← Return

Privacy

Last updated · 2026-04-22

What the protocol records

  • Email address. Used solely to dispatch the magic link that opens access. Stored with the session. Never shared, sold, or used for any other purpose.
  • Timezone. Captured from the device so the evening echo arrives at the local 20:00. Can be updated.
  • Impressions. Text, voice, or drawn marks recorded during the 11-minute morning window. Sealed on submission.
  • Echo responses. Yes, Uncertain, or No — marked once and then permanent.
  • Resonance matches. The system computes whose impressions resemble which others. Correspondents are rendered as anonymized tags. No participant can learn the identity of another.

Who has access

Impressions are readable only by the subject who sealed them. Row-level access is enforced at the database layer; no one inside Aenivum can browse another participant's archive. Automated moderation scans for content requiring human judgment (self-harm, credible threat, personally identifying information the subject may regret sharing). When a match surfaces, a single moderator reads that one entry and responds off-protocol.

Analytics

The protocol records timing, funnel shape, and outcomes via PostHog. Never impression content. Never echo content. Never correspondent identities. Events are anonymized by user ID; no third-party trackers run on any page.

Retention

The archive is permanent. Impressions cannot be selectively deleted — the subject can only withdraw the entire account. On withdrawal the archive is scrubbed within thirty days per GDPR. Depth-transition events are retained with a hashed user ID for audit.

Withdrawal

Open the archive, find the withdrawal action under the account panel. Confirmation is single-click. No guilt dialog, no win-back attempt. Withdrawal is final.

Processors

Ænivum relies on Supabase (auth, database, storage), Vercel (hosting), Resend (transactional email), OpenRouter (moderation and echo pairing via Qwen 3.6 and related models — processed in memory, not retained on the provider side), Stripe (subscription billing for participants who choose to sustain the protocol), and PostHog (analytics). Each processor receives only what it needs to perform its task. No processor has access to the complete subject record.

Jurisdiction

Aenivum honors GDPR, CCPA, and equivalent regimes. Requests — access, rectification, portability, deletion — go to the contact address published in the magic-link email. Response within 30 days.

Changes

When this notice changes, active participants receive a single email. No banner, no modal, no scroll interruption.