Privacy policy
This is a translation for convenience. The German version is the authoritative one.
Last updated: 8 August 2026
This policy applies to the Journex app and to the journex.tech website.
The main points in plain language
The detailed text below is the binding one. Here is what matters up front:
- You tell the app something about yourself. An artificial intelligence turns that conversation into a personal analysis. To do this, what you have written is transmitted to our AI provider Anthropic in the USA.
- Your data is stored on servers in the EU (Frankfurt am Main). The transfer to the AI is the exception to that, and we tell you here exactly what is transmitted.
- We do not sell your data. We show no advertising. There are no advertising trackers in the app and none on the website.
- Your conversations are not used to train AI models.
- In the social features, other people never see your Rank, your potential score or your analysis. Those stay with you.
- You can delete everything, at any time, directly in the app. Then it is gone.
If there is something you do not understand, or you want to know exactly what is stored about you: write to us. The address is in the next section.
1. Who is responsible
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Lars Haberland, Bühlenstraße 126, 71088 Holzgerlingen. Email: journex.team@gmail.com.
Full details: Legal notice.
2. Where your data is stored
The app runs on Supabase. The database and file storage are located in region eu-central-1 — Frankfurt am Main, Germany.
Exceptions where data leaves the EU are listed individually in section 5.
3. What we process — an overview
| Data | Purpose | Legal basis | Recipients |
|---|---|---|---|
| Guest account (random identifier) | Making the app usable before you sign up | Art. 6 (1) b | Supabase |
| Email, password hash, year of birth, consent record | Account, minimum age of 16, proof of consent | Art. 6 (1) b, Art. 6 (1) c | Supabase, Resend |
| Club (optional) | Team assignment for Missions | Art. 6 (1) b | Supabase |
| Answers in the onboarding conversation | Creating your analysis | Art. 6 (1) b | Supabase, Anthropic |
| Founder DNA, Insight cards, evidence quotes, history | Core function of the app | Art. 6 (1) b | Supabase |
| Journey: project, evidence, photos, files, check-in chat | Progress and feedback | Art. 6 (1) b | Supabase, Anthropic |
| AI memory ("canon") | Feedback free of contradictions | Art. 6 (1) b | Supabase, Anthropic |
| Missions: Squad, evidence, media, votes, chat | Social features and competition | Art. 6 (1) b | Supabase |
| Handle, display name, profile picture | How you appear to others | Art. 6 (1) b | Supabase |
| Rank, XP, points ledger | Progress display | Art. 6 (1) b | Supabase |
| Push token | Notifications | Art. 6 (1) a | Supabase, Expo |
| Usage statistics (event names) | Improving the app | Art. 6 (1) f | Supabase |
| Security log | Account protection | Art. 6 (1) f | Supabase |
| Reports and moderation decisions | Safety, legal obligations | Art. 6 (1) f, Art. 6 (1) c | Supabase |
| Device language and time zone | Correct language and time | Art. 6 (1) b | Supabase |
| Website: server logs | Operation and security | Art. 6 (1) f | Render, Cloudflare |
4. The individual processing operations
4.1 Guest account on first launch
So that you can start right away, the app creates an anonymous guest account the first time you open it. It consists only of a random identifier — no name, no email address. Everything you write in the conversation is initially attached to that identifier.
If you sign up at the end of the conversation, the guest account becomes your real account. If you stop before that, a guest account with your answers so far remains (see section 8 on deletion).
Legal basis: Art. 6 (1) b GDPR (performance of a contract).
4.2 Account and sign-up
We process your email address, your password (only as a cryptographic hash, we do not know it), your year of birth and, optionally, your club.
We need the year of birth for the minimum age of 16. We store it together with the record of which version of this policy and of the terms of use you agreed to, in which language and when.
To confirm your address and for messages about your account, we send emails through the provider Resend.
Legal basis: Art. 6 (1) b GDPR; for the consent record additionally Art. 6 (1) c GDPR.
4.3 The onboarding conversation and your Founder DNA
This is the processing you should know about most precisely.
What happens: You have a conversation with an AI that takes about five minutes. It asks around eight questions about concrete situations from your life — what you have set in motion yourself, what went wrong, what drives you, what annoys you about the way you work.
