Steel Magnolias is a community for women navigating divorce and separation. You're here because something hard is happening, or happened. We take your privacy seriously because we know what you're sharing with us, and because for some of you privacy isn't a preference, it's safety.
This is the full-product version of our Privacy Policy. It covers the Steel Magnolias mobile app and everything in it: your account, membership verification (as it arrives), the live community (The Oasis, topic chats, and Gardens), Roots (our community forum), direct messages, Receipts (a private documentation tool), AI features, notifications, and subscription billing. It replaces the earlier pre-launch waitlist version of this policy.
We've written this to be read, not skimmed. Where we use a specific term, we explain it. If anything is unclear, email us at hello@steelmagnolias.app and a real person will answer.
01Who we are
Steel Magnolias LLC, a California limited liability company, operates Steel Magnolias: the mobile app, the community, and related services. For any privacy question, write to hello@steelmagnolias.app.
02What we collect
We only list things we actually collect. If it's not listed here, we don't have it. (We describe features that exist at launch; some things below, like photo attachments in Receipts, are noted as not-yet-available, and we'll update this policy before any of them collect data.)
When you join our waitlist or early access
If you sign up on our website to join the waitlist or early access, we collect your email address (and which page you signed up from) so we can tell you when the app, or a new feature, is ready. That's all the waitlist collects.
If you were invited to our founding group, we also keep a one-way cryptographic hash of the invited email address (never the address itself in that record). It exists only to recognize you and apply your founding offer when you sign up, and it is used for nothing else.
When you create an account
- Your email address and a password. Your password is stored only as a secure, salted hash by our authentication provider. We never store or see your actual password.
- A confirmation that you are 18 or older. We store only a timestamp that you passed the age check. We do not collect or store your date of birth.
When you verify your membership
Membership verification is arriving in an app update. We are publishing this section before any verification happens, so nothing about it is a surprise: it describes exactly what will be collected when verification launches, and nothing is collected under it until then. We will name the verification provider here, and under "How we share it," before the first check runs. For every member whose account was not created by accepting the 2026-07-21 version of this policy or a later one (accounts from before that version was published, and any sign-up in flight at the switch), the email notice described under "Changes to this policy" comes at least 30 days before any of it applies to her.
Steel Magnolias is a community for women navigating divorce and separation, and membership will be verified: once verification launches, every new member completes the same short ceremony before joining the community, and every existing member completes the same ceremony during a grace window after launch, affirming the eligibility term in our Terms as part of it (recorded like any consent choice). The same door, for everyone, including the women who have been here since the beginning. The ceremony checks one thing: that a real, live adult is applying. It is not a gender test. No software anywhere in our system tries to judge gender from a face, and our reviewers follow written criteria that forbid judging it too. You affirm for yourself that our eligibility term fits you (see our Terms of Service, Section 3); the check itself only looks for a real, live person and estimates adulthood.
How the check works. You take a quick live selfie in the app. The photo travels directly from your phone to our verification provider over an encrypted connection: it never touches our servers, and we never store it, not even for a moment. On the provider's systems, the photo is checked for liveness (a real, present person, not a photo of a photo or a replayed video) and for adulthood (an estimate that the person is over 18, not an identification of who you are). The provider then permanently deletes the photo when the decision is made. That deletion is a contract term, not a courtesy: our agreement with the provider requires it, gives us audit rights to confirm it happens, and caps the timeline. For most applications deletion happens within minutes; it never takes longer than 72 hours, the ceiling that covers human review.
A person may look, and we say so. Most applications are decided by the automated check alone, in seconds, with no human involved. A woman on our team reviews any application the check is not sure about, every appeal, and a small random sample for quality. Whoever on our team reviews your application views the photo inside the provider's own review tool, on the provider's systems: our review accounts cannot download or export it, and the provider deletes it on the same schedule as every other photo. We tell you this plainly instead of pretending no human ever sees a verification photo.
Prefer a person from the start? You can skip the camera check entirely and book a short live video hello with a member of our team. It is a real-time video call: it is not recorded, and from the call itself the only thing we keep is the outcome. (Because it is a live call, the video passes through the call service that carries it while the call happens, the same way any video call works, and the call service keeps its ordinary session records, such as that a call happened and when, under its agreement with us.)
