Privacy Policy

Effective date: 24 August 2026. Last updated: 25 August 2026.

Who we are

Intropi is a hypnosis and meditation app. This policy explains what we collect, why, where it goes, and the choices you have. It is written to be honest about what stays on your device and the limited usage data we collect.

The organisation responsible for your data (the data controller) is GrowthNodes ApS, Havneholmen 70, 2nd floor, 1561 Copenhagen V, Denmark (CVR 40196021). You can reach us about any privacy question or request at support@growthnodes.xyz.

The short version

Built-in library sessions play from the app. A session you generate is rendered on our servers and stored in your private space so it can play back on your devices.

Usage analytics are separate and do not receive a generated session's id, title, audio, or written content. A small amount of account and app data also goes to our servers so features like sign-in, subscriptions, and rewards can work across your devices. We do not sell your data.

What stays on your device

The following information is stored only on your device and is used by the app's safety flows:

What we send to our servers

To provide generated sessions, accounts, subscriptions, and rewards, a limited set of data goes to our servers and service providers:

Analytics

We use PostHog to understand how the app is used so we can improve it. Events can include that a screen was opened or a feature was used, which built-in topic or session was picked, and how a session was rated. For a session you create, PostHog receives only that it was custom, without an identifier, title, audio, or written content. Events are tagged with an app-generated user id. Every internet request carries an IP address, but our PostHog project is set to discard client IP data, so it is not stored and your location is not derived from it. Session replay and console-log capture are off — the app never records your screen.

You can manage Anonymous usage stats in the app at Settings > Privacy. Turning it off saves the preference on your device and applies PostHog's opt-out control.

The public website also sends a small number of events to PostHog from our servers: when you submit a form, and when you click an app-store badge or a “Get the app” link. A click event carries the page path and which store was clicked, and nothing you typed.

Those website events are not tied to a person. Each carries a random identifier created for that single action and never reused, and PostHog is asked not to build a profile from them. The app's Anonymous usage stats switch does not cover them, because they happen outside the app; blocking the request in your browser stops them.

Why we are allowed to use your data (legal bases)

For people in the UK, the EU, and other regions with similar laws, the legal bases we rely on under GDPR Article 6 are:

The safety, mood, and goal information the app uses can count as special category (health-adjacent) data under GDPR Article 9. Mood ratings and broad built-in goal categories may be included in usage analytics. The words you write are never part of an analytics event — but to be clear about a distinction that is easy to blur: not in analytics is not the same as not stored. Everything you type in your own words — your written onboarding goal, the guide chat, and the Build-your-own prompt — is sent to and stored on our servers. Where that text includes special category data, we process it under your explicit consent, given when you choose to use those features, and delete it after 90 days or when you delete your account. You can withdraw consent at any time by clearing on-device information or deleting your account.

Who processes data for us (sub-processors)

We share the server-side data described above only with service providers that help us run the app, under contracts that limit how they may use it. We name them so you can see exactly who is involved and read their own policies:

A provider we have stopped sending data to. Earlier versions of this policy named Loops for lifecycle email. It receives nothing from Intropi any more — that moved to Encharge. We name it here rather than quietly deleting it, because it may still hold email addresses collected while it was in use, and holding data is still processing. If you want your address removed from that account, email us and we will do it.

An earlier version of this page said the same about Resend. That was wrong, and we are correcting it rather than quietly editing it out: Resend still delivers our website contact form. It is listed above as a current provider.

The app stores (Apple App Store and Google Play) also process your subscription receipt and entitlement when you buy premium. We never receive your card number.

If you bring your own AI key

The app has an optional Bring-your-own-key setting. If you paste in your own Anthropic, OpenAI, or OpenRouter API key, the app sends your session text directly from your device to that provider, using your key and under your own account with them. It does not pass through our servers, we never see that key, and we cannot see or delete what that provider stores. Your relationship there is with them, under their terms and privacy policy, not ours. This setting is off unless you turn it on.

What we do not yet claim about the AI providers. We are not going to tell you that the three providers above never keep your text or never use it to train a model, because we have not finished confirming that for the specific accounts we use, and saying it before we know would be worse than saying nothing. What we can tell you is what we control: we send them the words you type and nothing that identifies you, we do not send them your email, name, or account id, and we do not sell your content to anyone. We are working through their retention and training terms and will name the answers here once they are settled rather than leaving a comfortable gap.

Where your data is processed (international transfers)

Our database and your account data are hosted in the European Union (Frankfurt), and product analytics run on PostHog's EU region.

Some of our other providers process data elsewhere: the AI provider that writes your session processes in Singapore, and the fallback AI provider and the speech provider process in the United States. When data is transferred out of the UK or the EU, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the providers' own compliance measures. We are still confirming the exact mechanism in place with each of those three, and we would rather say that than imply it is settled.

How long we keep data

Your rights and how to use them

Depending on where you live, you have rights over your personal data. Under GDPR and UK GDPR these include the right to access, correct, erase, and receive a portable copy of your data, to object to certain uses, and to withdraw consent. Under the CCPA and CPRA in California, these include the right to know, the right to delete, and the right to opt out of the sale of personal data. We do not sell your personal data.

To exercise any right, email us at support@growthnodes.xyz. We do not yet offer an automated export, so to receive a copy of your data please ask us and we will respond within 30 days.

Deleting your account

You can delete your account from inside the app at any time. Deleting your account runs a server routine that erases the database records tied to your account, including your account email, rewards ledger and wallet, streaks, referrals, and push token. Deleting the app or your account also removes the on-device data described above from your device. If you prefer, you can ask us to delete your account by contacting support@growthnodes.xyz.

Children

Intropi is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a child has used the app, contact us at support@growthnodes.xyz and we will delete the data.

Changes to this policy

If we make material changes, we will update this page and change the "Last updated" date. Where appropriate, we will also let you know in the app.

How to contact us

For any privacy question or request, contact GrowthNodes ApS, Havneholmen 70, 2nd floor, 1561 Copenhagen V, Denmark (CVR 40196021) at support@growthnodes.xyz.

Read the Terms of Service