← Selfwise

Privacy Policy

Beh.Dev · Last updated 24 August 2026

Selfwise is operated by Beh.Dev. It is built so that the most personal thing in it — your answers, your goals, your journal — never leaves your device in a form anyone else can read. Two optional features, both off until you switch them on, are the only things that send anything at all: cross-device sync, which uploads a copy we cannot decrypt, and contributing to a reference set. This page explains exactly what that means, and what the exceptions are.

The short version

  • Your questionnaire answers, compass scores, goals, tasks and journal entries are stored in your browser. We do not have a copy, unless you switch on the reference-set contribution described below — which is off unless you turn it on.
  • You can use the whole app without an account, an email address, or a payment.
  • We collect an email address only if you give us one — for the waiting list, or to buy a subscription.
  • We do not sell data, we do not run advertising, and we do not use third-party trackers.

What is stored on your device

Everything you enter lives in your browser’s local storage as a “vault”: item responses, compass snapshots, goals, tasks, journal entries, and any API key you choose to add. In anonymous mode this is stored unencrypted, which means anyone with access to your browser profile can read it. If you connect a wallet, the vault is encrypted with a key derived from your signature, and we never see that key.

Because it is local: clearing your browser data deletes it, and we cannot recover it for you. Use Export in the Data panel to keep a copy.

What reaches our servers

If you join the waiting list

We store the email address you typed and which page you typed it on. Nothing else.

Anonymous usage measurement

To know whether the product works, we count how many people reach each step (opened the page, answered a question, signed up). Each event is exactly three fields: a step name, a random identifier that exists only for that browser tab and is never stored on your device, and a timestamp. There are no cookies, no persistent identifier, and no third-party analytics service. We cannot link two visits to the same person, and we do not try to.

If you subscribe

Payment is handled by Stripe. We never see or store your card details. We store the email address Stripe reports, your Stripe customer and subscription identifiers, and a licence key. That is what lets us restore your key if you lose it, and let you cancel.

If you use the AI companion

Your message and the relevant part of your compass are sent to Anthropic to generate a reply, through our server. We record only the number of messages you have sent this month, so the included allowance can be enforced. We do not store your message, the reply, or any part of either. Anthropic processes the request under their own terms: API content is not used to train their models, and is retained by them only for a limited period (typically up to 30 days) for abuse monitoring before deletion.

If you supply your own Anthropic API key instead, your browser talks to Anthropic directly and the request never touches our servers at all.

If the companion speaks

To produce a voice, the text of the reply is sent to OpenAI through our server and audio comes back. We record only the number of characters spoken, so the speech allowance can be enforced. Neither the text nor the audio is stored by us. OpenAI processes the request under their API terms: API content is not used to train their models and is retained by them only for a limited period (typically up to 30 days) for abuse monitoring. The same applies to voice clips sent for transcription.

If you talk to the companion

Speaking uses your browser’s own speech recognition. In most browsers — including Chrome and Edge — this sends the audio of your voice to the browser vendor’s servers (Google, in Chrome’s case) to be turned into text. That happens between your browser and them: it does not pass through us, we never receive the audio, and we cannot see or store it. It is also governed by their privacy policy, not ours.

We are telling you because it is the most sensitive thing the app touches and the one part we do not control. If you would rather no audio left your device, use the companion in text mode — the “Type instead” option beneath the controls. Typing never activates the microphone.

Your journal

Journal entries stay in your browser and are not sent anywhere by default — not to us, and not to the companion.

There is one switch, in the Journal panel, that lets the companion read your five most recent entries so it can suggest things to do. It is off unless you turn it on. While it is on, those entries are sent to Anthropic with your message, exactly like the rest of the conversation, and are not stored by us. Turning it off stops it immediately.

The weekly check-in (optional)

Both reminder channels are strictly opt-in and independent of everything else here.

Notifications: if you enable them, your browser gives us a push endpoint — a URL that lets us ring that one browser and nothing more. It identifies no person and links to nothing else we hold. Turning notifications off deletes it; endpoints the push service reports dead are pruned automatically.

Timed reminders: if you set a reminder for a particular time, your device sends us that time and a random id, so we know when to ring your browser. We are not told what the reminder is about. The words you see come from your own device, which keeps them; the notification is a doorbell, not a letter. Your timezone and any repeat pattern stay on your device too — it works out the individual moments itself and sends only those, so we hold a list of alarm times and cannot reconstruct the schedule behind them. Each entry is deleted the moment it is used, and turning notifications off deletes any still waiting.

Email: if you enter an address, we store it as pending and send one confirmation mail. Nothing is ever sent unless you click the link in it (double opt-in), and every reminder afterwards carries a one-click unsubscribe that deletes the address outright.

The free trial

Trying the companion without paying needs some way to count your free turns, and we have no accounts and no IP logs to count against. So the server issues a random token — it identifies nothing about you, is not derived from your device, browser or address, and cannot be linked to any other token. Your browser keeps it, and we store it alongside a count of the turns used.