What we store when you verify. The complete list, in the same spirit as the rest of this policy:
- The outcome. That you were verified, when, and by which path (the camera check, human review, or the live video hello), plus, if you used the camera check, the provider's reference code for the session. The reference code is a random identifier that labels the session; it is not your photo and contains nothing about your face. (The live video hello involves no provider, so that record carries no reference code.)
- Your consent and your affirmation. Dated, versioned entries in the append-only consent history described below: your affirmation of the eligibility term in our Terms of Service, recorded at your ceremony whichever path you take, and, if you used the camera check, the consent you gave before the camera opened.
- A device identifier from the application. When you verify, your phone's built-in app-integrity system (App Attest on iOS; hardware-backed key attestation on Android) proves the application came from a real installation of our app on a real device, and we keep the resulting key identifier. It is a cryptographic identifier for that installation of the app; it contains nothing about your face or body.
- Fairness bookkeeping. The small operational records that make the limits work: how many attempts you have used, when a cooldown ends, when an appeal happened, and, for members whose accounts were not created by accepting the 2026-07-21 version of this policy or a later one (accounts from before that version was published, and any sign-up in flight at the switch), when the notice of these changes was sent to you. (That last timestamp is what guarantees nothing here applies to you sooner than 30 days after the notice; if it isn't on record, the changes are not applied to you.)
That is the entire list of what verification stores about you. Two nearby things are worth naming so the picture is complete. First, no member's account carries a verification exemption: every member account carries a verification record naming its path. The only accounts with no verification at all are the demonstration accounts Apple and Google use to review the app (an exception we document with both stores; those are not member accounts and they see demonstration content, not the member community). Second, our servers record the steps of the verification funnel (verification started, method chosen, the automated decision, human review entered, verified, and first post) as analytics under the dedicated random analytics identifier described in this policy, never under your name, email, account ID, or handle, and never with a photo or a reason a check did not pass; see our What we measure page.
What we never store. Your photo. Any copy of it. Any "face template," embedding, or measurement derived from it. Your date of birth (the check estimates "adult"; it does not learn your birthday). None of these ever exist on anything we control: not on our servers, not in our database, not in backups. What our systems receive from the provider is the decision, the method, and the reference code, nothing more, and our integration with the provider is scoped so that our systems cannot retrieve images.
Our biometric data retention and destruction schedule. This is our published retention and destruction schedule for biometric information, including under the Illinois Biometric Information Privacy Act. The verification photo, and any measurement of face geometry the provider's systems derive from it while checking liveness and age, are collected by the provider for one purpose only: deciding your membership application. Our contract requires the provider to permanently destroy both when that decision is made, within minutes for most applications and never later than 72 hours after capture. That is the entire life of the data, far shorter than the outer limit the law allows (destruction when the purpose is satisfied, or within three years of your last interaction, whichever comes first). We do not store biometric identifiers or biometric information on our systems at all. We never sell, lease, trade, or otherwise profit from biometric data, and we never disclose it except as you consent or as the law requires; our contract binds the provider to the same rules.
Your consent comes first. The camera does not open until you have seen a consent screen that tells you, in writing: what will be captured, who will process it (the provider, by name), why, what happens to the photo, and the destruction schedule above. Your agreement is recorded as a dated, versioned entry in your consent history. If you would rather not consent to the camera check, the live video hello is always available instead, and if neither path works for you, write to hello@steelmagnolias.app and a person will help you find one that does.
If a check does not pass you. Sometimes a camera check fails a real woman: bad light, an older phone camera. When that happens you can simply try again, and after two attempts your application goes to a person automatically (our target: within 24 hours). The live video hello is offered at every step, and you can appeal any decision to a different reviewer. A failed attempt leaves no lasting record of your face anywhere: the provider destroys photos from failed attempts on the same schedule as every other photo, and nothing we store marks your face as having "failed." While your application is pending you are not shut out: crisis resources and educational content stay fully available.
When you delete your account. We delete the verification records above (the outcome, your consent entries, the device identifier, and the fairness bookkeeping) with your account, under either deletion mode described under "How long we keep it." (Accounts terminated for a serious safety violation keep the minimal, scrubbed record described there, and these records are part of it.) There is no photo to delete, because we never had one.
Verification is not one of the community AI features described under "How AI is used," and none of the AI consents in the app cover it; it has its own consent, described above.
