Privacy Policy
Your data is private by architecture.
Individual EPI data is never shared with any organization, employer, coach, or administrator. This is a design principle, not a policy setting.
Effective date: January 1, 2025 · Journey One LLC
1. Information We Collect
2. How We Use Your Information
3. Sharing and Disclosure
4. Individual Data Privacy
5. Data Retention
6. Security
7. Children's Privacy
8. Changes to This Policy
9. Contact
1. Information We Collect
We collect information you provide directly when you create an account (name, email address, and password), and information from music streaming services you connect (Apple Music or Spotify). From streaming services, we receive your listening history and playlist data — we do not store your streaming credentials. We also collect standard server log data (IP address, browser type, pages visited) for security and performance purposes.
2. How We Use Your Information
We use your listening behavior to calculate your EPI Score™ — a weekly measure of your emotional performance state. Your individual EPI Score is private to you. When CHRP® is deployed in an organizational context (sports teams, military units, enterprise), organizations see only anonymous aggregate trends — never individual data. We use your email address to send you product updates and account-related communications. We do not sell your data.
3. Sharing and Disclosure
We do not sell, rent, or share your personal data with third parties for marketing purposes. We may share data with service providers who assist in operating our platform (hosting, analytics) under strict confidentiality agreements. We may disclose information if required by law or to protect the rights and safety of CHRP®, our users, or the public. In the event of a merger or acquisition, user data may be transferred — we will notify you in advance.
4. Individual Data Privacy
Your individual EPI Score™ and listening behavior data are private by architecture. No organization, employer, coach, or administrator that uses CHRP® has access to your individual data. Organizational users see only anonymous, aggregated trends across their group. This is a core design principle, not a policy setting — it cannot be overridden by an organizational administrator.
5. Data Retention
We retain your account data for as long as your account is active. Listening history data used to compute your EPI Score is retained on a rolling basis. You may request deletion of your account and associated data at any time by contacting us at privacy@chrp.ai. Deletion requests are processed within 30 days.
6. Security
We use industry-standard encryption for data in transit (TLS) and at rest. We do not store your Apple Music or Spotify credentials — authentication is handled via OAuth. Our security practices are described in detail on our Security page.
7. Children's Privacy
CHRP® is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will delete it promptly.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on our website. Your continued use of CHRP® after the effective date of the revised policy constitutes your acceptance of the changes.
9. Contact
Questions about this Privacy Policy or our data practices? Contact us at privacy@chrp.ai.