Last updated: 2026-08-19
This policy describes how Audunn handles data. For your own account and workspace, Audunn is the controller. For your Members' personal data, Audunn is your processor and you (the coach) are the controller, so your Members should read your own privacy notice, not this one, for how their data is used.
Audunn is operated by Audunn, Jarlsberggade 5B, 4.2, 5000 Odense C, Denmark. Contact: audunn@realaudunn.com.
We do not use tracking cookies, third-party analytics, or advertising identifiers.
Where a coach's agent collects health and lifestyle information from a Member, for example body weight, food and nutrition, sleep, mood, injuries, or training logs, we store and process that information on the coach's instructions, as their processor, to run the coaching the Member signed up for. This is "data concerning health" under GDPR Article 9, and we treat the whole tracker and chat as such. Every chat message, including any health information it contains, is sent to the AI provider the coach has selected, to generate the agent's reply. Claude (Anthropic) is the default and the recommended choice. A coach, or a Member using their own key, may instead select OpenAI, Google Gemini, Kimi (Moonshot) or Grok (xAI); section 5 lists each one and where it processes data. Anthropic and OpenAI do not train on API inputs or outputs by default. Other providers' terms differ, and a provider's free tier in particular may be used to improve their models, so read the terms of any provider you enable before you enable it. The coach is responsible for obtaining the Member's explicit consent to this, and the platform provides a consent step for that purpose.
When you deploy an agent to Members you are the data controller for their personal data and we act as your processor. The Data Processing Agreement governs this. You are responsible for your Members' privacy notice, consent, and data-subject requests (we give you export and delete tooling).
Our staff may access a coach's workspace, and sign in to a Member account within it, only to fix problems (see the Terms) or to investigate a security or integrity issue. This access is least-privilege, logged, and visible to the coach. Members are told about this possibility through their coach's privacy notice.
One strictly necessary cookie keeps you signed in. No analytics or tracking cookies.
| Provider | Purpose | Location | Transfer basis (from EEA/UK) |
|---|---|---|---|
| Anthropic | Claude AI responses (via your key), the default | United States | SCCs + EU-US DPF |
| OpenAI | GPT responses, only if you select it (via your key) | United States | SCCs |
| Gemini responses, only if you select it (via your key) | United States | SCCs | |
| Moonshot AI | Kimi responses, only if you select it (via your key) | China | SCCs + transfer impact assessment |
| xAI | Grok responses, only if you select it (via your key) | United States | SCCs |
| Supabase (on AWS) | Database, auth, storage | Ireland (EU) | Not applicable |
| Vercel | Application hosting | United States | SCCs + EU-US DPF |
| Stripe | Payment processing | United States | SCCs + EU-US DPF |
| Resend | Transactional email | United States | SCCs |
| Unipile | DM sync (LinkedIn/Instagram/WhatsApp/Telegram), where enabled | EU | Not applicable |
| Apify | Content statistics, where enabled | EU/United States | SCCs |
| Telegram | Bot messaging, where a coach enables it | International | see note |
We are bring-your-own-key. Claude is the default and no other AI provider receives anything unless a coach or Member deliberately selects it and supplies their own key for it. Selecting Kimi (Moonshot) sends data to a provider in China, which has no EU adequacy decision; a coach choosing it takes on that transfer as controller and should say so in their own privacy notice. Telegram is an optional messaging channel a coach may switch on; it does not offer a standard processor agreement, so a coach enabling it should treat messages sent over it accordingly and disclose it to Members. We verify each provider's current transfer basis at go-live.
Passwords hashed by Supabase Auth. Your Anthropic key encrypted at rest (AES-256-GCM). All connections use TLS/HTTPS. Database encryption at rest via Supabase. Support access is least-privilege and logged.
You can export your data from the app at any time. Members delete their own account from Account; creators ask us to close a workspace and we action it within 30 days. If you are in the EEA, UK, Switzerland, or California, you have additional rights under GDPR or CCPA/CPRA; contact us to exercise them. A Member exercising rights over their own data should contact their coach, who is the controller.
We keep your account data until the account is deleted. A Member deleting their account removes their data immediately. A Member who withdraws health-data consent has that recorded, and it is flagged to their coach on the Member's profile so the coach stops collecting it. Billing records are kept as required by law. Anything else is removed within 30 days, except records the law requires us to keep.
We are established in Denmark and your database is hosted in Ireland, both in the EEA. Some sub-processors (Anthropic, Stripe, Resend, Vercel, Apify where US-routed, and OpenAI, Google or xAI where a coach selects them) are US-based; transfers to them from the EEA/UK/Switzerland rely on Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. Kimi (Moonshot) processes in China, which has no adequacy decision: that transfer relies on Standard Contractual Clauses together with a transfer impact assessment, and only happens where a coach or Member selects it.
Material changes are emailed before they take effect. Minor changes update the date above.
For any privacy question, email audunn@realaudunn.com. We respond within 30 days. As Audunn is established in Denmark (EEA), no Article 27 representative is required.