Privacy Policy
Last updated · August 8, 2026
This Privacy Policy explains what Crucible collects, how it is used, and the choices you have. Crucible is operated by Artorias Group LLC ("we", "us"). Crucible requires an account: your data is stored on your device as a working cache and synced to our cloud so it is backed up and available across your devices.
Information We Collect
- Profile: your display name, the "reasons" you write during onboarding, your @username, and — only if you choose to add them — a profile photo and a phone number.
- Activity: your daily habit completions and misses (including training, meditation, reading, and nutrition trials), your optional committed sleep schedule, and your program history, achievements, and progression.
- Age: when you create an account we ask for your birth month and year, only to check that you meet our minimum age of 13. We do not keep that date. All that is stored is which age band you fall into — "13–17" or "18 or over" — and it is kept on your device, not sent to our cloud.
- Account: your email address, handled by our authentication provider. If you sign in with Google or Apple, we receive basic account details from them (such as your email), never your password.
- Coliseum: your challenger connections, requests, and the taunts and salutes you exchange, plus skirmish and duel records, if you use those features.
- Photos and media: with your permission, the App can use the camera or photo library when you choose a profile photo or add a progress photo, and can save a progress photo back to your media library when you ask. Profile photos are stored for account and Coliseum use. Progress photos remain only on your device and are not uploaded to us.
- Usage analytics: product events, screen views, app-lifecycle events, feature use, coarse completion counts, subscription-funnel events, and crash or exception diagnostics (such as error messages, stack traces, and technical context) collected through PostHog. After sign-in, this data is tied to your stable Supabase account UUID. It is therefore pseudonymous, not anonymous.
- Subscription data: your stable Supabase account UUID and app-store purchase, product, subscription, trial, renewal, expiration, and entitlement status processed through RevenueCat. We do not receive your full payment-card details.
- Technical: a push-notification token and your device's time zone for reminders, plus app environment and diagnostic information attached to analytics and error reports.
We do not collect your contacts, precise location, or browsing history. We access the camera or photo library only when you invoke a photo feature and grant permission.
Health and Wellness Data
Some of what Crucible stores — your training, meditation, and nutrition completions and your sleep schedule — is wellness information that some laws (such as Washington's My Health My Data Act) treat as consumer health data. We collect it only because recording it is the point of the App, we use it only to run the App for you (progress, streaks, sync, and the reminders you've enabled), and we never sell it or share it for advertising. PostHog may receive coarse completion totals for product analytics, but we do not send specific trial names or trial IDs, your written reasons, or your sleep schedule in analytics events. Premium AI features do send some of this to Anthropic — the exact list is in "AI Features (Premium)" below, and your sleep schedule is not on it. You can access this information (Export), delete it (Erase / delete account), or stop providing it at any time from within the App, and you may also exercise these rights by contacting us at support@usecrucible.app.
How We Use Information
We use your information to run the App for you: to show your progress, maintain streaks, sync your data across your devices, power the Coliseum features you opt into, send the reminders you've enabled, manage subscriptions and premium access, understand feature use, evaluate feature flags, and diagnose crashes. Reminder messages may quote the "reasons" you wrote, to hold you accountable.
Usage Analytics, Feature Flags, and Error Reports
We use PostHog as a service provider for product analytics, feature flags, and crash and exception tracking. PostHog receives the usage and diagnostic data described above and, after you sign in, your stable Supabase account UUID. We use this information to measure the onboarding and subscription funnels (including selected plan, displayed price, and purchase success, failure reason, or restore status), understand aggregate use, decide which App features or configurations to show, and repair failures. We do not use session replay or send specific trial IDs in completion events. Analytics are enabled by default. You can turn off PostHog usage and exception capture from Settings → Share usage data; that device-level choice remains in effect across sign-out and sign-in.
Subscription Data
Apple or Google handles the payment transaction. RevenueCat receives your stable Supabase account UUID and the store-supplied subscription and entitlement information needed to display offerings, complete or restore purchases, verify premium access, and keep access current after renewals, cancellations, refunds, or expiration. We and RevenueCat use this information only to operate subscriptions and premium access; we do not send RevenueCat your email address through the App.
