Privacy Policy
1. Controller
Fabian Paulik
Nikolaus-Lenau-Str. 14
85757 Karlsfeld, Germany
Email: hello@perrenixapp.com
Website: perrenixapp.com
2. Which data we process and why
2.1 Registration and account
An account is required to use Perrenix. We process the following data:
- Email address (mandatory)
- First name (mandatory)
- Password (stored encrypted, no plaintext access)
- Time of registration and last login
- Date of your last activity in the app (needed for the release after inactivity, see 2.7)
Legal basis: Art. 6 para. 1 lit. b GDPR (performance of contract)
2.2 Two-factor authentication (2FA)
Perrenix optionally offers SMS-based two-factor authentication to secure your account. When activated, we process:
- Your mobile phone number (to send verification codes)
- The status of 2FA activation
The phone number is processed via Firebase Authentication (Google LLC) and forwarded to the respective SMS provider for SMS delivery.
When an SMS is sent, Google reCAPTCHA (Google LLC) runs an invisible check in the background to make sure the request comes from a person and not from an automated attack. Google processes technical data about your device and browser for this, such as your IP address. Legal basis for this check: Art. 6(1)(f) GDPR (protection against misuse).
Two-factor authentication is required for the “Everyone” level (see 2.7), so that every persona in “Discover” is backed by a real phone number.
Legal basis: Art. 6 para. 1 lit. a GDPR (consent through activation)
2.3 Reflection content and entries
The core purpose of Perrenix is personal self-reflection. For this we process:
- Free-text answers to daily reflection questions
- Free entries via the AI companion
- Photos and images uploaded by you
- Timestamps, streak data, and points balance
- Metadata for each answer: word count, reading level, time taken to write it, time of day and weekday, a counter within your session, language and category
- Names and years automatically detected in your text (simple text recognition in the app, no AI)
- Places you add to an entry – with coordinates if you choose the place via the place search (see 2.10)
- Your “About you” profile: voluntary details such as year of birth, place of birth, place of residence, profession, hobbies and countries visited – with a history of all changes
Legal basis: Art. 6 para. 1 lit. b GDPR (performance of contract)
2.4 Points system
Perrenix uses a points system for motivation. Points are awarded automatically for activities such as answering questions, daily login, or adding photos. We store the points balance and a log of the last 100 point awards.
Legal basis: Art. 6 para. 1 lit. b GDPR (performance of contract)
2.5 Health data (special categories pursuant to Art. 9 GDPR)
Processing takes place exclusively on the basis of your explicit consent (Art. 9 para. 2 lit. a GDPR). This is obtained separately when you first open the Health tab via an active checkbox.
Until your legacy is released, only you can see your health answers. They are never used for your AI persona and never sent to Google Gemini. Only if you explicitly choose this can they be read after the release – exclusively by the people you have marked as family in your circle of trust (see 2.7). This disclosure is also based on your explicit consent (Art. 9(2)(a) GDPR). You can withdraw your consent at any time.
2.6 Ancestry research
In the Ancestry tab you can write free-text entries about your family history and add documents (e.g. images or PDFs). We store:
- Free texts about family history
- Documents up to approx. 0.9 MB per entry – they are stored in your entry (transmitted encrypted and stored with Google)
- Metadata (timestamps, word count, document count)
Ancestry data is always private — not visible to others, not even after your legacy is released. The only exception are places that you release to your shared family tree yourself (see 2.10).
Legal basis: Art. 6 para. 1 lit. b GDPR (performance of contract)
2.7 Legacy and release
As long as you use Perrenix, nobody but you sees your answers and your persona. In the “Legacy” area you decide who may see what after a release. Without your setting, nothing is released.
Life story and persona – three levels:
- Nobody: nothing is released.
- Friends & family: your circle of trust and everyone who requests access with your unlock code and whom you do not stop.
- Everyone: all signed-in Perrenix users; your persona can then also be found under “Discover”. This level only applies with two-factor authentication by SMS – without it, “Friends & family” applies.
Health is set separately: “Nobody” or “Family only”. With “Family only”, after the release only the people you have marked as family in your circle of trust can read your health answers – never through the persona (see 2.5).
When a release happens – in two ways:
- After inactivity: if you do not open the app for the period you chose (6 months, 1, 2 or 5 years), we first send you an email and a reminder after 14 days. If you do not respond within 30 days, your legacy is released. Opening the app or using the confirmation link in the email resets the clock.
- After a request with your unlock code: someone enters your code, their name and their email address in the form at perrenixapp.com/legacy. We notify you by email. If you do not stop the request within your waiting period (7, 14 or 30 days, counted from when we notified you), your legacy is released. You can stop a request via the link in the email or in the app. If your legacy has already been released, anyone who requests access with the correct code gets access immediately.
If a release happened by mistake while you are still alive, you can take it back in the app (“Undo the release”).
