Privacy Policy β Eunomia
Version 1.10
Last updated: 2026-07-08
Overview
Eunomia is a personal reflection tool made by Joanna Bednarczyk, an independent developer based in Switzerland, operating under the trade name "Studio Volt" π¨π. The app is designed to help you organize your thoughts using a structured journaling method (the Padesky 7-column technique). The app is designed to keep your reflections on your device by default.
Eunomia is a personal reflection tool, not a substitute for professional mental health care. If you are in distress or crisis, please contact a qualified professional or local emergency services. The full target-audience disclaimer is in the Terms of Service.
This policy explains, in plain language, what data Eunomia handles, what stays on your device, what (if anything) leaves it, and the choices you have. If something here is unclear, write to contact@studiovolt.dev.
Short version: by default, your reflections, audio recordings, and transcripts are kept on your iPhone and are not transmitted to the developer. Cloud features are opt-in and off until you turn them on.
Who I am
Eunomia is developed and operated by Joanna Bednarczyk, an independent individual developer based in Switzerland, operating under the trade name "Studio Volt" ("I", "me", "the developer"). There is no corporate entity behind the app at this time. For privacy questions, including GDPR data subject requests, contact:
- Email: contact@studiovolt.dev
- Web: studiovolt.dev/privacy
If you are an EU/EEA resident, Joanna Bednarczyk (independent developer), Switzerland acts as the data controller for any limited information processed via the optional Cloud AI feature (described below). If the developer incorporates as Studio Volt GmbH or SA, that entity will assume the role of data controller; your non-waivable data-protection rights remain unaffected.
EU representative (GDPR Art. 27)
Eunomia is offered from Switzerland (outside the EU/EEA and the UK). Where the optional Cloud AI feature brings the developer's processing within the scope of Article 27 GDPR and Article 27 UK GDPR, any representative designated in the European Union or the United Kingdom will be identified here.
EU/EEA and UK residents can in any case exercise all of their data-protection rights and raise any GDPR or UK GDPR matter directly with the developer at contact@studiovolt.dev (subject line "GDPR"). Requests are handled in the same way regardless of where you live.
What is collected
On your device only (default behavior)
- Audio recordings of your reflections, saved as
.m4afiles in Eunomia's private app folder on your iPhone. - Transcripts generated by Apple's on-device speech recognition.
- Reflection entries (the 7-column structure: situation, mood, automatic thoughts, evidence, balanced thought, new mood, action) stored locally in the app's private storage on your device, protected by iOS device-level data protection where your device passcode is enabled.
- Preferences (language, haptics, AI assist toggle, etc.).
These items are stored on your iPhone. The developer does not receive, host, or back them up to any server the developer controls. If you delete the app or reset your iPhone, this on-device data is removed from the app's storage. (Whether copies persist in any device backup you have configured β for example an iCloud or local device backup you control β is governed by Apple's terms and your own backup settings, not by the developer.)
Information received when you opt in to Cloud AI
If β and only if β you turn on Cloud AI in Settings and confirm the consent screen, the text of the reflection you are working on is sent to a third-party AI provider to parse it into the 7-column structure. In that flow the following is received:
- An anonymous user ID (a random UUID generated on your device β not linked to your name, email, or Apple ID).
- Token usage counters (how many AI tokens your account has consumed in the current period). These are used to enforce fair-use limits on paid tiers.
- A device-integrity identifier provided by Apple's App Attest service, processed to confirm that requests come from a genuine, unmodified copy of the app and to prevent abuse. It is not linked to your identity or to the content of your reflections, and is retained only while the installation remains valid.
- Standard request metadata at the hosting provider (timestamp, request URL, response status, IP address) β access-log data used for security and abuse prevention. The contents of your reflections are not retained in these logs.
The audio file and your Apple ID are not received.
