Loading...
Loading...
Last updated:
Your privacy is important to us. This summary highlights key topics; the complete policy includes GDPR, CPRA, and COPPA detail.
For the full legal text (required for regulators and app-store review):
View Full Privacy PolicyWe collect information you provide directly to us, such as when you create an account, use our services, or contact us for support. If you enable Journal Handwriting OCR, we process handwriting images you choose to scan in order to convert them into editable journal text. OCR is optional and can be turned off in Privacy Settings.
We use the information we collect to provide, maintain, and improve our services, process transactions, and communicate with you.
We do not sell, trade, or otherwise transfer your personal information to third parties without your consent, except as described in this policy.
We implement appropriate security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.
You have the right to access, update, or delete your personal information. You can also opt out of certain communications from us.
When you photograph a handwritten journal page with the in-app "Transcribe handwritten page" button, the image is sent to our backend and processed by OpenAI's vision model for handwriting recognition. The transcribed text is shown to you for review before saving. **Images are not retained by default.** If you opt in via **Settings > Privacy > Journal Handwriting OCR** ("Help improve handwriting recognition"), we may store the image, AI draft transcription, and your corrected text as a private training pair to improve OCR accuracy. This opt-in is **off by default at launch**; when enabled, pairs are retained for up to **2 years**, then deleted or re-aggregated. This feature is available in the mobile app only.
Game Center may reorder suggested games using your gameplay history (and mood if provided) via our AI provider when **Personalization** and **Games & Activities** access are both enabled in Privacy Settings. Donny may reference recent game activity in chat when **Games & Activities** access is on. Turn either off in Settings → Privacy to use default catalog order and stop game-context in chat.
If you have any questions about this Privacy Policy, please contact Donny Wonny LLC at privacy@donnywonny.com. Our mailing address is 539 W. Commerce St #5827, Dallas, TX 75208.
If you are a resident of the European Economic Area (EEA), you have the right to: access your personal data, request erasure of your data (right to be forgotten), data portability (receive your data in a structured, machine-readable format), restrict or object to processing, and lodge a complaint with a supervisory authority. To exercise these rights, email privacy@donnywonny.com or contact our appointed EU representative below.
In accordance with EU GDPR Article 27, we have appointed an EU representative to handle inquiries from data subjects located in the European Union and European Economic Area. EU residents may contact our representative directly for any GDPR-related matters, including data subject access requests, deletion requests, and complaints. EU Representative: Euverify Ltd (Ireland) Unit 3D North Point House North Point Business Park New Mallow Road Cork, T23 AT2P Ireland Email: gdpr@euverify.com Secure verification + DSAR portal: https://gdpr.euverify.com/verify/a982def2-7d1a-46b3-bd09-b4789722d8d6
For UK residents, in accordance with UK GDPR (which continues to apply post-Brexit), we have appointed a separate UK representative to handle inquiries from data subjects located in the United Kingdom. UK Representative: Euverify Ltd (UK) 3rd Floor, 86-90 Paul Street London, EC2A 4NE United Kingdom Email: gdpr@euverify.com Secure verification + DSAR portal: https://gdpr.euverify.com/verify/a982def2-7d1a-46b3-bd09-b4789722d8d6
Under the California Consumer Privacy Act (CCPA), California residents have the right to: know what personal information is collected and how it is used, request deletion of personal information, opt out of the sale of personal information (we do not sell your data), and non-discrimination for exercising your privacy rights. To submit a verifiable consumer request, email privacy@donnywonny.com.
Donny Wonny is intended for users aged 13 and older. We do not permit accounts for children under 13 and apply a neutral age screen at sign-up that rejects any registration indicating an age under 13 — there is no under-13 account path. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will disable the account and delete that information promptly. Parents or guardians may contact us at privacy@donnywonny.com to request removal of their child's data.
When a verified guardian links a supervised minor's account (a family setup), the minor's direct messages are end-to-end encrypted with an additional 'escrow envelope' sealed to the guardian's identity key. Guardians decrypt supervised **direct messages**, **growth circles**, and **Encrypted Chat** locally in the **web Parent Portal** (donnywonny.com/dashboard) — our servers never hold plaintext. **Together Thread** is a separate server-readable group room. Safeguards: (1) every supervised E2E conversation displays a visible 'Your parent can read these messages' badge to the minor. (2) Guardian reads are written to the parental_audit log. Escrow can only be enabled by a verified guardian and cannot be silently changed.
If you signed up under parental supervision, you can request to lift supervision in the mobile app: Settings → Privacy → "Lift parental supervision". The request is sent to your guardian(s) with explicit Approve / Deny actions. Until they approve, supervision stays active. Requests auto-expire after 30 days, and you can re-request. **Self-attestation of age 18+ for immediate lift is not available in the app today** — guardian approval is required for all lift requests. After supervision lifts: you stay a member of your family group (you keep the shared family Donny and community access), but new direct messages and circle messages are no longer accessible to your guardian. **Important honest disclosure about historical messages:** messages you sent BEFORE the lift that were already accessible to your guardian via the parental escrow envelope remain decryptable on their device. This is a technical limit of end-to-end encryption — once a key has been used to decrypt content, that decryption cannot be retroactively undone, in the same way that any letter someone has already read cannot be made unread. Lifting supervision is forward-only protection. If you need a complete reset of all historical content, you can additionally delete your account and start fresh (Settings → Privacy → Delete account). Every step (request creation, guardian response, lift application) is written to your visible audit log.
