NAP product guide
How NAP stores, exports and deletes your information
NAP keeps information in two quite different places: your own browser, and — only if you choose to create one — your account. Which one applies depends on the tool, and the difference decides what you can export and what deletion can actually reach.
This guide is a plain description of the behaviour that is built today. It supplements the Privacy Policy and does not replace it; where the policy is more specific, the policy governs.
It deliberately makes no claim about encryption, backups, retention or deletion guarantees beyond what can be demonstrated in the product itself.
Last reviewed 2026-08-28
The two places information lives
- Browser-local: stored by your browser on the device in front of you. It never reaches NAP, it is not visible on your other devices, and clearing your browser's site data removes it.
- Account-backed: stored in NAP's database against your account, readable only by you when signed in, available on any device you sign in from, and included in your account data export.
Nothing moves from the first to the second on its own. Where a tool offers to copy device information into an account, it is an explicit control you press, and it is described in that tool's own guide.
Tool by tool
| Tool | Account required? | Where it is stored | Sync between device and account | Export | Delete or reset | Removed by account deletion? |
|---|---|---|---|---|---|---|
| Daily NAP Planner | No | Browser-local by default; a day becomes account-backed only when you press save while signed in | None. Saving is an explicit press, in one direction only | Saved days are in the account JSON export; a share-card PNG can be drawn on your device | "Delete my local planner data" on the planner; saved plans deleted from account privacy settings | Saved plans yes; the browser copy no |
| Sleep & Nap Journal | No | Browser-local when anonymous; account-backed when signed in and saved to the account | None automatically. A counted copy control moves device entries in when you ask | CSV and JSON from the journal; account entries also in the account JSON export | Per entry, "Clear device copies", or account deletion | Account entries yes; device entries no |
| Low-Energy Rescue Plan | No | Browser-local only. There is no account version of this tool | Not applicable | Plain-text download, or print and save as PDF | "Reset and delete from this device" | No — it is not in your account at all |
| Quick Start Pack (browser version) | No | Browser-local only | Not applicable | Download the PDF, or print what is on screen | The reset control on the pack page, or clear browser data | No — it is not in your account at all |
| NAP Recap | Yes | Account-backed. It describes what you already recorded; an optional reflection is saved to your account | Not applicable | Text export of the recap; reflections are in the account JSON export | Delete your account, or delete the underlying planning data | Yes |
| What tends to help? | Yes | Account-backed, readable only by you | Not applicable | CSV and JSON from the library; also in the account JSON export | Delete an entry, or delete your account | Yes |
| Limited-beta feedback | No | Stored by NAP with no account link and no raw IP address or browser user-agent; a keyed HMAC digest of the request address is kept separately for abuse prevention | Not applicable | No self-service export, because it is not linked to an account | No self-service deletion; kept up to 12 months, contact addresses removed within 90 days or when follow-up ends | Not linked to your account, so it cannot reliably be associated with you — an optional contact email may be separately present if you supplied one and consented |
| Account and profile information | Yes | Account-backed: sign-in details, preferences and consent history | Not applicable | In the account JSON export | Two-stage account deletion in account privacy settings | Yes, apart from a record that consent was withdrawn |
The same information without a table
If the table above is hard to read on your screen, here is the essential version in prose.
- The planner, journal, Rescue Plan and Quick Start Pack all work without an account, and by default keep what you write in your own browser.
- Only two of them can also store information in an account: the planner, when you press save, and the journal, when you save an entry while signed in or copy your device entries across.
- The Rescue Plan and the browser Quick Start Pack have no account version at all, so account deletion cannot remove them — you reset them yourself on the device.
- NAP Recap and "What tends to help?" require an account, are readable only by you, and are removed when your account is deleted.
- Feedback is not linked to your account, which also means it cannot reliably be associated with a person for self-service export or deletion. An optional contact email may be separately present if you supplied one and gave permission.
- You can export everything held against your account as one JSON file whenever you want, without asking anyone.
Browser-local information, in practice
- It belongs to one browser on one device. A different browser on the same laptop is a different store.
- Clearing browser or site data, using a cleanup tool, or an aggressive privacy setting can remove it without warning. NAP cannot recover it, because NAP never had it.
- Private or incognito storage behaviour varies by browser and is typically cleared when that private session ends, so do not rely on it without checking your own browser.
- Anyone else who uses that browser profile can open the tool and read what is there. On a shared or public computer, use each tool's own reset control when you finish.
