Naipa

Legal

Privacy Policy

Last updated:

Naipa is a journaling app. What you write in it is personal — sometimes more personal than you meant it to be — and that is the whole reason this page exists: to say plainly what we keep, what we do with it, and what we will never do.

Three promises first, so you do not have to hunt for them. We will never sell your information to anyone. We will never use it for advertising. What you write is yours, and you can ask us to delete it at any time.

1. Who is responsible

Naipa is an independent project run by Otto Jimenez, based in Colombia, who acts as the data controller for the information described here. Any question about your data goes to the address at the end of this page.

2. What we collect

Only what the app needs in order to work. There are five kinds:

  • Your account: your name and your email address. If you signed up with a password, we store an Argon2 hash of it, never the password itself. If you signed in with Google, Google tells us your email, your name and an account identifier; your Google password never passes through us.
  • What you write: the text of your answers, which card each one belongs to, its position in the session and the local date you played. Also the themes the weekly job assigns to each answer, and the weekly note it writes.
  • Your settings: language, tone, which day your week starts on, and whether the daily reminder is on and at what time.
  • Technical data: our servers keep short-lived access logs (IP address, time, route) to keep the service running and defend it from abuse. The naipa.co website uses Microsoft Clarity to see which pages get read, which sets cookies. The app carries no advertising and no third-party trackers.
  • How the app is used: a short, fixed list of moments — the app was opened, a first turn was started or finished, a signup was started or completed, the subscription screen was shown. Each one is a name and a time, and nothing else: no text you wrote ever reaches them. Before you have an account they are tied to a random identifier we generate on your device, which is not derived from anything about your phone, identifies you nowhere else, and disappears when you uninstall. We record them to know how many people get as far as playing, not to build a profile of anyone, and they go to our own servers and nowhere else.

3. What we do not collect

Nearly all of the game happens on your device. The deck, the daily turn, the timer and the reminders never touch the network: the reminder is a local notification your phone schedules by itself, not a push message from a server, and no card art is fetched from anywhere. The backend only ever receives days you have already played.

We do not collect your location, your contacts, your photos, your microphone, or any advertising identifier. We do not ask for them, and the app does not request those permissions.

4. What we use it for

Your information is used to:

  • Create your account, sign you in and keep your session alive.
  • Keep your entries safe and in sync, so you still have them if you change or lose your phone.
  • Produce the weekly summary: count the themes of the week and write the exploratory note that goes with them.
  • Send you the emails the service needs — the verification code and the password reset code. We do not send marketing email.
  • Keep the service secure and prevent abuse, and comply with legal obligations that apply to us.

We do not profile you for advertising and we make no automated decision that has legal effects on you. The weekly note is a note, not a judgement.

5. Sensitive information and your consent

Free association can end up saying something about how you are feeling, and Colombian law treats data touching on health or emotional life as sensitive. Answering is always optional: you can leave a card blank, write something trivial, or not play at all — nothing in the app punishes you for it.

By writing an answer you consent, freely and expressly, to us storing and processing it as described on this page. You can withdraw that consent whenever you want by deleting your account from the app's settings.

Naipa is not a psychological test, a diagnosis or a therapy. The themes it counts are not a clinical assessment of anything.

6. Artificial intelligence

Once a week a job classifies the answers of a finished week into one or two of seven themes and writes a short note about them. It is the only moment your text leaves our servers, and it works like this:

  • What is sent is the answer texts and the card ids, numbered. Your name, your email and your account id are not sent: the provider receives loose sentences with no way of knowing whose they are.
  • The note is written from what you wrote. The provider is given the week's answers along with the tally, and the note has to quote two of your own phrases word for word — the tally alone would only describe the numbers you are already looking at. The prompt forbids it from diagnosing, advising, interpreting what an answer says about you, or responding to anything serious it finds.
  • The providers are a configurable cascade, today Groq, Anthropic and OpenAI, used through their APIs. We do not use your answers to train any model, ours or anyone else's, and we choose providers whose API terms do not train on the data sent to them.
  • The app hides the note and the themes until you have one finished week behind you, so that what you read does not bias what you write next.

7. Who else sees it

We do not sell, rent or trade your personal information, and we never will. It is shared only with the providers that make the service run, each doing one job:

  • Our infrastructure provider, which hosts the server and the database.
  • Cloudflare, sitting in front of our domains as a delivery and protection layer.
  • Google, only if you choose to sign in with Google.
  • Mailgun, which delivers the verification and password reset emails.
  • The AI providers described in the previous section.
  • Microsoft Clarity, on the naipa.co website only — never in the app.
  • Google Play and Apple, whichever of the two sold you the subscription, which process the payment. We never receive your payment details: all we store is the identifier that store issues for your purchase, tied to your account, which is what lets us tell whether your subscription is active.

We may also hand over information when a competent authority requires it through a valid legal order. If that ever happens we will tell you, unless the law forbids us from doing so.

8. Where it lives and how long we keep it

The server and the database run on infrastructure rented outside Colombia, and the providers listed above may process your data in other countries. Both Colombian law and the GDPR allow this when the recipient offers adequate safeguards, and we work only with providers that do.

We keep your account and your entries for as long as your account exists — the whole point of the app is that you can look back at them. When you delete your account from the settings screen, it goes immediately, along with everything attached to it: your entries, your summaries and any session open on any device. If you would rather ask us by email, we complete it within 30 days. Access logs are kept for a short period, and a backup may hold a copy for a few weeks longer before it rolls over.

9. Security

Traffic travels over TLS, passwords are stored as Argon2 hashes, sessions use a short-lived access token plus a rotating refresh token, and the database is not exposed to the internet. Access to production is limited to whoever maintains the service.

No system is perfectly safe. If a breach ever affects your data, we will tell you and the competent authority as the law requires.

10. Your rights

Under Colombian Law 1581 of 2012 and its implementing rules, you may at any time:

  • Know what personal information we hold about you and how we are using it.
  • Update or correct anything that is wrong, incomplete or out of date.
  • Ask us to delete your data, and revoke the consent you gave.
  • Ask for a copy of your entries, in a readable format.
  • File a complaint with the Superintendencia de Industria y Comercio, after first raising it with us.

If you are in the European Economic Area or the United Kingdom, you also hold the rights the GDPR gives you — access, rectification, erasure, restriction, portability and objection — and you may complain to your national supervisory authority.

To exercise any of this, write to the address below from the email address on your account. We answer within the terms the law sets: ten business days for a query and fifteen for a claim, extendable as the law allows. Deleting your account is not something you have to ask for: you do it yourself from the settings screen, and it is immediate. If you would rather we did it, we complete it within 30 days.

11. Adults only

Naipa is meant for adults: you must be 18 or older to have an account. We do not knowingly collect information from minors, and if we find out that we have, we delete it.

12. Cookies

The naipa.co website uses Microsoft Clarity cookies to understand which pages are read and where people get stuck. The app itself uses no cookies.

You can block or delete them from your browser whenever you like; the site works exactly the same without them.

13. Changes to this policy

We may update this policy. When we do, the date at the top changes and the new version is published on this page. If a change is significant, we will tell you in the app or by email before it takes effect.

14. Contact

Questions about this policy, or a request about your data — access, correction, deletion — all go to the same place:

See also: Terms and Conditions