Legal

Privacy Policy

Effective date: 26 July 2026 · Last updated: 28 July 2026

1. Data controller

The data controller for StoicOs.ai and the app is Ed Korporaal, trading as StoicOs.ai, established in the Netherlands. Contact: ek@stoicos.ai. This policy covers the StoicOs.ai website and the mobile application, which share one account system and one backend.

2. What we collect

Account data: your name, email address, a unique account ID, your password (stored only as a bcrypt hash — we can never read it), your language preference and onboarding status. Your content: journal entries (morning reflection, daily practice, evening reflection and free entries), Academy exercise texts and reflective submissions, and — in — your conversations with the AI guide. Membership data: your membership number and status. Newsletter data: your email address and chosen language if you sign up for the newsletter or waitlist. Technical and security data: login attempts (for brute-force protection), an internal registry of active login sessions, standard server logs (timestamps, request paths, IP-derived connection data) and analytics data described in section 7.

3. Purposes and legal bases (GDPR)

We process your data to: (a) provide your account, journal, Academy and — performance of a contract (art. 6(1)(b) GDPR); (b) secure the service against abuse and unauthorised access — legitimate interest (art. 6(1)(f)); (c) send the newsletter you signed up for — consent (art. 6(1)(a)), withdrawable at any time; (d) understand how the public website is used, via analytics — legitimate interest / consent where required; (e) comply with legal obligations where applicable (art. 6(1)(c)). We do not sell personal data and we do not use your data for third-party advertising.

4. AI processing — what is and is not sent to AI providers

Your journal entries in My Journal are NOT sent to any AI provider. They are stored in our database and used only to show your journal back to you. What IS processed by AI: when you actively submit a reflective exercise for AI evaluation in the Academy (for example a Chamber session), and when you converse with the AI guide in , that specific text is sent to an AI language-model provider (Anthropic and/or OpenAI, via the integration service of our hosting provider Emergent) solely to generate the response. These providers process the text as a processor for that request; per our service agreements it is not used to train their models. Never include data of other people or highly sensitive details you do not want processed this way.

5. Processors and subprocessors

We use the following providers, each bound by data-processing terms: · Emergent (hosting platform: application servers and MongoDB database where accounts, journals and content are stored); · Cloudflare (CDN, security and traffic routing in front of the website and API); · Resend (transactional email such as welcome emails, and newsletter delivery); · Google Analytics 4 (website usage statistics); · Microsoft Clarity (anonymised usage analysis such as scroll and click behaviour on the public website); · Anthropic and/or OpenAI (AI language models, only for the AI features described in section 4). We will update this list when providers change.

6. International transfers

Some providers listed above (Cloudflare, Google, Microsoft, Resend, Anthropic, OpenAI and Emergent's infrastructure) process data on servers that may be located outside the European Economic Area, including the United States. Where that happens, transfers rely on the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses, supplemented by the providers' technical safeguards.

7. Cookies and similar technologies

Functional (necessary): secure httpOnly login cookies for your session on the website (access and refresh tokens), and a Cloudflare cookie (__cf_bm) for bot protection. Your language preference and, for Academy exercises, anonymous learner identifiers are stored in your browser's localStorage. Analytics: the public website uses Google Analytics 4 and Microsoft Clarity, which set cookies or comparable identifiers to measure how the site is used. These are not used to build advertising profiles by us. The app itself does not use tracking cookies; it stores your login tokens securely on your device.

8. Security

Measures in place include: TLS encryption for all traffic; passwords stored only as bcrypt hashes; httpOnly, secure session cookies on the web; short-lived access tokens with rotating, revocable refresh tokens for the mobile app; brute-force lockout on login; strict server-side ownership checks so one user can never read another user's journal; and access to the database restricted to the hosting environment.

9. Retention

Account data and your content are kept for as long as your account exists, so your journal remains available to you. Newsletter data is kept until you unsubscribe. Security logs (login attempts, session registry) are kept only as long as needed for protection of the service. Server and analytics data are retained per the retention settings of the providers in section 5. After account deletion, your data is removed from the active database; residual copies in backups of our hosting provider expire in the normal backup rotation and are not restored except for disaster recovery.

10. Your rights (GDPR)

You have the right to access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent at any time (for example for the newsletter) without affecting prior processing. To exercise any right, email ek@stoicos.ai from the address linked to your account. We respond within one month. You can also read, edit and delete your journal entries yourself at any time inside My Journal.

11. Account deletion and unsubscribe

Account deletion: you can initiate permanent deletion of your account directly in the app via My StoicOs → Danger Zone → Delete Account. You can also send your request to ek@stoicos.ai from your account email address — this route is available for all privacy requests. Every deletion request, whether started in-app or by email, is completed within 30 days after verification: your account, journal, exercise content and membership record are then removed from the active database and you receive confirmation. Newsletter: every newsletter contains an unsubscribe option, or email ek@stoicos.ai.

12. Complaints

If you believe we handle your data incorrectly, contact us first at ek@stoicos.ai — we take this seriously. You also have the right to lodge a complaint with the Dutch supervisory authority: Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

13. Children

The service is not directed at children under 16. We do not knowingly collect data from children under 16; if this has happened, contact ek@stoicos.ai and we will delete it.

14. Changes to this policy

We may update this policy when the service or our providers change. The 'last updated' date above always reflects the current version. For material changes we will inform you where reasonably possible.

15. Contact

Ed Korporaal, trading as StoicOs.ai, the Netherlands — ek@stoicos.ai.

The StoicOs.ai Newsletter

Practical Stoic wisdom, new Living Library articles and Academy insights — thoughtfully delivered. No spam, unsubscribe at any time.