Back to About

Privacy Architecture

Data Transparency

What you write here is the most honest thing you own. This page explains exactly how that material is handled — where it lives, who can see it, and what we cannot access.

Core Principles

Encrypted at Rest

Every journal entry, compass log, conversation record, and audit is encrypted before it is stored. The data is not readable in transit or at rest by anyone who does not hold your session — including us.

Visible Only to You

Your records are scoped to your authenticated account. No other user — not an admin, not a moderator, not another practitioner — can read your journal, your session logs, or your Erebus Audit submissions. The system enforces this isolation at the database layer.

No Cross-User Access

Row-level security ensures that every query is filtered by the requesting user's identity. There is no global read path. Even if an entity type is shared across the platform, your records within it are invisible to every account but your own.

No Training on Your Data

Your journal entries, conversation logs, and audit responses are never used to train language models or improve external systems. The AI that observes your patterns operates on your data in the context of your session — it does not learn from you for anyone else.

What Is Stored

Journal Entries

Your reflections, reframes, dark notes, and thin audits. Each entry is tied to your account and encrypted. You can delete any entry at any time — deletion is permanent and irreversible.

Conversation Logs

Records of your sessions with NYX, including the pattern tags she identified. These logs exist so NYX can maintain continuity across sessions — so she remembers what she observed last time without you having to repeat it.

Compass Logs & Character Entries

Structured self-tracking data — pull types, time pulls, body signals, intensity readings, and core-needs strain. Stored per user, encrypted, and deletable.

Erebus Audit Submissions

The intake responses you submit for analysis. The analysis result is generated, stored to your record, and delivered to the email you provided. No other account can access your submission.

What We Never Do

  • Sell your data to third parties.
  • Share your journal or logs with other users.
  • Use your reflections to train external AI models.
  • Access your entries for research without explicit consent.
  • Retain your data after you delete it — deletion is final.

Your Control

You can delete any record at any time from within the app. If you delete your account, all associated data is purged. There is no archive. There is no soft delete. What you remove is gone.

If you have questions about your data or want a full export of everything stored under your account, contact Base44 support and we will facilitate the request.