stillroom.
PERSONAL MEANS PERSONAL

Privacy Policy

Template requiring legal review before commercial launch. The operator must add its legal name, contact details, jurisdiction, retention periods, vendor list, and applicable privacy rights. This template describes the current MVP and is not legal advice.

What we collect.

We store your email, hashed password, display name, adult confirmation, preferences, session cookies, and account activity needed for security. Optional records include mood check-ins, journal entries and tags, saved messages, bookings, conversation messages, and contact requests.

Your journal and conversations.

Journal entries are accessible through your own account. The ordinary admin dashboard sees journal usage counts only. A paid session’s conversation is available to the booked member and the session host. Journal and chat text are excluded from product analytics and routine application logs.

Payments.

The payment provider handles card information. We do not store raw card details. We retain transaction identifiers, amounts, currencies, payment status, and booking records. Sandbox transactions in this preview are simulated.

Security and access.

Production connections use HTTPS. Passwords are salted and hashed with scrypt. Access is controlled on the server for private records. No online service can guarantee absolute security. Staff with infrastructure access may have technical access to stored data; operational access should be restricted and audited.

Emails and preferences.

Verification and reset emails are needed to manage an account. Daily reminders and booking emails are optional. Product news requires separate consent. You can change your preferences in Settings. No marketing campaign is sent by this MVP.

Privacy-conscious analytics.

We record limited first-party events, such as registration, opening a message, creating an entry, or completing a booking. We do not collect journal or chat contents in analytics. We do not install third-party advertising trackers. Operational security events help protect accounts.

Export and deletion.

Settings allows a JSON download of your account records, deletion of journal entries, and account deletion. Account deletion removes preferences, journals, moods, saved messages, notifications, and session chat content. Bookings and transactions are disconnected from the deleted account. The operator must define a financial retention policy before launch. Backups may retain data until their defined expiry.

Providers and retention.

The configured hosting/database platform, payment provider, and email provider process data needed to deliver the service. The operator must document each provider and any international transfers before launch. Retention periods and backup handling require a written policy.

Questions or requests.

Use the Privacy category in our contact form. Operator privacy contact: [TO BE COMPLETED BEFORE LAUNCH].