Your identity in the community
Inside Steel Magnolias you are known by a handle you choose: a nickname or phrase, never your real name. We deliberately steer you away from using your real name, your location, or a photo of yourself, and the app blocks identifying details in handles. Your profile picture is a simple monogram generated from your handle, not a photo you upload. Behind the scenes we generate an opaque identifier for the chat system; your real account ID, your name, and your email are never sent to our chat provider.
Your profile
- Optional bio and time zone, which you can edit.
- An optional stage you may select: Unraveling, Rebuilding, or Blooming. This is a way to describe what kind of support might fit you right now. It is not a clinical or diagnostic label, and you can skip it.
Your safety setting
When you join, we ask a single question, whether someone else might be able to see or use your phone, and store the answer as a safety setting (either "standard" or "high"). This is not a clinical or psychological screen. It changes how the app behaves on your device (for example, whether you receive notifications, and how the app hides its contents and locks). You can change it later in Settings.
The community: Roots, The Oasis, Gardens, and messages
When you post in Roots (our forum), talk in The Oasis or topic chats, take part in a Garden (a member-created group), or send a direct message, we store that content so the community works. Real-time messaging and groups are handled by our chat provider, Stream (see "How we share it"). The intro note you send with a direct-message request is stored in our database, where it remains after the request is accepted or declined.
A note on encryption: community chat and direct messages are not end-to-end encrypted. They are protected in transit and at rest, but we (and our chat provider) can process message content to operate and moderate the service. We tell you this plainly rather than imply a secrecy we don't provide.
Receipts, your private documentation tool
If you use Receipts, we store the entries you create (typed notes and/or voice notes) and their titles. Your typed text and the transcripts of your voice notes, along with their titles, are encrypted at rest with strong application-layer encryption (AES-256-GCM); the key lives only in our server environment, never in the database. Receipts entries are private to you: they are never shown to the community, never moderated, and never analyzed in aggregate. "Private to you" means no other member and no one on our community team ever sees them; it does not mean they're invisible to our systems. To transcribe a voice note, our servers (and OpenAI's, for that step) process the content. We don't read your entries for any other purpose.
For a voice note, the recording is held in a private, access-controlled storage area and sent to OpenAI's Whisper to be transcribed into text. Once it's transcribed, the recording is deleted: we keep the encrypted transcript, not the audio. (If a transcription fails, we keep the recording only so you can retry, then delete it. Photo and screenshot attachments in Receipts are not available yet; when they are, we'll update this policy before any are collected.)
Receipts is a personal documentation tool, not an evidence or legal-records system. We make no claims about chain of custody, court admissibility, or tamper-proof preservation, and editing an entry overwrites it.
Reports and blocks
If you report content, we store the report (who reported, what was reported, the reason, any note, and how it was resolved) as a safety record. If you block someone, we store the block so we can keep them away from you; the person you block is never told.
Notifications
If you turn on notifications, we register your device's push token and your notification preferences. You choose how much each kind of notification shows on your lock screen. For Garden messages and direct messages, you pick one of five levels: off, a generic "New activity," the kind of activity only (like "New direct message"), a named alert (for a Garden, which Garden it's in; for a direct message, who it's from), or the named alert plus a preview of the message itself. Message requests go up to who it's from. There is no message body to preview. Alerts from The Oasis and topic chats are always the generic "New activity": a support topic's name never appears on your lock screen, whatever your settings. For Gardens and direct messages, the starting level when you first turn notifications on is the full preview (we tell you that plainly before the system permission prompt appears), and you can dial any category down, or off, in Settings at any time (if you've set an app-lock PIN, raising a level asks for it first; lowering never does). If your safety setting is "high," you receive no push notifications unless you deliberately turn them on. Even then, content is capped at the kind of activity: never a name, a Garden, or message text. An alert from us never has to give you away on a screen someone else might be watching.
Your consent history
We keep a record of the consent choices you make in the app: for example, agreeing to the community AI disclosure, the direct-message guidelines, or the Receipts AI disclosure, and, once membership verification launches, your eligibility affirmation and (for the camera check) your verification consent, and any later withdrawal. This record is append-only: a new choice (or a withdrawal) adds a new entry rather than erasing the old one, so there's an honest history of what you agreed to and when. This record is deleted when you delete your account (except for accounts terminated for a serious safety violation, where it is retained as part of the minimal, scrubbed record described under "How long we keep it").
Separately, when you first agreed to this Privacy Policy and our Terms (at sign-up or on the waitlist), we kept a small acceptance record: your email, an anonymized IP address, your browser/device string, and which versions of the documents you agreed to. This is legal evidence of agreement; see "How long we keep it" for how it's treated.
