Privacy Policy
DRAFT - This policy is a placeholder pending legal review.
Last updated: August 02, 2026
Looking for a plain-language summary? Read our Privacy Commitment.
1. What We Collect
Deepen collects information you provide directly, including:
- Account information (email address, password)
- Diary-style entries (text and voice recordings)
- Contact details parsed from your entries (names, relationships, activities)
- Location data if you choose to tag entries
- Payment information processed through Stripe
2. How We Use Your Data
Your data is used to:
- Provide the core Deepen service: parsing entries, building your contact database, and surfacing relationship insights
- Process voice recordings into text via AI transcription
- Parse names, places, and activities from your entries using AI
- Send you notifications and reminders about your relationships
- Process payments and manage your subscription
3. Data Encryption & Security
We take the security of your personal information seriously. Entry text, contact names, phone numbers, email addresses, contact notes, recommendations, life events, key facts, organizations, and calendar events are encrypted at rest using Active Record Encryption. Data is also encrypted in transit using TLS. A few structural fields — saved location names/addresses, to-do descriptions, and the AI-parsed activity/notable-detail fields on an interaction (its description field is encrypted) — are not yet encrypted at rest; we are rolling encryption out to those tables.
Your password is securely hashed and stored separately from your account data. We enforce strong password requirements and provide account lockout protection against brute-force attacks.
4. Third-Party Services
Deepen uses the following third-party services to provide its functionality:
- Anthropic (Claude) - AI-powered parsing of your diary entries to extract contacts, activities, and relationships. Entry text is sent to Anthropic's API for processing.
- OpenAI (Whisper) - Voice-to-text transcription of audio entries. Audio recordings are sent to OpenAI's API for transcription.
- Stripe - Payment processing for subscriptions. We do not store your credit card details; Stripe handles all payment data.
- Sentry - Error tracking and monitoring to maintain service reliability. No personally identifiable information is intentionally sent to Sentry.
- Nominatim (OpenStreetMap) - Geocoding of saved location names/addresses into map coordinates. When you tag an entry with a location, that location's name/address is sent to Nominatim's API for lookup.
5. Data Retention
Your data is retained for as long as your account is active. When you delete an entry, a contact, or another record, it is immediately removed from your account, all views, search, and future exports, and held in a short recovery window (30 days) in case the deletion was accidental; we do not yet run an automated purge of that retained data once the window passes. Closing your account deactivates it and blocks further login, but does not by itself erase the underlying data — email us at the address below if you want your data purged sooner or more completely than our current automation handles, and we will do so by hand. Some data may also be retained in encrypted backups for up to 30 days.
6. Your Rights
You have the right to:
- Access - Export the data you've created in Deepen at any time through the Data Export feature (entries, contacts, interactions, relationships, locations, todos, recommendations, events, organizations, key facts, life events, and contact groups; conversation-topic summaries and original voice recordings are not yet included, though the transcribed entry text is)
- Correct - Edit your entries, contacts, and profile information
- Delete - Delete individual entries or contacts (soft-deleted, then held in a 30-day recovery window), or close your entire account
- Port - Download your data in a standard format via Data Export
7. Data Isolation
Deepen uses row-level security and application-level tenant isolation to ensure your data is completely separated from other users' data. No user can access another user's entries, contacts, or any other personal information.
8. Contact
If you have questions about this privacy policy or your data, please contact us at privacy@deeepen.com.