What becomes visible after the release – depending on your settings:
- Your name and your AI persona. It answers solely on the basis of your own answers – without health answers and without ancestry entries – and selected “About you” details (year and place of birth, place of residence, profession, hobbies, countries visited). This requires your consent to the AI features (see 2.8).
- An AI-generated profile summary: at the release, Google Gemini writes a short description of you from up to 60,000 characters of your answers (without health answers) and your “About you” details. It is shown with your persona and used for the search under “Discover”.
- Your health answers – only with “Family only” and only for the people marked as family.
Data we process for this – including data of other people:
- Names and email addresses of the people you add to your circle of trust, and whether you mark them as family. We only write to them once your legacy is opened for them.
- Name and email address of people who request access via the form at perrenixapp.com/legacy. They receive a confirmation and, if access is granted, an email with instructions. If access is granted, their email address stays stored with your legacy as an authorised person for as long as the release exists.
- Your unlock code (at least 10 characters). It is stored in your account so that we can check requests. It never appears in the legacy letter – you write it in by hand.
- Your legacy letter: the PDF is created on your device. If you have it emailed to you, it is sent via our server to the email address of your account (delivery via Zoho Mail); we do not store it.
To prevent misuse, wrong code entries (at most 10 per day and profile) and requests (at most 5 per profile and 3 per email address within 24 hours) are limited. In the profile we create at the release, we store the email addresses of authorised people only as a hash, not in plain text. Finished requests (stopped or released), including the requester’s name and email address, are deleted 90 days after the request date.
Legal basis: Art. 6(1)(a) GDPR (your consent through your settings) and, for health answers, Art. 9(2)(a) GDPR. For the data of your trusted contacts and of requesting persons: Art. 6(1)(f) GDPR (legitimate interest in carrying out your wishes and checking requests securely).
2.8 AI features (Google Gemini)
Perrenix offers an AI companion, an AI persona and a persona search under “Discover”. The following applies:
- Your inputs and excerpts from your answers are sent directly to the Google Gemini API (Google LLC, USA) for processing – also later, when others talk to your released persona.
- Transmission is encrypted via Firebase Cloud Functions (region: europe-west1).
- Google processes the content to respond to your request. We have concluded a Data Processing Agreement (DPA) with Google in accordance with Art. 28 GDPR.
- Your health answers are never sent to Google Gemini.
- At the release of your legacy, Gemini creates a short profile summary from your answers (see 2.7).
- Each user can make at most 40 AI requests per day. To enforce this, we count your requests per day.
- Conversations with a released Persona are saved only for you (the last 50 messages), so you can continue later. You can delete the history at any time.
Legal basis: Art. 6(1)(a) GDPR (your explicit consent in the app; you can withdraw it at any time and keep using Perrenix without AI)
2.9 Shared family tree
You can maintain a family tree together with relatives. Anyone who joins such a group can see the people and family relationships in the shared tree, as well as the names of the other members.
- Shared: names, years of birth and death and notes of the people entered in the tree, along with the family relationships.
- Not shared: your own reflection answers, your ancestry entries, uploaded documents and your profile. These remain solely in your account.
- What you contribute to the shared tree stays there even if you leave the group later — otherwise the tree would become incomplete for the remaining members.
- If you are linked to your own entry in the tree, only you can change the details of that person.
- If you delete your account, the same applies: people and changes you contributed stay in the tree for the other members. Your shared places are removed, and if you were the only owner of the tree, the longest-standing member becomes its owner.
Legal basis: Art. 6(1)(a) GDPR (consent by creating or joining a group)
2.10 Places and place search
You can assign a place to a memory and release that place individually to your shared family tree.
- Released are solely: the place, the year, your name and — only if you additionally choose so — the associated photo.
- Your written texts are never released. They remain visible to you alone until any legacy unlock. This applies regardless of whether you have released a place.
- Answers to health questions are entirely excluded from this feature; no place can be added there.
- Place search: when you search for a place, your search term and your IP address are transmitted to the Nominatim service operated by the OpenStreetMap Foundation (United Kingdom). This transmission only happens when you actively trigger the search — not while typing and not in the background.
- You can instead enter a place as free text at any time. No transmission to third parties takes place in that case.
- Map data: © OpenStreetMap contributors, available under the Open Database License (ODbL).
Legal basis: Art. 6(1)(a) GDPR (consent by actively triggering the search or by releasing a place)
2.11 Voice and appearance (voice, photo and video recordings)
You can voluntarily save recordings of your voice as well as photos and videos of yourself. They serve exclusively as material so that an AI can later recreate your voice and appearance.
- What is stored: Voice recordings, photos (one photo per view and year) and videos (e.g. a 360° video), each with the recording date and – if you have entered your year of birth – your age at the time of the recording.
- Storage location: Cloud Storage for Firebase in the EU (region europe-west1, Belgium).
- Who has access: Only you – you can view, listen to and delete your recordings in the app at any time. Other people, including your loved ones, never get to see or hear the recordings themselves; after your legacy is released they are processed exclusively for the AI recreation.
