← All documentsРусский

Privacy Policy

⚠️ DRAFT. Must be reviewed by a lawyer before publication. This is prepared text, not legal advice. It does not take effect until reviewed by a lawyer admitted to practise in Austria.

Version: 2026-08-22 · Effective: to be confirmed · Updated: to be confirmed


1. In short

We run a platform for mindfulness communities: chat, courses, live classes. This document explains what data about you we end up holding, why, and what you can do about it.

Three things worth knowing up front:

2. Who is responsible for your data

Controller (GDPR Art. 4(7)):

to be confirmed, to be confirmed to be confirmed, Austria Email: to be confirmed Phone: to be confirmed

About the schools. The school you join decides who is admitted to its classes and runs those classes itself. For the data a school processes for its own purposes (member lists, access, communication), the school and the platform are joint controllers (GDPR Art. 26). The allocation of duties is set out in the Teacher Agreement (document 5). You may bring any question to us — we will answer either way.

We do not appoint a Data Protection Officer. The conditions of GDPR Art. 37(1) are not met: we are not a public authority, our core activities consist neither of large-scale regular monitoring nor of large-scale processing of special categories. We will revisit this conclusion as we grow.

3. Where processing happens

What Where
Server: Matrix, database, backend to be confirmed, to be confirmed — Germany, EU
Course video Cloudflare R2, EU region
Payments Stripe (see document 6)
App store, push and — today — outgoing email Apple

The full list is in "Sub-processors" (06-subprocessors.en.md).


4. What data, and why

4.1 Account

What: email address, display name, an internal identifier, a Matrix identifier of the form @name:to be confirmed, your devices and sessions, a password hash (we never hold the password itself).

Why: so you can sign in and so the people you talk to recognise you. Basis: Art. 6(1)(b) — performance of our contract with you. How long: while the account exists; after deletion see §9.

4.2 Messages, files and voice notes

In encrypted rooms (the default for private and group conversation) the server stores ciphertext and encrypted attachments. We cannot decrypt them — the keys are only on your devices.

We do see metadata: who is in a room, when a message was sent, its type, the size of an attachment. This is unavoidable: a server that must deliver a message necessarily knows to whom and when.

In unencrypted rooms (a school's announced common rooms, which are marked as such) the server does see the content. Every room tells you honestly whether it is encrypted.

Basis: Art. 6(1)(b). How long: messages — while the room exists or until you delete them; chat files and voice notes — to be confirmed days.

4.3 Encryption keys

If you enabled key backup, an encrypted copy of your keys is stored on the server. It can only be opened with your recovery phrase, which we do not have. Lose the phrase and no one can restore your history, including us.

Basis: Art. 6(1)(b). How long: while the account exists.

4.4 School membership and access

What: which schools you joined, which courses and clubs are open to you, on what grounds (purchase, code, a decision by the school), your role, join requests.

Basis: Art. 6(1)(b). How long: while the account exists; payment facts per §4.6.

🔴 Special category data. Taking part in a mindfulness school may reveal your religious or philosophical beliefs — that is Art. 9 GDPR. Joining a school is therefore based on your explicit consent (Art. 9(2)(a)), and we do not use this information for marketing, profiling or recommendations. Withdrawing consent means leaving the school; withdrawal does not affect what was done before it.

4.5 Learning progress

What: which lessons are open and completed, your playback position.

Why: so you can resume where you stopped and so the teacher can see how the group is doing. Basis: Art. 6(1)(b). How long: while the account exists.

4.6 Payments

What: your customer identifier at the payment provider, amounts, currency, payment status, what was bought, dates, subscription status, refunds.

We do not hold card data. The payment provider takes and stores it; we receive only the outcome.

Basis: Art. 6(1)(b) for the purchase itself and Art. 6(1)(c) for keeping the records tax law requires. How long: 7 years — the retention period for accounting records under § 132 BAO (Austria). This period survives account deletion.

4.7 Class recordings

Governed by a separate document: recording-retention.md. In short: without your explicit consent your track is not recorded at all; withdrawal takes effect immediately and deletes what was already recorded; the consent decision log is kept longer than the recording itself (basis: Art. 17(3)(e), establishment and defence of legal claims).

4.8 Course video

What: requests for protected video — which lesson, when, from which address.

Why: paid video is unlocked by a short-lived signed token; without a request log we cannot tell you from a stranger who copied the link. Basis: Art. 6(1)(f) — protecting paid content from unauthorised access. How long: no longer than to be confirmed days.

4.9 Push notifications

A notification sent through Apple contains only event and room identifiers and an unread counter. Neither message text nor sender name is in it — your device fills those in after decryption.

Basis: Art. 6(1)(a) — you turn notifications on yourself and can turn them off in device settings. Notifications are off by default at server level.

