What this knows about you.
Last updated 2 Sep 2026
You talk to this about your drinking, your sleep, and the work you are avoiding. That is about as personal as data gets, so this page is written to be read rather than to be survived. The short version: it is a one-person company and that person can read what you write, another company in the United States runs the model and sees your messages, and you can take everything out or delete all of it without asking anyone.
Who holds this
Forvel is run by HERRMANN & Synové s.r.o., Blodkova 1280/8, 130 00 Praha 3, Czech Republic. Written to at matyasherrmann@gmail.com.
That is a company, and it is also one person. Nobody is employed here, there is no team and no support desk: the same person writes it, runs the server, and can read what you write. The company is who holds the data in law. The person is who can actually see it. That is the most important sentence on this page, so it is near the top rather than near the bottom.
Controller under Article 4(7) GDPR. No data protection officer is appointed: Article 37 requires one where special-category processing is a core activity carried out on a large scale, and this is not large scale. Write to the address above instead.
What it holds
Everything, in one list:
- Your account. Your email, the name you chose, and your timezone. If you set a password, what is stored is a scrypt hash of it, never the password. If you used Google, what is stored is your email and the account identifier Google gives us — never a Google password, and nothing else from your Google account.
- Your conversations. Everything you type to the coach, and everything it says back.
- What the coach worked out. Your commitments, what you said was in the way, sentences of yours it is allowed to quote back, and a rolling written summary of you it re-writes after every sitting.
- Your check-ins and readings. A mood, once a day. Eight areas of your life rated one to ten, re-taken each quarter.
- A sleep-risk reading. Worked out by the system from what you say, kept on your record, and never shown to you. See why we may hold this — it is the clearest example of the kind of data that section is about.
- How you used it. When each sitting happened, how many messages were in it, which model answered, and whether a reply was refused by the safety check.
Article 13(1)(c): the purpose is providing the coaching you signed up for, and the legal basis for the ordinary categories above is Article 6(1)(b), performance of a contract. Article 13(2)(e): all of it is necessary to provide the service. There is no optional field — nothing here is collected that the coach does not read.
A company in the United States reads your messages
The coach is not ours. Every message you send is passed to Novita AI, a company headquartered in the United States, which runs the model and sends the reply back. They can see what you wrote.
What does not go with it: your name, your email, your account number. The instructions call you “the user”. What does go with it, besides your words: today’s date, and the list of crisis helplines for your country — which means the request implies roughly where you are. We are not going to call that anonymous. It is your own words about your own life, and words like that identify a person whatever name is attached.
Novita’s published terms say they will not use what we send them to train their models, and will not log it for a human to read. Their terms do not say how long they keep it, and they publish no zero-retention option, so we cannot tell you a number. We have asked them. When there is an answer, it will be on this page.
Article 13(1)(e): recipient, acting as a processor. Article 13(1)(f): this is a transfer to a third country. Novita states that it relies on Standard Contractual Clauses and the EU–US Data Privacy Framework where applicable. We hold no data-residency commitment from them and no guarantee that inference runs inside the EEA. If that is not acceptable to you, the honest answer is not to use this.
Stripe handles the money, and sees only the money
If you start a subscription, Stripe takes the payment. Your card number goes straight to them through a frame they serve on the page — it is never in this website’s code and never touches our machine. We could not tell you your card number if you asked.
What we send them: your email address, so they can send you a receipt, and an account number that means nothing outside our database. What they send back: whether you are paid up and until when. That is the whole exchange. Nothing you have written to the coach, none of your readings, and nothing about what you use it for goes anywhere near them.
Stripe keeps its own record of the payment, as any payment company must, and their privacy policy governs that half. If you cancel, we keep the fact that a subscription ended and the date; the card details were never ours to keep.
Article 13(1)(e): recipient, acting as a processor for payment. Stripe Payments Europe is established in Ireland and the arrangement is governed by their Data Processing Agreement; onward transfer to Stripe, Inc. in the United States relies on Standard Contractual Clauses. Article 6(1)(b), performance of a contract — you cannot be charged for a thing without a payment processor, and Article 6(1)(c) for the invoice records tax law requires us to keep.
If you have an account we send you two emails, and a third company puts them in your inbox
One when you sign up, to check the address works. One if you ask to reset your password. That is the whole of what an account receives: no newsletter, no product update and no “we miss you”.
There is one other thing we send, and nobody receives it without asking twice. If you gave us an address for What survives, you get that document and a note when one of its rows changes. Nothing at all is sent until you confirm from the first email, and we keep the sentence you agreed to rather than a tick, because the point of a consent record is being able to show what you actually saw.
That list and your account are separate tables and an address never moves between them. Giving us one does not put you on the other, and leaving one does nothing to the other. Every email from the list carries an unsubscribe link that works in one press, without signing in and without being asked why. Your mail app may show its own unsubscribe button beside our name; that one works too, and it reaches the same place.
They all go out through Resend, which sees your email address and the text of the message. It does not see anything else about you: not your name, not a word you have written to the coach, not whether you have an account — the reset email is worded so that it says nothing either way.
