Enara is offered from Germany. That means the European General Data Protection Regulation (GDPR) applies to your data, wherever you live. This English version is provided for your convenience. In case of any dispute, the German version at getenara.app/datenschutz.html is the legally binding one.
1. Controller
Jakov Brekalo (sole proprietorship)
Schwanenplatz 3, 93047 Regensburg, Germany
Email: support@getenara.app
For any question about privacy, reach us at that email address. We have not appointed a separate data protection officer, because we are not legally required to.
2. Overview and basic principle
Enara is an app for journaling, rituals and a personal conversation with an AI companion. We handle your data sparingly. Much of it stays stored locally on your device. Data only leaves your device where a feature needs it to (account, syncing between devices, AI answers, voice recording). This policy explains what happens and when.
3. What data we process and what for
a) Account and sign in
An account is required to use the app. For it we process your email address and a password (stored encrypted). You can also sign in with Google or Apple, in which case we receive an identifier and your email address from those providers.
- Purpose: providing the account, signing in, syncing between devices.
- Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
- Processor: Supabase (see section 5).
b) Your content (journal, rituals, profile, conversations)
Your journal entries, ritual answers, your profile (among other things your name, date of birth for the star sign, your wish, your life area) and your conversations with the companion are first stored locally on your device. When syncing is switched on, they are additionally stored on our server (Supabase) so they are available on your devices. Transmission is encrypted (TLS). On the server, the data center's standard encryption and strict access rules (access only through your account) protect your data. Enara does not currently offer end to end encryption, meaning encryption where even we would be technically unable to read the content.
- Purpose: the core function of the app, backup and syncing of your entries.
- Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
c) Special categories and sensitive content
What you write in Enara can allow conclusions about your mental state or your health (Art. 9 GDPR). We only pass such content to an AI service if you have explicitly consented (Art. 9(2)(a) GDPR). We ask for that consent once, before Enara answers you for the first time, in a separate step during onboarding. It is voluntary: if you say no, your rituals, your journal, your sentences and the guide stay fully usable, Enara just will not answer you freely.
You can withdraw your consent at any time with effect for the future, in the settings under "Enara may answer". From the moment you withdraw it, no text leaves your device toward an AI service.
Separately from that, the switch "Enara may read what I write" controls whether your freely written journal pages feed into the conversation at all.
d) AI companion (coach)
When you write to the companion, your message and an excerpt of context are sent to Anthropic (Claude models) to generate the answer. The getting to know you conversation during onboarding, the daily nudges, the morning and evening greetings and the optional polishing of a journal entry also run through this service.
- Purpose: generating the companion's personal answers and texts.
- Legal basis: your consent, Art. 6(1)(a) GDPR, and for sensitive content additionally Art. 9(2)(a) GDPR (see section 3c).
- What Anthropic may do with it: content submitted through the programming interface is not used to train the models. According to Anthropic, inputs and outputs are deleted automatically within 30 days. Anthropic names one explicit exception: content flagged by their automated safety systems is kept for up to two years. That can affect exactly the kind of text that touches on self-harm or suicidal thoughts. A data processing agreement including EU standard contractual clauses is part of the terms of service.
- Note: Anthropic is based in the USA (see section 6 on transfers to third countries).
e) Voice input (transcription)
If you use voice recording, the recorded audio file is sent to Groq to be turned into text (Whisper transcription). The recognized text then lands in your input field, where you can edit it. We do not store the recording itself.
- Purpose: turning your speech into text.
- Legal basis: your consent, Art. 6(1)(a) GDPR, and for sensitive content additionally Art. 9(2)(a) GDPR (see section 3c).
- What Groq may do with it: For our account, storage is switched off entirely at Groq ("Zero Data Retention"). The recording and the recognized text are therefore not stored at Groq, only processed for the conversion. Without that setting it would be up to 30 days.
- Note: Groq is based in the USA and, by its own account, runs its data centers in the USA, Canada, Finland, Australia and Saudi Arabia; we do not control which location handles a given request (see section 6). A data processing agreement is in place; DP-Dock GmbH, Ballindamm 39, 20095 Hamburg, is named as the EU representative.
f) Subscription and purchases
Every new account gets 3 free days with full access, and no payment data is collected for that. A subscription ("Enara Plus") is handled through Apple's App Store or Google Play. Apple and Google process the purchase and payment data under their own responsibility. Through our service provider RevenueCat we only receive the status of your subscription, never complete payment data.
- Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
g) Notifications
If you switch them on, reminders and nudges are scheduled and shown on your device. For that the app needs the system permission for notifications.
- Legal basis: consent, Art. 6(1)(a) GDPR (switched on in the app and in your system settings).
h) Please note: you are talking to an artificial intelligence
Enara is not a real person. Her answers, greetings and nudges are generated by a language model. We tell you this before you speak with her for the first time, and permanently visibly in the conversation area of the app. This fulfills the transparency obligation under Article 50 of Regulation (EU) 2024/1689 (the AI Act), which applies from 2 August 2026.
Enara does not replace therapy, medical treatment or professional advice. If your words point to a crisis, she names places that can help and does not continue the coaching conversation.
How that works, and what it stores: the app checks the text you send for a fixed list of wordings that point to suicide or self harm. That check runs on our server before the language model is called, and it is the same list for everyone. Where the wording is ambiguous, Enara asks you what you meant instead of assuming. Grief, a loss, a breakup, an illness or losing a job are not treated as a crisis, and Enara stays in the conversation there.
When the check does apply, we store a short lived note that a crisis was detected, so that the protection also holds if you write again later or through another part of the app. That note contains no text of yours. It holds a pseudonymous key, the level, and a timestamp, nothing else. Neither the wording that triggered it nor any journal entry is stored, and the note is deleted automatically after twelve hours. Only our server can read it.
- Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in not answering a crisis with generated text, and Art. 9(2)(c) GDPR where the note allows conclusions about your health.
- Retention: twelve hours, then deleted automatically.
i) Contacting us
If you write to support@getenara.app, we process what you send us in order to handle your request. The mailbox is operated through Zoho (EU).
- Legal basis: Art. 6(1)(b) and (f) GDPR (handling the request, or legitimate interest in communicating with you).
j) News by email (optional)
If you turn on the switch "News by email" in the app settings, we use your email address to occasionally send you news about Enara (for example new features). We store the time of your consent as proof. Without that consent you receive no such emails from us. Pure account and contract messages (for example about signing in or about changes to the terms) are not affected by this.
- Purpose: information about news and features of the app.
- Legal basis: your consent, Art. 6(1)(a) GDPR in conjunction with Section 7(2)(2) of the German Act Against Unfair Competition (UWG).
- Withdrawal: at any time with effect for the future, directly in the app settings or by message to support@getenara.app.
k) Vision board (your photos)
In the vision board you can place your own photos. You pick them yourself from your device's media library. The app does not search your library and only sees the images you select. Every photo is scaled down before saving and stored locally on your device first. If syncing is switched on, a copy is additionally stored encrypted (TLS) in your private area at Supabase, so your board stays available on your devices. The storage path starts with your account identifier, and the access rules only allow your own account in.
If you delete an image or clear the board, the app removes the copy in your account with it. If you delete your account, all photos are deleted too.
- Purpose: displaying your vision board, backup and syncing between your devices.
- Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
- Processor: Supabase (see section 5).
- Note: your photos are not sent to an AI service and are not analyzed.
l) Sharing sentences
When you tap "Share" on a sentence, the app creates an image with that sentence on your device and hands it to your system's share sheet. Where it goes is your decision there, for example to Instagram, to WhatsApp or into your own photos. Nothing is transmitted to us and nothing is stored. Once you have picked an app, that app's privacy policy applies.
- Purpose: passing on a sentence as an image at your explicit instruction.
- Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
m) App lock (fingerprint, face or your own code)
You can set Enara to ask for your fingerprint, your face or a four digit code when you open her. If you use fingerprint or face, your device checks it and tells the app only "recognized" or "not recognized". We never receive biometric data, and it never leaves your device. If you choose a code, we do not store the code itself but a check value derived from it, combined with a random value. It lives in your device's protected key store (Keychain on iOS, Keystore on Android) and is not synced to your account. On a second device you therefore need to turn the lock on again.
If you forget your code, we cannot reset it, because we do not know it. The way back is to sign out and sign in again. Your entries live in your account and stay where they are.
- Purpose: protecting your entries from other people who can already unlock your device.