Purchase information
When you subscribe to a paid tier or buy a top-up, the transaction is processed entirely by Apple. The developer receives only an anonymized receipt indicating which tier is active. Your name, email, payment card, and billing address are never seen.
What is not collected
To be explicit, the following is not collected:
- Your name, email address, phone number, or Apple ID.
- Your location.
- Your contacts, calendar, photos, or any data outside of Eunomia.
- Cross-app or cross-site tracking identifiers.
- Advertising identifiers.
- Health data, biometric data, or any data from Apple HealthKit.
Eunomia does not include third-party advertising, analytics SDKs, or crash reporting in this version. If any of these are added in the future, this policy will be updated and consent will be requested where required.
How AI works in Eunomia
Short version: Cloud AI is OFF by default. Your reflections do not leave your iPhone unless you actively opt in. Under the AI provider's current API terms, reflection text sent to Cloud AI is not used to train its models.
Eunomia uses AI to turn your spoken or written reflections into the structured 7-column format. There are three possible AI paths, and you control which one is active.
1. Apple on-device AI (default on supported devices): on iPhones that support Apple Intelligence (iPhone 15 Pro and newer, iOS 18.1+), parsing happens entirely on your device using Apple's Foundation Models framework. Nothing leaves your iPhone. 2. Local mock parser (default on older devices): a simple rule-based parser that runs on your device and produces a draft you can edit by hand. Nothing leaves your iPhone. 3. Cloud AI (opt-in only): the text of the current reflection is temporarily sent to a third-party AI provider for richer parsing. You will see a clear consent screen the first time you enable this option, before any text is sent. Your reflection content is not retained by the developer beyond the time needed to return the result β only an anonymous token count is kept to enforce usage limits. Under the third-party provider's current API terms, API inputs are not used to train its models and are retained only for a limited period (typically up to 30 days) for abuse monitoring before deletion. Those provider terms are set by the provider and may change; the developer summarises them here in good faith but does not independently warrant the provider's processing.
You can switch Cloud AI off at any time in Settings β AI & Privacy. When it is off, no reflection text ever leaves your iPhone for AI processing.
A note on language coverage: Apple Intelligence supports a defined list of languages (English, German, French, Italian, Spanish, Portuguese, Japanese, Korean, Chinese, Dutch, Swedish, Danish, Norwegian, Turkish, Vietnamese, and others β see Apple's documentation). Polish is not currently supported by Apple Intelligence.
If your iPhone's speech language is one Apple Intelligence does not support, Cloud AI is the only path that can parse your reflections into the Padesky 7-column structure. For those languages, Cloud AI is required rather than optional β you'll be told this clearly during onboarding, given a 2-parse free trial, and you can decline. If you decline, parsing won't run; you can still record audio and read raw transcripts, but the structured fields stay empty until you fill them in by hand or enable Cloud AI in Settings β AI & Privacy.
On-device distress recognition
Eunomia may, on a best-effort basis and entirely on your device, recognise some words associated with distress and respond by showing crisis-resource information. This is a convenience feature, not a monitoring or safety system: it runs only on your device, is not relied upon to detect any crisis, and creates no record of any kind on, or sent to, any server. No "crisis flag" or health record about you is created, stored, or transmitted by the developer. The developer does not read or monitor your entries (see the Terms of Service, "No monitoring; no emergency service").
Speech recognition
Eunomia uses Apple's SFSpeechRecognizer with the on-device flag enabled. Transcription runs locally. Apple may retain limited diagnostic information about the speech engine itself under their own privacy policy; the developer has no access to it. See apple.com/legal/privacy for details.
Illinois residents β Biometric Information Privacy Act (BIPA) notice
For users in Illinois: Eunomia does not collect, capture, store, or use voiceprints, scans of face geometry, or any biometric identifier or biometric information as defined by the Illinois Biometric Information Privacy Act (740 ILCS 14/10). Speech-to-text transcription uses Apple's on-device SFSpeechRecognizer; the resulting text is not a voiceprint and is not used for identification. Audio recordings remain on your device unless you manually share them via the iOS Share sheet. No biometric data is sold, leased, traded, or otherwise disclosed.
