SessionGauge Privacy Policy
1. About this policy
This policy explains how SessionGauge handles personal information when you use its mobile app and related authentication pages.
SessionGauge helps you record and review personal sessions, medications, observations, and related information. These records may reveal sensitive information about your health or substance use.
This policy covers the current Personal Mode service. It does not describe a future professional or clinical service.
2. Information we handle
Depending on the features you use, we handle:
- Account information: your email address, account identifier, authentication information, and information supplied through Google when you choose Google sign-in.
- Profile information: information you enter in your profile and an optional profile photograph.
- Emergency contacts: names, contact details, and other information you choose to enter. Provide another person’s information only when you have permission or another appropriate basis to do so.
- Personal records: medications, session titles and timestamps, recorded substances, observations, self-reports, notes, session state changes, and associated saved reference or warning records.
- Preferences: display settings, time format, auto-lock choices, and biometric sign-in enrollment status.
- Support information: information you voluntarily send when contacting us.
- Technical information: [VERIFY AND LIST ACTUAL SERVER, AUTHENTICATION, SECURITY, CRASH, AND WEBSITE LOG DATA; INCLUDE IP ADDRESSES AND DEVICE INFORMATION ONLY WHERE COLLECTED].
We receive personal records from you and generate certain records through your use of the app, such as session timestamps and state changes.
3. How we use information
We use information to:
- Create and authenticate your account.
- Save, retrieve, and display your personal records.
- Provide the features you request, including session history and data exports.
- Apply your preferences and protect access to your account.
- Deliver account confirmation and password-recovery emails.
- Respond to support requests.
- Maintain service reliability, investigate problems, and address unauthorized access.
- Meet applicable legal obligations.
[CONFIRM WHETHER DATA IS USED FOR ANALYTICS, RESEARCH, ADVERTISING, OR AI TRAINING. DESCRIBE ANY SUCH USE AND REQUIRED CHOICES BEFORE PUBLICATION.]
4. Service providers and disclosures
SessionGauge uses service providers to operate the service:
- Supabase: account authentication, database hosting, and file storage.
- Resend: delivery of authentication emails, such as confirmation and password recovery.
- Cloudflare: hosting and delivery of the authentication website.
- Google: optional Google sign-in, when you choose it.
Providers receive information relevant to their functions. For example, email delivery involves the recipient address and email contents. Listing a provider does not mean that every provider receives your personal session records.
When you export and share information, the destination you select receives that exported information. Its handling is governed by that destination’s practices.
We may disclose information when legally required, to respond to valid legal process, or as permitted by law to address fraud, security threats, or threats to safety.
Sale and advertising disclosures: [CONFIRM WHETHER INFORMATION IS SOLD, SHARED FOR TARGETED ADVERTISING, OR USED FOR ADVERTISING. INSERT AN ACCURATE STATEMENT.]
Processing locations: [IDENTIFY ACTUAL HOSTING LOCATIONS AND RELEVANT CROSS-BORDER PROCESSING.]
5. Biometric sign-in and device storage
Biometric verification is performed by your device’s operating system. SessionGauge does not collect or store fingerprint images or facial biometric templates.
If you enable biometric sign-in, the app stores encrypted authentication credentials on your device so you can restore access after successful biometric verification.
Signing out can preserve biometric sign-in on that device. To remove it, disable biometric sign-in or select Remove saved sign-in from this device. Signing out is not the same as deleting your account or all saved credentials.
Some preferences and temporary export files are also stored on your device. Export files shared or saved outside the app remain under your control and are not removed when the app cleans up its temporary files.
6. Security
SessionGauge uses safeguards intended to limit unauthorized access, including authenticated access controls and protected storage for biometric sign-in credentials.
No system is completely secure. Protect your device, account credentials, and exported files. Device biometric enrollment should include only people you trust to access your account.
SessionGauge is not represented as an end-to-end encrypted vault. Authorized service operation and infrastructure may require access to stored information.
7. Retention and deletion
We retain information according to the following schedule:
- Account and personal records: [5 years].
- Operational and security logs: [2 Years].
- Backups: [2 Years].
- Support correspondence: [2 Years].
Hiding a session from history does not necessarily permanently erase its underlying records. Signing out or uninstalling the app does not delete information stored in the hosted service.
The current beta provides in-app account deletion for accounts that can confirm with an email and password. From Profile, Delete account permanently deletes this SessionGauge login and the online application records SessionGauge controls for this account, including personal records and profile photos. Shared reference catalogs and other people’s accounts stay. Backups, previously cached copies, and exports saved outside the app may remain. SessionGauge does not claim those copies are erased, does not invent how long they last, and cannot undo this action.
Google sign-in is not a supported in-app deletion step. If you cannot use a password in the app, email [email protected] to request deletion. Sending that message does not delete the account, and this policy does not promise a response time.
If an account cannot be deleted from the app because it is tied to professional records or another person’s session, email [email protected] for help.
8. Your choices and requests
You can edit supported profile information, manage preferences, and enable or disable biometric sign-in.
The app offers personal-data exports in JSON, CSV ZIP, Excel, PDF, and HTML. Exports describe their scope and limitations. Photographs are currently excluded; readable reports may not contain every field present in structured exports. Exports are not an import or restore backup.
Depending on your location and applicable law, you may have rights to access, correct, delete, or obtain a copy of your information, or to object to or restrict certain processing.
Contact [email protected] to make a request. We may need to verify your identity. [ADD ANY APPLICABLE APPEAL PROCESS AND REGION-SPECIFIC NOTICES.]
9. Age eligibility
SessionGauge is intended for people aged [18] and older.
If you believe a person below that age has provided personal information, contact [email protected] so we can investigate and take appropriate action.
10. Changes and contact
We will update the effective date when this policy changes. For material changes, we will provide notice and obtain consent where required by law.
Questions or privacy requests: [email protected].