Mr. Chud ← Back to mrchud.com Back Contact support
Privacy Policy

What we collect. What we never touch.

Mr. Chud only works if you can be brutally honest with it. So here’s the honest version of how your data works: no legalese walls, just the actual truth.

Last updated · September 4, 2026

Summary

  1. 01One log a day, no reruns
  2. 02What you write never reaches your friends
  3. 03Zero ad networks, zero data sales
  4. 04Nothing goes to an AI service until you say yes
  5. 05Delete your account, delete your data
01 · What we collect

It’s a short list. We only ask for what actually makes the app work.

Read this first · screen recording

The app records your screen while you use it. That is on by default, and you can turn it off in the app: Settings, under PRIVACY, the row called “analytics and recording.” Turning it off stops the counting and the recording on your phone, straight away. Text and pictures are meant to be blanked out on your device before a frame is ever stored, and on August 29, 2026 we checked one of our own recordings and found that this does not always work: ordinary interface text read back off it, and an account email address was legible in the box it had been typed into. We have written the correction, and until frames from a corrected build have actually been looked at we will not tell you a recording cannot hold something you had on screen. The bullet below headed “A recording of your screen” is the full account, including how to have your recordings deleted today rather than in 30 days.

  • Your email address: to create and secure your account (via Supabase Auth).
  • What Sign in with Apple or Google hands us: if you choose one of those buttons instead of an email code, the provider returns a unique account identifier, your email address (Apple’s may be a private relay address), and your name if you let it through. That is the whole of it. We ask for no other permission, we never read your Gmail, contacts, calendar, files or photos, and we never post anything anywhere on your behalf. What comes back is stored in Supabase Auth purely to be your login, is used for nothing else, is never sold, shared, or used for advertising, and is deleted with the rest of your account.
  • Your display name: the name your friends see, and the name that appears on anything you post to the public community board.
  • Your daily log: whatever you say, and whatever you type alongside it. A log now takes a voice note, so almost every day you log carries a recording, and that recording is kept as well as transcribed. The demand lifts in exactly two situations, both of them a door that is shut rather than a preference: a microphone your phone will not ask you about again, and a transcription service that will not answer. It never lifts because you would rather not, and there is no setting for it. The audio goes to OpenAI to become the text your score is generated from, which happens only after you have agreed to it on the screen described in section 03, and the file itself is stored in a private bucket where the friends you have accepted can press play on it for 14 days. The file is then deleted outright once it is 30 days old, whether or not you ask. Section 04 has the detail on who can hear it.
  • Your device’s time zone: a zone name like “Asia/Kuala Lumpur”, stored on your profile so a “day” ends at your midnight and not ours, and so an evening reminder fires at the hour you picked. It is a zone name, never a coordinate.
  • Your health score: the number your log generates, plus the average of your last 14 logged days.
  • Anything you post to the community board: the feature requests, comments, and votes you choose to submit. These are public by design, carry your display name, and are handled by Canny (see section 03). Nothing on the board is private; your daily logs never appear there.
  • Photos you attach to a day: at least one, and up to six. A photo is no longer something you add if you feel like it, it is part of what a log is. The demand lifts only if the picker on your phone will not open at all, which is the photo half of the same rule: compulsory for anyone who can, never impossible for anyone who cannot. The files live in a private bucket, and adding one grants your accepted friends’ accounts read access to it for the next 14 days. There is no per-photo private setting, so treat anything you attach as shared with your circle. Remove one and it comes off your day for everyone. Section 04 has the detail.
  • Your spoken promise: the one line you read out loud when you set up. The audio goes to OpenAI to be turned into text, and that text goes to Anthropic to check you actually said the line. This is the first thing the app ever sends to an AI service, so it is the moment the app stops and asks your permission: section 03 has the screen, the field-by-field list of what each company receives, and what neither of them is given. The clip itself is then kept, in a private folder that only your own account can read. That is the difference between it and a spoken daily log: a daily log is audible to your accepted friends for 14 days, and your promise is audible to nobody but you. It goes when your account goes.
  • Product analytics: Mr. Chud ships PostHog, and it is the only analytics SDK in the app. It records what you did, and separately it records your screen, which is described in full in the next bullet. Both stop when you turn analytics off in Settings. The event stream itself carries only: named product events (opened the app, finished onboarding, logged a day, saw the paywall), the screen you’re on, your Supabase user id, your app version, and your platform. It also records a recording of your screen, which gets a bullet of its own below because it needs more than a clause, and that bullet is the one to read. The PostHog SDK also attaches ordinary technical context to each event by itself: your device model, OS and OS version, app build, screen size, timezone and the SDK version. We tell PostHog to skip its IP-based location lookup, and that part does what we said it does: on August 30, 2026 we counted every event the app sent in the previous week, and not one of the 1,207 of them carried a city, a region, a postcode, a country or a coordinate. Here is the part we will not round off, because this page had it wrong until today. Skipping the lookup does not throw away the address the lookup would have read. Your phone reaches PostHog over the internet, so every event arrives carrying your IP address. An IP address can be resolved to an approximate place by whoever holds it. We already say exactly that about Sentry, two bullets below, and it