Effective July 30, 2026
Privacy without the fog.
This policy explains what Sin Is The Enemy collects, why it is needed, where it is handled, and the choices you have. The short version: we do not sell personal data, we do not use private Keeper conversations to train models, and optional analytics stays off until you allow it.
Who operates this service
Sin Is The Enemy operates this website and brotherhood platform. Privacy questions, access requests, and deletion requests can be sent to watchman@sinistheenemy.com.
What we collect
- Account and sign-in data: email address, anonymous callsign, a one-way password hash, verification status, session records, and email preferences.
- Interest-form data: name, email address, submission source, and timestamp when you join the First 100 or another launch list.
- Accountability data you choose to enter: primary fight, goals, profile answers, daily check-ins, notes, assessments, battle plans, wins, failures, triggers, gratitude, prayer entries, and mission progress.
- Brotherhood activity: community-room messages, reactions, flags, fireteam membership, partner requests, direct messages, and items you deliberately share with a partner or room.
- Operational data: timestamps, referral attribution, coarse abuse-prevention information such as IP-based rate-limit events, and aggregate usage counters that do not contain message text.
- Optional analytics: page-visit and device information from Google Analytics and Metricool only after you choose “Allow analytics.” Advertising storage and ad personalization are disabled.
Private Keeper conversations
Your one-to-one Keeper messages are sent to the Cloudflare-hosted AI service to produce a reply. The application does not write that conversation to its server database and does not use it to train a model. A short history stays in your browser session so the conversation works; closing the tab clears session-only history. Where an explicit on-device “remember” option is offered, that choice stores the history only in that browser until you turn it off or clear site data.
Why we use the data
We use the information above to operate sign-in, protect accounts, run check-ins and streaks, generate the plans or summaries you request, deliver community and partner features, moderate abuse, send service or opted-in email, measure aggregate reliability, and meet legal or safety obligations. We do not sell or rent personal data.
When information is shared
Information is processed by service providers needed to run the platform, principally Cloudflare for hosting, storage, email delivery, security, and AI inference. Google Analytics and Metricool receive analytics data only after consent. Information may also be disclosed when required by law, to protect a person from immediate harm, or to investigate abuse of the service.
Other members see only the content and callsign you choose to post or share through a community, fireteam, partner, or check-in sharing feature. Do not post information you do not want the relevant audience to see.
Retention
- Sign-in sessions expire after 30 days. One-time sign-in links expire after 20 minutes and are single-use.
- Hashed signup rate-limit identifiers expire after 24 hours. The raw network address is not stored with the interest-form record.
- Account and accountability records are kept while your account is active and until they are deleted on request, unless a limited record must be retained for security or legal reasons.
- Open-room history is bounded to the most recent 100 messages per room. Partner direct-message history is bounded to the most recent 200 messages per conversation and is wiped when the pairing is ended with the wipe action.
- Aggregate counters that contain no message content or account identifier may be retained for long-term product and reliability analysis.
- Optional analytics providers apply their own retention rules to data collected after consent.
Your controls
Use the gear button at the lower-left of any page to allow or reject optional analytics. You can clear browser storage in your browser settings. You can sign out to invalidate the current account session and use in-app wipe controls where offered.
You may request access, correction, export, or deletion by emailing watchman@sinistheenemy.com from the account email address. We may need to verify the request before acting.
Security
We use encrypted transport, server-side access checks, one-way password hashing, secure session cookies, bounded message history, rate limits, and moderation controls. No system is perfectly secure. Use a unique password and do not share access to a signed-in device.
Adults only
The platform is built for adults age 18 and older. We do not knowingly create accounts for children. Contact us if you believe a minor has provided personal information.
Changes
If this policy changes materially, the effective date will be updated and a notice may be posted in the app. Continued use after an update means the revised policy applies from its effective date.