Privacy Policy
Last updated: 2026-05-11
1. Who We Are
Aletheia Lattice ("we", "us", "our") is a personalized emotional journaling service available at aletheialattice.com. To exercise your rights or contact us about your data, write to hello@aletheialattice.com.
2. Data We Collect
- Account data: name, email address, and password (stored as a salted hash).
- Profile data: country, language, and phone (optional).
- Journal content: your daily reflections, emotional responses, and questionnaire answers. This is the core of our service.
- AI-generated insights: emotional profile summaries and narrative analyses produced on the basis of your journal entries.
- Payment data: billing information is handled exclusively by Stripe. We store only the Stripe subscription ID and status — never card numbers.
- Usage data: if you consent, aggregated analytics events are collected via Google Analytics 4 to help us improve the service.
3. Legal Basis
- Contract performance (Art. 6(1)(b) GDPR): we process your account, profile, journal, and payment data to provide the service you subscribed to.
- Consent (Art. 6(1)(a) GDPR): analytics cookies are only activated if you explicitly accept them via our consent banner.
- Legitimate interest (Art. 6(1)(f) GDPR): server logs and error monitoring for security and reliability.
4. How We Use Your Data
We use your data solely to provide and improve Aletheia Lattice. We do not sell your data. We do not use your journal content for training AI models beyond generating your own personalized content within the session.
5. Third-Party Processors
- Supabase — database and authentication (EU region)
- Anthropic — AI content generation (your journal context is sent per-session; not stored by Anthropic)
- OpenAI — semantic memory embeddings (excerpt-level vectors, no full text stored)
- Stripe — payment processing (PCI-DSS compliant)
- Google Analytics 4 — aggregated usage analytics (only with your consent)
- Hostinger SMTP — transactional email delivery
6. Retention
We retain your data for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we are required to retain it by law (e.g., financial records for 7 years).
7. Your Rights (GDPR)
If you are located in the EU/EEA, you have the following rights:
- Access: request a copy of your personal data.
- Rectification: correct inaccurate data.
- Erasure: request deletion of your account and data.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interest.
- Withdraw consent: withdraw analytics consent at any time via the cookie banner.
To exercise any right, email us at hello@aletheialattice.com. We will respond within 30 days.
8. Cookies
We use a single analytics cookie (Google Analytics 4) which is only activated with your explicit consent. No tracking cookies are set by default. You can change your preference at any time by clearing your browser's local storage for this site.
9. Changes to This Policy
We will notify you by email of material changes to this policy at least 14 days before they take effect.
10. Contact & Complaints
Email: hello@aletheialattice.com. You also have the right to lodge a complaint with your national data protection authority.