Privacy Policy
Contents
- About This Policy and the Controller
- What We Collect
- Purposes and Legal Bases
- Data About Mood and Wellbeing
- What Is Transferred to AI Providers
- Encryption and Who Can Read Your Entries
- Data on Your Device
- Who We Share Data With
- International Transfers
- Automated Processing and Profiling
- Advertising
- Your Rights
- How to Exercise Your Rights
- How Long We Keep Data
- Deleting Your Account
- Security Incidents
- Children's Privacy
- Cookies and Tracking
- Your Rights in the United States
- Changes to This Policy
- Contact
1About This Policy and the Controller
Version: 2026-09-13. This Privacy Policy takes effect on the date of this version and replaces all earlier ones.
The controller of your personal data is Amirich LLC (New York, USA), the operator of Andesha.
Questions about data and requests to exercise your rights, and general support: amirich.corp@gmail.com. Website: https://amirich.org
This document explains what data we collect, why, on what legal basis, to whom it is transferred, how long it is kept and what you can do about it. It covers the Andesha mobile app and the server services behind it.
We have tried to write it in plain language. If anything is unclear, write to amirich.corp@gmail.com and we will explain.
2What We Collect
Account data:
- email address and name;
- phone number and bio, if you fill them in;
- profile photo (avatar);
- interface language, time zone, notification settings;
- the fact and version of the documents you accepted at registration.
Diary content:
- text entries and their titles;
- voice recordings and their transcripts;
- photos you add and text recognised from them;
- AI analysis results: mood, stress and energy estimates, conclusions;
- conversations with MoodAI and the AI memory built from your entries;
- daily summaries, trends, goals and reminders.
Payment data:
- plan, subscription status, payment and refund history;
- AI token balance and consumption.
For purchases in the app, payment is taken by Apple (App Store) or Google (Google Play): we receive only the purchase and transaction identifiers, the product, and the dates and status of the purchase. For payments on our website, card details are handled by Stripe. In no case do we see or store your card number.
Technical data:
- device type and operating system, app version;
- sign-in times and technical request logs;
- error reports;
- on the Free plan — records of ad impressions and taps: the place in the app, the platform and the time (see section 11).
Support correspondence: the text of your messages to us and our replies.
3Purposes and Legal Bases
Performance of the contract with you (providing the service you signed up for):
- creating and maintaining the account, signing in;
- storing and synchronising diary entries;
- processing payments, subscriptions and token packs;
- service emails: sign-in codes, password recovery, payment receipts;
- handling support requests.
Your consent:
- processing entries, audio and photos by AI providers for transcription, analysis, summaries and answers;
- processing information about your mood and wellbeing (see the next section);
- push notifications and reminders where consent is required by law;
- in the European Economic Area, the United Kingdom and Switzerland — storing and reading information on the device by Google's advertising module on the Free plan, through Google's consent form (section 11).
Our legitimate interest:
- security of the service, prevention of abuse and fraud;
- aggregated, impersonal statistics about how the app is used;
- defending our rights in a dispute;
- on the Free plan — showing non-personalised ads and counting impressions and taps, which keeps that plan free (section 11).
Legal obligation: accounting and tax records of payments, responses to lawful requests from authorities.
We do not sell personal data, do not pass it to data brokers and do not use diary content to train AI models.
4Data About Mood and Wellbeing
Entries about mood, emotional state, stress and wellbeing may be treated as a special category of personal data — data concerning health — under Article 9 of the GDPR.
We process such data only on the basis of your explicit consent, which you give with a separate checkbox at registration and can withdraw at any time by writing to amirich.corp@gmail.com or by deleting your account.
This data has additional protection: it is stored encrypted, is not used for advertising, is not used to train models and is not visible to Andesha staff.
If you withdraw consent, AI processing stops. Entries already created remain in your account until you delete them yourself, and we no longer send them to AI providers.
5What Is Transferred to AI Providers
The AI features run on OpenAI. The following is transferred there:
- the text of entries — for analysis, MoodAI chat and daily summaries;
- audio files of voice entries — for transcription and analysis;
- images — for recognising text from a photo;
- the text you ask to be read aloud;
- in live voice conversation mode, audio goes from your device straight to OpenAI servers over a real-time connection, without passing through our server.
Instead of your email address and name we send a pseudonym — a hash of your identifier — so that requests can be attributed to an account without revealing who you are.
