Andesha

Privacy Policy

Andesha · Amirich LLC · Version 2026-09-13

Contents
  1. About This Policy and the Controller
  2. What We Collect
  3. Purposes and Legal Bases
  4. Data About Mood and Wellbeing
  5. What Is Transferred to AI Providers
  6. Encryption and Who Can Read Your Entries
  7. Data on Your Device
  8. Who We Share Data With
  9. International Transfers
  10. Automated Processing and Profiling
  11. Advertising
  12. Your Rights
  13. How to Exercise Your Rights
  14. How Long We Keep Data
  15. Deleting Your Account
  16. Security Incidents
  17. Children's Privacy
  18. Cookies and Tracking
  19. Your Rights in the United States
  20. Changes to This Policy
  21. Contact

1About This Policy and the Controller

Version: 2026-09-13. This Privacy Policy takes effect on the date of this version and replaces all earlier ones.

The controller of your personal data is Amirich LLC (New York, USA), the operator of Andesha.

Questions about data and requests to exercise your rights, and general support: amirich.corp@gmail.com. Website: https://amirich.org

This document explains what data we collect, why, on what legal basis, to whom it is transferred, how long it is kept and what you can do about it. It covers the Andesha mobile app and the server services behind it.

We have tried to write it in plain language. If anything is unclear, write to amirich.corp@gmail.com and we will explain.

2What We Collect

Account data:

Diary content:

Payment data:

For purchases in the app, payment is taken by Apple (App Store) or Google (Google Play): we receive only the purchase and transaction identifiers, the product, and the dates and status of the purchase. For payments on our website, card details are handled by Stripe. In no case do we see or store your card number.

Technical data:

Support correspondence: the text of your messages to us and our replies.

3Purposes and Legal Bases

Performance of the contract with you (providing the service you signed up for):

Your consent:

Our legitimate interest:

Legal obligation: accounting and tax records of payments, responses to lawful requests from authorities.

We do not sell personal data, do not pass it to data brokers and do not use diary content to train AI models.

4Data About Mood and Wellbeing

Entries about mood, emotional state, stress and wellbeing may be treated as a special category of personal data — data concerning health — under Article 9 of the GDPR.

We process such data only on the basis of your explicit consent, which you give with a separate checkbox at registration and can withdraw at any time by writing to amirich.corp@gmail.com or by deleting your account.

This data has additional protection: it is stored encrypted, is not used for advertising, is not used to train models and is not visible to Andesha staff.

If you withdraw consent, AI processing stops. Entries already created remain in your account until you delete them yourself, and we no longer send them to AI providers.

5What Is Transferred to AI Providers

The AI features run on OpenAI. The following is transferred there:

Instead of your email address and name we send a pseudonym — a hash of your identifier — so that requests can be attributed to an account without revealing who you are.

Reading aloud in Russian, Ukrainian and Tajik is done by our own speech synthesis on our servers: this text does not leave our infrastructure and does not consume AI tokens. For other languages, and if our synthesis is unavailable, the text is voiced by OpenAI or by the built-in voice of your device.

Under our agreement, OpenAI processes this data to fulfil the request and does not use it to train its models. On the OpenAI side, processing is additionally governed by its own privacy policy.

If you do not want your entries to be sent to an AI provider, do not use the AI features: the diary, search, export and reminders work without them.

6Encryption and Who Can Read Your Entries

The content of your entries, transcripts, conversations with MoodAI, daily summaries, AI memory and support messages is stored on our servers encrypted with AES-256-GCM.

Each user has their own separate key, and that key is itself encrypted with the service master key. Anyone who obtained the storage would see ciphertext, not text.

Andesha staff cannot read your entries through the admin panel. Administrators see only account data: email address, name, plan, payment history, token consumption and technical status. Texts, photos and voice recordings are not displayed there.

Data between the app and the server travels over an encrypted connection, and passwords are never stored in readable form.

No system is perfectly secure, but we design the service so that as little as possible could be exposed if something goes wrong.