What is transmitted: The entire conversation history is transmitted to our AI provider Anthropic — with every single answer the history so far, and at the end once more in full for the analysis.
What is created from it and stored: an archetype, a typology coined for you, a headline, a "hidden strength", a potential score (0–100), four to six rating axes, a classification as "Explorer" or "Builder", a first step, a trajectory forecast, four chapters for the reveal, five Insight cards and an evidence register: short verbatim quotes from your own answers showing what each statement is based on.
In addition, each time the analysis is created we store a snapshot of it, so that it stays traceable what was created about you and when.
Please also read section 6 — it explains what this automated analysis means and what it does not.
Legal basis: Art. 6 (1) b GDPR. The analysis is the main service of the app; without it there is no app.
4.4 Your Journey
If you set up a project, we process its title, target group and problem description. For each of the ten steps you submit a piece of evidence: a text and, optionally, photos or files. On top of that comes the short check-in dialogue with the AI that reads the evidence.
The project, the step and the evidence text are transmitted to Anthropic. Photos and files are not transmitted to the AI.
The files you upload are stored in a private storage area that only you have access to.
Legal basis: Art. 6 (1) b GDPR.
4.5 The AI memory ("canon")
Several AI functions talk to you in the app: the analysis that creates your DNA, and the guidance that suggests projects, explains steps and reads evidence.
So that these voices do not contradict each other, we keep a small canon: a short list of at most eight entries of at most 200 characters each, recording what you have already been told. This list is passed to the AI functions with every call.
These are shortened outputs of the AI, not additional information about you. The canon is deleted as soon as your analysis is created anew, and together with your account.
Legal basis: Art. 6 (1) b GDPR.
4.6 Missions, Squads and social features
If you take part in a Mission, we process your Squad membership, your posts in the Squad chat, your team's Mission evidence including media and your votes in the rating.
- Your Squad's Mission evidence is visible to the users who are allowed to vote as part of the Mission.
- Other people cannot see how you voted.
- Your Rank, your potential score and your analysis are not shown in any social feature.
- To present you, we use a handle, optionally a display name you choose, and a profile picture. You decide which of these you reveal.
- Friendships only come about through confirmation on both sides.
Legal basis: Art. 6 (1) b GDPR.
4.7 Rank and experience points
We store your points total, your level and a points ledger recording, for each event, what points were awarded for. This ledger is the reason we can show you in the app exactly where your points come from — and why nobody can manipulate them.
Legal basis: Art. 6 (1) b GDPR.
4.8 Push notifications
Only if you agree on your device do we store a push token and deliver notifications via the Expo Push Service. The content is kept to the minimum. To work out the right moment, we store your device's time zone.
You can withdraw your consent at any time in your device settings.
Legal basis: Art. 6 (1) a GDPR (consent).
4.9 Usage statistics
We log that certain things happened, in order to understand where the app gets stuck: that the app was opened, that a conversation was started or finished, that a step was opened or a piece of evidence submitted. Added to that are technical details such as a step number.
Free text, conversation content or evidence texts do not go into the statistics. No advertising identifiers are collected and no data is transmitted to analytics or advertising providers.
Legal basis: Art. 6 (1) f GDPR. You can object to this processing under Art. 21 GDPR.
4.10 Security log
To protect your account, we log security-relevant events: sign-ins, password changes, requested password resets, changes of the email address and signing out of all devices. You can view this log in the app.
Legal basis: Art. 6 (1) f GDPR.
4.11 Reports and moderation
If you report content or are reported yourself, we process the report, the content concerned and our decision about it.
Legal basis: Art. 6 (1) f GDPR and Art. 6 (1) c GDPR in conjunction with Regulation (EU) 2022/2065.
4.12 The journex.tech website
When you visit the website, our providers Render Services, Inc. (hosting) and Cloudflare, Inc. (delivery and protection), both USA, process technically necessary server logs: IP address, time, address requested, amount of data transferred, browser and operating system identifier.
The website sets no advertising or analytics cookies and embeds no external fonts, maps or video services. Technically necessary storage takes place without consent under section 25 (2) TDDDG (German Telecommunications Digital Services Data Protection Act).
Legal basis: Art. 6 (1) f GDPR.