4.10 Content reports

🔴 When you report a message from an encrypted room, your device attaches a decrypted excerpt of the conversation to the report — otherwise there would be nothing to review: the server only sees ciphertext.

This means: by filing a report you pass us the content of that excerpt, including other people's words. We use it only to handle the report.

What we keep: who reported, what, the reason, the attached excerpt, the decision and its reasoning. Basis: Art. 6(1)(c) — the platform's duty under the DSA to act on notices; Art. 6(1)(f) — community safety. How long: to be confirmed days after the case is closed, to allow an appeal; the excerpt is then deleted and only the record of the decision remains.

4.11 Moderation and action log

What: decisions by school staff (restriction, removal, ban), who took them and when, platform decisions, and users you have blocked.

Basis: Art. 6(1)(f) — safety and accountability; Art. 6(1)(c) — DSA. How long: 3 years (the general limitation period), so a decision can be appealed and explained.

4.12 Transcription of published video

Video and descriptions a school publishes (welcome video, course description, free previews) are checked before publication. Where the check covers video, speech is converted to text.

🔴 For now this check is manual. Speech transcription is not switched on yet: published material is reviewed by a person, and description texts are checked for references to paying elsewhere. The paragraph below describes what happens once transcription is enabled; no provider has been chosen for it (document 6, §3), and until one is, no voice processing takes place.

This is processing of personal data: the speaker's voice and the content of their speech. Basis: Art. 6(1)(c) and Art. 6(1)(f) — the app store's requirement to moderate published material and our legitimate interest in not losing the app. Details in document 7.

We do not transcribe or scan private conversations. Only what a school publishes for everyone is checked.

4.13 Support

What: your messages and requests. Basis: Art. 6(1)(b) and Art. 6(1)(f). How long: 2 years.

4.14 Technical logs and security

What: IP address, request time, device and app type, error codes.

Why: without this we could neither stop password guessing nor diagnose an outage. Basis: Art. 6(1)(f) — service security. How long: 14 days, then deleted automatically. Longer only for a specific incident.

4.15 Extra services, if a school enabled them

Neither is on by default. A room linked to an external service is marked.


5. What we do not do

6. Who receives data

Only those needed to make the service work: hosting, video delivery, payments, the app store, email. Each under a data processing agreement (GDPR Art. 28). Full list with purpose and location: 06-subprocessors.en.md.

Beyond that we disclose data only on a binding request from a public authority, and only to the extent required.

7. Transfers outside the EU

Core processing is in the EU. Some providers (Apple, Stripe, Cloudflare) may process data in the United States. This happens on the basis of the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework, where the provider participates in it. Details per provider in document 6.

8. Automated decisions

Content a school publishes goes through a check (§4.12), and as a result publication may be rejected. While the check is manual there is no automated decision at all; what follows applies from the moment automated checking is switched on.

🔴 Automation does not make the final decision. Any rejection can be appealed, and a human reviews the appeal. This is required by Art. 22 GDPR. The procedure is in document 7.

9. Retention — summary

Data Period
Account, profile while the account exists
Messages while the room exists / until you delete them
Chat files and voice notes to be confirmed days
Learning progress while the account exists
Payment records 7 years (§ 132 BAO)
Class recordings per recording-retention.md
Recording consent log longer than the recording, see the same document
Reports: attached excerpt to be confirmed days after the case closes
Moderation decisions 3 years
Technical logs 14 days
Support correspondence 2 years

If an item is the subject of a report, it is not deleted on schedule until the case is closed — otherwise there would be nothing left to review, and a decision must be reasoned.

10. Your rights

Under the GDPR you may:

How: email to be confirmed. We answer within one month; for a complex request the period may be extended by two further months — we will tell you.

You can delete your account in the app, without writing to us: Settings → Account → Delete account. Details in document 8.

Complaint to a supervisory authority. If you believe we are infringing your rights: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at. You may also complain to the authority where you live.

11. Age

The service is intended for people aged 16 and over. We do not knowingly collect data from children below that age. If such an account comes to light we will delete it — tell us at to be confirmed.

A child may watch a school's classes together with a parent — but then the account is the parent's, and an adult is responsible for it.

12. How we protect data

13. Data breach

If a breach occurs that could harm you, we will notify the supervisory authority within 72 hours and you without undue delay (Art. 33, 34).

14. Changes

We announce material changes in the app and by email at least 14 days before they take effect. Previous versions remain available at permanent addresses.

15. Languages

The source version is Russian. English translation: this document. In case of a discrepancy in meaning, the Russian version prevails.

16. Contact

Data questions: to be confirmed Support: to be confirmed Content reports: to be confirmed Postal address: to be confirmed, to be confirmed, Austria

“To be confirmed” in place of a detail means exactly that: the value has not been filled in yet. We do not put invented data here.