7Data on Your Device

Some data is kept on your phone so that the diary works offline:

Access tokens are stored in the secure storage provided by the operating system — Keychain on iOS and Keystore on Android.

You can turn on an app lock: biometrics or a separate 6-digit passcode. On a device other people can reach, we recommend it.

When you sign out or uninstall the app, the local database and the tokens are removed from the device. Copies your phone has already placed in iCloud or Google backups are governed by the settings and rules of those services.

8Who We Share Data With

We share data only with the companies the service cannot work without, and they act in different roles.

Processors — process data on our behalf, only on our instructions and only for the tasks listed:

Independent controllers — receive data within their own services, decide themselves how to process it and are responsible for that under their own terms and privacy policies:

We may also disclose data where the law requires it — for example under a lawful request from an authority — and where we are permitted to do so, we will tell you.

We do not sell personal data and do not pass it to data brokers, ad exchanges or social networks. If the business is sold or merged, data would transfer to the new owner with the same obligations, and we would notify you in advance so that you can delete your account first.

9International Transfers

Our processors — OpenAI, Stripe and Resend — are located in the United States, so your data is transferred outside the European Economic Area. Apple and Google, through whose stores purchases in the app are made, may also process purchase data in the United States; they do so as independent controllers under their own terms, and we exchange with them only purchase identifiers and statuses.

Transfers to our processors rely on the Standard Contractual Clauses approved by the European Commission, concluded with those companies, together with additional technical measures: encrypted transmission, minimisation of what is sent and pseudonymisation of identifiers.

On the Free plan, Google's advertising module sends the technical device data described in section 11 directly to Google, which may process it in the United States as an independent controller under its own privacy policy and transfer safeguards.

You have the right to obtain information about the safeguards applied to such transfers — write to amirich.corp@gmail.com.

Please bear in mind that the level of data protection in third countries may differ from that in your own, and that public authorities there may have powers of access that differ from those you are used to.

10Automated Processing and Profiling

Andesha analyses entries automatically: the AI produces mood, stress and energy scores, forms conclusions, summaries and trends, and shapes MoodAI's replies. This is automated processing with elements of profiling — building a picture of your emotional state over time.

These scores have no legal effect and are not used to take decisions about you: we do not use them to restrict access, set prices, evaluate you as a customer, or pass judgements to third parties.

You have the right not to rely on automated assessments, to contest them, to express your point of view and to ask for a human review — write to amirich.corp@gmail.com and we will look at the case ourselves.

You can delete any analysis together with the entry, or turn AI processing off entirely by withdrawing your consent. In that case the app keeps working as a plain diary.

11Advertising

Advertising appears only on the Free plan and is what allows that plan to remain free with no time limit. There is no advertising at all on the Starter and Pro plans. Ads are delivered through Google AdMob in non-personalised form.

Your diary content never goes into advertising. We do not pass your entries, transcripts, photos, voice recordings, analysis results or email address to Google or any other advertising network, and we do not use diary content or mood data to select ads or to build advertising profiles.

To show and count an ad, Google's advertising module receives technical data directly from your device: IP address, device model and operating system version, information about the app and about your interaction with the ad, diagnostic data about how the advertising module works, and device identifiers: on Android the advertising identifier and the app set identifier (App Set ID), on iOS the identifier for vendor (IDFV), which is different for apps from different developers. Google uses this data to serve ads, count impressions and prevent fraud under its own privacy policy (https://policies.google.com/privacy). You can reset or delete the Android advertising identifier in your phone settings.

Our own server records only the fact that an ad was shown or tapped, together with your account, the place in the app, the platform and the time, for advertising statistics.

If you are in the European Economic Area, the United Kingdom or Switzerland, the app shows Google's consent form (User Messaging Platform) before any ads are shown. Declining does not limit any other feature of the app. You can review or change your choice at any time in Profile → Privacy → Ad settings; this item appears when Google requires the consent form in your region.

The app does not ask for permission to track you across other companies' apps and websites (App Tracking Transparency on iOS) and does not use the IDFA advertising identifier.

