1. Scope and short version
This policy applies only to the Crown. application operated by Super Collective Family LLC, a Utah company. It does not govern the Super Collective Family website, waitlist, Family Audit, store, shipping, or website cookies.
Crown. is a private family space. We do not sell or rent personal data, share it for cross-context behavioral advertising, build advertising profiles, or add advertising, session-replay, or behavioral-analytics code. What your family properly seals on its own device reaches us only as unreadable ciphertext. What we can read is the limited account and operational information listed below.
2. What Crown. can read
We can read the email address and dates associated with an account; Family Unit names and mottos; roster display names; membership and invitation records; support messages you choose to send; email delivery outcomes; and security, abuse-limit, and app-health records needed to operate Crown. A family standing declared by its own subject is optional, blank by default, and sealed on the device, so the service stores only its unreadable form.
Sealed records still carry operational metadata such as account and Family Unit identifiers, sender or recipient identifiers, visibility, dates, client identifiers, delivery state, and integrity fingerprints. That metadata does not contain the sealed words.
3. What is sealed on your device
Journal titles and entries, private notes, Family Unit conversation, and self-declared family standing are sealed on the device before cloud synchronization when sealing is available. Crown. stores password-protected wrapped key material, but does not receive your password or an unwrapped content key and cannot use the wrapped material to read properly sealed words.
A small number of older records, or records created when sealing failed, may contain readable fields. Crown. migrates eligible records when the key is available and does not describe those legacy or failed records as end-to-end encrypted.
If you lose both your password and recovery code, nobody, including us, can restore properly sealed content. A person you share with can still copy what they open on their own device.
4. Local-first choices
The Journal and Crowned practice begin on your device. Optional cloud synchronization is controlled in Crown. When it is off, those surfaces do not request cloud content. Reads use the local copy first, and enabled writes send changed records in batches where practical.
Language, theme, reading size, unsaved drafts, daily-question selection, ritual and reading progress, guided-tour state, and similar personal engagement state remain on the device unless a screen plainly says otherwise. Device capability hints are used locally to choose a lighter or richer presentation and are not sent to us for profiling.
5. No location, of any kind
Crown. does not ask where a family lives. It requests no GPS or browser location and does not derive or store a country, postal code, address, or geographic coordinate, precise or approximate. An earlier version kept a deliberately rough region; that practice ended and the stored values were erased.
After a qualifying family ritual is successfully logged, the device may send a one-way daily token made from the active Family Unit key. Membership is checked and no more than one anonymous ember is counted for that Family Unit on its device-local day. The token cannot be reversed into the key. Public Sky results contain abstract positions and counts, never a Family Unit identifier, account identifier, name, device fingerprint, network address, or location.
6. Security and reliability records
Network addresses used to stop abuse are transformed into keyed hashes and are not stored in readable form. Short-lived security records may include that hash, a route, event type, severity, time, and scrubbed technical detail. Crown. does not derive a country from the network address.
Minimal scrubbed app-health reports may include a route, app version, locale, online state, timing, and a shortened error description. Product-use counts stay on the device. These records are for reliability and security, not advertising analytics, a browsing history, or a family score.
7. Cookies, sessions, and communications
Crown. uses no cookies for advertising or measurement. Essential sign-in and security session storage may be used to keep an account authenticated. We may send account confirmation, password recovery, invitation, security, support, and quiet-account notices. Local in-app alerts are optional and can be disabled in Crown. or device settings.
8. Why we use information
We use accessible information only to authenticate accounts, operate Family Units and invitations, synchronize the records you choose, deliver requested communications, prevent abuse, repair failures, meet legal obligations, and protect people and the service. We do not use it for advertising, resale, family scoring, attendance, streaks, or automated decisions with legal or similarly significant effects.
9. Service providers and processing
We use providers for hosting, authentication, storage, and email delivery. They process the information needed for those functions under their own legal obligations. Information may be processed in the United States and other places where those providers operate. Encryption limits readable content we can disclose, but does not make lawful requests for accessible metadata impossible.
10. Copies, correction, and deletion
The Journal can create a readable export by decrypting entries on your device and can create a still-encrypted backup. A readable download is no longer protected by Crown., so store it carefully. We can provide readable account and Family Unit metadata we hold and stored ciphertext, but cannot turn properly sealed content into readable text.
You can correct available account details and delete your account in Crown. Deletion removes covered account metadata, memberships, stored ciphertext, and wrapping material. It cannot erase copies already downloaded, records another person independently retained, or limited records that must age out under law, security, delivery, or provider backup schedules. Signing out removes Crown.-managed keys, local mirrors, drafts, queues, and caches from that browser or installed app.
11. Quiet accounts and retention
Crown. records app-open activity at most once per day. We send reminders near 150 and 173 quiet days. At 180 days, the automated process deletes covered account data. Opening Crown. resets that period. Other app records remain while the account exists or for the shorter operational period that created them; provider backups roll off on their own schedules.
12. Younger family members
Crown. welcomes families, including younger family members. Adults may create accounts independently. A person under the age of majority may create and use an account only through a valid invitation from a parent, legal guardian, or another adult legally authorized to consent for them. We do not ask for a birth date, government identification, or legal full name, and we do not guess age. The temporary age answer entered during onboarding is used on that device to choose the lawful path and is immediately discarded rather than stored.
If we learn that a younger person created an account without the adult involvement or consent required by law, contact support@scfbrand.com and we will take appropriate steps, including deletion where required. Crown. records the inviting account, issue time, single-use key, and redemption; it does not store a parent or guardian identity, the younger person's identity beyond their ordinary account and chosen display name, or a relationship edge, and it does not market this flow as verified parental consent.
13. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object, withdraw consent, or receive portable information, and to complain to a regulator. We do not charge or treat you differently for exercising a privacy right. We may confirm a request through information we already hold, normally the account email; we do not ask for a government identity document.
Encryption limits what we can make readable, not your rights to accessible data. We can provide or erase what we hold, and your readable sealed-content export is made inside Crown. with your own key.
14. Security and legal requests
We use access controls, encryption, rate limits, short retention, and deletion routines designed to reduce risk. No service can guarantee absolute security. Report a vulnerability to reports@scfbrand.com without accessing, retaining, or disrupting another person's data.
We respond to valid legal demands for information we actually hold and may challenge or narrow demands where permitted. We cannot create readable content from properly sealed records because we do not hold the key. If an incident triggers a legal duty to notify, we will notify affected people and authorities within the deadlines that apply and distinguish readable information from sealed information.
15. Changes and contact
If this policy changes materially, we will update its date and request renewed agreement in Crown. when rights or obligations materially change. For privacy requests, account questions, or a concern about a younger user, contact support@scfbrand.com. For a security vulnerability, contact reports@scfbrand.com.