Together groups expose **three separate messaging surfaces**: (1) **Shared Donny** — your private 1-to-1 AI thread (only you see it); (2) **Together Thread** — a shared, server-readable group room with @donny mentions, photos, and moderation (visible to all members; guardians may review in family shapes); (3) **Encrypted Chat** — Megolm end-to-end encrypted **text-only** messages between members. Growth circles also use Megolm E2E. Couples mode includes encrypted chat when enabled on the Together plan.
**Join-date scoping:** when someone joins an existing Together group, they see shared memories, activities, and group thread messages created on or after their join date — not content from before they joined. Existing members keep the full shared history. **Explicit consent:** inviters and invitees must acknowledge this before sending or accepting an invite; the group thread requires a separate opt-in before posting. **Archive on lapse:** when the Together **plan owner’s** subscription ends, the **Together shared stack** (Shared Donny, Together Thread, shared goals, shared memories, encrypted chat, group insights, group challenges, shared journals, and couple/family activities) is archived (hidden) for all members until the owner resubscribes — personal journals and personal Donnies are unaffected. **Free group connection, post feeds, and family safety tools** (parental controls, co-guardian, supervision) keep working unless that connection is ended. **Fresh start:** only the **plan owner** may reset the Together billing group, which permanently supersedes prior shared history and requires re-inviting members; this is irreversible.
Donny Wonny **growth circles** and **Encrypted Chat** on the Together plan use the Megolm group ratchet (Apache-2.0, same family as Matrix/Element). Your device encrypts messages before they leave; the server stores only ciphertext. **Together Thread** is intentionally server-readable for guardian visibility and @donny — do not use it for secrets. Other group chat surfaces remain server-readable unless E2E was explicitly enabled. Session keys rotate when a member leaves a circle or encrypted group. E2E translation requires a separate opt-in.
End-to-end encrypted direct messages are **not** keyword-screened on our servers — we cannot read ciphertext without breaking encryption. Safety relies on: user reports (with optional sample text you choose to include), behavioral metadata (such as message frequency patterns), optional **on-device safety metadata relay** from the mobile app when local keyword patterns match (counts and a hash only — not the message body), parental escrow for supervised minors via the **web Parent Portal**, and automated risk scoring on **server-readable** surfaces like Together Thread. High-risk signals may enqueue human review and, for supervised minors, parent alerts showing severity and alert type — not full message content unless you included it in a report.
We retain your personal data only as long as necessary to provide our services. Account data is retained while your account is active and for up to 30 days after a deletion request (grace period). Journal entries and user-generated content are deleted when your account is permanently removed. **Analytics:** raw event records are purged after **90 days**; anonymized daily rollups (event name + date + count only, no user IDs) are retained for **2 years**, then deleted. Payment records are retained as required by applicable tax law. You may request deletion at any time by contacting privacy@donnywonny.com.
We use the following third-party services to process your data: Firebase (Google) for authentication, database, and hosting; Stripe for payment processing; OpenAI for AI-powered features; Google Cloud Translation for the optional translate-on-display feature; SendGrid for transactional emails; and Sentry for error monitoring and crash reporting. Each processor is contractually required to protect your data in accordance with applicable privacy laws. Per OpenAI's API data usage policy, runtime conversation inputs and outputs (the prompts and replies during a normal chat) are not used to train OpenAI's foundation models. Separately, we may use highly-rated conversations to fine-tune our own custom Donny model — see the next section for full details + opt-out controls. We may add additional processors in the future and will update this policy accordingly.
Custom Donny model training is **disabled at launch**. When we enable it, only conversations you **affirmatively opt in** to share (Settings → Privacy → AI Training Preferences) may enter our training dataset — not automatic thumbs-up or engagement signals. Before any conversation enters that dataset it passes through a multi-stage PII redaction pipeline: (1) regex sweeps for email addresses, US + international phone numbers, US Social Security numbers, credit card numbers, ZIP codes, street addresses, and authentication tokens embedded in URLs; (2) your personal allow-list of names you've explicitly asked Donny to remember pass through unredacted; (3) named-entity recognition for people's names and organizations via an offline NLP library; (4) every original identifier is then stripped from the saved record — no user ID, no IP address, no granular timestamp (date only). The resulting record is anonymized. You can opt out at any time in Settings → Privacy → AI Training Preferences, delete conversations, or delete your account. Children's data (users under 13) is never used for AI training. **Teens aged 13–17** may opt in only when a verified parent has granted explicit consent; otherwise collection stays off. We can suspend the training pipeline platform-wide.
