Privacy Policy
Version: 2026-08-26 · Draft pending review by a qualified lawyer
The short version
- Your profile is private by default. Nothing about you is discoverable unless you choose to make it so.
- Your journal is yours alone. No coach, no moderator, no organisation administrator, no Comitry operator, and no analytics ever sees it. Deleting an entry deletes it outright.
- Your data is stored in the European Union, in Convex's
eu-west-1region. - We use a short list of service providers to run Comitry — Clerk for sign-in, Convex for the database, Stripe for payments, ImprovMX for the email you send us, and the companies that host and protect the site. Section 4 names all of them.
- We do not sell your data, we do not advertise to you, we do not profile you, and we do not use what you write to train anything.
The rest of this document is the detail behind those five lines.
1. Who is responsible for your data
The data controller is:
[TO BE CONFIRMED: registered company name and legal form][TO BE CONFIRMED: registered address]- Registration number:
[TO BE CONFIRMED: company number and register] - Privacy contact:
privacy@comitry.com - Data protection officer:
[TO BE CONFIRMED: whether a DPO is appointed and, if so, their contact details. If none is appointed, this line should say so and give the privacy contact instead.] - Supervisory authority:
[TO BE CONFIRMED: the data protection authority of the country of establishment — for a French entity, the CNIL]
You can always complain to the supervisory authority in the country where you live, whichever one that is.
2. What we collect, why, and on what legal basis
Your account and profile
| Data | Why | Legal basis |
|---|---|---|
| Email address and sign-in credentials | To let you sign in and to contact you | Contract |
| Handle | Names you everywhere on Comitry | Contract |
| Display name, and a short bio if you write one | Shown to others in groups and threads | Contract |
| Whether your profile is public | To honour the choice you made | Contract |
| Your confirmation that you are 18 or over | Comitry is adults only | Legal obligation |
| Language and timezone | To show the product in your language | Contract |
| Which documents you accepted, when, and a hashed record of the connection | To prove what you agreed to | Legal obligation |
| Sign-in events, device and IP address | To keep the account secure | Legitimate interest |
Your email address and password or social sign-in are held by Clerk on our behalf. We hold the profile.
What you do on Comitry
| Data | Who can see it | Legal basis |
|---|---|---|
| Messages you write in a group, including when you edited or deleted one | The other people in that group, and a moderator if it is reported | Contract |
| Direct messages | The person you sent them to, and us only if reported | Contract |
| Which groups you are in, and any alias in an anonymous group | The other people in that group | Contract |
| Connection requests, and who you have blocked | The other person sees a request; a block is not announced | Contract, and legitimate interest in letting you shut someone out |
| Journal entries and the 1–5 mood attached to one | Only you | Contract, plus your explicit consent for anything health-related — see section 3 |
| Coach content you can read, and what you subscribe to | You, and the coach knows they have a subscriber | Contract |
| Reports you make | Us, and the moderators who handle it | Legitimate interest in a safe service, and legal obligation |
| Moderation decisions about you | Us, and you | Legitimate interest, legal obligation |
| Records of privileged actions — a role granted, a moderation decision, an admin access | Us only | Legal obligation, legitimate interest in accountability |
If you subscribe to a coach
Payments are processed by Stripe. We never receive or hold your card number, and neither does the coach.
We store the fact of the subscription, the price, the currency, the status, the renewal date, the identifiers Stripe gives us, and whether a payment attempt failed. Legal basis: contract, and legal obligation for the accounting and tax records.
Stripe is never sent health-related data. It sees a customer, a subscription and an amount. A coach never sees your payment details, and can never change or cancel your payment method.
If you apply to be a coach
We collect the discipline you work in, where you practise, any licence or registration number and issuing body you choose to give, any documents you upload to support the application, and your acknowledgement of the scope of practice with its timestamp. A person at Comitry reads it, and we record who reviewed it, when, and their notes. Legal basis: contract, and our legitimate interest in not letting anybody sell coaching to a vulnerable audience unchecked.
If you are approved and take payment, Stripe collects the identity and bank details it needs for its own legal checks, directly from you. We hold your Stripe account identifier, the country, the currency, whether payouts are working, and what Stripe still needs — not your bank details or your identity documents.