was not honest to say it there and not here: this page used to tell you that an event from a recent version of the app arrives with no location on it at all, and the address had been sitting on every one of them the whole time. There is a setting on PostHog’s side that discards that address as the event lands instead of storing it. We switched it on on August 30, 2026. We checked it rather than assuming it: we sent one event just before the change and one just after, from the same computer on the same connection, and the earlier one has an address stored against it while the later one has none at all. It needed no update from you, and because it happens where the event lands rather than where it is sent, it covers every version of the app at once, including old ones already on phones that we can no longer change. Events sent by older versions, before the lookup switch existed, carried more than the address: a coarse city, a postcode and an approximate latitude and longitude, every one of them worked out from that same IP address and never from your device, and those older events are still in our analytics under your user id. The last event to carry a coordinate was sent on August 19, 2026. None of it comes from GPS, we never ask your device where it is, and we do not use any of it for anything. Section 04 has what happens to that record when you delete your account. The code enforces a hard no-content rule on events: every property that goes out on one is an enum, a boolean, a count, or a coarse band, so entry text, reflections, your Chud’s name, your username, your email and any token are structurally incapable of ending up in an event. That rule is about events, and it is not the whole story, because a screen recording is not a property and no rule about properties reaches one. Masking is what is meant to keep content out of a recording, and we are honest below about the day we found it does not always manage it. The next bullet is that, in full. Even your score goes in as a band (“60-79”), never the words behind it. It runs on our own PostHog project, it is used only to see which parts of the app work, and it is never used for advertising or joined with your activity in any other app or website.
  • A recording of your screen: PostHog also records the session itself. It is on by default, and there is a switch for it in the app: Settings, under PRIVACY, the row called “analytics and recording.” That screen names PostHog, says what a recording holds, and turns both the counting and the recording off on your phone the moment you press it. It is saved on your device, so it survives signing out. What a recording is for is the shape of the session: which screen you were on, where you tapped, what you scrolled past, how long you sat there, and the order you did it in. Text and pictures are meant to be covered over on your phone, inside the recorder, before a frame is stored, so that the words of your log, the transcript that came back, the reflection you typed, your promise, your Chud’s name, your username, your email and every photograph on your day leave your device as blank blocks. On August 29, 2026 we checked one of our own recordings, and that did not reliably happen. Ordinary interface text read back off it plainly, and on the sign-in screen an account email address was legible in the box it had been typed into. We are not going to tell you a recording never holds content when we have watched one hold an email address. Why it happens is worth a sentence, because it tells you what to expect: what leaves your phone is a picture of the real screen with rectangles painted over the parts that are not meant to be read, so every frame carries the real pixels underneath, and a rectangle that lands in the wrong place, or never gets worked out at all, leaves what is under it showing. The parts we have not caught leaking are not therefore safe. The account in that recording had no entries and no photos on it, so there was no log text and no picture on the screen to leak, and we have not yet watched a single frame of the writing screen or the reading screen. The system photo picker is drawn by a screen this app does not control and the recorder is told to cover those too, which is the same kind of promise as the rest of this paragraph, so read it the same way. We have written a correction to the masking and it travels with the app rather than with this page, so until frames from a corrected build have actually been looked at, treat anything the app draws on your screen as something a recording may hold, legibly. That is also the plainest reason the switch above exists. The rest of this has not changed and is worth having straight. A recording is never shown to your friends, never sold, never used for advertising, and never sent anywhere outside the processors in section 03. The recorder’s console and network channels are switched off, so a log line or a request address is not a second way out. A recording is deleted 30 days after it is made. Beyond the switch in the app there are two further controls and both work today: recording is also governed by a single setting on our side, which the app re-reads every time it starts, so it can be stopped on every phone at once without shipping an update, and if you would rather we held none of your recordings at all, email us and we will purge them now along with the rest of your analytics record.
  • Crash diagnostics: Mr. Chud ships Sentry, and it is the only crash-reporting SDK in the app. When the app crashes or hits an error it sends Sentry the error and its stack trace, your app version and build, your device model, OS and OS version, and your Supabase user id, so a crash can be tied to a session rather than guessed at. Sentry is never sent a screenshot, a view hierarchy, or a session recording: an unmasked picture of this app is a journal entry, so all three are switched off in the code and are meant to stay off. The screen recording described just above is PostHog’s, and none of it is ever copied here. It never receives the text of a log, your reflection, your Chud’s name, your username or your email. One thing we will not round off: the report travels over the internet to Sentry’s servers, so Sentry’s own systems see the IP address the request arrives from, and an IP address can be resolved to an approximate country and region. We never ask your device for its location, no coordinate is stored on a crash report, and we do not use that region for anything. Separately, Apple and Google may hand us their own crash reports through App Store Connect and Play Console, and only if your device is set to share diagnostics with them.

