Privacy Policy
Last updated: 4 August 2026 · Draft – have it reviewed by a lawyer before publishing.
Eunoa is a tool for reflection and journaling. It is not a substitute for therapy, does not make diagnoses, and is intended only for people aged 18 and over. Anonymity matters to us: there is no user account, and your conversation content stays on your device by design.
Controller
Zino Diem
Goldhaldenstrasse 23
8702 Zollikon
Switzerland
Email: zino@eunoa.space
Eunoa is operated by an individual. For access, rectification, or erasure requests, or in case of a dispute, the controller can be reached at the contact details above; email is the fastest route to a reply.
What data is processed
On your device (not by us):
- Your conversations, notes and saved memories are stored only locally on your device (encrypted) and are automatically deleted after 14 days. You can erase all of them in the app at any time.
On our server (Supabase):
- A random session identifier per conversation plus timestamps, to associate requests and limit abuse. This identifier contains no real name. Retention: 14 days.
- Safety events: if a message indicates a possible acute crisis (risk to self or others), we store the assessed risk level and a truncated excerpt (max. 500 characters) of the triggering message. Purpose: keeping the crisis detection safe and improving it. Retention: 14 days.
- Your IP address is processed technically when you make a request (request delivery, rate limiting). It is not stored persistently linked to your content.
We do not store full conversation transcripts on the server.
Recipients / processors
To provide the app we use carefully selected service providers:
- Anthropic – the AI model that generates replies and the crisis assessment.
- Vercel (AI Gateway) – routes requests to the AI providers, with zero-data-retention enabled (providers do not store the content).
- OpenAI – turns messages into a numerical representation (embedding) to find relevant prompts. Also with zero-data-retention.
- Supabase – hosts the database described above (sessions, safety events).
- Apple or Google – if you use voice input, your device's operating system converts speech to text, transmitting it to Apple or Google in the process.
Some of these providers process data outside the EU (including the USA). Such transfers rely on appropriate safeguards (e.g. EU Standard Contractual Clauses).
What we do not do
No advertising, no tracking, no analytics SDKs, no selling of data, no profiling.
Legal bases
Processing is based on your consent (Art. 6(1)(a) GDPR, confirmed at start) and on our legitimate interest in secure, abuse-free operation (Art. 6(1)(f) GDPR), in particular for crisis detection and rate limiting.
Your rights
You have the right to access, rectification, erasure, restriction and objection, and the right to lodge a complaint with a supervisory authority. Because we do not identify you, server-side data can only be addressed via the random session identifier; all server-side data is automatically deleted after 14 days in any case. You can delete local data yourself in the app at any time.
Minors
Eunoa is intended exclusively for people aged 18 and over.
Changes
We may update this policy. We will indicate material changes in the app and, where necessary, ask for renewed consent.
Contact
Privacy questions: zino@eunoa.space