Privacy Policy
In short. Nel is a journal you write to about your day. What you write is processed so that Nel can reply, remember context and prepare summaries. We do not sell your data, we show no ads and we do not train AI models on your entries. You can review, correct and delete everything from inside the app, including your whole account. Replies are generated by a third-party AI provider and part of our infrastructure is in the USA. Details below.
- Controller and contact
- Scope
- What data we process
- Purposes and legal bases
- Health and sensitive data
- Artificial intelligence
- Who processes data for us
- Transfers outside the EEA
- How long we keep data
- Your rights
- Security
- Age of users
- Notifications
- Product analytics
- Website and cookies
- Changes
1. Controller and contact
The controller of your personal data is DGC E-COM (a sole proprietorship registered in the Polish CEIDG business register), Gdynia, Poland, tax ID (NIP) 9581754483 Antoni Ciechanowicz DGC E-COMFull registration details
ul. Bosmańska 32 lok. 19, 81-116 Gdynia, Poland
NIP 9581754483
phone +48 516 091 084
e-mail dgcecomapps@gmail.com
dgcecomapps.pl
For anything related to personal data write to dgcecomapps@gmail.com or by post to the address in the registration details above. We reply without undue delay and at the latest within one month.
2. Scope
This policy covers the Nel mobile app (iOS and Android), its backend and this website. Processing is governed by Regulation (EU) 2016/679 (GDPR) and Polish data protection and e-services law.
3. What data we process
We collect only what the app needs to work as described in the Terms. We do not collect GPS location, contacts, photos or data from other apps.
| Category | Specifically | Source |
|---|---|---|
| Account | Account ID, e-mail address, name or display name (if shared by Apple or Google), account creation date, sign-in tokens | You, via Apple or Google sign-in |
| Onboarding and quiz answers | Answers to the introductory questions (how Nel should address you, goals, preferences) and results of the “Get to know each other” quizzes | You |
| Journal entries | The text of your messages to Nel, Nel’s replies, timestamps, mood labels and small next steps that follow from the conversation | You; replies are generated by an AI model |
| Nel’s memory | Short profile entries derived from conversations, day summaries, session summaries, topics to come back to | Generated by an AI model from your entries; editable by you |
| Summaries and reports | Weekly, monthly and yearly summaries, including simple statistics computed in code (days written, mood) | Generated from your entries |
| Habits and progress | Habit names, check-ins, streaks, completed course lessons, badges | You and your activity |
| Safety | A risk flag on a message in which an independent classifier or the model recognised a possible crisis; a hash of the message text used to avoid re-classifying, without the text itself | Generated automatically |
| Device settings | Time zone, country from regional settings (to pick helpline numbers), app language, app version, push token (if you enable notifications) | Your device |
| Subscription | Subscription status, chosen plan, product ID, renewal and expiry dates, billing-system events (no card data) | Apple or Google via RevenueCat |
| AI usage | Token counts and cost of each model call, daily and weekly limits, no content | Generated automatically |
| Product analytics | Pseudonymous events (e.g. “onboarding completed”, “first entry saved”) under a random ID, never with entry content | The app, unless you turn analytics off |
| Support | The content of your e-mails to us | You |
We never see your password: sign-in goes through Apple or Google, and Nel receives only a confirmation of identity plus the data you agree to share in the sign-in sheet.
4. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the service: account, journal, Nel’s replies, memory, summaries, habits, courses | Account, entries, memory, reports, habits, settings | Performance of a contract (Art. 6(1)(b) GDPR); for health data your explicit consent (Art. 9(2)(a)), see section 5 |
| Subscription handling and entitlement checks | Subscription, account ID | Performance of a contract (Art. 6(1)(b)) |
| Crisis safety: recognising content that suggests danger and showing helpline numbers | Entries, risk flags, country | Consent (Art. 9(2)(a)) and our legitimate interest in protecting users (Art. 6(1)(f)) |
| Cost and abuse control: usage limits, protection against automated calls | AI usage, account ID | Legitimate interest (Art. 6(1)(f)) |
| Reminders and notifications | Push token, time zone, chosen times | Performance of a contract at your request; system notification permission you can revoke |
| Product analytics | Pseudonymous events | Legitimate interest (Art. 6(1)(f)); object by turning it off in Settings |
| Support, complaints and disputes | Support, account | Performance of a contract and legal obligations (Art. 6(1)(b) and (c)) |
| Accounting and tax | Subscription | Legal obligation (Art. 6(1)(c)) |
We do not use your data for marketing, advertising profiles or sale to anyone.
