christina

Privacy policy

Draft, awaiting legal review. The final wording may change before launch.

Christina is run by Placeholder LLC, a limited liability company registered in California, United States ("we" and "us"). We decide how your personal data is used, and we are responsible for it under this policy. For a short overview, see your data.

What we collect

  • Your account: your email address, your name, your password and your language. We store only a one-way hash of your password, never the password itself.
  • Your agreements: that you accepted the terms, and whether you gave or withdrew your consent to health information, with the version of each wording and the dates.
  • Your health and wellbeing information, only with your explicit consent:
    • your conversations with Christina, and their summaries;
    • what Christina remembers about you: notes about what matters to you, such as the people in your life, what you are working on and what helps you;
    • your paths, your session history and your mood entries;
    • safety records: if a message suggests you may be in danger, a record that crisis resources were shown to you, and when, without your words.
  • Sign-in records: the time, IP address and browser of each sign-in, to keep you signed in and to notice if someone else uses your account. To slow down anyone guessing passwords or codes, we also keep a count of attempts per IP address, for up to a day.
  • Server logs: the page or service requested, the result and how long it took. They contain no IP address, email address or message text.
  • Visits to our public pages: when you open one of the pages outside the app, we record which page it was, the website that sent you, your browser, operating system, type of device, screen size and language, and the country, region and city your IP address points to. To tell visitors apart, we also record a code made from your IP address and browser, which changes every day and cannot be turned back into either. We keep no IP address and set no cookie for this. We count nothing inside the app and not the crisis page, and nothing at all if your browser sends Global Privacy Control or Do Not Track. We keep these records only in this form, and never try to find out who made a visit.

We do not ask for your location, and we do not use advertising cookies, tracking pixels or third-party analytics.

Health information

What you tell Christina can reveal how you feel, your mental health or other health information. In the European Union and the United Kingdom this is a special category of personal data, and several US states call it consumer health data. We only collect and process it with your explicit consent, which we ask for with its own checkbox, separate from the terms. You can create an account without giving it, but Christina cannot talk with you, remember you or keep your mood entries until you do. You can give it later, in the app.

You can withdraw your consent at any time in your settings, without closing your account. Withdrawing deletes, straight away and for good, all your health and wellbeing information: your conversations and their summaries, what Christina remembers about you, your paths, your session history, your mood entries and your safety records. Before you confirm, we offer you a copy of it. Only your account stays, with your agreements, so that you can still sign in, and give your consent again if you want to start over.

If you live in Washington, Nevada or another state with a consumer health data law, our consumer health data privacy policy sets this out in the form that law requires.

Why we use it

  • To run your account. Your account and agreements, to provide the service you signed up for. For people in the EU and the UK, the legal basis is our contract with you.
  • To talk with you and remember you. Your health and wellbeing information, used only for your conversations, what Christina remembers and your mood entries. The legal basis is your explicit consent.
  • To keep you safe. Your safety records, based on your explicit consent.
  • To keep the service secure and working. Sign-in records and server logs, based on our legitimate interest in a secure and reliable service.
  • To learn how people find Christina. Visit records, to see which public pages people read and where they come from, based on our legitimate interest in improving the site.
  • To write to you about your account. Your email address, to send codes that confirm your address, links that reset your password, and messages about your account. The basis is our contract with you.
  • To show that we respect your choices. Your agreements, which the law requires us to be able to show.

What we never do

  • We do not sell your personal data, and we do not share it for advertising.
  • We do not use your conversations or notes to train AI models, and we only use language model providers that do not train on them either.
  • No one reads your conversations, except when you report one of Christina's replies (we then read that reply and the messages around it), when you ask us to look at something, or when the law requires it.

Who processes it for us

A few service providers process personal data for us. Each one may use it only on our instructions, under a contract that protects it.

ProviderWhat it does for usWhere
DigitalOceanRuns our servers and databaseUnited States
SMTP.comDelivers our emailsUnited States
BackblazeKeeps encrypted copies of our database for up to 30 days; it cannot read themUnited States
AnthropicRuns the language model that writes Christina's replies. To write each reply it receives the recent part of your conversation, the notes Christina keeps about you and your first name. It does not train on any of it, and it deletes it within 30 days, or within two years if its safety systems flag a message as breaking its rulesUnited States

We add every new provider to this list before it receives any personal data.

When you choose a password, we check whether it has appeared in known data breaches, through the Have I Been Pwned service. That check sends the first five characters of a scrambled form (a hash) of the password and nothing else, so neither the password nor anything about you leaves us.

We may also disclose personal data when the law requires it, such as in response to a valid court order, or when it is needed to protect someone's life. If Christina is taken over by another company, your data will move with it under this policy, and we will tell you before that happens.

Where your data is kept

Your data is stored in the United States. If you use Christina from another country, including from the EU or the UK, your data is transferred to the United States, where data protection law may differ from the law where you live.

How long we keep it

  • Your account and agreements: until you delete your account.
  • Your health and wellbeing information: until you withdraw your consent or delete your account.
  • Sign-in records: until you sign out, or after 30 days without use.
  • Codes we email: stored only as a one-way hash, and valid for 5 minutes.
  • Server logs: older logs are overwritten as new ones arrive.
  • Visits to our public pages: 13 months.
  • Backups: kept for 30 days, then overwritten.

When you delete your account, we delete your data from our database straight away, and it is gone from our backups within 30 days. The same goes for your health and wellbeing information when you withdraw your consent. We keep only a record that an account was deleted, and when, without your name, email address or anything you wrote, for twelve months.

Your rights

Wherever you live, you can:

  • ask for a copy of your data, in a format you can take elsewhere;
  • have it corrected;
  • delete your account and your data;
  • withdraw your consent to health information, which deletes that information, keeps your account, and does not affect what we did before;
  • object to how we use your data, or ask us to limit it.

You can withdraw your consent and delete your account in your settings. For anything else, write to contact@christina.app from the email address on your account. We answer within 30 days, and we never treat you differently for using these rights. If you live in the EU or the UK and you are not satisfied with our answer, you can complain to your data protection authority.

Age

Christina is only for people aged 18 and over. If we learn that someone under 18 has an account, we delete it.

Security

We protect your data with encrypted connections, one-way hashes for passwords and codes, a database that cannot be reached from the internet, and access limited to the people who run Christina. No system is perfectly secure. If a breach puts your data at risk, we will tell you and the authorities as the law requires.

Cookies

Christina uses up to three cookies, all of them for it to work:

  • a sign-in cookie that keeps you signed in, for up to 30 days;
  • a language cookie that remembers the language you chose, for up to 400 days;
  • an appearance cookie that remembers whether you chose light or dark in your settings, for up to 400 days; it exists only if you chose one.

We use no analytics or advertising cookies, so there is nothing to accept or refuse.

Changes to this policy

We publish every change here, with a new date at the bottom of the page. If a change matters, we will email you before it applies.

Contact

Questions, requests and complaints: contact@christina.app.

Last updated October 2, 2026