
When you use DPNR we collect:
| Purpose | Legal basis |
|---|---|
| Deliver Companion, Decision Room, Mirror Room, and other guided AI features | Contractual necessity |
| Store and display your content and history | Contractual necessity |
| Process subscription payments | Contractual necessity |
| Anonymised analysis to improve AI prompts and product design | Legitimate interest (opt-out available) |
| Aggregate usage reporting (no individual attribution) | Legitimate interest |
| Email transactional messages (account confirmation, billing) | Contractual necessity |
We use anonymised, aggregated data to understand how people use the app and to improve the AI models and prompts. Specifically:
Your content is sent to Anthropic's Claude models, via AWS Bedrock, to generate reflections and suggestions. This runs under Anthropic and AWS's own commercial API data-use terms, under which your inputs and outputs are not used to train their models.
We do not send your email address or account ID to our AI provider — only the content needed to generate a response, and only for the duration of that request.
We share data only with:
We do not sell personal data to third parties.
Under applicable data protection law you have the right to:
To exercise rights not covered in-app: privacy@dpnr.app
All data is encrypted in transit (TLS) and at rest. Your personal content — decisions, reflections, journal entries, and conversations — is additionally protected with per-user application-level encryption: each account has its own encryption key, wrapped under your password (and a one-time recovery code) using AWS KMS. That key is only ever unwrapped, server-side, for a limited window tied to your own session or a feature you've enabled (such as a Daily Card or Weekly Recap) — never held decrypted at rest or kept available indefinitely. This is not end-to-end encryption in the sense that only your device can ever read your content: our systems can and do decrypt it, briefly, to do the processing those features require. We never store your password in plain text, and if you lose both your password and your one-time recovery code, this content cannot be recovered by us or anyone else — there is no backend override.
We use a session cookie to keep you signed in, alongside authentication tokens (issued by AWS Cognito) held in your browser. We do not use tracking or advertising cookies.
We'll notify you by email at least 14 days before any material change to this policy.
Data controller: DPNR Ltd · Tel Aviv, Israel · privacy@dpnr.app