Privacy Policy
Last updated: 6 August 2026
This policy explains what n1 Circle ("we", "us") collects, why, and what control you have. It applies to the n1 Circle website, apps and services.
The short version:
Your tracking data — protocols, logs, measurements, photos, journal — is private by default. Only you can see it unless you deliberately share a specific item.
We never sell your data, and there is no advertising on the platform.
Identity verification is performed by a specialist provider. We never receive or store your identity documents or biometric data — only a reference and the outcome.
The AI assistant reads your personal records only with your explicit consent.
You can export your data, and delete your account, at any time, in-product.
1. What we collect
Account. Email address, username (handle), display name, and any avatar or bio you add. When you sign up we record a timestamp of your confirmation that you are 18 or older. Sign-in uses one-time email codes, so we never hold a password for you.
Your private tracking data. What you enter in the tracker: protocols and their history, administration logs, vials and inventory, body measurements, progress photos, injection sites, and journal entries. We treat this as sensitive. It is private to your account by default, it appears in no feed and no search, and other members cannot access it by any route. It becomes visible to others only if you deliberately share a specific item (see section 6).
Community content. Posts, comments, polls, reactions, saves, follows, reports and direct messages, together with the audience you chose for each item.
Payments. Payments are processed by our payment processor (Stripe). We receive and keep transaction records — what was bought, when, for how much, and its status — but card details go directly to the processor; we never receive your card number.
Identity verification. If you choose to verify, the check (identity document, liveness, face match) happens with our verification provider (Didit). We receive a reference identifier and the result. Your documents and biometric data are processed by the provider under their privacy terms and are never transmitted to or stored by us.
Technical and security data. Standard logs: requests, timestamps, approximate device and browser information, and security signals such as hashed identifiers used for rate limiting and abuse prevention. Our sign-in protections are deliberately built so that even our own logs do not reveal whether a given email or username has an account.
2. How we use it
To provide the platform: your tracker, your subscriptions and entitlements, the community and its audience rules, notifications you have opted into, and support when you contact us. To keep the platform safe: rate limiting, abuse prevention, and moderation — including automated screening of new posts. To bill you correctly. And to fix problems, using error and performance monitoring.
We do not use your content or data for advertising, and we do not sell it to anyone.
3. The AI assistant and automated screening
If you subscribe to the AI assistant, your questions and the material needed to answer them are processed by our AI provider to generate the response. Retrieval is permission-checked: the assistant can only draw on content your account is allowed to see. Your private records are included only when you explicitly consent, and you can withdraw that consent at any time in settings.
Community posts may be screened automatically at submission to flag likely rule violations for human review.
We do not use your data to train AI models. Our AI providers process it to deliver the feature.
4. Who we share data with
We share data only with the service providers that run the platform, and only what each needs: database and infrastructure hosting, web hosting, payment processing (Stripe), identity verification (Didit), email delivery (Resend), AI processing, and error monitoring. Each processes data on our behalf to provide their service.
Beyond that, we disclose data only if the law requires it, to protect the safety of members or the public, or to enforce our terms. If n1 Circle is ever part of a business transfer, your data would remain protected under a policy at least as protective as this one, and you would be notified.
What *other members* see is governed by your choices: your profile and community posts are visible to their chosen audience; verified-only content is visible to verified members; your private tracker is visible to no one.
5. Photos and metadata
Progress photos live in private storage with signed, expiring access — there is no permanent public link to them. When you choose to share a photo to the community, we create a separate copy with location and device metadata (EXIF/GPS) removed, show you a preview of exactly what will be visible, and publish only that scrubbed copy. If a shared post is deleted or its audience changes, the shared copy is removed or restricted accordingly. Your original stays private.
6. Sharing from your tracker
Nothing in your private tracker is ever attached to a post automatically. Sharing is item-by-item: you select exactly what to include, choose the audience, and see a final preview before anything is published. Remember that restricted visibility is not confidentiality — verified members can see what you share to verified spaces.
7. Retention and deletion
You can delete your account in settings at any time. Deletion takes effect immediately — your account and content disappear from every feed and search — and your data is permanently deleted after a short grace window that exists so an accidental deletion can be reversed. Deletion revokes your sessions and notification subscriptions and removes your private media.
Some records survive account deletion where we have a legitimate need to keep them: payment and billing records, and moderation and safety records (kept so that enforcement cannot be erased by deleting an account). These are kept only as long as needed for those purposes.
You can export your data from settings at any time.
8. Security
Data is encrypted in transit. Access is controlled at the database layer with row-level security on every table, private media uses signed expiring links, and administrative functions are locked to specific roles and audited. No system is perfectly secure, and we make no absolute promises — but the platform is built so that the failure of any one layer does not expose your private data, and we test those boundaries as part of building every feature.
9. Your choices and rights
In-product, you can: view and edit your information, export your data, control every notification category, manage AI consent, and delete your account. Depending on the law that applies to you, you may also have rights to request access, correction, deletion or portability of your personal data, or to object to certain processing. To exercise anything you cannot do in-product, email hello@n1circle.com — we respond to every request.
10. Cookies and local storage
We use them for what the platform needs to work: keeping you signed in, remembering preferences, and device-local conveniences like recently viewed compounds and favourites. We do not use third-party advertising cookies.
11. Age
The platform is for adults 18 and over. We do not knowingly collect data from anyone under 18; if we learn we have, we delete the account and its data.
12. Changes and contact
If we change this policy in a material way, we will notify members through the platform or by email before the change takes effect.
Privacy questions and requests: hello@n1circle.com.