Your app lock (PIN and Face ID)
If you set up an app-lock PIN, it never leaves your device. It is stored as a salted, hashed value in your device's secure keychain, marked so it can't be backed up or moved to another device. It is not stored on our servers, and we cannot recover it for you. That's deliberate: because your PIN never reaches us, no one can pressure us into handing it over, and no one but you, on this device, can reset it. Face ID or fingerprint unlock, if you enable it, is an optional convenience handled entirely on your device. Your Face ID and fingerprint data stay in your device's secure hardware; they are never sent to us. (Membership verification, when it launches, is separate from your app lock: it uses the camera, never Face ID or your fingerprint, and it works as described under "When you verify your membership." We never store that photo either; our systems receive only the decision.)
Two-factor authentication (optional)
You can add two-factor authentication to your account in Settings (if you don't see it yet, it's arriving in an app update). It works with an authenticator app on your device that generates short-lived codes, never codes sent by text message, which can be intercepted or light up a lock screen someone else might see. To verify your codes, our authentication provider stores the enrollment secret your authenticator app and our servers share. At setup we also give you backup codes, which we store only as secure one-way hashes. Like your password, we can't read them back, and each one works once.
If you lose both your authenticator app and your backup codes, recovery is a deliberate, human process: we verify it's you using things about your account (never your legal identity, which we don't have), we notify your account email, and we hold the change open for a seven-day waiting period before it completes, so no one can quietly strip this protection off your account.
Subscription and payments
Subscriptions are processed by Apple (App Store) or Google (Google Play). We never receive or store your card or payment details. To link a purchase to your account, we share your pseudonymous account identifier (a random ID, not your name) with Apple or Google.
On our website
Our marketing website and admin tools use PostHog, along with Vercel's analytics and speed-insights tools, for pseudonymous analytics and performance measurement. These tools record page views, clicks, scroll depth, performance metrics, approximate location (country/region/city, derived from your IP address by our analytics provider, which discards the IP at ingestion; your IP address is never stored with your analytics data), and basic device/browser information. To keep these measurements consistent across pages, a random identifier is stored in your browser's local storage; we do not use analytics cookies. We do not use advertising identifiers, third-party tracking pixels, or any cross-app tracking, anywhere.
In the mobile app
The measurements in this section arrive with app version 1.0.3. If you joined before this change, they take effect for your account 30 days after we emailed notice of it.
The app measures how its features are used, under the same rules as everything else we measure: pseudonymously, minimally, and with the full list published on our What we measure page.
Here is what that means in practice. The app records specific, individually named product events (for example: signup completed, an onboarding step completed, the paywall viewed, a message sent in community chat, a post made in the forum) under the same dedicated random analytics identifier described below. That identifier is never your name, email, account ID, or handle. Events carry small technical labels drawn from fixed lists (for example: which community surface, which subscription plan, which sign-in method, whether a consent was granted, the platform, and the app version), never content and never your identity: no message text, no post text, no titles, no search terms, no free text of any kind, ever. We do not use automatic capture, and we do not record your screen or replay your sessions, ever.
Some parts of the app send nothing at all. Receipts, direct messages, the app lock and privacy shield, and every crisis flow emit no analytics events of any kind.
If you tell us during onboarding how you heard about Steel Magnolias, that answer is recorded as one of these events. The question is optional, and skipping it changes nothing about your membership.
On Android only, when the app is installed from a link in one of our own campaigns, Google Play passes along the campaign labels from that link (which campaign, which channel). We keep those labels only when they match the known values of our own campaigns; anything else is discarded. They describe our link, not you.
The single anonymous age-check event still works as before: when someone does not pass the 18+ age check, a one-time random identifier tied to no account records the blocked attempt. (Once membership verification launches, the verification funnel steps listed under "When you verify your membership" are recorded under the dedicated random analytics identifier.)
When you delete your account, the analytics records held under your identifier are deleted and the identifier itself is severed.