The honest consequence: clearing your browser data discards the token and earns a fresh trial. We know, and we have chosen this rather than fingerprinting you to prevent it.

Sync across devices (optional, off by default)

Sync exists so your journal and goals can follow you from a phone to a laptop. It is the only feature that stores your content on our servers, and it does nothing until you turn it on in the Data tab.

What we hold. One encrypted blob and one handle. The blob is encrypted with AES-GCM-256 on your device before it is sent. The handle is what tells us which blob is yours; it is derived from your sync key through a one-way function, and it cannot be turned back into that key.

What we cannot do. Read it. The encryption key is derived from a sync key that is generated on your device, shown to you once, and never transmitted. We considered deriving it from your licence key instead, which would have spared you a second secret — and rejected that, because we store licence keys, so we would then be able to decrypt every journal on the service while this page claimed otherwise. There is no recovery path, for us or for you: if you lose the sync key, the data on our server is permanently unreadable.

What is excluded. Your licence key, your own API keys, and your trial token are never included in the blob. They stay on each device.

What we do not link it to. The handle is not stored alongside your licence, your email, or any identifier. If you hold a subscription your licence key is sent with an upload so we can apply the larger size limit, and it is discarded once that check is done — it is not written next to the blob. We log no IP address against it.

Deleting it. “Turn off and delete from server” in the Data tab issues a real deletion of the row, not a flag. Sync data is also removed after twelve months without a single sync, since a blob nobody can open and nobody is using is a liability rather than a service.

Legal basis. Consent under Art. 6(1)(a) GDPR, given by switching it on and withdrawn by switching it off, which also deletes the stored copy.

Contributing to a reference set (optional, off by default)

The compass reports a score but cannot say where that score sits compared to anyone else, because we have no reference data. Building that reference set is only possible if people choose to contribute to it. In the Data panel you can turn this on. It is off until you do, nothing else switches it on, and the app works identically either way.

What is sent when it is on: your answers to the questionnaire items, the axis scores computed from them, how much of each bank you have answered, the language you answered in, and two numbers — how many tasks you have created and how many you have marked done.

What is never sent: your journal entries, your conversations with the companion, the titles of your tasks, your goals, your email address, or your licence key. Nor your IP address, which our servers do not store for any purpose.

Pseudonymous, not anonymous. A random identifier is generated on your device and sent with the answers. It is stored only in your vault, and we hold nothing that connects it to your name, email or subscription. It exists for one reason: so that if you change your mind we can find exactly your contribution and delete it. We use the word pseudonymous because an identifier that makes deletion possible also makes the records linkable to each other, and calling that “anonymous” would overstate it.

Withdrawing. Turning the setting off sends a deletion request and removes the records. If that request fails, the setting stays on and tells you so, rather than showing you an off switch while the data is still here. Legal basis is your consent under Art. 6(1)(a) GDPR, which you may withdraw at any time under Art. 7(3).

What we deliberately do not collect

Our servers can see your IP address, browser, and country on every request, as any web server can. We do not write any of it down. There is no visitor log, no device fingerprint, and no profile built from your behaviour. Our hosting providers (Cloudflare) keep their own short-lived operational logs, which is outside our control and true of any website.

Your rights

Beh.Dev is established in Germany, so the GDPR (DSGVO) applies directly and we are the controller (Verantwortlicher) for the data described here. You may request a copy of the personal data we hold, ask us to correct or delete it, restrict or object to its processing, and receive it in a portable form. In practice we hold very little: an email address, and subscription identifiers. Write to privacy@selfwise.space and we will action it within 30 days. Deleting your account data does not delete the vault on your device — use Clear in the Data panel for that.

You also have the right to complain to a supervisory authority (Aufsichtsbehörde). In Germany that is the data-protection authority of the federal state in which we are established; you may also contact the authority where you live.

Legal bases (Art. 6 DSGVO): performing our contract with you for subscription and companion processing (Art. 6(1)(b)); your consent for the waiting list (Art. 6(1)(a), withdrawable at any time); and our legitimate interest in knowing whether the product works, for the anonymous step counts (Art. 6(1)(f)).

Retention

  • Waiting-list emails: until you ask us to remove them, or launch.
  • Usage counters: the current and previous month, then deleted.
  • Reference-set contributions: kept until you withdraw them. Because they carry no identity beyond a random id, we cannot expire them on your behalf — the switch in the Data panel is the control.
  • Subscription records: for as long as the subscription is active, plus the period tax law requires us to keep invoices.

Children

Selfwise is not intended for people under 16 and we do not knowingly collect their data.

Not a medical service

Selfwise is a self-reflection tool. It is not a medical device, it does not diagnose anything, and it is not a substitute for professional help. If you are struggling, please talk to a doctor or a local support service.

Changes

If we change what we collect, we will change this page and update the date at the top. Material changes will be announced in the app.

Contact

privacy@selfwise.space

© 2026 Beh.Dev — Selfwise. All rights reserved.
Legal & support