Reading aloud in Russian, Ukrainian and Tajik is done by our own speech synthesis on our servers: this text does not leave our infrastructure and does not consume AI tokens. For other languages, and if our synthesis is unavailable, the text is voiced by OpenAI or by the built-in voice of your device.
Under our agreement, OpenAI processes this data to fulfil the request and does not use it to train its models. On the OpenAI side, processing is additionally governed by its own privacy policy.
If you do not want your entries to be sent to an AI provider, do not use the AI features: the diary, search, export and reminders work without them.
6Encryption and Who Can Read Your Entries
The content of your entries, transcripts, conversations with MoodAI, daily summaries, AI memory and support messages is stored on our servers encrypted with AES-256-GCM.
Each user has their own separate key, and that key is itself encrypted with the service master key. Anyone who obtained the storage would see ciphertext, not text.
Andesha staff cannot read your entries through the admin panel. Administrators see only account data: email address, name, plan, payment history, token consumption and technical status. Texts, photos and voice recordings are not displayed there.
Data between the app and the server travels over an encrypted connection, and passwords are never stored in readable form.
No system is perfectly secure, but we design the service so that as little as possible could be exposed if something goes wrong.
7Data on Your Device
Some data is kept on your phone so that the diary works offline:
- entries you have already opened or loaded, together with their analysis, are stored in the app database;
- drafts and a queue of changes waiting to be synchronised;
- settings and cache.
Access tokens are stored in the secure storage provided by the operating system — Keychain on iOS and Keystore on Android.
You can turn on an app lock: biometrics or a separate 6-digit passcode. On a device other people can reach, we recommend it.
When you sign out or uninstall the app, the local database and the tokens are removed from the device. Copies your phone has already placed in iCloud or Google backups are governed by the settings and rules of those services.
8Who We Share Data With
We share data only with the companies the service cannot work without, and they act in different roles.
Processors — process data on our behalf, only on our instructions and only for the tasks listed:
- OpenAI (USA) — AI analysis, transcription, chat, text recognition from photos, speech synthesis for languages our own synthesis does not cover.
- Stripe (USA) — payments on our website. Stripe receives your email address and payment details; we do not receive the card number.
- Resend (USA) — sending service emails: sign-in codes, password recovery, notifications.
- Hosting and infrastructure providers, where our servers and file storage run.
Independent controllers — receive data within their own services, decide themselves how to process it and are responsible for that under their own terms and privacy policies:
- Apple (App Store) and Google (Google Play) — purchases of subscriptions and token packs in the app. The store takes the payment under its own terms and privacy policy and sends us signed purchase data and notifications: purchase and transaction identifiers, the product, dates and subscription status. To check a Google Play purchase, our server sends its purchase token to Google.
- Google AdMob (USA) — non-personalised advertising on the Free plan only. Diary content and your email address are not passed to it; the technical device data Google receives to show ads is described in section 11.
We may also disclose data where the law requires it — for example under a lawful request from an authority — and where we are permitted to do so, we will tell you.
We do not sell personal data and do not pass it to data brokers, ad exchanges or social networks. If the business is sold or merged, data would transfer to the new owner with the same obligations, and we would notify you in advance so that you can delete your account first.
9International Transfers
Our processors — OpenAI, Stripe and Resend — are located in the United States, so your data is transferred outside the European Economic Area. Apple and Google, through whose stores purchases in the app are made, may also process purchase data in the United States; they do so as independent controllers under their own terms, and we exchange with them only purchase identifiers and statuses.
Transfers to our processors rely on the Standard Contractual Clauses approved by the European Commission, concluded with those companies, together with additional technical measures: encrypted transmission, minimisation of what is sent and pseudonymisation of identifiers.
On the Free plan, Google's advertising module sends the technical device data described in section 11 directly to Google, which may process it in the United States as an independent controller under its own privacy policy and transfer safeguards.
You have the right to obtain information about the safeguards applied to such transfers — write to amirich.corp@gmail.com.
Please bear in mind that the level of data protection in third countries may differ from that in your own, and that public authorities there may have powers of access that differ from those you are used to.
10Automated Processing and Profiling
Andesha analyses entries automatically: the AI produces mood, stress and energy scores, forms conclusions, summaries and trends, and shapes MoodAI's replies. This is automated processing with elements of profiling — building a picture of your emotional state over time.
These scores have no legal effect and are not used to take decisions about you: we do not use them to restrict access, set prices, evaluate you as a customer, or pass judgements to third parties.
You have the right not to rely on automated assessments, to contest them, to express your point of view and to ask for a human review — write to amirich.corp@gmail.com and we will look at the case ourselves.
