← Palaestra

Privacy Policy

Last updated: March 21, 2026

Palaestra is a judgment training system for founders. Your decision data is the core of the product — it’s how the system learns your patterns and helps you improve. This policy explains exactly what we collect, why, and what we will never do with it.

We do not sell your data to third parties. Ever.

We do not share your data with advertisers.

We do not use your data to train AI models.

Your reflections, decisions, and Ledger entries are encrypted before they leave your device. They are stored in encrypted form on our servers. We cannot read them. When you request an AI Judgment Report, your device decrypts the data temporarily and sends it to our analysis system, which processes it and discards the input. At no point is your unencrypted text stored on our servers or accessible to Palaestra staff.

We do not track your location, contacts, or any data outside the app.

What We Collect

DataWhat It IncludesWhy
Trial decisionsWhich option you chose, how long you hesitated, whether your choice matched the historical outcomeTo compute your accuracy patterns across decision domains
ReflectionsThe text you write in response to decision scenariosTo identify recurring patterns in your decision psychology
Ledger entriesReal-life decisions you log, your conviction score, temperature, pressure tags, expected outcome, domain, and settlement outcome after 90 daysTo assess your conviction calibration over time
Decision patternsStatistical analysis of your accuracy across domains and cognitive trapsTo generate your Judgment Report and adapt your training
Protocol answersYour responses to guided Decision Protocol questionsTo structure your thinking and create documented, pre-registered decisions
Account infoDisplay name, email address, identity selectionAuthentication and personalization

How Your Data Is Protected

Sensitive text — your reflections, Ledger entries, and protocol answers — is encrypted using AES-256-GCM before it reaches our servers. Even in a worst-case database breach, an attacker would get ciphertext, not your actual decisions and fears.

Your data is stored on Supabase (US data center) with row-level security ensuring that only your authenticated session can access your records. Authentication tokens are stored in your device’s secure enclave, not in general app storage.

Third-Party Services

ServiceWhat It ReceivesPurpose
SupabaseAccount info, encrypted decisions and reflectionsAuthentication and data storage
RevenueCatAnonymous purchase eventsSubscription management
PostHogAnonymous event counts only — no personal text, no reflections, no decisionsUsage analytics
Apple / GoogleStandard app store analyticsApp distribution

No other third parties receive any data. We do not use advertising SDKs, tracking pixels, or data brokers.

Data Retention

Your data is retained as long as your account is active. If you cancel your premium subscription, your data remains — the free tier continues working with your accumulated history.

If you delete your account, all data is permanently and irreversibly removed from all systems within 30 days. This includes decisions, reflections, Ledger entries, protocol answers, and your profile. Deletion is real. We do not soft-delete or deactivate.

Your Rights

You can export all your data at any time. The “Download Your Data” option in the app produces a complete JSON file containing every decision, reflection, Ledger entry, and protocol answer associated with your account.

You can delete your account at any time from the Profile screen. Deletion is permanent and cannot be reversed.

If you are in the EU, you have additional rights under GDPR including the right to access, rectify, restrict processing, and lodge a complaint with your local data protection authority. If you are in California, you have rights under CCPA including the right to know, delete, and opt out of the sale of personal information (we never sell personal information).

Analytics

We use PostHog in privacy-first mode. Autocapture is disabled. We receive only explicitly defined events: event type, timestamp, numeric identifiers, and categorical values (like decision domain or trap tag). We never receive the text of your reflections, decisions, or protocol answers through analytics.

Children

Palaestra is designed for adult founders and business operators. We do not knowingly collect data from anyone under the age of 16. If you believe a child has provided us with data, contact us and we will delete it immediately.

Changes to This Policy

If we make material changes, we will notify you through the app before the changes take effect. Continued use after notification constitutes acceptance.

Contact

Questions about your data? Email privacy@getpalaestra.com

© 2026 Palaestra · Terms · FAQ · Contact