What stays where
Privacy in plain language.
Hinga separates browser-local Guest data, private Google-account sync, and your public Sanctuary Codename.
Guest mode
You can browse, breathe, check in, and journal without giving Hinga a name, email, or profile picture. Guest journal pages, Stones, bookmarks, inspiration favorites, and drafts stay in this browser and may be lost if its site data is cleared. A published community post is stored in Firebase and becomes visible to other visitors. Publishing or reporting starts an Anonymous Firebase Guest session when no access option has been selected yet.
Google-connected sync
Connecting Google moves supported content from the current browser into owner-only Firebase documents so it can be available on other signed-in devices. Hinga content documents do not store your Google name, Gmail address, or Google profile picture.
Sanctuary Codename
Google-connected users receive a customizable codename. Public community posts use that codename rather than Google account details. Guest posts display “Guest.”
Who can still access account information
Your email is not displayed publicly, but it is held by Google and Firebase Authentication so sign-in can work. The Owner Moderator may access authentication records for security, support, deletion, or legal obligations. Hinga does not describe this as absolute anonymity.
Your private content
Firestore Security Rules limit normal access to the signed-in owner of each journal entry, Stone, bookmark, inspiration favorite, and codename. The project owner retains elevated technical access and limits its use to operating, securing, restoring, or legally maintaining Hinga.
Community limits
Community posts, comments, and Room messages become public immediately. Reported posts enter the Owner Moderator queue; concerns about comments or Rooms can be sent through Beta feedback. Hinga is not monitored continuously.
Requests and concerns
Use the Beta feedback control and choose “Privacy or account request” to contact the Owner Moderator without attaching your Gmail address or private writing. Do not place journal content, passwords, or emergency requests in that form.
Retention and control
Guests can export or clear supported local data from the account page. Submitted community posts are not cleared with browser data; contact the Owner Moderator for removal help. Google-connected data remains until the user removes it through available controls or requests account assistance. Moderator audit records may be retained for security and accountability even when related content is removed.