Privacy Policy
Last updated: June 2026
CalmBody ("we," "our," or "us") is committed to protecting your privacy. This policy explains what information we collect, how we use it, and your rights regarding your data.
1. Information We Collect
When you use CalmBody, we collect:
- Account information — your name, email address, job title, and profile details you provide
- Wellness check-in responses — your daily mood, energy, and mindset ratings
- Survey responses — your answers to team surveys (stored anonymously in aggregated results)
- Messages — direct messages and group chat content you send within the app
- Gratitude and shout-out entries — content you choose to submit
- Suggestion box submissions — submitted anonymously or with your name, per your choice
- Usage data — app activity such as check-in streaks and Thrive Points
2. How We Use Your Information
We use your information to:
- Provide and operate the CalmBody app and its features
- Show you your personal wellness history, streaks, and Thrive Points
- Display team shout-outs and gratitude posts to your colleagues
- Deliver messages between team members
- Generate anonymized, aggregated wellness trends for your organization's leadership
- Send you app invitations and account-related emails
3. What Leaders Can and Cannot See
CalmBody is built with a privacy-first approach for staff:
- Organization admins can see anonymized, aggregated team wellness trends — not individual responses
- Survey results are hidden until a minimum number of team members have responded, protecting individual privacy
- Check-in responses are never visible to managers or admins on an individual level
- Suggestion box submissions marked anonymous are never linked to your identity in any admin view
4. Data Sharing
We do not sell your personal information. We share data only with:
- Supabase — our database and authentication provider, which stores your data securely
- Your organization — only anonymized, aggregated trends as described above
- Law enforcement — only if required by law or to protect safety
5. Data Security
Your data is stored securely using Supabase, which provides encryption at rest and in transit, row-level security policies, and SOC 2 compliant infrastructure. Access to individual data is restricted by role-based permissions enforced at the database level.
6. Data Retention
We retain your data for as long as your account is active. If your account is deactivated by your organization, your data remains in our system for 90 days before being permanently deleted. You may request deletion at any time by contacting us.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and data
- Opt out of non-essential communications
To exercise any of these rights, contact us at the email below.
8. Children's Privacy
CalmBody is intended for use by adults (18+) in professional settings. We do not knowingly collect data from anyone under 18.
9. Changes to This Policy
We may update this privacy policy from time to time. We will notify users of significant changes via the app or email. Continued use of CalmBody after changes constitutes acceptance of the updated policy.
10. Contact Us