shutap
roomshalls

Privacy Policy

Effective: July 1, 2026 · Controller: Shutap

1. Our approach.

Shutap is built to be pseudonymous and privacy-protective. You write under a pseudonym, and our Scrubber automatically removes personal identifiers (names, addresses, specific locations, phone numbers, emails) from what you write before it is stored — we keep only the scrubbed version.

2. What we collect.

  • Account: a pseudonym, your email (for sign-in and check-ins), timezone, notification preferences, consent records.
  • Content: your stories and check-in responses — stored only in scrubbed (de-identified) form.
  • Usage: analytics about how you use the app (via PostHog), tied to a pseudonymous ID, not your name.
  • Device/technical: standard log/device data.

3. How we use it.

To run the community and companion; to deliver check-ins; to provide the Mirror (your patterns over time, for subscribers); to produce aggregated, de-identified insights (“what usually happens when…”); to keep the service safe; and to comply with law. We do not sell your personal information.

4. AI processing.

Your messages are processed by AI models (Google’s Gemini, accessed through the Lovable AI Gateway) to generate companion and Mirror responses. These responses are generated automatically and are for support and reflection only. We do not use your content to train AI models, and we send it to these providers solely to generate your response.

5. Service providers (subprocessors).

Lovable / Supabase (hosting and database), Resend (transactional email), PostHog (product analytics), and Google (Gemini, via the Lovable AI Gateway, for AI responses). Each processes data only to provide its service.

6. Legal/safety disclosure.

We may disclose information where required by law (e.g., valid legal process) or to prevent imminent harm. Crisis-flagged content is kept private, excluded from public display and from our aggregated corpus, and is never sold or monetized.

7. Retention.

We keep your data while your account is active and as needed for the purposes above; you can delete your content or account at any time (Section 9).

8. Security.

We use reasonable technical and organizational measures to protect your data. No system is perfectly secure. In the event of a breach affecting your personal data, we will notify you and authorities as required by applicable law.

9. Your rights.

Depending on where you live (including under GDPR and California’s CCPA/CPRA), you may have the right to access, correct, delete, export (port), object to, or restrict processing of your personal data, and to withdraw consent. You can delete your stories and your account, and request a data export, from Account & Data settings, or by emailing privacy@shutap.com. We do not sell personal information, so there is nothing to opt out of in that respect. We will not discriminate against you for exercising these rights.

10. Children.

Shutap is for adults 18+. We do not knowingly collect data from anyone under 18; if we learn we have, we delete it.

11. International transfers.

If you access Shutap from outside the United States, your data may be processed in the U.S. and other countries where our providers operate. Where required, we rely on Standard Contractual Clauses and equivalent safeguards for transfers of personal data out of the EEA, UK, and Switzerland.

12. Cookies.

We use essential cookies needed to sign you in and keep the service secure, plus privacy-preserving analytics (via PostHog) to understand how the app is used. Where required (e.g., in the EU/UK), we show a consent banner and load non-essential cookies only after you agree.

13. Changes & contact.

We’ll post updates with a new effective date, and notify you in-app of material changes. Questions or requests: privacy@shutap.com.