Introduction
Welcome to Donny Wonny ("we," "our," or "us"). We are committed to protecting your privacy and ensuring you understand how we collect, use, and safeguard your personal information.
This Privacy Policy applies to the Donny Wonny mobile application, website, and all related services (collectively, the "Services"). By using our Services, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Information You Provide
Account Information:
- Email address
- Username/display name
- Password (stored using industry-standard one-way hashing; we never see or store the plaintext)
- Age attestation — at first launch you enter your age (for example,
16) to confirm you meet the minimum age for your region. We do not require your full date of birth for global signup. If you optionally provide a date of birth during registration, we use it only for age eligibility and minor protections. - Profile picture (optional)
User-Generated Content:
- Journal entries (encrypted at rest on our servers — not end-to-end encrypted; see Cloud-Synced Wellness Data and §4.1.0)
- Mood tracking data
- Goals and achievements
- Donny AI conversation history
- Creative works (art, stories, scrapbooks)
- Community posts and comments
- Voice journal audio recordings (processed for transcription, then immediately deleted — not stored)
Donny Appearance Preferences:
- When you use Customize Donny, we store your equipped accessories (up to three at a time), aura color theme, hoodie color, and any outfit, room, or animation packs you have applied
- These choices are private to your account, synced to our servers for cross-device use, included in data export, and deleted when you delete your account
- Hoodie and aura selections are cosmetic only and are not visible to other users
Donny camera features (on your device only):
- Eye tracking (not offered at launch): When enabled in a future release, optional on-device front-camera face detection may animate Donny's gaze. Frames would stay on your device and would not be uploaded.
Engagement Features Data:
- Challenge participation progress and completion data
- Badge/title awards and display preferences
- Community comment threads and emoji reactions
- Notification frequency preferences (per-category: instant, daily digest, weekly digest, or off — managed in Settings → Notifications)
- Pending digest notifications queued for delivery (title, body, category, channel, dispatched flag) — auto-deleted within 30 days of send
- Rewards marketplace redemption history
- Growth Points earn ledger (action type, amount, timestamp — used for balance integrity and abuse review)
- User matching interests and bio (opt-in "Find Your Pod" feature — you choose what to share)
- Live canvas collaboration: when you opt in to draw with collaborators on artwork (Creative Studio or project-linked art), stroke data, cursor positions, undo/clear actions, and layer state may be transmitted in real time via our servers to other invited editors in the session; saved artwork and auto-generated PNG thumbnails are stored in your account
- AI-generated journal prompts (based on mood tags, time of day, and goal titles — no raw journal text sent to AI)- Bug reports (title, description, reproduction steps, severity, and automatically detected device/platform information submitted with the report) Social Features Content:
- Journey data: When you set a Journey to public, your progress score breakdown (consistency, volume, completion, streak momentum, milestones) and activity statistics are visible to all users. Private Journeys are not shared. You control this setting per Journey.
- Spark Series data: When you create a Spark Series, the title, description, daily spark challenges, category, difficulty, and your display name are visible publicly. Your subscribers' individual day-by-day progress is private.
Family/Group Information:
- Group connections (with consent)
- Group membership information
- Family dashboard settings
- Parental control preferences
Social & Collaboration Data:
- Friend connections and friend request history
- @Mentions in posts and comments (who you tagged and who tagged you)
- Collaborative project membership, roles, and content contributions
- Project invitations sent and received
Cloud-Synced Wellness Data:
- Journal entries, mood check-ins, streaks, and habit tracking data are synced to our servers to enable cross-device access and prevent data loss
- Journal entry text may be screened on our servers with the same automated keyword-based safety rules used for Let It Out (not a medical assessment) so we can surface crisis resources when appropriate — and, if you are a supervised minor and a medium or high crisis level is detected, your linked parent/guardian may be notified (crisis level and source only — not your journal text). Journal entries are not end-to-end encrypted — they are encrypted at rest on our servers.
- Private journal text is sent to our servers for crisis screening even when you have not shared the entry with Donny. When you create or update a journal entry, up to approximately the first 4,000 characters of the entry text are transmitted to our crisis-screening endpoint for automated safety classification, regardless of your "share with Donny" setting. The text is used for classification only; safety alerts never include your journal content.
- XP, levels, coins, and progression data are synced to our servers (server is the source of truth for progression)
- Habit definitions, completion logs, and statistics
- This data is encrypted in transit and at rest. Account access controls limit who can open your wellness records; our servers may run automated crisis keyword screening on journal text as described above (this is not a medical assessment and does not make journals end-to-end encrypted)
Let It Out (Venting) Data:
- When you use the "Let It Out" feature, your venting text (free for all users) or voice (Premium or redeemed physical journal code — recorded on device, transcribed on our servers, audio deleted after transcription) and selected emotions are screened with automated keyword-based safety classification on our servers to assign a crisis level (low / medium / high) and surface supportive copy and hotline resources when appropriate. This is not a medical assessment.
- We store session history (emotion, type, duration, timestamp, and crisis level). We do not store your full vent text in session history — only metadata needed for your history list.
- If a medium or high crisis level is detected for a supervised minor, linked parent/guardian accounts receive a safety alert containing only the crisis level and source (not the vent text), via email, push notification, and/or the parent notification inbox. Medium-level alerts follow the family's notification settings; high-level safety alerts are always delivered regardless of notification preferences — a deliberate child-safety design (see Crisis Safety Signals below).
- Emergency resources (such as the 988 Suicide & Crisis Lifeline) may be surfaced automatically when a high crisis level is detected.
Crisis Safety Signals & Emergency Contact:
- Automated crisis screening runs on three sources: Let It Out vent text, journal entries (including entries not shared with Donny — see Cloud-Synced Wellness Data above), and Donny chat messages. A medium or high crisis signal from any of these sources may trigger the parental/guardian safety alerts described above for supervised minors. Alerts contain the crisis level and source only — never the underlying text.
- High-level safety alerts to guardians of supervised minors are always delivered regardless of family notification preferences. Medium-level alerts respect the family's notification settings. This always-deliver behavior for high-level signals is a deliberate child-safety choice and cannot be disabled.
- Emergency contact (opt-in): You may optionally designate one emergency contact by providing their name and email address in Settings → Privacy → Donny AI Privacy. If you enable this feature and a high-level crisis signal is detected from any of the three sources above, we send your designated contact an email that identifies you by name and states that our safety tools detected a high-level distress signal (including which feature it came from, e.g. "Journal" or "Donny Chat"). The email never includes your journal, vent, or chat content. This feature is off by default; see §3.8 for how this data is shared. You can change or remove your emergency contact, or turn the feature off, at any time in the same settings screen.
Phone Verification Data:
- If you choose to verify your phone number, we collect your phone number and send a one-time verification code via SMS
- Your phone number is stored in hashed form and is used only for account verification and security purposes
- We do not use your phone number for marketing or share it with third parties
Offline Cache & Background Sync Data:
- When your device is offline, we temporarily store pending actions on your device using encrypted local storage. This includes journal entries, spark completions, achievements, goals, and Donny chat messages you send while offline (queued for server processing when connectivity returns).
