Privacy Policy
Last updated: July 15, 2026
This policy explains what 12Stride collects, why, and what control you have. The short version: we collect only what the product needs, we don’t sell or advertise with your data, you can export everything as JSON, and deleting your account really deletes it after a 30-day grace window.
1. What we collect
- Account data — name, email address, a hash of your password (never the password itself), and, if you sign in with Google, the Google account identifier Google shares with us.
- Product content — your visions, goals, tactics, time blocks, completions, scores, and reviews: the material you create by using the app.
- Preferences — your timezone (synced from your browser unless you pin it), reminder time, and notification toggles.
- Billing data — if you subscribe, payment is handled by Stripe; we store your plan, billing cycle, and Stripe customer/subscription identifiers. Your card number never touches our servers.
- Email log — which lifecycle reminders we sent you and when, so we never double-send.
We do not collect advertising identifiers and we do not track you across other sites.
2. How we use it
To run the product: compute your weeks and scores in your timezone, show your plan, send the reminders you have turned on (verification, password reset, weekly-review and planning nudges), and process subscription payments. Legal bases (GDPR): performance of contract for the product itself, consent for optional reminders (each one has a toggle and an unsubscribe link), and legitimate interest in securing the Service.
3. Who processes it
We use a small set of processors to operate the Service: our hosting provider (app and API), our managed PostgreSQL database provider, Resend (transactional and reminder email), Stripe (payments), and Google (only if you choose Google sign-in). Each receives only what its function requires. We never sell personal data.
4. Cookies
12Stride uses only essential cookies: your session (so you stay signed in) and security tokens (CSRF). There are no advertising or cross-site tracking cookies, which is why there is no cookie banner.
5. Your rights and controls
- Export — Settings → Danger zone → “Export my data” downloads everything as JSON, any time.
- Correction — your profile and preferences are directly editable in Settings.
- Deletion — Settings → Danger zone → “Delete account” locks the account immediately and permanently erases it, and all its data, after 30 days (the grace window exists so an accidental deletion can be reversed by contacting us). After the purge nothing recoverable remains.
- Email opt-out — every reminder type has a toggle in Settings and every reminder email has an unsubscribe link. Transactional email (verification, password reset) is sent only when you trigger it.
If you are in the EU/EEA or UK you additionally have the rights of access, portability, restriction, and objection, and the right to complain to your data protection authority. Write to us and we will honor them.
6. Security and retention
Passwords are hashed with bcrypt; sessions are short-lived signed tokens re-checked against the database on every request; all traffic is encrypted in transit. We keep your data for as long as your account exists, plus the 30-day deletion window. Payment records are retained as required by tax law by Stripe, not by us.
7. Changes and contact
If this policy changes materially we will notify you before the change takes effect. Privacy questions or rights requests: [email protected].
