Privacy Policy

Last updated September 24, 2026

This is a draft written in plain language, not a substitute for legal advice. It describes what Fulcrum collects today and how to control it.

What we store

To run the product, we store:

  • your account details: name, email, and timezone
  • the quests, side quests and rituals you create, and their history
  • your expedition sessions (focus timers) and the XP they earned
  • your sign-in method (password or a linked Google/GitHub account) — never a plain-text password
  • your active sessions, so you can see and revoke devices signed in as you
  • feedback you send from inside the app, with the page you sent it from and your browser, so we can follow up on it

Analytics

We use PostHog to understand which features get used, routed through our own domain rather than posthog.com directly. It sees which pages you open and which actions you take — not the content of your quests or rituals.

Who processes it

Data is processed by the infrastructure that runs Fulcrum:

  • MongoDB Atlas, for the database
  • Vercel, for hosting the app
  • Resend, for account emails (verification, password reset) and for forwarding your feedback to us
  • Google or GitHub, only if you choose to sign in with them

We do not sell your data, and we do not share it with anyone else.

Exporting and deleting your data

From Settings → Account you can download everything tied to your account as a single JSON file, or permanently delete your account. Deletion is immediate and cannot be undone — there is no recovery period.

How long we keep it

We keep your data for as long as your account exists. Deleting your account removes it straight away, except for records we're required to keep for legal or security reasons (for example, abuse logs), which we keep no longer than necessary.

Contact

Questions about this policy or your data can go to privacy@fulcrumapp.co.