Subscription lifecycle events (server-side)
When Apple or Google tells our servers that your subscription changed (a trial started, became a paid membership, renewed, was cancelled, or was refunded), we record that event in our analytics under a dedicated random analytics identifier. That identifier exists for exactly this purpose: it is never your name, email, account ID, or handle; it is never shown to anyone; and it is never used to sign you in or to link you to other members. These events tell us, in aggregate, how many trials become memberships and how many members stay. They carry no content and nothing about how you use the app: only the subscription's lifecycle step, the store, the plan and its price tier (founding or standard), a technical de-duplication key that identifies records of the same underlying change (so duplicate store deliveries can be recognized and filtered), and, when a membership ends, whether the loss was voluntary or a billing failure. When you delete your account, we delete the analytics records held under your identifier and sever the identifier itself. See our What we measure page for the full picture of what we do and don't collect.
03How we identify you
We're built to be pseudonymous. The behavioral data we collect (our website analytics, the app's product events described under "In the mobile app," the server-side subscription lifecycle events described above, and, once membership verification launches, the verification funnel events) is tied to pseudonymous identifiers (random IDs), never to direct identifiers like your real name or address, so patterns can inform the product while you stay unidentifiable as an individual. Inside the app you're known by a handle you choose, never your real name, and the app's product events are held under the dedicated random analytics identifier, never your handle, name, or email.
The one place we rely on a direct identifier is the account/contact layer: your email address, because we need it to sign you in and reach you. We don't join your email to website analytics. This pseudonymous-by-design approach is a foundation of Steel Magnolias, in the app and on the website alike.
04How we use it
Everything we collect, we use for one of the purposes below. Nothing else.
- To run the service: create and secure your account, show you the community, deliver your messages and notifications, and operate Receipts.
- To keep the community safe: moderation, handling reports and blocks, and enforcing our Terms and Community Guidelines.
- To process your subscription: through Apple or Google.
- To improve the product: by looking at our website analytics, the app's product events, the pseudonymous subscription lifecycle events described above, the verification funnel events (once verification launches), and community trends in aggregate, never to profile you as a named individual.
- To contact you: service emails (like account or security notices) and, only if you haven't opted out, occasional non-essential updates.
We do not sell your data, and we do not use it for advertising.
05How we share it
We work with a small set of service providers. Each gets only what it needs for its specific job, and each is bound by a contract to protect your data.
- Supabase: our database, authentication, and file storage.
- Stream: real-time community chat, groups, and direct messages, and the relay of push notifications to Apple and Google.
- OpenAI: transcription of Receipts voice notes (Whisper). This is the one place your content reaches OpenAI, and only when you record a voice note after consenting.
- Anthropic (Claude): powers our AI features. At launch, the live AI feature is voice transcription in Receipts (handled by OpenAI above); Claude powers community AI helpers and documentation features in Receipts as those features roll out, and your content is sent to it only after you consent at the relevant in-app gate (the community AI disclosure at onboarding, or the Receipts disclosure the first time you use it). We name Claude here so the disclosure you see in the app matches this policy.
- Apple and Google: process your subscription payment (we never see your card) and deliver push notifications.
- Resend: sends our transactional emails, such as account and launch notifications.
- Our verification provider (named here before membership verification launches): performs the live selfie check (liveness and an over-18 estimate) on its own systems, as our processor, when you verify your membership, and hosts the review tool our team uses for human review. Our contract requires the provider to permanently destroy the photo and anything derived from it when the decision is made (never later than 72 hours after capture), forbids it from using your photo for anything except your verification (including training its systems), and gives us audit rights to confirm its deletion happens as promised. See "When you verify your membership."
- PostHog: pseudonymous analytics for our website and admin tools, the app's product events described under "In the mobile app" (recorded under your dedicated random analytics identifier), the single anonymous age-gate-block count described above, the server-side subscription lifecycle events described above (same identifier), and, once membership verification launches, the verification funnel events described under "When you verify your membership" (same identifier, nothing biometric).
- Vercel: hosts the application and backend, and provides our website analytics and performance metrics.
We also use infrastructure and security providers (such as Upstash and Vercel BotID, for rate-limiting and bot protection) that process technical request data such as IP addresses to keep the service running and safe.
We do not sell your data. We never have. We never will. This isn't a promise we'll quietly revise when revenue gets tight. It's the foundation of the trust this community is built on. We do not share your personal information with advertisers, and we do not allow anyone to use it to profile you.
We disclose information only when legally required. If we receive a subpoena, court order, or similar legal demand, we respond to the narrowest extent the law requires, and we notify the affected member when we're legally permitted to.
06How AI is used
We're specific about this because trust matters here.
