Privacy Policy
Effective 18 July 2026 · Last updated 18 July 2026
1. Who we are
Commense is a personal dashboard for tracking habits, mood, and money.
This service is operated by Commense App (ABN 85 703 121 204), based in Australia (“we”, “us”, “our”). We are the data controller for the information described below.
Contact: privacy@commense.app
2. What we collect
We collect only what the app needs to work. We do not buy data about you, and we do not build advertising profiles.
Information you give us
| Data | Examples |
|---|---|
| Account | Name, email address, password (stored hashed — we never see it) |
| Settings | Language, currency, time zone, financial-year region |
| Habits & goals | Goal names, targets, frequencies, completion logs |
| Mood | Mood ratings and any notes you add |
| Cycle tracking | Menstrual cycle start dates and the predictions calculated from them |
| Other metrics | Anything else you choose to track (sleep, water, weight, custom metrics) |
| Financial data | Transactions you import from a bank CSV — dates, descriptions, amounts, and the categories you assign; net-worth figures you enter; bills and subscriptions |
| Images | Any pictures you upload to an image widget |
| Support | Anything you send us by email |
Information collected automatically
| Data | Purpose |
|---|---|
| Usage analytics | Which features are used, aggregated — to improve the product |
| Error reports | Technical details when something breaks, so we can fix it |
| Basic log data | IP address, browser type, timestamps — standard server logs |
What we do not collect
- We have no access to your bank. There is no bank-sync connection. You export a CSV yourself and choose what to import. We never hold your banking credentials.
- We never see your card details. If and when we introduce paid plans, payments will be handled entirely by our payment provider (see §5).
3. Why we use it, and our legal basis
We’re an Australian business, so the Privacy Act 1988 and the Australian Privacy Principles govern how we handle your information.
“Legal basis” is a GDPR concept rather than an Australian one. Because anyone can sign up from anywhere, GDPR also applies to us for people in the UK or EU — so for transparency, here is the basis we rely on for each purpose:
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Providing the app, your account, and your dashboard | Performance of a contract |
| Storing and displaying the data you log | Performance of a contract |
| Mood and cycle tracking | Your consent — see §4 |
| AI categorisation of transactions (optional) | Your consent — see §4 |
| Processing payments and subscriptions (when paid plans are introduced) | Performance of a contract |
| Security, fraud prevention, fixing bugs | Legitimate interests |
| Product analytics (aggregated) | Legitimate interests |
| Marketing emails | Your consent — withdrawable at any time |
Where we rely on consent, you can withdraw it at any time without affecting the rest of the service.
4. Two things that deserve their own section
Health-related data (mood and cycle)
Two optional features can involve health data: mood tracking, and cycle tracking (menstrual cycle dates and the predictions we calculate from them). Neither is part of your dashboard unless you choose to add it — using them is your decision.
Because mood, and especially menstrual/reproductive information, may be treated as health data under GDPR — which carries additional protection, and which we know is deeply personal — we handle it with particular care:
- It is never shared, never sold, and never used for advertising or profiling.
- It is never sent to the AI feature described below.
- It is stored with the same private, per-user, database-enforced isolation as the rest of your data (§7), and we disclose it to no one except the infrastructure providers needed to store it securely (§5).
- You can remove these trackers and delete all associated data at any time, without losing access to anything else.
AI categorisation of transactions (optional)
If you turn on AI categorisation, the transaction description (the merchant text) is sent to Anthropic’s API to suggest a category. This happens on our server, never from your browser.
- It is off by default and entirely optional. The manual categorisation and rules engine do the same job without it.
- We send only the merchant description — the short text that identifies where a transaction is from. We do not send the amount, your name, your email, or any account identifiers.
- Anthropic processes this to return a category and, under their commercial API terms, does not use it to train their models.
- Your mood, habits, and health-adjacent data are never sent to the AI.
If you would rather no data ever left our systems for this purpose, simply leave the feature off.
