as the product changes.
Contact
[Founder: your support or DPO contact email here.]
This page is a founder draft, not a final privacy policy — it needs a real legal review, and a few sections below have open decisions marked for the founder before this goes live.