- Our AI is a host and helper, never a professional. At launch, the only live AI feature is voice-note transcription in Receipts (via OpenAI's Whisper). As we add AI features, they may help welcome new members, surface relevant past discussions, and assist with moderation. AI is never a therapist, doctor, lawyer, or crisis worker; it never gives professional advice; and it never pretends to be a human member or the founder. AI-generated content is labeled. There is no private one-on-one AI chat companion.
- Consent comes before processing. Community AI is disclosed and agreed to during onboarding. The AI in Receipts (transcription, and documentation features as they arrive) is disclosed and agreed to the first time you use Receipts, with the providers named. You can review these disclosures anytime in the app's privacy settings, and withdraw your Receipts AI consent there.
- Receipts is private. Your Receipts entries are kept private to you, never shown to the community or other members, and never analyzed in aggregate.
- Community content used for product insight is aggregated and anonymized. When we study how the community is doing to improve it, we look at themes and patterns across many members, never quoting or singling out an individual.
- Your data is never used to train AI models. OpenAI does not train on data sent through its API and deletes it after a short abuse-monitoring window (up to 30 days); Anthropic does not train on your data. We do not use member content to train external AI models.
07How long we keep it
We keep different kinds of data for different lengths of time, and we list them separately so it's clear.
- Your account and community content (profile, posts, chats, messages, Gardens): kept while your account is active. When you delete your account, this content is removed or anonymized depending on the mode you choose; see the two deletion modes below for exactly what each does.
- Receipts entries: kept until you delete them or delete your account. Receipts content is never kept in anonymized form when you delete your account; it is removed in either deletion mode. Voice audio is deleted right after transcription.
- Your in-app consent history: kept for the life of your account (it's an append-only record), and deleted when you delete your account (except for accounts terminated for a serious safety violation; see below).
- Membership verification (once it launches): the outcome record, your consent entries, the device identifier, and the fairness bookkeeping are kept for the life of your account, and we remove them when you delete it (for accounts terminated for a serious safety violation, they are part of the minimal scrubbed record described below). Your verification photo is different: we never hold it at all, and the provider is required by our contract to destroy it when the decision is made, never later than 72 hours after capture. The full schedule is published under "When you verify your membership."
- Your acceptance record (the sign-up/waitlist agreement evidence described above): kept for about 4 years as legal evidence that you agreed to these documents, and retained even after you delete your account for that purpose. It's just your email, the agreement metadata, and which versions you accepted, stored apart from everything you did in the app and never used to contact you or to rebuild your activity. It exists to protect both you and us.
- Subscription status and the pseudonymous identifier that links a purchase to your account: kept while needed to manage your subscription and entitlements. Apple and Google, as the payment processors, hold the actual transaction and financial records under their own policies; we never receive your card or payment details.
- Analytics events (PostHog): website events are held under pseudonymous random identifiers and are never joined to your name or email; aggregated, non-identifying metrics may persist for trend analysis. (The anonymous age-gate-block signal carries only a one-time random ID and isn't linkable to anyone.) The app's product events and subscription lifecycle events (and, once membership verification launches, the verification funnel events) are kept under your dedicated random analytics identifier while you have an account, and are deleted (identifier and events both) when your account is deleted.
- Voice audio at OpenAI: OpenAI may retain it for up to 30 days for abuse monitoring, then deletes it; it is not used for training.
When you delete your account, we schedule the deletion and hold it for 30 days: a window during which you can change your mind and cancel. We can't shorten that window; after it passes, the deletion runs and can't be undone. You choose between two modes:
- Anonymize (default). We remove your account and de-name your contributions: your forum posts are detached from you, and on your retained chat and direct messages we replace your handle with a neutral label (like "Member-1a2b3c4d"), so nothing you wrote still shows your chosen name. A direct message you sent stays visible to the person you sent it to, but under that neutral label.
- Full deletion. We remove your account and your contributions outright, including your chat messages and direct-message conversations.
Whichever mode you choose, your Receipts entries are fully removed (they are never kept in anonymized form), and any voice audio was already deleted right after transcription.
If we have to terminate an account for a serious safety violation, we keep a minimal, scrubbed record (for the audit trail and to keep block lists working) rather than fully deleting it.
08Your rights
You have the following rights over your data. Use the in-app tools where they exist, or write to hello@steelmagnolias.app.
- Access. Ask for a copy of the data we hold about you, including your consent history where retrievable.
- Correction. Update your profile and account details in Settings, or ask us.
