Privacy Policy
Here's how we handle your data β short, honest, and free of legal jargon.
What is Robin all about?
Robin is a personal AI companion: journal, goals, habits, health, relationships and a chat with Robin. You use Robin by signing in and creating content. This policy describes what data this generates, on what legal basis and for what purpose we process it, where it's stored and what rights you have.
What data do we process?
- Account: email address, name, password hash (bcrypt β we never see the plain text).
- Content: everything you create in the app β journal entries, conversations with Robin, goals, routines, relationships, health and fitness data, your own notes.
- Payment data: for a paid plan, the details needed to process it (see "Payment" below). We don't see your full credit card details β those are processed by our payment provider.
- Session cookie: a strictly necessary cookie (
robin_session) that keeps you signed in. No tracking, no third parties. - Server logs: technical logs (IP, timestamp, path) are kept for 7 days for troubleshooting and abuse prevention, then deleted.
On what legal basis do we process?
- Account & provision of the service β to perform our contract with you (Art. 6(1)(b) GDPR).
- Special content (health, mental and emotional topics, relationships) β only with your explicit consent (Art. 9(2)(a) GDPR, see the next section).
- Server logs, security, abuse prevention β our legitimate interest in stable, secure operation (Art. 6(1)(f) GDPR).
- Payment processing & retention of invoice data β contract (lit. b) and legal obligations under tax and commercial law (Art. 6(1)(c) GDPR).
Sensitive content: only with your explicit consent
Journal, "Reflection" (formerly "Therapy Session"), health and relationship data are among the specially protected categories under Art. 9 GDPR. We only process such content and transmit it to AI models if you give us your explicit consent when you register β via a separate, non-pre-ticked box, kept apart from these Terms. You can withdraw this consent at any time with effect for the future, in your account settings or by email; the lawfulness of any processing carried out before then remains unaffected.
Where is your data stored?
On a server in Germany (Hetzner, Falkenstein). The server is only reachable over a private network (Tailscale) β no open SSH ports to the internet. All connections to the app run over HTTPS.
AI models & transmission to the providers
Robin uses ready-integrated AI models such as Claude, GPT or Gemini β you don't need your own API key. You pick your model yourself, or Robin picks it automatically in Smart mode. To generate a response, our server transmits your respective input to the chosen provider; there it is processed to create the response and is not used to train the models. If EU data protection matters especially to you, you can choose EU mode: Robin then runs exclusively via Google Gemini with server locations in the EU, and your data never leaves the EU.
Before each transmission, identifying data (name, address, phone number) is pseudonymised on your device β the AI provider sees [PERSON_1] instead of your name, for example. This pseudonymisation reduces the risk but is not anonymisation: transmission to the AI providers remains genuine processing of personal and, where applicable, special category data (Art. 9 GDPR). The transmitted content itself can be re-identifying β for instance through described life circumstances, dates or connections.
Where the providers are based and how the transmission is secured:
- Anthropic (Claude), OpenAI (GPT) β USA. Transmission takes place on the basis of the EU-US Data Privacy Framework (adequacy decision) and/or the EU Standard Contractual Clauses (Art. 46 GDPR).
- Google (Gemini) β by default the USA (likewise on the basis of the EU-US Data Privacy Framework or the EU Standard Contractual Clauses). In EU mode, by contrast, your requests are processed exclusively via Google data centres in the EU (EU data residency) β in which case no transfer to the USA takes place.
We have data processing or processing agreements in place with the AI providers. What data the respective provider processes beyond that is governed by its own privacy policy.
The transmitted inputs are not used by the AI providers to train the models. They may, however, be stored at the provider for a limited time (usually a few weeks, e.g. for abuse and security prevention) and deleted afterwards.
Other people's data
When you write about other people in your content (e.g. family, partner, friends, colleagues), their data is processed too β in part special category data under Art. 9 GDPR. We minimise this as far as possible: identifying third-party data is generalised before transmission to the AI providers (e.g. [PERSON_1]) and not stored permanently in identifying form. Even so, please do not enter any identifying data about third parties β meaning no full names, addresses or contact details of other people. You share responsibility for the content you record about third parties.
Crisis detection
Your inputs are automatically checked for crisis and suicide signals so we can show you a help banner with emergency and crisis-helpline numbers when needed (Art. 13(2)(f) GDPR). This is not an automated decision with legal effect within the meaning of Art. 22 GDPR: it does not lock your account and involves no disclosure to third parties (such as authorities or relatives). The notice is intended purely as support.
Payment
We process plan payments via Stripe (Stripe Payments Europe, Limited, Ireland; where transmitted to Stripe, Inc. in the USA, on the basis of the EU-US Data Privacy Framework or the Standard Contractual Clauses). Stripe acts partly on our behalf (processing under Art. 28 GDPR) for payment processing, and partly as an independent controller for its own purposes such as fraud prevention and legal obligations. Full payment-instrument data (e.g. card or account details) is processed exclusively by Stripe; we only receive the information needed for contract and invoice management (e.g. name, amount, payment status). The legal basis is performance of the contract (Art. 6(1)(b) GDPR).
Backups β your responsibility
Important: Robin is run by a single person. We operate technical backups for server operation, but we don't guarantee individual recovery of your content. You are responsible for regularly exporting a copy of your data yourself.
In the app settings you'll find the option "Backup & data export" β there you can download all your data at any time as a ZIP archive, readable Markdown or structured JSON. We recommend at least one export per month.
How long do we keep your data?
- Account + content: until you delete your account.
- Demo accounts: automatically deleted after 2 hours. In demo or trial mode you should not enter any real sensitive data.
- Server logs: 7 days.
- Invoice and payment data: as long as statutory retention obligations apply (up to 10 years under tax and commercial law).
Automated decisions
Robin makes no solely automated decisions with legal effect or similarly significant impact within the meaning of Art. 22 GDPR. The AI offers prompts and reflections β you make the decisions.
Your rights under the GDPR
- Access (Art. 15): you can see all your data yourself in the app β the export gives you a complete copy.
- Rectification (Art. 16): all content is directly editable in the app.
- Erasure (Art. 17): under Settings β "Delete account", your account is removed completely β conversations, journal, everything. Irreversibly.
- Restriction (Art. 18): in certain cases you can have processing restricted.
- Data portability (Art. 20): the export gives you your data in a machine-readable format (JSON).
- Objection (Art. 21): by email to robin@elli.website.
- Withdrawal of consent (Art. 7(3)): you can withdraw consent you have given at any time with effect for the future.
- Complaint (Art. 77): with the competent supervisory authority β for Bavaria: Bayerisches Landesamt fΓΌr Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.
Cookies & tracking
We set only a technical session cookie (robin_session) that keeps you signed in. No Google Analytics, no advertising cookies, no tracking pixels, no fingerprinting. That's why there's no cookie banner either.
Processors & recipients
- Hetzner Online GmbH (Falkenstein, DE) β server hosting (processing under Art. 28 GDPR).
- Stripe Payments Europe, Limited (Ireland) β payment processing.
- AI providers β see above, depending on your choice.
Contact & contact form
When you write to us via the contact form or by email at robin@elli.website, we process your details solely to handle your request (Art. 6(1)(b) or (f) GDPR) and delete them once they are no longer needed and no retention obligations stand in the way.
Changes to this policy
If this policy changes materially, we'll inform registered users by email.