Privacy Policy

Last updated: February 22, 2026

Overview

Protocol is a habit tracking app. We collect the minimum data necessary to provide the service. We do not sell your data, run ads, or track you across the web.

What We Collect

When you use Protocol, we store:

  • Account information: email address and hashed password
  • Habit data: the habits you create, their domains, and daily completion records
  • Mood entries: daily mood ratings you optionally record
  • Journal entries: text entries you optionally write
  • Timer data: time tracking records for habits with timers enabled
  • Notes: optional notes attached to habit completions

How We Use Your Data

Your data is used solely to provide the Protocol service to you. This includes displaying your habits, calculating streaks, generating trend charts, and syncing across your devices. We do not use your data for advertising, analytics, or any purpose other than running the app.

Data Storage & Security

Your data is stored in a Supabase-hosted PostgreSQL database with row-level security enabled. This means your data is isolated — only you can access it through your authenticated account. Data is encrypted in transit (TLS) and at rest.

Third-Party Services

We use the following third-party services to operate Protocol:

  • Supabase — database and authentication
  • Vercel — web hosting and deployment
  • Stripe — payment processing (if applicable)

These services have their own privacy policies. We do not share your habit data, journal entries, or mood records with any third party.

Cookies

Protocol uses only essential cookies required for authentication (session cookies). We do not use analytics cookies, advertising cookies, or any third-party tracking scripts.

Data Export & Deletion

You can export all of your data as a JSON file at any time from your account settings. You can permanently delete your account and all associated data at any time. Deletion is immediate and irreversible.

Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access your personal data (available via data export)
  • Rectify inaccurate data (editable in the app)
  • Erase your data (account deletion)
  • Port your data (JSON export)
  • Object to processing (contact us)

Children's Privacy

Protocol is not intended for children under the age of 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, please contact us and we will delete it.

Changes to This Policy

We may update this privacy policy from time to time. Continued use of Protocol after changes constitutes acceptance of the updated policy. The date of the last update is shown at the top of this page.

Contact

If you have questions about this privacy policy or your data, contact us at hello@getprotocol.me.