01Data we collect
- Account data: your name, email address, and profile identifier from your sign-in provider (e.g. Google), plus basic settings like timezone.
- Your reflections: daily check-ins, notes, weekly reports generated for you, and the next actions you choose.
- Subscription data: your plan (Free/Pro) and subscription status. Payment is processed by Paddle (see §4) — we never receive or store your full card details.
- Usage data: product analytics events (e.g. "check-in saved", "report viewed"), how you arrived at our site (referring site and campaign parameters), device/browser type, and approximate usage patterns. Analytics events never contain the text of your reflections or notes.
- Session recordings: to diagnose problems and improve usability, our analytics provider records how you move through the product — the pages you open, where you click, and how you navigate. All text is masked inside your browser before the recording is sent, so your reflections, notes, and anything else you type are never captured. We do not record the contents of network requests or browser logs.
- Approximate location: our error-tracking and analytics providers (see §4) record an approximate, city-level location derived from your IP address — to diagnose technical errors and to understand which regions visitors come from. We do not use it to track you, and neither error reports nor analytics events contain your reflections or notes.
02How we use your data
- To provide the Service: store your check-ins, generate your weekly reports, and sync your subscription entitlements.
- To generate reports with AI: relevant check-in content is sent server-side to our AI provider (currently OpenAI) solely to produce your report. Under our API terms with the provider, this content is not used to train their models.
- To improve the product: aggregated, event-level analytics (never reflection text) help us understand what works.
- To bill you: Paddle, as Merchant of Record, processes payments and related data.
We do not sell your personal data, and we do not use your reflections for advertising.
03What we never do with your reflections
- Never include reflection or note text in analytics, logs, error reports, or session recordings.
- Never share them with third parties, except the AI provider processing your report and our hosting infrastructure.
- Never make them visible to other users. Access is enforced at the database level (row-level security): only your account can read your rows.
04Service providers
We use a small set of processors to run Qorivel: Supabase (authentication and database), Vercel (hosting), OpenAI (AI report generation, server-side), Paddle (payments — as Merchant of Record, Paddle is an independent controller of payment data under its own privacy policy), PostHog (product analytics — we share your email address and name to identify your account, together with usage events, device and browser information, and masked session recordings; never the text of your reflections or notes), Google Analytics (website analytics — Google Analytics sets a cookie-based identifier in your browser and receives how you arrived at Qorivel (referring site and campaign parameters), the pages you view, basic interactions with them (scrolling, and clicks on links leading away from Qorivel), sign-up funnel events, device and browser information, and an approximate, city-level location derived from your IP address; never your email, name, or the text of your reflections or notes. This data is kept for 14 months and is not used for advertising — Google signals, ad personalization, and Google Ads linking are all turned off), and Sentry (error diagnostics — when something goes wrong, we send an error report containing your account identifier, technical error details (message, stack trace, app release, and environment), and an approximate, city-level location; never your email, name, or the text of your reflections or notes).
05Data retention and deletion
- Your data is retained while your account is active.
- You can delete your account in Settings at any time. Deletion permanently removes your profile, check-ins, reports, and actions from our database. A minimal billing record (subscription mapping) is retained where required for financial and legal compliance; full transaction records are held by our payment processor.
06Security
Data is encrypted in transit (HTTPS). Access is restricted by row-level security so each user can only access their own data. Server-side secrets are never exposed to the client.
07Your rights
Depending on where you live (including under US state privacy laws), you may have the right to access, correct, delete, or receive a copy of your personal data, and to opt out of certain processing. You can exercise deletion directly in Settings, or contact us at qorivel@gmail.com for any request. We will not discriminate against you for exercising your rights.
09Children
The Service is not directed to children under 13, and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
10International transfers
We operate from the Republic of Korea and host our core data (authentication, database, application hosting) with providers in the United States — Supabase (us-east-1) and Vercel (US-East). Other processors (our AI, analytics, and error-diagnostics providers) may process data in the United States under their own privacy terms. This includes Google Analytics (Google LLC, United States), which receives the traffic-source, campaign, page-view, and sign-up funnel data described in §4 — never your reflections or notes — so that we can understand how visitors find and enter Qorivel, and keeps it for 14 months. Where data crosses borders, we rely on our providers' standard safeguards.
11Changes and contact
We may update this policy; material changes will be notified in-product or by email. Questions or requests: qorivel@gmail.com.