Policies & disclosures

Privacy Policy

NAP is operated by NAP Actually LLC. NAP is built to need as little of your information as possible. The Daily NAP Planner works anonymously in your browser. An account is optional: it exists so that the information you choose to save is kept for you and available on your other devices, and so that the account-only features NAP has built can work.

Published for the NAP limited beta. Last updated 22 September 2026.

This document describes how NAP currently works, written in plain language by the founder. It is not legal advice, and it does not replace advice from a lawyer or a clinician about your own situation.

NAP mobile app for iOS and Android

The NAP mobile app for iOS and Android stores Planner, Journal, check-in, Low-Energy Rescue Plan, context-note, template, and preference information locally on your device. The mobile app has no account, advertising, tracking, payment collection, or server sync, and NAP does not receive that locally stored content.

Sharing and export happen only when you choose them, and send information only to the destination you select. The mobile app's automatic-backup settings ask Android and iOS not to include NAP-managed app data in cloud backup or device transfer, but operating-system and device-maker behavior is outside NAP's control, so this is not a guarantee against every copy.

Uninstalling NAP, deleting its app data, using Delete all local NAP data, or losing the device may permanently remove locally stored information. You can export a Rescue Plan before deletion. The delete control removes NAP-owned tool data on that device; there is no mobile-app cloud account to delete.

The NAP website is separate from the mobile app: website accounts, support forms, and Stripe processing operate as described in the relevant sections below. Privacy and support questions can be sent to hello@napactually.com.

Using the planner without an account

If you are not signed in, everything you type into the Daily NAP Planner — check-in levels, tasks, notes, and reflections — is stored in your own browser's local storage. It is not transmitted to NAP, and NAP cannot read it. The Sleep & Nap Journal and the Low-Energy Rescue Plan work the same way.

Clearing your browser or site storage, or choosing “Delete my local planner data” in the planner, removes that local data permanently. There is no backup and no server copy to restore.

Private or incognito windows behave differently from browser to browser. In most browsers anything saved in a private session is cleared when that session ends, but NAP cannot promise a specific behaviour for every browser or device — check your own browser's documentation if that matters to you.

Website analytics

On the website only, NAP's hosting layer loads a first-party, privacy-minimal analytics script from /~flock.js. For a page view it sends the page URL and path, referring page, browser user-agent, locale, a country derived from the browser's time zone, and a random session identifier to the same-site /~api/analytics endpoint. The identifier is stored in a secure first-party cookie for up to 30 minutes. The deployed tag does not enable the script's performance or Web Vitals reporting. This website mechanism is separate from NAP's product-event contract, whose transmission remains switched off, and from the native iOS and Android apps, which contain no analytics transmission.

The website analytics request concerns the page visit. NAP's Planner, Journal and Rescue Plan fields stay in local browser storage unless you deliberately use an account-backed save or another stated submission action; those field values are not added to this page-view request by NAP's website code.

If you create an account

An account holds your email address, an optional display name, and the information you deliberately save. In plain terms that means: your planning preferences; check-ins, planned days, tasks, reflections and day context; account-backed journal entries for nights, naps and rest; your My NAP customization — your own task categories, day templates, check-in measures and planning rules; the “what tends to help?” notes you write yourself; your Weekly NAP Recap reflections; and records of the imports, exports, consents and any safe connection metadata associated with your account.

Saved records are protected by row-level database rules so that they are readable only by your own signed-in session. NAP staff do not browse personal planner records as part of routine content or support work.

From Account and privacy settings you can download one complete JSON export of the account datasets you own, delete your planning data while keeping the account, or delete the account and its records entirely.

That export deliberately leaves some things out: raw provider credentials and access tokens for any connected source, passwords and session secrets, internal security and abuse-prevention material, and form records that are not tied to your account. Those exclusions exist because they are secrets or are not reliably yours to identify — the current list is shown on the Account and privacy page itself.

Information you send through forms

The newsletter form, contact form, and story submission form save what you send to NAP's database so that a human can reply or so that the newsletter can be sent. Those records are private: they are not publicly readable, and they are not used for advertising.

Outbound newsletter delivery is not active, so NAP does not currently send newsletter confirmation or newsletter issue emails. Forms tell you this at the point of submission rather than implying an email is on its way. Supabase Auth separately sends the account-verification and password-reset messages required for the optional account flow.

Because these records are keyed to the email address you gave rather than to an account, they are not part of the self-service account export. You may ask for a copy of, correction of, or deletion of anything you submitted through the contact page.

Limited-beta feedback

The feedback form stores only what you type: the product area, the feedback type, your written notes, and an optional ease-of-use answer. It works without an account, and nothing from your account, planner, journal, or tools is attached to a feedback submission.

No raw IP address and no browser user-agent string is stored with your feedback. To limit abuse of the public form, NAP stores a keyed HMAC digest of the requesting address separately from the submission; it is not reversible into an address by NAP and is not joined back to your feedback.

An email address is stored only if you enter one and tick the separate box giving NAP permission to contact you about that feedback. Without that permission the address is discarded before the feedback is saved. Feedback never enrols you in the newsletter, creates an account, sends email, or authorises any testimonial or marketing use.

Because feedback carries no account link, it cannot reliably be matched to you for the self-service export or account deletion. Ask through the contact page if you want a submission removed. Feedback is used only to improve and support NAP, is readable only by NAP administrators, and is never published. Raw feedback is kept for up to 12 months. An optional contact address is removed within 90 days, or as soon as the follow-up conversation ends, whichever comes first. Until automated retention exists, an administrator carries out this cleanup manually each quarter, and can also delete a submission or remove just its contact address at any time on request through the contact page.

Health information

Please do not send NAP detailed health information. NAP is not a healthcare provider, is not a covered entity under health privacy laws such as HIPAA, and cannot offer the protections a clinical relationship provides.

NAP does not ask for a diagnosis, a medication list, or clinical records, and what you save is planning information rather than a medical record, monitoring, or a diagnosis.

Connected Insights, including wearable connections and manual sleep logging, is optional and off by default. Each connection asks for separate, explicit consent before any data is requested, and you can disconnect and delete imported data at any time.

Self-reported and wearable numbers in NAP are planning inputs, not clinical measurements, and NAP does not interpret them medically.

What NAP will never do

  • Sell your personal information.
  • Share your planner entries with advertisers or partners.
  • Use health-related or wearable information for advertising.
  • Include sensitive health measurements in a workplace summary unless you explicitly choose to.
  • Add tracking that you cannot see disclosed here.

Your choices

You can use NAP without providing any personal information. You can delete planner data at any time from the planner itself, and account holders can view, export, correct, or delete their saved information from Account and privacy settings.

Published for the NAP limited beta. Last updated 22 September 2026. This text describes how NAP currently works, written in plain language by the founder. It is not legal advice.