Your data, your rules

Privacy Policy

Last updated: July 14, 2026

Your entries are private. Full stop.

What you write in Design Your Day — your morning check-ins, gratitude, evening reflections, worksheet answers, and marble-jar notes — is visible only to you. Not to Christine. Not to the coaching team. Not to other users. Not to advertisers.

This Privacy Policy explains what Christine Randall Coaching & Consulting, LLC ("we," "us," "our") collects when you use Design Your Day™ (the "App"), why we collect it, and the choices you have. We wrote this in plain English because your privacy deserves to be understandable.

1. The short version

  • We don't read your entries. Your journal content is stored in a secure database with row-level security — the technical control that ensures only your logged-in account can retrieve it.
  • We don't sell your data. Ever. Not to advertisers, brokers, or anyone else.
  • You can delete everything. Email us and we'll erase your account and all your entries within 30 days.
  • We collect the minimum to run the app. Your email so you can log in, and your entries so you can come back and see them.

2. What we collect

Information you give us

  • Account: your email address and a password (stored as a one-way cryptographic hash — we never see or store the actual password), and an optional display name.
  • Your journal content: morning check-ins, 3 musts, gratitude, evening reflections, worksheet responses, marble-jar entries, and any notes you write inside the App.
  • Billing: if you subscribe, our payment processor (Stripe) collects your payment details on their servers. We never see or store your card number. We receive only your subscription status.
  • Support messages: anything you email to info@christinerandall.com.

Information collected automatically

  • Technical logs: IP address, browser type, and timestamps of requests — used to keep the app running and to detect abuse.
  • Session cookies: a single cookie to keep you signed in. No advertising or cross-site tracking cookies.

What we do NOT collect

  • No advertising identifiers.
  • No location tracking.
  • No social-media pixels or third-party ad trackers.
  • No selling or sharing of your data with data brokers.

3. How your entries are protected

Row-level security: only you can read your rows

Our database enforces access rules at the row level. Every request for your journal entries includes your authenticated user ID, and the database rejects any query that tries to read another user's rows. Even if someone else was logged in, they physically cannot see your entries.

Christine can't read your journal

As the app owner, Christine has administrative access to the platform for billing, support, and security — but not a "view any user's entries" feature. The app is not built with one, and we do not export or open journal content unless you send it to us (for example, when you paste an entry into a support email).

Additional safeguards:

  • All traffic to and from the App is encrypted in transit (HTTPS / TLS).
  • Data is encrypted at rest by our hosting provider.
  • Passwords are hashed with industry-standard algorithms — we never see them.
  • Access to production systems is limited to essential maintenance.

No online service can promise perfect security, but we build with the assumption that your entries are the most sensitive data in the app and design accordingly.

4. Service providers we use

We keep this list short on purpose. Each of these is bound by their own privacy terms:

  • Supabase (via Lovable Cloud) — database, authentication, and hosting.
  • Stripe — subscription billing and tax handling. Stripe processes your payment information on their infrastructure.
  • Lovable AI — generates your weekly and monthly summaries from your own entries. Summary generation is processed and returned to your account; it is not used to train third-party models.

We do not use advertising networks, analytics resale, or data-broker services.

5. Your rights

You have the right to:

  • Access — see everything we have about you.
  • Correct — fix anything that's wrong.
  • Export — get a copy of your entries.
  • Delete — erase your account and all associated data.
  • Cancel — end your subscription anytime.

To exercise any of these, email info@christinerandall.com. We respond within 30 days. Depending on where you live, you may have additional rights under laws such as the GDPR (EU/UK) or CCPA (California) — the rights above cover them.

6. Data retention

We keep your entries as long as your account exists so you can look back at them. When you delete your account, we permanently delete your entries within 30 days, except for a limited set of records we're legally required to keep (like billing records for tax purposes).

7. Children

Design Your Day is intended for adults 18 and older. We don't knowingly collect data from anyone under 18. If a minor uses the App with a parent or guardian's knowledge and consent, that's between them — but the account and any data associated with it remain the responsibility of the adult account holder. If you believe a child has created an account without parental consent, email us and we'll delete it.

8. Changes to this policy

If we make a meaningful change (for example, adding a new service provider), we'll update the "Last updated" date and notify you by email at least 14 days before it takes effect.

9. Contact

Questions? Concerns? Want your data deleted? Email info@christinerandall.com or write to:

Christine Randall Coaching & Consulting, LLC
601 W. 57th Street
New York, NY 10019
(929) 459-9550