They are an American company and we send through their Irish region, so the email itself is handled inside the EU rather than crossing the Atlantic. We are not going to tell you that means no American ever sees it: their staff can reach their own systems to support them, and that is covered by Standard Contractual Clauses rather than by geography. It is a smaller claim than “your data stays in Europe” and it is the true one.
The two account emails are plain text, deliberately. An HTML email carries a tracking pixel at almost every provider that offers one, and we would rather not be able to tell whether you opened something than promise we did not look.
What survives is laid out rather than plain, because a document with citations in it is easier to read that way. The same promise holds and it is switched off rather than sworn to: open tracking and link rewriting are turned off on the domain those are sent from, so there is no pixel in one and no link in one is redirected through us. You do not have to take that on faith — view the source of any of them and look.
Article 13(1)(e): recipient, acting as a processor. Article 13(1)(f) is not engaged by the send itself, which stays in the EEA; Standard Contractual Clauses cover the administrative access described above. Article 6(1)(b) — an account you cannot get back into is not an account we have delivered.
Your voice stays on this machine. The words you send do not.
The check-in and the open coach have a microphone button. Nothing listens until you press it, and your browser is the thing that asks for permission, not us. While it is recording, your browser shows its own indicator — that indicator is the truth, not anything on this page.
The audio goes to our own server and no further. One program on that same machine turns it into text, writing the words as you speak so you can watch them arrive. It is not a service. It is not a company. No recording of your voice is sent to Novita, or to anyone else, ever.
There is nothing to keep. Your speech is turned into text as you say it, a fraction of a second at a time, and each fragment is gone the moment its words exist — so a recording is never assembled in the first place. Nothing is written to a disk, to the database, or to a log, and the microphone stops itself after two minutes at the outside. There is no recording to hand over, because one is never made.
Here is the part that matters most, and it is the part people get wrong. The text lands in the box for you to read and change. Nothing is sent until you send it. And once you do, it is a message like any other — which means it goes to Novita and is kept exactly like a message you typed. Speaking instead of typing keeps your voice private. It does not make what you said private.
Article 13(1)(c): the purpose is turning speech into a message you then choose to send. Article 5(1)(e): storage limitation is met by not storing it at all. Article 9 applies to what you say, not to the fact you said it aloud — voice here is a way of typing, not a biometric. Nothing identifies you from the sound of your voice, and no voiceprint, speaker model or embedding is derived, stored or compared.
Why we are allowed to hold the sensitive part
Some of this is what the law calls special-category data — anything about your health. Conversations about drinking, sleep and mood land there, and two things we store are in that category whether or not you ever discuss health directly: your daily mood check-in, and the sleep-risk reading the system works out and keeps.
That last one is worth being plain about. It is not something you told us. The system reads what you say, decides whether your sleep sounds like something a doctor should look at, and writes the answer to your record. You are never shown it. It still exists, so this page names it.
The basis for holding any of that is your explicit consent, given as its own tick when you signed up — not buried in accepting the terms. You can take it back, and taking it back is deleting the account, because the coach cannot run without it.
Article 9(2)(a). No other condition in Article 9(2) fits: (h) requires a health professional bound by an obligation of secrecy, and there is not one here. Withdrawal under Article 7(3) does not affect the lawfulness of anything done before it.
What the encryption does, and what it does not
Twenty-one columns holding your own words are encrypted with AES-256-GCM before they reach the database — the coach’s written memory of you, what it has stopped asking you about, your commitments, what you named as the obstacle, the sentences it is allowed to quote back, anything you write to us on a report form, any time you tell us the coach has you wrong, any time you tell it no, the words any sealed claim about you was built out of, and anything you work out for yourself on a grid.
One fact about a sealed claim does leave, and it is a count. When a claim opens, whether it held or turned out wrong becomes one tally mark in a public figure at how often we are wrong, added to everybody else’s. What the claim said, what it was measured against, whose it was and when it opened do not go anywhere. The breakdown is withheld entirely until ten claims under the same template have opened, because with fewer than that a rate is one person’s fortnight to anybody who knows how few people are here.
A twenty-second column is sealed the same way and is not your words at all: the secret behind your two-factor codes, if you have turned those on. It is a key rather than a sentence, and it is in the same envelope for the same reason — a copy of the database that leaves this machine should not carry the thing that stands between a stolen password and your account.
The key sits on the same machine as the database, because the server has to decrypt a transcript to build the next reply. So this protects a stolen disk, a snapshot taken by the hosting provider, a database dump that leaves the machine, and ransomware. It does not protect against someone who is actually inside the server, because whoever controls that process controls the key. Proton publishes the same limit about its own AI for the same reason. Beating it needs hardware we do not have.
One thing is deliberately left unencrypted: the text of your messages. It carries a full-text index, and that index is the only way the coach can find something you said in a sitting that has since closed. Encrypted text cannot be searched, so sealing it would silently break the coach’s memory. We chose the memory. What answers that column instead is how long it is kept.
Article 32. Also in place: the database listens only on the machine’s own loopback interface, passwords are hashed with scrypt, session tokens are stored only as a SHA-256 hash, and nightly backups are encrypted to a public key whose private half is not on the server.
