Privacy policy.
Last updated 24 August 2026.
The short version
Your ledger is encrypted before storage. It is never sold or shared with advertisers, and only people you choose can see it. The site has no analytics, ads, or third-party scripts. Accounts require no email address, phone number, or third-party sign-in.
What is collected
An account and its ledger consist of:
- Your username, display name, and a memory-hard scrypt hash of your password.
- Your commitments, marks, and daily check-ins.
- Ideas and notes you save. These stay private even when you share your ledger.
- Shares, groups, visibility settings, and reactions.
- Your time zone, so dates follow your local day.
Hosting logs may include IP addresses for security and operations.
What is not collected
There are no analytics, ads, tracking pixels, session recorders, or third-party scripts. Your password is not stored; only its memory-hard scrypt hash is kept inside the encrypted account record. Your data is not sold, rented, used for advertising, or used to train models.
Cookies
One necessary, non-tracking cookie is used:
- __Host-fd_session — your encrypted, origin-bound session. It lasts thirty days. Changing your password ends other sessions.
How it is protected
Ledger data is encrypted with AES-256-GCM before storage. Each account has a separate encryption key, sealed by AWS KMS. Your username is encrypted and indexed only by a keyed hash; your password hash sits inside the same encrypted record. Traffic uses TLS with HSTS preloading.
Who else can see it
Sharing is off by default and can be revoked at any time. It is settled one person at a time: for each person you choose whether they see your year grid at all, and on top of that whether they also see the wording of your commitments and whether they may open your month day by day. Any of it can be turned off again later. Being in a group with somebody shares nothing by itself — it only puts them on your list, where you decide. They see your username and display name, but no other account details.
Amazon Web Services hosts the app and database. Data may also be disclosed when legally required.
Where it is stored
Data is stored on Amazon Web Services in the United States. UK and EEA data is transferred under AWS safeguards for international transfers.
Your rights, and deletion
You can ask for a copy, correction, or deletion of your data. Deletion removes the account and ledger and destroys its encryption key.
There is no address to send that request to. This site publishes none, because no mailbox stands behind one and an address that bounced would be worse than none at all. So there is at present no route for making the request; if that changes, it will be named here.
Accounts hold no contact details either way, and only a hash of the recovery code is stored. Without the password or the code, the ledger cannot be recovered by anyone.
Changes
The date above changes when this policy does.
Contact
There is none to publish. This site asks for no address and keeps none, and it does not offer one of its own. What it holds about you is what the sections above describe.