What we can see, and what we can’t.

Everything you write here is encrypted on your device before it is sent, and we do not hold the key. This page is the complete list of what that leaves us able to see.

Written in plain language on purpose, and current as of 30 August 2026. A lawyer will tighten the wording before long; the promises will not get weaker.

The one place your words travel readable.

To generate a reply, your message and the recent conversation are sent to Anthropic, the AI provider, unencrypted - a model cannot read sealed bytes. We do not store, log or keep any of it, and under our zero-data-retention arrangement Anthropic does not retain it after the request completes and does not train on it.

We are telling you this rather than implying it does not happen. Any service running an AI chat has this same step; the difference is whether they say so, and what happens to your words on their side of it. Here: nothing is kept.

Everything we hold.

This is the whole list, not highlights.

  • Your sign-in email address

    It is how you sign in and how we reach you about your account. This is the one piece of readable personal information we keep on purpose.

  • Scrambled fingerprints of email and IP address

    One-way keyed hashes used to stop abuse of sign-in and safety limits. They cannot be reversed into the original.

  • Your conversations, memory, practice plans and questionnaire answers - as sealed bytes

    Encrypted on your device before they are sent. We do not hold the key, so we cannot read them: not for support, not for training, not under pressure.

  • Lesson progress and quiz choices

    Which lessons you finished and which fixed option you picked. Never free text.

  • Subscription status

    Whether you are trialling, subscribed or lapsed, kept in sync with Stripe. Card numbers never touch us; they go to Stripe directly.

  • Timestamps, counts and running costs

    When you sign in, how many messages you send and when. We also keep a monthly total of what your replies cost us to generate. That is a length and a price, never what you wrote. Billing and abuse prevention, nothing else - though we say plainly that timing patterns are themselves a signal, and this is the strongest one we can see.

What is not on the list, because it does not exist: advertising trackers, analytics on what you write, profiles of your symptoms, and data sales. There is nothing to sell - we cannot read the only thing that would be worth anything.

Cookies: signing in sets the essential cookies that keep you signed in, and that is all. No tracking cookies, no advertising cookies, no third-party cookies.

Who processes it.

Six companies touch some part of the list above, each for one job. No advertising partners, no data brokers.

  • Anthropic

    Runs the AI model. The one place your words travel unencrypted - see above. Zero data retention: inputs and outputs are not kept after the request and are not trained on.

  • Stripe

    Payments. Your card details go to Stripe, never to us.

  • Resend

    Sends sign-in links and billing emails. Sees your email address.

  • Vercel

    Hosts the website and holds its server logs, which is where errors are monitored. The AI path is built to log nothing, so what you write does not reach them.

  • MongoDB Atlas

    Stores the data listed above, sealed bytes included.

  • Microsoft Clarity

    Engagement analytics on the landing and pricing pages only - how visitors move around those two pages. It does not run inside the app, and it is nowhere near anything you write.

Most of these companies are based in the United States, so the data each one handles crosses borders: your email address to Stripe and Resend, server logs to Vercel, and the one unencrypted model call to Anthropic. Your sealed conversations cross borders too, and stay exactly as unreadable there as here - the key never travels at all.

Support staff see metadata, never words.

An administrator can look an account up by email and see the same metadata listed above - status, sign-in times, subscription state - to help with billing or access. Every administrative action is logged with who did it and when. An administrator cannot read a conversation, for the same reason nobody else can: the key is not here.

Deleting, and being forgotten.

Resetting your vault destroys every sealed record immediately and keeps your account. Losing every unlock method you enrolled means your conversations are already gone for good - we cannot recover them, and that is the design, not a failure of it.

To delete your account entirely, email hello@usemaybe.app from your sign-in address and it is done, including the email address itself.

Your rights, and the law this runs under.

This service is operated from Australia and handles personal information under the Australian Privacy Principles, including the notifiable data breaches scheme. It is for adults: 18 or over, or younger with a parent or guardian’s knowledge and agreement, as the sign-up asks.

If this policy changes in a way that matters, you get an email before the change applies - the same promise the terms make, because a privacy policy edited quietly is not worth the page it sits on.

Questions, complaints, or a request to see what we hold about you: hello@usemaybe.app. If our answer does not settle it, the Office of the Australian Information Commissioner takes complaints at oaic.gov.au. The terms of use are at /terms.