Privacy policy · draft
What we hold.
This is a first-pass draft to close the current 404, not a reviewed legal document. Bracketed items need a decision from you; the whole thing needs a licensed attorney’s review before you take payment or submit to app stores, and the Play Store’s VPN/Device Admin review process will likely expect this policy to be reachable and accurate. See “Before this is final” at the bottom.
Effective date: 09/03/2026
Last updated: 09/03/2026
1. Who we are
This policy explains how Prodigal - The Way Back LLC (“Prodigal,” “we,” “us”) handles information in connection with the Prodigal website, web app, and mobile applications (the “Service”).
2. The short version
We collect the minimum needed to run your account and track your progress through the program. If someone sponsors your account, they pay for it and see nothing of what you do in it. Your vow, journal entries, and similar reflective content never leave your device. There is no code path in the app that uploads them, and we designed it that way deliberately.
3. Information we collect
Account information. Email address and authentication data, handled through our authentication provider (Supabase).
Usage and progress data, stored on our servers:
- Which days of the program you’ve listened to, and when
- Session-level progress (e.g., percentage of a session completed)
- Content-blocking status metadata (e.g., whether blocking is active), not the specific sites or content encountered
- Sponsor/admin relationship data, if you connect a sponsor account
Information we do not collect or store on our servers:
- Vow recordings
- Journal entries
- “Night” / setback entries and any notes attached to them
- Anything else in that category of reflective, local-only content
This content is stored in your device’s local storage (IndexedDB) only. We have no access to it, cannot recover it if you switch devices or clear your browser/app data, and it is not visible to sponsor or admin accounts under any circumstance.
Payment information. Handled directly by our payment processor (Stripe, once billing is live); we do not receive or store your full card number.
4. How sponsor / admin accounts work
If someone sponsors your account, they pay for it and nothing else.They cannot see your session progress, what you have listened to, your vow recordings, your journal entries, your night entries, or whether you have opened the app at all. None of that is transmitted anywhere a sponsor account could reach it, and the reflective content never leaves your device in the first place. This separation is structural, not a setting you have to configure.
5. How we use information
To operate your account and the program itself, to process payments, to respond to support and privacy requests, and to maintain and improve the Service.
We do not sell your personal information. [Confirm and keep this true. If you ever add analytics or ad tooling, this line needs revisiting before it does.]
6. Who we share information with
We use the following service providers to operate Prodigal, each of which processes data on our behalf:
- Supabase: authentication and database hosting
- Vercel: application hosting
- Zoho Mail: email/support communications
- Stripe: payment processing [once wired]
We don’t share your information with advertisers, and we don’t share it with anyone outside these operational providers except where required by law.
7. Data retention and deletion
You can delete your account from within the app. Deleting your account removes your server-side data (profile, listening history, sponsor connections) [confirm this matches how the account-deletion route actually behaves once the current table cleanup work is finished]. Locally stored content (vow, journal, night entries) is only removable by clearing it from the device itself, since we have no server-side copy to delete.
8. Your rights
Depending on where you live, you may have rights to access, correct, or delete your personal information, and to know what’s collected and why. To make a request, contact us at privacy@theprodigalapp.com.
[If you expect users in California, the EU/UK, or other jurisdictions with specific privacy statutes (CCPA/CPRA, GDPR, etc.), this section needs jurisdiction-specific language. That’s an attorney-review item, not something to guess at.]
9. Children’s privacy
The Service is intended for users 18 and older. We do not knowingly collect information from anyone under 18. If you believe a minor has provided us information, contact us at privacy@theprodigalapp.com and we’ll remove it.
10. Security
We use reasonable administrative and technical safeguards to protect your information, including database-level access controls scoping each user’s data to that user alone. No system is perfectly secure, and we can’t guarantee absolute security.
11. Crisis resources
If you are in crisis, you can call or text 988 (Suicide & Crisis Lifeline) any time, free of charge. This is never limited by your subscription or account status.
12. Changes to this policy
We may update this policy from time to time. We’ll update the “Last updated” date above when we do.
13. Contact
Privacy questions or requests: privacy@theprodigalapp.com
General support: [SUPPORT EMAIL]
Before this is final: flag for attorney review
- Jurisdiction-specific rights language (Section 8): CCPA/CPRA if you expect California users, GDPR/UK GDPR if any EU/UK users, other state privacy laws (several have taken effect since 2024). Needs a real review, not a guess.
- Confirm the account-deletion description (Section 7) matches actual behavior once the
USER_TABLESfix and the current schema cleanup ship. Don’t publish a claim the code doesn’t back up yet. - Data processing agreements with Supabase/Vercel/Zoho/Stripe: worth confirming each provider’s own DPA covers what this policy promises.
- Play Store’s specific policy-URL and data-safety-form requirements for apps requesting VPN and Device Admin permissions. Check current requirements against this draft before submission, since store policy language shifts.
- Breach notification obligations vary by state. Worth a specific check given the sensitivity of what this app’s userbase is trusting you with.