SD Shade Diary
Privacy Terms Checkout Reserve

Legal

Privacy Policy

This policy explains how Shade Diary handles personal information for the public website, waitlist, access request flow, web purchase flow, and iOS app access.

Effective May 26, 2026 Company: Shade Diary, operated by Clueless Creations Contact: support@shadediary.com
Current Snapshot Notice At Collection How We Use Data Processors Your Choices Children Purchase Disclosure

Current Snapshot

Shade Diary is operated by Clueless Creations LLC. Shade Diary is a pre-dye planning product. The public site collects waitlist and access request information and, when you use the Shade Read flow at /check/, it also collects Shade your hair answers, TikTok or formula references, and your email address so your session can be connected to iOS app access. Subscription billing through Stripe (via RevenueCat) is configured for the web purchase path and becomes active when checkout is ready. PostHog product analytics is active when you use the Color Read flow.

If the product starts collecting materially different categories of data, we will update this policy before that change takes effect.

Your Hair Answers And Health-Adjacent Information

The Color Read flow at /check/ asks questions about your hair that may include hair-health details such as scalp reaction history, current irritation, chemical treatment history (bleach, henna, metallic dyes), breakage or sensitivity flags, current hair level, and target shade. This information is used solely to compute your personalized Safety Notes and full Color Read. It is not sold, used for advertising profiling, or shared except with the service providers listed below that are necessary to operate the Color Read flow.

The iOS app may let you choose hair photos, formulas, shade entries, and dye-day notes. Shade Diary should be treated as a beauty planning aid, not medical, dermatology, allergy, or professional colorist advice.

Notice At Collection

Category Examples Purpose Currently active?
Identifiers and contact details Email address, normalized email hash, consent status. Waitlist updates, purchase access, support, deletion requests. Yes, through the waitlist forms.
Pre-dye intent Shade goal, source, mode, optional note. Prioritize Color Read demand, segment product updates, improve product messaging. Yes, if you submit a form.
Hair answers and health-adjacent details Current hair level, scalp reaction history, chemical treatment history (bleach, henna, metallic dyes), breakage or sensitivity flags, gray coverage percentage, vibrancy goal, developer preference, target shade name. Compute the Safety Notes result (Soft Go / Strand Test First / Pause And Soften / Salon Zone) and generate the full Color Read; stored temporarily for your session only. Yes, when you complete the Color Read flow at /check/.
Purchase access request Selected annual or weekly plan, timestamp, referrer, user agent. Save your selected plan and route you to checkout when purchase links are ready. Yes, when you press an access request button.
Account and access data Email address (optional, for iOS redemption), anonymous app user ID (UUID stored in your browser), iOS installation UUID (generated on first app launch, stored on-device, used as the PostHog distinct_id in the iOS app — never leaves the device outside of analytics events), subscription customer ID, access status, session token. Authenticate purchase access, restore access, and connect web purchases to the iOS app. Active when you start checkout or app access. Full account features may be added later.
Commercial information Product selected, subscription status, renewal and cancellation status, processor receipt identifiers, billing-issue flags. Provide paid access, manage subscriptions, prevent fraud, support refunds. Configured for web purchases through RevenueCat and Stripe; active when checkout is ready. Apple may process in-app purchases in the iOS app.
User content Hair photos you choose, formula notes, Saved Shade Entries, Day 3 follow-up in the iOS app; TikTok URL or formula text you enter in the web Color Read flow shade-goal step. Generate and save Color Reads, shade entries, reminders, and privacy-controlled share cards. Shade-goal fields active in the web Color Read flow. Photos and saved shade entries belong in the iOS app experience.
Device, log, and diagnostic data IP-derived request data, user agent, referrer, timestamps, error logs, app diagnostics. Operate the service, secure the site, debug issues, improve reliability. Partly active through Cloudflare request handling.
Support communications Emails, requests, issue descriptions, attachments you choose to send. Answer questions, resolve access issues, process privacy requests. Active if you contact us.

How We Use Information

  • To provide the website, waitlist, access request flow, app access, and paid full Color Read features.
  • To send product updates, purchase or redemption instructions, service notices, and support replies.
  • To understand which hair-color goals, formulas, and risk moments users care about.
  • To keep safety stop conditions visible and avoid hiding high-risk warnings behind a paywall.
  • To prevent abuse, debug the Worker, protect accounts, and comply with legal obligations.
  • To improve the product experience without selling personal information or sharing it for cross-context behavioral advertising as currently configured.

Processors And Service Providers

Shade Diary uses service providers to run the product. They process data on our behalf or under their own customer terms, depending on the feature.

  • Cloudflare — website hosting, Worker runtime, request handling, temporary session storage for your hair answers and Color Read results (72-hour TTL per session), and access cache.
  • RevenueCat — configured for web purchases and active when checkout is ready. Receives your anonymous app user ID, selected plan, purchase timestamp, and access status. Manages subscription lifecycle events (purchase, renewal, cancellation, expiration, billing issues). RevenueCat processes payment card data through its Stripe integration on your behalf. See RevenueCat's Privacy Policy.
  • Stripe — configured for web purchases through secure web billing and active when checkout is ready. Receives billing details (card number, expiry, CVC, billing address) directly in an inline Stripe Elements iframe. Card numbers are never transmitted to or stored in the Shade Diary Worker. Stripe performs fraud checks and issues payment receipts under its own terms. See Stripe's Privacy Policy.
  • Supabase — not currently integrated. No Supabase SDK is loaded on this site and no data is sent to Supabase. This entry is retained as a placeholder in case account features are added in a future version.
  • Apple — App Store distribution, in-app purchases, receipts, refunds, and subscription management.
  • Resend — transactional email delivery for iOS redemption instructions sent on initial web purchase. Receives your email address only when you provide it and only to send that message.
  • PostHog — active in the web Color Read flow when you use /check/. Receives anonymized Color Read events (steps completed, Safety Notes result reached, Pro unlock shown, purchase completed). Your email is hashed with SHA-256 before being sent to PostHog — the raw email address is never transmitted as an event property. PostHog processes data under its own privacy terms.
  • Google Fonts and Higgsfield CDN — font delivery and hosted static design or marketing imagery.

Payment card numbers are handled by Stripe, not stored directly in the Shade Diary Worker or waitlist database.

Cookies, Analytics, And Advertising

The public homepage and Color Read flow load a Shade Diary analytics wrapper. It sends PostHog events only when a public PostHog key is configured; otherwise the wrapper records no PostHog events.

The Color Read flow at /check/ uses PostHog for product analytics. PostHog records which Shade Diary steps you complete, your Safety Notes verdict, whether the paywall was shown, and whether a purchase was completed. PostHog may set a first-party cookie or use localStorage to assign an anonymous session identifier. UTM parameters from the URL (utm_source, utm_medium, utm_campaign, utm_content, utm_term) are captured and associated with your session as super-properties. Your raw email address is never sent to PostHog; if you provide an email, a SHA-256 hash is used for identity stitching only. We do not use PostHog data for cross-context behavioral advertising.

The iOS app generates a random installation UUID on first launch. This UUID is stored on-device (not synced to iCloud) and used as the PostHog distinct_id for in-app analytics events. It is not linked to your Apple ID, email address, or payment identity. Uninstalling the app permanently removes this UUID from your device.

Stripe Elements sets cookies or tokens on Stripe's own domain (js.stripe.com) as part of fraud prevention and payment processing. RevenueCat may set session tokens in your browser's localStorage. These are necessary for checkout and subscription management and are not used for advertising.

Private admin tools and consumer account flows may use necessary authentication cookies or tokens. Apple may set cookies on its own domains for App Store and in-app purchase flows.

Retention

  • Hair answer session data and Color Read results — stored with a 72-hour time-to-live per session. Automatically purged 72 hours after creation. Also purged within 30 days of a verified deletion request, and within 90 days of account termination.
  • Purchase access records — retained for up to 12 months for fraud prevention and conversion analysis, then purged unless a longer period is required by law.
  • Subscription and access records — retained for the duration of the active subscription plus 7 years to meet accounting, tax, and dispute-resolution obligations.
  • Waitlist and purchase-interest records — kept until no longer needed for operations, until you ask us to delete them, or until a longer period is required for security or compliance.
  • Support communications — retained as long as needed to resolve the request, then archived for up to 3 years unless a legal obligation requires longer retention.
  • Payment processors (Stripe, RevenueCat, Apple) retain billing, refund, and tax records under their own legal and operational requirements.

Your Choices And Rights

  • Email us at support@shadediary.com to request access, correction, export, deletion, or marketing opt-out.
  • You can choose not to submit waitlist forms, access request buttons, app photos, or optional notes.
  • You can manage subscriptions through the processor that billed you, such as Apple, Stripe, or secure web checkout.
  • California residents may request to know, delete, correct, and limit certain uses of personal information. Shade Diary does not sell personal information and does not share personal information for cross-context behavioral advertising. To exercise your right to opt out of any future sale or sharing, or to submit any other California privacy request, email support@shadediary.com with "Do Not Sell or Share My Personal Information" in the subject line.
  • We do not discriminate against users for exercising privacy rights.

Security

We use reasonable technical and organizational safeguards for a small early-stage product, including limited public data collection, Cloudflare infrastructure, protected admin routes, and payment processors for card handling. No internet service can guarantee perfect security.

International Users

Shade Diary is currently built for users in the United States. If you use the site or app from another country, your information may be processed in the United States and other countries where our providers operate.

Children

Shade Diary is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 submitted information, contact us and we will delete it. Users under the age of majority should use Shade Diary only with permission from a parent or guardian.

Changes

We may update this policy as Shade Diary moves from waitlist to checkout, iOS app, subscriptions, and account features. The effective date will be updated when the policy changes materially.

Subscription Purchase Disclosure

This disclosure applies when you purchase a Shade Diary subscription through the web Color Read flow at /check/.

  • Prices: Shade Diary Pro — Annual: $59.99 per year (default); Weekly: $12.99 per week. Prices shown at checkout control and may differ from these reference prices if updated before you purchase.
  • Billing processor: secure web billing. Payment card data is entered directly into a Stripe-hosted form and is not stored by Shade Diary.
  • Auto-renewal: Subscriptions renew automatically at the end of each billing period (annually or weekly) until you cancel. The renewal charge is the same price as your initial purchase unless we notify you of a change in advance.
  • No free trial: There is no free trial. Your card is charged at the moment you confirm purchase.
  • How to cancel: Log in to the subscription portal linked in your purchase confirmation email, or email support@shadediary.com. Cancellation takes effect at the end of the current billing period. You retain access until that date.
  • Refund policy: Payments are non-refundable. Requests received within 48 hours of the first charge will be considered on a case-by-case basis. Email support@shadediary.com with your receipt to request a review. If you purchased through Apple, refund requests must go through Apple's App Store process.
Shade Diary Privacy Terms support@shadediary.com