Privacy

Last updated August 9, 2026.

Camic Health is an independent project, built and operated by Joel Sandén based in Sweden (EU). This page describes, in plain language, what data the app collects, what it's used for, who else sees it, and what to do if you want it gone. If anything here is unclear, email joel@camic.app: that's a real inbox, not a form that goes nowhere.

Interactive web app & optional integrations

The primary way to use Camic Health is our in-app web experience: every account has access to interactive in-app AI chat, guided technique sessions, mood check-ins, goal tracking, and personalized insights/reports that run directly on our servers.

Optionally, you can also use Camic Health's technique library, check-ins, and session history via an MCP connector inside external clients like Anthropic's Claude. When you use an external client like Claude, your conversation transcript happens inside that client and is governed by their privacy policy (e.g. Anthropic's Privacy Policy). What Camic Health's servers receive during an MCP tool session is limited to tool calls and execution metadata (which tool was called, whether it succeeded, how long it took, and which technique was referenced). When tools are called to save explicit artifacts (such as a mood check-in, goal, or end-of-session summary), those structured items are saved to Camic Health's database. Our servers never receive or store raw conversation transcripts from external MCP clients.

What we collect

Account. Email, and optionally a name/avatar if you sign in with Google. There's no guest/anonymous mode: every account is created via a magic sign-in link or a social login. An unused account isn't automatically deleted. It sits there until you ask us to remove it or until purged during periodic maintenance (see Retention and deletion).

Sessions. Signing in creates a session record: a session token, an expiry, and (standard for most web sessions) the IP address and browser user-agent used to sign in. This is what keeps you logged in; it's not used for tracking beyond that.

What you actually log. Mood check-ins (a 1-10 rating plus an optional note and tags), technique usage (which technique, when), saved goals (goals and progress milestones you choose to keep), and conversation summaries (a short recap written at the end of a session, not a full transcript). For an MCP session, Claude writes this recap at the end; the actual conversation happens inside Claude and never reaches our servers at all. For an in-app chat, a background worker distills the same kind of recap from the thread afterward. This is the primary data most insights are built from. In-app chat also keeps its own full message history; see the next paragraph.

AI-feature data. Every account, free or paid, can use these: cached AI-generated insights (themes, technique effectiveness, patterns), personal check-in tag suggestions, sent progress reports, your report and reminder preferences, and, unlike the session summaries above, the full message history of any in-app chat you use, stored as-is so the conversation can pick back up later.

Billing. Every account, including the free ($0) tier, has a real subscription record in Stripe: a Stripe customer ID and a mirror of your subscription (plan, status, and renewal dates), not your card number. It's a flat-rate plan; there is no billed overage. See Payments below.

Usage metering. For AI features that call a model on our own servers, we record how many tokens each call used: never the raw prompt or response, just token counts and modeled micro-USD costs, so usage (and your remaining monthly AI credits) can be tracked accurately and plan allowances enforced.

We run no advertising or behavioral-tracking scripts. The one exception is Vercel Web Analytics, which gives us aggregate, cookie-less page-view counts. It doesn't identify you or track you across sites. The only cookies we set are our sign-in system's own: a session cookie plus short-lived helper cookies used during sign-in, nothing for tracking.

How the AI features handle your data

These features call a language model on our own servers (not inside Claude), routed through the Vercel AI Gateway. We pick a model per feature mainly for cost and capability, and that choice (including which company's model it is) can change over time. Rather than name a specific provider here and risk this page going stale the next time we do, here's what's actually configured right now:

No AI Model Training. We access AI language models exclusively via commercial API endpoints. Neither we nor our API model providers (such as OpenAI, Anthropic, or Google via Vercel AI Gateway) use your prompts, check-in notes, summaries, or chat messages to train foundation AI models.