- Offline Donny chat: When you send a message without connectivity, Donny may reply using on-device fallback responses (not full AI). Your message is queued locally and sent to our servers for AI processing when you reconnect.
- When connectivity is restored, a background sync service automatically uploads pending data to our servers. This may occur while the app is not in the foreground.
- Offline cached data is cleared upon successful sync or upon logout
- Background sync does not collect any new data — it only transmits previously queued actions
Language & Locale Preferences:
- Your selected language preference is stored locally on your device (encrypted)
- We support 8 languages: English, Spanish, French, German, Japanese, Arabic, Korean, and Chinese
- Your device locale may be automatically detected to suggest a default language; this detection happens locally and is not transmitted to our servers
Payment Information:
- Web payments are processed by Stripe; mobile in-app purchases are processed by Apple App Store (iOS) and Google Play Store (Android) via RevenueCat
- We store only: subscription tier, status, and transaction IDs
- We do NOT store credit card numbers or banking details
- Apple and Google handle all payment method data for in-app purchases; we never receive your card details for those transactions
Product Catalog & Virtual Currency Data:
- Purchase history for customization packs (outfits, animations, rooms), content packs (wellness toolkits, meditation programs), and virtual currency (Donny Coins and Gems)
- Virtual currency balances (coins and gems) and transaction history (credits, debits, purchase source)
- We store: product ID, category, price paid, purchase timestamp, and Stripe session ID
- Virtual currency transactions are recorded for balance accuracy and dispute resolution
Refund Request Data:
- Refund requests store: user ID, requested amount, eligible amount, reason, status, and timestamps
- Support notes (free-text refund correspondence): retained for 90 days after the refund is closed, then anonymized
- Transaction-linked refund and chargeback ledger fields (amount, date, status, Stripe/RevenueCat/processor IDs): retained for 7 years for accounting, tax, and dispute resolution
- After the 90-day support window, narrative refund notes are anonymized; aggregate refund statistics may be retained longer without identifiers
Donny Den (Themed Community Rooms) Data:
- When you create or join a Donny Den themed community room, we collect the room name, description, theme, rules, and your membership role (owner or member)
- Text posts in a Donny Den room feed are stored on our servers and encrypted at rest. Donny Den room content is not end-to-end encrypted (unlike E2E-enabled direct messages, growth circles, and Encrypted Chat — see §4.1.1)
- Optional room chat (when enabled) follows the same server-readable model
- Room membership lists are visible to other room members. Public rooms display name, description, theme, and member count in Discover
- Room moderation actions (warnings, mutes, bans) are logged for abuse prevention
- If you are a minor (under 18), age-restricted rooms are not accessible to you
Together / Family Plan Data:
- The Together plan (
groupsSKU) is a paid family subscription — separate from Donny Den community rooms - Family linking, parental controls, Together Thread, Encrypted Chat, and supervision features are described in §4.1.1 and the Family sections of this policy
Peer Mentorship & Live Sessions:
- Mentor profiles, bookings, payouts, and circle membership are stored on our servers
- Live audio/video mentorship calls are delivered through a third-party communications provider (currently Daily.co, Inc.). Session signaling and metadata are processed on our servers; call media is not end-to-end encrypted like direct messages
- Optional session recording requires active opt-in from both the mentor and the booking mentee for that specific session; either party may withdraw consent before or during the call, which stops recording immediately
- Mentor circle posts, comments, and feeds are server-readable (encrypted at rest, not E2E) and may be screened with automated moderation rules
- AI-generated session summaries (covered by the booking platform fee, not sold separately) process transcript text from sessions where both parties opted in to recording; summaries are stored in your account per our Terms §17
Primitive Voice & Video Calls:
- Members may start optional voice or video calls within Donny Den, Group, Couple, or Family primitives when they are a member of that space
- Calls use the same third-party communications provider as mentorship sessions (currently Daily.co, Inc.). Session signaling and metadata are processed on our servers; call media is not end-to-end encrypted
- Calls require membership in the primitive; we log call start/end metadata for abuse prevention and rate limiting
- You may end a call at any time. Connection quality is not guaranteed
Merchandise Store Data:
- When you browse or purchase physical or digital merchandise, we collect: items viewed, items added to cart, purchase history, shipping address (for physical items), and order status
- Shipping addresses are stored only for the duration needed to fulfill and deliver your order, plus 90 days for returns/disputes, and are then permanently deleted
- Payment for merchandise is processed through Stripe (see Payment Information above); we never store your card details
Print-on-Demand Vendors (Data Processors):
- Physical merchandise is fulfilled by third-party print-on-demand providers — currently Printful, Inc. (apparel, accessories, posters) and Lulu Press, Inc. / Lulu Direct (books, journals, printed paper goods).
- For each physical order, we transmit the following minimum data to the relevant vendor: your name, shipping address, email address (for shipping notifications), the SKU of the item ordered, and a unique order reference. We do not share your Donny Wonny account ID, in-app activity, journal entries, or any companion-related personal data with these vendors.
- The vendors send signed webhook events back to us reporting fulfillment status, tracking numbers, and any cancellations or returns. We retain a separate fulfillment audit log (not linked to your journal or companion data) for fraud prevention and refund processing, with each vendor event de-duplicated by event ID.
- Each vendor processes your data under its own privacy policy: Printful — https://www.printful.com/policies/privacy; Lulu — https://www.lulu.com/about/privacy.
- You may request that we delete your shipping address from our systems after the 90-day returns window by contacting privacy@donnywonny.com.
Games & Mini-Games Data:
- When you play games or mini-games within the app, we collect: game scores, completion status, time played, and any virtual rewards earned
- Game data is used to award XP, coins, and badges and to track your progress
- Leaderboard participation is optional; if you opt in, your display name and score are visible to other players
- Game performance data may be used in anonymized aggregate form to improve game balance and design
1.2 Information Automatically Collected
Device Information:
- Device type and model
- Operating system version
- Unique device identifiers
- Mobile network information
- Device fingerprint (used solely for ban evasion prevention — see Section 2.5)
Usage Data:
- Features used and interaction patterns
- Session duration and frequency
- App performance and crash reports
- Clickstream data
Location Data:
- General location (city/region) based on IP address
- Precise location only if explicitly granted (for location-based features)
Local Weather Context (opt-in only): If you enable Local Weather in Settings → Privacy, the app reads your device location, rounds it to approximately city-level precision (~1 km), and sends only those rounded coordinates to Open-Meteo (a weather data provider) to look up current conditions. No account identifier is sent with the request. We use the resulting weather conditions to:
- show local conditions on your Home screen;
- attach the observed weather and a coarse place label (e.g., "Chicago, US") to mood check-ins you save, for your own mood-pattern insights;
- optionally personalize notifications; and
- give your Donny companion ambient awareness in chat (only a short weather-condition phrase such as "it's rainy where you are" is included in the AI request — never your coordinates or place name).
Weather data is cached on your device for at most 45 minutes. Turning Local Weather off stops all of the above immediately and deletes the cached weather data from your device. Precise GPS coordinates are never stored in your history or shared with the AI provider.
