Privacy

What we collect, and how to check.

A product about owning your own data has to be able to survive its own privacy policy. Here is everything, in plain language, and a way to verify it without trusting us.

The short version

This site sets no cookies, embeds no third-party trackers, and loads nothing from any other company. There is no advertising network here, and nothing about your visit is sold, shared or brokered. Not as a policy we promise to keep. As a thing you can watch not happening.

We do count two things on the marketing pages, and we would rather say so than be caught at it: how many times a page was opened, and which named buttons were pressed. That request goes to this domain and nowhere else. The database it lands in has no column for an IP address, a device, a browser string, or a full web address, so those cannot be recorded even by accident. What is stored is the page path, the name of the button, the country your connection resolves to, and a random identifier your browser made up for itself. No scroll tracking, no session recording, no profile, and nothing that follows you to another site. Automated browsers are not counted at all, so our own test runs never appear as visits.

How to check that yourself

Open your browser's developer tools, switch to the Network tab, and reload any page on this site. Every request goes to this domain, and there is no other company in the list. On the homepage you will see one request to /api/track: that is the counting described above, and you can read exactly what it sent. Then open the Application or Storage tab. There are no cookies. Local storage holds cnt.anon, the random identifier this browser made up for itself: delete it and a new one is made, and nothing is lost. If you have used the composer or the app, it also holds cnt.shares (the tokens that let you END a view you shared, which is the only thing that proves the share is yours), cnt.vault.v1 (your file, encrypted) with its cnt.vault.meta.v1 record count, cnt.passkey.v1 if you set up a passkey, and cnt.passkey.declined if you turned that offer down — a single flag, and the only thing stopping us asking you again. Every one of those is yours, none of them is sent anywhere, and deleting them deletes what they hold rather than hiding it: delete that last one and the passkey offer comes back on your next unlock.

The intake tool sends nothing. Once the page has loaded it makes no network request at all. Not fewer. None. Watch the Network tab while you use it: your records never leave the tab they were typed into.

The composer is the same until you ask it to share. Composing, editing and sealing happen with no request of any kind. Pressing Create the link makes exactly one: it uploads the encrypted view, and beside it five things we can read, because holding the view for you needs them — the label you typed, the kind of view it is, how long the link should last, the access code if you set one, and a random token your browser invented so that it, and only it, can end the share. The key that opens the view is not among them. It stays in your browser and travels only in the part of the link after the #, which browsers never send to a server, so what reaches us is a box we do not have the key to. Pressing End this share makes one more, which deletes those bytes. You can watch both happen, and you can read what they contained — that list is the whole list.

This matters most on the intake tool, where you might type real details about your life. That page does its encryption in your browser and sends nothing anywhere. You can watch the Network tab stay silent while you use it.

What we collect when you sign up

If you enter your email, and optionally your first name, we receive those two things and nothing else. They are emailed to us so we can contact you about Continuum. We do not have a marketing list, we do not run drip campaigns, and we do not pass your address to anyone.

Our email is sent through Resend, which processes the message on our behalf. Our site is hosted by Netlify, which like every web host keeps standard server logs including IP addresses for a limited period. Those two companies are our only processors.

What we do not collect

The product preview

The preview uses a fictional person and says so on every screen. It writes nothing to storage and makes no network requests while you use it. Close the tab and it is gone.

Your choices

Email us at privacy@reddenda.com and we will tell you everything we hold about you, correct it, or delete it. Because the only thing we hold is an email address you gave us, that is a short conversation. We will complete a deletion within 45 days and usually the same week.

Your browser's Global Privacy Control signal is honoured by default, because there is no sale or sharing of personal information here to opt out of.

Children

Continuum is for adults. Do not use this site or create a file if you are under 18.

When this changes

Continuum is being built. When the product stores your file, syncs to other services or introduces accounts, this page will change before that ships, not after, and the date at the top will say so. Material changes will be emailed to anyone who has given us an address.

We have missed that order once and will not pretend otherwise: the composer began uploading encrypted views to our server before this page described it, and the description above was written afterwards. That is the standard this section is held to, and the reason it is written down rather than smoothed over.

Who we are

Continuum is operated by TwinFlame Investments LLC, a Wyoming limited liability company. Reach us at privacy@reddenda.com.