We also hold a record of every subscription payment made to you: the gross amount, our fee, the processing cost, your net, and any amount deducted after a lost dispute.
What you have to give us, and what you do not
Only four things are genuinely required, and only because the service or the law cannot work without them: an email address (to have an account at all), a handle, a confirmation that you are 18 or over, and payment details if you choose to subscribe to a coach. Without those we cannot give you an account, or cannot take a payment.
Everything else is optional and skipping it costs you nothing: a display name beyond your handle, a bio, making your profile public, joining a group, writing a journal entry, attaching a mood to one, applying to be a coach. Nothing is nagged and nothing is withheld because a field is empty.
What we do not collect
- No advertising or tracking identifiers, and no third-party analytics
- No location beyond the country a payment implies
- No profile picture — Comitry does not store or host one
- No files, images or attachments. The only thing anyone can upload is a document supporting a coach application
- No health data we ask you for. There are no symptom questionnaires, no assessments, and no scores. The 1–5 mood is a note to yourself, and nothing interprets it
- Nothing about anyone under 18, knowingly
3. Data that reveals something about your health
Some of what you write on Comitry may reveal something about your physical or mental health — in your journal, in a group, or in a message to a coach. Under the GDPR that is special category data, and it gets stricter treatment.
- The legal basis is your explicit consent, recorded with its version and date. It is asked for on its own, separately from the terms and the privacy policy: writing your first journal entry gives it, and nothing else on Comitry asks for it or depends on it.
- The journal is an optional feature and nothing else depends on it. Comitry works in full without a single journal entry: you can join groups, message people, read content and subscribe to a coach without writing anything about your health. Consenting is genuinely a choice, which is what makes the consent worth anything.
- You do not have to disclose anything about your health, anywhere on Comitry, to anyone, ever.
- It is never used for advertising, profiling, automated decision-making, or training any model.
- Journal entries are readable only by their author, enforced in the code rather than by policy. The functions that read them are scoped to the person who wrote them, an operator or administrator is refused by name, and no function aggregates them.
- It is stored in the EU and encrypted in transit and at rest.
You can withdraw that consent at any time, in Settings → Account, as easily as it was given. Withdrawing deletes every journal entry and every mood outright — there is no other basis on which we would be allowed to keep them, so they go with the consent, and nobody can get them back, including us. The journal will take nothing more until you give the consent again. Deleting your account withdraws it too, and deletes them all. Withdrawing does not affect what was lawful before you withdrew.
What you choose to say about your health in a group or a direct message is visible to the people you said it to. We cannot unsay it for you, and neither can they. The Community Guidelines ask everyone not to repeat it anywhere else.
4. Who processes your data for us
These are the companies that receive your personal data. Convex, Clerk, ImprovMX and our host act on our instructions under a data processing agreement, and may not use your data for their own purposes.
If you email one of our addresses, ImprovMX carries the message. The addresses in
these documents — contact@, privacy@, coaches@, billing@ and
safety@comitry.com — are forwarding addresses rather than mailboxes. ImprovMX
receives what you send and passes it to the inbox we read; it does not keep the
message afterwards. Whatever you put in an email to us therefore passes through
ImprovMX first, and then sits in our inbox for as long as we need it to answer you.
Stripe is different, and we would rather say so than round it off. For part of what it does, Stripe acts on our instructions. For the rest — preventing fraud, meeting its own anti-money-laundering and identity-check obligations, and improving its own products — Stripe decides for itself and is responsible for it in its own right. We cannot instruct it not to run those checks. Stripe's own privacy notice covers that part, and it is worth reading if you pay for anything here. The same is true in a smaller way of Clerk, which is responsible in its own right for the account record it holds about our use of its service.
| Service | What it does | Where data is stored |
|---|---|---|
| Convex | Database and backend | European Union, eu-west-1 |
| Clerk | Sign-in, accounts and sessions | [TO BE CONFIRMED: the region configured on the production Clerk instance] |
| Stripe | Payments, payouts and card storage | European Union and the United States |
| Cloudflare | Bot protection on sign-up, which briefly sees your IP address and browser characteristics | European Union and the United States |
| ImprovMX | Forwarding email sent to our published addresses to the inbox we read | European Union — its mail servers resolve to AWS eu-west-3, Paris |
[TO BE CONFIRMED: hosting provider and region. The application currently reads a Vercel geolocation header, so Vercel is the assumed default; it also processes request logs and IP addresses.] |
Serving the website and the app | [TO BE CONFIRMED] |
Your country is worked out from your IP address in one place only: to decide which currency and tax treatment applies to a payment. We do not store a location history.
