Privacy Policy
Effective date: 24 August 2026. Last updated: 25 August 2026.
Who we are
Intropi is a hypnosis and meditation app. This policy explains what we collect, why, where it goes, and the choices you have. It is written to be honest about what stays on your device and the limited usage data we collect.
The organisation responsible for your data (the data controller) is GrowthNodes ApS, Havneholmen 70, 2nd floor, 1561 Copenhagen V, Denmark (CVR 40196021). You can reach us about any privacy question or request at support@growthnodes.xyz.
The short version
Built-in library sessions play from the app. A session you generate is rendered on our servers and stored in your private space so it can play back on your devices.
Usage analytics are separate and do not receive a generated session's id, title, audio, or written content. A small amount of account and app data also goes to our servers so features like sign-in, subscriptions, and rewards can work across your devices. We do not sell your data.
What stays on your device
The following information is stored only on your device and is used by the app's safety flows:
- Your optional wellbeing screening answers about pregnancy, epilepsy or seizures, psychosis, current thoughts of self-harm, severe dissociation, and a pacemaker or other implanted cardiac device.
What we send to our servers
To provide generated sessions, accounts, subscriptions, and rewards, a limited set of data goes to our servers and service providers:
- Generated sessions. A session you generate is rendered on our servers. Its audio blocks and script text are stored in your private space so the session can play back on your devices.
- Account email. Only if you create or upgrade to an account. You can use the app anonymously first, without an email.
- A random user id. A generated identifier (a UUID) that lets your data sync without using your name.
- Timezone. Used to schedule daily features and time-based rewards correctly.
- Sign-in identity. If you sign in with Google or Apple, the identity those services return so we can recognise you.
- The rewards economy. Your currency ledger, wallet, streaks, referrals, and chest rolls. The ledger includes short human-readable reason labels, such as the name of the feature or quest that earned a reward.
- Push token. A device notification token, only if you turn notifications on, so we can deliver reminders you asked for.
- The things you type in your own words. Three places in the app take free text, and all three are stored on our servers so we can understand what people need and improve the app: the goal you write during onboarding, the guide chat, and the Build-your-own prompt. All of it is kept for 90 days and deleted when you delete your account, whichever comes first.
Analytics
We use PostHog to understand how the app is used so we can improve it. Events can include that a screen was opened or a feature was used, which built-in topic or session was picked, and how a session was rated. For a session you create, PostHog receives only that it was custom, without an identifier, title, audio, or written content. Events are tagged with an app-generated user id. Every internet request carries an IP address, but our PostHog project is set to discard client IP data, so it is not stored and your location is not derived from it. Session replay and console-log capture are off — the app never records your screen.
You can manage Anonymous usage stats in the app at Settings > Privacy. Turning it off saves the preference on your device and applies PostHog's opt-out control.
The public website also sends a small number of events to PostHog from our servers: when you submit a form, and when you click an app-store badge or a “Get the app” link. A click event carries the page path and which store was clicked, and nothing you typed.
Those website events are not tied to a person. Each carries a random identifier created for that single action and never reused, and PostHog is asked not to build a profile from them. The app's Anonymous usage stats switch does not cover them, because they happen outside the app; blocking the request in your browser stops them.
Why we are allowed to use your data (legal bases)
For people in the UK, the EU, and other regions with similar laws, the legal bases we rely on under GDPR Article 6 are:
- Contract. To provide the app, your account, subscriptions, and rewards.
- Legitimate interests. To keep the app secure, prevent abuse of the reward systems, and improve the product with coarse analytics.
- Consent. For notifications and, where required, for analytics. You can withdraw consent at any time.
The safety, mood, and goal information the app uses can count as special category (health-adjacent) data under GDPR Article 9. Mood ratings and broad built-in goal categories may be included in usage analytics. The words you write are never part of an analytics event — but to be clear about a distinction that is easy to blur: not in analytics is not the same as not stored. Everything you type in your own words — your written onboarding goal, the guide chat, and the Build-your-own prompt — is sent to and stored on our servers. Where that text includes special category data, we process it under your explicit consent, given when you choose to use those features, and delete it after 90 days or when you delete your account. You can withdraw consent at any time by clearing on-device information or deleting your account.
