Last updated: February 23, 2026
When you use VirtuePath, we collect information you provide directly:
Your data is stored in a PostgreSQL database hosted by Neon with encryption at rest and in transit. The application is hosted on Vercel. Passwords are hashed using bcrypt with a cost factor of 12. Sessions use signed JWT tokens with HS256 encryption.
We use the following third-party services:
We do not sell your personal data to any third parties.
We use a single httpOnly session cookie (virtuepath_session) to maintain your login session. This cookie is strictly necessary for the service to function and expires after 7 days. We do not use tracking or advertising cookies.
We retain your data for as long as your account is active. When you delete your account, all associated data (check-ins, journal entries, goals, streaks, and points) is permanently deleted via cascading database constraints.
VirtuePath is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us.
We may update this privacy policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.
If you have questions about this privacy policy or your data, please contact us at privacy@virtuepath.app.