Third parties (sub-processors)
The app relies on as few third parties as possible. Each is engaged under a written data-processing agreement restricting use of any personal data to the disclosed purpose:
- Apple Inc. (USA) and Apple Distribution International Ltd. (Ireland) β App Store distribution, in-app purchases, and on-device speech recognition and Apple Intelligence (where available). Subject to Apple's privacy policy.
- OpenAI, L.L.C. (USA) β when, and only when, you opt in to Cloud AI, the text of your reflection is processed by OpenAI to generate the structured output. Engaged under a data-processing agreement incorporating the European Commission's Standard Contractual Clauses (Decision 2021/914, Module 2: Controller-to-Processor), supplemented by technical and organisational measures. Under OpenAI's current API terms, API inputs are not used to train its models and are retained only for a limited period (typically up to 30 days) for abuse monitoring before deletion. These provider terms are set by the provider and may change.
- Cloudflare, Inc. (USA) β hosting and routing for Cloud AI requests, engaged under a data-processing agreement. Cloudflare keeps standard access logs (timestamp, URL, status, IP) but does not retain the content of forwarded requests beyond ephemeral transit. Engaged under a data-processing agreement incorporating the European Commission's Standard Contractual Clauses (Decision 2021/914), supplemented by technical and organisational measures.
Subscription purchases, receipts, and entitlements are handled by Apple (see the Apple entry above); the developer receives only an anonymized flag indicating which tier is active.
Your data is never sold or shared with anyone for advertising or marketing.
International transfers (GDPR Chapter V, Swiss revFADP Art. 16β19)
Personal data is transferred to the United States to the recipients listed above only when you opt in to Cloud AI. Transfers from the EEA, the UK, and Switzerland are made under the following safeguard:
- European Commission's Standard Contractual Clauses (Decision 2021/914, Module 2: Controller-to-Processor) β incorporated into the data-processing agreement with each US recipient (OpenAI, L.L.C. and Cloudflare, Inc.), supplemented by technical and organisational measures (encryption in transit, access controls, and the minimum-necessary data principle). For UK data subjects, the SCCs are read with the UK Information Commissioner's International Data Transfer Addendum; for Swiss data subjects, with the amendments recognised by the FDPIC.
Further information about the applicable data-processing terms and transfer safeguards is available on request to contact@studiovolt.dev.
Sub-processor change notice
If a sub-processor is added, replaced, or removed in a way that materially changes how your data is processed, this Privacy Policy will be updated and you will be notified in-app before the change takes effect.
Sharing your entries (outbound disclosures)
Eunomia includes a Share affordance on individual entries and on the History screen. When you tap Share, Eunomia hands the content of the selected entry or period to the native iOS Share sheet, which then routes it to whichever destination app you pick (Messages, Mail, Notes, a third-party app, etc.).
Once content leaves the iOS Share sheet:
- You become the data controller for that outbound disclosure under GDPR Art 4(7) / Swiss revFADP. The recipient and the channel are entirely your choice.
- Eunomia does not see, log, or transmit the recipient address, the destination app, or whether the share completed.
- Eunomia has no control over what the receiving party does with the content. If you share with a third party (friend, family member, mental-health professional, etc.), the terms of that disclosure are between you and them.
- Standard iOS Share sheet behaviour applies β Apple's privacy policy governs the sheet itself.
The very first time you use the Share affordance, Eunomia shows a confirmation modal so this is clear before any disclosure happens.
Data retention
- On-device data (audio, transcripts, entries) stays on your iPhone until you delete it. You can delete an individual entry from the History screen, or all data by uninstalling the app.
- Cloud AI usage counters (anonymous UUID + token totals): kept only for as long as needed to enforce usage limits, then deleted automatically. They are not linked to your identity.
