Legal
Privacy Policy
Effective date: May 1, 2026
TryConnection ("we," "our," or "us") is a recovery support tool — not a surveillance platform. This policy explains what data we collect, why we collect it, and how we protect it. We do not sell your data. We do not run advertising. Everything we collect exists to help you build the capacity to heal.
1. What we collect and why
A. Data stored locally on your device
The Chrome extension stores the following in your browser's local storage. This data never leaves your device unless you explicitly use a feature that sends it (such as AI coaching or event sync).
- Your profile — name, recovery orientation, challenges, vulnerability patterns, trigger context, and filter preferences. Used to personalize Sam's coaching.
- Behavioral signals — a rolling 200-entry log of extension activity (e.g., intervention shown, urge surfed, partner notified). Used for pattern analysis and the Learning Report.
- Urge sessions — up to 100 session summaries from conversations with Sam. Used to surface patterns over time.
- Journal entries — up to 20 post-slip journal entries with AI-generated pattern notes. Stored locally only.
- Social check-ins — up to 30 entries from the social media pause card. Used for pattern tracking and Sam's context.
- Browsing log — a 7-day rolling log of domains visited while the extension is active (domain name, page title, visit duration, category). Used for the daily Learning Report. Not written during monitoring-pause windows. Never shared with partners.
- App usage days — a count of unique calendar days you've used the extension. Used to trigger milestone check-in emails sent to your own email address.
B. Data stored in your browser's sync storage
Chrome sync storage may be synced across your devices by Google if you are signed into Chrome. We store:
- Name and email address — used to send coaching session emails and milestone messages.
- Partner information — name, email, and relationship of up to three support people you designate. Used only to send partner notification emails that you initiate or that are triggered by your activity.
- Extension settings — block list, content filters, monitoring preferences, and safety-net sensitivity. Used to configure the extension's behavior.
C. Data sent to our servers
We operate a backend on Vercel ("tryconnection.app") and a database on Supabase. The following data is transmitted to our servers:
- Email address and device identifier — a randomly generated ID that persists per device. Used to associate events across devices and prevent duplicate records.
- Behavioral events — a structured log of event types (e.g., domain visited, urge session started, social check-in completed) along with timestamps, categories, and severity levels. Used to power cross-device sync and future dashboard features. No browsing content, page titles, or full URLs are included — only domain names and behavioral metadata.
- Onboarding submission — name, email, challenges, and orientation from the website sign-up flow. Stored in our database and used to pre-configure the extension.
D. AI coaching conversations
When you talk with Sam, your messages are sent through our server proxy to Anthropic's Claude API. Conversations are processed in real time to generate Sam's response. We do not store conversation transcripts on our servers. Anthropic may retain API request data subject to their own privacy policy.
Your user context (name, orientation, recent signals, recovery patterns) is included in each API request so Sam can respond to your specific situation. This context is assembled from locally stored data and transmitted only at the moment of the conversation.
E. Partner notification emails
When you trigger a partner notification — or when certain configured events occur — we send an email to the support people you have designated. These emails are sent via Resend from hello@tryconnection.app. They describe the general nature of the event (e.g., "[Name] is working through something difficult right now") but do not include browsing history, specific content accessed, or journal entries.
You control which events trigger partner notifications. Partners are only notified when you have explicitly set up that behavior in the extension.
2. What we do not collect
- We do not collect the content of web pages you visit.
- We do not collect search query text.
- We do not collect passwords, form inputs, or financial information.
- We do not use advertising networks or analytics trackers.
- We do not sell, rent, or trade your data to any third party.
- We do not share behavioral data with your support partners — only the notification emails you have configured.
3. Third-party services
TryConnection uses the following third-party services to operate:
- Anthropic — AI model provider. Coaching conversations are processed via their API. See anthropic.com/privacy.
- Supabase — database and backend infrastructure. Data is stored in US-East AWS regions. See supabase.com/privacy.
- Vercel — hosting for the marketing site and API. See vercel.com/legal/privacy-policy.
- Resend — transactional email delivery. See resend.com/legal/privacy-policy.
4. Data retention
- Local device data — retained until you uninstall the extension or clear storage manually.
- Behavioral events (Supabase) — retained for up to 12 months, then deleted automatically.
- Onboarding submissions — retained indefinitely unless you request deletion.
- Coaching conversations — not stored by us. Subject to Anthropic's retention policy.
5. Your rights and choices
- Access — you can view all locally stored data by opening the extension's DevTools console.
- Deletion — you can clear local data by uninstalling the extension. To request deletion of server-side data (Supabase records), email us at the address below.
- Opt out of partner notifications — you can remove all partners from Settings at any time.
- Opt out of sync — cross-device sync requires your email to be set in the extension. Removing your email from extension settings will stop future sync events from being sent.
6. Security
All data transmitted between the extension and our servers is encrypted via HTTPS. Our API endpoints require a shared secret header that is not exposed to third parties. Supabase access is gated by a service role key stored as a server-side environment variable only.
No security system is perfect. We recommend not entering sensitive personal information (beyond your name and recovery context) in coaching conversations.
7. Children
TryConnection is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child has submitted personal data to us, contact us and we will delete it.
8. Changes to this policy
We may update this policy as the product evolves. We will post the new effective date at the top of this page. Material changes will be announced via the extension or by email if we have your address.
9. Contact
Questions, deletion requests, or anything else — reach us at: hello@tryconnection.app
TryConnection