My Within
Política de privacidad
Última actualización: July 2026
This Privacy Policy explains how My Within (operated by Inside Out Harmony e.U., an Austrian sole-proprietor company — VAT ATU82926238 · FN 668345 k · Landesgericht Feldkirch) collects, uses, and shares your personal data. We follow the EU General Data Protection Regulation (GDPR), the Austrian Data Protection Act (DSG), and equivalent laws where applicable.
1. Data controller
Inside Out Harmony e.U., Außerlitzstraße 10a, 6780 Schruns, Austria. VAT ATU82926238 · FN 668345 k · Landesgericht Feldkirch. Data-protection contact: privacy@my-within.com. Supervisory authority: Österreichische Datenschutzbehörde (DSB), Barichgasse 40-42, 1030 Wien — https://www.dsb.gv.at.
2. Data we collect
· Account: name, email, password hash, language, avatar (optional). · Journal & practice: journal text and voice recordings, mood scores, breakout session logs, EVA chat messages. · Health & biometrics (optional): heart rate + HRV from a paired device or Apple HealthKit / Google Health Connect. We NEVER access data you have not explicitly linked. · Payments: Stripe processes card data; we only store subscription tier, invoice IDs, and last-4 for display. · Device & diagnostic: device model, OS version, crash logs (via Sentry if enabled), IP address for rate-limiting.
3. Why we process it (legal bases)
· Providing the Service (contract, Art. 6(1)(b)). · EVA/WEVA AI analysis of your inputs (explicit consent, Art. 9(2)(a) as this may include emotional/health data). · Coach data-sharing (your explicit toggle in Collaboration Settings, revocable any time). · Fraud prevention & security (legitimate interest, Art. 6(1)(f)). · Legal compliance & tax records (Art. 6(1)(c)).
4. Sub-processors
· Emergent Integrations — routes requests to Anthropic (Claude) and OpenAI (Whisper STT, TTS) for WEVA/EVA analysis. Prompts are pseudonymised before egress. · Stripe Payments Europe, Ltd. (Ireland) — payments + subscriptions on web. · RevenueCat, Inc. (USA · EU-U.S. DPF) — App Store / Play Store receipt validation. · Hetzner Online GmbH — MongoDB hosting in Helsinki, Finland (EU/EEA). · Sentry EU (Frankfurt, DE) — error diagnostics, PII stripped at source. · PostHog EU (Frankfurt, DE) — anonymised product analytics, IP anonymised. · Google Firebase FCM (Dublin, IE) — push tokens & delivery only. · Resend — transactional email delivery. We have signed Art. 28 GDPR agreements with all sub-processors.
5. AI-specific processing & automated decisions (Art. 22)
When EVA/WEVA analyses your journal or chat, we transmit only the specific text/audio needed. Providers contractually do not train on your data by default. Voice recordings are deleted from disk immediately after transcription. WEVA/EVA outputs are informational only — they do not make binding decisions about you. You may request human review by emailing privacy@my-within.com. WEVA is not a diagnostic tool and never replaces a licensed clinician.
6. International transfers
Some sub-processors are in the USA. Transfers are covered by the 2021 Standard Contractual Clauses and — where applicable — the EU-US Data Privacy Framework (DPF). Primary data storage remains in the EU.
7. Retention
We keep your data as long as your account is active. On deletion we cascade-delete your personal data, except (a) invoices retained 7 years for Austrian tax law (BAO §132), (b) minimal anti-abuse logs for 90 days, and (c) pseudonymised audit rows for 7 years.
8. Your rights
· Access (Art. 15) — export all your data. · Rectification (Art. 16) — edit your profile. · Erasure (Art. 17) — delete your account. · Portability (Art. 20) — machine-readable JSON export. · Restriction / Objection (Art. 18, 21) — email privacy@my-within.com. · Complain to your supervisory authority (Austria: DSB — https://www.dsb.gv.at).
9. Cookies & tracking
The web app uses only a session token in local storage. We do not use advertising cookies or advertising SDKs — My Within is ad-free.
10. Children
We do not knowingly collect data from users under 16. All signups require age-16+ confirmation (Art. 8 GDPR).
11. Security
TLS 1.2+ in transit, AES-256 at rest, bcrypt password hashing, isolated databases per environment, and rate-limiting on all AI endpoints.
12. Breach notification
In the event of a breach likely to risk your rights, we notify the DSB within 72 hours (Art. 33) and you directly where required (Art. 34).
13. Contact
Data controller: Inside Out Harmony e.U. — privacy@my-within.com. General inquiries: support@my-within.com.