⚡ Squova← Back to home

Privacy Policy

Last updated 30 September 2026. This is a preliminary draft pending review by a licensed attorney and does not constitute legal advice.

This Privacy Policy explains how Squova ("Squova", "we", "us", or "our") collects, uses, shares, and protects personal data when you use the Squova application, website, squad-intake form, and related services (the "Service"). Squova is currently operated by an individual and is not a registered company, and it is offered to a global audience. Please read this policy together with our Terms & Conditions.

1. Who we are and the rules we follow

Squova is an independent, individually operated project and is not yet incorporated as a company. The individual operator is the controller responsible for your personal data.

This policy is written to align with major privacy frameworks, including the EU and UK GDPR and the California CCPA/CPRA. Where the mandatory law where you live gives you stronger rights, those rights apply.

2. The data we collect

We collect only what is needed to operate and understand the Service. We do not use third-party advertising pixels, fingerprinting, or cross-site tracking.

  • Squad-intake data: your email address and, if you choose to provide them, your goal and IANA timezone. We also store the landing placement, UTM source, UTM medium, UTM campaign, and referring page supplied with the form.
  • Account data: your email address and encrypted password for email registration, or the email and basic profile information Google passes to us when you use Google sign-in.
  • Profile and social data: a pseudonym, generated avatar settings, timezone, focus area, goal, squad membership, and visibility preferences (including your real-name visibility toggle in private Friends squads).
  • Squad activity data: daily objective descriptions and completion state, chat messages, encouragement reactions, safety chip usage, invitations, and shared streak history.
  • Notification and device data: if you choose to enable device push notifications, we store your browser push subscription endpoint and cryptographic keys to deliver squad alerts and reminders. You can revoke push notification permissions at any time via your browser or profile settings. In-app notifications are also delivered directly within the interface.
  • Moderation records: records of users you choose to mute or block, and message reports you submit for review, processed to maintain squad safety and prevent unwanted interactions.
  • First-party launch events: a random session identifier and allowlisted product milestones such as a landing visit, intake submission, account creation, onboarding completion, squad join, first objective, and first scoring day. These event records do not contain an IP address, advertising identifier, device fingerprint, or cross-site identifier.
  • Technical data: limited request information such as IP address, browser and device type, and timestamps processed by our hosting and infrastructure providers for delivery, security, logging, and abuse prevention.
  • Local preferences: settings kept in your browser or through first-party cookies, such as theme, active squad selection, and whether a celebration has played.

We do not collect precise geolocation, government identifiers, or payment-card details.

3. Why we use your data

Where the GDPR applies, we use account, profile, squad, and activity data to provide the Service under our contract with you. We use limited technical data to secure and operate the Service under our legitimate interests.

  • We use your intake email, optional matching details, and source attribution to organize compatible squad intakes and send the squad-intake updates you requested. This processing is based on your consent, which you may withdraw at any time.
  • We use your email to create and secure your account and to deliver essential confirmation, password-recovery, and account-security messages.
  • We use your timezone, focus area, and goal to configure your profile and help form compatible squads.
  • We use objectives, completions, messages, reactions, and streaks to provide the core accountability features.
  • If you opt in, we use your device push subscription to deliver timely squad reminders, teammate nudges, and streak status notifications.
  • We process blocks, mutes, and reports under our legitimate interest to protect users from harassment and maintain squad integrity.
  • We use privacy-preserving launch events to measure whether visitors form and retain functioning squads, not to build advertising profiles.

4. What your squad can see

Other members of your squad can see your pseudonym, generated avatar, focus area and goal, daily objectives and completion state, chat messages, reactions, and contribution to the shared streak. In private Friends squads, members can also see your real name only if you explicitly choose to turn on the real-name visibility setting. Your email, password, intake record, and login identifiers are never shown to squad-mates.

5. Who we share data with

We do not sell personal data or share it for advertising. We use a small number of trusted processors to operate the Service:

  • Supabase hosts the database, manages authentication, powers realtime features, and stores application data under strict row-level security.
  • Vercel hosts and serves the application and processes request logs and technical data needed to deliver it.
  • Resend delivers account-security and squad-intake emails, stores intake contacts in the configured Squova Segment, and manages unsubscribe status for broadcasts.
  • Push service gateways (such as Apple Push Notification service, Google FCM, or Mozilla Push Service) route encrypted push notifications to your browser if you have enabled notifications.
  • Google authenticates you if you choose Google sign-in and passes us your email and basic profile information.
  • DiceBear generates avatar images from a non-identifying seed. Loading an avatar sends the device IP address and avatar seed to DiceBear.

We may also disclose data when required by law, to enforce our Terms, or to protect users and the Service.

6. International data transfers

Our infrastructure and service providers operate in multiple regions, including the United States and the European Union. Where international transfers occur, we rely on established transfer mechanisms provided by our processors, such as standard contractual clauses.

7. How long we keep data and deletion

We retain squad-intake records while the intake is active and while you remain subscribed to the requested updates. We suppress further broadcasts when you unsubscribe. You may ask us to delete the intake record at any time.

We retain account data while your account is active. You can delete your account at any time directly in the app settings, which removes your profile, objectives, messages, reactions, push subscriptions, and memberships. Anonymous or aggregate squad-level streak history that is not personal to you may be retained. Limited data may remain temporarily in encrypted backups or where law requires retention.

8. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your data, and to withdraw consent. You can self-serve account deletion directly within the application settings, or contact support@squova.com to exercise any privacy right or request deletion of an intake record.

9. Children's privacy

The Service is intended for people aged 16 and over. We do not knowingly collect personal data from children under 16. Contact us if you believe a child has provided personal data so we can take appropriate steps.

10. How we protect your data

Connections use HTTPS/TLS. Supabase handles authentication and hashed passwords. Database row-level security protects user-facing tables. The intake and launch-event tables have no browser policies or browser table privileges and are written only by server-side code. The optional intake-detail step uses a short-lived opaque token stored in an HttpOnly cookie; the database stores only its hash.

No transmission or storage method is completely secure, and we cannot guarantee absolute security.

11. Cookies and local storage

We use necessary first-party cookies and local storage. We do not use advertising or third-party tracking cookies.

  • Authentication cookies keep you signed in and manage your session.
  • An active squad cookie (squova:active-squad) preserves your active squad selection across dashboard navigation and chat.
  • A short-lived invite cookie carries a pending squad invitation through signup and onboarding.
  • A 24-hour HttpOnly intake-profile cookie authorizes the optional goal and timezone update. Duplicate and honeypot submissions receive the same outward cookie shape.
  • A first-party HttpOnly launch-session cookie keeps a random identifier for up to 90 days so we can connect allowlisted funnel milestones. It is not used across other websites.
  • Local storage remembers client preferences such as theme, chat state, install-prompt dismissal, and one-time celebration state.

12. Changes to this policy

We may update this policy as the product changes. We will revise the last-updated date and give reasonable notice of material changes.

13. Contact us

For privacy questions, data requests, or concerns, please contact support@squova.com.