Your privacy is important to us. This Privacy Policy explains how Catalyst collects, uses, stores, and protects your personal information. We are committed to transparency and to complying with all applicable federal and state privacy laws, including the FTC Act and the California Consumer Privacy Act (CCPA).
Collected through app analytics (no third-party tracking) and our backend systems.
We use anonymized, aggregate data to understand which features provide the most value, improve daily focus scoring accuracy, optimize task recommendation quality, and test new features before rollout.
What We Do NOT DoWe do NOT sell your voice recordings, conversations, calendar data, or any personal information to third parties for any purpose.
| Situation | What's Shared | Why | Your Consent |
|---|---|---|---|
| ElevenLabs (TTS) | Voice response text | Generate voice responses | Yes (in-app consent) |
| OpenRouter (LLM) | Conversation context | Generate coaching responses | Yes (in-app consent) |
| VPS Hosting | Encrypted backups | Secure data storage | Yes (in-app consent) |
| Telegram | Message content | Enable messaging | Yes (in-app consent) |
| Payment Processor | Payment info | Process subscriptions | Yes (during checkout) |
| Legal Requirement | As required by law | Court order compliance | No (legal process) |
ElevenLabs (Text-to-Speech): Converts Catalyst's responses to voice. ElevenLabs does NOT store your personal data permanently.
OpenRouter (LLM Inference): Generates AI-powered coaching responses. OpenRouter does NOT permanently store your conversations.
Telegram (Messaging): Enables Telegram-based communication. Telegram has its own privacy policy at telegram.org/privacy.
VPS Hosting: Stores encrypted backups and databases. All data encrypted at rest (AES-256) and in transit (TLS 1.3).
At Rest: All voice recordings, conversation transcripts, and stored data encrypted with AES-256.
In Transit: All data transmitted using TLS 1.3 encryption with HTTPS-only connections and certificate pinning.
| Role | Access Level | Purpose |
|---|---|---|
| Founder | Full access | Oversight and development |
| Authorized Developers | Read-only for debugging | Issue resolution only |
| Third-Party Services | Ephemeral access | Provide services only |
Every access to your data is logged with timestamp and purpose. Logs are retained for 2 years.
| Data Type | Retention Period | When Deleted |
|---|---|---|
| Conversation transcripts | 90 days after session | 90 days after deletion request |
| Voice recordings | 90 days after session | 90 days after deletion request |
| Usage patterns | 12 months | 12 months (or 90 days if requested) |
| Crash reports | 90 days | 90 days |
If a breach occurs, we will notify you within 60 days, describe the breach, explain what we are doing to address it, and provide guidance on steps you can take.
You can view all stored conversations, voice recordings, and usage data, and export all your data in a readable format.
How: In Catalyst app → Settings → Privacy → Download My Data, or email privacy@catalystgoals.com
You can delete your account and all associated data, specific conversations, or voice recordings.
How: In Catalyst app → Settings → Privacy → Delete My Data, or email privacy@catalystgoals.com
We delete your data within 90 days. Third-party services do NOT retain your data. VPS backups are securely destroyed.
California residents can request ALL data collected (not just last 12 months) under CCPA 2026.
How: Email privacy@catalystgoals.com with subject "Data Export - CCPA". Complete export in JSON within 30 days.
You must consent before we collect, store, or share any personal data. We use explicit opt-in with no pre-checked boxes, no false urgency, no misleading placement, and no dark patterns.
If you are a California resident, your rights include:
How: Submit request to privacy@catalystgoals.com. Response within 30 days. No fee.
For automated decision-making (e.g., task recommendations, daily focus scoring), we conduct risk assessments before the December 2027 deadline, disclose significant impacts, and provide opt-out where feasible.
Catalyst is NOT intended for children under 16. We do NOT knowingly collect personal information from children under 16. If we discover such collection, we delete it immediately.
If you are outside the United States, your data is processed in the United States. We use Standard Contract Clauses for data transfers and appropriate security measures. This policy is based on U.S. law (FTC, CCPA). Additional local protections may apply.
If we change this policy, we will post the updated policy in the Catalyst app, email you notice of material changes, and explain what changed and why.
Privacy Questions: privacy@catalystgoals.com (response within 30 days)
Legal Inquiries: legal@catalystgoals.com