Ascend

Data & Compliance

Last updated: June 2, 2026

Ascend operates globally and is committed to handling your data lawfully, transparently, and securely. This page summarizes the frameworks we align with and the practical controls we have in place. For full detail see our Privacy Policy and Terms of Service.

Regulatory frameworks

  • EU GDPR & UK GDPR — lawful bases documented per processing activity; data subject rights honored within 30 days; SCCs + UK IDTA for international transfers.
  • CCPA / CPRA (California) — right to know, access, correct, delete, and limit use of sensitive personal information. We do not sell or share personal information.
  • VCDPA, CPA, CTDPA, UCPA and other US state privacy laws — handled under the same controls as CCPA.
  • COPPA — service is not directed to children under 13; under-16 sign-ups are not permitted.
  • Brazil LGPD & Canada PIPEDA — equivalent rights honored on request.
  • Apple App Store — App Tracking Transparency respected; we do not track users across other apps and websites for advertising.

Data subject & consumer requests

You can exercise your rights directly in the app (Settings → Profile to edit, Settings → Danger zone to delete) or by emailing privacy@ascends.live. We verify the identity of the requester and respond within 30 days (extendable once for complex requests, with notice).

Sub-processors

  • Supabase — managed Postgres, authentication, file storage.
  • Cloudflare — hosting, CDN, DDoS protection.
  • Google & OpenAI (via Lovable AI Gateway) — AI model inference. Inputs and outputs are not used to train third-party models.
  • Stripe — payment processing on the web.
  • Apple & RevenueCat — iOS in-app purchase processing and receipt validation.
  • Resend (or equivalent) — transactional email.

An up-to-date list is available on request to privacy@ascends.live. We will notify you of material changes.

International data transfers

For transfers of personal data outside the EEA/UK to the US or other third countries, we rely on the European Commission's Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum, combined with supplementary measures: encryption in transit (TLS 1.2+), encryption at rest, role-based access, and audit logging.

Security controls

  • Row-level security on every user-owned table; least-privilege service roles.
  • TLS in transit; AES-256 at rest on our managed database and storage.
  • Secrets stored in a dedicated secret manager, never in source.
  • MFA on all administrative accounts.
  • Automated dependency & vulnerability scanning; timely patching.
  • Logging and alerting for suspicious activity.
  • Documented incident response plan and breach-notification process.

Retention & deletion

Account and app data is retained for as long as your account is active. When you delete your account, production data is removed within 30 days and purged from encrypted backups within 90 days. Limited billing records may be retained as required by tax law (typically 7 years).

AI & automated processing

Ascend's AI features generate suggestions and coaching responses. They do not make decisions that produce legal or similarly significant effects on you. Inputs and outputs are processed solely to deliver the feature you asked for and are not used by us to train third-party models.

Cookies

We use only strictly-necessary cookies (login session, CSRF protection) and limited functional local storage (UI preferences). We do not use third-party advertising or cross-site tracking cookies, so we do not display a cookie consent banner outside of that scope. If we add optional analytics in the future, we will request opt-in consent in EEA/UK.

Reporting a concern

Privacy: privacy@ascends.live
Security vulnerabilities: security@ascends.live
Supervisory authority: you may also lodge a complaint with your local data protection authority (e.g. the UK ICO or your national EU DPA).