privacy
sanctuary is a consumer wellness product. we do not claim hipaa compliance for the consumer harbor. we implement healthcare-grade privacy practices with honest limits. enterprise covered entities seeking a baa: hello@joinsanctuary.io.
the commitment
sanctuary exists to harbor travelers through difficult seasons, not to harvest their data. your reflections, your cairn, your stones, your rituals: they belong to you. this is not a policy position. it is an engineering decision.
we collect as little as possible. what we do collect, we hold carefully. what we do not need, we do not take.
your digital vault
your thoughts stay on your device first. cairn entries, journal pages, expedition memory, and personal reflections are stored locally unless you explicitly enable cloud sync after signing in.
if you enable sync, an authenticated copy of your harbor state is stored so you can restore across devices. that copy is protected with tls in transit and infrastructure encryption at rest (aes-256). it is not end-to-end encrypted on-device yet. sanctuary systems can access synced state for operations and safety review as described here and in the trust center.
local-first by default. sync is opt-in. healing never requires an account. if our servers disappeared tomorrow, unsynced reflections would still be on your device.
the minimal threshold
we collect only what is necessary to keep the path open for you:
- a chosen name (the pseudonym you use)
- an email address, only if you opt into cloud sync or account recovery
- basic device information: device type, OS version, app version, and crash data
- app preferences and settings you configure
this is the minimal threshold. nothing more.
what we will never touch
these are structural boundaries, not best-effort promises:
- raw text of your cairn entries (these stay on your device)
- personal cairn content or cairn details (unless cloud sync is enabled, and then only in encrypted form)
- your real name, phone number, or contacts
- your location, camera, microphone, or photos
- advertising identifiers or biometric data
- your browsing history outside sanctuary
dove and the anthropic boundary
Dove is sanctuary's conversational companion, powered by Anthropic's language model. when you speak with Dove, your messages are sent to the Anthropic API in real time so that Dove can respond.
a short window of recent context is maintained locally on your device so conversation feels continuous. you can clear local dove history anytime.
limited conversation context may be retained for safety and abuse review as described in legal and the trust center. we do not sell dove messages. we instruct Anthropic not to use your conversations to train their models under our agreement.
authentication, cookies, and measurement
sanctuary uses secure session tokens for authentication when you sign in. they are not used to build advertising profiles from your reflections.
optional aggregate measurement (google tag manager / google ads) may run to understand how travelers find the harbor. it is consentable via the privacy banner and never receives your journal, dove chat, or cairn content. see trust.
trusted infrastructure
sanctuary works with a small number of trusted services:
- Anthropic: language model for Dove and expedition attunement
- Netlify: hosting and serverless functions
- Supabase: authentication and optional synced harbor state
- Stripe: sovereign billing when checkout is enabled
- Google Tag Manager / Google Ads: aggregate marketing measurement (consentable)
- Resend: operational safety alerts for crisis flags
each provider is limited to delivering their service. full list lives in the trust center.
one-click sovereignty
we keep your account data for as long as your account is active. when you choose to leave, we honor a complete account purge:
- account data is deleted from active systems upon request
- synced backups are purged within 90 days
- some anonymized, aggregate counts (not content) may be retained for understanding broad patterns
you have the right to be forgotten. when you delete your account, we delete it. we do not keep shadow profiles.
you can export everything sanctuary has stored about you when signed in. if you are in the EU, UK, or EEA, gdpr rights apply. if you are in california, ccpa rights apply.
children's privacy
sanctuary accounts are intended for adults aged 18 and older. we do not knowingly create accounts for anyone under 18. if we learn that a traveler under 18 has created an account, we will delete it and associated account data.
parents or guardians who believe their child has used sanctuary should contact us at hello@joinsanctuary.io.
changes to this policy
if we make material changes to this policy, we will notify you in the app before the changes take effect. the effective date at the top always reflects the current version. we will not quietly erode the commitments made here.
contact
questions, concerns, or requests about your data and sovereignty: