Legal
The short version: Navigate is designed to keep your data on your device wherever possible. No account is required to use the core tools, and usage tracking is off by default. This page explains exactly what is stored, where, and why.
Navigate is operated by Dr Richard Pomfret, Therapy on the Hill. Data controller for UK GDPR purposes.
The majority of Navigate's state is stored in your browser's localStorage and sessionStorage. This data never leaves your device unless you explicitly enable a feature that sends it.
All local keys use the anima- prefix. You can clear all local data at any time via Settings → Delete my data, or through your browser's site data settings.
Analytics are disabled by default. You can turn them on in Settings.
If you enable analytics:
If you later disable analytics, the device ID is deleted from your device and no further data is sent. Previously collected anonymous data is retained per the retention schedule below.
Lawful basis: Consent.
If you submit feedback through the app, your message and basic context (feedback type, approximate session state) are stored in our Supabase database. No name or email is attached unless you choose to include them in the message.
Please do not include sensitive personal information in feedback messages.
Lawful basis: Legitimate interest (product improvement).
If you purchase Navigate Plus, Clinician Pro, or any paid tier:
Purchase data is retained for the duration of your active subscription plus six years, to meet UK financial record-keeping requirements.
Lawful basis: Contract performance.
If you join the beta list from the landing page, your email address is stored in Supabase so we can send you occasional updates about Navigate.
This is entirely optional. You can unsubscribe at any time:
Lawful basis: Consent.
Navigate Plus includes optional AI-assisted journal reflections and a companion chat. These features are powered by Google Gemini.
When you use an AI feature, Navigate sends the following to our server-side proxy (/api/gemini), which forwards it to Google:
The Gemini API key is never exposed to your browser — all requests go through our server. Google's data handling is governed by the Gemini API terms.
Please do not include sensitive personal information — names of other people, clinical history, or identifying details — in AI feature inputs.
Lawful basis: Consent (via use of the feature).
Navigate uses the following sub-processors. Only the data described is shared with each.
| Provider | Purpose | Data shared | Privacy policy |
|---|---|---|---|
| Supabase | Database & auth | Feedback, analytics events (opt-in), purchases, beta leads | supabase.com/privacy |
| Stripe | Payment processing | Email, payment method, purchase amount | stripe.com/privacy |
| Vercel | Hosting & serverless | Request metadata, error logs | vercel.com/legal/privacy-policy |
| Google Gemini | AI reflections (optional) | User-provided text prompts | ai.google.dev/terms |
| Sentry | Error monitoring | Stack traces, browser/OS version, anonymised user context | sentry.io/privacy |
| Data | Retained for |
|---|---|
| Local browser storage | Until you clear it or use Settings → Delete my data |
| Anonymous analytics events | 30 days |
| Aggregated daily statistics | 24 months (non-identifying) |
| Feedback submissions | 12 months |
| Purchases & subscription records | Duration of subscription + 6 years |
| Beta mailing list | Until you unsubscribe |
If Navigate processes any personal data about you, you have the following rights:
To exercise any of these rights, contact us using the details below. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
You can delete all locally stored data immediately via Settings → Delete my data in the app, or by clearing site data for navigateregulation.com in your browser settings.
Contact us and we will delete your data within 30 days.
Navigate is operated by Dr Richard Pomfret, Therapy on the Hill.
For questions about this notice, data requests, or to report a privacy concern, please get in touch.