Privacy Policy
Last Updated: July 17, 2026
Effective Date: July 17, 2026
1. Overview & Data Controller
KATCHIMEDIA, LLC (“Company,” “we,” “us,” or “our”) operates The Trigger Tracker™ web application, mobile software, and internal backend data nodes (collectively, the “Service”). We respect your privacy and are deeply committed to protecting your personal data through strict architectural enforcement. This Privacy Policy outlines our methodologies for collecting, processing, routing, isolating, and erasing user data, explicitly aligned with the General Data Protection Regulation (GDPR) (EU) 2016/679, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and other global data frameworks.
The designated Data Controller for all data compiled through the Service is:
KATCHIMEDIA, LLC
1201 W Peachtree St NW Ste 2625 PMB 95440
Atlanta, GA, 30309-3499
Contact Email: privacy@katchimedia.com
2. Categories of Data Collected & Legal Basis
We handle data through minimalist ingestion methods to ensure data protection.
A. Data Provided Directly by the User
| Data Category | Specific Examples | Core Purpose | Legal Basis (GDPR Art. 6) |
|---|---|---|---|
| Account Identity | Email address, secure hashed password. | User authentication, session management, security alerts. | Performance of a Contract (Art. 6(1)(b)) |
| Subscription Data | Billing address, chosen tier, subscription status, tokenized Stripe descriptors (No raw credit card data is touched or stored by us). | Financial execution, processing renewals, recurring account upgrades. | Performance of a Contract (Art. 6(1)(b)) / Legal Obligation |
| Support Records | Communications, support tickets, email logs sent to customer care. | Addressing user issues, answering inquiries. | Legitimate Interests (Art. 6(1)(f)) |
B. Special Category Sensitive Data (Explicit Consent Required)
| Data Category | Specific Examples | Core Purpose | Legal Basis (GDPR Art. 9) |
|---|---|---|---|
| Trigger Logs & Journal Content | Tracked physiological symptoms (heart rate spikes, panic sensations), stress severity, emotional trigger descriptions, and open text journal entries. | Generating user dashboards, computing pattern recognition metrics, and enabling "generate-reframe" personalization options. | Explicit Consent (Art. 9(2)(a)) |
🔒 SPECIAL CATEGORY DATA ARCHITECTURE PROTECTION
Because data inputs to The Trigger Tracker™ contain details regarding personal mental wellness, trauma tracking, and physiological patterns, this data is classified as Special Category Data under GDPR Article 9 and Sensitive Personal Information under CCPA/CPRA.
We require explicit opt-in confirmation before you can log data. AI-personalized reframing is enabled by default for Premium accounts and can be turned off at any time from your account settings. You retain the absolute right to revoke your consent at any time. Revocation can be initiated by deleting specific data entries or formatting your complete account via the in-app settings panel. Upon account deletion, all active production logs will be permanently erased from our primary databases within 30 days.
C. Data Collected Automatically (Technical Infrastructure Logs)
Device & Connection Metrics: IP addresses (truncated and anonymized for analytics), operating system profiles, browser user-agent tokens, application crash logs, and hosting performance telemetry routed via Vercel.
Legal Basis: Legitimate Interests (Art. 6(1)(f)) to maintain absolute platform security, block DDoS vector threats, and prevent multi-tenant data cross-contamination.
3. AI Processing Architecture & Third-Party Sharing Rules
3.1 The Anthropic Claude API Integration: The Trigger Tracker™ utilizes the enterprise-grade Anthropic Claude API to drive its specialized “generate-reframe” personalization features. When a Premium user commands the system to parse a trigger log or reframe a stressful scenario, a secure text payload containing only the specific localized entry is passed via encrypted TLS channels to Anthropic PBC endpoints.
3.2 Strict Data Protection Zero-Retention Guardrails:
- No Training Consent: Under the strict enterprise data privacy agreements executed with Anthropic, no user data submitted from The Trigger Tracker™ is ever utilized, retained, or reviewed to train foundational AI models.
- Transient Context Isolation: Payload text segments are treated as transient query structures. No user names, billing parameters, or account email identifiers are ever attached or transmitted to the AI endpoint.
3.3 Data Processing Opt-Out: You can toggle off the “generate-reframe” features entirely within your profile control dashboard. Disabling this block prevents any text inputs from ever routing through third-party AI frameworks.
4. Data Processing Providers & Subprocessors
To maintain system operations, we share data with the following core subprocessors:
- Supabase, Inc.: Complete multi-tenant cloud backend database processing. Data is stored within isolated multi-tenant parameters with PostgreSQL Row-Level Security (RLS) active, ensuring no system users can access or exploit other users’ data nodes.
- Vercel, Inc.: Primary web app hosting, edge routing, deployment pipelines, and operational firewall security.
- Stripe, Inc.: Subscription management, customer billing portals, tokenized credit card authorization, and anti-fraud oversight.
- Resend, Inc.: Automated delivery of functional platform transactional emails, verification codes, and invoice receipts.
- GitHub, Inc.: Source control hosting, repository deployment monitoring, and automated build integrity.
5. Data Retention Matrix
| Data Structure | Active Retention Window | Post-Deletion Processing | Rationale |
|---|---|---|---|
| Account Profile & Email | Duration of active account lifecycle. | Hard deletion from PostgreSQL records within 30 days. | Basic account mapping. |
| Trigger Logs & Entries | Kept continuously while user account is active. | — | Core user-directed service feature. |
| Stripe Billing Data | Retained indefinitely as controlled by Stripe. | Kept per tax laws. | Strict adherence to statutory IRS and localized corporate audit regulations. |
| Technical Server Logs | Purged within 30 days. | Systematic automated deletion via Vercel rotation. | Infrastructure analytics and platform security monitoring. |
6. Your Rights Under Global Frameworks (GDPR & CCPA/CPRA)
Under applicable legal umbrellas, you possess the following actionable rights:
- Right of Access & Portability: You can request a clear, machine-readable export of all data logs, sensation matrices, and journal entries linked to your profile. This is downloadable directly via a single-click JSON or CSV mechanism inside your settings interface.
- Right to Rectification: You can modify, edit, update, or completely rewrite individual logs, entry notes, and identity parameters within the application screens at your discretion.
- Right to Erasure (“Right to Be Forgotten”): You can request complete termination of your data files. Upon request, all data records except required corporate financial records are completely purged.
- Right to Object & Restrict Processing: You possess the unconditioned right to withdraw your consent for sensitive data parsing, block AI processing linkages, and restrict transactional communication arrays.
- Right to Non-Discrimination: The Company will never restrict user options, degrade system metrics, or alter pricing layers for any user choosing to exercise their legal data privacy rights.
To enforce any of these rights, please execute your requests within the software settings dashboard or transmit an official legal notice to our privacy desk: privacy@katchimedia.com.