CarryThis (carrythis.app) is a free psychological workbook and daily habit tracking app. This policy explains exactly what data we collect, why we collect it, where it goes, and what control you have over it. We wrote this in plain language because you deserve to actually understand it.
1. What We Collect
Here is every piece of data we store on our servers, with nothing omitted. What the app keeps on your device, which never reaches us, is listed straight after it.
Email address
Provided when you create your account. Used to log you in and send reminder emails if you enable them.
Your name, if you give it
Two optional places ask for a name and we store both. The display name you can set on your dashboard or settings page is kept with your account and used to greet you in the app and in reminder emails. The name you sign the workbook contract with, on the final step, is stored with your workbook answers. Both appear in your JSON export; either name can appear in your PDF — the contract name where you signed, the display name on the cover. You can change or blank either one at any time, and neither is required to use CarryThis.
Password
Hashed by Supabase Auth before storage. We never see or store your actual password.
Workbook answers
Your text responses across the seven workbook steps. This is deeply personal content, and it stays private (see section 4).
Daily check-in data
Your daily responses (yes, partial, or no) and the dates they were recorded. Written reflections are notstored on our servers today — the columns for them are not live, so they stay on your device only. See “what is kept on your device” below.
User settings
Your preferred reminder time and timezone. Used to send reminders at the right time.
Push notification subscription
If you opt in to push notifications, we store a VAPID-based subscription endpoint. This is handled directly between your browser and our server; no third-party push services are involved.
That is everything we hold on our servers. We do not collect your phone number, location, IP address logs, device fingerprints, or any other personal information beyond what is listed above.
Also: what is kept on your device
The app also keeps text in your browser’s local storage, on the device you are using. This is a safety net: writing is mirrored there the instant you type it, before anything is sent to us, so a failed save or a closed tab does not destroy it. It never leaves your device. It is not sent to us, is not attached to your account, is not visible on your other devices, and is not included in the JSON or PDF export. If you clear your browser’s site data, anything here that has not been saved to your account is gone.
Unsaved workbook text (ct:draft:…)
A copy of what you type in the workbook, written on every keystroke and deleted the moment our server confirms it was saved. Text that never saved stays until you clear it; entries older than 180 days may be dropped if your browser runs out of storage space.
Replaced workbook answers (ct:displaced:…)
If two open tabs disagree about an answer, the version that was replaced is kept here instead of being destroyed, so you can get it back. Deleted only when you choose to discard it.
Daily reflections (ct:reflection:…)
Your answers to “what went well” and “what would you adjust”. Today this is the only place these exist: the database columns they belong in are not live yet, so the save fails and the text remains on this device alone. It is not in your account and not in your export. Deleted when a save finally succeeds, or when you discard it.
Recovery note (ct:recovery:…)
What you type into “one small thing you can do right now” on a partial or missed day. Like the reflection above, this cannot reach our servers today, so it stays here until you clear it.
Preferences (theme, carrythis-install)
Whether you chose light or dark, and whether you dismissed the “add to home screen” prompt (with a count of how many times it was shown). No writing of yours is in either. These stay until you clear your site data.
Momentary keys (ct:saved:…, email-banner-dismissed)
When one tab saves an answer it announces the new value to your other tabs through a key that is written and removed in the same instant; nothing is retained. The dismissal of the “confirm your email” banner is kept in session storage and disappears when you close the tab.
How to clear it:the app’s own Discard buttons remove a specific draft, and clearing site data for carrythis.app in your browser settings removes all of it at once (that also signs you out, and permanently erases anything not yet saved to your account). Clearing on-device storage does not touch what is stored on our servers, and deleting your account does not reach into your browser: do both if you want everything gone.
2. Why We Collect It
Every piece of data maps to a specific function. There is no data collected “just in case” or for future use.
| Data | Purpose |
|---|---|
| Account login, password reset, email reminders | |
| Name | Greet you in the app and in reminder emails; sign your workbook contract |
| Password hash | Authentication |
| Workbook answers | Save your progress, generate your PDF export |
| Check-in data | Track your daily streaks and consistency |
| Settings | Send reminders at the time and timezone you chose |
| Push subscription | Deliver push notifications you opted into |
3. Where Your Data Is Stored
Your data lives on infrastructure provided by the following services, all of which are based in the United States:
- Supabase: Hosts the database where your account, workbook answers, check-in data, and settings are stored. Also handles authentication.
- Cloudflare: Hosts the application, provides DNS and network security, and delivers the email reminders you asked for. Cloudflare processes your requests and receives your email address solely to send those messages. It does not have access to your stored workbook data.
4. Who Can See Your Data
You, and only you.
Your workbook answers and check-in responses are protected by Supabase Row Level Security (RLS) policies. This means the database itself enforces that only your authenticated account can read or modify your data. There is no admin panel that lets us browse user content. We built it this way on purpose.
We do not sell, share, rent, or give your data to any third party. Not for advertising, not for analytics, not for research, not for any reason. There are no exceptions.
5. Cookies
We use one cookie: the Supabase authentication session cookie. It keeps you logged in. That is its only function.
We do not use tracking cookies, advertising cookies, analytics cookies, or any third-party cookies. There is no cookie banner because there is nothing to consent to beyond basic session management.
6. Third-Party Services
We use two external services to run CarryThis. Each has its own privacy policy:
We do not use Google Analytics, Mixpanel, Facebook Pixel, or any analytics or advertising service. There is no tracking code on this site.
7. Data Retention
Your data is kept for as long as your account exists. If you delete your account, all associated data (workbook answers, check-in history, settings, and push subscriptions) is permanently deleted. We do not keep backups of deleted accounts.
If you reset your workbook through the settings page, your workbook answers are permanently deleted at that time. Check-in data is retained separately unless you delete your account entirely.
8. Your Rights
Regardless of where you live, we extend the same rights to all users:
Access your data
Everything you have entered is visible in the app at any time. Your workbook, your check-ins, your settings: it is all accessible to you directly.
Export your data
From your settings page you can download a complete, machine-readable export of your account details, workbook answers, check-ins, and settings as a JSON file. You can also export your workbook as a human-readable PDF from your dashboard. The PDF is generated in your browser; the JSON export is assembled on our server from your own records and returned only to you. Both cover what is stored on our servers: text still held only on your device, including your daily reflections, is not in either file (see section 1).
Delete your data
You can reset your workbook from the settings page, or request full account deletion by contacting us at hello@carrythis.app. Deletion requests are processed within 30 days.
Opt out of communications
You can disable email reminders and push notifications at any time from the settings page. We will never email you for marketing purposes.
For California residents (CCPA): You have the right to know what personal information we collect, to request its deletion, and to not be discriminated against for exercising these rights. We do not sell personal information. To make a request, email hello@carrythis.app.
For EU/EEA residents (GDPR): Our legal basis for processing your data is your consent (you created an account) and legitimate interest (delivering the service you signed up for). You have the right to access, rectify, erase, restrict processing of, and port your personal data. You may also withdraw consent or lodge a complaint with your local data protection authority. To exercise any right, email hello@carrythis.app.
9. Children
CarryThis is not designed for anyone under the age of 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, please contact us at hello@carrythis.app and we will delete it immediately.
10. Changes to This Policy
If we change this policy, we will update the date at the top of this page. For significant changes (like adding a new third-party service or changing how we handle data) we will notify you by email. We will not reduce your rights or expand our data collection without clear notice.
11. Contact
If you have questions about this policy or your data, reach us directly:
CarryThis is operated from the United States.