Privacy Policy
1. Introduction
Welcome to Toast & Fig Jam. I am an independent creator, and I operate this project personally.
This Privacy Policy explains what I collect, how I use it, who helps process it, how long I keep it, and how you can ask to access or delete it.
2. Important Health and Wellness Boundary
Toast & Fig Jam is a personal wellness and reflection tool. It is not medical care, therapy, diagnosis, treatment, crisis support, or a substitute for professional assessment.
The Service collects wellness-adjacent information, including state scores, check-in answers, and nervous system reflections. Some privacy laws may treat this kind of information as sensitive personal information or health-related data. I handle it with that level of care.
3. Information I Collect
3.1 Account Information
- Email address
- Password, stored as a hashed value
- Plan type, subscription or entitlement status, onboarding status, email verification status, and account timestamps
3.2 Wellness and Check-In Information
To provide the reflective tools, I may collect:
- Vitality or state scores
- State labels such as Survival, Fragmented, Regulating, Coherent, Flow, or Vitality
- Check-in answers and saved reflections
- Daily state history and pattern-related history
- Bio-Harmony focus path choices, saved doorway preferences, and coded statement, subdomain, or desire selections when you choose or save them
- Newsletter or reminder preferences you choose to submit
3.3 Automatically Collected Information
- IP address
- Browser type and device information
- Cookie and consent preferences
- Browser-stored preferences, such as a saved Bio-Harmony doorway kept on your device
- Usage analytics, including page and event activity when analytics consent allows it
3.4 Email Correspondence
If you email me, I receive your email address, message, attachments, and any information you choose to include so I can respond to your request. Please share only what is needed, and do not email passwords, sign-in links, full card numbers, or sensitive check-in writing. Email is not an emergency or clinical support channel.
3.5 Payment and Subscription Information
If you choose a paid subscription, payment is processed by Stripe. I do not collect or store your full card number. The Service may store local subscription records needed to provide account access, such as your entitlement status, plan status, current paid period, cancellation status, refund status, selected focus paths, billing event summaries, and a record of your recurring-payment authorization, including the terms version and acceptance time.
4. How I Use Your Information
I use the information collected to:
- Operate the Service and keep your account available
- Show your check-in result and related reflections
- Save state history when you use account-based features
- Send verification, password reset, reminder, or other service-related emails
- Send marketing or educational emails when you have signed up for them
- Process subscriptions, document recurring-payment consent, send billing notices and confirmations, manage paid access, support cancellations, and respond to billing or refund requests
- Understand aggregate usage and improve the Service
- Maintain security, prevent misuse, and comply with legal requirements
I do not sell your data.
5. Legal Basis for Processing
If privacy laws such as GDPR apply to you, I process your information based on the reason for the specific use.
- Consent, for wellness check-in data, optional emails, and analytics where consent is required
- Contractual necessity, to provide the account and tools you requested
- Legitimate interests, to keep the Service secure, understand basic usage, and prevent misuse
- Legal obligations, where I need to keep or disclose information to comply with applicable law
You can withdraw consent by contacting me, using available unsubscribe links, changing cookie settings where available, or stopping use of the Service.
6. Data Retention
I keep personal information only as long as needed for the purposes described in this Policy, unless a longer period is required by law.
- Account information is kept while your account is active.
- Check-in responses, state history, saved reflections, and pattern history are kept while your account is active or until you ask for deletion.
- Local subscription, entitlement, focus-path, billing event, refund-request, recurring-payment authorization, and transactional billing communication records are kept while needed to provide paid account access, handle billing support, document consent, or meet legal and financial recordkeeping needs. Recurring-payment consent evidence may be kept for at least three years, or one year after the subscription ends, whichever is longer, when required.
- Newsletter and reminder records are kept until you unsubscribe or ask for deletion.
- Email verification tokens expire after 24 hours.
- Password reset tokens are temporary and expire after the reset window shown in the reset flow.
- Refresh tokens expire after 30 days, and access tokens expire after 15 minutes.
- Security and operational logs may be kept for a limited period to protect the Service and investigate misuse.
7. Deletion and Access Requests
You may ask to access, correct, delete, or receive a copy of your personal information, depending on the laws that apply where you live.
To request deletion or access, email privacy@toastandfigjam.com from the email address connected to your account or subscription. I may need to verify that the request is really from you before acting on it.
Account export includes account information, submitted check-in and reflection records, and local billing records connected to your account, such as entitlement status, focus-path records, and billing event summaries. The export does not include private Stripe identifiers such as full customer, subscription, session, event, payment, charge, or price IDs.
When an account is deleted, the Service deletes the account and associated personal data tied to that account, including saved check-ins, state history, reflections, prediction history, tokens, newsletter subscription records, subscriber check-in history tied to the same email address, local paid entitlement records, local focus-path records, and local billing event records, unless retention is legally required. Limited recurring-payment consent and transaction evidence may be retained for legal or financial recordkeeping. Stripe may also retain payment and transaction records according to its obligations. Some preferences may be stored locally in your browser. Browser-local data may not appear in an account export unless it has also been submitted to the account system, and you can remove it from the browser controls where available.
8. Third-Party Service Providers
I use service providers to run the Service. They may process information only as needed to provide their services to Toast & Fig Jam.
- Vercel, for hosting and serverless infrastructure
- Neon, for production Postgres database hosting
- Resend, for transactional and service-related email delivery
- Google Workspace, for receiving, storing, and responding to business email, including any information you voluntarily include
- Stripe, for payment processing, subscription management, billing portal access, cancellation, and refund processing
- Beehiiv, for newsletter subscriptions and email publication tools
- Google Analytics, for analytics when permitted by your cookie and consent settings
- Google Fonts, for font delivery used by the website
I may update this list if the providers used to run the Service change.
9. Cookies and Analytics
The Service may use cookies, local browser storage, and similar technologies to keep you signed in, remember preferences, improve site performance, and understand usage trends.
Analytics storage starts denied by default and is updated based on your cookie consent choice where the consent banner is shown.
10. Data Security
I take reasonable technical and administrative steps to protect your information, including hashed passwords, access controls, rate limits, security headers, and HTTPS-based hosting.
No online service can guarantee absolute security. If I learn of a security issue that affects your information, I will take appropriate steps based on the nature of the issue and applicable law.
11. Children's Privacy
The Service is not intended for individuals under age 13. I do not knowingly collect personal information from children under 13. If I learn that I have collected such information, I will delete it.
12. International Transfers
Your information may be processed in countries outside your own. I take reasonable steps to make sure information is handled securely wherever it is processed.
13. Your Privacy Rights
Depending on your location, you may have rights to access, delete, correct, restrict, object to processing, receive a copy of your data, or withdraw consent.
California residents may have rights under CCPA/CPRA, including the right to know, delete, correct, and limit the use of sensitive personal information. EU and UK residents may have rights under GDPR or UK GDPR.
I do not sell personal information. Toast & Fig Jam uses Google Analytics only when consent allows and uses Beehiiv when you choose to subscribe. Some disclosures may qualify as sharing under applicable law. Where required, I provide the applicable consent or opt-out control.
14. Changes to This Policy
I may update this Privacy Policy as the Service changes or legal requirements change. The date at the top shows when it was last updated.
15. Contact
If you have questions about this Privacy Policy or want to request access, correction, deletion, or another privacy action: