Privacy Policy

Last updated: August 2026

Who we are

Noctua is operated by AGNÉLIS, a sole trader registered in the United Kingdom. AGNÉLIS acts as the data controller under UK GDPR. Address: Bradford BD6 1RE, West Yorkshire, United Kingdom. Contact: contact.agnelis@gmail.com.

What data we collect

We collect data you voluntarily enter into the app:

  • Account data: email, name, profile photo
  • Journal entries: content, mood markers, emotions
  • Dream entries: content, symbols, emotional tone
  • Shadow work: responses, selected emotions
  • Menstrual cycle data: dates, symptoms, phases
  • Birth data (Premium): date, time, and place of birth. Entered voluntarily, used to personalise planetary workbooks.
  • Technical data: IP addresses (anonymised), login timestamps, device identifiers for push notifications (subscription endpoints). Stored for technical purposes only.

IMPORTANT: journal entries, dream entries, shadow work entries, and menstrual cycle data are classified as special category data under UK GDPR Article 9. They include information about your mental and physical health. We process them solely based on your explicit consent given at registration.

Crisis detection

Noctua checks the text you write for words that indicate a crisis: suicidal thoughts, self-harm, violence, eating disorders and similar. This is a comparison against a word list, not artificial intelligence. No text is sent anywhere for this purpose.

In several places, when preparing your shadow work questions, a report, a Reflection, or a prompt sent in a notification, we also check your earlier entries. We check only entries from the last 30 days, never older. This is still the same comparison against a word list, carried out on our side, and no text is sent anywhere for this purpose.

When something is recognised, we show you helpline numbers. We record that it happened, when, on which screen, and whether the signal was acute or general.

If the message asks you to confirm it and you press “I understand, continue”, we also record that confirmation: that it happened, when, on which screen, in which language, and which version of the message you were shown. We keep the exact text of that message, so that it is possible to reconstruct what was actually on the screen and not merely a version number. If the message appeared alongside a saved entry, we also record a reference to it: its identifier, the screen, and the time it was created. If it appeared before you had saved anything, we record only the name of the screen.

We do not store what you wrote. Not the whole entry, not a fragment, not the word that matched. The record says that something happened. It does not say what. This applies to confirmations as well. The reference to an entry says which entry it was. It does not say what you wrote in it.

We do this so that help appears when it may be needed, and so that we do not return with the same message on every following entry. It is not used to judge you or to build a profile of you.

We do this so that it can later be shown that support was in fact presented to you, in what form and when. It is a record of what the application showed and whether it was acknowledged. It does not assess how you are, or how well you are coping.

No one reviews these records: there is no screen, panel or report in Noctua that shows their content. They are read only by counting mechanisms, with no access to the content of a record: one checks how many times this happened in the last seven days, the other counts how many records have passed 90 days and are due for deletion.

Noctua is not an emergency service and does not contact anyone on your behalf. In an urgent situation, call the numbers in the Grounding section.

Legal basis for processing

We process your data under UK GDPR based on the following legal grounds:

  • Article 6(1)(b), namely performance of a contract with you (provision of Noctua services)
  • Article 6(1)(f), namely legitimate interests of the controller (security, technical monitoring)
  • Article 9(2)(a), namely your explicit consent for processing special category data (mental health, menstrual cycle data)

How we use your data

Your data is used solely to:

  • Display your entries and track your progress
  • Generate personalised reports and insights (Premium subscription)
  • Generate shadow work questions based on your entries (automated process using artificial intelligence)
  • Process payments (via Stripe, we do not store card details)
  • Communicate with you on technical matters

We never sell your data. We never display advertisements. We never share your data with third parties for marketing purposes.

Who we share your data with (subprocessors)

To provide Noctua services, we use the following subprocessors. Each has appropriate data processing agreements compliant with UK GDPR:

  • Supabase Inc., database hosting and authentication, location: London (United Kingdom)
  • Vercel Inc., web application hosting, location: EU/USA
  • Stripe Inc., payment processing, location: EU/USA
  • Anthropic PBC, AI-generated questions and analyses (Claude model), location: USA
  • Sentry (Functional Software, Inc.), application error monitoring, location: EU
  • Resend Inc., feedback reply delivery, location: USA

Anthropic's full subprocessors list is available at: trust.anthropic.com/subprocessors

Important: Anthropic does not use data sent via API to train its models. Your entries are not used for training purposes. This is confirmed in Anthropic's Data Processing Addendum (DPA) available at anthropic.com/legal/dpa.

Data transfer outside EU/UK

Some of our subprocessors (Anthropic, Vercel, Stripe) may process your data in the United States. To ensure an adequate level of data protection, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and the UK Addendum to the EU SCCs.

Anthropic has a Data Processing Addendum (DPA) with Standard Contractual Clauses automatically incorporated into commercial terms. The full document is available at anthropic.com/legal/dpa.

Profiling and automated decision-making

Noctua uses artificial intelligence (Claude by Anthropic) to generate personalised shadow work questions and reports based on your entries. This constitutes profiling under UK GDPR Article 22.

Important: AI-generated questions and analyses are reflective in nature only and do not produce legal or similarly significant effects on you. AI does not make decisions for you and does not provide a diagnosis. It does not judge you or assign you labels. Questions and readings are something to consider, not a verdict.

There is one exception and we name it plainly: crisis detection recognises the level of a signal and records it (see the Crisis detection section). This is not done by AI but by comparison against a word list, and it exists to surface help, not to assess you.

Your rights

Under UK GDPR you have the right to:

  • Access your data (Article 15)
  • Rectify your data (Article 16)
  • Delete your data (right to be forgotten, Article 17)
  • Restrict processing (Article 18)
  • Data portability in machine-readable format (Article 20)
  • Object to processing (Article 21)
  • Withdraw consent at any time (Article 7), without affecting the lawfulness of processing before withdrawal
  • Not being subject to automated decision-making (Article 22)

To exercise these rights, email contact.agnelis@gmail.com. We will respond within 30 days as required by UK GDPR.

Data security

We apply appropriate technical and organisational measures to protect your data:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Row Level Security ensures each user sees only their own data
  • Regular backups
  • Error and security incident monitoring

In the event of a data breach posing a high risk to your rights and freedoms: we will notify you without undue delay and report the breach to the ICO within 72 hours as required by UK GDPR Articles 33-34.

Cookies

We use only essential cookies to maintain your login session. We do not use tracking, advertising, or analytics cookies.

Data retention

Your data is retained for as long as your account is active. Upon account deletion, all data is permanently removed within 30 days. Technical logs (Sentry) are retained for up to 90 days and used solely for security and error monitoring. Push notification device identifiers are deleted upon withdrawal of consent or account deletion.

Crisis detection records (the fact, the time, the screen, the level of the signal) are retained for 90 days from detection and then deleted. They are removed earlier together with your account.

We keep confirmations of crisis messages indefinitely, because they exist to show that help was presented. After your account is deleted the record remains but stops being linked to you: your identifier is removed and what stays is a value derived from your email address, which cannot be used to find you unless you provide that address yourself.

Children's data

Noctua is intended for users aged 16 and over. We do not knowingly collect data from individuals under 16. If we discover that an account belongs to a minor, it will be immediately deleted along with all data.

Changes to this privacy policy

We reserve the right to update this privacy policy. We will inform you of significant changes by email or in-app notification at least 30 days before they take effect. The date of the last update is shown at the top of this page.

Contact and complaints

For privacy-related questions: contact.agnelis@gmail.com. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the United Kingdom if you believe your data is being processed unlawfully. ICO: ico.org.uk.