Back to home

Privacy Policy

Last updated: May 12, 2026

Welcome to Dopafy (www.dopafy.app). We take the protection of your personal data seriously. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your personal information.

Dopafy is operated by Alexander Alber (sole proprietor), Tömlingerstr. 21, 81375 Munich, Germany ("we", "us", "our").

1. Data Controller

The data controller responsible for your personal data is: Alexander Alber Tömlingerstr. 21 81375 Munich, Germany Email: info@inzpyre.me

2. What Data We Collect

2.1 Account Data

When you create an account using Apple Sign-In or email-based authentication (magic link), we receive:

2.2 Onboarding & Profile Data — Stored on your device only

During the onboarding questionnaire, you provide information such as age, fitness level, health goals, work schedule, dietary preferences, sleep habits, available fitness equipment, focus areas, priority ranking across 6 life categories, and wellbeing, energy, and concentration baselines.

Your full questionnaire response is stored exclusively in SwiftData on your iPhone and is never transmitted to our servers. When you use AI-powered plan generation, the relevant subset is sent ad hoc to Anthropic (Claude) via our Edge Function and not persisted server-side — see section 6.

2.3 Health Data (Apple HealthKit)

If you choose to connect Apple Health, Dopafy reads the following data from your device: daily step count, sleep analysis, workouts, nutrition data, mindful minutes, resting heart rate and HRV, weight and body fat percentage.

HealthKit data is read locally on your device. It is only transmitted to our servers if you explicitly grant consent for AI-powered health analysis (see section 6).

2.4 Usage Data on Our Servers

The following operational data is stored on our servers (Supabase, Ireland):

2.5 Bad-Habit Check-ins — Stored on your device only (GDPR Art. 9)

Bad-habit check-ins capture sensitive health information (smoking, alcohol, drugs, pornography, social media excess, etc.) and are explicitly classified as special category data under GDPR Article 9. Stored exclusively in SwiftData on your iPhone — never transmitted to our servers.

Free-text notes, daily wins, daily learnings, and tomorrow's priority remain on-device permanently. Detailed per-day entries are kept for 90 days, then automatically rolled up into weekly category counts (kept for 12 months) and finally monthly aggregates (kept indefinitely at low resolution). Only the category counts ever flow into AI pattern analysis — never the free-text fields.

2.6 Weekly Reflections — Stored on your device only

Weekly reflections capture wellbeing, concentration, and energy scores (1–10) plus free-text energizers and drains. All of it stays on your iPhone. Free-text fields are automatically erased after 90 days; numeric scores remain so long-term trend analysis still works. When you use AI pattern analysis, only the numeric scores are sent to Anthropic.

2.7 Career Check-ins — Stored on your device only

If you use the Career Check-in feature, we capture satisfaction, fun, learning curve, and stress scores (1–10) plus free-text problem descriptions and reflection notes. All on-device only. Numeric scores retained; free-text fields auto-erased after 90 days. Never transmitted to Anthropic or any third party.

2.8 Goals — Stored on your device only

If you use the Goals module, goal titles, descriptions, and types, milestones and progress entries, deadlines and completion status stay in SwiftData on your iPhone. Goal titles and notes can be highly personal, so we keep them entirely off our servers.

2.9 Calendar Integration (Local Only)

Dopafy can write your routines as events to your iOS Calendar via EventKit. This data stays entirely on your device and is never transmitted to our servers.

2.10 Technical Data

We automatically collect minimal technical data required to operate the service: device type and OS version, app version, preferred language.

2.11 Diagnostic Data (MetricKit)

Apple's MetricKit framework provides crash reports and performance metrics from iOS to the app. We store these locally in the App Group container for in-app diagnostics. We do not transmit MetricKit data to our servers, Supabase, or Anthropic. iOS independently sends crash reports to Apple via the standard system mechanism. The data is not linked to your account.

2.12 Data We Do Not Collect

2.13 External Links

The app references the Arthur Brooks Happiness Scale (learn.arthurbrooks.com) as an educational resource within the Weekly Reflection feature. This link opens in Safari; we do not share any data with this website.

2.14 Screen Time & Digital Wellness Data (Local Only)

If you enable the Screen Time management features, the following data is stored locally on your device in the App Group container: opaque app and category tokens from Apple's Family Controls framework, Digital Sunset schedule settings, daily screen time limit settings and threshold data, temporary unlock override status and expiry timestamps, unlock wait-timer configuration.

All Screen Time data remains entirely local in the App Group container shared between the main app and its on-device extensions. No Screen Time data is transmitted to our servers, Supabase, or Anthropic. The opaque tokens cannot be used to determine the names of your apps.

Dopafy uses four on-device App Extensions: DeviceActivityMonitor (monitors thresholds and sunset schedules), DeviceActivityReport (generates usage reports shown in the app), ShieldConfiguration (customizes blocking-screen appearance), ShieldAction (handles interactions with blocking screens, e.g. unlock requests).

