How the decision coaching app handles your data
Last updated: September 17, 2026
Summary — in one minute
The privacy architecture of this product is different from typical applications, and we want to state this clearly from the outset:
Below are the full details.
The Claritix application is operated by certified decision coach Banu Ünal Ergün.
Data Controller: Banu Ünal Ergün
Contact: [email protected]
Most AI coaching applications store conversations on central cloud servers. We do not store your decision history.
The primary copy of your decision entries, coaching conversation history, Decision Constitution, Discovery profile, coaching wheel assessments, and sealed envelopes remains strictly within your device's local database (IndexedDB). A relevant message is processed when you request an AI response; when you submit a session request to Banu, you intentionally share the information entered in that form with Banu. Both explicit operations are described below.
As a direct result:
| Data Type | Storage Location |
|---|---|
| Decision titles and reflective texts | Device (except content you intentionally include in a session request) |
| Complete coaching conversation transcripts | Device |
| Decision Constitution (values, risk tolerance) | Device |
| Discovery profile (strengths, core values, fears) | Device |
| Coaching wheel measurements and reflections | Device |
| Sealed envelopes and forecast predictions | Device |
| Reminders and local notification schedules | Device |
Account Information: Your email address. We do not use passwords; upon login, we issue a one-time verification code to your email. The code itself is stored only as a cryptographic hash.
Session Request (Optional): If you submit the human-coach form, your name, verified account email, form text, and active decision title (if any) are emailed to Banu Ünal Ergün. This data is used only to review your request, respond to you, and discuss possible session details. The app neither takes payment nor creates an automatic reservation through this action. A configured email service provider is used for delivery.
Usage Counters: Aggregate counts of messages, reports, and advisory board sessions utilized to enforce fair-usage policies. These counters contain no conversational content — we know how many messages were sent, never what was said.
Encrypted Backup (Optional): If you choose to back up your data, it is encrypted on your device (PBKDF2 with 250,000 iterations + AES-GCM-256), and only an unreadable encrypted ciphertext block is transmitted to our server. We never receive your password; therefore, we cannot open or view your backup. If you forget your password, the backup is permanently unrecoverable — if we possessed the ability to reset it, that would mean we could inspect your data.
Product Events (Telemetry): To understand feature engagement and onboarding friction, we record a predetermined, fixed list of product events (e.g., "onboarding completed", "board session accessed"). This list is hardcoded in the application; no free-form text is sent. Decision content, chat transcripts, email addresses, and IP addresses do not enter telemetry.
Error Logs: Only the fixed `client_error` event and timestamp are stored when the app faults. Error messages, stack traces, and device identifiers are not written to disk.
Precise GPS location, contacts, photo gallery, calendar, SMS, phone call records, biometric data, microphone, or camera access. We do not request advertising identifiers (IDFA / Android Advertising ID).
Emotional intensity estimation is derived purely from the text you submit — we do not perform vocal tone or facial expression analysis.
To produce conversational coaching responses, your message prompts are processed by Google (Gemini). This involves transferring textual prompts outside Türkiye and is essential for providing the service.
Technical Safeguards: Before any text is dispatched to Google, identifying patterns including Turkish Identity Numbers (TCKN), telephone numbers, email addresses, IBANs, and credit card numbers are automatically redacted. Personal names are intentionally retained — removing the relationship context in phrases such as "my manager John" would render coaching unhelpful.
Data Retention: Coaching conversations are never stored on our application servers. Google processes the prompts under enterprise API provisions and does not use client submissions to train foundational models.
If you do not accept this processing, you will not be able to use the application, as AI coaching functionality cannot operate without this pipeline.
| Right | How to Exercise |
|---|---|
| Access to your data | Profile → Export My Data (complete JSON archive) |
| Data portability | The same standardized JSON export file |
| Erasure / Right to be forgotten | Profile → Delete All My Data (instantaneous and irreversible) |
| Rectification | In the "Know Yourself" screen, you can directly edit any parameter held by the coach |
| Withdrawal of consent | Deleting the app from your device immediately purges all local records |
In-app export and erasure cover decisions, chats, sealed envelopes, the Constitution, Discovery profile, and wheel assessments. If you are signed in, “Delete All My Data” also removes the server-side account record, usage record, and encrypted backup in the same flow. To delete a session request already delivered by email, contact [email protected]; the mailbox copy cannot technically be erased from within the app.
The application is not intended for individuals under the age of 18, and we do not knowingly collect personal data from minors.
This release processes no payments whatsoever: there are no in-app purchases, subscriptions, or payment paths. Consequently we process no payment data at all — no card details, no billing address, no subscription status.
If a paid plan is introduced later, payments will be handled by the app stores (Apple App Store / Google Play); even then we will never view or store your card details.
| Data Category | Retention Period |
|---|---|
| Data stored on your device | Until you delete it or uninstall the app |
| Account record & usage counters | For the duration of your active account |
| Login verification codes | 15 minutes (automatically purged) |
| Encrypted cloud backup | Until you delete it |
| Session request email | For as long as needed to handle the request and related communication, subject to legal retention duties |
| Anonymized error logs | For as long as needed to investigate technical failures and protect the service |
When this policy is modified, we will provide notification within the application. For material changes, your renewed acknowledgment will be requested.
For any inquiries concerning data privacy: [email protected]