Private by design
Privacy Policy
CaveSignal is built around sensitive personal check-ins, so collecting less and limiting access are core product requirements.
Effective September 14, 2026
What we process
We process account details such as your email and display name; feelings, support preferences, and notes you choose to save; consent records; trusted-connection, sharing, invitation, and Cave Note data; and limited technical information needed for security, reliability, and fraud prevention. Invitation secrets are stored only as one-way hashes.
Why we process it
We use this information to authenticate you, save your private history, provide features you request, protect the service, and understand reliability without placing private note content in routine analytics.
Who can see it
Check-ins are private to your account by default. CaveSignal does not sell emotional or journal data and does not use it for targeted advertising. Creating or accepting a trusted connection does not reveal your existing check-ins. Sharing requires you to choose the recipient and confirm the specific share.
Service providers
CaveSignal uses carefully scoped providers to operate the service, including Vercel for hosting, Supabase for authentication and data, Cloudflare for security verification, and Google when you choose Google sign-in. They process data under their own contractual and security obligations.
Retention and control
We retain information while it is needed to operate your account, meet security and legal requirements, or resolve disputes. Clearing history hides those check-ins from your account. You can export your retained account data or permanently delete your account and stored signals from the Account page.
Security and age
We use encrypted connections, server authorization, database row policies, security challenges, and limited data exposure. No online service can promise perfect security. CaveSignal’s current beta is limited to adults aged 18 or older.
