Privacy Policy
Last updated: 28 July 2026
Who we are
Kansha is a daily gratitude journalling app operated by Matt Hughes, trading as MHDS Consulting, based in the United Kingdom. Our website is at https://getkansha.co.uk.
As the operator of this service, Matt Hughes is the data controller for the personal data you provide when using Kansha.
For any privacy-related questions, contact us at matt@getkansha.co.uk.
What data we collect
We collect only what we need to provide the service:
- Account data — your email address, used for sign-in and optional daily reminders.
- Journal entries — the text you write each day, your mood score, and the date.
- Reflection answers — your responses to the optional deep-reflection prompts.
- Food & energy logs — if you choose to use the food diary feature.
- Goals — your year goals, if you set them.
- Notification preferences — your preferred reminder time and whether reminders are on.
- Push subscriptions — a browser push token if you enable push notifications.
- Usage metadata — your subscription tier and, if you use them, your weekly review and practice-exercise entries.
We do not collect your name, phone number, location, or any payment card details directly. If you upgrade to Pro, payment is handled entirely by Stripe.
How we use your data
Your data is used solely to provide and improve the Kansha service:
- To store and display your journal entries, mood scores, and reflections.
- To generate AI insights about patterns in your entries (see AI section below).
- To send your daily reminder email or push notification, if you have enabled them.
- To maintain your subscription status.
We do not use your data for advertising, marketing profiling, or sale to third parties. We do not display ads.
AI insights and your journal entries
Kansha's AI insights feature sends a summary of your recent journal entries to Anthropic's Claude API in order to identify patterns — the people, places, and habits that consistently appear in your moments of gratitude.
What is sent: the text content of up to 30 of your most recent journal entries (with their dates and mood scores), up to 20 recent food-diary entries, your current goals, and up to 8 recent weekly reviews. Entries you have locked are never included. No other personal data is sent.
Before anything is sent, you are shown a screen listing exactly what is about to go. The 30-entry limit is enforced in the application itself, not just stated here.
What is not sent: Your email address, account details, or any data from other users.
Anthropic processes this data in accordance with their Privacy Policy and Usage Policy. We have a Data Processing Agreement in place with Anthropic.
AI insights are optional. You can use Kansha's journalling, mood tracking, and other features without ever generating an insight.
Gratitude letters and other people's details
Kansha lets you write a gratitude letter and, if you choose, email it to the person it is about. That is the only feature where we handle information about someone who is not a Kansha user.
What we store: the recipient's name as you typed it, and — only if you actually send the letter — their email address, so that you can see who a letter went to. Both sit in your account, under the same row-level security as your entries, and are deleted with everything else when you delete your account.
What we send: the letter text and the recipient's name and email go to SendGrid, our email provider, to deliver that one message. The email comes from a Kansha address with your display name attached, and your notification email is set as the reply-to so a reply reaches you rather than us.
What we do not do: we do not add recipients to any mailing list, do not email them again, do not use their address for anything else, and do not sell or share it. They are not enrolled in anything by receiving a letter.
Please only send a letter to someone you would reasonably expect to welcome one. You can delete a letter, including the stored recipient details, at any time from the Letters page. If someone has received a letter and wants their details removed, email matt@getkansha.co.uk and it will be done.
Data storage and security
Your data is stored securely using Supabase, a PostgreSQL-based database platform hosted on AWS in the EU (Ireland). Supabase applies row-level security policies so that your data is only accessible to your own account.
All data is transmitted over HTTPS. We do not store your journal entries in plain text outside of the database; entries exist in Supabase and are fetched only by your authenticated session or (for AI insights) by the Kansha server functions on your explicit request.
We use SendGrid to send reminder emails. SendGrid processes your email address and the content of the reminder message in order to deliver it.
Third-party processors
We share data with the following sub-processors only as necessary to provide the service:
- Supabase — database and authentication. EU-hosted.
- Anthropic — AI insight generation (journal text only, on request).
- SendGrid — email delivery for reminders.
- Netlify — web hosting and serverless functions.
- Stripe — payment processing for Pro subscriptions (handles card data directly; we never see it).
We have Data Processing Agreements in place with each processor. No data is shared with any other third parties.
Analytics
We use Vemetric to understand which pages are used and which are ignored. Kansha is built by one person, and without this the only alternative is guessing.
What it collects: the page path, referrer, rough device type and country. Visitors are counted using an anonymous daily-rotating hash rather than a cookie, so the same person on two different days is not linkable.
What it never collects: your IP address, your email, your name, or any content from your journal, jar, letters or practice exercises. Analytics runs in the page; it has no access to your data.
Vemetric is open source and hosts its servers in the EU. If you would rather not be counted at all, any browser content blocker will stop the script loading, and Kansha works exactly the same without it.
Your rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access — you can download all your data at any time from the Settings page.
- Right to erasure — you can permanently delete your account and all associated data from the Settings page. Deletion is immediate and irreversible.
- Right to rectification — you can edit or delete individual journal entries at any time.
- Right to portability — your data export (available in Settings) provides all your entries in JSON format.
- Right to object — you can disable AI insights, email reminders, and push notifications at any time in Settings.
To exercise any right not covered by in-app tools, email us at matt@getkansha.co.uk. We will respond within 30 days.
Legal basis for processing
We process your personal data under the following legal bases:
- Contract — storing your entries and account data is necessary to provide the service you signed up for.
- Consent — sending reminder emails and push notifications requires your opt-in, which you can withdraw at any time in Settings.
- Legitimate interests — improving the reliability and security of the service.
Data retention
We retain your data for as long as your account is active. If you delete your account, all personal data is permanently deleted immediately — including journal entries, food logs, mood scores, goals, and your email address.
Anonymised, aggregated analytics (such as total entry counts with no user identifier) may be retained for product improvement purposes.
Cookies
Kansha does not use tracking cookies or advertising cookies. We use a single functional session cookie to keep you signed in.
We load one third-party script: Vemetric, a privacy-first analytics tool that counts page views so we can see which parts of Kansha are actually used. It sets no cookies, stores no IP addresses, and does not track you across sites or sessions — which is why there is no consent banner to click through. It records that a page was opened. It cannot see anything you have written.
Changes to this policy
If we make material changes to this privacy policy, we will notify active users by email at least 14 days before the change takes effect. The most recent version is always available at https://getkansha.co.uk/privacy.
Contact and complaints
For any privacy questions, contact Matt Hughes at matt@getkansha.co.uk.
If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection regulator, at ico.org.uk.