That’s it. No GPS or precise location, no contacts access, no browsing history, no advertising identifiers, and no microphone access outside of two moments: the voice note a daily log requires, and the promise you read out loud at setup. Both of those are asked for where they happen, and neither is asked for before it happens. On both platforms the microphone dialog is raised by the recorder you are looking at, the first time you press record on it. In practice that is during setup, on the promise step, because reading the promise out loud is the first recording the app ever asks anyone for; if you reach the log first, the log raises it there instead. Before either of those, and before anything is sent to a transcription service, the app shows you the AI permission screen described in section 03. Your photo library is never opened: the picker that appears belongs to iOS or to Android, it runs outside this app, and what comes back is the pictures you tapped and nothing else, so Mr. Chud has no reading of your library and never asks for one.

02 · What we never share

This is the part we take the most seriously, because it’s the whole reason you’d trust the app enough to be honest in it.

  • The text of your entry is stored in your own row in our database, because that row is what makes your “Days” calendar work months later. As text, it goes to Anthropic for exactly as long as it takes to score it, it never goes to your friends, and it is never sold or handed to an advertiser. One exception belongs in this sentence rather than three paragraphs further down: unless you have turned recording off, your screen is being recorded, and the masking that is meant to keep your words out of those frames does not reliably work. On August 29, 2026 we read legible text off one of our own recordings, so a picture of your entry, as it looked on your screen, may be sitting in a recording held by PostHog. That is a second processor holding your words, and we are not going to call it anything else. The switch is in Settings under PRIVACY, and section 01 is the full account. The audio of the voice note goes to OpenAI to become that text, and the recording is then kept on our side: the friends you have accepted can play it for 14 days (section 04). They get the sound of your day and nothing else. Apart from what a screen recording may have caught, the text of the entry, the reflection you wrote on it and every caption stay with you. The third bullet in this section, and the recording bullet in section 01, are the full account of that exception.
  • Mr. Chud is one person, and that person can technically query the database your row sits in. Nobody reads your entries as a matter of routine, and no feature anywhere in the app shows the text of one of your entries, or the reflection you wrote on it, to anyone but you. We used to say flatly that no other company is given access to them. That is no longer a promise we can make without a caveat: a screen recording is meant to cover text over before it leaves your phone, and on August 29, 2026 we found that it does not always manage it, so a recording held by PostHog could contain something drawn on a screen you were looking at. That is the failure described in section 01, we are fixing it, you can switch recording off in Settings under PRIVACY, and it is the reason this sentence now carries an exception instead of an absolute. Section 04 is exact about what a friend does reach, and it is the score a day earned and never the words behind it.
  • The screen recording described in section 01 is the one place where this section has a hole in it, and we would rather point at it than paper over it. Masking does happen on your phone, inside the recorder, before a frame leaves the device, but on August 29, 2026 we read legible interface text and an account email address out of one of our own recordings, so we cannot tell you that no copy exists anywhere in which the text of your entry, your reflection, your promise or a photograph is readable. What we can tell you is that a recording is never shown to your friends, never sold, never used for advertising, and never sent to anyone outside the processors in section 03, and that it is deleted after 30 days or sooner if you ask. Section 01 has what we know, what we have not been able to check, and how to have yours deleted today.