Network Information (for platform integrity):
- IP address at time of login and registration (used solely for ban evasion prevention — see Section 2.5)
People search (friends, projects, circles, DMs):
When you search for someone to invite or message in the app, we match @username (prefix) and display name (substring). Email addresses are never searchable — not for friends, projects, circles, couples, family invites, or direct messages. Results show only public profile fields (name, username, avatar, bio excerpt) subject to age and discoverability settings.
1.3 Information from Third Parties
- Social media profile information (if you choose to connect accounts)
- Authentication data from Firebase Authentication
- Payment confirmation from Stripe
2. How We Use Your Information
2.1 To Provide and Improve Services
- Create and manage your account
- Deliver personalized AI companion experiences
- Generate mood insights and analytics
- Provide journaling and wellness features
- Enable family/group features (Connections, Together)
- Enable Donny Den themed community rooms and public Journeys
- Fulfill merchandise orders and manage shipping/returns
- Provide in-app games, track scores, and award virtual rewards
- Process payments and manage subscriptions
2.2 For Safety and Security
- Detect and prevent fraud or abuse
- Enforce our Terms of Service
- Protect against security threats
- Monitor for crisis language (for safety interventions)
- Verify user age for COPPA compliance
- Enforce permanent bans and timed suspensions (see Section 2.5)
- Prevent ban evasion via IP address and device fingerprint matching
2.3 For Communication
- Send important service updates
- Respond to customer support requests
- Notify you of new features or changes
- Send promotional communications (with your consent)
2.4 For Analytics and Research
- Understand usage patterns
- Improve AI models and recommendations
- Conduct anonymized research
- Generate aggregate statistics (never personally identifiable)
2.4.1 AI Training Data & Your Control
We may use anonymized conversation data and interaction patterns to fine-tune our custom Donny model. You have full control over whether your future conversations are eligible:
-
Opt-Out by Default (Affirmative Opt-In Required): New users are opted out of AI training. The onboarding flow shows a dedicated AI Training Consent modal where you must affirmatively toggle ON to participate. This matches GDPR's "freely given, specific, informed" consent standard and the CCPA / CPRA opt-in expectation for sensitive uses.
-
Easy Opt-Out: If you previously opted in, go to Settings > Privacy (mobile app or donnywonny.com/settings/privacy) to opt out anytime with one tap.
-
What Happens When You Opt Out:
- Your future conversations and journal entries will NOT be added to the training dataset.
- Only anonymized aggregate statistics (e.g., "users in age group 25-34 prefer evening journaling") may be used.
- Your personalized experience continues normally.
- You can change your preference anytime.
-
How We Protect Training Data:
- Before any opted-in content enters training, we remove or de-identify direct identifiers (such as account IDs, contact details, and precise timestamps) and apply automated and manual review steps designed to prevent re-linking to your account.
- The saved record contains no user ID, no IP, and no granular timestamp — only de-identified text plus date-only metadata where applicable.
- Data is encrypted in transit (TLS 1.2+) and at rest on our servers.
- OpenAI is our fine-tuning provider. We configure OpenAI organization Data Controls so API inputs/outputs are not used to train OpenAI foundation models.
- Training datasets are stored in a segregated, anonymized dataset that is never linked or joined back to your account or profile.
-
Retention: Anonymized training records are retained for up to 5 years, then deleted or re-aggregated on a rolling schedule. Records contain no user ID, IP, or granular timestamp — only de-identified text plus date-only metadata. When you delete underlying conversations or your account, source personal-data records are removed before any further de-identification, so no new excerpts are produced from your account. If you previously opted in and later opt out, we stop adding new records; existing anonymized rows age out under the 5-year schedule. Because rows in the anonymized corpus are not linked to an account, individual corpus rows generally cannot be located for deletion on request once ingested; this is permitted under GDPR Recital 26 and the CCPA de-identification framework when data is truly anonymized. Counsel review is required before the training pipeline is enabled in production.
2.4.2 Donny Profile Memory & Birthday Personalization
Donny may use profile details you explicitly provide (such as your display name and birthday month/day from signup) to personalize conversations — for example, greeting you by name or wishing you a happy birthday on your birthday. These facts appear in Settings > What Donny Remembers and are stored as system memory facts, not extracted from chat.
- Chat memory (opt-in): Automatic fact extraction from Donny conversations is off by default. Turn it on in Settings > Privacy (mobile app or donnywonny.com/settings/privacy) if you want Donny to learn additional short facts from chats.
- Deletion: You can delete any memory fact in the app, or delete your account to remove all personal data per our Data Deletion page.
2.4.3 Photo Transcription (Handwriting OCR) for the Donny Wonny Guided Journal
When you photograph a handwritten journal page using the in-app "Transcribe handwritten page" button, the image is uploaded over TLS to our backend and sent to OpenAI's vision-capable model for handwriting recognition. The transcribed text is returned to you so you can review and edit it before saving.
- Image storage: By default, the raw photo bytes are NOT retained after transcription completes. We may retain a non-identifying reference for abuse prevention only.
- Vision learning (opt-in only): If you have opted in via Settings > Privacy > Journal Handwriting OCR in the mobile app (Help improve handwriting recognition), we may store the image, the AI's draft transcription, and your final corrected text together as a private training pair. This is used solely to improve OCR accuracy and is excluded by default for new users. This feature is disabled at launch; when enabled, pairs are retained for up to 2 years, then deleted or re-aggregated. (Not available on the website.)
- Revocation: You can disable this at any time in the same settings panel. Pre-existing training pairs can be deleted on request via privacy@donnywonny.com.
2.4.4 Voice Transcription (Whisper) for Journal Entries
When you tap the microphone button to dictate a journal entry, the audio clip is uploaded over TLS to our backend and sent to OpenAI's Whisper model for speech-to-text. The transcript is returned to you so you can review and edit before saving.
- Audio storage: By default, audio is NOT retained after transcription. Only the transcript text and an audio length value are kept (the transcript is part of your journal entry; the length is used for analytics and abuse prevention).
- Voice learning (opt-in only): If you have opted in to Help improve voice transcription in Settings > Privacy on the mobile app, we may store the audio + corrected transcript pair to improve our models. Off by default. (Not available on the website.)
- Revocation: Disable any time in Settings > Privacy (mobile app or donnywonny.com/settings/privacy).
2.5 Ban Evasion Prevention
When a user is permanently banned for violating our Terms of Service, we record their IP address and device fingerprint at the time of the ban. These identifiers are stored in separate security records and are checked during registration and login to prevent the banned user from creating new accounts.
What we store:
- IP address (stored as a one-way hash) linked to the banned user ID
- Device fingerprint (stored as a one-way hash) linked to the banned user ID
- Timestamp and reason for the ban
What we do NOT do:
- We do NOT use device fingerprinting for advertising, tracking, or analytics
- We do NOT share banned identifier data with third parties
- We do NOT fingerprint users who are in good standing
Retention: Banned identifier records are retained for as long as the associated ban is active. If a ban is lifted by an admin, the corresponding identifier records are removed. Appeals can be submitted through the platform (see our Terms of Service §3.5 for the appeals process).
