joshua421

Last updated 22 September 2026

Privacy

This public website offers the character quiz and appearance preview without an account. Account sign-in and connected services described below are not enabled on this public release.

joshua421 is a companion for reflecting on your day and setting it before God. That is about the most private thing software can be handed, so this page is written to be read rather than to be survived.

Privacy contact

Kenneth Cheung is the contact for privacy questions, requests and complaints about Joshua421 in Australia. Contact kc.work@gmail.com.

The service is offered by invitation only, and invitations are not issued to residents of the European Union, the European Economic Area or the United Kingdom. That is a deliberate limit on which privacy regimes apply, not an oversight.

The public character quiz

The homepage appearance preview stays in page memory and does not change an account’s character or save a look. The character quiz works without an account. Answers and the resulting profile are calculated in your browser and held only in the page’s memory. They are not sent to our server or an AI service, written to browser storage, or attached to your account. Reloading or leaving the quiz clears them. Links to Bible passages open an external site; your quiz answers are not included in those links. The invited reflection beta has the separate account and Google permissions described below.

What is stored about you

Your account record contains your email address, your Google account identifier, your timezone, your two nudge hours, whether nudges are on, the identifier of the calendar joshua421 created for you, two per-day markers that stop a nudge being sent twice, the date you joined, and your Google refresh token.

The refresh token is stored as AES-256-GCM ciphertext. The key is held in the application’s environment and never in the database, so a copy of the database on its own cannot be used to reach your Google account.

The iPhone and iPad app also creates a sign-in record with a random identifier, a verification hash, an expiry time and the version of your AI-sharing consent. The sign-in record expires after ten minutes and is removed when used or during subsequent sign-in housekeeping. Mobile sessions contain a hash of the app credential, your account identifier, the consent version and a thirty-day expiry. The credential itself is held in your device’s Keychain. Signing out revokes that app session; account deletion removes all of them.

What is never stored

Your reflections
The conversation is not written to any database of ours. When you close the page, or the operating system closes the mobile app, it is gone from here. Unfinished conversations do not sync between devices. Only what you explicitly approve is kept, and it is kept in your own Google Calendar — read back from there each time, never mirrored.
Your calendar
Events are read live from Google for the day you are reflecting on, held in memory for the length of that request, and discarded.
Your inbox
joshua421 has no permission to read email and does not ask for one. It can only send.
Analytics about you
No third-party analytics, no advertising identifiers, no tracking pixels, no behavioural profile. The website uses a sign-in cookie and a short-lived cookie to secure the Google authorization flow.

Google data — what is accessed and why

Alongside your Google identity and email address, signing in requests the permissions below for the features described on the homepage.

See and edit calendar events
calendar.events — to read the events of the day you are reflecting on so the conversation is about your actual day, and to write the notes and day summaries you approve. Nothing is written without your approval in that session.
Create and manage the app’s own calendar
calendar.app.created — to create the separate “joshua421” calendar when you connect the calendar-reflection feature. Account deletion now preserves this external calendar and its contents. This permission applies to calendars created by the app.
Send email on your behalf
gmail.send — to send your morning and evening nudge from your own address, to yourself. It is used for no other recipient and no other message.

joshua421’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can withdraw these permissions at any time from your Google account’s permissions page. Doing so stops the service immediately; nothing already written to your calendar is affected, because it belongs to you.

Who else sees anything

Four services, each doing one job. No data is sold, and none is shared for advertising, ever.

Anthropic
The companion is a Claude model. What you type, and the day’s calendar entries it is reflecting on, are sent to Anthropic’s API to be answered. This is the one place your reflections leave your control, and it is unavoidable in a product of this kind — it is the model doing the listening. Anthropic processes API traffic under its commercial terms and does not train models on it. joshua421 keeps no copy either way.
Google
Sign-in, your calendar, and the sending of your nudges. Your own account, under Google’s own privacy policy.
Supabase
The database holding account records, mobile sign-in/session records and invite requests described on this page. No reflection transcript is stored there.
Vercel
Hosting. Ordinary server logs may briefly record request metadata such as IP address and timing; they never contain reflection content.

If you asked for an invite

The invite request form stores your name, email address, self-declared country and whatever you chose to write, so that a real person can read it and answer you. It is used for that and nothing else — you are not added to a mailing list, because there isn’t one.

If you selected an EU, EEA or UK country, nothing is stored at all: the request is refused before it reaches the database, and you are told why on the spot.

Ask at kc.work@gmail.com and your request is deleted.

Leaving

Delete your account from the account page. This removes your hosted account records and stored connection, and attempts to revoke Google access. Provider revocation can fail; you can also remove access in your Google account settings. Device-only plans and saved device copies are not erased by this server request. What remains is the joshua421 calendar in your own Google account, with everything you chose to keep in it — it is yours, and it stays whether or not you keep using this. Delete it yourself if you’d rather it were gone.

You can also ask for a copy of what is held, or a correction to it, at kc.work@gmail.com. In practice the answer is the short list at the top of this page; you are welcome to have it in writing.

Where this stands legally

joshua421 is operated from Australia and handled under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Reflections about faith are sensitive information under that Act, and they are collected only with your consent and only for the purpose described here.

Data is processed in Australia and the United States, the latter because Anthropic’s and Google’s services are hosted there.

If this policy changes in a way that affects what is collected or who sees it, invited members are emailed before it takes effect — not after.