  • We do not sell your data. Ever. To anyone. Full stop.
  • We don’t run ads and there is no ad-network tracking code anywhere in the app.
  • Your entries are never used to train anyone else’s model beyond what’s strictly needed to score that one entry.
In plain words

Your friends see your scores, your streak and level, your Chud, and the two names you chose: your display name and the name you gave him. A log now takes a photo and a voice note, so almost every day you log grants their accounts read access to a picture for 14 days and lets them play a recording for 14 days. They can also open your card and page back through a calendar of your days, which gives them a date and the score you earned on it, with no cut-off and for every month your account has existed. They never see the text of your entry, or the reflection you wrote on it, on the board or in that calendar. That line doesn’t move.

03 · Who handles your data

We use a small number of outside services (“processors”) to run Mr. Chud. Each one only gets what it needs to do its single job. None of them get the full picture, and none of them may use your data for anything beyond running the app.

Two of them are AI services, and this is the whole of what they get

AI services · what is sent, who it goes to, and your permission first

Two of the processors on this page are outside AI companies: OpenAI, which turns speech into text, and Anthropic, which reads the text of a log to generate your score. Every single thing Mr. Chud sends to an AI service is one of the four rows below, with two additions we would rather spell out than let you discover. If the Anthropic read comes back with a severe self-harm finding, we send that same entry text to Anthropic once more to check that specific finding before the app acts on it. And a nightly server job sends Anthropic a single full stop and asks OpenAI to describe the transcription model, purely to check our two keys are still alive; that job carries nothing of yours. Apart from it, nothing goes on a schedule or in the background, and nothing containing your words goes without you starting it.

We ask you before the first one, inside the app. Setup reaches a step where you record a spoken promise, and that recording is the first moment any of this could happen. On that step, before the microphone opens, the screen itself names OpenAI and Anthropic, says what each one receives and what it does with it, and states what never leaves your phone. The button you press to record is the agreement, and it is labelled that way. Nothing is sent unless you press it. Next to it, a decline continues setup without recording and without sending anything. A link on the same panel opens the full detail without leaving the app, and you can change your answer later in Settings. Settings links back to this page whenever you want to read the long version again.

Your daily voice note to OpenAI

What is sent: the audio file, the name of the transcription model, and a language code so it decodes in the language you speak. That is the entire request. It carries no name, no email address, no account id, no device id, no time zone, no tags, no photos, no score, and nothing you have written on any other day. What it is used for: turning what you said into the text of that day’s log, which is the text your score is generated from. OpenAI hands the text back and its job is finished.

Your spoken promise to OpenAI

What is sent: the audio of the one line you read out loud at setup, the model name, and a language code. Nothing else. What it is used for: turning that line into text so the next step can tell whether you said it. This one happens during setup, before you have an account at all, so there is no identity in existence to attach.

