Privacy Policy
Last edited July 2026
This policy explains what information Edda collects, why, and how it's used. Edda is built for logging activity, whether you're tracking something on your own or sharing a Journal with others — the guiding principle is that your data belongs to your Journal, and your personal information is never shown to people you haven't chosen to share a Journal with.
Information we collect
We collect the minimum needed to run the app:
- Account information — your email address, used for sign-in (magic link, Google, or Apple sign-in).
- Global profile — a display name, emoji, and color you set once for your account. This is never shown to other members of your Journals.
- Journal-scoped identity — a separate display name, emoji, and color per Journal you join, shown only to other members of that Journal.
- Journal content — activity types, logged activities, notes, custom field values, and photos you or other members add to a shared Journal.
- Photos — compressed before upload and stored against the specific log entry they're attached to.
- Device & push notification data — a push token tied to your account, used to deliver notifications you've opted into.
- Usage & diagnostic data — basic product analytics and crash reports, used to find and fix bugs and understand which features are actually used.
- Subscription status — whether your account is on the Free or Pro tier, managed through the App Store or Google Play.
What we don't collect
- We don't collect a date of birth. Account creation requires acknowledging you're 13 or older.
- We don't sell your data to third parties, ever.
- We don't show your global profile to other Journal members — only your Journal-scoped identity.
How your data is shared inside a Journal
Anything you log to a Journal — activities, notes, photos, reactions — is visible to the other members of that Journal, according to your role's permissions. Row-level security is enforced on every table: members of one Journal can never read another Journal's data.
Be mindful of what you log
Journals can hold anything you choose to log. Edda doesn't limit what you can log, and doesn't apply any special handling to particular categories of content — it's stored and shared with your Journal members. You're responsible for what you log — consider what you're comfortable sharing with your Journal members before you add it, especially sensitive details like medications or health notes. You're asked to acknowledge this directly the first time you use Edda.
Third-party services we use
Edda is built on a small number of trusted infrastructure providers, each handling a specific job:
- Supabase — database, authentication, and file storage for all app and Journal data, hosted in the EU (Paris, eu-west-3 region).
- Google Sign-In / Apple Sign-In — optional social sign-in, if you choose those methods.
- RevenueCat — manages Pro subscription status and receipt validation with the App Store / Google Play.
- PostHog — product analytics, used in aggregate to understand feature usage.
- Sentry — crash and error reporting, used to find and fix bugs.
- Google AdMob — displays ad banners to Free-tier users only. Pro subscribers never see ads.
- MailerLite — if you sign up for launch updates on this website, your email address and platform preference (Android, iOS, or both) are stored with MailerLite to send you that notification.
Each of these providers processes data only as needed to provide their specific service to Edda.
This website's analytics
This website (getedda.com, separate from the app) also uses PostHog for basic page-view analytics — which pages are visited and roughly how. It's configured to keep nothing in cookies or local storage: identifiers exist only in memory for the current page and are gone when you close the tab, so no consent banner is required.
Launch notification signup
This website offers an optional signup form for launch updates. If you enter your email address, it's sent to MailerLite along with your platform preference (Android, iOS, or both), and used only to email you when Edda becomes available. This is separate from your in-app account — signing up here doesn't create an Edda account, and creating an Edda account doesn't add you to this list. You can unsubscribe at any time using the link in any email we send, or by contacting hello@getedda.com.
Data retention & deletion
Your data is retained for as long as your account and Journal memberships are active. A Journal deleted by its admin can be recovered for 30 days, after which it is permanently erased, photos included.
You can also delete any individual entry you've logged, including its photos, directly in the app at any time — no account deletion required.
When you leave a Journal, you choose what happens to the activity history you contributed there:
- Transfer your records — your entries stay in the Journal's shared history, re-attributed to a local member that keeps your Journal display name and avatar but is no longer linked to any account.
- Delete everything — entries where you are the only credited member are permanently and immediately erased, photos included. Entries you share credit on with other members are kept for them, with your credit removed.
To delete your account: open Edda, go to Account, and tap Delete account. You make the same transfer-or-delete choice separately for each Journal you belong to, and then your login, your global profile, and your membership in every Journal are immediately and permanently deleted. Journals where you are the only account holder are deleted entirely at the same moment, photos included. If you can't sign in to reach that screen, email support@getedda.com from the address on your account and we'll delete it for you.
What's always removed: your account credentials, your global profile (name, avatar), and your membership in every Journal.
What may be retained: entries other members share credit on — deleting your account is not the same as deleting a shared household's history — and append-only audit logs used for accountability within a Journal (e.g. who approved an entry), which may keep your Journal display name, no longer linked to any account. Autocomplete suggestions derived from values previously typed in a Journal also persist, with no record of who typed them.
Children's privacy
Edda is not directed at children under 13, and account creation requires acknowledging you meet that minimum age. We do not knowingly collect data from children under 13.
Changes to this policy
We'll update this page if how we handle data changes, and update the "last edited" date above. Material changes that require re-acknowledgement will prompt you the next time you open the app.
Contact
Questions about this policy or your data can be sent to hello@getedda.com.