Privacy Policy

Prep · prep.circuvent.com · Last updated 3 August 2026

This policy describes what Prep collects, what it is used for, and what we deliberately cannot see. It is written to be checkable against the software rather than to be reassuring.

The short version. Your working data stays in your browser and syncs to your account so you do not lose it. Documents you store in the vault are encrypted on your device before they are uploaded — we cannot read them, and neither can an administrator or anyone who obtains a copy of the database. You can delete your account and everything in it from Settings at any time.

Who we are

Prep is operated by Circuvent Technologies. For any privacy question, or to exercise the rights described below, contact support@circuvent.com.

What we collect

DataWhyRequired?
Email address To identify your account and let you sign in Yes
Name Shown in the app and on documents you generate No
Password Stored only as a scrypt hash. We never hold the password itself Only for password sign-in
Session records IP address, browser or device description, and times, so you can review and revoke the devices signed into your account Yes
Your app data Applications, skills, habits, goals, notes and similar — whatever you enter. Synced so it survives a lost device No, sync can be avoided by not signing in
Documents Encrypted on your device before upload. We store ciphertext only No
Community profile and posts Visible to other members. Only created if you opt in No
Activity log Sign-ins, failed sign-ins, administrative actions — for security and abuse investigation Yes

What we cannot read

Documents stored in the vault are encrypted in your browser using AES-256-GCM, with a key derived from a passphrase that is never transmitted. The server receives only ciphertext. Filenames and descriptions are encrypted too, because a filename alone can reveal what a document is.

This is a technical guarantee rather than a promise of good behaviour: there is no mechanism by which we could decrypt your documents, and the administration interface has no route to them.

The consequence: if you forget your vault passphrase, your documents cannot be recovered — by you, by support, or by anyone. There is no reset, because a reset would mean we could decrypt them.

Where your data goes

Infrastructure

Optional features you switch on

What we do not do

Visitor statistics

We count page views so we can tell whether anyone is finding the site and which pages are useful. This is measured by us, on our own servers. There is no Google Analytics, no third-party script, and nothing is shared with anyone.

No cookie or identifier is stored on your device for this, which is why the site has no cookie banner — there is nothing to consent to. We also do not store your IP address. Instead, each day a random secret is generated and used to turn your connection into a short code. That code lets us tell two visits apart on the same day without knowing who either of you is, and the secret is deleted after two days, after which the codes cannot be linked back to anyone at all — by us, by anyone who obtained our database, or by a court order.

For each view we record:

Nothing here is connected to your account. There is no user identifier in this data and no way to add one, so it cannot be used to see what any particular person looked at. That is a deliberate limit on what we are able to do, not only on what we promise to do.

If your browser sends a Do Not Track or Global Privacy Control signal, we record nothing at all for your visit.

Notifications and two-factor authentication

If you turn on push notifications, your browser gives us an address to deliver to, plus two keys that belong to your device. We store those so we can send you a notification, and nothing else — they cannot be used to read anything from your device or to identify you elsewhere. Turning push off, or clearing your browser data, removes the address. We also delete it automatically as soon as the push service tells us it has stopped working.

If you turn on two-factor authentication, we store the shared secret your authenticator app uses, encrypted, along with hashes of your recovery codes. Recovery codes are hashed the same way passwords are, so nobody can read them out of the database — which is also why we can only show them to you once.

Quiet hours need to know your timezone to be any use, so your browser's timezone is saved with your notification preferences. It is used for that and nothing else.

Taking your data with you

You can download everything we hold about your account at any time from the Account page, without asking us. It includes your profile, everything you entered in the app, your own community posts, your notification history and the security log.

Two things are worth knowing about that file. Your vault documents are included but stay encrypted, because that is the only form we have — download readable copies from the Documents page instead. And other people's messages are excluded, even from conversations you took part in: those are their words, not your data.

The recovery module

Prep includes optional support for people reducing or stopping a compulsive behaviour. Anything you record there — journal entries, triggers, progress — is part of your synced app data and is not visible to administrators through the administration interface, which deliberately shows counts and sizes only.

This module is not a medical service. It does not diagnose or treat anything and does not replace professional care.

How long we keep it

Deleting your account

Open Settings → Account → Delete account, in the app or on the web. You will be asked for your password and to type your email address, because it cannot be undone.

This removes your account, your synced data, your encrypted documents and the files behind them, your community profile, your linked Google account and all active sessions.

If you cannot access your account, email support@circuvent.com from the address you registered with and we will delete it for you.

Your rights

Depending on where you live, you may have the right to access, correct, export or erase your data, and to object to or restrict its processing. Export and erasure are available in the app; for anything else, contact us at the address above. You also have the right to complain to your local data protection authority.

Security

No system is perfectly secure. If you find a vulnerability, please report it to support@circuvent.com.

Children

Prep is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will remove it.

Changes

If this policy changes materially we will say so in the app before the change takes effect. The date at the top always reflects the current version.