Privacy
The short version
No ads. No tracking cookies. No data selling. Your reflections stay on your device unless you choose to save them, and finishing keeps an anonymous count of your answers — no name, no email, and nothing you typed unless you tick the box to show it on the community wall. AI processing by Anthropic (they don't train on your data). Anonymous analytics via Plausible. You can delete everything anytime (a card you put on the community wall comes down from the device you added it on).
Your creative journey is personal. Here's how we treat your data:
Your conversations and reflections: The free-text responses you type during the experience (memories, project descriptions, chat messages) are sent to Anthropic's AI to personalize your experience in real time, but they are not stored on our servers unless you choose to save your journey (see below). Your conversations are not saved after your session ends unless you opt in.
What we do collect: We store anonymous, non-identifying response patterns (like which creative medium you chose or which fear resonated) in a database hosted in the United States via Supabase. Long-form answers are never included in this collection—only structured selections, plus one narrow exception: if you type your own reason for creating and tick the box to show it on the community wall, that phrase is stored with the anonymous snapshot, capped at a sentence or two, with obvious contact details removed before storage (email addresses, links, phone numbers, and social handles), and may appear, unattributed, with your creative medium, on the community wall (the home page and the community page) — and you see that exact card, your words as they will be kept with your medium beside them, on the screen before you tick. The wall works the same way for everyone else: after you choose your reason, you are shown the exact card the wall would display — a line in the site’s words for the reason you chose, with your creative medium — and it appears there only if you tick the box beside it. The card you see is the card that is kept: it is stored exactly as shown and never re-worded afterwards. You can take your card down again at any time from the device you added it on — on the closing screen, or on the community page (see Your control below). Your card goes up only once that browser has kept the key for it; if it can’t (private browsing, a full store), the card isn’t added and the closing screen says so. Every card on the wall is one whose person holds that key: cards added before the key existed were taken down on 1 September 2026. The wall shows nothing about where you are, and we no longer record your location with the snapshot at all. Leave a box unticked and your answers only ever join the anonymous counts; the other “other”-style answers you might type (what you want to give, why this project, what’s in the way) are never part of this collection at all. Snapshots taken in a workshop room are never on the community wall and never in the community page’s counts — the newest answers there would otherwise be readable as that room’s; they do count in one site-wide figure, the fear percentages shown mid-journey, which are counts, never anyone’s individual answers. If you leave a message for future visitors, that message is stored and may be shown to others after an automated moderation check (we also review and can remove messages). If you provide your email for a reminder, follow-up nudge, or community check-in, we store your email along with the context you provided (such as your commitment, core reason, project details, and relevant selections) so we can personalize the message. For forge follow-ups, this includes your project name, description, scope, check-in status, and day-one actions so we can remind you what you committed to. Emails are used only for the purpose you signed up for and are never shared or used for marketing.
AI: This experience uses Anthropic's Claude to generate personalized reflections, power the chat mode, and moderate community messages. Your inputs are processed by Anthropic's API in real time. To personalize return visits, locally saved summaries of your previous journeys — which feelings or fears you chose, your commitments, your forge project history, and key phrases from what you shared — are sent along with your new session so the AI can build on what you've already explored rather than starting from scratch. Anthropic does not train on this data, though they may retain API inputs for up to 30 days for trust and safety purposes per their terms. We log each AI request with a one-way hash of your IP and email (not the originals), along with the model used and token count, so we can monitor costs and detect abuse. This log is never used to identify you personally. See Anthropic's privacy policy for details.
Guided sessions: If you have given a guide access to your journeys, they can see the reflection from each one — the structured choices you made (like your creative medium, the fear that resonated, the permission you needed, and your confidence rating), your personalized manifesto, and what you shared during the experience (your commitment, dedication, saved moments, project details, and any custom answers). Your guide cannot see the letters from your journey (your letter to your past self, and the letter written to you), the dated notes you write to yourself on your journey page, your raw AI conversation and the private signals drawn from it, or — if you've journeyed before — your private reflection on how your reasons have changed. Quick logs are different: when you leave a quick log, your guide sees the whole entry — the note, the mood, the medium you picked and the date — and the AI session preparation built for your guide draws a mood pattern from your logs over time. Your guide also sees the profile details you keep on your journey page: what you're working on, your creative intention and cadence, and the display name you choose. If a summary of your conversation was generated, it stays private unless you choose to share it with your guide from your saved journey page; your earliest creative memory is likewise private by default and shared only if you choose. You can change either decision at any time there. AI-powered session preparation for your guide uses the same boundary — it only sees what you've chosen to share.