AI Features (Premium)
Two premium features send information to Anthropic (the AI provider), and only these two:
- AI-composed reminders: your written reasons and your current day's completion count, used to compose the notification text, which is delivered back to your device.
- The Oracle: your written reasons, your current streak, how many of today's trials you have completed, the name of the trial you complete least often, and the Oracle's Codex — a short record the Oracle keeps of your milestones (gates passed, streaks lost, levels reached, programs completed, decrees kept or fallen).
We do not send your name, your email address, other contact details, or your committed sleep schedule with either request. Anthropic processes this data as a service provider and, under its API terms, does not use it to train its models. The Oracle's Codex is shown to you in full inside the App, so you can read exactly what it holds.
What Other Users Can See
Nothing about you is visible to other users unless you use the Coliseum. A signed-in user who searches your exact @username can see your display name, @username, and avatar before you accept a request. Accepted challengers can also see your rank and level, campaign mode, today's completed and available trial counts, programs completed, achievements and showcase, selected title, avatar, champion, equipped items and profile cosmetics, skirmish history, duel status, and duel history and results. A direct duel opponent can see your daily duel totals, final scores and results, and a snapshot of your display name, @username, avatar, title, cosmetics, and champion as they appeared for that duel. Your written reasons, exact per-trial history, sleep schedule, phone number, and email are never visible to other users.
Cloud Backup & Sync
Your data is stored on your device as a working cache and synced to our cloud so it is backed up and available when you sign in on another device. Your account is the key to that data, so keep your credentials safe. You can export or erase your data at any time from Settings.
Service Providers
When you use the App, push notifications, or premium features, we rely on:
- Supabase — authentication and encrypted cloud database and file storage.
- Expo / Firebase Cloud Messaging — delivery of push notifications.
- Anthropic — composing premium AI reminders and Oracle consults (see above).
- PostHog — product analytics, feature flags, and crash and exception tracking (see above).
- RevenueCat — subscription purchase, restore, entitlement, and renewal management (see above).
These providers process data on our behalf under their own security and privacy terms. Our servers are located in the United States, so if you use the App elsewhere your synced data is processed in the United States. We do not sell your personal information, and we do not share it with anyone for advertising.
Data Retention
We keep your cloud data while your account is active. When you erase your data or delete your account in the App, we delete your associated records (profile, habit history, sleep schedule, challenger connections, device tokens, and notification logs). Short-lived operational records, such as notification-delivery entries, are kept only as long as needed to run those features.
Your Choices and Controls
- Export: download a copy of your data from Settings → Export my data.
- Erase and delete your account: Settings → Erase all data wipes this device and deletes your account and its synced records together. This cannot be undone.
- Notifications: turn reminders on or off any time in Settings.
- Usage analytics: turn PostHog analytics and exception capture off or on from Settings → Share usage data.
- Coliseum: decline or remove challengers at any time; Coliseum notifications have their own switch.
- Account: sign out from Settings → Manage account.
Depending on where you live (for example the EU/UK, California, or Washington), you may have additional statutory rights to access, correct, delete, or port your data, or to withdraw consent. The in-app controls above cover these; for anything else, contact us at support@usecrucible.app and we will respond as the law requires. We never discriminate against you for exercising your rights.
Children's Privacy
Crucible is not directed to children under 13, and we do not knowingly collect personal information from them. The App is intended for people 13 and older, including teenagers. When you create an account we ask for your birth month and year and stop anyone under 13 from continuing; we keep only the derived age band, on your device, never the date itself. For users ages 13–17, the same pseudonymous PostHog analytics and error-reporting posture described above applies: it is enabled by default and can be turned off in Settings. We do not sell their information or use it for targeted advertising. If you believe a child under 13 has provided us information, contact us and we will delete it.
Security
We use industry-standard measures, including per-user access controls and encrypted transport, to protect your data. Authentication tokens are stored in your device's secure storage. No method of transmission or storage is perfectly secure, however, and we cannot guarantee absolute security.
Changes to This Policy
We may update this Policy as the App changes. We will revise the "Last updated" date and, where appropriate, notify you in the App.
Contact
Questions about your privacy? Contact us at support@usecrucible.app.