Privacy policy
Effective September 13, 2026.
My Hitch is provided by Snuffridge Group. This policy covers the Android app com.snuffridge.myhitch, its dedicated Play-test service and its support website. For privacy questions, contact privacy@snuffridgegroup.com.
Information we process
Connected accounts use your verified email address, account identifier, display name and profile choices, including your selected home time zone, industry and position. Rotation dates and Work/Home durations provide your calendar and connected Relief features. Google sign-in supplies authentication identity information; Supabase can also store your Google profile name and references to your profile photo in authentication metadata. This does not grant your Relief partner access to those authentication records.
Private life-event titles, notes and artwork choices remain on your device by default. Sharing your rotation sends operational dates, phases and protected-date flags to your authorized Relief partner; those flags show that a date is restricted without sending its private title or note. Relief requests send requested event intervals, coverage and give-back dates, agreement status and balance information. Only reason fields you explicitly choose to share are disclosed.
Authentication and service requests also process security and operational metadata, including IP address, approximate city and country derived from the connection, browser or device user-agent information and request paths. This is not GPS tracking. The app does not request location, camera or microphone permission; selecting a time zone does not measure your location.
Purpose and providers
We use this information to authenticate you, preserve account ownership, provide your rotation, coordinate authorized Relief agreements, protect the service and handle deletion requests. Your Relief partner sees only the information authorized through those features. Free and Premium access differ; signing out or reinstalling does not grant Premium.
Supabase provides authentication and hosted database services. Google provides Google sign-in and Google Play distribution. Cloudflare provides website hosting and scheduled deletion processing. These providers process service and security information under their own policies. Their operational records are separate from our private recovery-copy retention described below; this policy does not assign an unverified retention period to provider logs.
My Hitch does not contain advertising or use an app behavioral-analytics or crash-reporting SDK in this testing release. We do not sell your personal information.
Security and account verification
Connected requests use HTTPS. Android account sessions and recovery state use Keystore-backed secure storage. Ordinary local calendar and event data is not all encrypted at rest.
Online verification is not yet available on this website. Where external deletion verification is enabled, your browser sends email credentials directly over HTTPS to Supabase Auth. Google verification uses temporary browser-bound verification state encrypted in browser storage. The deletion receipt is also encrypted there, while the authenticated website session remains in memory. The website Worker does not store email passwords or bearer session credentials. A short-lived Google callback code can appear in the incoming page URL; it is removed from browser history before subsequent client requests. Provider request and security logs may still process that incoming request.
Your choices
You can edit your profile and local events, choose which reason fields to share, disconnect under the Relief balance rules, sign out and request account deletion. Signing out does not delete your account or cancel a pending deletion request.
Optional portable backups use your passphrase for encryption and are saved to the location you choose. Keep that passphrase private. Exported files remain under your control, including any synchronization performed by your chosen document provider.
Deletion and recovery copies
A confirmed deletion request immediately disables connected account access and new sharing. Private operational account and profile data is deleted within 30 days. There is no cancellation period. Only the surviving partner's necessary anonymous operational history remains, such as dates, day amounts, applied schedule effects and unresolved status. The deleted participant is shown as “Deleted account.” Deletion does not automatically settle or release owed Relief days, apply a pending proposal or reverse the partner's approved schedule.
Private Play-test server recovery copies, including temporary restored copies, have a seven-day rolling expiry policy. Cleanup is checked hourly and at local sign-in on the protected computer that holds them. If that computer is off or unavailable, a file is in use or cleanup fails, expiry is delayed until a successful cleanup; this is not an unconditional seven-day maximum. These private local recovery copies are access-restricted but are not encrypted at rest. Recovery must preserve deletion decisions so deleted accounts are not revived.
This recovery-copy policy does not govern provider operational logs or backups users export themselves. User-owned exports cannot be erased remotely. An in-app deletion request clears that account's local app data after confirmation; an external request cannot immediately erase offline devices. Other devices learn revocation on a subsequent connection.
Policy updates
We will update this page and its effective date when material handling practices change.