Privacy Policy
Last updated: 8 July 2026
Dextenso Consult SRL
Avenue Louise 523, 1050 Brussels, Belgium
Enterprise number: BE0478.404.790
Email: contact@ondyne.ai
Personal Data We Collect
Data you provide: email, profile info, journaling text, preferences, communications. This may include special categories (emotional states, beliefs, health reflections). We process such data only with your explicit consent.
Data collected automatically: device info, IP address, OS/app version, usage metrics, crash logs.
How We Use Your Data
Operate and provide the Ondyne service.
Generate personalized contemplative insights and prompts.
Maintain, secure, and improve the app.
Sync your content across devices.
Communicate updates and provide support.
Comply with legal obligations.
Use of Journaling & Emotional Data
Your reflections may be processed to generate prompts, suggestions, and deeper self-reflection cues.
Processing is supportive, not medical or therapeutic, and does not involve automated decision-making with legal effects.
Legal Bases
Contractual necessity (Art. 6(1)(b) GDPR).
Legitimate interests (Art. 6(1)(f)).
Consent (Art. 6(1)(a)).
For special-category data we rely on explicit consent (Art. 9(2)(a)) plus the need to provide the requested wellness features.
AI Models & Processors
Ondyne uses third-party AI models — including models from Anthropic (Claude), OpenAI (GPT), and Google (Gemini) — routed through OpenRouter. Your inputs are processed by these models to generate your mirror, insights, and prompts.
When you use voice dictation, your audio is transcribed by Deepgram. Audio is processed in real time to produce text and is not used to train models.
We set OpenRouter’s data-collection policy to “deny” on every request, so routing is restricted to providers that do not log or train on prompts, and your content is not reused for external model training.
These providers act as GDPR processors under Article 28 agreements; data is minimized and pseudonymized where possible.
Data Storage
We store data on Supabase (EU-hosted) under a GDPR-compliant DPA with strong access controls.
Sub-processors
We rely on the following processors, each under a GDPR Article 28 data processing agreement:
Supabase — database and storage hosting (EU region).
Vercel — application hosting and content delivery.
OpenRouter — routing to AI model providers (Anthropic, OpenAI, Google), with data collection set to “deny”.
Deepgram — real-time voice transcription.
Stripe — subscription payment processing.
We will update this list before adding a new sub-processor.
Security
Encryption in transit (TLS) and at rest.
Role-based access controls, audits, and secure development practices.
Your Rights
Access, rectify, delete (“right to be forgotten”).
Withdraw consent, restrict processing, data portability, object.
File a complaint with the Belgian Data Protection Authority.
Contact: contact@ondyne.ai.
Children’s Privacy
Ondyne is not intended for individuals under 13 years old.
International Transfers
When data reaches AI providers outside the EU, transfers rely on SCCs, adequacy decisions, or equivalent safeguards.
Retention
We keep data only as long as needed for the stated purposes or as required by law.
You can delete your data via the app or by contacting us.
Changes & Contact
We may update this policy and will notify you of significant changes.
Questions: contact@ondyne.ai.