Legal / Privacy Policy
How URGE Handles Your Data
No dark patterns. No surprise tracking. Just what we collect, why, and what you can do about it.
1. What We Collect
To run URGE, we collect only what we need to provide the service:
Account Information:
- Email address (required for account creation and authentication)
- Username (unique identifier you choose)
- Account creation and last update timestamps
- Authentication credentials (hashed passwords managed by Supabase Auth)
Habit Tracking Data:
- Streak data: current streak count, longest streak, start dates, reset timestamps
- Urge events: when you resist or give in, with optional notes
- Relapse records: streak length at time of relapse, triggers, feelings, and optional notes
- Journal entries: up to 3 entries per day, each limited to 500 characters
Subscription & Payment Data:
- Subscription status (active, cancelled, expired, etc.)
- Payment provider customer ID (linked to your account)
- Subscription ID and end dates
- Payment processing is handled entirely by our payment provider—we never see or store your payment card details
Technical Data:
- Browser and device information (for compatibility and support)
- Session data (to keep you logged in)
2. How We Use Your Data
Core Service Delivery:
- Authenticate your account and maintain your login session
- Calculate and display your current streak and longest streak
- Log and track your urges (resisted or gave in) with timestamps
- Record relapses with associated context (triggers, feelings, notes)
- Store and display your journal entries (up to 3 per day)
- Send you 3 automated accountability emails per day (The Sentinel)
- Manage your subscription status and billing
Service Improvement:
- Aggregate anonymized usage patterns to understand how the service is used
- Identify bugs and technical issues
- Improve features and user experience
- No personal identifiers are included in aggregated analytics
Security & Legal:
- Prevent fraud, abuse, and unauthorized access
- Comply with legal obligations and respond to valid legal requests
- Enforce our Terms of Service
3. What We Don't Do
- No selling your data: We never sell, rent, or trade your personal information to third parties for marketing or any other purpose.
- No advertising networks: We don't use advertising networks, ad trackers, or behavioral profiling systems.
- No hidden trackers: We don't embed third-party tracking scripts that follow you across the web.
- No data mining: We don't analyze your journal entries or personal notes for marketing or other commercial purposes.
- No sharing with social media: We don't integrate with social media platforms or share your data with them.
- No cross-site tracking: We don't use technologies like fingerprinting to track you across different websites.
4. Third-Party Services
URGE relies on the following third-party services to operate. Each service only receives the data necessary to perform its function:
Supabase (Database & Authentication):
- Stores all your account data, streaks, relapses, journals, and urges
- Handles user authentication and session management
- Hosts our PostgreSQL database
- Subject to Supabase's privacy policy and security standards
Payment Provider (Dodo Payments):
- Processes subscription payments
- Stores payment method information (we never see your card details)
- Manages subscription lifecycle (active, cancelled, etc.)
- Subject to the payment provider's privacy policy
Email Service Provider:
- Sends automated accountability emails (The Sentinel)
- Receives your email address and email preferences
- May track email opens and clicks for delivery confirmation
Hosting Provider (Vercel):
- Hosts the URGE application
- May log IP addresses and request metadata for security and performance
- Subject to Vercel's privacy policy
All third-party providers are contractually required to handle your data securely and only use it for the purposes we specify. We regularly review our third-party relationships to ensure they meet our privacy standards.
5. Cookies & Local Storage
We use cookies and browser storage to provide essential functionality:
Authentication Cookies:
Required to keep you logged in. These are session-based and expire when you log out or after a period of inactivity.
No Third-Party Cookies:
We don't set third-party cookies or allow third parties to set cookies on our site.
If you block all cookies, URGE will not function correctly as authentication requires cookies to maintain your session.
6. Data Retention & Deletion
While Your Account Exists:
We retain all your data (account information, streaks, relapses, journals, urges) for as long as your account is active. This allows you to access your complete history and track your progress over time.
Account Deletion:
When you delete your account, we immediately and permanently delete all of your data:
- Your user account and profile information
- All streak data (current streak, longest streak, timestamps)
- All relapse records (including notes, triggers, feelings)
- All journal entries
- All urge events (resisted and gave in)
- Subscription information (after any required billing period)
This deletion is permanent and cannot be undone. Due to database cascade relationships, when your user account is deleted, all related records (streaks, relapses, journals, urges) are automatically deleted as well.
Backup Retention:
Database backups may retain your data for up to 30 days after account deletion. These backups are encrypted and are only used for disaster recovery. After 30 days, backups containing your data are permanently purged.
Payment Records:
We may be required by law to retain certain payment transaction records for a period (typically 7 years for tax and accounting purposes). These records contain minimal information (transaction ID, amount, date) and do not include your personal habit tracking data.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
Right to Access:
You can request a copy of all personal data we hold about you, including your account information, streaks, relapses, journals, and urge events. You can access much of this data directly through your dashboard.
Right to Correction:
You can update your account information (email, username) at any time through your settings. You can edit or delete your journal entries and notes.
Right to Deletion:
You can delete your account at any time through your settings. This immediately and permanently deletes all your data as described in Section 6.
Right to Data Portability:
You can request an export of your data in a machine-readable format (typically JSON). Contact us to request a data export.
Right to Object:
You can object to certain processing of your data. For example, you can unsubscribe from accountability emails, though this may limit core functionality.
Right to Withdraw Consent:
Where we rely on your consent for data processing, you can withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us at contact@urges.app. We will respond to your request within 30 days, or sooner where required by law.
8. Security Measures
We implement multiple layers of security to protect your personal data:
Encryption:
- All data in transit is encrypted using TLS/SSL
- Passwords are hashed using industry-standard algorithms (never stored in plain text)
- Database backups are encrypted at rest
Access Controls:
- Database access is restricted to authorized personnel only
- Multi-factor authentication required for administrative access
- Regular security audits and access reviews
Infrastructure Security:
- Hosting on secure, SOC 2 compliant infrastructure (Vercel, Supabase)
- Regular security updates and patches
- Firewall protection and intrusion detection
Incident Response:
- We monitor for security breaches and unauthorized access
- If a breach occurs, we will notify affected users within 72 hours as required by law
- We maintain an incident response plan
No system is 100% secure, but we treat your data with the seriousness it deserves. If you discover a security vulnerability, please report it to contact@urges.app.
9. Children's Privacy
URGE is not intended for users under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. If we discover we have collected data from a child, we will delete it promptly.
10. International Data Transfers
URGE is operated from the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. By using URGE, you consent to this transfer.
We ensure that any international data transfers comply with applicable data protection laws. Our third-party service providers (Supabase, Vercel, payment processors) may also process data in various locations worldwide, but they are contractually bound to protect your data according to our standards.
11. Data Breach Notification
In the event of a data breach that compromises your personal information, we will:
- Notify affected users within 72 hours of discovering the breach (or sooner if required by law)
- Provide clear information about what data was compromised
- Explain the steps we are taking to address the breach
- Offer guidance on steps you can take to protect yourself
- Report the breach to relevant data protection authorities where required
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other reasons. When we make changes:
- We will update the "Last Updated" date at the bottom of this policy
- For material changes, we will notify you via email or through a prominent notice in the application
- We will provide a summary of significant changes
Your continued use of URGE after changes become effective constitutes acceptance of the updated policy. If you disagree with the changes, you may delete your account at any time.
13. Contact & Questions
For privacy questions, data requests, or concerns about how we handle your data, contact us:
Email: contact@urges.app
Response Time: We aim to respond to all privacy inquiries within 30 days, often sooner.
Language: No legalese required—plain language is welcome. We're here to help.
Last Updated: March 25, 2026