Data reaching the United States
Convex, Clerk, Stripe and Cloudflare are United States companies with European infrastructure. Storing data in Europe is not the whole story: if staff or systems in the United States can reach it, that counts as a transfer, and it needs a legal basis of its own.
- Clerk is certified under the EU-US Data Privacy Framework, so transfers rely on the European Commission's adequacy decision for that framework.
- Stripe is certified under the same framework, and the entity we contract with is in Ireland.
- Convex is not certified under that framework. Transfers to Convex rely on the
European Commission's standard contractual clauses.
[TO BE CONFIRMED: a transfer impact assessment for Convex should be completed and kept on file, and the executed, dated processing agreement obtained.] - Cloudflare —
[TO BE CONFIRMED: the transfer mechanism, which depends on how bot protection is configured on the production sign-in instance.]
You can ask us for a copy of the safeguards for any of these, at the privacy contact above, and we will send it.
Our providers use their own sub-contractors, and each of them publishes a list. We watch those lists for changes and can object to a new one. If we add a provider of our own, we update this policy before it starts processing anything.
We do not sell or rent your data, and we never will. We do not share it with advertisers, data brokers, or anyone else not in the table above.
5. When we would disclose data to someone else
- Because the law requires it — a valid order from a court or a competent authority. We check that it is valid, give the minimum that answers it, and tell you unless we are legally prevented from doing so.
- To protect someone from serious harm, where we believe there is a genuine risk to life and disclosure is necessary. We do not monitor for this and we do not promise to spot it.
- If our business is sold or reorganised, to the buyer, who takes on this policy. We would tell you first.
6. What your organisation can see
Organisation plans are designed but not on sale, so today nobody has an organisation administrator looking at anything. When they exist, these limits are already built and tested.
An administrator sees aggregate engagement only — for example how many members were active in a period. They cannot see:
- Your journal entries or the moods in them
- The content of any message
- Which groups you joined
- Anything that identifies you individually
A figure is only shown for a group of at least 10 people. Below that, nothing is displayed at all rather than a zero, and where hiding one figure would let it be worked out by subtracting the others, a second figure is hidden too.
7. Safety
Comitry does not list support services or helplines, and does not direct you to a particular one. We do not scan your messages or your journal, and nothing you write triggers an alert to a moderator, a coach, or your organisation.
If we ever surface support resources in response to something written, it will be shown only to the person who wrote it, it will not be reported to anyone, and the text that prompted it will never be stored — only that resources were shown, which rule matched, and for which country.
Comitry cannot respond to emergencies and does not monitor for them.
8. How long we keep things
| Data | Retention |
|---|---|
| Profile and account data | While your account exists |
| Journal entries and their moods | Until you delete them; all of them are deleted when you delete your account |
| Messages you sent | Kept in the conversations they belong to, detached from your profile when you delete your account |
| Your handle | Kept indefinitely after deletion, on its own, so nobody can reuse it — see section 9 |
| Reports and moderation decisions | 12 months after the matter is resolved — deleted by a daily job |
| Audit records of privileged actions | 24 months — deleted by the same daily job |
| Records of the documents you accepted | [TO BE CONFIRMED: retention for consent evidence. Recommended default: 5 years after the account is closed, matching the general limitation period.] |
| Coach application documents | [TO BE CONFIRMED: recommended default: deleted 12 months after the decision, or 3 months after a rejection.] |
| Payment, invoice and payout records | [TO BE CONFIRMED: the statutory accounting retention of the country of establishment — 10 years for a French company.] |
| Technical logs and payment event records | [TO BE CONFIRMED: recommended default: 12 months.] |
When a retention period ends the data is deleted, not archived. The two periods above that are stated as a number of months are enforced by a job that runs every day. The rows still marked as to be confirmed are not enforced by anything yet, because we will not invent a period and then delete your data to match it.
9. What deleting your account actually does
You can delete your account yourself, from your account settings. We are telling you exactly what happens because "delete" is a word products use loosely.