12Your Rights

If you are in the EU or the EEA, the GDPR gives you the rights listed below. We extend the same rights to every user, wherever they live:

Exercising these rights is free. We do not degrade the service or change prices because you have used them.

13How to Exercise Your Rights

The fastest routes are built into the app: edit your profile, delete an individual entry, export your data, delete your account.

For anything else, write to amirich.corp@gmail.com from the email address linked to your account. We reply within 30 days; in complex cases we may extend that period by up to two further months and will explain why.

We may ask you to confirm your identity — usually with a code sent to the account email address. This is to stop someone else from obtaining your data.

We may refuse a request only where the law allows — for example if fulfilling it would disclose another person's data — and we will always give the reason.

If you believe we process your data unlawfully, you may complain to the data protection authority of your country of residence, your place of work, or the place where you believe the infringement occurred. We would be grateful for a chance to resolve it first: amirich.corp@gmail.com.

14How Long We Keep Data

When a retention period expires, data is deleted. Purchase records and advertising statistics, which remain after the account is deleted, are kept without a link to it.

15Deleting Your Account

You can delete your account in the app settings at any time. Here is exactly what happens:

Deleting the account does not cancel a subscription bought through the App Store or Google Play. Cancel it in the subscription settings of your Apple ID or Google Play account, otherwise the store will keep charging you.

After deletion, only the following remains with us:

Copies held by processors are deleted on their own schedules under our agreements with them.

Export anything you care about before deleting: once the archive period has passed, we cannot restore it.

16Security Incidents

We monitor the security of the service and keep our systems updated. If a personal data breach nevertheless occurs, we act as follows:

Because entry content is stored encrypted with individual keys, gaining access to the storage alone does not reveal the text of your entries.

If you notice something suspicious in your account or find a vulnerability, write to amirich.corp@gmail.com — we treat such reports as a priority.

17Children's Privacy

Andesha is intended only for people aged 18 and over. We do not knowingly collect data about children and we offer neither a children's version nor a parental-consent mechanism.

If we discover that an account was created by a person under 18, we block it and delete the associated data.

If you believe a minor has created an account, or that we hold a child's data, write to amirich.corp@gmail.com — we will check and delete it.

18Cookies and Tracking

The Andesha mobile app does not use cookies and does not embed third-party analytics or advertising trackers that would follow you across other apps and websites.

Your signed-in session is maintained by access tokens kept in the secure storage of the operating system.

On the Free plan, Google's advertising module may store service data on the device, such as your choice in the consent form, and may use device identifiers (the advertising identifier and App Set ID on Android, IDFV on iOS) for impression counting and fraud prevention; see section 11 for details. The advertising itself stays non-personalised, and the app does not ask for tracking permission (App Tracking Transparency).

The web admin panel, which is used by our staff and not by users, relies only on strictly necessary session cookies.

19Your Rights in the United States

If you live in California, the CCPA as amended by the CPRA gives you the rights below. We extend the same rights to residents of every other US state with a comparable privacy law, and in practice to all our users:

We do not sell your personal information and we do not share it for cross-context behavioural advertising. Ads on the free plan are non-personalised.

Entries about mood and wellbeing are sensitive personal information. We use them only to provide the service you asked for and never to infer characteristics about you for advertising.

To exercise any of these rights write to amirich.corp@gmail.com. We answer within 45 days and may extend once by another 45 days when a request is complex, telling you why. You may authorise an agent to act for you; we will ask for proof of that authority.

20Changes to This Policy

We may update this Policy — for example when features, processors or legal requirements change. The current version and its date are shown at the beginning of the document.

We will notify you of material changes by email or in the app at least 14 days before they take effect. If a change concerns processing that requires consent, we will ask for your consent again rather than assume it.

Earlier versions are available on request at amirich.corp@gmail.com.

21Contact

Andesha, a service by Amirich LLC (New York, USA)

We reply to privacy enquiries within 30 days.

You also have the right to lodge a complaint with the supervisory authority of your country.

Document version: 2026-09-13.