The text of your daily log to Anthropic

What is sent: the text of that one entry, and nothing else. Typed and dictated text are the same thing by this point, because a voice note has already become text. We would rather be exact about the part people assume: the tags you picked, the mood you picked, your photos, your display name, your email address, your account id, your time zone, your streak, your level, your earlier entries and every score you have ever had are not in the request. What it is used for: reading that entry once, choosing the plain-language ratings your 0-100 score is computed from, and writing the short reflection you read afterwards. The number itself is worked out by our own code, not by the model.

The transcript of your promise to Anthropic

What is sent: the text that came back from the transcription above, quoted inside a fixed instruction we wrote. No audio, no name, no email address, no account id. What it is used for: deciding, once, whether you made a genuine attempt at the line, so that reading it aloud means something. It answers yes or no, and nothing from that answer is stored against you.

Equal protection, which is a statement about them and not only about us. We confirm that every processor named on this page provides protection for what it receives that is the same as, or equal to, the protection described here. That covers Supabase, PostHog, Sentry, RevenueCat and Canny on the same terms as the two AI services, because the obligation follows the data rather than the category of company, and because the screen-recording hole described in section 01 involves a processor that is not an AI service: each is engaged as a processor, each may use what it receives only for the single job named in its card, none may sell it, use it for advertising or pass it on for another party’s own purposes, and each is bound to hold it securely. The two AI services are bound by that list under the commercial API terms we accepted with them, and they carry one obligation beyond it that is worth naming on its own: neither may train a model on what we send. Anthropic’s Commercial Terms of Service put it in those words, verbatim: “Anthropic may not train models on Customer Content from Services.” OpenAI’s published enterprise privacy page states that data from its API platform, after March 1, 2023, is not used to train its models unless the customer has explicitly opted in, and we have not opted in. We read both of those pages ourselves on September 3, 2026, and we have linked them below so you can check us rather than believe us.

And here is what we will not state, because we could not verify it. Neither request asks either company to keep anything, and neither carries a zero-retention flag, so whatever each one holds afterwards is its own default rather than something we chose. OpenAI’s own page, read on the date above, says it may securely retain API inputs and outputs for up to 30 days to run the service and identify abuse, and removes them after that unless it is legally required to keep them. We did not find an equivalent published figure for the Anthropic API, so we are not going to print a number for it, and we would rather admit that than round it off. Whatever either company holds is governed by its policies rather than ours. We hold no account of yours with either of them, so there is nothing on their side filed under your name for us to go and delete.

Read them at first hand: OpenAI privacy policy, OpenAI enterprise privacy, Anthropic Commercial Terms of Service, Anthropic Privacy Center.

Everyone else who handles your data

Supabase Singapore region

Hosts your account and database. Your email, scores, streaks, and log metadata live here.

Anthropic AI scoring

Reads the text of your daily log for exactly as long as it takes to generate your 0-100 score. It also reads the transcript of your setup promise, once, to judge whether you said the line. That’s its entire job. The block at the top of this section, what the AI services get, lists field by field what is in each of those two requests and what is deliberately left out of them, and it is where the permission you give first is described.

OpenAI (Whisper) speech to text

Turns speech into text, in two moments and no others: the voice note every daily log carries, and the promise you read out loud at setup. OpenAI’s only job is the transcription, and it never receives anything else about you. What happens to the clip afterwards is decided on our side, not theirs, and it is no longer thrown away: a spoken daily log is kept in a private bucket and is playable by the friends you have accepted for 14 days (section 04), and the promise clip is kept privately to you alone. Neither half is a preference any more: a log needs a voice note, so OpenAI transcribes a recording on almost every day you log, and the promise was always spoken by design. Section 01 names the two situations where the app stops asking for one, and neither of them is you choosing to skip it. The block at the top of this section, what the AI services get, lists exactly what is in a transcription request and what is not, and it is where the permission you give first is described.

RevenueCat subscriptions

Manages Mr. Chud Prime: your plan, trial status, and renewal dates. It is handed your Supabase user id when you sign in, so a subscription follows your account rather than the handset you bought it on. It never sees your logs or your score.