2.15 Anonymized Weekly Usage Snapshots — Opt-out available

Once per ISO week, the app posts one bucketed summary to our backend to help us understand macro-level retention and feature impact. The snapshot contains only the following bucketed values:

What is deliberately not in the snapshot: your user ID, email, Apple ID, device ID, IP address, free text, exact scores, exact dates, routine titles, goal contents.

Where it lives: the analytics_snapshots table on Supabase (Ireland, eu-west-1), with Row-Level Security enabled — only a server-side function with the service role can write, and it discards the authenticated user identity before inserting.

Legal basis: GDPR Art. 6(1)(f) — legitimate interest in macro-level product improvement. Because the snapshot is anonymous and cannot be traced back to you, it is technically not personal data under GDPR Art. 4(1); we describe it here for transparency.

Opt-out: open the app → Profile → Privacy and toggle "Share anonymized usage data" off. From the next snapshot interval onward, no further data is sent.

3. How We Use Your Data

We use your personal data for the following purposes:

4. Legal Basis for Processing (GDPR Art. 6)

5. Data Storage & Security

Server-stored data (account, plan structure, routine completions, streaks, score history, achievements, energy-driver entries, anonymized weekly snapshots) is hosted by Supabase Inc. on AWS infrastructure in Ireland (eu-west-1) — entirely within the European Union.

Local-only data (questionnaire response, bad-habit check-ins, weekly reflections, career check-ins, goals, wellness configuration, all free-text reflections) is stored exclusively in SwiftData on your iPhone with complete-until-first-user-authentication file protection. iOS automatically backs up this store via iCloud (encrypted by Apple).

6. AI-Powered Analysis & Consent

6.1 Plan Generation

During onboarding, your questionnaire responses are sent to Anthropic (Claude AI) via a Supabase Edge Function to generate your personalized routine plan. This processing is covered by the legal basis of contract performance. No HealthKit data is included in this step.

6.2 Meal Suggestions

Your dietary preferences and restrictions are sent to Anthropic (Claude AI) to generate personalized meal recommendations. Legal basis: contract performance.

6.3 Health & Behavioral Data Analysis (Requires Explicit Consent)

If you choose to use the AI health analysis feature, the following aggregated, anonymized data is sent to Anthropic (Claude AI): health summaries (steps, sleep, workouts), nutrition summaries, vitals (resting heart rate, HRV), body metrics (weight, body fat), scores, bad-habit category counts (never the free-text fields), routine completion data, weekly reflection numeric scores (never the free-text notes), energy-driver entries, and your priority rankings.

What is never sent to Anthropic: your name, email, Apple ID, any free-text from weekly reflections, bad-habit free-text (notes, daily wins, daily learnings, tomorrow's priority), career check-in problem text, goal progress notes.

Before the first AI analysis, you will see an explicit consent dialog explaining exactly this. You must actively agree before any data is transmitted. You can withdraw consent at any time in Settings → Apple Health → "AI Data Analysis Consent".

6.4 How Anthropic Processes Your Data

7. Data Sharing & Subprocessors

We do not sell, rent, or trade your personal data. We share data only with the following subprocessors, strictly for operating the app:

We do not share your personal data with any other third parties or advertisers. We do not use any third-party analytics SDKs. The anonymized weekly snapshots described in section 2.15 are stored on our own Supabase instance and never shared with anyone.

9. Data Retention

Retention differs by category and storage location. Server-side data persists for the lifetime of your account; local-only data follows a tiered retention model:

When you delete your account through the app, all your server-side data is permanently removed. A 30-day grace period applies for accidental deletions, after which the server records are unrecoverable. Local-only data is removed immediately and cannot be recovered. Statutory retention obligations take precedence where applicable.

10. Your Rights Under GDPR

As a data subject in the European Union, you have the following rights:

To exercise any of these rights, please contact us at info@inzpyre.me. We will respond within 30 days.

Note on anonymized snapshots: the rights of access, rectification, and erasure (Art. 15–17 GDPR) apply to personal data that can be linked to you. The anonymized weekly snapshots described in section 2.15 contain no identifier and cannot be tied to your account, so technically these rights do not apply to them. The effective control is the opt-out toggle in Settings.

You also have the right to lodge a complaint with a supervisory authority: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18, 91522 Ansbach, Germany www.lda.bayern.de

11. Children's Privacy

Dopafy is not intended for children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe that a child under 16 has provided us with personal data, please contact us immediately at info@inzpyre.me, and we will take steps to delete such data.

12. Push Notifications

Dopafy may send push notifications for routine reminders, check-in prompts, goal reminders, and motivational messages. You can enable or disable notifications at any time through your device settings. We use Apple Push Notification service (APNs) to deliver these notifications.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

14. Contact

If you have any questions about this Privacy Policy or your personal data, please contact us:

Alexander Alber (sole proprietor) Tömlingerstr. 21 81375 Munich, Germany Email: info@inzpyre.me Website: www.dopafy.app