5. Who we share it with
We do not sell your personal information. We share it only with the service providers who make the app work:
| Provider | What they handle | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | Northeast Asia (Tokyo, Japan) |
| Vercel | Application hosting | Global CDN |
| Anthropic | AI categorisation — only if you enable it (§4) | US |
| PostHog | Aggregated product analytics and error reports | US |
If and when the relevant features launch, we will also use:
| Provider | What they handle | Where |
|---|---|---|
| Lemon Squeezy | Payments, subscriptions, invoicing (merchant of record) — when paid plans are introduced | US/Global |
| Resend | Delivery of account emails (e.g. password resets) — when enabled | US/Global |
| Mailchimp | Mailing list — only if you subscribe | US |
Each provider is bound by their own data-processing terms and may only use the data to provide their service to us. We may also disclose information where we’re legally required to, or to protect someone’s safety or our legal rights.
Where your data lives
Your account, habits, mood, financial data, and images are stored in Japan (Tokyo). Other providers listed above operate from the United States.
We are based in Australia, so your data is held outside Australia. Where data originates in or moves out of the UK/EEA, transfers rely on appropriate safeguards — including, for Japan, the European Commission’s adequacy decision, and Standard Contractual Clauses where a provider requires them.
6. How long we keep it
| Data | Retention |
|---|---|
| Your logged data (habits, mood, transactions) | Until you delete it, or your account is deleted |
| Account details | For the life of your account |
| Backups | Up to 30 days, then purged on rotation |
| Analytics & error reports | Up to 12 months |
| Basic server logs | About 30 days |
| Payment records (once paid plans exist) | As required by Australian tax law (generally 5 years) |
When you delete your account, your data is deleted from our live systems promptly and cycles out of backups within 30 days.
7. How we protect it
- Row-level security. Every table in our database enforces, at the database level, that you can only ever read or write your own rows. This is not just application logic — the database itself refuses to return anyone else’s data.
- Encryption in transit and at rest.
- Passwords are hashed. We cannot see them, and neither can anyone else.
- No card data touches our systems.
- Access to production data is limited to what’s necessary to operate and support the service.
No system is perfectly secure, but the data you keep here is sensitive and we treat it that way.
8. Images on your dashboard
Any images you upload to an image widget are stored in private cloud storage (Supabase Storage, Tokyo, Japan).
- The storage is not publicly accessible. There is no public link to your files.
- Images are served to you through short-lived, signed URLs that expire — not a permanent public address.
- Access is scoped to your account. Other users cannot retrieve your images, and neither can anyone without a valid signed link.
- Deleting an image from your dashboard deletes the underlying file.
We do not scan, analyse, or use your images for any purpose. They are not sent to the AI feature described in §4.
9. Your rights
You can, at any time:
- Access the data we hold about you
- Correct anything inaccurate
- Delete your account and your data
- Export your data in a portable format
- Restrict or object to certain processing
- Withdraw consent for mood tracking, cycle tracking, AI categorisation, or marketing
Most of this you can do yourself in the app. For anything else, email privacy@commense.app and we’ll respond within 30 days.
Complaints
If you’re unhappy with how we’ve handled your data, please tell us first — we’d rather fix it. You also have the right to complain to a regulator:
- Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au
- UK/EU: your local supervisory authority
10. Cookies and analytics
- Essential cookies — to keep you signed in. These can’t be turned off without breaking the app.
- Analytics — aggregated, to see which features people use. Our analytics (PostHog) is configured not to use advertising cookies.
We do not use advertising cookies or third-party tracking pixels. We do not sell your data to advertisers.
11. Children
Commense is not intended for anyone under 16, and we don’t knowingly collect data from them. If you believe a child has given us information, contact us and we’ll delete it.
12. Changes to this policy
If we change this policy in a way that materially affects you, we’ll email you before it takes effect. Otherwise we’ll update the date at the top.
13. Contact
Commense App
ABN 85 703 121 204
privacy@commense.app
commense.app
← Back to Commense