Canny optional · community board

Runs the public feature-request board inside the app. The first time you open it, we create a Canny user for you carrying your display name and email address. The email is how we recognise you across posts, and it is never shown to other users. Anything you post, comment, or vote on lives in Canny. It never sees your logs or your score, and if you never open the board, nothing about you is ever sent there.

PostHog product analytics

Counts what happens in the app so we know which parts work: product events, the screen you’re on, your app version and platform, attached to your Supabase user id. It also receives a screen recording of your session: where you tapped and in what order, drawn on a picture of the screen you were looking at, with masking applied on your phone that is meant to cover every piece of text and every image. On August 29, 2026 we found that it does not reliably cover them, and an account email address was legible in one of our own recordings. Both of these stop when you turn analytics off, in Settings under PRIVACY. Recordings are deleted after 30 days. An event still carries no content, because the app cannot put any into one; a recording is the part we will not promise for, and section 01 is the long version. Like any server it sees the IP address an event arrives from, which places you in an approximate region. The location lookup is off, so no city, postcode or coordinate is worked out from it, and since August 30, 2026 the address itself is discarded as the event lands rather than stored on it. No advertising, no cross-app or cross-site tracking.

Sentry crash reports

Receives a report only when something breaks: the error, its stack trace, your app version and build, your device and OS, and your Supabase user id. Never a screenshot, never a view hierarchy, never a session recording, and never a word you wrote. The screen recording in PostHog’s card is not shared with it. Like any server it sees the IP address a report arrives from, which places you in an approximate region; we never use it and never ask your device where it is.

04 · What your friends see

Your circle sees both of the names you typed: your display name, and the name you gave your Chud, which the board prints next to it on every card. They also see the art style you picked for him, his current state on the ten-step ladder (Goated, Locked In, Mid, Fell Off, Cooked, Burnt, Wrecked, Folded, Walahi, Big L), your health score and its daily delta, your streak, and your level. The number the board shows by default is the average of your last 14 logged days, the same number your Chud wears. The board can also be switched to a single day, and on that one a friend who has not logged that day reads as no log rather than as a number. On the average board there is a number for everyone who has ever logged, including someone who stopped weeks ago: their average simply holds where their last 14 logged days left it. Those are 14 days they logged, not the last 14 days on the calendar, so an average can be older than it looks, and a friend who has been away still shows one. Their copy of your row is also told how many days it has been since you last logged, whether or not the card prints it.

Your accepted friends are also granted access to the photos you attach to a day. Every photo you add is shared with them the moment you add it, there is no per-photo private setting in the app, and the grant reaches back 14 days and no further. Remove a photo and it comes off your day for everyone. The leaderboard prints those photos on your card, so your circle sees them as pictures and not only as a permission. A log now requires at least one photo, so this is no longer a thing that happens on the days you opt into it. Treat any day you log as a day your circle gets a picture from. If you would rather a day stayed yours alone, the only way left is not to log it.

A log now requires a voice note (section 01 has the two narrow cases where that demand lifts), so there is a recording of your voice on almost every day you log, and your accepted friends can press play on it, on your card on the leaderboard, for 14 days from the day you logged it. After that the clip expires and is deleted, and the card simply says there is no voice note for that day. What crosses is the audio and nothing else: not the transcript it produced, not your reflection, not a caption. Blocking someone, or the clip being reported, ends their access to it immediately. Typing more is not a way around this one: the words you type are still yours alone, and the recording still goes out. If you would rather a day was not audible to anyone, the only way left is not to log it.

Your circle can also open your history. Your card on the leaderboard opens a calendar of your days, laid out the same way as the one on your own Days tab, and a friend can page back through it a month at a time. Two things cross, per day: the date, and the score that day earned. Nothing else on the day is sent to them. Not the text of your entry, not the reflection, not the notes the model wrote while it was scoring you, not your running average at that point in time, and no handle that would let their app ask for any of it.

