HG Loop
Privacy
Last updated [DATE THIS IS PUBLISHED].
HG Loop records what you did each day and turns your week into one deliberate decision. Doing that means holding some personal data about you. This page says exactly what, why, who else sees it, and how to get it back or get rid of it.
It is written to be read rather than to cover us. If anything here is unclear, ask, and we will fix the wording rather than explain it once.
Who is responsible
Hagen Growth is the data controller for everything described here.
[LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COMPANY REGISTRATION NUMBER]. Questions and requests: [PRIVACY CONTACT EMAIL].
What we hold
Your email address. It is how you sign in and where reminders go. It is the only thing we ask for that identifies you, and we never ask for your name.
Your settings: timezone, which day your week starts, the date you joined, whether reminders are on and at what hour.
What you decided to practice: the behaviors you set up, their schedules, your usual and minimum versions, when in the day you meant to do them, and how you planned to return after a miss.
What happened: for each scheduled day, what you recorded - as planned, a minimum version, less or more than planned, a miss, a day taken off, or that you could not remember. Days you never answered stay empty rather than counting as anything.
Anything you wrote: notes on a day or a behavior, what you said usually breaks your consistency, and the direction you said you were heading.
Your answers to the daily questions, on their one-to-five scales. These ask how the day felt, how much you trusted yourself, and how you slept - which over months could say something about how you are doing generally. They are optional: you choose which to switch on when you set up, you can turn any of them off at any time, and you can skip any of them on any day without it counting as anything.
Your weekly reviews: the observations, what you made of each one, the decision you chose, and whether you said the review was useful.
Technical: a session cookie that keeps you signed in. If bot protection is switched on, Cloudflare receives your IP address when you use the sign-in form.
Why we hold it, and on what basis
To run the app for you - recording days, building your weekly review, keeping your streak. This is necessary to provide what you signed up for (GDPR Article 6(1)(b)).
To send reminder emails, if you have them on. Part of the service you asked for, switchable off in settings or from the link at the foot of every reminder.
To have part of your weekly review written with AI. The review is what HG Loop is for, so this is part of providing it rather than an extra we ask permission for (Article 6(1)(b)) - but you can switch it off in settings anyway, and the review still works without it.
To keep the sign-in form from being used to send mail to strangers in bulk, where bot protection is switched on. Our legitimate interest in not having our service abused (Article 6(1)(f)).
Reviews written with AI
If you leave this on, your week's counts and anything you wrote are sent to Anthropic, which writes the observations and questions in your weekly review. Your email address is never sent, and nothing in what we send identifies you.
Nothing is sent until the week is finished and you have answered for the days it covers. Everything that comes back is checked against your actual records before you see it.
Anthropic deletes what we send within 30 days, except where something has been flagged by their safety systems or they are legally required to keep it. Their terms forbid training any model on it.
You can turn this off in settings. With it off, your review is built from your records alone - the same counts, the same streak, the same decision, with fewer sentences. Reviews already written stay as they were.
Who else processes it
We do not sell your data, and nobody gets it for advertising. These are the companies that handle it in order to run the service, each under a data-processing agreement:
Neon - the database, hosted in Frankfurt.
Render - runs the application itself, in Frankfurt.
Anthropic - writes the weekly review, only if you allowed it. Processed in the United States.
Resend - sends your sign-in links and reminders. Processed in the United States.
Cloudflare - bot protection on the sign-in form, where switched on. Receives your IP address.
Some of these process data outside the EU. Where they do, the transfer rests on the safeguards the GDPR provides for it - the European Commission's standard contractual clauses, or the EU-US Data Privacy Framework where the company is certified under it. Each one is named in our record of processors, which we will show you if you ask.
How long we keep it
Your records stay until you delete them or delete your account. Nothing expires on its own, because a habit record is only worth having if it goes back far enough to show you something.
Sign-in links expire shortly after they are sent and stop working once used. Sessions expire after 30 days.
When you delete your account it goes immediately and completely from the app. Our database keeps an automatic change history for 7 days so we can recover from technical faults, and your data is fully gone once that week has passed. Nothing in that history is read, used or restored in the meantime except to recover the service from a fault. We cannot shorten the window for one account, and we would rather say so than imply otherwise.
What you can do
Get a copy. Settings gives you every record we hold about you as a single file, including everything you wrote, at any time and without asking us.
Correct it. Everything you entered can be edited in the app.
Delete it. Settings deletes your account and everything in it. There is no undo, and the 7 days above is the only qualification.
Object, or withdraw a permission. Turning off AI reviews or reminders takes effect immediately and needs no explanation.
Complain. If you think we have handled your data badly, tell us at [PRIVACY CONTACT EMAIL] - and you can complain to Datatilsynet, the Danish Data Protection Agency, at datatilsynet.dk, whatever we say.
Decisions about you
Nothing here decides anything about you. The weekly review describes what you recorded and asks questions about it; it does not score you, rank you, or produce a judgment that affects you in any way with legal or similar consequences. There is no automated decision-making in the sense of Article 22, and no profiling for any purpose outside the app.
The review may suggest a reason something happened. When it does it says so as a suggestion, and everything it says is checked against your actual records before you see it. You can mark any observation as not fitting, and that disagreement is kept rather than discarded.
Keeping it safe
Everything travels over an encrypted connection and is stored in a managed database in Frankfurt. Sign-in links and session tokens are stored only as hashes, so a copy of our database is not a way into anyone's account. Access to production data is limited to those who need it to run the service.
No system is perfect. If something happens to your data that puts you at risk, we will tell you, rather than waiting to see whether you notice.
Age
HG Loop is not intended for children, and we do not knowingly collect anything from anyone under 16. If you believe a child has an account, write to us and we will remove it.
Cookies
One cookie, which keeps you signed in. It is not used to track you, it is not shared, and there is nothing to consent to because the app cannot work without it.
There is no analytics, no advertising and no third-party tracking anywhere in HG Loop.
Changes
If this page changes in a way that affects you, we will say so by email rather than quietly updating the date at the top.