Controller
Roman Olichowski, Bahnhofstraße 20, 56112 Lahnstein, Germany. E-Mail: support@myhumancode.app.
Website and app
Visiting this website does not create an app account or send interview answers to AI. Website visits and email contact are covered by https://myhumancode.app/en/privacy. The information below concerns the app where a feature is available and configured in your version.
Local use and accounts
Profile details and answers can initially be stored on your device. Planet, transit and numerology calculations run locally. This does not mean the entire app makes no network connections. For registration and sign-in, Supabase Auth processes your email address, password for authentication, account ID and session tokens; your confirmation of the minimum age and terms is also recorded with a timestamp. The purpose is to provide and secure your account. Legal basis for required account data: Art. 6(1)(b) GDPR.
Profile, journal and history
Name, date, time and place of birth, interview answers, archetypes and result texts, personal goal, journal and check-in entries and mentor messages are stored locally and, when signed in, synced to your Supabase account. The purpose is to provide your chosen features and saved history (Art. 6(1)(b) GDPR for ordinary personal data). AI sharing is a separate choice: withdrawing it does not automatically stop account synchronisation.
Sensitive content
Free text may contain specially protected information such as health data, religious beliefs or political views. Please do not enter this information in the pre-release version or submit confidential information about other people. Entering text or accepting terms is not explicit consent under Art. 9 GDPR. The existing choice to share information with AI is not presented here as blanket permission to process such content. The handling of sensitive free text, including an appropriate legal basis, must be settled before the general app launch.
AI features and your choice
For analysis, daily reflections, the mentor and voice transcription, the app separately asks for consent to sharing (Art. 6(1)(a) GDPR). Depending on the feature, the profile details used, including name and birth details, interview answers, goal, results, daily and transit data or chat messages are sent through our AI server to OpenAI. The mentor sends at most the last 14 messages plus the personal context used. Your choice is saved per account on the current device. These AI transfers are blocked without consent. You can withdraw it in Settings; new requests are blocked and ongoing client requests are aborted. This does not delete information already received by a provider or affect the lawfulness of processing before withdrawal.
Voice and reading aloud
Recording requires your device microphone permission. For transcription, up to 120 seconds of audio is sent through our server to OpenAI. The app initiates cleanup of temporary recordings after a transcription attempt or cancellation; our AI server does not create its own audio or prompt files. This does not rule out separate provider retention. Built-in web speech recognition and reading aloud may use your browser or operating system’s speech services; exclusively local processing is not promised.
Reports and abuse prevention
If you report an AI response, the selected response (up to 12,000 characters), reason, account ID, review status and timestamp are stored in Supabase and processed by the operator for review. The server also limits requests by IP address and account. Usage records contain account/request ID, AI feature, date, status and timestamps, but no prompt or audio content. Purposes are handling reports, security and preventing abuse (Art. 6(1)(f) GDPR).
Purchases and subscriptions
When store purchases are enabled, Apple or Google handles the purchase. RevenueCat receives your app account ID and purchase/subscription information such as product, term and status to associate and verify access rights. Our server checks access to paid features using that information. This purchase flow does not provide us with full card details or banking credentials. Processing to provide your chosen subscription: Art. 6(1)(b) GDPR. The stores’ own processing is also governed by their privacy notices.
Optional usage analytics
Usage analytics is off by default. If PostHog is configured for your app version and you agree, selected events such as viewing a purchase page are sent with a timestamp and a random persistent device identifier; a verified purchase may also include the monthly or annual plan. Our event code adds no account ID or free text. The identifier is pseudonymous, not anonymous; the connection also exposes technical request data to the recipient. The purpose is to improve the experience, based on your withdrawable consent (Art. 6(1)(a) GDPR and § 25(1) of the German TDDDG). Withdrawal stops new events and removes the local identifier, but does not delete events already held by PostHog.
Reminders
Reminders are scheduled locally with your device permission. Their local data may contain the account ID. This reminder feature does not upload a push token to our server.
Retention in the current app
Profile, results, goals, journal and mentor history generally remain until you delete them or your account. AI reports currently have no additional automatic expiry. Displaying a limited mentor history does not delete older messages. AI usage records older than 35 days are removed when that account next reserves an AI request; no daily cleanup is configured when there are no further requests. Daily reflections are cached locally and are not currently removed simply because they are old. IP request-limit counters are held in memory in 15-minute windows. These are not retention periods for separate provider logs or backups.
Providers and operating details awaiting confirmation
Depending on the feature, the prepared app integrates Supabase (accounts and sync), OpenAI (AI), RevenueCat (purchase status), PostHog (optional analytics) and Apple or Google (stores). The AI server’s hosting provider also processes technically necessary connection data. The actual contracted entities, production storage regions, log/backup periods and any safeguards required for transfers outside the EEA still need final confirmation and must be specified here before the general app launch. This advance notice does not promise exclusively European processing or that particular contracts have already been concluded.
Deletion and contact
Account deletion removes account-linked records from our app database and initiates cleanup of that account’s local storage on the device used. It does not cancel a store subscription or automatically erase every copy, provider log, backup, RevenueCat record or past analytics event. For the steps and a deletion request without app access, see https://myhumancode.app/en/delete-account. Contact: support@myhumancode.app.
Your rights and minimum age
Subject to the applicable legal conditions, you have rights of access, rectification, erasure, restriction, portability and objection, and may withdraw consent. Send requests to support@myhumancode.app; necessary details for handling requests and any required identity checks are processed to fulfil our data protection duties (Art. 6(1)(c) GDPR). You may complain to a supervisory authority, such as the LfDI Rhineland-Palatinate in Germany: https://www.datenschutz.rlp.de/. The app is intended for people aged 16 and over. A minimum age does not replace any legally required consent from a representative.
Automated analysis
The app associates answers with symbolic archetypes and generates personal reflection texts. This is neither a medical diagnosis nor decision-making with legal or similarly significant effects. Results may be inaccurate; you decide which suggestions to use.