What happens to what you write
Draft, pending review by a Dutch privacy lawyer before public launch. The substance below describes how the app is actually built; the wording may change. Last updated: see the repository history.
The short version
Everything you type into 90 Days is stored by your browser, on your device. It is not sent to us. We do not have an account system, we do not run analytics on what you write, and there is no crash reporter that captures your entries. For the app as it exists today, the honest label is: no data collected.
Where the data lives
- On your device only. Your day log, lapse notes, your written why and your plan are kept in this browser's local storage (IndexedDB) for this site. They stay there until you or the browser removes them.
- No account. The app works fully without signing up. There is no email address, no username, no password.
- What the web server sees. Serving the page involves an ordinary web request, so the hosting provider sees the usual technical details of that request, such as your IP address, for delivery and abuse prevention. That is about the page load, not about what you write in the app. Once the app has loaded it works offline.
- Fonts. The pages load typefaces from Google Fonts, which means your browser makes a request to Google's font servers. No app content is involved in that request.
Why we built it this way
Information about someone's sexual behaviour is special category data under the GDPR, the same tier as health records. The safest way to handle it is not to hold it. That is a design decision rather than a policy promise, which is the only kind worth trusting.
Sync across devices: opt in, off by default
Sync exists, and it is off until you turn it on. With it off, nothing leaves your device and no server of ours receives anything from the app. Turning it on is a separate, explicit choice, not something bundled into accepting terms.
- Your data is encrypted on your device, with a passphrase you choose, before any of it leaves. The server holds exactly five things: a random account identifier, the salt, the initialisation vector, the encrypted blob and a timestamp. It does not hold the passphrase and cannot read the contents.
- If you lose the passphrase, the synced copy cannot be recovered, not by you and not by us. That is a consequence of the server not being able to read it, and there is no way to have both.
- You can turn sync off and delete the stored blob at any time, from the 90 tab.
The optional recovery email. Sync works on one device without any address. To open the same backup on a second device you can attach an email address to the account. It is stored by our authentication provider, Supabase, alongside the random account identifier, not in the table holding the encrypted blob, and never next to anything readable about you. It is used for one thing: sending a six digit code so a device can prove which account to open. We never email you about your progress, and the address cannot decrypt anything, because the passphrase is still required afterwards. Deleting everything deletes the account, and the address with it.
Deleting and exporting
- Deleting. The 90 tab has a "Delete everything" button. It wipes this device, and if sync is on it also deletes the encrypted blob and the account, including any recovery email, from the server. You can also clear this site's storage in your browser settings, or delete the app from your home screen along with its site data. With sync off there is nothing on our side to request the deletion of.
- Exporting. The app has a JSON export on the 90 tab. It writes a file containing your own data, which covers portability and doubles as your backup.
Things we will not add
Analytics on your entries. A crash reporter that captures app state. Server side backups of readable data. An AI feature that sends your notes to any API. Notifications keyed to your behaviour. Selling, sharing or analysing what you write, at any price.
Contact
Questions about this page, or about data protection generally: [CONTACT EMAIL]. If you are in the EU you also have the right to complain to your national data protection authority; in the Netherlands that is the Autoriteit Persoonsgegevens.