How we handle your day

Privacy Policy

v1.1.0Effective

Chimesong is an independent project by Esharive Joshua Akpevweoghene, based in Delta State, Nigeria. This page describes the current online-only localhost release candidate. Public launch remains pending verification of the deployed providers, processing arrangements, and operational retention policy.

What Chimesong is

You describe your day. Claude by Anthropic provides a score and reflection, except when a safety response is needed. Entries are private by default. Sharing is an explicit choice, subject to moderation. Shared posts use a pseudonym and are visible to other signed-in users; the Feed requires an account. Chimesong is a reflection app, not a mental-health service.

What we collect

  • Account basics: email, profile settings, and a generated pseudonym. Supabase Auth processes passwords and manages sessions.
  • Entries: day text, scores, and AI reflections, stored with your account so you can revisit them.
  • Interactions: shared posts, comments, reactions, ratings, reports, appeals, moderation results, and game progress.
  • Preferences: theme, sensory choices, timezone, AI persona, and consent choices.
  • Security records: hashed IP/browser information for consent evidence, browser/region-derived security fingerprints, login events, and audit events. These are security identifiers, not advertising profiles. Hashing does not necessarily make a record anonymous.
  • Optional telemetry: only with valid analytics consent, browser performance measurements and coarse route categories can be sent to Chimesong. Current production telemetry handlers acknowledge and discard these payloads; no external analytics vendor is enabled.

We do not sell your entries or use advertising trackers. Browser timezone, request-region information, and security processing should not be mistaken for a promise that no technical identifiers are processed.

Why we process it

Account and entry processing provides the service you request. Signup records acceptance of the Terms and Privacy Policy, and the application checks required consent before scoring. Security, moderation, and audit records support abuse prevention and accountability. Optional analytics has a separate, withdrawable choice.

The operator must confirm the applicable lawful bases and deployed processing arrangements before public launch. Accepting a notice is not a blanket waiver of privacy rights.

Providers and transfers

  • Supabase supplies database and authentication functionality. Local testing does not establish a production hosting region, backup schedule, or deployed encryption configuration.
  • Anthropic receives entry text needed for AI processing. A stateless scoring request does not mean zero retention. Its published API policy describes deletion of inputs and outputs within 30 days by default, with exceptions for certain services, agreements, safety enforcement, and law. Chimesong does not claim a zero-data-retention agreement. See Anthropic's retention policy.
  • Web hosting, payment activation, processor agreements, and international-transfer arrangements require deployment review. A planned provider is not represented here as an active or verified production arrangement.

Infrastructure providers may separately process request and security logs. Their deployed settings and terms must be verified before public use.

Current retention and deletion behavior

  • Entries remain until you delete them or delete your account. The application does not currently enforce an automatic five-year entry expiry.
  • Deleting an entry removes its associated public post and dependent interactions through the existing deletion rules.
  • No automatic 90-day moderation purge or two-year report purge is implemented. Those earlier schedules were inaccurate and are not promises of the current release.
  • Consent records linked to a profile are deleted with that profile; they are not retained for an additional year by the current schema.
  • Account deletion removes the account, profile, owned entries, posts, and dependent user records through application deletion and database cascades.
  • Security audit records can remain after account deletion with the actor's profile link cleared. Event details, target identifiers, or hashes may remain. They are not all included in the self-service export and are not necessarily anonymous. No automatic audit-record expiry is currently implemented.
  • Provider logs and backups are separate from live application deletion. No fixed 35-day backup expiry has been verified for public deployment.

The operator must approve and verify the operational retention, backup, and residual security-record handling before public launch. This page does not invent a schedule that the application cannot enforce.

Your choices and rights

Use Settings to download the available account-data JSON export or delete your account. Use History to delete entries. The export covers supported account, entry, and interaction records, not every operational or provider log.

For access, correction, erasure, portability, or an objection to processing, contact klarkkrampus@gmail.com. Applicable rights and response obligations depend on your jurisdiction. You may contact the Nigeria Data Protection Commission (NDPC) or your local supervisory authority.

Manage cookies is available in the landing footer, legal pages, and Settings. Optional analytics is off without valid consent. Withdrawal stops subsequent telemetry sends; it cannot retract a request already sent. A browser Global Privacy Control signal overrides prior analytics consent.

Age and safety

Signup includes an age-eligibility acknowledgement. It is not independent age verification. If you believe an ineligible child has an account, contact klarkkrampus@gmail.com. Do not put identifying details about children or other people into shared entries.

AI output is not medical advice or a clinical assessment. Crisis guidance is available at /safety; this application is not an emergency service.

Cookies and browser storage

The Cookie Policy describes session and request-security cookies, saved sensory settings, local game state, and optional telemetry. Clearing cookies does not necessarily clear localStorage; your browser offers separate site-data controls.

Changes and contact

Material notice changes update the version above and the Changelog. The application uses versioned consent records for required policy acceptance. Questions reach klarkkrampus@gmail.com.

Questions? Reach out to klarkkrampus@gmail.com.