Privacy Policy

Here's how we handle your data β€” short, honest, and free of legal jargon.

Last updated: 4 June 2026 Β· Controller: Joannis Papatheodorou, Christian-Schad-Str. 2a, 63743 Aschaffenburg Β· Contact: robin@elli.website Β· full details in the Legal Notice

What is Robin all about?

Robin is a personal AI companion: journal, goals, habits, health, relationships and a chat with Robin. You use Robin by signing in and creating content. This policy describes what data this generates, on what legal basis and for what purpose we process it, where it's stored and what rights you have.

What data do we process?

On what legal basis do we process?

Sensitive content: only with your explicit consent

Journal, "Reflection" (formerly "Therapy Session"), health and relationship data are among the specially protected categories under Art. 9 GDPR. We only process such content and transmit it to AI models if you give us your explicit consent when you register β€” via a separate, non-pre-ticked box, kept apart from these Terms. You can withdraw this consent at any time with effect for the future, in your account settings or by email; the lawfulness of any processing carried out before then remains unaffected.

Where is your data stored?

On a server in Germany (Hetzner, Falkenstein). The server is only reachable over a private network (Tailscale) β€” no open SSH ports to the internet. All connections to the app run over HTTPS.

AI models & transmission to the providers

Robin uses ready-integrated AI models such as Claude, GPT or Gemini β€” you don't need your own API key. You pick your model yourself, or Robin picks it automatically in Smart mode. To generate a response, our server transmits your respective input to the chosen provider; there it is processed to create the response and is not used to train the models. If EU data protection matters especially to you, you can choose EU mode: Robin then runs exclusively via Google Gemini with server locations in the EU, and your data never leaves the EU.

Before each transmission, identifying data (name, address, phone number) is pseudonymised on your device β€” the AI provider sees [PERSON_1] instead of your name, for example. This pseudonymisation reduces the risk but is not anonymisation: transmission to the AI providers remains genuine processing of personal and, where applicable, special category data (Art. 9 GDPR). The transmitted content itself can be re-identifying β€” for instance through described life circumstances, dates or connections.

Where the providers are based and how the transmission is secured:

We have data processing or processing agreements in place with the AI providers. What data the respective provider processes beyond that is governed by its own privacy policy.

The transmitted inputs are not used by the AI providers to train the models. They may, however, be stored at the provider for a limited time (usually a few weeks, e.g. for abuse and security prevention) and deleted afterwards.

Other people's data

When you write about other people in your content (e.g. family, partner, friends, colleagues), their data is processed too β€” in part special category data under Art. 9 GDPR. We minimise this as far as possible: identifying third-party data is generalised before transmission to the AI providers (e.g. [PERSON_1]) and not stored permanently in identifying form. Even so, please do not enter any identifying data about third parties β€” meaning no full names, addresses or contact details of other people. You share responsibility for the content you record about third parties.

Crisis detection

Your inputs are automatically checked for crisis and suicide signals so we can show you a help banner with emergency and crisis-helpline numbers when needed (Art. 13(2)(f) GDPR). This is not an automated decision with legal effect within the meaning of Art. 22 GDPR: it does not lock your account and involves no disclosure to third parties (such as authorities or relatives). The notice is intended purely as support.

Payment

We process plan payments via Stripe (Stripe Payments Europe, Limited, Ireland; where transmitted to Stripe, Inc. in the USA, on the basis of the EU-US Data Privacy Framework or the Standard Contractual Clauses). Stripe acts partly on our behalf (processing under Art. 28 GDPR) for payment processing, and partly as an independent controller for its own purposes such as fraud prevention and legal obligations. Full payment-instrument data (e.g. card or account details) is processed exclusively by Stripe; we only receive the information needed for contract and invoice management (e.g. name, amount, payment status). The legal basis is performance of the contract (Art. 6(1)(b) GDPR).

Backups β€” your responsibility

Important: Robin is run by a single person. We operate technical backups for server operation, but we don't guarantee individual recovery of your content. You are responsible for regularly exporting a copy of your data yourself.

In the app settings you'll find the option "Backup & data export" β€” there you can download all your data at any time as a ZIP archive, readable Markdown or structured JSON. We recommend at least one export per month.

How long do we keep your data?

Automated decisions

Robin makes no solely automated decisions with legal effect or similarly significant impact within the meaning of Art. 22 GDPR. The AI offers prompts and reflections β€” you make the decisions.

Your rights under the GDPR

Cookies & tracking

We set only a technical session cookie (robin_session) that keeps you signed in. No Google Analytics, no advertising cookies, no tracking pixels, no fingerprinting. That's why there's no cookie banner either.

Processors & recipients

Contact & contact form

When you write to us via the contact form or by email at robin@elli.website, we process your details solely to handle your request (Art. 6(1)(b) or (f) GDPR) and delete them once they are no longer needed and no retention obligations stand in the way.

Changes to this policy

If this policy changes materially, we'll inform registered users by email.