- Cloudflare access logs: retained for a short period per Cloudflare's standard policy, then deleted.
- AI provider logs (if you used Cloud AI): up to 30 days, per the provider's API policy, then deleted.
Your rights
If you are in the EU/EEA, UK, or Switzerland (GDPR)
You have the right to:
- access the data held about you,
- ask the developer to correct it,
- ask the developer to delete it (right to erasure),
- object to or restrict processing,
- request a copy in a portable format,
- withdraw consent for Cloud AI at any time, and
- complain to a supervisory authority (in Switzerland: the FDPIC; in your EU country, your national DPA).
Lawful basis for processing. On-device data is processed based on the legitimate interest of providing the app you installed. Cloud AI inputs are processed based on your explicit consent. Anonymous usage counters are processed on the basis of legitimate interest in operating the service fairly.
Because the data received is not linked to your real identity, in most cases the most effective way to exercise these rights is to delete the app (which removes your local data) and stop using Cloud AI (which stops new server-side data). To raise a formal request, write to contact@studiovolt.dev.
If you are in Switzerland (revFADP / nFADP, in force September 2023)
Under the revised Swiss Federal Act on Data Protection, you have the right of access (Art. 25), correction (Art. 32(1)), deletion (Art. 32(2)), and to object to processing. The Swiss supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC / EDΓB) β edoeb.admin.ch. Cross-border transfers of personal data to the United States (the Cloud AI providers, OpenAI and Cloudflare) are made under EU Standard Contractual Clauses with the amendments recognised by the FDPIC, supplemented with technical and organisational measures.
If you are in California (CCPA / CPRA)
In the prior 12 months, the categories of personal information collected (only if Cloud AI is enabled) are: Identifiers (a random UUID generated on your device) and Customer Content / Other Information (the text of the reflection you submit for AI parsing). Sources: directly from your device. Business purpose: providing the AI parsing feature you requested (Cal. Civ. Code Β§1798.140(e)(1)). Disclosed to: the Cloud AI provider and Cloudflare as service providers under written contract restricting use to the disclosed purpose.
The developer does not and has not in the prior 12 months: sold personal information, shared personal information for cross-context behavioral advertising, or processed sensitive personal information for purposes beyond those permitted under Β§1798.121(a). You have the right to know, delete, correct, and limit; to exercise, email contact@studiovolt.dev. You will not be discriminated against for exercising these rights.
Children under 13 (COPPA / GDPR Art. 8)
Eunomia is not directed to children under 13 and does not knowingly collect personal information from children under 13 (COPPA, 15 U.S.C. Β§6501) or from children under 16 in EU Member States applying the higher age (GDPR Art. 8). The App Store age rating of 4+ reflects content classification only; the intended audience is 17+ per the Terms of Service. If you believe a child under 13 has provided information, contact contact@studiovolt.dev for prompt deletion.
Children (general)
Eunomia is intended for users aged 17 and older, consistent with the Terms of Service target-audience exclusion. Information from minors below that age is not knowingly collected. If you believe a minor has used the app, please contact contact@studiovolt.dev.
Changes to this policy
If material changes are made, the version number will be updated, the "last updated" date will change, and you will be notified in-app before the change takes effect. Older versions will be archived at studiovolt.dev/privacy/archive.
Contact
- General: contact@studiovolt.dev
- Privacy & GDPR: contact@studiovolt.dev
- Web: studiovolt.dev
Appendix: Apple App Privacy Labels mapping
This appendix is for transparency about what is declared in App Store Connect. See APP_STORE_PRIVACY_LABELS.md in the repository for the full mapping. In summary:
- Default app (Cloud AI off): no data is collected from the device.
- Cloud AI on: User Content (Other User Content) and Identifiers (User ID β anonymous) are collected, not linked to identity, and not used for tracking.
- Purchases: handled by Apple; not collected beyond an anonymized tier flag.