Last updated: 23 July 2026

Quiet Signal (“Quiet Signal”, “we”, “us”, “our”) is operated by Valentigo. This notice explains what personal data we collect through the Quiet Signal app and website, why, how long we keep it, and the choices and rights you have. It applies wherever Quiet Signal is used.

If you have questions about this notice or your data, contact us at support@quietsignal.co.uk.

1. Important context: what Quiet Signal is (and isn’t)

Quiet Signal is a self-guided wellness check-in and journaling tool for people living with chronic pain, PTSD, or anxiety. It is not a medical device, does not provide diagnosis or treatment, and is not a crisis or emergency service. The in-app Support/Crisis screen provides links to third-party crisis lines and emergency services – we do not monitor journal entries in real time and cannot respond to an emergency. If you are in immediate danger, contact your local emergency number.

2. Data we collect

Account data: email address, and if you use Google Sign-In, the basic profile information Google provides (name, email, profile photo). Authentication is handled by our backend provider, Supabase.

Check-in data: your daily Pain, Anxiety, and Energy scale entries and any optional notes.

Journal data: free-text journal entries you write.

Sharing data: if you use the Share feature, the trusted contact’s name/contact method, and the content of the check-in you choose to share. Shared check-ins are viewable by the recipient via a public web link that does not require the recipient to log in or create an account.

Settings and preferences: display settings (dark mode, high contrast), chosen background photos, and your region/country selection for crisis resources.

Data you request: if you use Data Export, we compile your check-ins, journal entries, recipients, and shared messages into a file for you.

Crash and error data: if the app crashes or hits a technical error, an automatic report is sent to Sentry, our crash-reporting provider, so we can find and fix the bug. Reports contain technical details only – device model, operating system version, app version, and what went wrong in the code – never your journal entries, check-in scores, notes, or IP address. Crash data is stored on Sentry’s servers in the European Union and automatically deleted after at most 90 days.

We do not currently run third-party analytics or advertising SDKs in the app. Sentry, our crash-reporting tool, is the only third-party diagnostic SDK in the app (see “Crash and error data” above).

3. Special note on health data

Your Pain, Anxiety, and Energy check-ins and journal entries are health-related information and are treated as special category data under UK GDPR. We only process this data on the basis of your explicit consent, given when you create an account and use these features. You can withdraw this consent at any time by deleting your account (Settings > Delete Account), which permanently removes this data as described in Section 5.

4. How we use your data

  • To provide the check-in, journal, history/trends, and sharing features you use directly.
  • Crisis-language screening: every journal entry is automatically scanned by an automated, non-AI, lexicon-based process before any other processing happens. This check is mandatory and cannot be turned off. Entries flagged by this process are excluded from all further insight generation and are not processed for any other purpose by this feature.
  • Weekly insights: for entries not flagged above, we generate plain-language theme and sentiment summaries using a fixed keyword/category dictionary. We do not send your journal content to any third-party AI or language-model service.
  • Long-term storage management: check-in data older than 90 days is folded into a monthly plain-language summary and the original detailed entries are deleted, for both free and Pro users. Retention length does not depend on subscription tier.
  • To maintain the security, integrity, and reliability of the service.
  • To respond to support requests sent to support@quietsignal.co.uk.

5. How long we keep your data

  • Detailed check-in and journal data: up to 90 days, after which check-ins are summarized (see Section 4) and journal entries are deleted per the same policy window used for insight generation.
  • Account and settings data: for as long as your account is active.
  • If you delete your account, your profile, check-ins, journal entries, recipients, shared messages, and monthly summaries are permanently deleted. This is irreversible.

6. Who we share data with

We use the following service providers (subprocessors) to run Quiet Signal:

  • Supabase – database, authentication, and backend hosting.
  • Google – if you choose Google Sign-In, for authentication only.
  • Expo/EAS – app build and delivery infrastructure.
  • Hostinger – hosts quietsignal.co.uk and our support email.
  • Sentry – crash and error reporting (technical device and error details only, stored in the European Union).
  • Apple App Store / Google Play – for app distribution and, for Pro subscribers, payment processing (Quiet Signal does not receive or store your payment card details).

We do not sell your personal data, and we do not share your health-related data with third parties for marketing or advertising purposes.

If you use the Share feature, the content you choose to share is made available to the recipient(s) you designate via a link. Anyone with that link can view the shared content without logging in – only share with people you trust, and treat the link as sensitive.

7. International data transfers

Our service providers may process data outside the UK. Where this happens, we rely on appropriate safeguards recognised under UK GDPR (such as Standard Contractual Clauses or an adequacy decision) to protect your data.

8. Your rights

Under UK GDPR, you have the right to:

  • access the personal data we hold about you;
  • correct inaccurate data;
  • request erasure of your data (available directly in-app via Delete Account, or by contacting us);
  • export your data in a portable format (available directly in-app via Data Export, or by contacting us);
  • object to or restrict certain processing;
  • withdraw consent at any time, without affecting processing carried out before withdrawal;
  • lodge a complaint with the UK Information Commissioner’s Office (ico.org.uk) or your local data protection authority.

To exercise any of these rights, contact support@quietsignal.co.uk or use the relevant in-app setting.

9. Security

We use industry-standard measures to protect your data, including row-level security policies on our database restricting access to your own records, and encrypted connections between the app and our backend. No system is completely secure, and we cannot guarantee absolute security.

10. Children

Quiet Signal is not directed at children and is not intended for use by anyone under 18. We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, contact support@quietsignal.co.uk so we can delete it.

11. Changes to this notice

We may update this notice from time to time. We will post the updated version at this URL with a revised “Last updated” date, and where changes are material, we will provide additional notice in the app.

12. Contact us

Quiet Signal (operated by Valentigo)
Email: support@quietsignal.co.uk
Website: quietsignal.co.uk