Spark Circles are different, and a kindler is not a guide. Being in a circle gives nobody access to your journeys. The kindler running it sees anonymous patterns across the whole room — the most common fears or mediums chosen — and never what any one person wrote. If you come back to a circle you have been in before, you can choose to share your earlier journey so the kindler can see how your answers shifted; that shares your structured selections only (things like your medium, the fear that resonated, your confidence rating), and never your writing, your manifesto, or your letters. You are asked before that happens, and it is off unless you say yes.
Guide and kindler accounts: If you apply to be a guide or kindler, we collect what you submit on the application — your name, email, organization (if provided), and what you tell us about how you'll use the program — so we can review the application, set up your account, and send your magic-link sign-in. Approved accounts also store the operational data the dashboards need (your status, settings, and the activity described in the sections above). You only receive feature-update emails if you checked the opt-in box, and every such email includes an unsubscribe link. To close an account or remove your application data, email us.
Spark Circle shift-tracking (opt-in, both sides): Some kindlers choose to enable a "track participant shifts" mode for their room — a setting they turn on at room creation (or later from the dashboard). When enabled, returning participants who have a previous WDYC journey see a welcome-back prompt at room-join asking two things: whether to revisit or start fresh, and whether to share their previous answers with the kindler for cohort discussion. If the kindler never enables shift-tracking on the room, no prompt is shown and the room runs in fully-anonymous mode (the default). When you DO see the prompt and submit your choices, your peppered email hash is recorded for that workshop so we can count returners — even if you choose NOT to share prior data, a row is stored marking your participation choice (this is what lets your "no" actually mean no on subsequent visits). If you ALSO choose to share your prior journey, a reference to your most recent saved journey is linked alongside the row, and the kindler can see how your answers shifted between sessions; if you don't, the share field stays null and the kindler never sees your identity or prior data — only the aggregate count of "X chose not to share." You can erase everything (the row, the link, all of it) at any time via "delete all my data" at /journey — every workshop participation record tied to your email is removed in the same sweep.
Analytics: We use Plausible, a privacy-focused analytics tool. It collects no personal data, uses no cookies, and does not track you across the web. We track anonymous usage patterns like which journeys are most popular, where people drop off, and which selections are most common (e.g., creative medium, obstacle type). When a page's web address contains a private access link — like a saved-journey, share, or sign-in link — that secret is stripped and replaced with a generic label before any analytics event is recorded, so it never reaches Plausible. None of this is tied to you as an individual.
Rate limiting: To prevent abuse and control costs, our server functions count how often requests arrive from your IP address. We store the address itself alongside a request count — not a hashed version, and we’d rather say so than imply otherwise. These records are removed by a scheduled cleanup, which currently runs weekly, so a record can persist for up to about a week (and up to about ten days for the daily counter that protects our AI features). They are never associated with your journey, your email, or anything else you provide, and they are never used to identify you — they exist solely to stop automated abuse and runaway costs.
Feedback survey: If you fill out the optional feedback survey at the end of a journey, your responses (like your rating and what stood out) are stored to help us improve the experience. After submitting feedback, you may optionally provide your email if you'd like to share more about your creative experience in a personal conversation. Your email is stored solely for that purpose, and removed after 90 days if we haven't been in touch.
Third-party services: We use the following services to operate this experience. Your data is shared with them only as needed to provide the functionality described above: Supabase (database hosting, United States), Anthropic (AI processing), Resend (email delivery for reminders, follow-ups, and check-ins), Plausible (privacy-focused analytics), Netlify (hosting and serverless functions), Sentry (error monitoring — when something breaks, the technical error report may include a hashed identifier, never your reflections), and Stripe (payment processing for guide and kindler purchases — card details go directly to Stripe and never touch our servers). None of these services receive your data for marketing or advertising purposes.
What we don't do: We don't sell your data. We don't track you across the web. We don't run ads. We don't send marketing emails.
Local storage: We use your browser's local storage to save your progress if you leave mid-journey (cleared after 24 hours). If you complete a journey, your generated manifesto, letter, and forged project history are saved locally so you can see them if you return. This data stays on your device and is automatically cleared after 90 days of inactivity, or sooner if you choose to clear it. The only cookie on this site is the optional sign-in session cookie described below. You can clear local data anytime using the "clear my data from this device" button at the bottom of any page, or in your browser settings. Clearing local data does not affect any journeys you chose to save to our server—you can recover your personalized experience anytime by signing in with your email at /journey.
