last updated · june 2026
privacy.
v0.1 draft. this page is a working version. it has not been reviewed by a lawyer yet. when it is, this notice will come down. you can email
nik@thinknik.ca with questions any time.
lostaf is a place for self-reflection. that means the site only really works if you can save things — what you've read, what you're tracking, what you're sitting with. this page explains, in plain language, what lostaf stores about you, how it's used, and what your control over it looks like.
what is stored
when you sign in with google, lostaf keeps:
- your email and display name (from google) — used to recognize you when you come back
- thinkers and articles you save
- your daily 1 habit log (which habits you marked done on which dates)
- your religion passport: the tradition you picked, and your three short reflections (what it means to you, how you live it, how you walk with it)
- gratitude entries you write
- journal entries, prompt responses, mood logs, and other path-tool inputs (psychology, stoicism, existentialism, etc.)
- your astrology birth data (only if you choose to enter it)
- ai-generated readings cached against your inputs, so the same prompt doesn't burn the same compute twice
- the "personalize this tab" text you write — used to color the ai readings on that tab
- a security audit log: an internal record of every write to your data (which row, when), kept so we can detect tampering or unauthorized changes if they ever happen
how it's used
your data is used to make your own dashboard work. that's it. it personalizes your readings, tracks your progress, surfaces what you saved. it is not shared with anyone, not sold, not used to train any model.
who can see it
only you. lostaf uses row-level security at the database — every query is scoped to your user id. another signed-in user cannot read your data, by design.
third parties
lostaf depends on a few outside services to run. they touch your data only as needed to provide their service:
- google — sign-in. lostaf receives your email and name from your google account when you sign in.
- supabase — the database and auth provider. your data lives in a postgres database hosted in their canadian region.
- netlify — site hosting.
- anthropic (claude api) — used by some path tools to generate readings. when used, lostaf sends only the specific inputs needed (your prompt and the relevant tab context), never your full account.
cookies and tracking
lostaf uses one cookie: an auth session token from supabase, set when you sign in, removed when you sign out. there is no third-party analytics, no advertising pixel, no cross-site tracking.
your control
you can:
- sign out any time
- email nik@thinknik.ca to export everything stored about you
- email the same address to delete your account and all your data permanently
- request a copy of the audit log entries for your account
data location
your data sits in supabase's canadian region (montreal). that means it stays within canadian jurisdiction.
retention
your data is kept for as long as your account is open. delete the account and it is removed permanently within thirty days (the lag is to allow recovery from accidental deletes). backups beyond that window are encrypted and rotate out on a normal schedule.
changes
if this policy meaningfully changes, the date at the top of this page changes too. if the change affects what is stored or how it is shared, signed-in users see a notice on the dashboard before the change applies.
contact
questions, requests, anything: nik@thinknik.ca.