3. How We Share Your Information
3.1 We Do NOT Sell Your Personal Data
We do not and will never sell your personal information to third parties.
3.2 Service Providers
We share data with trusted service providers who assist us:
- Firebase/Google Cloud: Authentication, database, hosting
- Stripe: Web payment processing
- SendGrid (Twilio Inc.): Transactional email delivery (e.g., welcome emails, receipts, security alerts, purchase confirmations)
- Apple App Store / Google Play Store: Mobile in-app purchase processing (iOS and Android subscriptions)
- RevenueCat: Mobile subscription management and lifecycle events (does not store payment method data)
- Didit (Didit Pte. Ltd.): Age assurance verification for users in regions that require it (AU/MY ARSMP and similar). We send verification session metadata only — not journal or chat content.
- OpenAI: AI conversation generation (encrypted in transit; per OpenAI's API data usage policy, API inputs and outputs are not used to train OpenAI models)
- Giphy (GIPHY, Inc.): GIF search in feeds, group chat, and DMs. Your search query is sent to our API, which proxies the request to Giphy. We do not send your Donny Wonny account ID to Giphy; Giphy may process your IP address and query per Giphy's privacy policy
- Open-Meteo: Local weather lookups when you have enabled the opt-in Local Weather feature. Receives only your device coordinates rounded to ~1 km — no account identifier, name, or other personal data (Open-Meteo terms)
- Google Cloud Translation API: Language translation when the user has enabled auto-translate (and, for end-to-end encrypted content, separately enabled the explicit Translate end-to-end encrypted messages opt-in). Per Google's terms, translation request content is not used to train Google's models.
- Expo (650 Industries, Inc.): Push notification delivery. Push notifications — including safety-alert titles and bodies — are routed through Expo's push notification service to reach your device. Notification content transits Expo's infrastructure but safety alerts never contain journal, vent, or chat text.
- Sentry (Functional Software, Inc.): Application error monitoring and crash reporting (technical logs and device info — see §4.3)
- Daily.co, Inc.: Live audio/video call delivery for mentorship sessions and primitive voice/video calls (session signaling and metadata — see §1.1)
- ClamAV (open-source antivirus): Optional malware scanning of direct-message attachments on our servers before storage (see §5.4)
- Cloud infrastructure providers: Google Cloud Platform
- : Anonymized usage analytics
All service providers are contractually required to protect your data in accordance with applicable privacy laws.
3.3 Legal Requirements
We may disclose information if required by law, such as:
- In response to valid legal requests (court orders, subpoenas)
- To protect rights, safety, or property
- To prevent fraud or security threats
- To comply with regulatory obligations
3.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you and ensure continued protection.
3.5 With Your Consent
We may share information for other purposes with your explicit consent.
3.6 Public Features (Journeys, Spark Series)
Certain features are opt-in public:
- Journeys (public): When you set a Journey to public in Journey settings, your progress score, milestone badges, and activity statistics (entry count, streak length, and similar aggregates) are visible to other Donny Wonny users who view or follow that Journey. Journal entries and private notes are never included — only the aggregate stats shown on your Journey page.
- Spark Series: Your created series and its daily challenges are publicly visible. Individual subscriber progress is private.
You control public/private settings for Journeys in the Journey settings. Spark Series can be unpublished at any time.
3.7 Together Plan (Group Features)
If you join or create a pod, three distinct messaging surfaces exist:
- Shared Donny — private (per-user AI thread): Each member has their own 1-to-1 conversation with Shared Donny. Your messages in your private thread are NOT visible to other group members. Shared Donny uses high-level group context for personalization but does not surface another member's private messages to you.
- Together Thread (shared, server-readable): A group-wide room where every member + Shared Donny appear in a single feed. Every message you post here is visible to every other group member, including parents and children. This is opt-in: before you can post for the first time, you must explicitly accept a consent notice. Photos, GIFs, and @donny mentions are supported here. This surface is not end-to-end encrypted — parents and guardians may review messages.
- Encrypted Chat (end-to-end encrypted, text-only): A separate private text channel between family members, encrypted on your device before it is sent. Text only — no photos or GIFs in this surface. Parental supervision may apply for supervised minors (see §4.1.1).
- Group admin actions: a parent in the group can soft-delete any Together Thread message. A member can soft-delete their own messages. Soft-deletion removes the text and marks the message as removed; it is not recoverable.
- Children and shared visibility: parents and legal guardians can read everything the child posts in Together Thread by default. If you do not want a child's messages visible to other group members, do not enable them in Together Thread; the per-user private Shared Donny thread and Encrypted Chat remain available per their respective privacy models.
- Automated moderation: every Together Thread message is screened for harm indicators (self-harm content, harassment, sexually explicit content) before delivery. Messages flagged as high-severity are hidden from other members pending review and may generate a safety alert to the group's parent guardians.
You can find all three surfaces from Growth Hub → Connect → My pod in the mobile app (Family, Friends, or Couples pod home).
3.8 Emergency Contact Crisis Notifications (Opt-In)
If you opt in to the emergency-contact feature (§1.1), you are asking us to share limited information with a third party of your choosing:
- When a high-level crisis signal is detected from Let It Out, a journal entry, or Donny chat, we send an email to your designated emergency contact that includes your name, the fact that a high-level distress signal was detected, and the feature it came from. Your journal, vent, and chat content is never included.
- Your emergency contact is a third party who is not a Donny Wonny user (or need not be one), and by designating them you confirm you are comfortable with them learning that you use Donny Wonny and that a high-level safety signal was detected.
- This feature is off by default and entirely opt-in. You control it — including the contact's name and email — in Settings → Privacy → Donny AI Privacy, and you can disable it or change the contact at any time.
- Alerts to the same contact for the same source are rate-limited (we will not repeatedly email your contact for the same signal within a short window). We keep a log of emergency-contact alerts sent (contact email, source, crisis level, timestamp) for safety auditing.
- This is separate from the parental/guardian safety alerts for supervised minors described in §1.1 and §6.3, which do not require opt-in.
3.7.1 Together shared history, consent, and subscription lifecycle
- Join-date scoping: When someone joins an existing Together family, they see shared memories, pod activities, and Together Thread messages created on or after their join date — not content from before they joined. Existing members keep access to the full shared history for that family.
- Explicit consent before invite/accept: The plan owner must acknowledge that new members join the existing shared space before sending an invite. Invitees must acknowledge shared-history visibility before accepting. Together Thread requires a separate opt-in before the first post.
- Archive on lapse: When the Together plan owner's subscription ends, the Together shared stack — shared journals, couple and family activities, Shared Donny, Together Thread, shared memories, pod activities/challenges, and the pod dashboard — is archived (hidden from API access) for all members until the owner resubscribes to Together. Individual journals, personal Donny threads, and non-group features are unaffected. Parental controls, co-guardian, and family supervision on the Family shape keep working without Together. Free pod connection and post feeds in Couple, Group, or Family spaces keep working unless that connection is ended separately.