There is no cut-off on this one, and that is the part to read twice. The photo grant and the voice grant stop at 14 days. The calendar does not. It reaches back as far as your account does, so a friend who joined your circle today can page back to the score you earned on your very first day, and will still be able to next year. A day you did not log has no tile, so what they read off that calendar is also which days you skipped. A day you logged that never got a reading shows as logged with no number against it. Photographs and recordings are not part of this: page back into a month older than 14 days and there is nothing to look at and nothing to play, only dates and numbers.

Only an accepted friend can open it, blocking someone ends it in both directions the moment the block exists, and removing someone from your circle ends it outright.

They never see the text of your entry, or the reflection you wrote on it, on the board or in that calendar. The board and the calendar both run on the score, not the confession behind it. That’s the whole design.

The community board is the one public surface: posts, comments, and votes you make there are visible to every other Mr. Chud user, under your display name. Your logs and scores are never posted there for you.

05 · Retention & deletion

We keep your logs and scores for as long as your account exists. That’s what makes your “Days” calendar and campaign progress work over months. Read that line together with section 04: because we keep the scores, and because your circle can open a calendar of them, the length of your account is also the length of a friend’s reach into your score history. Deleting your account is the only thing that shortens it.

Photos are the exception, and they expire on their own. A scheduled job deletes every attached photo once it is 90 days old, whether or not you asked. Your friends’ access to one runs out much sooner than that, at 14 days.

Spoken daily logs expire too. A recording carries its own expiry from the moment you log it: 30 days, after which it is deleted from storage by a scheduled job. Your friends’ access runs out well before that, at 14 days. The text it was transcribed into stays with your day, because that is what your calendar and your score are built on.

Screen recordings run out on the same 30-day clock. The recording PostHog makes of a session is deleted 30 days after it is made. What is inside one is section 01’s subject: the masking that is meant to cover every word and every picture does not reliably do it, so treat a recording made today as something that may hold readable content until the clock takes it. Two ways to shorten that. Turn recording off in Settings under PRIVACY, and no new one is made. Or, if you would rather not wait out the 30 days on the ones already made, email us and we will purge yours now.

Delete your account, delete your data

Delete your account and your data goes with it: email, entries, scores, history, the photos on your days, any spoken logs still inside their 30 days, the promise clip you recorded, and your Canny identity (name, email, and votes). Not hidden, not anonymized. Deleted, from Supabase and from Canny. Anthropic and OpenAI only ever receive one entry or one clip at a time, to do one job, and we hold no account of yours with either of them, so there is nothing on their side filed under your name for us to delete. What each of them retains under its own API policies is governed by those policies rather than by ours: section 03 quotes the one published figure we were able to read for ourselves, OpenAI’s up to 30 days for API inputs and outputs, and says plainly that we did not find an equivalent published figure for the Anthropic API and will not invent one.

Two honest limits. Your subscription record lives with Apple or Google and with RevenueCat, who keep it as a billing record. It is not ours to erase on request, it never contained a log, a score, or a word you wrote, and after deletion it points at an account that no longer exists. Your analytics events, and any screen recordings still inside their 30 days, sit in PostHog under your old user id. The events hold nothing you wrote. A recording may, for the reason section 01 gives, so ask and we will purge that person record and its recordings outright rather than leaving them to run out the clock.

One honest exception. Anything you posted to the public community board (feature requests and comments) stays on the board after you leave, because other people voted on it and replied to it. Your name comes off it: deleting your account strips your identity from those posts and they show as written by “a chud.” If you want a specific post taken down entirely, email us and we’ll remove it.

06 · Children

Mr. Chud is meant for people 13 and up. If you’re under 13, please don’t use it. If we learn that a user is under 13, we’ll delete the account.

07 · If this policy changes

This policy will keep evolving as the app does. When it changes, we’ll update the date at the top of this page, and we’ll notify you in-app before anything meaningfully different takes effect.

Questions?

Ask us anything, including “why did my Chud rot this week.” Mr. Chud is currently a one-person operation, run by Ben Yap, based in Malaysia.

benyap1220@gmail.com
Mr. Chud
Molded with care · no Chuds were harmed, yet
Privacy Terms
© 2026 mrchud.com