HEXED

Privacy Policy

Effective Date: October 2025

Welcome to HEXED, where we turn your rage into ritual—and protect your data like it's sacred. This Privacy Policy explains what we collect, why we collect it, and how we guard it like a sigil in a salt circle.

By using HEXED (the "App," "we," or "us"), you agree to this Privacy Policy.

🔮 1. Information We Collect

Account Information

When you create an account, we collect:

  • Email address
  • Username
  • Password (securely encrypted, never stored in plain text)

Ritual & App Usage Data

When you use the app, we collect information about your activity—such as:

  • Which rituals you perform or start
  • Choices made within a ritual (e.g., selected spell types, survey responses)
  • App interactions and frequency of use
You have control over how much of your ritual data is preserved. When a ritual is completed, sensitive and negative text inputs are automatically [redacted] in the database. This ensures your private reflections stay private—even from us.

Analytics & Cookies

We use Google Analytics and similar tools to understand how the app is used, improve performance, and design better rituals. This may include anonymized technical data like:

  • Browser or device type
  • Operating system
  • General location (city or region)

You can disable cookies or analytics tracking in your browser settings.

💳 2. Payment Information

If you make a purchase through HEXED, payment processing is handled by Stripe, which securely collects your payment details. We do not store or access your credit card information.

Stripe's privacy policy can be found here.

🔥 3. How We Use Your Data

We use the information we collect to:

  • Operate and maintain the App
  • Customize your experience (for example, recommend a ritual or spell)
  • Analyze performance and improve functionality
  • Communicate with you about your account, updates, or new features
  • Maintain security and prevent misuse

We do not sell or share your personal information for advertising or marketing.

🕯️ 4. Data Storage and Security

Your information is stored securely on servers hosted by trusted providers (currently AWS or DigitalOcean). We follow best practices for encryption, password hashing, and database security.

If we ever use Firebase or another hosting service, the same protections will apply.

🌑 5. Data Retention and Deletion

You can request that your data be deleted at any time by contacting us at hexed@rhiannonvaughn.com.

Additionally, upon ritual completion, sensitive emotional inputs are automatically redacted in our system to protect your privacy.

If you delete your account, your profile and all personal data will be permanently removed from our servers within 30 days.

🪞 6. Your Rights

Depending on your location, you may have rights to:

  • Access a copy of your data
  • Correct or update personal information
  • Request deletion of your data
  • Withdraw consent to data collection

To exercise these rights, contact us at hexed@rhiannonvaughn.com.

⚙️ 7. Third-Party Services

We may use the following trusted services:

  • Google Analytics (usage metrics)
  • Stripe (payments)
  • Firebase (app hosting and storage, future use)
  • AWS / DigitalOcean (secure hosting)

Each service has its own privacy practices, which we encourage you to review.

🧿 8. Children's Privacy

HEXED is not intended for users under 16. We do not knowingly collect personal data from minors.

📜 9. Changes to This Policy

We may update this Privacy Policy as we grow or summon new features. If we make significant changes, we'll notify you via email or in-app message.

✉️ 10. Contact

Questions about your privacy or data?
Email us at hexed@rhiannonvaughn.com

In short: your secrets stay sacred. We collect only what's needed to make HEXED work and keep it safe. The rest? Purified by fire. 🔥