Privacy
Solarity is a goal tracker you share with a few friends. This describes exactly what it stores, who can see it, and when it goes away.
Last updated 4 September 2026
Who runs this
Solarity is run by Ryan Hang, one person, not a company. That means there is no support team standing between you and whoever holds your data: it is the same person either way. Questions, requests, or anything about your data: ryanhang07@gmail.com.
You must be 18 or older to use Solarity.
What is collected
- From signing in. Your email address, either way. If you use Google, also the name on your Google account — and Solarity never sees your Google password. If you sign up with a password instead, it is stored scrambled by Supabase in a form that cannot be turned back into what you typed, and nobody here can read it.
- Your profile. A username, an optional display name, an optional picture, and your timezone — which the app needs to know when your day ends.
- Your goals and check-ins. Goal titles, categories, the dates you checked in, and any note or photo you attached.
- Your Circles. Which Circles you belong to, your role in each, and when you joined.
- Notifications. If you turn on push, the address your browser gives us to reach that device, and a label for it. That address belongs to your browser's own push service — Apple, Google or Mozilla — so sending you a notification means contacting them.
- Your IP address. Every site sees one. Solarity does not store it in its database, but the hosting provider records it with the request, and opening an invite link counts an attempt against it so a stranger cannot guess their way into a Circle.
There is no analytics, no advertising, and no tracking across other sites. Solarity does not sell anything about you. The only email it sends is about your account — confirming your address and resetting your password — and there is no mailing list to be on.
Why it is collected
- To run the thing you signed up for. Your profile, goals, check-ins and Circles exist because the app cannot show you your streak or show your Circle your day without them. This is most of it.
- Because you switched it on. Push notifications and showing your streaks on your profile are both off until you turn them on, and turning them off again stops the processing.
- To keep it from being abused. Counting invite attempts against an IP address, and keeping reports, exist so a stranger cannot guess their way into a Circle and so there is a record when somebody posts something they should not have.
Nothing here is processed for advertising, profiling or any automated decision about you. There is no such system to opt out of.
Who can see it
Nothing here is public. Every page needs an account, and nothing is readable by search engines or by anyone signed out.
Your profile is visible to anyone with an account. That is your username, your display name, your picture and the month you joined. Anyone signed in who knows or guesses your username can open it — usernames are how people find each other, so they are not secret.
Your streaks and totals are off by default. They appear on your profile only if you turn them on in settings, and you can turn them off again at any time.
Everything else is limited to Circles you joined. Circles are invite-only and capped at ten people.
- Circle members see your username, your picture, whether you checked in today, and your streak.
- Notes are private unless you share them. There is a tick box on each note, and it is off by default. Un-sharing takes effect immediately and applies to notes you already wrote.
- Photos are visible by default to the Circles that can see the goal. A photo is the proof, so it is shared where the goal is.
- Hiding a goal hides its title, note and photo in that Circle, while still counting it toward your day. You can hide a goal in one Circle, in all of them, or none.
- Blocking hides your profile from someone and theirs from you. It does not remove either of you from a Circle you both joined, and they are not told.
Reports, and what a moderator can see
You can report a check-in photo, a check-in note, or a profile belonging to someone in one of your Circles. A report records what was reported, who reported it, and anything you typed.
An administrator can read the specific thing that was reported — that note or that photo — even if it was never shared with them, because there is no way to judge a report without seeing what it is about. They see nothing else: not your other goals, not your other days, and nothing nobody reported.
Administrators can mark a report reviewed, actioned or dismissed. The dashboard cannot delete your content or suspend your account; anything of that kind is done by hand and would be a separate decision.
Solarity is run by one person, so today that administrator is ryanhang07@gmail.com. Every grant or removal of that access is recorded.
How long it is kept
- Photos: 90 days. Then the image is deleted automatically. The check-in itself, and your streak, stay.
- Notifications and daily digests: 90 days.
- Goals, check-ins and streaks: until you delete them or delete your account.
- Your picture: until you replace or remove it. It has no expiry date, unlike a check-in photo.
- Reports, and the record of who was given moderator access: kept. Nothing deletes these on a schedule. A report is the only account of why something was actioned, and a record that expired would be no record at all.
Getting your data, and getting rid of it
Export. One JSON file, from your settings. It contains:
- your profile and timezone
- your streaks and totals
- every goal, with its category, deadline and dates
- every check-in, with its note
- which days you completed in full
- the Circles you are in, your role, and when you joined
Not in the file: your notifications, the devices you turned push on for, who you have blocked, reports you filed, your notification settings, your sun colour, when you accepted these terms, and your email address. Write to ryanhang07@gmail.com for any of those and you will get them.
Deletion. Delete your account from settings. It happens immediately and cannot be undone. If you would rather write, email ryanhang07@gmail.com from the address on your account and it will be done for you.
What deletion removes. Your account, your profile, your picture, your notes, your photos, your notifications and the devices you turned push on for. The picture and the photos are deleted from storage, not just unlinked.
Two things deletion does not do. Your check-in records stay, with your name and any note removed from them. They are part of other members' shared history — the days a Circle completed together — and erasing them would silently rewrite other people's streaks.
And a report keeps its shape without your name in it. If you reported something, or were reported, the report survives with the link to your account removed, as does the record of any moderator access that was granted or taken away. Both are accounts of a decision somebody made, and a decision with no record is not reviewable.
What you can ask for
Wherever you live, you can do all of these. Where you live may also give you a legal right to them, and the answer is the same either way.
- See it, and take a copy. The export above, plus anything it leaves out on request.
- Correct it. Your username, display name, picture and timezone are all editable in settings. Anything else, write.
- Delete it. One button in settings. The section above says exactly what stays and why.
- Object to something, or ask that it stop. Including the parts you did not switch on, like counting invite attempts.
- Complain to a regulator in your country, without asking here first.
Anything that is not a button gets an answer within 30 days, usually much sooner. Write from the address on your account so it is clear who is asking: ryanhang07@gmail.com.
Who else touches it
Solarity runs on other people's infrastructure. These providers process data on its behalf:
- Supabase — Database, file storage, and sign-in
- Vercel — Hosting. Its request logs include your IP address
- Upstash — Rate limiting. Invite links are counted against an IP address, so signed-out attempts reach it
- Google — Sign-in, if you use it. It tells Solarity your email address and the name on the account
- Brevo — Sends Solarity's email — confirmation links, password resets, and nothing else. It handles your address and the link
Where it is. All of it is stored and processed in the United States. If you are in the UK or the EU, using Solarity means your data goes there.
Cookies
Only the ones the app needs. They keep you signed in, remember whether you have already seen today's check-in screen, and remember that you dismissed a prompt.
There are no advertising or analytics cookies, and nothing here follows you to another site. That is also why Solarity has no cookie banner: there is nothing to consent to.
Security
Check-in photos and profile pictures both live in private storage and are served through links that expire within the hour. Every rule about who can read what is enforced by the database itself rather than by the app, so a bug in a screen cannot show someone a goal they were not meant to see.
If something goes wrong. If data is exposed in a way that puts you at risk, you will be emailed at the address on your account as soon as the scope is understood, and the relevant regulator told within 72 hours of it being discovered. That is a commitment from one person, not a team with a rota, which is exactly why it is written down here.
No system is perfect, and this one is early. If you find something wrong, please write.
Changes
If this changes in a way that matters, the date at the top changes.
It will not email you about a change. Solarity can send mail about your own account, but there is no announcement list and nothing that writes to everyone, so the honest version is that the date is the notice. If that ever changes, this paragraph changes with it.