🛡️ Privacy Policy — First5Minutes

Last updated: October 31, 2025

1. Introduction

First5Minutes ("we," "our," or "us") helps users turn daily intentions into meaningful missions. We respect your privacy and are committed to protecting your personal data. This policy explains what we collect, how we use it, and your rights.

2. What We Collect

We collect only the minimum information needed to provide our service:

  • Account information: email, name, and authentication ID (via Clerk).
  • Activity data: missions you create, completion evidence (text, images, short videos), and timestamps.
  • Device data: anonymized usage analytics (e.g., PostHog, Google Analytics) to improve app performance.

We do not collect sensitive data (health, biometrics, finance) or share any data with third parties for advertising or marketing.

3. How We Use Your Data

We process your data solely to:

  • Authenticate your account and maintain session security.
  • Store and display your missions, streaks, and progress.
  • Improve user experience and app reliability.
  • Provide opt-in notifications and reminders.

We never sell, rent, or trade your information.

4. How We Store and Protect Data

  • Data is encrypted in transit (HTTPS) and at rest.
  • Access is restricted to authorized personnel.
  • We host data in privacy-compliant regions (e.g., EU or equivalent).
  • Backups are secured and automatically purged after retention periods.

5. Third-Party Services

We may use:

  • Clerk for secure authentication.
  • Supabase / PostHog / Google Analytics for performance and analytics.

All partners comply with GDPR and process data under our instructions only.

6. Your Rights

Under GDPR and global privacy laws, you may:

  • Access, correct, or delete your data.
  • Request export of your data in a portable format.
  • Withdraw consent or close your account anytime.

To exercise your rights, email: reachinminutes@gmail.com

For our complete terms of service, please visit our Terms of Service page.

EU users can also review our GDPR Compliance Statement.

7. Data Retention

We keep user data only as long as necessary to operate the service. Deleted accounts and evidence are permanently removed within 30 days.

8. Changes to this Policy

We may update this policy as our services evolve. Any material change will be announced via in-app notice or email.