← back

Privacy

Last updated 2026-06-28. Written in plain language, not legalese.

The short version

What you say to Catalyst is meant to stay between you and the AI. We built the data layer to support that — but we want to be honest about where the protection is real and where it has limits.

What we collect

  • Your account info (email, name) — held by Firebase Auth.
  • The conversations you have with Catalyst, the summaries the AI generates about them, and a quiet model of who you are that improves the AI’s responses over time.
  • Basic product analytics about how you use the app — for example, that a message was sent and a count of how many — so we can tell whether Catalyst is working and where it breaks. We never attach the contents of what you write to these events. No tracking pixels, no ad networks, no advertising profiles.
  • The analytics are tied to the same random ID as the rest of your data, not to your name or email.

How your data is stored

  • Pseudonymous storage. Your conversations and profile are stored under a random ID that isn’t linked to your name or email in the same place. Browsing the database doesn’t show “Catalyst staff saw Sy’s chat” — it shows content under an anonymous ID.
  • Encryption at rest. The actual content of your messages, summaries, and profile is encrypted using AES-256-GCM before it’s written to the database. A database leak without our encryption key would expose ciphertext, not your words.
  • Encryption in transit. Standard TLS between you, our servers, and the AI provider.

Who can access your data — honest version

The AI has to read what you write to respond to you. There’s no way around that — that’s the product. Beyond the AI:

  • Operators (us). Technically, someone with admin access could decrypt and read your data. We don’t do this as a matter of policy. Every admin-side access is logged to a record tied to your account, and you can ask to see those logs.
  • Anthropic (the AI provider). When the AI generates a response, your message and the relevant context are sent to Anthropic. Under their commercial terms, Anthropic does not train its models on your data, and retention is limited to what those terms allow (short-term, for operating and abuse-monitoring the service) — not kept long-term for their own use.
  • Nobody else. We don’t sell, share, or license your data to advertisers, data brokers, marketers, or anyone else.

Who we share data with (our processors)

A few outside services power Catalyst. Each one only ever gets the slice of data it needs to do its job, and none of them are allowed to use your data for their own purposes.

  • Anthropic — the AI itself. When Cat replies, your message and the relevant context are sent to Anthropic’s models to generate the response.
  • Stripe — payments. Handles your card and subscription. We never see or store your full card number; Stripe does that on their own PCI-compliant systems.
  • Google Firebase — accounts and infrastructure. Firebase Authentication holds your login (email, name), and our database runs on Google’s cloud.
  • PostHog — product analytics. Receives the usage events described above (that an action happened, not what you wrote), so we can see whether the product works.

We don’t sell, rent, or license your data to any of them, or to advertisers, data brokers, or marketers.

When we might cross that line

  • Safety. If you express imminent danger to yourself or others, we may route you to crisis resources and, in extreme cases, take other action a reasonable person would expect.
  • Legal. If we’re legally compelled (subpoena, court order), we’ll comply — but we’ll push back on overreach and notify you where we’re permitted to.
  • Debugging — only with your consent. If you report a bug and we need to see your data to fix it, we’ll ask first.

Your rights

  • Export. You can ask for everything we have on you in a portable format.
  • Delete. You can wipe your account at any time from the app. We delete the data immediately. Backup copies (if any exist for disaster recovery) roll off within 30 days.
  • Correct. If we have something wrong about you, you can correct it — either by talking to Catalyst about it or by contacting us directly.

What we are not

  • We are not a therapist. We don’t diagnose, treat, or provide medical advice. If you’re dealing with something that needs clinical care, please talk to a professional.
  • We are not HIPAA-covered. We’re a consumer wellness tool, not a healthcare provider. If you need HIPAA-grade protection, a licensed therapist is the right tool.
  • We do not provide end-to-end encryption today. For the AI to do its job, content has to be readable on our servers. Mobile (when it ships) will add client-side encryption that narrows the exposed surface.

Changes

We’ll update this page if we change how we handle your data. We’ll notify you in the app before any change that makes the protection weaker. We won’t notify in advance for changes that make it stronger.

Contact

If you have questions about any of this, or want to exercise any of the rights above, contact us at privacy@catalystcoach.app.