- Invited members when the payer lapses: Members who joined on someone else's Together plan lose access to the Together shared stack (shared journals, activities, memories, Together Thread, pod challenges, etc.) while the plan is inactive. They receive an in-app notification and push when the family or couple space is archived. Couple post feeds remain available.
- Fresh start (admin only): The plan owner may optionally reset the family pod, which archives prior shared history for all members and requires re-inviting everyone. This action is irreversible and requires explicit confirmation in the app.
- Co-guardians: A primary guardian may add up to one co-guardian (for example, a spouse). Co-guardians share full parental-controls authority over supervised children in the family, including visibility into Together Thread and safety alerts. Adding a co-guardian requires explicit confirmation in the app.
4. Data Security
4.1 Encryption
- In Transit: All data transmitted using HTTPS/TLS 1.3 encryption
- At Rest: All databases encrypted at rest via Google Cloud Platform
- Local Storage: Sensitive on-device data (journal entries, mood logs, gratitude entries) is encrypted before it is written to device storage. Non-sensitive caching (usage counters, UI preferences) uses an in-memory store.
- Purchase Check (mindful spending tool): If you use the optional Purchase Check tool in Growth Hub → Wellness, your work-rate inputs (for example take-home pay, hours worked, pay-stub figures, and items you save to “sleep on it” for 24 hours) are stored only on your device in encrypted local storage. We do not upload wage or purchase-check data to our servers, use it for advertising, or include it in routine cloud sync. Premium tie-ins may read your active goal title and progress from your account (same as the Goals feature) only to show contextual copy on device; that goal data is otherwise handled under your normal account data practices below.
- Passwords: Handled by our authentication provider using industry-standard one-way hashing; we never receive or store your plaintext password. Two-factor backup codes we issue are also stored using one-way hashing.
- AI insights (opt-in): When you enable AI-powered journal insights, journal text may be sent to our AI provider for analysis; results are stored in your account
- Crisis keyword screening: Journal, Let It Out, and Donny chat text may be analyzed on our servers with automated keyword rules (see §5.5.1). This processing is separate from optional AI insights and is not end-to-end encrypted
4.1.0 Surfaces that are NOT end-to-end encrypted
The following are encrypted in transit and at rest on our servers but are server-readable for safety, moderation, sync, or product features — they are not E2E:
- Journal entries (including crisis keyword screening)
- Let It Out vent text during classification (session history stores metadata, not full vent body)
- Donny AI companion conversations
- Donny Den room posts (text feed; optional room chat when enabled)
- Donny Den room chat when enabled
- Mentor circle feeds, mentorship bookings, and optional recordings/summaries
- Community posts, Together Thread, and other server-readable group surfaces described elsewhere in this policy
Direct messages, growth circles, and Encrypted Chat are described in §4.1.1.
4.1.1 Direct Messages and End-to-End Encryption
- Supported clients: End-to-end encryption is available on the current Donny Wonny mobile application for Android or iOS from official app stores, for conversation types where E2E is enabled. Web-only access and conversation types designed for moderation or shared family visibility are not end-to-end encrypted on device.
- What is encrypted end-to-end: On supported clients, direct messages and certain group chats (including growth circles and Encrypted Chat in Together families) are encrypted on your device before transmission. We store and relay only encrypted content and cannot read those message bodies ourselves.
- What is not end-to-end encrypted: See §4.1.0 for server-readable surfaces (journals, AI chat, community feeds, Together Thread, mentorship features, and similar).
- Parental supervision: When a verified guardian supervises a teen account (13–17), the guardian may access certain encrypted communications through the Parent Portal after local decryption on their device. Supervised minors see a clear in-app notice that their parent may read these messages. Together Thread and other server-readable family surfaces may also be visible to guardians. This is disclosed at setup and cannot be changed without guardian action.
- Stranger contact: A user who has never been connected to a minor cannot send unrestricted messages — first contact may require acceptance by the recipient (and, where applicable, a guardian).
- Optional message backup: You may optionally protect a device-encrypted backup of message history with a PIN. We store the encrypted backup but cannot read its contents. Repeated incorrect PIN attempts may permanently remove access to that backup. Parents of supervised minors may reset their child's backup as part of supervision controls.
- Translation: Auto-translate is off by default. If you enable it, message text may be sent to Google Cloud Translation after decryption on your device. End-to-end encrypted content requires a separate explicit opt-in before translation. See §3.2.
- DM attachments (photos and files): Optional encrypted files in direct messages are encrypted on your device before upload. We store encrypted files and basic delivery metadata only (such as file type, size, and delivery status). We cannot read attachment contents. Sending and receiving attachments is free for eligible accounts (subject to age, parental, and safety policies). Automated checks on stored files are not a guarantee that decrypted files are free of malware. Staff may review metadata only when you report an attachment or when automated checks fail.
4.1.2 Fraud & Safety Signals (Cross-Account Abuse Detection)
To detect harassment and ban evasion, we may temporarily retain limited technical and behavioral signals related to messaging activity (such as hashed network identifiers, platform-provided device identifiers, and message timing patterns). We do not store the plaintext of message bodies in these safety records and do not use these signals for advertising or profiling.
These signals are retained for 30 days and then automatically deleted. They are stored separately from your profile and advertising data and are used only for abuse prevention. Automated signals may inform review workflows, but a human reviewer makes the final decision on any account suspension. You may contest a suspension via the appeals process in our Terms of Service §3.5.
4.2 Access Controls
- Role-based access control (RBAC)
- Multi-factor authentication for admin access
- Employee access limited to need-to-know basis
- Periodic internal security reviews
4.3 Security Monitoring
- Application error monitoring via Sentry
- Rate limiting and abuse detection on all API endpoints
- Firebase infrastructure security managed by Google Cloud Platform
- Our infrastructure providers (Google Firebase, Stripe, SendGrid/Twilio, Apple, Google Play, RevenueCat, OpenAI) maintain their own independent security audit programs
No system is 100% secure. While we implement industry-standard security measures, we cannot guarantee absolute security.
5. Your Privacy Rights
5.1 Access and Portability
- Access: Request a copy of your personal data
- Portability: Download your data in machine-readable format
- Rectification: Correct inaccurate information
5.2 Deletion and Restriction
- Right to Delete: Request deletion of your data
- Restrict Processing: Limit how we use your data
- Object: Object to certain types of processing
5.3 How to Exercise Your Rights
Email: privacy@donnywonny.com
In-App: Settings > Privacy > Data Rights
Response time: Within 30 days (GDPR) or 45 days (CCPA)
All data-rights requests are tracked in our compliance system with unique request IDs. You can check the status of any pending request in-app or by contacting us. We maintain a full audit log of compliance actions and consent changes for accountability.
If we deny your request (appeal). You may appeal any decision to refuse a privacy request by replying to our decision or emailing privacy@donnywonny.com with the subject line "Appeal" and your request ID. A person who was not involved in the original decision will review it. We will respond in writing within 45 days of receiving the appeal, explaining the outcome and our reasons. If we deny the appeal, we will tell you how to contact your state Attorney General or other supervisory authority to submit a complaint. This appeal right is available to residents of every US state whose law provides one (including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia) and, as a matter of practice, to everyone else.
