Privacy Policy
Last updated: 12 July 2026
In short
- Enodo is a private space for self-reflection. We collect as little as possible to run it.
- Your reflections are never used to train AI models, and never sold or used for advertising.
- Your entries are encrypted (AES-256) and stored on our servers so the App can work across your devices and use AI features. We do not read your entries.
- To generate insights, your text is sent to our AI provider (Anthropic) and processed only to give you a response — not to train their models.
- You can export or delete your data, or delete your account, at any time.
1. Who is responsible for your data
Enodo is operated by Ilia Elistratov, an individual developer based in Türkiye. For any privacy question or request, contact us at il.elistratov@gmail.com.
2. What we collect
- Account data: your email address (used to create and secure your account).
- Guest mode: you can start using the App without creating an account. Your entries are still stored encrypted on our servers under a temporary identifier, and are linked to your account if you create one later.
- Your Content: the text of your reflections, journal entries, and anything you add in the App.
- Technical data: basic device and usage information (e.g. app version, device type, interactions) needed to run and improve the App.
- Payment data: handled by Apple or Paddle. We do not see or store your card details; we may receive limited transaction status (e.g. whether a subscription is active).
3. Why we process your data, and our legal basis
- To provide the App (create your account, save your reflections, generate insights) — legal basis: performance of our contract with you.
- To keep the App secure and working and to improve it — legal basis: our legitimate interests.
- To communicate with you about your account (e.g. password reset, essential notices) — legal basis: contract / legitimate interests.
- Where the law requires consent (for example certain analytics), we ask for it and you can withdraw it at any time.
4. Where your data is stored
Your account and Your Content are stored on our backend infrastructure provided by Supabase. Unlike some device-only apps, Enodo stores your reflections on secure servers so features can work across sessions and devices.
5. AI processing
When you use AI features, the relevant text is sent to our AI provider, Anthropic, which processes it solely to generate the response you requested and returns it to the App.
- Your content is not used to train Anthropic's models (their API does not train on submitted data by default).
- We do not sell your content and do not use it for advertising.
6. Who we share data with (service providers)
We share data only with providers that help us run the App, under their own privacy terms:
- Supabase — data storage and authentication.
- Anthropic — AI processing.
- Apple and Paddle — payment processing for subscriptions.
- PostHog — product analytics. We send pseudonymous usage events (such as onboarding steps and feature usage) — not the content of your reflections.
- Resend — email delivery (such as password resets and account notifications).
We do not sell your personal data to anyone.
7. Your rights
Depending on where you live (including under the EU GDPR and Türkiye's KVKK), you can:
- access a copy of your data;
- correct inaccurate data;
- delete your data ("right to be forgotten");
- export your data;
- object to or restrict certain processing;
- withdraw consent where processing is based on it.
To exercise any of these, contact us at il.elistratov@gmail.com.
8. Deleting your account and data retention
You can delete your account at any time in the App. When you do, we delete Your Content and account data from our active systems within a reasonable period. Some minimal records may be kept where required by law (e.g. accounting or fraud prevention).
9. International data transfers
Our providers may process data outside your country, including in the United States. Where required, such transfers rely on appropriate safeguards (such as Standard Contractual Clauses).
10. Children
Enodo is intended for users 18 and older. We do not knowingly collect data from children. If you believe a minor has used the App, contact us and we will delete the data.
11. Security and encryption
Your reflections and other personal entries are encrypted using AES-256, both in transit and at rest. The encryption key is stored separately from the database in a secure vault, so if someone gained access to the raw database, they would see only unreadable data. Access between users is isolated, so one user cannot read another user's entries.
Your entries are decrypted only automatically, inside our secure server functions, and only to perform the actions you requested (such as generating an insight or sending text to the AI). We do not read your entries and we do not access them manually.
Please note: because AI features require your text to be processed on our servers, Enodo is not end-to-end encrypted — full end-to-end encryption would make AI-generated insights impossible.
No system is 100% secure, but we apply reasonable technical and organizational measures to reduce risk.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date above and, for material changes, notify you in the App or by email.
13. Contact
For any privacy question or request: il.elistratov@gmail.com.