Skip to content
← The Trigger Tracker

Privacy Policy

Last Updated: August 25, 2026
Effective Date: July 17, 2026

The short version

This is a plain summary, not the legal text. The full policy below is the one that applies.

What we collect

We collect your email address. We collect what you log. That means what you write, where in your body you felt it, and how strong it was. We also record your IP address when you ask us to email you a sign-in link.

What we never do

We never sell your data. We never show you ads. We never use your entries to train AI models.

Who can see it

You can see your entries. Our database is set up so that no other user can read them. A few services help run the app. One stores your data. One handles payments. If you pay for Full Access, a single entry can be sent to an AI service to write your reframe. You can turn that off in Settings.

How long we keep it

We keep your entries until they are deleted. We erase the sign-in records after 30 days. When your account closes, we erase your data within 30 days.

How to delete it

Go to Settings and choose “Delete your account”. This erases your account and everything you logged. You can also email privacy@katchimedia.com and we will do it for you. If you pay for Full Access, deleting also cancels it, and the rest of the period you paid for is not refunded.

1. Overview & Data Controller

KATCHIMEDIA, LLC (“Company,” “we,” “us,” or “our”) operates The Trigger Tracker™ web application, mobile software, and internal backend data nodes (collectively, the “Service”). We respect your privacy and are deeply committed to protecting your personal data through strict architectural enforcement. This Privacy Policy outlines our methodologies for collecting, processing, routing, isolating, and erasing user data, explicitly aligned with the General Data Protection Regulation (GDPR) (EU) 2016/679, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and other global data frameworks.

The designated Data Controller for all data compiled through the Service is:

KATCHIMEDIA, LLC

1201 W Peachtree St NW Ste 2625 PMB 95440

Atlanta, GA, 30309-3499

Contact Email: privacy@katchimedia.com

2. Categories of Data Collected & Legal Basis

We handle data through minimalist ingestion methods to ensure data protection.

A. Data Provided Directly by the User

Data CategorySpecific ExamplesCore PurposeLegal Basis (GDPR Art. 6)
Account IdentityEmail address, secure hashed password.User authentication, session management, security alerts.Performance of a Contract (Art. 6(1)(b))
Subscription DataBilling address, chosen tier, subscription status, tokenized Stripe descriptors (No raw credit card data is touched or stored by us).Financial execution, processing renewals, recurring account upgrades.Performance of a Contract (Art. 6(1)(b)) / Legal Obligation
Support RecordsCommunications, support tickets, email logs sent to customer care.Addressing user issues, answering inquiries.Legitimate Interests (Art. 6(1)(f))

B. Special Category Sensitive Data (Explicit Consent Required)

Data CategorySpecific ExamplesCore PurposeLegal Basis (GDPR Art. 9)
Trigger Logs & Journal ContentTracked physiological symptoms (heart rate spikes, panic sensations), stress severity, emotional trigger descriptions, and open text journal entries.Generating user dashboards, computing pattern recognition metrics, and enabling "generate-reframe" personalization options.Explicit Consent (Art. 9(2)(a))

🔒 SPECIAL CATEGORY DATA ARCHITECTURE PROTECTION

Because data inputs to The Trigger Tracker™ contain details regarding personal mental wellness, trauma tracking, and physiological patterns, this data is classified as Special Category Data under GDPR Article 9 and Sensitive Personal Information under CCPA/CPRA.

We require explicit opt-in confirmation before you can log data. AI-personalized reframing is enabled by default for Premium accounts and can be turned off at any time from your account settings. You retain the absolute right to revoke your consent at any time. Revocation can be initiated by deleting specific data entries or formatting your complete account via the in-app settings panel. Upon account deletion, all active production logs will be permanently erased from our primary databases within 30 days.

C. Data Collected Automatically (Technical Infrastructure Logs)

Device & Connection Metrics: IP addresses (truncated and anonymized for analytics), operating system profiles, browser user-agent tokens, application crash logs, and hosting performance telemetry routed via Vercel.