5. Health and sensitive data
A journal may naturally contain information about your wellbeing, emotions, mental health, relationships, beliefs or intimate life. Such content is special-category data under Art. 9 GDPR. We process it only on the basis of your explicit consent, which you give when you create an account and choose to write in Nel. Without this consent Nel cannot work, because the whole service consists of replying to what you write.
You can withdraw consent at any time: by deleting your entries and memory in Settings (withdrawal for the future) or by deleting your account (withdrawal together with deletion of all data). Withdrawal does not affect the lawfulness of processing carried out before it.
Nel is not a medical device, does not diagnose and keeps no medical records. We do not share your entries with doctors, insurers, employers or authorities unless the law requires it (section 7).
6. Artificial intelligence
Nel’s replies, memory entries, day summaries, reports and risk classification are generated by large language models. How it works:
- What goes to the model. For each reply we send your current message, a limited window of recent messages, selected memory entries, the previous day’s summary, habit names and onboarding information. The risk classifier receives the message text. Weekly reports receive day summaries, not raw entries.
- Who runs the model. Models run on the infrastructure of Replicate, Inc. (USA). Currently these are Claude models by Anthropic. The provider receives the prompt content; it does not receive your e-mail address or account ID.
- No training. We do not train our own models on your data, and we use providers through their business API terms, under which prompt data is not used to train the provider’s models.
- Memory is under your control. Everything Nel “remembers” is shown on the memory screen. You can correct or delete each entry and switch memory off entirely, in which case Nel does not use the profile, day summaries or follow-up topics.
- No decisions with legal effect. Nel makes no automated decisions about you with legal or similarly significant effects (Art. 22 GDPR). The risk flag only serves to show you helpline numbers inside the app. We do not notify emergency services, family or anyone else.
- The model can be wrong. AI output may be inaccurate or incorrect. Do not treat it as medical, legal or financial advice.
7. Who processes data for us
We do not sell or share data for marketing. We use trusted providers who process data on our behalf under data processing agreements (Art. 28 GDPR), only to the extent needed to provide the service:
| Provider | Role | Data | Location |
|---|---|---|---|
| Convex, Inc. | Database and app backend (servers, job scheduling) | All data in section 3 except support e-mails | USA |
| Clerk, Inc. | Sign-in and account management | Account ID, e-mail, name, Apple/Google identity, sessions | USA |
| Replicate, Inc. | Running AI models (Anthropic Claude models) | Prompt content described in section 6 | USA |
| RevenueCat, Inc. | Subscription handling and entitlement verification | Account ID, subscription status and history, store transaction IDs | USA |
| Apple Inc. / Apple Distribution International Ltd. | Sign in with Apple, App Store payments, push delivery (APNs) | Per Apple’s policy; we receive identity and purchase status | Ireland / USA |
| Google Ireland Ltd. / Google LLC | Google sign-in, Google Play payments, push delivery (Firebase Cloud Messaging) | Per Google’s policy; we receive identity and purchase status | Ireland / USA |
| Expo (650 Industries, Inc.) | Sending push notifications to devices and delivering app updates | Push token, notification title and body (no entry content), app version ID | USA |
| PostHog, Inc. | Product analytics | Pseudonymous events without content, under a random ID | EU (servers in Germany) |
| [WEBSITE HOSTING PROVIDER] | Hosting this website | Server logs (IP address, time, requested URL) | [COUNTRY] |
We may also disclose data where the law or a lawful request of a competent authority requires it, and to legal and accounting advisers as needed for a dispute or accounts. In a reorganisation, sale or merger of the Operator, data may pass to a legal successor bound by this policy.