5. Recipients and transfers to third countries
We use the following providers as processors under Art. 28 GDPR. We have corresponding contracts with all of them.
| Provider | What for | Location |
|---|---|---|
| Supabase | Database, accounts, file storage, server functions | EU (Frankfurt am Main) |
| Anthropic PBC | AI analysis of the conversation, the evidence and the guidance | USA |
| Expo | Delivery of push notifications | USA |
| Resend | Sending account emails | USA |
| Render Services, Inc. | Hosting the website | USA |
| Cloudflare, Inc. | Delivery and protection of the website | USA / global network |
Transfers to the USA. For the providers marked "USA", a transfer to a third country takes place. The basis for this is the European Commission's standard contractual clauses under Art. 46 (2) c GDPR and, where the provider is certified, the EU-US Data Privacy Framework under Art. 45 GDPR.
Even with these safeguards, it cannot be entirely ruled out that US authorities access data without you having the same legal remedies available as in the EU. We consider the transfer to our AI provider indispensable, because without it the app's central function does not exist — and we say so here explicitly, so that you know before you start the conversation.
No use for training. Under our AI provider's terms, the content transmitted through the interface is not used to train its models.
Beyond that, we only pass on data where we are legally obliged to. We do not sell data and we do not run advertising.
6. Automated analysis
Your Founder DNA is created fully automatically. A language model reads the conversation history and generates the analysis from it, including a potential score between 0 and 100 and the axis values.
What that means:
- This analysis has no legal effect and no similarly significant impact on you within the meaning of Art. 22 GDPR. Nothing is decided about you — something is offered to you.
- The score is not a test result, not a grade and not a comparison with other people. There is no comparison group. It is a starting point within the app.
- The analysis is based on an evidence register drawn from your own statements, which you can view in the app.
- Language models make mistakes. If a statement is wrong or bothers you, you can write to us. We will check it and correct or delete it (Art. 16, Art. 17 GDPR).
Journex makes no statements about health. The analysis is not a psychological or medical diagnosis.
7. Minors
Journex can be used from the age of 16. In Germany, people can validly consent to processing themselves from that age (Art. 8 GDPR, section 25 BDSG — German Federal Data Protection Act). We do not verify the age you state; if we learn of an account belonging to a younger person, we delete it.
We have deliberately written this text as simply as we can and put a short version at the top (Art. 12 (1) GDPR).
8. How long we store data
| Data | Retention |
|---|---|
| Account and all content attached to it | until you delete the account |
| Guest accounts without sign-up | 90 days after last use |
| Snapshots of the analysis | with the account |
| Usage statistics | 12 months |
| Security log | 12 months |
| Reports and moderation decisions | 12 months after receipt |
| Consent record | at most 3 years after account deletion |
| Server logs of the website | 7 days |
If you delete your account in the app under Profile → Security → Delete account permanently, your account, your analysis, your evidence, your files, your posts and your points ledger are permanently deleted. Data may persist in backups for a short time; it is no longer used and is overwritten in the normal backup cycle.
Posts in a Squad chat may remain visible to other participants in their view, where this is necessary to keep the conversation comprehensible; they are then no longer attributed to you.
9. Your rights
You have the right at any time to:
- Access the data we process about you (Art. 15 GDPR);
- Rectification of inaccurate data (Art. 16 GDPR);
- Erasure (Art. 17 GDPR) — built into the app, see section 8;
- Restriction of processing (Art. 18 GDPR);
- Data portability (Art. 20 GDPR);
- Objection to processing we base on a legitimate interest (Art. 21 GDPR);
- Withdrawal of consent with effect for the future (Art. 7 (3) GDPR).
Write to us at journex.team@gmail.com. We answer within one month.
Right to complain. You can lodge a complaint with a data protection supervisory authority, in particular with the authority where you habitually reside or with the authority responsible for us: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (the data protection supervisory authority of the German state of Baden-Württemberg), Königstraße 10a, 70173 Stuttgart, phone 0711 615541-0, poststelle@lfdi.bwl.de.
10. Changes to this policy
We adapt this policy when the app or the legal situation changes. The version published in the app applies. In the event of significant changes, we will inform you in the app or by email.