- NAP does not back up browser-local information, and there is no undo after a reset.
Exporting what is in your account
- Sign in and open your account privacy settings.
- Choose the export control. NAP assembles everything held against your account.
- A single JSON file downloads to your device, named with the date.
- Open it in any text editor, or keep it as an archive. It is yours, and export is never a paid feature.
There is one complete export, and starting it from account privacy settings or from the reports page produces the same file. It covers your profile and preferences, saved plans, tasks, check-ins and reflections, journal and sleep records held in the account, daily context, personal observations, your "What tends to help?" library, recap reflections, your My NAP setup (categories, day templates, custom check-in measures and planning rules), your import and export history, product access and any role your account holds, connection metadata, and your consent history. The page also lists what is deliberately left out and why — encrypted provider tokens above all, which are never exported. Individual tools keep their own smaller exports: CSV and JSON in the journal and the help library, a text export in the Recap, a plain-text download in the Rescue Plan, and a share-card PNG in the planner.
Deleting your information
There are two account-level deletions, and both use the same deliberate two-stage confirmation: a destructive confirmation dialogue, plus an acknowledgement checkbox that starts unchecked. Neither can be undone.
- Delete planning data — removes every saved check-in, plan, task and reflection, and leaves your account, email preferences and consent history in place.
- Delete your account — removes your login and the NAP information attached to it. A record that consent was withdrawn is kept without your planning information.
Account deletion cannot reach your browser. The planner's local copy, device journal entries, the Rescue Plan and the browser Quick Start Pack all survive it, and you remove those yourself with each tool's reset control or by clearing your browser's site data.
Export first if you want to keep anything. Once a deletion runs there is no self-service recovery.
The installed app and offline caching
NAP can be installed as an app, which uses a service worker to keep public pages available offline. That cache has a strict boundary, defined in one place in the code so it cannot drift.
- Only public pages are cached: articles, resources, and the free tool pages themselves.
- Never cached: anything under your account, Connected Insights, My NAP, the admin area, sign-in and password reset, and every server or API call.
- A response is never cached if the request carried an authorization header, if the response sets a cookie, or if it is marked private or no-store.
- Only successful GET requests from NAP's own origin are eligible at all.
- Offline, a generic offline page is shown rather than a personalised one.
In short, the offline cache holds pages anyone could read, not anything about you. What you type into a browser-local tool is kept by that tool's own storage, not by the offline cache.
Feedback and optional contact information
- Feedback is submitted through NAP's own server, which stores no raw IP address and no browser user-agent with it. A keyed HMAC digest of the request address is kept separately for abuse prevention.
- It is not linked to your account, even if you are signed in at the time.
- An email address is included only if you provide one and give explicit permission to be contacted about that submission.
- That address is used for that submission only and never joins a newsletter, mailing list or marketing sequence.
- Raw feedback is kept for up to 12 months. Contact addresses are removed within 90 days, or when follow-up ends, whichever comes first. Cleanup is currently a manual quarterly task.
- Because a submission is not linked to an account, it cannot reliably be associated with a person for self-service export or deletion of a specific one.
What this guide does not claim
- It makes no claim about encryption methods, key handling or infrastructure security.
- It makes no claim about backup schedules or how long a deleted record may persist in routine infrastructure backups.
- It does not promise a deletion timescale beyond what the product does when you press the control.
- It is a description of product behaviour, not a legal document. The Privacy Policy is the governing text.
What to do next
- Export or delete your account data
One JSON export, two-stage deletion, and your consent history. Sign-in required. Sign-in required.
- Read the Privacy Policy
The governing text on how information is handled.
- Open your account settings
Everything stored against your account. Sign-in required. Sign-in required.
- Back to the tools
Every tool available today, and what each one stores.
- Ask a question
For anything that needs a person rather than product feedback.
Privacy and limitations
- Browser-local information belongs to one browser on one device, is never sent to NAP, and cannot be recovered by NAP if it is cleared.
- Creating an account does not migrate browser-local information; nothing crosses over without an explicit control.
- Account deletion is two-stage and permanent, and it cannot remove anything stored in your browser.
- Feedback is not linked to your account, so it cannot be self-service exported or deleted.
- The offline cache holds public pages only; account, insights, My NAP and admin routes are never cached.
- This guide supplements the Privacy Policy and makes no claim about encryption, backups or retention beyond what the product demonstrably does.