Audunn

Privacy Policy

Last updated: 2026-08-19

This policy describes how Audunn handles data. For your own account and workspace, Audunn is the controller. For your Members' personal data, Audunn is your processor and you (the coach) are the controller, so your Members should read your own privacy notice, not this one, for how their data is used.

1. Who we are

Audunn is operated by Audunn, Jarlsberggade 5B, 4.2, 5000 Odense C, Denmark. Contact: audunn@realaudunn.com.

2. What we collect from creators

We do not use tracking cookies, third-party analytics, or advertising identifiers.

2a. Special-category (health) data we process for coaches

Where a coach's agent collects health and lifestyle information from a Member, for example body weight, food and nutrition, sleep, mood, injuries, or training logs, we store and process that information on the coach's instructions, as their processor, to run the coaching the Member signed up for. This is "data concerning health" under GDPR Article 9, and we treat the whole tracker and chat as such. Every chat message, including any health information it contains, is sent to the AI provider the coach has selected, to generate the agent's reply. Claude (Anthropic) is the default and the recommended choice. A coach, or a Member using their own key, may instead select OpenAI, Google Gemini, Kimi (Moonshot) or Grok (xAI); section 5 lists each one and where it processes data. Anthropic and OpenAI do not train on API inputs or outputs by default. Other providers' terms differ, and a provider's free tier in particular may be used to improve their models, so read the terms of any provider you enable before you enable it. The coach is responsible for obtaining the Member's explicit consent to this, and the platform provides a consent step for that purpose.

3. Your role as controller

When you deploy an agent to Members you are the data controller for their personal data and we act as your processor. The Data Processing Agreement governs this. You are responsible for your Members' privacy notice, consent, and data-subject requests (we give you export and delete tooling).

3a. Support access

Our staff may access a coach's workspace, and sign in to a Member account within it, only to fix problems (see the Terms) or to investigate a security or integrity issue. This access is least-privilege, logged, and visible to the coach. Members are told about this possibility through their coach's privacy notice.

4. Cookies

One strictly necessary cookie keeps you signed in. No analytics or tracking cookies.

5. Sub-processors

ProviderPurposeLocationTransfer basis (from EEA/UK)
AnthropicClaude AI responses (via your key), the defaultUnited StatesSCCs + EU-US DPF
OpenAIGPT responses, only if you select it (via your key)United StatesSCCs
GoogleGemini responses, only if you select it (via your key)United StatesSCCs
Moonshot AIKimi responses, only if you select it (via your key)ChinaSCCs + transfer impact assessment
xAIGrok responses, only if you select it (via your key)United StatesSCCs
Supabase (on AWS)Database, auth, storageIreland (EU)Not applicable
VercelApplication hostingUnited StatesSCCs + EU-US DPF
StripePayment processingUnited StatesSCCs + EU-US DPF
ResendTransactional emailUnited StatesSCCs
UnipileDM sync (LinkedIn/Instagram/WhatsApp/Telegram), where enabledEUNot applicable
ApifyContent statistics, where enabledEU/United StatesSCCs
TelegramBot messaging, where a coach enables itInternationalsee note

We are bring-your-own-key. Claude is the default and no other AI provider receives anything unless a coach or Member deliberately selects it and supplies their own key for it. Selecting Kimi (Moonshot) sends data to a provider in China, which has no EU adequacy decision; a coach choosing it takes on that transfer as controller and should say so in their own privacy notice. Telegram is an optional messaging channel a coach may switch on; it does not offer a standard processor agreement, so a coach enabling it should treat messages sent over it accordingly and disclose it to Members. We verify each provider's current transfer basis at go-live.

6. Security

Passwords hashed by Supabase Auth. Your Anthropic key encrypted at rest (AES-256-GCM). All connections use TLS/HTTPS. Database encryption at rest via Supabase. Support access is least-privilege and logged.

7. Your rights

You can export your data from the app at any time. Members delete their own account from Account; creators ask us to close a workspace and we action it within 30 days. If you are in the EEA, UK, Switzerland, or California, you have additional rights under GDPR or CCPA/CPRA; contact us to exercise them. A Member exercising rights over their own data should contact their coach, who is the controller.

8. Retention

We keep your account data until the account is deleted. A Member deleting their account removes their data immediately. A Member who withdraws health-data consent has that recorded, and it is flagged to their coach on the Member's profile so the coach stops collecting it. Billing records are kept as required by law. Anything else is removed within 30 days, except records the law requires us to keep.

9. International transfers

We are established in Denmark and your database is hosted in Ireland, both in the EEA. Some sub-processors (Anthropic, Stripe, Resend, Vercel, Apify where US-routed, and OpenAI, Google or xAI where a coach selects them) are US-based; transfers to them from the EEA/UK/Switzerland rely on Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. Kimi (Moonshot) processes in China, which has no adequacy decision: that transfer relies on Standard Contractual Clauses together with a transfer impact assessment, and only happens where a coach or Member selects it.

10. Changes

Material changes are emailed before they take effect. Minor changes update the date above.

11. Contact

For any privacy question, email audunn@realaudunn.com. We respond within 30 days. As Audunn is established in Denmark (EEA), no Article 27 representative is required.

Terms of ServicePrivacy PolicyData Processing AgreementCoach Guidance: collecting client data safely