PRIVACY POLICY
Last Updated: November 28, 2025
This policy is currently under legal review. Some provisions may be updated before final publication.
CTRL+ALT+BLOCK ("we", "us", "our") operates the CTRL+ALT+BLOCK mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App.
1. Information We Collect
1.1 Information You Provide
- ▹Account Information: Email address and password when you create an account
- ▹Profile Information: Display name, avatar (optional), breakup date, healing archetype quiz responses
- ▹User-Generated Content: Journal entries, ritual completions, Wall of Wounds posts, chat messages with AI Operators
- ▹Payment Information: Processed by Apple App Store, Google Play Store, or RevenueCat; we do not store your credit card details
1.2 Information Collected Automatically
- ▹Usage Data: App interactions, features used, rituals completed, no-contact check-ins, tarot pulls
- ▹Device Information: Device type, operating system, unique device identifiers
- ▹Log Data: IP address, access times, error logs for crash reporting
1.3 AI Interaction Data
- ▹Text Chat: Messages sent to AI Operators are processed by OpenAI's GPT-4o API
- ▹Voice Calls: Audio is streamed in real-time to OpenAI's Realtime API for processing; we do not permanently store voice recordings
- ▹Context Data: Your archetype, streak information, and tier are shared with AI to personalize responses
2. How We Use Your Information
We use your information to:
- ▹Provide, maintain, and improve the App
- ▹Personalize your experience (rituals, AI responses, tarot interpretations)
- ▹Process transactions and manage subscriptions
- ▹Send service-related notifications (streak reminders, ritual prompts)
- ▹Monitor usage patterns and optimize performance
- ▹Detect and prevent fraud, abuse, or violations of our Terms
- ▹Comply with legal obligations
3. Data Sharing
We do not sell your personal information. We share data only with:
| Third Party | Purpose | Data Shared |
|---|---|---|
| Supabase | Backend infrastructure, database, authentication | Account data, usage data |
| OpenAI | AI text and voice processing | Chat messages, voice audio, user context |
| RevenueCat | Subscription management | User ID, purchase history |
| Apple/Google | App distribution, payments | Transaction data |
| Railway | Voice call proxy server | Session tokens, audio streams |
4. Data Retention
- ▹Account Data: Retained until you delete your account
- ▹Chat History: Retained for 90 days, then auto-deleted
- ▹Voice Sessions: Audio is processed in real-time and not stored; session metadata retained for 30 days
- ▹Journal Entries: Retained until you delete them or your account
- ▹Wall of Wounds Posts: Retained until removed by you or moderation action
5. Your Rights
You have the right to:
- ▹Access: Request a copy of your personal data
- ▹Correction: Update inaccurate information via your profile
- ▹Deletion: Delete your account and associated data
- ▹Data Portability: Request your data in a portable format
- ▹Opt-Out: Disable optional notifications in app settings
Account Deletion
To delete your account:
- Go to Profile → Settings → Delete Account in the App, or
- Email us at system_admin@ctrlaltblock.com with your account email
Upon deletion, we permanently remove your profile, credentials, journal entries, ritual history, chat history, voice session records, Wall of Wounds posts, and points balance. Some data may be retained for legal compliance (e.g., transaction records for tax purposes) for up to 7 years.
6. Data Security
We implement industry-standard security measures:
- ▹TLS 1.3 encryption for data in transit
- ▹AES-256 encryption for data at rest
- ▹Row-Level Security (RLS) policies in our database
- ▹Regular security audits and penetration testing
- ▹Secure JWT-based authentication
7. Children's Privacy
CTRL+ALT+BLOCK is not intended for users under 18 years of age. We do not knowingly collect information from minors. If we discover we have collected data from a user under 18, we will delete it promptly.
8. International Users
Our servers are located in the United States and Europe. By using the App, you consent to the transfer of your data to these locations. We comply with GDPR for EU users and offer the same privacy protections to all users regardless of location.
9. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via in-app notification or email. Continued use of the App after changes constitutes acceptance of the updated policy.
10. Contact Us
For privacy-related inquiries, contact us at: system_admin@ctrlaltblock.com