Deleted immediately and permanently
- Every journal entry and every mood in one
- Your bio, your display name and your profile details
- Your profile's visibility — it stops being reachable, searchable or public
- Your group memberships, so you are no longer counted as a member of anything
- Your connections, in both directions
Kept, and why
- Your handle. It stays reserved for ever, so that nobody else can take it and appear to be you in the threads and links that still mention it. It is kept on its own: no name, no bio, nothing public attached to it. We rely on our legitimate interest in preventing impersonation in a product where people talk about their mental health with people they chose to trust. You can object to this at the privacy contact above, and we will weigh your objection against that interest and answer you.
- What you wrote in group conversations and direct messages, detached from an active profile — it shows as written by "a member who has left", with no name, no handle and no link. The other people in those threads have their own interest in their conversation continuing to make sense, and removing one side of it rewrites theirs. If a specific message you wrote needs to go, ask us and we will consider it on its facts.
- Records the law requires us to keep — payment and tax records, records of what you consented to, and audit records of privileged actions — for the periods in section 8, and for nothing else.
Deleting your account also cancels any subscription you pay for. It does not refund the month you are in unless you also have a right under section 8 of the Terms of Service.
10. Your rights, and how to use them
Write to privacy@comitry.com for any of these. We
answer within one month, and tell you if we need longer and why. It is free
unless a request is excessive, and we will say so rather than quietly charging you.
- A copy of your data, in a machine-readable format, from your account settings. Ask for it there and it is built for you as a JSON file: your profile, your messages, your journal entries, your groups, your subscriptions, your consent records and anything you have reported. The file is deleted seven days after it is ready, because the link to it is enough on its own to open it — ask for a new one whenever you need it.
- Correction. You can edit your display name and bio yourself at any time. Your handle cannot be changed by anyone, including us — section 4 of the Terms of Service explains why. Your email address is changed through your sign-in settings.
- Deletion. Delete your account from your settings, or ask us. Section 9 says what deletion does and does not reach.
- Restriction — ask us to stop using your data while a disagreement is being worked out.
- Objection to anything we do on the basis of a legitimate interest, including keeping your handle. Tell us why, and we will weigh it and answer.
- Withdraw your consent to health-related content at any time, in Settings → Account, which deletes every journal entry and every mood with it.
- Portability — the export above is machine-readable and yours to take elsewhere.
- Complain to your national data protection authority, whether or not you have complained to us first.
There is no automated decision-making on Comitry that has any legal or significant effect on you. No decision about your account is taken by software alone.
11. Security
- All traffic uses HTTPS, with HSTS
- Data is encrypted in transit and at rest
- A strict content security policy limits what the browser may load
- Secrets live only on the backend deployment, never in the codebase, and the repository is scanned for leaked secrets on every change
- Access to production data is limited to people who need it, and every privileged action — a role granted, a moderation decision, an administrative access — is written to an audit log that is only ever added to
- Dependencies are scanned for known vulnerabilities on every change
- Authorisation is enforced in the backend functions, with a test suite over the permission rules, because the database itself has no row-level security
If a breach puts your data at risk, we notify the supervisory authority within 72 hours where the law requires it, and we tell you directly where there is a high risk to you. We will say what happened, what it means for you, and what we are doing, rather than a reassuring paragraph with nothing in it.
12. Cookies and similar technologies
Comitry sets only what it needs to work:
- Sign-in cookies set by Clerk, which keep you signed in and protect the session
- A theme cookie, which remembers whether you chose light or dark
- A language cookie, which remembers which language you chose
- Cloudflare's bot-protection cookie on the sign-up page, which is there to stop automated account creation
There are no advertising, tracking or analytics cookies, no pixels, and no third-party trackers. Because every cookie we set is strictly necessary or is a preference you set yourself, there is no consent banner. If we ever add anything that is not strictly necessary, we will ask you first and it will be off until you say yes.
13. Children
Comitry is for adults. We do not knowingly hold data about anyone under 18. If you believe we do, write to the privacy contact and we will check it and delete it.
14. Changes to this policy
If we change this policy materially we will tell you and ask you to accept the new version. The version you accepted, and the date, is recorded, and previous versions stay published so you can see what changed.