This Privacy Policy describes how invoq (“we”, “us”) collects, uses, shares, and protects your personal data when you use the invoq iOS app and this website (together, the “Service”). It applies to users in the European Union, the United Kingdom, the EEA, Switzerland, California, and globally to the extent local law applies.
If anything here is unclear, write to hello@magentic.nl.
1. Who we are
Data controller: Magentic BV, Ruyschstraat 77-2, 1091BX Amsterdam, the Netherlands. KvK registration number: 99971879.
If you are in the EU/EEA and have a complaint we have not resolved, you have the right to lodge it with your national Data Protection Authority.
2. What data we collect, and why
2.1 Account data
- Apple ID identifier and (optionally) name + email received via Sign in with Apple. Used to create and authenticate your account. An account is only created when you sign in — your onboarding answers stay on your device until then. Lawful basis: contract performance.
2.2 Practice data
- Onboarding answers: goal, scene, identity, obstacle, plan, action pattern, aesthetic preference, voice preference, morning time. Provided by you. Used to generate your daily visualisation script.
- Commitments / completions you record in the app. Used to feed the next day’s script with context. Lawful basis: contract performance.
2.3 Generated content
- Daily script (text) generated by Anthropic on our behalf.
- Daily audio (MP3) generated by ElevenLabs on our behalf, then stored in a private Supabase Storage bucket. Lawful basis: contract performance + explicit consent for AI processing (see §3).
2.4 Subscription data
- Receipt and entitlement state received from Apple via RevenueCat. We do not see your card number — Apple processes payment. Lawful basis: contract performance, legal obligation (tax).
2.5 Device data
- Timezone (read locally, never your location).
- iOS version, device model via Expo when you install the app.
- App update checks. Each time the app starts, it asks Expo’s update service whether a newer version of the app’s own code is available, and downloads it if so. This request carries your IP address, iOS version, the app version, the ID of the update currently running, and a random ID created when the app is installed (it resets if you reinstall). If the app crashed the last time it started, the request also carries that error message, so a faulty update can be rolled back. It contains no account data and is not used to identify you. Lawful basis: legitimate interest in delivering fixes and improvements to the app.
- App version, build number and update ID, attached to the usage events in §2.6, so we can tell which version of the app an event came from.
- Crash logs and diagnostic data if you opt in via iOS Settings → Privacy & Security → Analytics. Lawful basis: legitimate interest in keeping the app working.
2.6 Product analytics (first-party)
- Usage events — for example that you played a session, recorded a commitment, or completed onboarding — with a timestamp, linked to your account. We collect these ourselves in our own database (Supabase); no third-party analytics or advertising SDK is embedded in the app. Used to understand how the app is used, improve it, and personalize your experience. Not shared with anyone, not used for advertising, and never used to track you across other companies’ apps or websites. Deleted with your account. Lawful basis: legitimate interest in improving the Service.
- Before you sign in, we record the same kind of usage events — for example that the app was opened, or which onboarding step you reached — under a random ID created by the app on your device. It is not your Apple ID, not an advertising or device identifier, and it resets if you reinstall the app. These events contain no onboarding answers (those stay on your device until you sign in, see §2.1). If you sign in, the events are also linked to your account and deleted with it. If you never sign in, they are never linked to an account or to your name, email or Apple ID. Lawful basis: legitimate interest in understanding where people stop before creating an account.
2.7 What we never collect
- Your photos. invoq never reads or browses your photo library and never uses your camera. It only adds a card to your Photos when you tap Save, with your permission.
- Your location.
- Contacts, calendar, microphone, or any other system data.
- Identifiers from your Apple ID beyond the one Apple gives us during sign-in.
2.8 What you should not put in
invoq is designed for goals you can control — a habit, a pattern, a way of being. The free-text fields (identity, obstacle, plan) are not the right place for health, medical, clinical, religious, political, or other sensitive personal information. Please do not enter that kind of information. If something you’re working through is medical or clinical in nature, share it with a qualified professional instead.