You can delete any analysis together with the entry, or turn AI processing off entirely by withdrawing your consent. In that case the app keeps working as a plain diary.
11Advertising
Advertising appears only on the Free plan and is what allows that plan to remain free with no time limit. There is no advertising at all on the Starter and Pro plans. Ads are delivered through Google AdMob in non-personalised form.
Your diary content never goes into advertising. We do not pass your entries, transcripts, photos, voice recordings, analysis results or email address to Google or any other advertising network, and we do not use diary content or mood data to select ads or to build advertising profiles.
To show and count an ad, Google's advertising module receives technical data directly from your device: IP address, device model and operating system version, information about the app and about your interaction with the ad, diagnostic data about how the advertising module works, and device identifiers: on Android the advertising identifier and the app set identifier (App Set ID), on iOS the identifier for vendor (IDFV), which is different for apps from different developers. Google uses this data to serve ads, count impressions and prevent fraud under its own privacy policy (https://policies.google.com/privacy). You can reset or delete the Android advertising identifier in your phone settings.
Our own server records only the fact that an ad was shown or tapped, together with your account, the place in the app, the platform and the time, for advertising statistics.
If you are in the European Economic Area, the United Kingdom or Switzerland, the app shows Google's consent form (User Messaging Platform) before any ads are shown. Declining does not limit any other feature of the app. You can review or change your choice at any time in Profile → Privacy → Ad settings; this item appears when Google requires the consent form in your region.
The app does not ask for permission to track you across other companies' apps and websites (App Tracking Transparency on iOS) and does not use the IDFA advertising identifier.
12Your Rights
If you are in the EU or the EEA, the GDPR gives you the rights listed below. We extend the same rights to every user, wherever they live:
- Access — to find out whether we process your data and to receive a copy of it.
- Rectification — to have inaccurate data corrected; the profile can be edited in the app at any time.
- Erasure (the "right to be forgotten") — to have your data deleted; account deletion is available in the app.
- Portability — to receive your data in a structured, machine-readable format and transfer it to another service; export is built into the app.
- Restriction of processing — to require us to stop using the data temporarily, for example while a dispute about its accuracy is being resolved.
- Objection — to object to processing based on our legitimate interest.
- Withdrawal of consent — at any time, without affecting the lawfulness of processing carried out before the withdrawal.
- Not to be subject to a decision based solely on automated processing — see the section on profiling.
- Complaint — to lodge a complaint with a supervisory authority.
Exercising these rights is free. We do not degrade the service or change prices because you have used them.
13How to Exercise Your Rights
The fastest routes are built into the app: edit your profile, delete an individual entry, export your data, delete your account.
For anything else, write to amirich.corp@gmail.com from the email address linked to your account. We reply within 30 days; in complex cases we may extend that period by up to two further months and will explain why.
We may ask you to confirm your identity — usually with a code sent to the account email address. This is to stop someone else from obtaining your data.
We may refuse a request only where the law allows — for example if fulfilling it would disclose another person's data — and we will always give the reason.
If you believe we process your data unlawfully, you may complain to the data protection authority of your country of residence, your place of work, or the place where you believe the infringement occurred. We would be grateful for a chance to resolve it first: amirich.corp@gmail.com.
14How Long We Keep Data
- Account data — for as long as the account exists.
- Entries, transcripts, photos, audio, analysis and conversations — until you delete them, or until the account is deleted.
- Deleted account — 50 days in the archive, then permanent deletion.
- Entries you delete individually — removed from the server without an archive period and from the device at the next synchronisation.
- Sign-in codes and password recovery links — a few minutes, after which they expire.
- Technical server logs — kept for a limited time and overwritten automatically; the content of diary entries is not written to them.
- Security logs of the service (administrator actions and access to data) — up to 180 days, then deleted automatically; they contain no diary content.
- Records of ad impressions and taps (Free plan) — while the account exists; after the account is permanently deleted, the link to it is removed and only impersonal statistics remain.
- Records of purchases and payments, including App Store, Google Play and Stripe transaction identifiers — while the account exists they are linked to it; after the account is permanently deleted the link is removed, and the record itself (product, amount, currency, date, transaction identifiers) remains for accounting and tax purposes and so that the same purchase cannot be credited twice. Apple, Google and Stripe also keep this data under their own rules.
- Consent records — for as long as the account exists; they are deleted together with the account when it is permanently deleted.