You can choose a preferred language in Settings ? Notifications & Translation and enable 'Auto-translate incoming content' to have user-generated text (posts, comments on posts and family activities, mentor bios, mentor circle posts and comments, direct messages, and supervised DMs visible in the Parent Portal) automatically translated when displayed to you. Translation requests are sent to Google Cloud Translation v3 (a Google Cloud sub-processor). To reduce cost and provider exposure for frequently-shared content, translated results are cached on our servers for 30 days, keyed by a SHA-256 hash of (source language, target language, text). The cache is content-keyed and is not associated with any individual user, so identical content posted by different users is translated only once. The original text is always preserved and a 'Show original' toggle is always available. End-to-end encrypted direct messages are NOT translated by default � translating an E2E message requires explicit opt-in, either via Settings ? Notifications & Translation ? 'Allow translation of end-to-end encrypted messages', or by long-pressing an encrypted message and choosing 'Always allow'. Both surfaces clearly disclose that translation sends the decrypted plaintext to Google Translation. You can disable auto-translation, revoke the E2E opt-in, or change your preferred language at any time in Settings. Because cache entries are not linked to any user account, individual cache entries cannot be deleted on request; all entries automatically expire 30 days after they are created.
Donny Wonny LLC is based in the United States and our entire production infrastructure runs in US-region Google Cloud Platform: cloud database in a US multi-region (Iowa, South Carolina, Oklahoma), cloud storage and application servers in Iowa. If you use Donny Wonny from the EU, EEA, UK, or any other country, your personal data is transferred to the United States for processing and storage. We do not operate separate regional data centers. We rely on the following lawful transfer mechanisms, layered for defense in depth: (1) The EU-US Data Privacy Framework (DPF) � adopted by the European Commission in July 2023 and used by our US-based sub-processors that are DPF-certified (Google Cloud, Stripe, Vercel). DPF certification provides an adequacy decision under GDPR Article 45. (2) The UK Extension to the EU-US Data Privacy Framework (the 'UK Data Bridge') � active since October 2023 � provides the equivalent adequacy basis for UK residents under UK GDPR. (3) Standard Contractual Clauses (SCCs) � the 2021 EU Commission-approved modules � incorporated into our data-processing agreements with sub-processors that are NOT DPF-certified (currently OpenAI, SendGrid/Twilio, RevenueCat, Sentry). For UK transfers, the UK ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs applies. EU and UK data subjects retain all GDPR rights regardless of where their data is processed and may exercise those rights via our appointed Article 27 representatives (see the EU and UK GDPR Representative sections above) or directly via privacy@donnywonny.com.
In the event of a data breach that poses a risk to your rights and freedoms, we will make every effort to notify affected users within 72 hours of confirming the breach, in accordance with GDPR requirements. Notifications will be sent via email to your registered address. We will also notify the relevant supervisory authorities as required by law. Our team will investigate, contain, and remediate any breach and provide information about what data was affected and steps you can take to protect yourself.
To provide a more personalized experience, Donny Wonny uses AI to generate periodic summaries of your conversation history with your Donny companion. These summaries ("memory") are stored on your account and used to inform future AI responses. Memory summaries are derived from your conversations and stored in our secure database. You can request deletion of all AI memory data at any time by contacting privacy@donnywonny.com. Memory data is included in any account export or deletion request.
Donny Wonny reads your mood check-in history (scores and labels you voluntarily enter) to adjust the tone and personality of your AI companion � for example, a more playful tone when you've been feeling great, or a calmer, more supportive tone during harder weeks. This analysis is performed automatically using data you submit and is used solely to improve your in-app experience. This data is not sold or shared with third parties.
If you have notifications enabled, Donny Wonny sends a weekly recap summary via push notification and email, containing statistics about your activity (messages sent, mood entries, streaks). You can opt out of weekly recap emails at any time by visiting your notification settings at donnywonny.com/settings/notifications, replying "unsubscribe" to any recap email, or updating your preference in the mobile app. Your opt-out preference is saved to your account and respected immediately.
During onboarding, we collect optional preferences such as your personal growth focus area, preferred check-in time, current goal, and notification preference. This information is stored on your account and used to personalize your Donny companion's responses and your app experience. You may update or delete these preferences at any time from your profile settings.
When you create or join a Spark Hub (a creator's themed content channel), we store your membership status, join date, and the Hub identifier. Spark Hub creators' display names and taglines are publicly visible. The list of Hub members is visible only to the Hub owner. Joining or leaving a Hub updates an aggregate member count but does not disclose your identity to other members. You may leave any Hub at any time, which immediately removes your membership record. Note: Spark Hubs are separate from the "Together" group plan tier described elsewhere in this policy; the latter is a private shared space for up to six family or friend members and has its own data-handling rules.

EU and UK data subjects: our appointed Article 27 representative is Euverify Ltd. Click the badge above to verify our status or submit a Data Subject Access Request (DSAR), deletion request, or other GDPR inquiry through their secure portal.
We're here to help you understand how we protect your data.
Donny Wonny LLC · 539 W. Commerce St #5827, Dallas, TX 75208 · privacy@donnywonny.com
Contact Us