- Purpose: After your legacy is released, AI recreations of your voice and appearance (e.g. a phone call or 3D/VR) that only the friends and family you have chosen can use. Such recreations are always clearly labelled as AI. This feature is not yet available; until then the recordings are only stored. Before any AI recreation starts, we will name the service used for it here.
- Withdrawal and deletion: You can withdraw your consent in the app at any time. Your recordings then stay stored only for you until you delete them, and they are not used for any AI. You can delete individual or all recordings at any time; when your account is deleted, all recordings are deleted.
Legal basis: Art. 6(1)(a) GDPR and, insofar as biometric data is concerned, Art. 9(2)(a) GDPR (explicit consent, separate from the consent to the AI Persona)
2.12 Website
Our website perrenixapp.com is hosted by Netlify, Inc. (USA). When you visit it, Netlify processes technically necessary data in server logs – such as your IP address, date and time, the page requested and browser information – to deliver the website and keep it secure. These logs are kept only for a short time.
- Fonts: we load them from our own server; no connection to Google is made for this.
- Browser storage: we only use your browser’s local storage (localStorage) to remember that you closed the language hint or chose a language. We do not use any analytics or tracking tools.
- Request form: on perrenixapp.com/legacy, people can request access to a legacy with an unlock code. The name, email address and code entered are sent directly to our server (Firebase Cloud Functions, region europe-west1) – see 2.7.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, working website)
3. Data transfer and storage location
| Service | Provider | Purpose | Location |
|---|---|---|---|
| Firebase Firestore | Google LLC | Data storage | EU |
| Firebase Auth | Google LLC | Authentication, 2FA | EU |
| Firebase Cloud Functions | Google LLC | Backend logic | EU (europe-west1) |
| Cloud Storage for Firebase | Google LLC | Voice and image recordings | EU (europe-west1) |
| Google Gemini API | Google LLC | AI features (companion, persona, search) | USA¹ |
| Google reCAPTCHA | Google LLC | Protection against misuse when sending SMS (2FA) | USA¹ |
| Zoho Mail | Zoho Corporation B.V. (Netherlands) | Sending emails (reminders, requests, releases, legacy letter) | EU |
| Netlify | Netlify, Inc. | Website hosting | USA¹ |
| Nominatim | OpenStreetMap Foundation | Place search (only on your input) | United Kingdom² |
¹ For transfers to the USA we rely on the EU Standard Contractual Clauses (SCC) and the EU-US Data Privacy Framework.
² The United Kingdom is covered by an adequacy decision of the EU Commission, so no separate safeguard is required. Only the search term you enter and your IP address are transmitted — never the content of your entries.
4. Storage duration
- Account data and content: Until account deletion
- Account deletion: We delete your account and your content immediately. Only contributions to a shared family tree (people and changes) remain for the other members (see 2.9); your shared places are removed.
- Phone number (2FA): Until 2FA is deactivated or the account is deleted
- Circle of trust and unlock code: Until you remove them or your account is deleted
- Legacy requests: Open requests until they are stopped or released; finished requests, including the requester’s name and email address, 90 days after the request date
- Profile created at the release: Until you take back the release, set everything to “Nobody” or your account is deleted
- Voice and image recordings: Until you delete them or your account is deleted
- Saved Persona conversations: Until you delete the history, the persona is no longer released to you, or your account is deleted
- Daily AI counters: 30 days
- Counters to prevent misuse (wrong code entries, legacy letter emails, request limits): 2 days
- Expired invitations to a shared family tree: 30 days after expiry
5. Your rights
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR) — "right to be forgotten"
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7 para. 3 GDPR)
Contact: hello@perrenixapp.com
Competent supervisory authority: Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 27, 91522 Ansbach, Germany, www.lda.bayern.de
6. Data processing agreements
Google LLC (Firebase and Gemini API) — DPA via the Firebase Data Processing Terms.
Zoho Corporation B.V. (Zoho Mail) — data processing agreement in accordance with Art. 28 GDPR.
No selling of your data, no ads; data is only transferred to the services listed in section 3 and to the people you choose yourself.
7. Data security
- All connections are TLS-encrypted
- Firebase Firestore Security Rules restrict access to authenticated users
- Ancestry data is always private at the database level; others can only read health answers if you chose “Family only” and your legacy has been released
- Passwords are securely hashed by Firebase Auth
- Optional 2FA for additional account protection
8. Death of the user and digital legacy
The release of your legacy (after inactivity or after a request with your unlock code) is carried out to the best of our technical ability, but without guarantee. Heirs may request account access by providing a death certificate and certificate of inheritance. Relatives may request complete deletion.
9. Children and minors
Perrenix is intended exclusively for persons aged 18 and over.
10. Automated decision-making
Perrenix does not make any automated decisions with legal effect (no profiling within the meaning of Art. 22 GDPR). The AI companion serves exclusively as a conversational partner.
11. Changes
Material changes will be communicated by email or via in-app notification.