Data inventory

RESOLUT DATA INVENTORY ANNEX

Annex to the Privacy Policy (/privacy-policy): a user-auditable map of every data category

Storage is Supabase (database and auth, eu-west-1 Ireland) unless stated. "RLS owner-only" means database row-level security restricts reads and writes to your own account. "Encrypted beyond operator reach" means AES-256-GCM under per-user derived keys (or, for couple content, a key derivable only by the two linked partners' sessions); the operator sees only ciphertext and cannot decrypt. "Cascade on deletion" means the data is destroyed when you delete your account.

CategoryExamplesPurposeStorage and accessEncryptionRetentionProcessor(s)
Authenticationanonymous user ID, email (once added), password hash, session tokenssign-in, session persistenceSupabase Auth; admin sees only a yes/no "has email" flagprovider infrastructure; password hasheduntil account deletion; abandoned anonymous accounts (no email, onboarding never completed, inactive 30+ days) auto-deletedSupabase
Onboarding self-reportspathway, readiness stage, triggers, gender, crisis-entry flag, ToS acceptancetailor the experience you asked for; record consentRLS owner-only; enum/state values, no free text; not on any admin surfacestructured data (no free text exists here)cascade on deletionSupabase
Optional demographicsage band, prior recovery engagement ("declined" stored distinctly)age-appropriate defaults, personalisationsame as abovestructured datacascade on deletionSupabase
Journaljournal entriesyour private writing spaceyou only; never read by the coach or any profilingencrypted beyond operator reachcascade on deletion (destroyed)Supabase (ciphertext)
Why statementsdated archive of your Whyyour anchor, surfaced only to youyou onlyencrypted beyond operator reachcascade on deletionSupabase (ciphertext)
Difficult-day and setback notesoptional free-text notes on logsyour own recordyou onlyencrypted beyond operator reachcascade on deletionSupabase (ciphertext)
Foundation contentidentity statement, Ulysses commitment, trusted contact name and phonefeatures you set up yourself; trusted contact opens your own phone's SMS/call app only, nothing passes through Resolut and the contact is never made awareyou onlyencrypted beyond operator reachcascade on deletionSupabase (ciphertext)
Check-in and state logssession-gate state (okay / hard day / struggling / setback), urge outcomes, mission completions, mode changes, softening-window state, risk window, mode preferencedrive the app's supportive behaviourRLS owner-only; no admin query pathstructured data (enum/number, no free text)cascade on deletionSupabase
User-authored missionscustom missions a user writes themselvespersonal goals the user sets alongside the app's suggested missionsRLS owner-only; you onlyencrypted beyond operator reach (per-user key)cascade on deletionSupabase (ciphertext)
Behavioural countersintercept, setback, difficult-day counts with timestampsprogress and cadence logicRLS owner-onlystructured datacascade on deletionSupabase
Internal profile classificationdominant type, confidence state and scoreinvisible content ordering; the score is never shown to anyoneRLS owner-only; read server-side by the coach route; not on any admin surfacestructured datacascade on deletionSupabase
Coach operational datarate-limit counter, recent app-generated responsesrate limiting, anti-repetitionRLS owner-onlyapp-generated text, not yourscascade on deletionSupabase
Coach generation payloadmoment type, app-day integer, fixed check-in label, fixed variant, bounded counter, up to 120 chars of our own mission copygenerate the coach messagesent transiently to Google Gemini; no user free text or identifiers ever includedin transit (TLS)not stored by us beyond the anti-repetition tableGoogle Gemini
Product analyticsfixed-enum events (session start, article opened, coach message count, account deleted marker) with an internal user referencecount feature usage; the table has no free-text or JSON column and cannot hold contentwrite-only for users; readable only by an allowlisted admin with two-factor auth, in aggregatestructurally content-freesurvives account deletion; retained indefinitely in v1 (no purge job)Supabase (first party; no third-party analytics)
Feedbackyour submitted feedback textimprove the appencrypted under a separate operator key; readable by the operator by design behind allowlist + two-factor auth; you cannot re-read itAES-256-GCM (operator-decryptable exception)survives account deletionSupabase
Paymentsplan, status, period dates, amount (USD), provider IDs, webhook eventsgrant and manage access; idempotency; recordsRLS select-own; writes server-side; admin sees subscription status onlystructured data; no card, phone, or M-Pesa data is ever stored by uscascade on deletion for our rows; processor keeps its own records; financial records may be retained as required by lawSupabase, IntaSend (Paddle dormant, not live)
Checkout data at the payment provideryour phone number / M-Pesa / card detailstaking your paymententered on the provider's hosted page; never touches our serversprovider's ownper the provider's retention policyIntaSend
Founding counteraggregate count of founding membersenforce the 150 capsingle aggregate row, identifies no onen/apermanent; never decrementedSupabase
Waitlistemail (pre-launch signups)launch notificationdeleted on account deletion by your own emailnoneuntil launch cleanup or your deletionSupabase
Couple data (only if you link)link record, check-in facts (date only, no mood), shared goals, shared messages (≤500 chars)the couple features you both opted into; the app's only user-to-user communicationvisible only to the two linked partners; a partner has no path to your individual recovery data; either partner can sever the space at any timegoals and messages encrypted beyond operator reach (couple-shared key); link/check-in records are structured datashared content deleted when either account is deleted; link severedSupabase
Push subscriptiondevice endpoint, keysdeliver the one opted-in reminder (risk window)stored per device; notification body may include your own identity statementendpoint/keys structured; content in transit via the push servicecascade on deletion; revoked when you opt outbrowser push services (e.g. FCM, Mozilla)
CookiesSupabase sb-* session cookieskeep you signed in (essential)your browsern/acleared on logout; short-lived tokens with rotationSupabase (via our domain)
localStorage / sessionStoragebuffered onboarding answers (cleared after commit), card-dismissal and cadence flags, personalisation settings, once-per-open gate flag, legacy journal/Why keys (cleared after server migration)app state on your deviceyour device onlyn/auntil cleared by app logic or by younone
Server logsrequest/error logs possibly containing user IDs and payment references (never recovery content or secrets)operations, debugging, webhook audithosting and database platformsprovider infrastructureVercel runtime logs ~30 minutes (current plan); Supabase logs 24 hours; platform-managedVercel (iad1, USA), Supabase (eu-west-1, Ireland)
Transactional emailyour email address, message content (welcome, receipts, subscription, password reset)account and payment communications; sender noreply@resolut.sitesent to your own address onlyin transit (TLS)per Resend's retentionResend
Crisis linkoutbound link to findahelpline.comcrisis resource accessplain link; no data passes, no parameters, no API calln/an/anone
Under-18 redirectnothingage gatingthe age gate runs before any account creation; a redirected minor leaves zero records of any kindn/an/anone