Effective date: 18 July 2026 Last updated: 18 July 2026
Resolut is a self-help application for people working on recovery from pornography use and related behavioural patterns. The service is operated by Bradley Tanga Nyaim, Chief Operator, Nairobi, Kenya ("we", "us", "the operator"). The operator is the data controller for the personal data described in this policy.
Contact for everything in this policy, including data rights requests: support@resolut.site.
The service may in future be transferred to a company (for example Ember AI Solutions). If that happens, this policy and your agreements with us may be assigned to that company. We will give you notice of any such transfer. Your continued use after notice constitutes acceptance of the assignment; no further consent is required, and your rights under this policy are not reduced by the transfer.
This policy is written under the Kenya Data Protection Act, 2019 as our primary regime. Where you are in the European Economic Area or United Kingdom, the GDPR / UK GDPR applies as described in Section 12. Where you are a California resident, the CCPA/CPRA applies as described in Section 13. We are not currently registered with the Office of the Data Protection Commissioner of Kenya; we operate below the mandatory registration thresholds, and the substantive duties of the Act apply to us regardless of registration.
Because Resolut is a recovery app, much of what you give it is sensitive by its nature. Information about behavioural addiction and recovery is health-related. Under the Kenya Data Protection Act this is sensitive personal data, and under GDPR Article 9 it is special category data. We process it only to run the app for you, on the lawful bases in Section 6.
All personal written content in Resolut is encrypted such that the operator cannot read it. The only exception is feedback you explicitly choose to send. Section 5 states exactly who can read what. We do not sell your data, we do not run advertising, and there are no ad trackers in the app.
Resolut is for users 18 and over. The age confirmation runs before any account is created. Users who indicate they are under 18 are redirected to appropriate external support (findahelpline.com); no account is created and no data of any kind is collected from them.
You can use Resolut without an email address. An email becomes required by your 18th day of use, and before any purchase.
a. Account data (Supabase Auth). An anonymous user identifier; once you add one, your email address and a password hash; session tokens.
b. Onboarding and settings you provide. Your chosen pathway (individual, partner, couple), readiness stage, primary triggers, gender (Male / Female / Prefer not to say), whether you entered through the crisis path, terms acceptance and its timestamp, optional age band and prior recovery engagement (declining to answer is stored as "declined", distinct from unanswered), personalisation setting, notification settings and timezone.
c. Encrypted personal content. Your journal entries, your "Why" statements, the optional notes on difficult-day and setback logs, your identity statement, your Ulysses commitment, and your optional trusted contact's name and phone number. These are encrypted with AES-256-GCM using keys derived per user. We cannot read them. The trusted contact is only ever used on your own device to open your own phone's SMS or call app; nothing is sent or received through Resolut, and that person is never contacted by us and has no visibility of being listed.
d. Usage and state logs (no free text). Session check-in states (okay / hard day / struggling / setback), urge-tool outcomes, mission completions, mode changes, behavioural counters (for example intercepts and setbacks with timestamps), softening-window state, your stated risk window and mode preference, and an internal profile classification with a confidence score that is never shown to you or to any admin surface.
e. Product analytics (first party). A table of count-only events (for example "session started", "article opened", "coach message sent"). The event vocabulary is a fixed list and the table is structurally incapable of holding content: there is no free-text or JSON column. We do not use any third-party analytics service.
f. Coach data. A rate-limit counter and recent app-generated coach responses (kept to avoid repetition). This is text the app generated, not text you wrote.
g. Payments. Subscription records (provider, plan, status, period dates, amount paid in USD, provider reference IDs) and payment webhook events. We never receive or store your card number, phone number, or M-Pesa handle; the payment instrument is entered on the payment provider's own hosted page.
h. Feedback. If you send in-app feedback, it is stored encrypted under a separate administrative key. Unlike everything else you write, feedback is readable by the operator by design, and only after passing an allowlist plus two-factor authentication gate. You cannot re-read feedback after sending it, and it is retained after account deletion (Section 9).
i. Couple features (only if you link with a partner). The link record, check-in facts (that a check-in happened on a date, with no mood or state), shared goals, and short shared messages (up to 500 characters). Shared goals and messages are encrypted under a couple-shared key derivable only by the two linked partners' own sessions; the operator cannot read them. Linking gives your partner no access whatsoever to your individual recovery data. The couple space is the app's only user-to-user communication.
j. Push subscriptions. If you opt in to the risk-window reminder, your device's push endpoint and its keys.
k. Server logs. Our hosting provider keeps short-lived request and error logs (Section 9), which may contain user identifiers and payment reference strings, but never your recovery content or secrets.