Insights (themes, effectiveness, patterns) and progress reports are built from your saved summaries and check-ins, put through a privacy filter first, every time:

In-app chat and background summarization work more like standard AI chat features: what you type goes to the model close to as-is, in real time, so we don't run the same anonymization filter step there. If you ask the assistant to look something up (a past session, a check-in), the tool result (including its exact timestamp) becomes part of what the model sees for that reply. If you'd rather keep something out of a chat prompt entirely, not mentioning it there is the more private option, or use the MCP connector inside Claude instead, which never reaches our model-calling code at all. When an in-app chat thread ends, a background worker generates a summary so your overall session history stays up to date.

Crisis-safety detection in in-app chat. The in-app chat scans your message text for language that may indicate acute distress or self-harm risk, using a deterministic keyword match (not a clinical or diagnostic assessment), so it can proactively lead its reply with crisis-support resources (a local hotline number). Only a content-free record that this safety check occurred is stored (never the message text itself). This check runs only for the in-app chat, not for conversations through the MCP connector in Claude.

Across both: prompt and response content is never logged or stored by us beyond what's already described on this page: there's no separate "AI request log." What we keep afterward is a token count and cost record, for credit metering, and, for insights, the resulting structured output (e.g. "recurring theme: work stress"), not the raw text that produced it. In-app chat is the one exception: the messages themselves are kept in full as your chat history, as described above, so the conversation can continue later.

None of this is a clinical read on you. It's reflection tooling built on top of what you've already shared. It doesn't evaluate, diagnose, or treat anything. See how the insights actually work for the full picture, including what they can't tell you.

Who else sees it

We don't sell data, and we don't share it for advertising. The below are the outside services this app relies on to run at all. Each sees only what it needs to do its job:

Payments

If you subscribe to a paid plan, Stripe handles the actual payment. We never see or store your credit card details: only a Stripe customer ID and your subscription status (active, canceled, etc.), which is how the app knows what credit allowance you're entitled to.

Emails we send

The app sends four main types of email to users:

  1. Sign-in links: sent on demand when you log in without a password.
  2. Progress reports: weekly or monthly narrative progress recaps (opt-in).
  3. Check-in reminders: daily or weekly nudges if you haven't logged a mood check-in yet during the period (opt-in).
  4. Session invites: occasional pattern-triggered invitations when your check-ins suggest a technique might help right now (opt-in).

Every recurring or optional email includes a one-click unsubscribe link that works without logging in, and preferences can be toggled anytime in your account settings. Turning off any of these emails does not affect any saved session, goal, or check-in data.

Usage-limit notice: an account gets one transactional email per billing period if AI usage passes 80% of what's included in its plan allowance. This notice is transactional (it concerns account status, not marketing), so it does not contain an unsubscribe link.

Security and data protection

We take reasonable technical and organizational measures to safeguard your personal data:

Retention and deletion

Deleting your account can be requested anytime by emailing joel@camic.app. The data model behind the app is engineered so that once an account deletion is executed, everything tied to it (sessions, check-ins, goals, conversation summaries, cached insights, progress reports, chat history, and usage records) is deleted along with it in the same operation, not left behind in orphaned tables.

If you would like to pause or adjust specific feature emails without deleting your account, see Emails we send above or adjust your settings under your account profile.

Your choices and rights

If you are located in the European Economic Area (EEA), UK, California, or another jurisdiction with formal data privacy regulations (e.g. GDPR or CCPA) and wish to exercise statutory data rights, email joel@camic.app. As a small independent project, requests are handled directly by the developer, so please allow reasonable time for processing.

Not a clinical service

Camic Health (the app and this policy both) is reflection tooling, not clinical assessment, diagnosis, or treatment, and using it doesn't create a relationship with a healthcare provider. If you're struggling, please consider reaching out to a qualified mental health professional, or, if you're in crisis, a local emergency service or crisis line.

Changes to this page

If this policy changes in a way that matters, we'll update the date at the top. Checking back occasionally is the best way to stay current.

Contact

Email joel@camic.app for any privacy questions, data access requests, or account deletion.