Privacy Policy
What HushJar keeps, who can see it, and what happens when you delete it.
Last updated 2 September 2026
What we store
Only what the service needs to work:
- Your account. Your name if you gave one, your email address, your phone number if you added one, whether each has been verified, and when you signed up and last signed in.
- Your jars and their items. The jar's name and settings, and for each item its description, its link and any images you upload.
- Answers. What a recipient did with an item — put it back, ripped it up, took it on — and whether they finished it or set it aside until later.
- How a jar reaches you. Your quiet hours and time zone for each jar, and the PIN or pattern set on its lock screen.
- Access and invitations. The access keys that open a jar and when they expire, and the email address a jar was offered to.
We do not sell any of it, we do not use it to advertise to you, and there is no third-party analytics or tracking in HushJar.
Who can see what
An answer belongs to the person who gave it. Only the recipient who answered can see what they said about an item. The owner of the jar never sees it — not which item was drawn, not what was decided, not what was finished. The owner sees a count of how many items have been drawn, and nothing more.
The items in a jar are visible to the owner who wrote them and to the one recipient the jar is currently shared with. Nobody else has access, and a jar is never public.
How long a jar stays open
When you share a jar, HushJar mints an access key that expires after the window you chose — anywhere from an hour to a month. When it lapses, the recipient can no longer open the jar and must ask you to extend it. You can revoke access at any time without waiting for the key to expire.
Who else handles your data
HushJar runs on Amazon Web Services in Canada, with the database and application hosted by Convex. Email is sent through Amazon SES and text messages through Twilio, so the address or number a message goes to passes through them. Item images are stored in a private Amazon S3 bucket and served through Amazon CloudFront using links that expire shortly after they are issued; the bucket itself is not readable from the web.
If you turn on notifications on a device, the nudge reaches it through that browser's push service — Apple, Google or Mozilla, depending on the browser. What passes through them is the same few words as the email: never what is in a jar.
These are the only companies that process your data, and each does it for us.
Keeping it safe
Traffic is encrypted in transit, and stored data is encrypted at rest by the providers above. Signing in uses a token kept in your browser's local storage; signing out removes it.
One honest limit: a jar's lock screen — its PIN or pattern — stops somebody glancing at your phone. It is not a security boundary, and it is not what keeps other accounts out of your jar. Server-side permission checks do that.
Deleting your account
Deleting your account destroys your account record, your sign-in details, the answers you gave as a recipient, your per-jar settings and your access requests, and cancels any invitations waiting on your address. Jars shared with you simply end, and their owners are told that they did.
We refuse the deletion while you still own a jar, and we name the jars in the refusal. A jar you own holds another person's answers, and leaving should not erase somebody else's record as a side effect. Delete those jars yourself first — that destroys their answers as a deliberate act — and the account will then delete.
Deletion is immediate and permanent. There is no recovery period, and a deleted address can be used to sign up again straight away.
How long we keep things
Jars, items and answers stay until you delete them or delete the jar. Expired access keys and finished invitations are kept only as the record of what happened to that jar. Everything goes when the account it belongs to is deleted.
Children
HushJar is not for people under 16, and we do not knowingly keep data about them. If you believe a child has an account, write to us and we will remove it.
Changes, and getting in touch
If this policy changes in a way that affects what we store or who can read it, we will say so before the change takes effect. To ask what we hold about you, to correct it, or to have it deleted, write to privacy@hushjar.com.