5.4 California Privacy Rights (CPRA / CCPA)
California residents have rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, "CPRA"). Specifically, you have the right to:
- Know what categories of personal information ("PI") and sensitive personal information ("SPI") we have collected, the sources, the business or commercial purpose, and the categories of third parties with whom we share it.
- Access the specific pieces of PI we hold about you.
- Delete PI we have collected from you, subject to limited exceptions (e.g. where retention is required by law, for security, or to complete a transaction).
- Correct inaccurate PI we hold about you.
- Portability — receive your PI in a structured, commonly used format (JSON, Markdown, and PDF are supported via Settings → Privacy → Export My Data).
- Opt out of the sale or sharing of your PI for cross-context behavioral advertising. We do not sell your PI and we do not share PI for cross-context behavioral advertising. Because we do not engage in either activity, there is nothing to opt out of, but the statutory right is preserved and a "Do Not Sell or Share My Personal Information" link is provided in the website footer and in the Settings → Privacy screen of the mobile app.
- Limit the use and disclosure of your Sensitive Personal Information to purposes necessary to provide the service. Sensitive PI we collect includes your precise geolocation (only if you grant the permission), account credentials, and the contents of your communications. Direct messages and growth circles may be end-to-end encrypted on supported clients (see §4.1.1). Journal entries, Let It Out vent text, and Donny AI chats are encrypted in transit and at rest on our servers but are not end-to-end encrypted — our servers may run automated crisis keyword screening on journal and Let It Out text as described in §4.1.0 and §5.5.1. A "Limit the Use of My Sensitive Personal Information" link is provided in the same locations as #6 above. Selecting it will disable any non-essential SPI use.
- Non-discrimination — we will not deny you service, charge you a different price, or provide a lower quality service because you exercised any of the rights above.
- Authorized agent — you may designate an authorized agent (such as a family member or attorney) to make a request on your behalf. Verification of your identity and the agent's authority is required.
We do not knowingly collect or sell the personal information of consumers under 16 years of age without affirmative authorization. For users under 13, see Section 6 (COPPA).
To exercise any CPRA right, email privacy@donnywonny.com or use Settings → Privacy in the mobile or web app. We will respond within 45 days as required by statute, with a one-time 45-day extension if the request is complex.
5.5 European Privacy Rights (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018:
- Access (Article 15) — confirm whether we process your personal data and obtain a copy.
- Rectification (Article 16) — correct inaccurate data.
- Erasure / "Right to be Forgotten" (Article 17) — delete your personal data, subject to limited exceptions.
- Restriction of processing (Article 18) — limit how we use your data while a dispute is pending.
- Data portability (Article 20) — receive your data in a structured, commonly used, machine-readable format.
- Objection (Article 21) — object to processing based on our legitimate interests, including profiling for safety detection.
- Withdraw consent at any time, where we rely on consent as the lawful basis (Article 6(1)(a)).
- Lodge a complaint with your national supervisory authority. A list is published by the European Data Protection Board.
5.5.1 Automated Decision-Making and Profiling (GDPR Article 22)
You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significant effects concerning you. The following describes the automated processing we perform and your rights with respect to each:
- Crisis screening ("Let It Out", journal entries, and Donny chat). Let It Out vent text, journal entry text (including entries not shared with Donny), and Donny chat messages are classified on our servers using automated keyword-based rules (not a medical diagnosis). Medium or high levels from any of these sources may trigger a parental safety alert for supervised minors (crisis level and source only — not the underlying text); high-level alerts are always delivered to linked guardians regardless of family notification settings (§1.1). High-level signals may also trigger an email to your opt-in emergency contact (§3.8). Crisis hotline resources are surfaced to you when appropriate. Trust & safety may review flagged accounts separately; the screened text is not routinely human-reviewed. Parents/guardians may restrict Let It Out via Family Content Settings.
- Proactive Donny check-ins (on by default). Donny may proactively initiate check-in messages based on your recent on-platform activity patterns — for example journal entries, goal progress, and mood check-ins. This is enabled by default for new accounts, limited by a frequency cap and quiet hours (10pm–8am by default). It is a personalization feature and does not produce legal or similarly significant effects. You can turn proactive check-ins off entirely, or adjust their frequency, allowed types, and quiet hours, in Settings → Privacy → Donny AI Privacy → Proactive check-ins.
- Safety / abuse detection on community and server-readable content. Automated content moderation flags community posts and other server-readable content that match defined patterns (CSAM, violent threats, doxxing, harassment). Flagging may temporarily hide the post pending human review by our trust & safety team.
- End-to-end encrypted direct messages (1:1 DMs). Message bodies are encrypted on your device before transmission; we cannot read encrypted message content on our servers. Safety for E2E DMs relies on: (a) user reporting and abuse workflows, (b) parental supervision for supervised minors via the Parent Portal, and (c) automated moderation on server-readable surfaces (AI chat, Let It Out, journals, Together Thread) — not on E2E message bodies. When you report a message or when our systems detect concerning patterns from available metadata, we may review the report and limited non-content signals. High-risk signals may enqueue human review and, for supervised minors, parent safety alerts (severity and alert type only — not full message content unless you included it in your report).
- Ban-evasion detection. Limited cross-account safety signals (described in §4.1.2) may feed automated review workflows. A human reviewer makes the final decision on any account suspension. You have the right to contest a suspension via the appeals process described in our Terms of Service §3.5.
To exercise any of the rights above, email privacy@donnywonny.com. For users in the EU/UK, you may also email dpo@donnywonny.com (subject line: "GDPR request"). Where GDPR Article 27 requires an EU/UK representative, you may instead use our Euverify representative contacts in Section 12. If we are required to appoint a Data Protection Officer under GDPR Article 37, dpo@donnywonny.com is the contact point for that role.
5.5.2 AI Training and Your Personal Data
Default: no training without your affirmative opt-in (see §2.4.1). Unless you turn on AI training consent in Settings → Privacy, we do not use your personal content to train our models or any third-party provider's models.
When you have not opted in:
- End-to-end encrypted direct messages, circle messages, and voice DM metadata (transcript, duration, audio link) are not readable by us for training.
- Journal entries, Let It Out vent text, and Donny companion conversations are not added to our training corpus.
- Let It Out vent text may still be screened for safety on the server; we retain session metadata (crisis level, timestamp, emotion) but not the full vent body in your history store.
When you have opted in (§2.4.1):
- Only de-identified, anonymized excerpts from eligible sources (Donny conversations and journal entries you created while opted in) may enter our segregated training dataset, subject to the protections described in §2.4.1.
- E2E DM, circle, and voice DM content remains unreadable by the server and is never included in training, even if you opted in elsewhere.
Donny companion API processing (separate from training): Conversations with our Donny Wonny AI companion are sent to OpenAI under our data-processing agreement. OpenAI processes API requests under its API data-use terms; when our organization-level data controls are enabled, those inputs/outputs are not used to train OpenAI's foundation models (see §2.4.1). Sub-processors are listed in our Data Processing Agreement.
