Hꜣw Privacy Policy

Effective date: October 2, 2026

Hꜣw stores the information needed to run accounts, calendars, reminders, reflections, Ma'at Flow activity, journaling, profiles, sharing, notifications, and support. Some features can be used locally on your device. Account-backed features sync through our Supabase backend.

1. Information We Collect

We may collect account identifiers, email addresses or provider sign-in identifiers, profile information you provide, app settings, calendar and planner entries, reminder details, journal and reflection content, Ma'at Flow content and activity, posts, comments, shared-calendar data, direct-message metadata or content where supported, device notification tokens, diagnostic timestamps, and support messages.

2. Account and Profile Data

Your account data is used for authentication, sync, support, security, and account recovery. Profile fields such as display name, handle, avatar, biography, follows, posts, comments, and shared activity may be visible to other users depending on the feature and the actions you take.

3. Journaling and Reflections

Journal entries, private reflections, notes, and personal reflection history are private by default. They may be processed by the app and backend to save entries, restore them across devices, generate reflection features, and provide support when you ask us to investigate an issue.

4. Calendar and Planner Data

Calendar entries, planner items, reminders, flows, and related notes are private by default unless you share them, import shared content, invite another user, or use a feature that makes selected content visible to someone else. Google-imported event copies are private to your account and are not shared through Hꜣw's event-sharing features.

5. Ma'at Flow Activity

Ma'at Flow enrollment, progress, saved flows, posted flows, shared flows, completion activity, and related metadata may be stored so the app can run flows, restore state, sync devices, power profile/community features, and deliver reminders.

6. AI-Powered Features

AI-powered or automated features may process user-entered reflections, prompts, profile context, flow activity, calendar context, or other app content to generate guidance, summaries, suggestions, labels, or reflections. Google-imported calendar data is not automatically sent to our AI guidance or reflection services. If you independently copy information into a prompt or reflection, that content is processed as part of the feature you choose. AI output may be imperfect, and you should review it before relying on it or sharing it.

7. Push Notifications

If you enable push notifications, we may store device tokens, browser subscription data, platform identifiers, permission state, delivery timestamps, and diagnostic information needed to send, troubleshoot, and measure notification delivery. You can disable notifications in the app or device settings.

8. Calendar Sync and Device Integrations

If you enable calendar sync or other device integrations, the app may access the device calendar, imported event data, files you choose to import, app links, sharing inputs, widgets, text-to-speech, or platform services such as Apple, Google, Firebase, and operating-system notification services. You can manage many permissions in device settings.

Google Calendar Import

Connecting Google Calendar is optional and separate from signing in. We request read-only access to your calendar list and calendar events, together with your Google account identifier and email to identify the connection. Calendar names, identifiers, and colors let you choose which calendars to import. We read events from the calendars you select to display and update read-only copies in Hꜣw. We do not create, edit, or delete events in Google Calendar.

Google returns event records when we import your selected calendars. We retain event titles, descriptions, locations, dates and times, all-day status, event and recurrence identifiers, and the source calendar's name and color. Descriptions can contain links or other information supplied by an event's creator. Imported copies are stored in our Supabase backend and cached on your device for display. Google access and refresh tokens are stored encrypted on the backend so automatic imports can continue while the app is closed.

We use Google-imported data to provide and maintain calendar import, display, search, and updates to your copies. It is not automatically sent to our AI guidance or reflection services. We do not sell it, use it for advertising, or share it with other Hꜣw users. Supabase processes this data to provide backend storage and synchronization. Transfers of Google data are limited to providing these visible features with your consent, necessary security purposes, compliance with applicable law, or a change of ownership after your explicit prior consent. Human access is limited to your affirmative agreement to access specific data, necessary security purposes such as investigating a bug or abuse, or compliance with applicable law.

Pausing automatic import retains existing copies. Deselecting a calendar removes that calendar's imported copies from active storage. Disconnecting removes the connection's stored credentials and imported copies. Deleting your Hꜣw account also deletes its active imported calendar data. Device caches are refreshed as the app receives these changes. Copies may remain in offline caches or backups until those caches update, are cleared, or are overwritten. Import diagnostics contain counts and error categories rather than event content and are removed after 30 days. Imported events do not have a fixed age-based expiry while their calendar remains connected.

Use Settings > Calendar Import to pause, choose calendars, or disconnect. Disconnecting in Hꜣw does not revoke the Google account's app authorization or change your Hꜣw sign-in. You can separately remove Hꜣw's access in your Google Account connections.

Hꜣw's use and transfer of information received from Google APIs adhere to the Google API Services User Data Policy, including its Limited Use requirements. These specific limits govern Google data wherever broader statements in this policy might otherwise apply.

9. Supabase and Backend Storage

We use Supabase for authentication, database storage, storage, realtime features, and backend functions. Backend functions may process account data to sync content, send notifications, generate or evaluate guidance, support sharing, moderate content, delete accounts, and protect the service.

10. Data Sharing and Visibility

Private journal, calendar, planner, and personal flow activity are private by default. Social posts, comments, profile details, shared flows, shared calendars, messages, and invite responses may be visible to other users or recipients when you choose to post, share, invite, message, or interact with community features. We may share data with service providers needed to operate the app, and when required for legal, safety, security, support, or abuse-prevention reasons. We do not sell personal data or use third-party advertising tracking.

11. Data Retention

We keep account data while your account is active or as long as needed to provide the service, maintain security, comply with legal obligations, resolve disputes, prevent abuse, or preserve backups. Some logs, diagnostics, cached generation data, deleted content, and backup copies may persist for a limited period before being removed or overwritten.

12. Account Deletion

You can request deletion from Settings in the app by choosing Delete account, or by visiting haw-info.pages.dev/delete-account. Account deletion can delete or anonymize user-associated data depending on technical, legal, security, and recipient-copy needs. Content you shared with another user may remain in that user's account where the product preserves recipient copies or where retention is legally or technically necessary.

13. Minors

The app is not intended for children under 13. If you are under the age of majority where you live, use the app only with permission and involvement from a parent or guardian where required.

14. User Data Rights

Depending on where you live, you may have rights to request access, correction, deletion, portability, objection, or limits on certain processing. Email support with the account email when possible so we can verify and respond to your request.

15. Contact and Support

Email jaralephillips@gmail.com for privacy, data rights, support, moderation, or deletion requests.

Support: haw-info.pages.dev/support

Account deletion: haw-info.pages.dev/delete-account

Terms and conditions: haw-info.pages.dev/terms