Experiment
policy · plain terms

Privacy

You write down honest things about your own life here — how you slept, what you didn't manage, what you noticed. That deserves a policy you can actually read, so this one says what is collected, exactly who else sees it, and how to delete all of it.

last updated 26 July 2026

The short version

  • 01Your experiments, check-ins, notes and attachments are private to your account by default. Other people see them only if you publish an insight, and publishing is per-item and reversible.
  • 02There are no ads, no analytics and no third-party trackers in this app.
  • 03If you agree to it, your writing is sent to Anthropic's Claude API to power the Designer, the Consent Gate and your reports — that's the one place your words leave our own infrastructure as a matter of routine. You're asked first, and saying no keeps every feature.
  • 04You can delete your account, and everything in it, from inside the app at any time.

Who is responsible

EXPERIMENT is the data controller for the information described here. For anything on this page — access, correction, deletion, a complaint — write to hello@experimentmag.com. If you are in the UK or EU and you aren't satisfied with the response, you can complain to your national data protection authority (in the UK, the ICO).

What is collected

Account. Your email address, a password (stored hashed by our auth provider — never in readable form), and the display name you choose.

Your experiments. The question, hypothesis, measures and duration you design, the record of your consent to run it, and everything you log: daily check-in values, written reflections, and whether you did or didn't do the thing that day.

Attachments. Photos, short video, voice notes and data files you attach to a check-in. These are stored in a private bucket, scoped to your account, and served to you through short-lived signed links. Nobody else can address them.

Health and wellbeing information. Much of what you track — sleep, mood, energy, food, exercise, symptoms — counts as health data under UK/EU law, and is treated as such. It is collected on the basis of your explicit consent, given at the Consent & Risk Gate before each experiment runs, and you can withdraw that consent by deleting the experiment or your account.

Pulse answers. The occasional one-tap questions you answer, kept longitudinally so the app can suggest experiments. Everything gathered, and exactly how a suggestion was derived, is shown to you under You.

Things you choose to share. Published insights, reactions, your public profile, and joining a study. Publishing is always an explicit act, can be done anonymously, and can be withdrawn.

Notifications. If you turn on push, the browser gives us a push endpoint and its keys, which we store so a nudge can reach you. Turning push off removes it.

Reminder times and your timezone. An experiment can carry reminders — times you chose when you designed it, like half an hour before a bedtime you're trying to keep. To fire those on your own clock we store the times against that experiment, along with the timezone your browser reports, and a record of which reminder was sent on which day so you don't get the same one twice. The timezone comes from your device, never from your IP address, and is used for nothing else. Reminders are sent as push notifications only — never by email — and you can switch them off for every experiment at once under Notifications, or change and delete individual times on the experiment itself.

Moderation. Text you publish to the Feed is screened before it appears — by pattern rules and by our AI provider — and if you report something or block someone, that record is kept. This screening is the one thing that runs whether or not the AI setting above is on, because it protects the people who would read the post rather than serving you a feature; it applies only to the words you choose to publish. Your private check-ins are never screened, ever. People you have blocked are not told, and can't see your block list.

No advertising identifiers, no location tracking, no contact-list access, and no third-party analytics or advertising SDKs are used.

Who else sees it

Anthropic (Claude API) — the Experiment Designer, the Consent & Risk Gate, your reports and the Reflect function are generated by Claude. To do that, the relevant content — your design conversation, your check-in notes and measures, your own written conclusions — is sent to Anthropic's API. It is not used to train models. This only happens if you agree to it. You're asked before the first time, and you can switch it off (or back on) whenever you like under You. With it off, all four of those surfaces still work — they're composed from your own data on our own servers instead.

Supabase — the database, authentication and file storage behind the app, and the sender of account emails (sign-up confirmation, password reset).

Vercel — hosting. Standard server logs (IP address, user agent, requested path) are produced as a by-product of serving the site.

Push services — when you enable notifications, delivery goes through the push service your browser or device uses (Google, Apple or Mozilla). They see the notification payload in transit.

Sponsors of sponsored experiments only. If — and only if — you join an experiment marked Sponsored and agree to its data terms at the bright line shown before you join, that sponsor receives the results of that experiment. Wearable data is never shared with a sponsor, and your other experiments, your logs and your identity are not part of it. Sponsored items are labelled as such wherever they appear.

Other participants — statistics only. When you join a study, your raw logs never leave your account. Contributions are combined by a database function that returns aggregate statistics only, and stays locked until enough people have joined that an aggregate can't identify anyone.

Nothing is sold, and nothing is shared for advertising. Data may also be disclosed where the law requires it.

How long it's kept

Your content is kept until you delete it or delete your account. Deleting an experiment removes its check-ins, attachments, consent record and report immediately. Deleting your account removes everything, including the account itself — see Delete your account. Encrypted backups roll off within 30 days of deletion.

Three things survive deletion, and it's worth being straight about them: aggregate study statistics already computed; sponsored-experiment results already delivered under a consent you gave at the time; and reports you filed about someone else's content, which stay open with your identity stripped off them, because the thing you reported is still there and still needs acting on. None of the three identifies you, and the first two can't be recalled from a recipient after the fact.

Your rights

You can ask for a copy of your data, ask for it to be corrected, withdraw consent, or have it erased. Erasure is built into the app and needs no correspondence: use Delete your account. For anything else, email hello@experimentmag.com and expect a reply within 30 days.

Security, transfers and age

Everything travels over HTTPS. Your rows are protected by row-level security at the database, so one account cannot read another's, and attachments sit in a private bucket reachable only through signed links scoped to you.

Our processors operate in the UK, EU and United States, so data may be transferred and processed outside your country under the standard contractual protections those providers offer.

EXPERIMENT is for adults. It isn't directed at children, and accounts are not knowingly created for under-18s. If you believe a minor has an account here, email hello@experimentmag.com and it will be removed.

Changes

If this policy changes in a way that affects what is collected or who receives it, the date at the top changes and you'll be told in the app before the change takes effect.