Emotional CompassMy diary
To the compass

Privacy

Updated 6 September 2026

This is what you trust us with about your state. So, briefly and without evasions: what is stored, where exactly, who sees it, and how to erase everything in one move.

The short version

  • Only you can see your entries. Neither I nor anyone else can reach them through the site.
  • There are no visitor counters, no ads and no tracking on this site at all.
  • There is no password — so there is nothing to steal.
  • You can delete your whole history yourself, with one button in the diary, without writing to anyone.

Below is the same thing in the detailed, formal form GDPR asks for.

Who is responsible for your data

The data controller is Yuliia Bodnar, a private individual, Romania.

Questions about your data, requests for a copy or for deletion — privacy@eviora.app. I answer personally, usually within a few days; the law allows a month.

What is stored

While you are simply going through the compass and saving nothing, nothing that points to you reaches the database.

When you save a state to the diary, what is stored is:

  • your email address — only to send you a sign-in link and to recognise you next time;
  • the compass position: three axes, depth, the "mix of emotions" mark;
  • your answers to the clarifying questions;
  • the name of the emotion the compass showed;
  • when the entry was made and which moment the state belongs to;
  • your note, if you wrote one.

If you wrote a note before signing in, it waits separately for up to a day — otherwise it would be lost every time an email is opened in another browser or on another device. Nobody can read it there, myself included: there is no read access to it at all. As soon as you sign in, the note moves into your entry and disappears from the waiting area.

Separately, and with no link to you whatsoever, the fact that the compass showed you a result is stored: the compass position, the clarifying answers and the name it gave. This is recorded every time, even if you tap nothing further — otherwise I would only ever see the people who bothered to answer, and would believe the compass to be more accurate than it is.

Twice — at the start and on the result screen — the compass asks how clear you are about what you are feeling. Both answers go into the same anonymous record: the difference between them is the only way to see whether the compass helps at all. It is a number from 1 to 5, with no text about you.

If you answer the "Was it accurate?" question, your answer is stored alongside. None of these questions are required: then only what was shown remains.

That record contains no email, no identifier and no note — not even I can tie it back to a person. The only thing in it is a random key for a single run of the compass: it exists solely so two answers from the same run are not counted as two separate visits, it lasts exactly that run and is never stored anywhere. This is the data the accuracy of the compass is tuned on.

If you tapped "Let me know when it is ready", your email, interface language and the number of entries you had at that moment are stored.

The hosting and database keep technical request logs: IP address, time, browser type. These are standard server logs kept for security and diagnostics; they are short-lived and I do not use them to identify anyone.

The hosting also counts visits: which page was opened, which site you came from, country and device type. This is how I see whether people find the compass at all. The counting is done by the same Vercel that serves the pages — no new company is involved. These counts are not linked to your account or to the emotion the compass showed: they contain nothing but the page address.

What is stored in your browser

There are no advertising or analytics cookies — none. Visit counting works without them too: it writes no cookies and nothing into browser storage, so there is nothing to ask consent for.

Browser storage (localStorage) holds two things: the fact that you are signed in, and a state waiting to be saved if you requested a link but have not followed it yet. Both disappear when you sign out or clear the site data.

Why, and on what legal basis

Under GDPR an emotional history is a special category of data, close to health data (Art. 9). So the basis here is not "legitimate interest" but your explicit consent.

  • The diary and sign-in — to provide what you came to use: contract (Art. 6(1)(b)) together with your explicit consent for a special category of data (Art. 9(2)(a)), which you give when you save your first state.
  • The anonymous statistics of results shown, of the "Was it accurate?" answers and of the two clarity answers — to make the compass name states more precisely and to let me see whether it actually helps. This data is anonymised, so GDPR no longer applies to it.
  • The list for the full version — your consent, given by tapping the button.
  • Technical logs and visit counting — legitimate interest: keeping the site running, unbroken, and knowing whether anyone needs it (Art. 6(1)(f)).

You can withdraw consent at any time: delete your entries or write to me. Withdrawal does not make what happened before it unlawful.

How long it lives

Diary entries — until you delete them yourself. There is no automatic cleanup: the history is the value, and it should not quietly evaporate.

Deleting the account removes all your entries at once — that is built into the database, not into my memory of things not to forget.

The anonymous statistics remain — nothing "yours" can be erased from them, because nothing of yours is in them.

Who else touches this data

I do not sell or hand your data to anyone. But the site does not hang in mid-air — three providers keep it running, each with one narrow role:

  • Vercel — site hosting;
  • Supabase — database and link sign-in; server in Frankfurt, Germany;
  • Resend — delivery of the sign-in emails.

And, plainly, about me. The service shows me nobody else's diary — there is simply no such screen. But I do have technical access to the database itself, because without it the database cannot be maintained: fixing a bug, making a backup, carrying out your deletion request. That is what I use it for, not for reading.

All three act as processors: they may not use this data for their own purposes. Diary data sits in the EU and does not travel beyond it. Sign-in emails pass through Resend infrastructure, which may sit outside the EU; that email contains nothing but your address, the link and an emotion identifier — notes never go into email.

Personalized guidance

If you order personalized guidance, you write in the form what happened. That text is read by a living person — me — in order to write you a reply. That is the main thing to know, and it is exactly what the separate checkbox is for: not consent to “processing”, but consent to someone reading your words.

Stored along with the text: your email, your language, the emotion the compass named, the price and the order number.

The guidance is built only from what you wrote in that form. Your diary is not opened for it — there is no link between an order and your entries in the database itself, so looking there is not possible even by accident.

Nobody can read an order through the site, including you: you get the confirmation on screen and by email, not by querying the database.

30 days after the guidance is sent, the text of the order is erased. What remains is the fact of the purchase: date, amount and number — needed for accounting and to answer “what did I actually order”.

Payment is handled by Paddle, a separate company acting as payment processor. It sees your email and the amount and the order number; it never sees the text you wrote. Card details are not seen by me either: they never pass through Eviora at all. That company's script runs on the payment page only — nowhere else on Eviora. On the pages where you describe your state it is absent entirely: it learns about you only when you go to pay.

Your rights

Under GDPR you have the right to:

  • know what is stored about you and receive a copy;
  • correct anything inaccurate;
  • delete everything — yourself or through me;
  • take your data in a portable form;
  • withdraw consent;
  • object to processing and ask for it to be restricted.

The fastest route for the first three is the diary itself. For the rest — privacy@eviora.app.

If you feel your data was handled badly, you have the right to complain to a supervisory authority. In Romania that is ANSPDCP (dataprotection.ro), but you may also complain to the authority in your own country.

How to delete everything right now

Sign in to the diary and tap "Delete all entries". It is final and needs no confirmation from me.

To remove the account and the email address with it — write to privacy@eviora.app from the address it is registered to.

Age

This service is not intended for children under 16. I deliberately do not collect age data — which means I cannot verify this and rely on your honesty.

If something changes

The date of the last update is at the top of this page. If something material changes — what is collected, why, or who sees it — I will tell you by email or with a visible notice on the site, not with a quiet edit.