You may disable the AI companion entirely in Settings → Privacy → AI Features. That stops conversational AI processing but does not affect other parts of the service.
6. Children's Privacy (COPPA Compliance)
6.1 Age Verification
- Users must be 13+ to create an account in the United States and other regions where 13 is the applicable minimum.
- Higher regional minimums apply where required by law (for example 16+ in Australia and Malaysia for account creation from those countries' IP addresses; 18+ in India at signup from India IP addresses — verified parental consent for under-18 is not offered in-app today; 14+ in South Korea under PIPA). We derive region from network signals at signup and enforce the applicable minimum.
- We do not knowingly create accounts for users below the applicable minimum age.
- Default age signal: numeric age attestation at first launch (not full date of birth). At launch we enforce regional minimum ages using attestation plus IP-based region gates. Where law requires stronger assurance for social or community features, we may add third-party age verification that confirms you are in an eligible age band (for example, 16+) without us storing your ID or date of birth — only a verification result and audit token.
6.1.1 Australia (pre-launch note)
Australia's Online Safety Amendment (Social Media Minimum Age) Act may apply to services classified as age-restricted social media platforms (ARSMP). We treat our community and messaging features as potentially in scope and enforce 16+ signup from Australia. Before marketing in Australia we plan third-party age assurance (see legal/AGE_ASSURANCE_APPROACH.md) in addition to age attestation. Counsel review is required before AU campaigns.
6.1.2 Malaysia (pre-launch note)
Malaysia's Online Safety Act 2025 Child Protection Code (effective 1 June 2026) requires licensed large social media platforms to block under-16 accounts and verify age with official ID. We enforce 16+ signup from Malaysia regardless of scale and will implement vendor age verification if counsel confirms we are in scope. We do not retain government ID images or numbers on our servers when using a verification provider.
6.2 Parental Consent (Email Plus — users 13–17)
For users aged 13–17 in the United States and comparable regions:
- Parent or guardian email is required at account creation.
- We send the parent/guardian a verification email with a link and code (FTC-approved "Email Plus" method).
- Until the parent verifies, the teen may use solo features (journaling, Donny chat, habits, wellness) but not unrestricted social features (community posts, stranger DMs, Donny Den community rooms).
- Parents may revoke consent at any time via the email flow or by contacting parents@donnywonny.com.
- Teens can request a resend of the verification email from Settings → Parental Consent.
6.3 Parental Controls
Parents can:
- Review their child's information
- Request deletion of their child's data
- Refuse further collection of information
- Monitor activity through Family Dashboard
- Receive automated safety alerts when a medium or high crisis level is detected in their child's use of "Let It Out", journal entries, or Donny chat (alerts include the crisis level and source only — not the content of the vent, journal entry, or chat). Medium-level alerts follow the family's notification settings; high-level alerts are always delivered regardless of notification preferences (see §1.1)
- Restrict or allow their child's access to specific features (including conversations and the "Let It Out" feature) via Family Content Settings
6.4 Limited Data Collection for Minors
For users between the applicable regional minimum age and 18:
- We collect only necessary information
- No targeted advertising
- Enhanced content moderation
- Limited community features
- Default profile visibility is private for new under-18 accounts (the user or, where the product allows, a guardian may change this later)
Contact for parental requests: parents@donnywonny.com
6.5 Age-appropriate notices
A shorter, teen-language summary of this policy and related account rules is published at https://www.donnywonny.com/privacy/teens. That page is a summary only. This Privacy Policy and the Terms of Service remain the binding legal documents.
Supervised under-18 accounts see an in-app notice that a parent or guardian can receive safety alerts and use Family & Safety tools. Safety alerts include the crisis level and source only — not journal, chat, or Let It Out text (see §6.3).
7. Data Retention
7.1 Active Accounts
- Account data: Retained while account is active
- Journal entries: Retained until deleted by user (or removed with account deletion)
- Mood, habit, and progression data: Retained while account is active
- Friend connections and project data: Retained while account is active
- Analytics data: Raw event records are automatically purged after 90 days; anonymized daily aggregates (event name + date + count only, no user IDs) are retained for 2 years, then deleted
- Session and ephemeral auth data (session tokens, short-lived temp buffers): Automatically purged after 30 days
- Application and security logs: Retained for 90 days
- Abuse and safety classifier signals: 30 days (see §5.5.1)
- Moderation and safety action logs (reports, warnings, mutes, bans, appeals): 5 years
- Ban evasion identifiers (IP / device fingerprint hashes): While the associated ban is active; removed when the ban is lifted (see §2.5)
- Payment and subscription transaction metadata (Stripe / RevenueCat / IAP IDs, amounts, dates, plan SKUs — never full card numbers): 7 years for US tax and accounting purposes
- Refund support notes (free text): 90 days after closure, then anonymized
- Refund / chargeback ledger fields (transaction-linked amounts, status, processor IDs): 7 years
- Compliance request records (GDPR/CCPA/access/deletion tickets): 7 years
- Consent and legal-acceptance change history: 7 years
- Cookie consent records: 12 months (365 days)
- AI training corpus (anonymized, opt-in only): Up to 5 years, rolling deletion — pipeline disabled at launch
- Handwriting OCR training pairs (opt-in only): Up to 2 years — disabled at launch
7.2 Deleted Accounts
- Account deletion is processed within 30 days
- End-to-end encrypted direct messages: We anonymize your identifying metadata on our servers and remove your encryption keys. Counterparties may still retain encrypted message copies on their devices (and optional encrypted backups they control). We cannot delete ciphertext stored only on another user's device.
- Encrypted backups may retain data for up to 90 additional days (operational default may be shorter)
- Some data may be retained for legal/compliance purposes per the schedules above (e.g., payment ledgers, moderation archives)
- Anonymized analytics aggregates may be retained without user identifiers
7.3 Legal Holds
Data subject to legal obligations may be retained beyond standard periods.
8. International Data Transfers
8.1 Where Your Data Lives
Donny Wonny LLC is based in the United States and our entire production infrastructure runs in US-region Google Cloud Platform:
- Cloud database — United States multi-region (Iowa, South Carolina, Oklahoma)
- Cloud storage (uploads, backups) — United States (Iowa)
- Application servers — United States (Iowa)
If you use Donny Wonny from the EU, EEA, UK, or any other country outside the United States, your personal data is transferred to the United States for processing and storage. We do not operate separate regional data centers.
8.2 Lawful Transfer Mechanisms
We rely on the following lawful transfer mechanisms (layered for defense in depth):
- EU-US Data Privacy Framework (DPF) — adopted by the European Commission in July 2023. Provides an adequacy decision under GDPR Article 45. Used by our US-based sub-processors that are DPF-certified (Google Cloud, Stripe, Vercel — verify at https://www.dataprivacyframework.gov).
- UK Extension to the EU-US Data Privacy Framework (the "UK Data Bridge") — active since 12 October 2023. Provides the equivalent adequacy basis for UK residents under UK GDPR. The UK Government recognises participating US organisations as providing an adequate level of data protection.
