Duskline / legal

Privacy Policy

Duskline · Last updated 2026-07-17

Operator: Guy Levi (the "Operator"), operating the Duskline app. Contact: noumenon.aii@gmail.com.

Duskline is not therapy, diagnosis, medical advice, crisis support, or a substitute for professional care. If you may hurt yourself or someone else, contact local emergency services or a crisis hotline now.

Personal data handled by Duskline includes nightly entries, thoughts, an optional assessment, derived profile, subscription status, account email when you sign in, authentication identifiers, an encrypted local account-to-journal binding, local reminder and first-run settings, practice-completion dates, coach-consent preference, and cart or custom-product records. Duskline schedules local notifications and does not request or store an Expo push token.

Nightly entries include mood, cleared thought, lesson, tomorrow focus, focus outcome, and timestamps. Thoughts include text, source, and timestamp. The derived profile contains display name, theme words, mentioned people, pressure words, goal words, preferred tone, and update time. Subscription status contains entitlement and purchase-state information.

Nightly entries, thoughts, assessment, derived profile, seed thought, and account-to-journal binding are encrypted at rest on your device. Reminder settings, first-run state, practice completion, coach consent, cart state, and other non-journal preferences are stored locally but are not encrypted by Duskline. The current app does not upload, remotely store, or sync your journal. When you explicitly enable and invoke the AI coach, the selected context described below is transmitted for that request.

Sub-processors: Supabase for optional account sign-in, account deletion, coach request authorization and rate limiting, and running the AI coach Edge Function; GroqCloud for AI coach generation using the Groq-hosted open-weight openai/gpt-oss-120b model; RevenueCat for subscription entitlement; Apple App Store and Google Play for store billing and refunds. OpenAI developed the model weights but does not receive Duskline's API requests in this integration.

Legal bases for processing: contract performance to run the app, account, export, and billing features; consent where you opt in to sign-in, local notifications, and the AI coach; legitimate interests for security, abuse prevention, rate limiting, reliability, and debugging without personal journal text in logs; legal obligation for tax, accounting, chargeback, and compliance records tied to purchases.

For a nightly coach reflection, GroqCloud may receive the current entry, up to eight recent non-crisis entries, and up to six recent non-crisis thoughts. For a milestone report, GroqCloud may receive up to thirty selected non-crisis entries, up to fifteen recent non-crisis thoughts, and only theme, pressure, goal, and tone fields from the derived profile; display name and mentioned-people fields are excluded. Requests require sign-in, an active Plus entitlement, current Groq-specific coach consent, and server verification that Groq Zero Data Retention is enabled. Crisis-flagged entries do not invoke the coach, and crisis-flagged thoughts are never sent.

Retention: local data remains until you delete it, clear app data, or uninstall. Duskline application code does not persist coach request text on its servers. With the required Zero Data Retention setting, Groq says it does not persist customer inputs or outputs for reliability or abuse monitoring; Groq always retains content-free usage metadata. Groq automatically uses organization-isolated prompt caching for this model in volatile memory; cached prompt data cannot be manually disabled and expires after about two hours without use. Supabase retains content-free coach quota counters until they roll forward or the account is deleted. Any encrypted journal rows from a dormant pre-production sync implementation are blocked from client access and must receive an owner-approved export, deletion, or documented retention disposition before production launch. RevenueCat, Apple, and Google retain billing records under their legal and platform rules.

Your rights: access, delete, export, and rectify your personal data. The in-app export is a versioned archive of local journal, profile, progress, consent and reminder settings, cart, and local account-binding data; processor-held account and billing records are not included in that local file and may be requested through the support contact above. You may also object, restrict processing, withdraw consent where processing depends on consent, and opt out of sale or sharing where those rights apply. The Operator does not sell personal data.

Deletion: when signed out, Delete this device's journal purges Duskline local data, scheduled reminders, temporary export residue, the local account binding, and vault key from the device. When signed in, Delete account and data first requires recent password reauthentication, deletes the authenticated Supabase account and associated Duskline server rows, then performs the same local purge and signs out. Duskline reports when reminder or temporary-file cleanup cannot be verified. Account deletion does not cancel an App Store or Google Play subscription; cancel it in the applicable store to stop future billing. Billing records may remain with RevenueCat, Apple, and Google where law or platform rules require it.

Security: your local records are encrypted at rest on the device, account sign-in uses standard authenticated access, and the Groq API key is kept server-side in a Supabase Edge Function secret, never in the app. A coach-provider change invalidates previously stored provider consent and requires a new opt-in.

Children: Duskline is not intended for children under 13 or the minimum age required by local law.