Privacy Policy

— Last updated 17 August 2026

1. Who We Are

[BUSINESS_NAME] operates Shadow Guide, an AI-powered conversational tool exploring Jungian depth psychology themes. We are based in [OPERATOR_REGION].

Shadow Guide is not a mental health service and does not provide therapy, medical advice, or crisis support. See our Terms of Service for the full disclaimer.

2. What Data We Collect

CategoryDetails
AccountEmail address — collected when you sign in with Google or request a one-time sign-in code by email
WaitlistYour email address, if you choose to ask to be notified when the service opens. Collected on the basis of your consent (confirmed by a double opt-in link), used solely to send a single launch notification, and never used for anything else. No IP address is stored with a waitlist signup. You can withdraw at any time by writing to the contact address on the About page; the entry is then deleted
ContentChat messages, dreams, reflections, intake responses, and other text you enter into the service
Optional detailsYour analyst's email address, if you choose to save it in Settings. This is shown back to you only — it is never included in AI processing and never used to contact your analyst
Derived dataPer-user tracker state extracted from your conversations to provide continuity across sessions. Specific fields stored include: alchemical stage and stage-dwell counter, shadow themes, dream log and dream reflections, integration milestones, session notes, closing sentences, function profile (Jungian cognitive-function inference), user preferences (cognitive vs somatic, directive vs spacious), crisis flag (whether crisis-adjacent material has been disclosed in a turn), and saturation flag (whether the system has detected the sitting is reaching its natural close). These fields are produced by automated AI inference of psychological state from your messages — you can request the full contents of your tracker by contacting us via the About page.
TechnicalIP address (used for rate limiting; IP addresses also appear in our hosting provider's standard access logs, retained for a limited period), timestamps, error logs (scrubbed of personal content)

3. How We Use Your Data

4. What We Do NOT Do

5. Third-Party Processors

ServicePurposeRegion
xAI (Grok API)Processes your messages to generate the conversation responses you read, and periodically composes the longitudinal portrait that gives the guide continuity across sessions. xAI states that it never trains on API inputs or outputs without explicit permission. Our account uses xAI's zero-data-retention API mode, under which requests and responses are not stored after processing — our systems verify this on each responseUS-based
Anthropic (Claude API)Supporting processing around the conversation: titling your sittings, and acting as the standby for the background jobs in this table — if a primary provider's call fails, the same job runs on Anthropic instead, so your messages may also reach Anthropic. Depending on our current configuration, Anthropic can also serve the conversation itself. Anthropic does not use API data to train its models; under its standard commercial API terms inputs and outputs are deleted within 30 days, and retained longer only in limited cases — for example where its automated safety systems flag content (up to 2 years, with classification scores up to 7 years), where retention is legally required, or where a different governing agreement appliesUS-based
OpenAIBackground processing of your messages: after each exchange, extracting the session-tracker state that gives the guide continuity (including detection of crisis-adjacent material), summarising older session history, and generating the written reflection on a dream you record. OpenAI states that API data is not used to train its models by default, and that abuse-monitoring logs are retained for up to 30 daysUS-based
Voyage AIGenerates vector embeddings of conversation-derived text to power the app's long-term memory retrieval. The resulting embeddings are stored in our own EU databaseUS-based
GoogleIdentity provider for "Sign in with Google". When you choose this option, Google shares your email address with us to create and recognise your accountGlobal (US-based)
ResendTransactional email — delivers one-time sign-in codes to the email address you enter at login, and (if you join the waitlist) the single waitlist confirmation and launch notificationUS
Lemon SqueezyPayment processing and billing (Merchant of Record). Active only once paid subscriptions become available — see the Refund Policy.US
SentryError monitoring with strict PII scrubbing enabled (see section 4)EU (Germany)
RailwayInfrastructure hosting (application servers + PostgreSQL database)EU (Amsterdam, europe-west4)
CloudflareDNS resolution and (where applicable) edge caching; no user-content caching is currently routed through CloudflareGlobal

"US-based" names the provider's home jurisdiction. It is not a guarantee that processing occurs only in the United States — each provider's own data-processing terms govern where its infrastructure runs. Where a row states a specific processing region (for example Sentry or Railway), that reflects a setting or contract we hold.

6. Data Retention and Deletion

Your data is retained while your account is active. You can request a full export of your data at any time, or request deletion of all your data, by emailing the contact address listed on the About page.

We aim to acknowledge deletion requests within 7 days and to complete deletion within 30 days of receipt, in line with POPIA Section 24 and GDPR Article 17 (Right to Erasure). Deletion includes your tracker state, conversation history, dream reflections, and account record. Backup copies follow our standard 7-day daily / 4-week weekly retention cycle and are purged within that cycle once your primary data is deleted.

Waitlist signups are kept only until the service opens (or until you withdraw, whichever comes first), and the list is deleted once the launch notification has been sent.

7. Your Rights — POPIA ([OPERATOR_REGION] Users)

Under the Protection of Personal Information Act (POPIA), you have the right to:

To exercise any of these rights, see the contact details on the About page.

8. Your Rights — GDPR (EU Users)

If you are located in the EU, you have equivalent rights under the General Data Protection Regulation (GDPR): right of access, rectification, erasure, restriction of processing, data portability, and the right to object. See the contact details on the About page.

9. Security

All data is encrypted in transit via HTTPS. User data is stored in managed PostgreSQL (EU region) with routine backups. Error monitoring is configured with strict scrubbing to prevent any therapeutic content from reaching external services.

10. Children

Shadow Guide is not intended for users under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has used the service, please contact us so we can delete their data.

11. Contact

For privacy-related questions or to exercise your data rights, see the contact details on the About page.