SIDERIA

Privacy Policy

Last updated: August 27, 2026

Sideria is operated by Marcus DuPont, an individual based in New York, United States ("we," "us," "our"). It is built on the principle that the safest data is data we never hold in a readable form. This policy describes exactly what we collect, what we can see, what we cannot — even ourselves — and what never leaves your device at all.

What We Collect

Aggregate Service Measurements

We use Discovery activity to understand how well people can reach one another and whether the social sky remains safe and equitable. Daily measurements cover reach, exposure distribution, unanswered pulses, mutual connections, fading connections, isolated regions of the network, reports, and blocks.

Daily graph-health records contain aggregate counts and statistical measurements. They contain no user IDs, habit IDs, pulse IDs, connection IDs, email addresses, or habit names. Anonymous safety-event records contain an event type and, where relevant, the pulse reflection depth. We delete those raw safety-event records after 90 days and retain the daily aggregate measurements.

We use these measurements for service safety, reliability, capacity planning, and product improvement. They do not power advertising, cross-app tracking, or individual behavioral profiles.

What Stays Only on Your Device

Some of the most personal things in Sideria never reach our servers at all:

Because these never leave your device, we cannot read them, recover them, or restore them. If you log out or delete the app, they are gone — that is the trade-off for keeping them entirely yours.

What We Can See — and What We Cannot

Habit names are encrypted at the application layer.

The name you give a habit (e.g. "meditate," "stop drinking," "Wednesday meetings") is encrypted in our application before it is written to the database, using AES-256-GCM with a key held outside the database. A snapshot of our database — by us, by a contractor, by a leaked backup, by a court order producing a database dump — yields opaque bytes for habit names, not readable text. We cannot read your habit names. We are not pretending to, because we deliberately gave that ability up.

What we can see, and act on.

We can see, and our moderation systems do see, content that you actively send to other people through Sideria. Specifically, pulses (the brief signal you can send to people you are connected with) are classified for harmful content at send time. We do this because pulses leave you and reach someone else — they are not your private notebook.

We do not have a person-to-person messaging surface.

Sideria is, by design, not a chat app. There is no free-text messaging between users. The social signals are limited to: ambient indicators that someone showed up, anonymous pulses, and beacons that invite someone you know to a shared habit. This is both an aesthetic choice and a safety choice.

What Other People Can See About You

Discovery is off by default and is chosen per habit. What others can ever see is deliberately narrow:

What We Do Not Collect

We do not use analytics SDKs, advertising networks, or data brokers. We do not sell, rent, or share your data with anyone, and we do not use it to train AI models.

Third-Party Services

How We Protect Your Data

Breaking Habits and Recovery

Sideria supports recovery, sobriety, and other sensitive tracking. These habits default to private visibility. Our encryption design means that even if our database were fully compromised, the literal text of your private recovery habits would remain unreadable. This is intentional and is the architecture we will maintain.

Mood Readings

If you choose to record your mood — your inner "weather" — we store it as a value on a five-point clarity scale, with an optional short note, on our servers so it can appear in your own calendar and reflections. This is health-adjacent information, and we treat it accordingly: it is owner-scoped, it has no social read path, it is never shared with another user or any third party, and it is never used for advertising or tracking. You can delete any reading, and all readings are removed when you delete your account.

Abuse, Harm, and Reporting

If you receive a pulse from another user that is harassing, hateful, exploitative, or otherwise harmful, you can report it. Reports go to a human who reviews and can remove the sender from the social pool. We act on reports involving threats to safety as quickly as we are able. For content involving the safety of a minor, we follow mandatory reporting requirements applicable to our jurisdiction.

Because habit names are encrypted, we cannot proactively scan private habit content for safety issues — only content that you actively send to another person is subject to moderation. We believe this trade-off is the right one for the population this app serves; we are clear about it here so you understand exactly what oversight we do and do not have.

Your Rights

You can export all your data (JSON or CSV) from Settings at any time. You can delete your account from Settings → danger zone. The deletion flow requires you to type DELETE to confirm, and the action is irreversible.

When you delete your account: your email, username, password, and supporter status are wiped from our database; your habits, completion history, sent and received pulses, kindred connections, discovery profile, mood readings, and device tokens are deleted; you can no longer sign in with that email, and the email is freed for re-registration. The deletion takes effect immediately — any active session token stops working on the next request. Anything kept only on your device (your journal, Steady) is cleared from the app when you log out.

What we keep, and why: if you were the subject of a moderation action (an abuse report against you, an admin incident record, an evidence snapshot), we preserve that record after deletion. This is so we can recognize patterns of harm across accounts and protect other users from someone deleting and re-registering to escape suspension. These preserved records contain no personally identifying information about you beyond what was necessary at the time of the incident. If you have never been the subject of a moderation action, nothing is preserved.

Backups are retained for up to 30 days for disaster recovery, after which they are permanently destroyed. A deletion request applies to live data immediately; it propagates through backup expiry over the following 30 days.

De-identified daily service measurements remain after account deletion. These aggregate records have no account identifier and cannot be attributed to an individual account.

Children

Sideria is not directed at children under 13 in the United States, and we ask for your year of birth at sign-up to enforce this. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, contact us at the address below and we will delete it. Outside the United States, equivalent local minimum age rules apply.

Changes

If we make a material change to this policy, we will notify you through the app and by email before the change takes effect when reasonably possible. The notice will summarize the change, identify its effective date, and link to the published policy. Earlier versions remain available upon request.

Contact

Questions about your data, requests for export or deletion, or reports of abuse: support@sideria.io