Authentication Abuse Log: Separately from the analytics telemetry described above, and unlike it, we record the full IP address of any request that asks us to send an authentication email (a sign-in link, a signup confirmation, or a password reset). This log exists for one purpose: to stop the signup form being used to send unwanted email to people who never requested it. It is never used for analytics, advertising, or profiling. Entries are retained for 30 days and then deleted automatically. The email address in each entry is stored only as a cryptographic hash, never in readable form, so the log cannot be used to reconstruct who was contacted.

Legal Basis: Legitimate Interests (Art. 6(1)(f)) to maintain absolute platform security, block DDoS vector threats, prevent abuse of our authentication forms against third parties, and prevent multi-tenant data cross-contamination.

3. AI Processing Architecture & Third-Party Sharing Rules

3.1 The Anthropic Claude API Integration: The Trigger Tracker™ utilizes the enterprise-grade Anthropic Claude API to drive its specialized “generate-reframe” personalization features. When a Premium user commands the system to parse a trigger log or reframe a stressful scenario, a secure text payload containing only the specific localized entry is passed via encrypted TLS channels to Anthropic PBC endpoints.

3.2 Strict Data Protection Zero-Retention Guardrails:

  • No Training Consent: Under the strict enterprise data privacy agreements executed with Anthropic, no user data submitted from The Trigger Tracker™ is ever utilized, retained, or reviewed to train foundational AI models.
  • Transient Context Isolation: Payload text segments are treated as transient query structures. No user names, billing parameters, or account email identifiers are ever attached or transmitted to the AI endpoint.

3.3 Data Processing Opt-Out: You can toggle off the “generate-reframe” features entirely within your profile control dashboard. Disabling this block prevents any text inputs from ever routing through third-party AI frameworks.

4. Data Processing Providers & Subprocessors

To maintain system operations, we share data with the following core subprocessors:

  • Supabase, Inc.: Complete multi-tenant cloud backend database processing. Data is stored within isolated multi-tenant parameters with PostgreSQL Row-Level Security (RLS) active, ensuring no system users can access or exploit other users’ data nodes.
  • Vercel, Inc.: Primary web app hosting, edge routing, deployment pipelines, and operational firewall security.
  • Stripe, Inc.: Subscription management, customer billing portals, tokenized credit card authorization, and anti-fraud oversight.
  • Resend, Inc.: Automated delivery of functional platform transactional emails, verification codes, and invoice receipts.
  • GitHub, Inc.: Source control hosting, repository deployment monitoring, and automated build integrity.

5. Data Retention Matrix

Data StructureActive Retention WindowPost-Deletion ProcessingRationale
Account Profile & EmailDuration of active account lifecycle.Hard deletion from PostgreSQL records within 30 days.Basic account mapping.
Trigger Logs & EntriesKept continuously while user account is active.Core user-directed service feature.
Stripe Billing DataRetained indefinitely as controlled by Stripe.Kept per tax laws.Strict adherence to statutory IRS and localized corporate audit regulations.
Technical Server LogsPurged within 30 days.Systematic automated deletion via Vercel rotation.Infrastructure analytics and platform security monitoring.

6. Your Rights Under Global Frameworks (GDPR & CCPA/CPRA)

Under applicable legal umbrellas, you possess the following actionable rights:

  • Right of Access & Portability: You can request a clear, machine-readable export of all data logs, sensation matrices, and journal entries linked to your profile. This is downloadable directly via a single-click JSON or CSV mechanism inside your settings interface.
  • Right to Rectification: You can modify, edit, update, or completely rewrite individual logs, entry notes, and identity parameters within the application screens at your discretion.
  • Right to Erasure (“Right to Be Forgotten”): You can request complete termination of your data files. Upon request, all data records except required corporate financial records are completely purged.
  • Right to Object & Restrict Processing: You possess the unconditioned right to withdraw your consent for sensitive data parsing, block AI processing linkages, and restrict transactional communication arrays.
  • Right to Non-Discrimination: The Company will never restrict user options, degrade system metrics, or alter pricing layers for any user choosing to exercise their legal data privacy rights.

To enforce any of these rights, please execute your requests within the software settings dashboard or transmit an official legal notice to our privacy desk: privacy@katchimedia.com.