Session cookie: If you sign in — to view your saved journeys, or as a guide or kindler using a dashboard — we set a single HttpOnly session cookie so you stay signed in (about 30 days). It contains only a signed token with a hashed identifier, never your email address or any reflection content. It is encrypted in transit (HTTPS only), inaccessible to JavaScript, and is not used for tracking of any kind. Signing out, using "clear my data from this device," or clearing cookies in your browser settings removes it. If you never sign in, no cookie is ever set.
Saving your journey: At the end of an experience, you can choose to save your journey so you can revisit it later. Add your email and it's kept on our servers and reachable from any device by signing in; without one, the full journey stays in the browser on the device you used. If you request a reminder, a check-in, or a note to your future self, we first email you a save link — opening that link is what saves your journey to your email, and your reminder then includes a link back to what you found. Your free-text responses and AI-generated reflections (your manifesto, letter, chat responses, and other personalized content) are stored in our database. If you share your journey's link, the person you send it to sees only a highlight — your manifesto and the heart of your why — not your private letters, chat, or other reflections; the full journey appears only when you open the link signed in with the email that owns it. The highlight is still personal, so share the link thoughtfully. When you create a share link you're shown a one-time removal code — that code is the only way to take the public page down (we store it the way passwords are stored, so we can't show it again or take the page down by email address), and every share expires on its own after 90 days. Deleting your saved journeys does not remove share pages you've created. Saved journeys expire after two years of inactivity — signing in to your journey list, opening a journey while signed in, or saving one all reset the clock, so anything you're still engaging with stays available. Opening a shared or bookmarked link while signed out shows the journey but does not reset its clock.
Finding your journeys: You can access all your saved journeys by entering your email at /journey. We'll send you a secure sign-in link (valid for 30 days, single use) that opens all journeys associated with your email. If it expires, just request a new one — a lapsed sign-in link never affects the journeys themselves. When you email yourself a journey, we store a one-way hash of your email address (not the email itself) alongside that journey so it can be found later. If you've saved multiple journeys over time, they are all linked to the same email hash so a single sign-in shows your full history. Signing in also restores your personalized return experience (welcome-back screen, creative context) if it was cleared or if you're on a new device.
Data retention: Reminder emails and forge follow-up nudges are one-time messages — once sent, your email address is removed from the record 90 days after the message is delivered. Any AI-generated content stored alongside your email (such as personalized day-one actions) is also removed at that time. The anonymous parts of the record (like your core reason and project name) are kept to help us understand how people use the experience. Monthly creative check-in subscriptions remain active until you unsubscribe using the link in any check-in email; your email is removed 90 days after you unsubscribe. Rate-limiting records are removed by a scheduled cleanup that runs weekly, so they persist for up to about a week — up to about ten days for the daily counter behind our AI features. AI usage logs are retained for cost monitoring but contain only hashed identifiers, not personal information. Saved journeys are automatically deleted after two years of inactivity — signing in to your journey list, opening a journey while signed in, or saving one each reset the expiry of every journey tied to your email to roughly two years from that activity (we don't rewrite a timestamp more than once a day, so it can land up to a day short). An expired journey stops being readable immediately; the sweep that physically removes it runs weekly, so the row itself can persist for up to about a week after that. Anonymous snapshot data is retained indefinitely in aggregate form.
Your control: You can permanently erase everything yourself at any time: sign in at /journey, scroll to the bottom of your journey list, and use the delete all my data link. We'll send a confirmation email; once you click through and confirm, every record tied to your email is deleted from our servers. A few things aren't tied to your email at all, which is what keeps them anonymous — and is also why deletion can't find them: public share pages you've created, your answers to the optional feedback survey, and a card you put on the community wall. Taking a share page down requires the one-time removal code you were shown when you created the link, and each expires on its own 90 days after it was made. A wall card comes down from the device you added it on: the browser that saved it holds a private key for that one card (we keep only a fingerprint of the key, never the key itself, so nothing else can find the card and nothing on our side can cancel the key), and “remove it” on the closing screen or on the community page takes the card down and deletes the words you typed with it — the delete all my data flow does the same when you run it from that device. Clearing that device’s local data forgets the key, so take the card down first if you want it gone. (If you gave us your email in the “want to go deeper” box, that one is deleted.) Deleted records are removed from our live systems straight away. We keep encrypted database backups on a rolling 30-day basis, which are overwritten automatically as they age out; we don't restore individual records from them. Two services we rely on keep their own records: our email provider retains delivery logs, including the address a confirmation was sent to, for a short period; and Stripe keeps the payment records it is legally required to hold. Neither is used to rebuild your journey. If you'd rather we handle it, you can also email us and we'll take care of it within 30 days.
Last updated: August 2026
See also: Terms of Service