3. AI processing: what is sent, and to whom
To generate your daily visualisation, we send the following to our AI sub-processors:
| Sub-processor | Purpose | What we send |
|---|---|---|
| Anthropic, PBC (Claude API) | Write a short (roughly 3-minute) daily script tailored to your answers | The non-personal text of your goal, scene, identity, obstacle, plan, action pattern, aesthetic preference, voice preference, and recent commitments. Never your name, email, Apple ID, photos, or device identifiers. |
| ElevenLabs Inc. (Text-to-speech) | Convert the script into spoken audio | The script text (above) and your chosen voice label. Never your name, email, Apple ID, photos, or device identifiers. |
| OpenAI, L.L.C. (Image generation) | Paint the background image for your affirmation card — subscribers only, once per goal | A short image brief written by Claude from your goal and scene — for example the light and architecture of a city you named. It is a description of a place, not your own words, and carries no account identifier. Never your name, email, Apple ID, photos, or device identifiers. |
This processing happens only after you have explicitly accepted the in-app AI Processing consent screen. You can withdraw consent at any time in Settings → Privacy → AI processing. Withdrawal stops the generation of new sessions; sessions already generated remain available on your device.
Lawful basis: explicit consent (GDPR Art. 6(1)(a) and Art. 9 where applicable).
4. Other sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| Apple Inc. | Sign in with Apple identity tokens, in-app payments | US / EU |
| Supabase Inc. | Authentication, database, audio file storage | EU — Ireland (eu-west-1) |
| RevenueCat Inc. | Subscription lifecycle and receipt validation | US |
| Anthropic, PBC | AI script generation | US |
| ElevenLabs Inc. | Text-to-speech | US |
| OpenAI, L.L.C. | Affirmation card image generation (subscribers) | US |
| Expo (650 Industries, Inc.) | Delivering app updates | US |
| Netlify, Inc. | Marketing website hosting | EU / Global edge |
| Google LLC | Google Analytics 4 (consent-gated, IP anonymised) | US |
We have a Data Processing Agreement (DPA) with each sub-processor, either signed or included in their terms of service, that requires GDPR-compliant safeguards. International transfers rely on the EU Standard Contractual Clauses (SCCs).
5. How long we keep your data
- Account, onboarding, goals: until you delete your account.
- Daily sessions (text + audio): until you delete your account.
- Usage events linked to your account (§2.6): until you delete your account.
- Usage events recorded before sign-in (§2.6): automatically deleted after 90 days. Copies linked to your account (if you signed in) follow the rule above.
- Subscription receipts: retained 7 years after expiration for tax compliance.
- Backups: rolling 30-day window. A deleted account is removed from backups within 30 days.
6. Your rights
You have the right to:
- Access a copy of your data — via Settings → Privacy → Download my data, or by writing to the address above.
- Rectification — edit your onboarding answers in Settings.
- Erasure — via Settings → Account → Delete account. When you delete your account we remove your data from our database and storage, and request deletion from our sub-processors on your behalf within 30 days (GDPR Art. 19).
- Portability — your export is a standard JSON file.
- Restriction (Art. 18) or objection (Art. 21) — you can pause AI processing for your account at any time via Settings → Privacy → AI processing. For other restrictions or objections, write to us at the address above.
- Withdraw consent at any time — via Settings → Privacy → AI processing.
- Lodge a complaint with your national Data Protection Authority.
We respond to requests within 30 days.
7. Children
invoq is for users aged 16 and over, and is not directed to children. If we learn we have collected data from anyone under 16, we will delete it immediately.
8. Security
Audio files are stored in a private bucket with row-level security. Auth tokens are stored in iOS Keychain via expo-secure-store. All network traffic uses TLS.
8.1 Breach notification
If we become aware of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority within 72 hours of becoming aware of it (GDPR Art. 33). Where the breach is likely to result in a high risk to you, we will also notify you without undue delay (GDPR Art. 34).
9. Changes to this policy
We will update the Last updated date above when the policy changes. If a change materially affects how we use your personal data, we will tell you in the app or by email before it takes effect.
10. Contact
hello@magentic.nl
Magentic BV
Ruyschstraat 77-2
1091BX Amsterdam
The Netherlands