Privacy
Your reflections never leave your browser.
Honest Minutes invites people to write down things they haven’t told anyone. That only works if the privacy promise is real, so this page describes exactly how the site behaves — in plain language, without the fog.
Last updated
The short version
- Anything you write in a reflection stays in your own browser. It is never transmitted to us, and we have no copy of it.
- If you join a list, we store your first name and email address so we can send you what you asked for.
- We don’t sell or share your data, and we use no advertising or cross-site tracking.
- You can leave at any time, and ask us to delete your record.
Who we are
Honest Minutes publishes a daily reflection question by email and at honestminute.com. For anything in this policy, contact us at hello@honestminute.com.
Under UK and EU data protection law we are the controller of the personal data described below.
What stays on your device
The writing area, the five-minute reflection, and every saved answer use your browser’s local storage. That data is written by code running on your own machine, and it stays there.
Specifically, what you write is never:
- — sent to our servers; no endpoint accepts it
- — included in an analytics event
- — placed in a URL or query string
- — passed to any AI or machine-learning service
- — shared with advertisers or data brokers
Sharing a question shares the question and its public link, never your answer. Because we hold no copy, clearing your browser data deletes a reflection permanently — we cannot restore it for you.
We also store one small preferences entry recording whether you’ve already seen the opening sequence. That is all.
What this browser is holding
This browser is holding no reflections.
What we store
If you join a list, our database holds:
- — your first name, so the email can greet you
- — your email address, so we can send it
- — which lists you asked for: the daily question, the journal waitlist, early access to the app
- — a short referral token such as
instagramordirect, so we know roughly where people find us. No full URLs, no query strings, nothing identifying. - — whether the subscription is active, and the dates it was created and last changed
One person is one record. Adding the journal waitlist to an existing subscription updates that record rather than creating a second one.
Why we’re allowed to hold it
We rely on your consent, given when you submit the signup form, to send the emails you asked for. You can withdraw it at any time by unsubscribing, which doesn’t affect anything sent before then.
We rely on our legitimate interests in keeping the site working and free from abuse for basic security measures such as rate limiting.
Who else touches it
This list is short deliberately. Three companies process data on our behalf, each under a data processing agreement:
- — Supabase hosts the subscriber database
- — Resend delivers the emails
- — Vercel hosts the site and serves its pages
We do not sell your data, share it for anyone else’s marketing, or pass it to data brokers. We would disclose it only where legally required.
These providers may process data outside the UK and EEA. Where they do, transfers are covered by the safeguards in their own terms, such as Standard Contractual Clauses.
How long we keep it
We keep your subscriber record for as long as you’re subscribed. If you unsubscribe, we keep a minimal record marked unsubscribed so we don’t accidentally email you again, and delete it entirely on request.
Reflections have no retention period, because we never receive them. They last exactly as long as your browser keeps them.
Your rights
You can ask us for a copy of what we hold, have it corrected or deleted, receive it in a portable format, object to processing, or ask us to restrict it. Email hello@honestminute.com and we’ll action it — there is no form and no queue.
If you’re in the UK and think we’ve handled your data badly, you can complain to the Information Commissioner’s Office at ico.org.uk. If you’re in the EU, complain to your national supervisory authority.
Security
The site is served over HTTPS. Database credentials are held as server-side environment variables and never reach the browser, and writes to the subscriber database happen only in server code. No system is perfectly secure, but the safest data is the data nobody holds — which is the main reason reflections never leave your device.
Children
Honest Minutes isn’t intended for children under 13, and we don’t knowingly collect their personal data. If you believe a child has subscribed, email us and we’ll remove the record.
Changes to this policy
If this policy changes we’ll update the date at the top of the page. If a change materially affects how we use your data, we’ll tell subscribers by email rather than quietly editing the page.
Before launch, have this reviewed. This page accurately describes how the site behaves, but it was drafted as a starting point and is not legal advice. A solicitor familiar with UK GDPR, EU GDPR and CCPA should review it before Honest Minutes takes real subscribers — particularly the named data controller and its registered address, the retention periods, and whether a CCPA “Do Not Sell or Share” notice is needed for your audience.