- Deletion. Delete your account from within the app (see "How long we keep it" for how deletion works).
- Opt out of non-essential email. Reply "unsubscribe" to any non-essential email, or email us, and we'll stop sending you non-essential email. We handle these requests by hand and honor them within 10 business days. Our mailing address is at the bottom of this policy. (Service messages, like security and account notices, aren't promotional and continue.)
09Your California privacy rights
If you're a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to:
- Know and access the personal information we collect about you.
- Delete your personal information (with limited exceptions, such as records we're legally required to keep).
- Correct inaccurate personal information.
- Opt out of the sale or sharing of your personal information.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising, so there's nothing to opt out of, but you have the right regardless. Because we use sensitive personal information (such as your account credentials, and, once membership verification launches, the verification check described under "When you verify your membership") only as needed to provide the service (a purpose permitted under Civil Code section 1798.121(d)), we are not required to offer a separate "Limit the Use of My Sensitive Personal Information" option, and we don't use or disclose it for any other purpose. We will not discriminate against you for exercising any of these rights: your access, experience, and price stay the same.
To exercise these rights, use the in-app tools or email hello@steelmagnolias.app. We'll confirm a verifiable request within 10 business days and respond within 45 days (we may extend once, with notice). You may use an authorized agent to make a request for you; we may ask for proof of authorization and verify your identity to protect your account.
10How we protect it
- Encryption in transit. All connections use HTTPS.
- Encryption at rest. Your data is encrypted in our database, and Receipts entries get an additional layer of strong application-layer encryption (AES-256-GCM), with the key held only in our server environment.
- Strict access controls. Every table in our database enforces row-level access rules, and Receipts storage is locked to our service layer alone.
- Your app lock stays on your device. Your PIN is never sent to us and we can't recover it; your Face ID and fingerprint data never leave your device. (The membership verification photo is different data on a different path, and we never store it: it goes from your phone to the verification provider, which is required by our contract to destroy it at the decision. See "When you verify your membership.")
- Optional two-factor authentication. You can require a code from an authenticator app on your device to sign in; backup codes are stored only as one-way hashes, and removing the protection without your codes takes a human-verified, seven-day process.
- IP anonymization. Our website analytics provider discards IP addresses at ingestion; they are never stored with your analytics data.
- No training of external AI models on your data.
No system is perfectly secure. If a breach affects your personal information, we'll notify you without undue delay and in the manner the law requires. We maintain an internal incident-response process.
11Children
Steel Magnolias is for adults. You must be 18 or older, and the age check runs before an account is created, so no minor's account or data is stored. (Once membership verification launches, its ceremony also checks that an adult is applying, a second layer on top of the age gate.) We do not knowingly collect information from anyone under 18; if we learn we have, we delete it. If someone doesn't pass the age check, we record only an anonymous count that a block occurred, with a one-time random identifier tied to no account or profile. The app is not directed to children.
12Crisis and safety
Steel Magnolias is a peer-support platform; we are not a crisis service. Crisis resources are always available to you, free, regardless of whether you subscribe. If you or someone you know is in crisis, please reach out:
- 988: Suicide and Crisis Lifeline (call or text 988)
- 1-800-799-7233: National Domestic Violence Hotline (text "START" to 88788)
- 911: Emergency services
These resources are available 24/7 and staffed by trained professionals.
13Legal and medical information
Steel Magnolias is a peer-support platform that provides general information. We are not a law firm. We are not a medical or mental health provider. We do not provide legal advice, therapy, or medical advice. Whenever legal or medical topics come up, we recommend you consult a licensed attorney and/or a licensed mental health professional in your state for advice specific to your situation.
14International users
Steel Magnolias is intended for users in the United States. We do not target or knowingly offer the service to residents of the European Union, the United Kingdom, or other regions outside the United States. If you are outside the United States, please don't use the service or submit your information.
15Changes to this policy
We may update this policy as Steel Magnolias evolves. When we make significant changes that affect your rights, we'll notify members by email at least 30 days before the change takes effect, with a plain-language summary of what's changing and why, and we'll update the "Last updated" date above. If you'd like a copy of a previous version, email us.
16Contact us
For any privacy question, write to hello@steelmagnolias.app. We read every message, and you'll hear back from a person.
Our mailing address:
Steel Magnolias LLC 2108 N ST #16274 Sacramento, CA 95816
Steel Magnolias LLC · 2108 N ST #16274 · Sacramento, CA 95816