Last updated: July 2026
H.O.W. was built around one rule from the start: no accounts, no passwords, and no personal information required to use it. There's one honest exception to that, for people who choose to subscribe — explained clearly below, not buried in fine print.
Your mood, journal, gratitude, goals, and check-in history are written directly to your browser's local storage and never sent to our servers at all — not encrypted-and-stored, not "private via access rules" — simply never transmitted. We could not read them even if compelled to, because we never receive them in the first place. Your partner cannot see any of it either, including whether or when you've checked in — the shared journal entry described below is the only thing a partner ever sees. The trade-off: this data lives only on this device. If you clear your browser data, switch devices, or reinstall, it's gone — there's no backup or recovery, by design.
There is no chat or messaging feature in H.O.W., and your partner does not see your check-in activity. Instead, if you subscribe to Share ($3/month), you can choose to let your connected partner read that day's mood and journal note together, as one entry — meant as a jumping-off point for a real conversation when you meet in person or check in by phone, not a replacement for one.
Sharing is entirely opt-in, one entry at a time, and end-to-end encrypted: the entry is encrypted on your device before it ever leaves it, using a key that only your device and your partner's device hold. Our server stores only the encrypted, unreadable version — we genuinely cannot read it, and neither can anyone who might compel us to try. See "How shared entries are encrypted" below for the technical detail.
The moment you check the "share this entry" box and save, that day's mood and journal note are encrypted together and sent as one entry. Nothing else — not your principle reflection, not other days' entries, not your goals, not your check-in history — is ever affected. You can unshare (delete) a previously shared entry at any time, whether or not you're still subscribed. H.O.W. supports one active partner connection at a time; disconnecting also removes anything you'd previously shared with that partner.
Non-subscribers' partners see nothing at all — not journal content, not check-ins, nothing.
When you first open H.O.W., your device generates its own encryption keypair. The private half never leaves your device — it's stored only in your browser's local storage, the same as your journal. Only the public half is ever sent to our server, which is safe by definition: a public key can't be used to decrypt anything on its own.
To share an entry, your device and your partner's device combine your private key and their public key (and vice versa) to arrive at the exact same shared encryption key, without that key ever being transmitted anywhere — a standard, well-established technique called Diffie-Hellman key agreement. Your device uses that shared key to encrypt the entry before sending it; your partner's device uses the same derived key to decrypt it after receiving it. Our server only ever handles the encrypted result.
The practical consequence: there is no key on our servers capable of decrypting a shared entry, under any circumstance — not a data breach, not an insider, not a legal order compelling us to produce it. We would have nothing readable to hand over.
You can optionally connect a Google Calendar so that today's events from it show up automatically on your Today tab — useful for a dedicated "Sponsor" or "H.O.W." calendar you keep for program-related meetings. This is entirely opt-in and off by default.
If you connect it: you'll sign in with Google and choose which one of your calendars to use. We request read-only access to your calendars — H.O.W. can never create, edit, or delete anything in your Google Calendar, and it only reads from the single calendar you pick, not your full account. We read the events for that calendar for the current day only, each time you view the Today tab, to display their title, time, and location.
The credential that lets us read your calendar (an OAuth refresh token) is stored securely on our server and is never sent to your browser or exposed to anyone operating the app directly — it's used only inside a locked-down server process to fetch that day's events on your behalf. We don't use your calendar data for anything else: not analytics, not advertising, not sharing with any third party.
You can disconnect at any time from the Today tab, which deletes the stored credential immediately, or by revoking H.O.W.'s access directly from your Google Account permissions page.
The free features — daily principle, mood, journal, gratitude, sobriety counter, goals, check-ins, and connecting with a partner — never require any personal information at all.
If you subscribe to unlock Share, our payment processor, Stripe, collects the information it needs to charge a card and send you a receipt — typically an email address and billing details. That information is held by Stripe, under their own privacy practices, not by us. What we store on our side is a single reference ID linking your anonymous device record to your Stripe subscription — not your email, name, or card details, none of which ever reaches our database.
If you never subscribe, none of this applies to you — you remain fully anonymous.
H.O.W. is meant to be a long-term companion, not something that expires — your local data sticks around on your device indefinitely so your progress has continuity. You can permanently delete everything yourself, at any time, from the "Delete everything" button on the Partners tab — it removes your entire server-side footprint (profile, partner connection, shared entries, subscription record) immediately and irreversibly, and clears everything saved on this device.
H.O.W. is built on a small number of third-party infrastructure providers, who process data on our behalf:
| Provider | What they handle |
|---|---|
| Supabase | Hosts the database where your partner connection and any entries you've explicitly shared (encrypted, unreadable to us) are stored. Never receives your private mood, journal, gratitude, goals, or check-in history. |
| Stripe | Processes payment for the optional Share subscription; holds your email/billing details if you subscribe |
| Google Calendar | If you choose to connect a calendar, provides read-only access to the events on that calendar so we can display today's on the Today tab. Nothing is written back to your calendar. |
We don't sell or share data with anyone beyond what's needed to run the app, and we don't use tracking or advertising services.
Because there's no account or login, your identity in H.O.W. is tied to this device and browser. If you clear your browser data, switch devices, or reinstall, there's no way to recover your existing local data (mood, journal, gratitude, goals, sobriety date, check-in history — including your encryption key, so previously shared entries become permanently unreadable even to you) or your server-side history (partner connection) — a new install starts fresh, with a new identity and a new shareable code.
This policy may be updated as the app changes. Meaningful changes will be reflected here with an updated date.
Questions about this policy can be sent to info@serendip.cloud. To delete your data, use the "Delete everything" button on the Partners tab — since we can't access your device-local data or authenticate as you, we're not able to delete it on your behalf from outside the app.