When a retention period expires, data is deleted. Purchase records and advertising statistics, which remain after the account is deleted, are kept without a link to it.
15Deleting Your Account
You can delete your account in the app settings at any time. Here is exactly what happens:
- the account is deactivated immediately and moves into an archive for 50 days;
- during those 50 days you can restore everything simply by signing in — nothing is lost;
- after 50 days a scheduled background process on our servers permanently deletes entries, transcripts, analysis, conversations, AI memory, audio files, photos, the avatar and all related records. This really happens, and it cannot be undone.
Deleting the account does not cancel a subscription bought through the App Store or Google Play. Cancel it in the subscription settings of your Apple ID or Google Play account, otherwise the store will keep charging you.
After deletion, only the following remains with us:
- records of purchases and payments — without a link to the account, for accounting and tax purposes and so that the same purchase cannot be credited twice;
- impersonal advertising statistics (Free plan) — impressions and taps without a link to the account;
- security logs of the service without diary content — for up to 180 days;
- technical server logs — until they are automatically overwritten;
- the minimum needed to defend against a legal claim.
Copies held by processors are deleted on their own schedules under our agreements with them.
Export anything you care about before deleting: once the archive period has passed, we cannot restore it.
16Security Incidents
We monitor the security of the service and keep our systems updated. If a personal data breach nevertheless occurs, we act as follows:
- we contain the incident and cut off further access;
- if the breach is likely to result in a risk to your rights, we notify the competent supervisory authority within 72 hours of becoming aware of it;
- if the risk is high, we also notify you directly — by email and in the app — explaining what happened, which data was affected and what we recommend you do;
- we document the incident and the measures taken.
Because entry content is stored encrypted with individual keys, gaining access to the storage alone does not reveal the text of your entries.
If you notice something suspicious in your account or find a vulnerability, write to amirich.corp@gmail.com — we treat such reports as a priority.
17Children's Privacy
Andesha is intended only for people aged 18 and over. We do not knowingly collect data about children and we offer neither a children's version nor a parental-consent mechanism.
If we discover that an account was created by a person under 18, we block it and delete the associated data.
If you believe a minor has created an account, or that we hold a child's data, write to amirich.corp@gmail.com — we will check and delete it.
18Cookies and Tracking
The Andesha mobile app does not use cookies and does not embed third-party analytics or advertising trackers that would follow you across other apps and websites.
Your signed-in session is maintained by access tokens kept in the secure storage of the operating system.
On the Free plan, Google's advertising module may store service data on the device, such as your choice in the consent form, and may use device identifiers (the advertising identifier and App Set ID on Android, IDFV on iOS) for impression counting and fraud prevention; see section 11 for details. The advertising itself stays non-personalised, and the app does not ask for tracking permission (App Tracking Transparency).
The web admin panel, which is used by our staff and not by users, relies only on strictly necessary session cookies.
19Your Rights in the United States
If you live in California, the CCPA as amended by the CPRA gives you the rights below. We extend the same rights to residents of every other US state with a comparable privacy law, and in practice to all our users:
- Right to know what categories of personal information we collect, why we collect them, and who receives them
- Right to access a copy of the personal information we hold about you
- Right to delete your personal information
- Right to correct inaccurate personal information
- Right to limit the use of sensitive personal information
- Right not to be discriminated against for exercising these rights: the price and quality of Andesha stay the same
We do not sell your personal information and we do not share it for cross-context behavioural advertising. Ads on the free plan are non-personalised.
Entries about mood and wellbeing are sensitive personal information. We use them only to provide the service you asked for and never to infer characteristics about you for advertising.
To exercise any of these rights write to amirich.corp@gmail.com. We answer within 45 days and may extend once by another 45 days when a request is complex, telling you why. You may authorise an agent to act for you; we will ask for proof of that authority.
20Changes to This Policy
We may update this Policy — for example when features, processors or legal requirements change. The current version and its date are shown at the beginning of the document.
We will notify you of material changes by email or in the app at least 14 days before they take effect. If a change concerns processing that requires consent, we will ask for your consent again rather than assume it.
Earlier versions are available on request at amirich.corp@gmail.com.
21Contact
Andesha, a service by Amirich LLC (New York, USA)
- Personal data and rights requests: amirich.corp@gmail.com
- General support: amirich.corp@gmail.com
- Website: https://amirich.org
We reply to privacy enquiries within 30 days.
You also have the right to lodge a complaint with the supervisory authority of your country.
Document version: 2026-09-13.