How long it is kept
A sitting’s messages are emptied 90 days after that sitting has been folded into the coach’s memory — not 90 days after you wrote them. The job runs nightly, and it refuses to run at all rather than guess a window.
What survives that, indefinitely: the coach’s rolling summary of you, the themes it keeps seeing, quotes taken word-for-word from your messages, your commitments, what you named as the obstacle, your check-ins and your readings. Those are copies taken at the time, not pointers into the message, so emptying the message does not remove them. The transcript goes; the memory of it does not. Most people do not expect that, which is why it is in bold.
The message rows themselves stay after their text is emptied — when you talked and how often, not what you said. And if a sitting is never folded into memory, its messages are never emptied; that is a fault when it happens, not a policy.
Backups are separate. They are taken nightly and encrypted, and deleting your account does not reach into one that was already made. They age out.
Article 13(2)(a). The retention period is configured as a promise rather than a tuning value, and the job exits with an error rather than defaulting if it is unset.
Deleting it
Open Account in the app and erase it. Your account row goes and twenty-eight foreign keys cascade from it: sittings, messages, commitments, what you named as the obstacle, your check-ins, your readings, and the coach’s memory of you. There is no soft delete and nothing is kept in a deleted state. You will need to be signed in — an account cannot be erased by somebody who is not in it.
One thing survives on purpose, and only if it applies to you. A code you signed up with stays marked as used, with your name taken off it. It records that a code was spent, not who spent it, so it cannot be handed out again. Most accounts have no code and nothing survives at all.
Article 17. The deletion is a single statement against the account row; the database performs the rest. Backups already taken are covered above.
What you can do
- Take a copy of everything. In the same Account panel: Export everything first. One JSON file with every sitting, commitment and reading in it, decrypted on the way out. No request, no waiting, no asking us.
- Sign out everywhere. Ends every session on the server, not just the one in this browser.
- Correct it. Your timezone you can change yourself. For your name or email, write to us — an email change is an identity change and needs asking.
- Object, or ask us to stop. Write to us. In practice, for a service that is only this, stopping is deleting.
- Take your consent back. That means deleting the account. Nothing done before stays unlawful, and nothing happens after.
- Complain about us. Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, uoou.gov.cz. You do not have to come to us first.
Articles 15, 16, 17, 18, 20, 21, 7(3) and 77. The export covers Article 15 and Article 20 together: it is the whole record, in a structured, machine-readable format, available without a request.
What we do not do
No trackers. No advertising. Nothing about you reaches a company that measures people for a living. The two fonts are served from our own machine rather than Google’s. The website is built out of nine pieces of other people’s code — React, the framework around it, a library that measures where lines of text break, one that checks the shape of data, Stripe’s two, and our own.
One of them talks to somebody, and it is Stripe. Its script is fetched from Stripe only when a payment form is actually on your screen — not when you sign in, not on any other page — and the card fields themselves are a frame Stripe serves. That is the point of doing it that way: your card number is never in this website’s code and never reaches our machine. If you never open a payment form, nothing on this site contacts anyone but us.
Our server looks up the weather, and it does not say who for. To know whether the hour you picked for something is about to be wet, it asks the Norwegian Meteorological Institute about a place on the map — the middle of your timezone, the same point for everyone in it, with no name, no account and not your computer’s address. It is a question about Czechia, not about you. The answer never reaches this website either; it only decides whether your own if-then is worth putting in front of you. Forecasts are Based on data from MET Norway, used under CC BY 4.0.
This is enforced rather than promised: the site sends your browser a Content-Security-Policy header telling it to refuse connections to any host except our own API and Stripe’s. You can check that yourself in the network tab.
We do count how many people reach each step. How many opened this site, how many pressed Start, how many finished the introduction, how many put a card in. That is one row per step per day, holding a name, a date and a number, plus one word naming where a link was posted when the link said so. There is no identifier in it of any kind: not a cookie, not your address, not your account, not your device, not the page you came from. Two people who did the same thing on the same day are the same row, and there is no order inside it to recover. It cannot be joined back to you because there is nothing in it to join on, and that is a fact about the table rather than a promise about our behaviour: the build fails if a column that could identify you ever appears in it.
Two cookies. Neither needs your permission, and here is why:
- The one that signs you in. A random token; the database only ever stores a hash of it. Lasts 30 days, extends as you use it, and cannot outlive 90 days without you signing in again.
- The one for signing in with Google. Only set if you press that button, to stop somebody forging the sign-in. It lives ten minutes and is deleted the moment you come back from Google.
That is why there is no cookie banner. A banner would need a cookie to remember your answer, and it would be the only unnecessary cookie on the site.
Article 5(3) of the ePrivacy Directive exempts storage that is strictly necessary to provide a service the subscriber explicitly requested. Session management and sign-in security are the textbook cases.
Changes, and getting hold of us
If something material changes — a new recipient of your data, a new purpose, a longer retention window — the date at the top of this page changes and you will be asked again rather than assumed to have agreed. Wording fixes will not do that.
Write to matyasherrmann@gmail.com. It is one person, so it may take a couple of days, and it will be answered by the person who wrote this.