This is the exact access model as built:
We collect nothing without a currently implemented purpose. We do not use your data to train AI models.
| Processor | Role | What reaches them |
|---|---|---|
| Supabase | Database and authentication | All data described in Section 4, encrypted content as ciphertext. Hosted in eu-west-1 (Ireland): data at rest in the EU. |
| Vercel | Hosting and serverless functions | Requests are processed in iad1 (Washington D.C., USA); short-lived request and error logs may include user IDs and payment references, never recovery content. |
| IntaSend (Kenya) | Payment processing (M-Pesa, cards) | Amount, currency, plan label, a payment reference containing your user ID. Your phone number or card details go directly to IntaSend's hosted checkout, not to us. |
| Google (Gemini) | AI coach generation and evaluation | Only bounded, whitelisted fields: the moment type, your app-day number, a fixed check-in label, a fixed dashboard variant, a bounded counter, and up to 120 characters of the app's own mission library copy. Never your journal, Why, free text, email, or any identifier. |
| Resend | Transactional email (from noreply@resolut.site) | Your email address and the content of the transactional message. |
| Browser push services (e.g. FCM, Mozilla) | Delivering the opted-in risk-window reminder | Your device push endpoint and the notification text, which may include your own identity statement if you opted in to that reminder. |
| findahelpline.com | Crisis resource directory | Nothing. It is a plain outbound link; no data passes to it. |
Paddle (an international payment provider) exists in the codebase in a dormant, sandbox state and is not a live processor; no user data flows to it. If it is activated, this policy will be updated first.
We operate from Kenya. Your data at rest is stored in the European Union (Ireland). Request processing and short-lived server logs transit the United States (Vercel, Washington D.C.), and payment processing for M-Pesa occurs in Kenya. Where the Kenya DPA or GDPR requires safeguards for transfers, we rely on our processors' standard contractual protections and published compliance frameworks. For details, contact support@resolut.site.
sb-* access and refresh tokens), so you stay signed in. They are cleared on logout. There are no analytics or advertising cookies.Under the Kenya Data Protection Act you have the right to be informed, to access your data, to correction, to deletion, and to object to or restrict processing. In the app you can view and edit your data directly, export it (the in-app export endpoint works even past the paywall), and delete your account entirely. For anything you cannot do in-app, email support@resolut.site. We respond within the timelines the applicable law requires. If you are unsatisfied, you may complain to the Office of the Data Protection Commissioner (Kenya) or your local supervisory authority.
Your recovery data is special category data under Article 9, processed on the basis of your explicit consent, and stored at rest in the EU. You additionally have the rights to data portability (use the in-app export), to withdraw consent at any time without affecting prior processing, and to lodge a complaint with your supervisory authority. Automated processing note: the app's internal profile classification adjusts which content is surfaced to you; it produces no legal or similarly significant effects, no fully automated decisions are made about you in that sense, and you can raise any concern about it with us.
This is the Service's initial launch. We do not sell or share your personal information as those terms are defined in the CPRA, and we have never done so, including in the preceding 12 months. We do not use or disclose sensitive personal information for purposes beyond providing the service you asked for. You have the rights to know, access, correct, and delete your personal information, and the right not to be discriminated against for exercising them. Exercise them in-app or via support@resolut.site. We do not process opt-out preference signals because we do not sell or share data.
Row-level security scopes every read and write to your own account. All personal written content is encrypted with AES-256-GCM under per-user derived keys (or, for the couple space, a key derivable only by the two linked partners), and is unreadable to the operator. Administrative access is gated by an allowlist plus mandatory two-factor authentication. Session tokens are short-lived (15 minutes) with rotation. Enforcement columns on user records are writable only server-side and guarded by a database trigger. No security is absolute; Section 5 states the access model exactly.
If a personal data breach occurs that is likely to result in a risk to you, we will notify the Office of the Data Protection Commissioner (and, where GDPR applies, the relevant supervisory authority) within 72 hours of becoming aware of it where required, and we will notify affected users without undue delay when the law requires it or when we judge you need to know to protect yourself.
We may update this policy. Material changes will be notified in the app or by email before they take effect. The "Last updated" date at the top always reflects the current version.
The Data Inventory Annex (/data-inventory), a full, user-auditable table of every data category, its purpose, storage, encryption status, retention, and processor, forms part of this policy. The Terms of Service are at /terms-of-service.