8. Transfers outside the EEA
Some providers in section 7 process data in the United States. Transfers rely on the European Commission’s adequacy decision for the EU-US Data Privacy Framework where the provider is certified, and otherwise on the Standard Contractual Clauses adopted by the European Commission (Art. 46(2)(c) GDPR) with supplementary measures such as encryption in transit. You can obtain a copy of the safeguards by writing to the address in section 1.
9. How long we keep data
- Entries, memory, summaries, habits, progress: as long as you have an account. You can delete them at any time in Settings (“Delete all data”) without deleting the account. Subscription expiry does not delete data.
- Account: until you delete it in the App (“Delete account”) or on request to the address in section 1. Deleting the account removes all the data above, the account at the sign-in provider and your analytics profile.
- Risk flags: deleted with the entries and the account. The hashes used to avoid re-classification are deleted automatically after 180 days.
- Billing-system subscription events: technical markers deleted after 90 days; subscription status as long as you have an account.
- Accounting data: for the period required by tax and accounting law (as a rule 5 years from the end of the year).
- Support correspondence: up to 3 years after the case is closed, for potential claims.
- Infrastructure provider backups: removed in the provider’s standard cycle after deletion from the main database.
10. Your rights
You have the right of access, rectification, erasure, restriction, data portability, objection to processing based on legitimate interest, and withdrawal of consent at any time.
Most of these you can exercise yourself in the app:
- Access and portability: the “What Nel remembers” screen shows everything Nel remembers, and your entry and summary history is available in the app. You can obtain a copy of your data in a machine-readable format by writing to the address in section 1; we provide it within 30 days.
- Rectification: every memory entry can be edited.
- Erasure: “Delete all data” in Settings removes entries, memory, summaries and reports; “Delete account” in the App (or a request by e-mail) removes everything including the account.
- Objection to analytics: the toggle in Settings.
- Limiting AI profiling: the memory toggle on the “What Nel remembers” screen.
Requests that cannot be handled in the app go to the address in section 1. We may ask you to confirm your identity, for example by writing from the e-mail address linked to the account.
You also have the right to lodge a complaint with a supervisory authority, in Poland the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl, or with the authority of your EU country of residence.
11. Security
- All communication between the app, our backend and providers is encrypted in transit (TLS).
- Data in the database is encrypted at rest by the infrastructure provider.
- Every database query runs in the context of the signed-in user; server code returns only data belonging to that account.
- Keys to AI and billing providers live only on the server, never in the app on your device.
- Sign-in tokens are stored in the device’s secure system storage (Keychain on iOS, Keystore on Android).
- Staff access to production data is limited to the necessary minimum and used only for support and incident handling.
No system is fully secure. If a data breach occurs that is likely to result in a high risk to your rights, we will inform you in accordance with Art. 34 GDPR.
12. Age of users
Nel is intended solely for adults (18+). We do not direct the service at children and do not knowingly collect data of minors. If we learn that an account belongs to a person under 18, we will delete it together with its data. If you believe this has happened, write to the address in section 1.
13. Notifications
Push notifications stay off until you enable them in the app and in the system. A notification is a short reminder or a question referring to a topic from your conversation, without quoting your entries. You can disable notifications at any time in the app or system settings; we then delete the device token.
14. Product analytics
To learn which screens work and which lose users, we collect product events (e.g. “onboarding started”, “message sent”, “subscription purchased”). Events are tied to a random identifier, not to your e-mail, and never contain entry content, memory, habit names or onboarding answers. Analytics is on by default under our legitimate interest; you can turn it off in the app’s Settings, and deleting your account also deletes your profile in the analytics tool.
15. Website and cookies
This website is static. It uses no cookies, analytics tools, advertising pixels or embedded third-party content. The hosting provider may keep standard server logs (IP address, time, requested URL, browser) for security and diagnostics, under the provider’s retention cycle.
16. Changes
We may update this policy when the app, providers or the law change. We will inform you of material changes in the app or by e-mail before they take effect. The current version is always available at this address with the effective date at the top.