- Standard Contractual Clauses (SCCs) — the 2021 EU Commission-approved modules (Implementing Decision (EU) 2021/914) — incorporated into our data-processing agreements with sub-processors that are NOT DPF-certified (currently OpenAI, SendGrid/Twilio, RevenueCat, Sentry). Each of these sub-processors has signed Google Cloud-style or vendor-specific SCCs with us.
- UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs — applied alongside SCCs for UK-origin data transfers to sub-processors that have not separately certified under the UK Extension to the DPF.
8.3 Transfer Impact Assessment
For each non-adequacy-decision sub-processor, we maintain an internal Transfer Impact Assessment ("TIA") that evaluates:
- The legal regime of the destination country (US)
- The category of personal data transferred
- The supplementary measures in place (encryption at rest, encryption in transit, access controls, sub-processor audit reports)
Our TIA is part of our internal Record of Processing Activities (Article 30 record) and is available to EU/UK supervisory authorities on request via our Article 27 representatives.
8.4 Your Rights Regardless of Location
EU, EEA, UK, and Swiss data subjects retain all rights under their applicable data-protection law (right of access, rectification, erasure, restriction, portability, objection, withdrawal of consent, complaint to supervisory authority) regardless of where the data is processed. Exercise those rights via:
- Your account Settings → Privacy in the mobile app
- Our Article 27 representatives — Euverify Ltd (EU and UK) — full addresses and DSAR portal in Section 12
- privacy@donnywonny.com
9. Cookies and Tracking Technologies
9.1 Types of Cookies
- Essential: Required for service functionality
- Analytics: Understand usage patterns (anonymized)
- Preferences: Remember your settings
- Marketing: Deliver relevant content (with consent)
9.2 Cookie Management
- Manage cookies in your browser settings
- Opt out of analytics cookies via our cookie banner or Cookie Settings
- Note: our website does not currently respond to browser Do Not Track (DNT) or Global Privacy Control (GPC) signals — use the cookie banner and Settings → Privacy controls instead (see Cookie Policy §5.4)
Note: Opting out of analytics cookies is separate from opting out of AI training. To control AI training, see Section 2.4.1 or go to Settings > Privacy (mobile) or donnywonny.com/settings/privacy (web).
See our Cookie Policy for details.
10. Third-Party Links
Our Services may contain links to third-party websites or services. We are not responsible for their privacy practices. We encourage you to read their privacy policies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- In-app notifications
- Email to your registered address
- Prominent notice on our website
Continued use after changes constitutes acceptance.
12. Contact Us
Privacy Questions
Email: privacy@donnywonny.com
Mail:
Donny Wonny LLC
Privacy Department
539 W. Commerce St #5827
Dallas, TX 75208
Data Protection Officer
Email: dpo@donnywonny.com
If and when we are required to designate a Data Protection Officer under GDPR Article 37, this inbox is the designated contact point for that role.
EU Representative (GDPR Article 27)
For data subjects in the European Union and European Economic Area:
Euverify Ltd (Ireland)
Unit 3D North Point House
North Point Business Park
New Mallow Road
Cork, T23 AT2P
Ireland
Email: gdpr@euverify.com
Secure verification & DSAR portal: https://gdpr.euverify.com/verify/a982def2-7d1a-46b3-bd09-b4789722d8d6
UK Representative (UK GDPR Article 27)
For data subjects in the United Kingdom:
Euverify Ltd (UK)
3rd Floor, 86-90 Paul Street
London, EC2A 4NE
United Kingdom
Email: gdpr@euverify.com
Secure verification & DSAR portal: https://gdpr.euverify.com/verify/a982def2-7d1a-46b3-bd09-b4789722d8d6
You may contact our representatives directly for any GDPR matter, including access, deletion, portability, and complaints. Contacting them does not limit your right to contact us at privacy@donnywonny.com or to complain to your supervisory authority.
Complaints
EU/EEA residents can lodge complaints with their local supervisory authority.
13. State-Specific Disclosures
13.1 California
- We do not sell personal information
- Categories of data collected: See Section 1
- Purposes: See Section 2
- Categories shared: See Section 3
13.2 Nevada
Nevada residents may opt out of the sale of personal information (we don't sell data). Nevada also regulates "consumer health data" under SB 370; see §13.5.
13.3 Texas
Donny Wonny LLC is a Texas company, and Texas residents have rights under the Texas Data Privacy and Security Act (TDPSA): to confirm processing and access their personal data, correct it, delete it, obtain a portable copy, and opt out of targeted advertising, sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects. We do not sell personal data and we do not engage in targeted advertising. We process sensitive personal data (including data that may reveal mental or physical health information you choose to share with us, such as mood and journal content) only with your consent or as otherwise permitted by law. Exercise these rights via Settings → Privacy or privacy@donnywonny.com, and appeal a denial as described in §5.3.
13.4 Other US State Privacy Laws
Residents of other states with comprehensive privacy laws — including Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Utah, and Virginia — have rights substantially similar to those described in §5.4 and §13.3 (access, correction, deletion, portability, opt-out of sale/targeted advertising/profiling, and, where provided, appeal). Some of these laws also give you the right to withdraw consent to sensitive-data processing. Contact privacy@donnywonny.com to exercise any of these rights; we honor them regardless of your state of residence.
13.5 Consumer Health Data (Washington, Nevada, Connecticut)
Because Donny Wonny is a wellness product, some of what you choose to share with us — mood check-ins, journal content, "Let It Out" entries, and crisis-screening signals — may qualify as consumer health data under Washington's My Health My Data Act, Nevada's SB 370, and Connecticut's health-data amendments. For residents of those states:
- We collect this data only to provide the wellness features you use, and only with your consent where consent is required.
- We do not sell consumer health data, and we do not share it for advertising. We would not do so without the separate, specific written authorization those laws require.
- We do not use consumer health data for targeted advertising or to profile you for advertising purposes.
- You may withdraw consent and request deletion of consumer health data at any time via Settings → Privacy or privacy@donnywonny.com; deletion requests are honored as described in §7.2, subject only to the legal-hold and financial-record exceptions listed there.
- Employee and contractor access to this data is limited to the need-to-know basis described in §4.2.
Washington residents: this section, together with §1 (what we collect), §2 (why), §3 (who we share with), §5 (your rights), and §7 (retention), is our consumer health data disclosure. Direct questions or complaints to privacy@donnywonny.com.
14. Additional Information
14.1 De-Identified Data
We may create de-identified or aggregated data that cannot reasonably identify you. This data is not subject to this Privacy Policy.
14.2 AI and Automated Decision-Making
- AI is used for content recommendations and insights
- Product feedback may be automatically triaged for internal engineering prioritization; this does not affect your account or billing (see §5.5.1)
- You can request human review of automated decisions
- AI decisions do not have legal or similarly significant effects
14.3 Marketing Communications
- You can opt out of marketing emails anytime
- You will still receive transactional/service emails
- SMS marketing requires explicit consent (where offered)
By using Donny Wonny, you acknowledge that you have read and understood this Privacy Policy.
Last Updated: September 2, 2026
Effective Date: February 28, 2026