- Legal basis: performance of a contract, Art. 6(1)(b) GDPR. This processing happens entirely on your device.
n) Rating in the App Store
Enara occasionally asks you for a rating, at most twice a year and only after a moment where something was finished. The dialog itself comes from Apple or Google, not from us. We do not learn whether it was shown to you, whether you rated the app, or what you wrote. The stores give us those numbers only in aggregate.
So that the app does not ask too often, it remembers on your device when it last asked and in which version. These counters stay local and are deliberately not synced to your account. Settings also holds a permanent entry, "Rate Enara", that takes you straight to the store.
- Purpose: helping other people find Enara.
- Legal basis: legitimate interest, Art. 6(1)(f) GDPR. Apple and Google are responsible for what happens inside the store itself.
o) Visiting our website (getenara.app)
Our website is served through GitHub Pages (GitHub, Inc., USA). When you visit it, GitHub processes technically necessary connection data (in particular IP address, date and time, the file requested, browser identifier) in server logs, in order to deliver the page and keep the service secure. We ourselves collect no personal data when you visit the website.
- No cookies: the website sets no cookies and uses no analytics or tracking services. A cookie banner is therefore not required.
- Your language choice stays on your device: so the site can greet you in the language you last chose, it stores a single value in your browser's local storage (
enara-sprache, holding eitherdeoren). Nothing else is stored there. That value is never sent to us, it cannot be used to recognise you across websites, and it serves no analytics purpose. No consent is required for it, because the storage is strictly necessary for the service you asked for (section 25(2) no. 2 TDDDG). You can delete it at any time in your browser settings. - Fonts served locally: all fonts are hosted on our own web space. Visiting the site opens no connection to Google Fonts or any other font service.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in delivering the website securely and reliably). GitHub is certified under the EU-US Data Privacy Framework (see section 6).
4. No advertising, no tracking
Enara uses no advertising networks and no analytics or tracking tool for marketing purposes. That holds for the app and for the website. We only send news by email if you have explicitly consented (section 3j).
5. Service providers we use (processors)
We use carefully selected service providers, with each of whom a data processing agreement (Art. 28 GDPR) is in place or is to be concluded:
- Supabase (account, database, server functions). Server location Frankfurt am Main, region eu-central-1. Provider: Supabase, Inc., USA.
- Anthropic (the companion's AI answers). USA. Data processing including EU standard contractual clauses is part of the terms of service.
- Groq (voice transcription). USA. A data processing agreement is in place, EU representative: DP-Dock GmbH, Hamburg.
- RevenueCat (technical handling and status management of the subscription). USA.
- Apple (Sign in with Apple, App Store, subscription).
- Google (Sign in with Google, Google Play, subscription).
- Zoho (email mailbox for support). EU data center.
- Expo (technical foundation of the app, app delivery).
- GitHub (hosting of the website getenara.app). USA, certified under the EU-US Data Privacy Framework.
6. Transfers to third countries (USA)
Some service providers (in particular Anthropic and Groq, possibly also Apple, Google, Supabase, RevenueCat) process data outside the EU. Such transfers take place on the basis of appropriate safeguards under Art. 44 et seq. GDPR. For Anthropic, Groq, Supabase and RevenueCat those are the standard contractual clauses of the EU Commission: none of these four is certified under the EU-US Data Privacy Framework (as of 30 July 2026, checked against the official participant list). A Data Privacy Framework certification does exist for GitHub, where this website is hosted. You can request a copy of the standard contractual clauses from us.
7. Storage period
We store your data for as long as your account exists and it is necessary for the purposes named above. Through the function "Start over (delete everything)" in the app you can delete your content on the device and in the cloud. If you delete your account, the associated data is deleted, unless statutory retention obligations (for example under tax law) prevent that.
8. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). You can withdraw consent you have given at any time with effect for the future (Art. 7(3) GDPR). To do so, write to support@getenara.app.
You can also exercise your right to erasure yourself and immediately: in the app under Settings, at the very bottom, with "Delete account permanently". That removes your access, all entries, your photos and your conversation, on the device and on our server. It cannot be undone. A running subscription is not cancelled by this, that runs through your App Store account. Next to it there is "Start over", which only empties the content and leaves your account in place.
9. Right to complain
You have the right to complain to a data protection supervisory authority. The authority responsible for us is: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
10. Changes to this privacy policy
We adjust this policy when the app or the legal situation changes. The version available here and in the app at the time applies.