Back

DPNR · InnerOS

Privacy & Data Policy

Effective date: June 2026 · Last updated: June 2026

What We Collect

When you use DPNR we collect:

  • Account data: Email address, hashed password (managed via AWS Cognito) or OAuth token, and subscription tier.
  • Your content: Everything you type into the app — Companion conversations, Decision Room narratives and options, Mirror Room reflections, journal check-ins, commitments, and outcomes.
  • Usage data: AI token consumption per session, step completion events, and timestamps.
  • Payment data: Subscription status and billing history. Card details are held exclusively by Grow (our payment processor) — we never store raw card numbers.

How We Use Your Data

PurposeLegal basis
Deliver Companion, Decision Room, Mirror Room, and other guided AI featuresContractual necessity
Store and display your content and historyContractual necessity
Process subscription paymentsContractual necessity
Anonymised analysis to improve AI prompts and product designLegitimate interest (opt-out available)
Aggregate usage reporting (no individual attribution)Legitimate interest
Email transactional messages (account confirmation, billing)Contractual necessity

Anonymised Analysis

We use anonymised, aggregated data to understand how people use the app and to improve the AI models and prompts. Specifically:

  • All personal identifiers are stripped before analysis.
  • We look at patterns — e.g. which lens types are most used, common emotional themes — never at individual narratives.
  • Aggregated findings may inform product decisions, published research, or AI model improvements.
  • You can opt out by emailing privacy@dpnr.app with the subject "Opt out of analytics".

AI Processing

Your content is sent to Anthropic's Claude models, via AWS Bedrock, to generate reflections and suggestions. This runs under Anthropic and AWS's own commercial API data-use terms, under which your inputs and outputs are not used to train their models.

We do not send your email address or account ID to our AI provider — only the content needed to generate a response, and only for the duration of that request.

Data Sharing

We share data only with:

  • Amazon Web Services (AWS) — authentication (Cognito), database and encrypted content storage (DynamoDB), and AI response generation (Bedrock/Anthropic Claude — sent the conversation content needed for that request only)
  • Grow — Israeli payment processing (billing data only)
  • Render — application hosting

We do not sell personal data to third parties.

Data Retention

  • Your decisions and reflections are retained for as long as your account is active.
  • When you delete your account, all personal data is permanently deleted within 30 days.
  • Anonymised, aggregated analytics data (no personal identifiers) may be retained indefinitely.
  • Payment records are retained for 7 years as required by Israeli accounting law.

Your Rights

Under applicable data protection law you have the right to:

  • Access: See all data we hold about you (use "Download my data" in account settings)
  • Portability: Export your data as machine-readable JSON
  • Erasure: Delete your account and all associated data (use "Delete my account" in account settings)
  • Correction: Edit your decisions and reflections directly in the app
  • Restriction: Ask us to pause processing while a dispute is resolved
  • Objection: Opt out of legitimate-interest processing (analytics)

To exercise rights not covered in-app: privacy@dpnr.app

Security

All data is encrypted in transit (TLS) and at rest. Your personal content — decisions, reflections, journal entries, and conversations — is additionally protected with per-user application-level encryption: each account has its own encryption key, wrapped under your password (and a one-time recovery code) using AWS KMS. That key is only ever unwrapped, server-side, for a limited window tied to your own session or a feature you've enabled (such as a Daily Card or Weekly Recap) — never held decrypted at rest or kept available indefinitely. This is not end-to-end encryption in the sense that only your device can ever read your content: our systems can and do decrypt it, briefly, to do the processing those features require. We never store your password in plain text, and if you lose both your password and your one-time recovery code, this content cannot be recovered by us or anyone else — there is no backend override.

Cookies

We use a session cookie to keep you signed in, alongside authentication tokens (issued by AWS Cognito) held in your browser. We do not use tracking or advertising cookies.

Changes

We'll notify you by email at least 14 days before any material change to this policy.

Data controller: DPNR Ltd · Tel Aviv, Israel · privacy@dpnr.app