Who processes data for us (sub-processors)
We share the server-side data described above only with service providers that help us run the app, under contracts that limit how they may use it. We name them so you can see exactly who is involved and read their own policies:
- Z.ai (GLM): writes the session script when you use Build your own, and answers Guide Chat. It receives the text you type and our instructions to the model. It does not receive your name, email, or account id. z.ai privacy policy
- OpenRouter: the same job as above, used as a fallback when the first provider is unavailable. OpenRouter routes the request on to a model provider, so that provider also receives the text. openrouter.ai/privacy
- DeepInfra: turns the finished script into speech. It receives the script text and the voice you chose, but not the words you originally typed and not your account id. deepinfra.com/privacy
- Encharge: lifecycle and product email. It receives your email address and the account signals we use to decide which message to send. encharge.io/privacy
- Supabase: database, authentication, and storage hosting. supabase.com/privacy
- PostHog (EU): product analytics. posthog.com/privacy
- RevenueCat: subscription and purchase management. revenuecat.com/privacy
- Expo: push notification delivery. expo.dev/privacy
- Stripe: payments for subscriptions bought on the web app. Stripe receives your email address and your payment details directly — we never see or store your card number. Purchases made inside the iOS or Android app go through Apple or Google instead, not Stripe. stripe.com/privacy
- Resend (US): delivers the email our website contact form sends, and may receive an address submitted to the early-access form. It no longer handles lifecycle email — that moved to Encharge. resend.com/legal/privacy-policy
- Cloudflare (US): private R2 storage for generated session audio and script text; website hosting; the Turnstile bot check; and the early-access email form, which receives the email address you submit and your IP address. cloudflare.com/privacypolicy
A provider we have stopped sending data to. Earlier versions of this policy named Loops for lifecycle email. It receives nothing from Intropi any more — that moved to Encharge. We name it here rather than quietly deleting it, because it may still hold email addresses collected while it was in use, and holding data is still processing. If you want your address removed from that account, email us and we will do it.
An earlier version of this page said the same about Resend. That was wrong, and we are correcting it rather than quietly editing it out: Resend still delivers our website contact form. It is listed above as a current provider.
The app stores (Apple App Store and Google Play) also process your subscription receipt and entitlement when you buy premium. We never receive your card number.
If you bring your own AI key
The app has an optional Bring-your-own-key setting. If you paste in your own Anthropic, OpenAI, or OpenRouter API key, the app sends your session text directly from your device to that provider, using your key and under your own account with them. It does not pass through our servers, we never see that key, and we cannot see or delete what that provider stores. Your relationship there is with them, under their terms and privacy policy, not ours. This setting is off unless you turn it on.
What we do not yet claim about the AI providers. We are not going to tell you that the three providers above never keep your text or never use it to train a model, because we have not finished confirming that for the specific accounts we use, and saying it before we know would be worse than saying nothing. What we can tell you is what we control: we send them the words you type and nothing that identifies you, we do not send them your email, name, or account id, and we do not sell your content to anyone. We are working through their retention and training terms and will name the answers here once they are settled rather than leaving a comfortable gap.
Where your data is processed (international transfers)
Our database and your account data are hosted in the European Union (Frankfurt), and product analytics run on PostHog's EU region.
Some of our other providers process data elsewhere: the AI provider that writes your session processes in Singapore, and the fallback AI provider and the speech provider process in the United States. When data is transferred out of the UK or the EU, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the providers' own compliance measures. We are still confirming the exact mechanism in place with each of those three, and we would rather say that than imply it is settled.
How long we keep data
- Generated session content is kept in your private storage so it can play back on your devices.
- Account and rewards data is kept while your account is active and is erased when you delete your account.
- What you type in your own words — your written onboarding goal, Guide Chat, and Build your own — is stored on our servers so we can see what people are asking for and make the app better at it. Only we can read it — it is locked to our service role, not readable by the app or by other users. When you delete your account, everything tied to your account is erased with it. It is also deleted automatically after 90 days, whether or not you delete your account — a job runs every night and removes anything older than that.
- Analytics events are retained for a limited period to spot trends, then removed or aggregated so they no longer identify a device. Your typed text is never part of an analytics event — for a session you create, analytics records only that it was custom.
- Records we must keep by law (for example, tax or transaction records tied to a purchase) are kept only for as long as the law requires.
Your rights and how to use them
Depending on where you live, you have rights over your personal data. Under GDPR and UK GDPR these include the right to access, correct, erase, and receive a portable copy of your data, to object to certain uses, and to withdraw consent. Under the CCPA and CPRA in California, these include the right to know, the right to delete, and the right to opt out of the sale of personal data. We do not sell your personal data.
To exercise any right, email us at support@growthnodes.xyz. We do not yet offer an automated export, so to receive a copy of your data please ask us and we will respond within 30 days.
Deleting your account
You can delete your account from inside the app at any time. Deleting your account runs a server routine that erases the database records tied to your account, including your account email, rewards ledger and wallet, streaks, referrals, and push token. Deleting the app or your account also removes the on-device data described above from your device. If you prefer, you can ask us to delete your account by contacting support@growthnodes.xyz.
Children
Intropi is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child has used the app, contact us at support@growthnodes.xyz and we will delete the data.
Changes to this policy
If we make material changes, we will update this page and change the "Last updated" date. Where appropriate, we will also let you know in the app.
How to contact us
For any privacy question or request, contact GrowthNodes ApS, Havneholmen 70, 2nd floor, 1561 Copenhagen V, Denmark (CVR 40196021) at support@growthnodes.xyz.