TensenTensen

Legal

Privacy

Privacy Policy for tensen.app

Last updated: 31.08.2026

Who Is Responsible for Your Data

The controller of your personal data is NewTech Builders s.r.o., Id. No. 21811911, with its registered office at Příčná 1892/4, Nové Město (Praha 1), 110 00 Praha, Czech Republic ("Provider", "we"). You can reach us about anything in this policy at [email protected] or at the postal address above.

This Privacy Policy ("Policy") describes how we collect, use and share personal data when you use tensen.app and the Tensen mobile application (together "Tensen"). It forms an integral part of the Terms of Use.

What We Collect

Account data. Your e-mail address, your display name, your login credentials or your Apple sign-in identifier, your language, your currency and your subscription state. We need this to give you an account. The legal basis is performance of our contract with you.

Journal content. The dreams you write, the structured fields you set (date of the night, mood, vividness, recall clarity, lucidity, nightmare and recurring flags), the tags you or the AI features attach, and your rescripting entries. This is the service. The legal basis is performance of our contract with you.

Dictation. When you dictate a dream, the recording is transcribed by the speech recognition built into your device's operating system, Apple's on iOS and Google's on Android. Tensen receives only the resulting text and stores it as journal content. We never receive the audio, we never upload it, and we never store a recording.

Sleep data from Apple Health and Health Connect. Described in its own section below.

Usage and technical data. Device type, operating system version, application version, crash reports and basic interaction counts, used to keep the service working and to fix defects. The legal basis is our legitimate interest in operating and improving a reliable service.

We do not collect advertising identifiers, we do not track you across other applications or websites, and we do not build advertising profiles.

Sleep and Health Data

With your explicit permission, Tensen reads sleep records from the health store on your device: Sleep Analysis from Apple Health on iOS, and sleep sessions from Health Connect on Android. This access is read-only. Tensen requests no write permission, and your sleep records are never written back to Apple Health or Health Connect and are never modified there.

What we read. Sleep sessions and their stages (in bed, awake, light, deep and REM) for recent nights. Nothing else. We request no other health or fitness data type.

How we use it. Sleep samples are read on your device, grouped per night, and synced to your Tensen account so that each night of sleep can be lined up with the dream you logged for that night. That correlation is the only purpose.

What we never do with it. We never use health data for advertising or any form of marketing, we never use it to track you, we never sell it, we never transfer it to a data broker, we never use it to train any AI model, and we never send it to our AI providers. It is not used to diagnose, treat or monitor any medical condition. Tensen does not store it in iCloud or in any Google backup.

How long we keep it. Synced sleep records are kept for as long as your account exists and are deleted when you delete your account, on the schedule set out in "How Long We Keep Your Data" below.

Withdrawing access. You can revoke Tensen's health permission at any time, in the Health application or iOS Settings on iOS, and in Health Connect settings on Android. Revoking it stops any further reading immediately. You can delete your account and everything in it, including every sleep record already synced, from inside Tensen.

AI Processing of Your Journal

If you use the AI features, the text of the dream entry you are working on is sent to our AI provider so that it can extract structured tags (symbols, people, places, themes, emotions) and generate reflective notes about the themes in the entry. The AI provider processes the text on our instructions under a data processing agreement, and it is contractually prohibited from using your content to train its own models.

This processing exists to support journalling and pattern finding. It is not used for advertising, it is not used to diagnose any condition, and it produces no automated decision with legal or similarly significant effects for you.

Free accounts can journal, log structured fields and tag manually without any AI processing of their entries.

Who Receives Your Data

We use the following processors, all under written data processing agreements:

  • Anthropic PBC (United States) and OpenAI, L.L.C. (United States), for the AI features described above.
  • RevenueCat, Inc. (United States), for subscription state on iOS and Android.
  • Stripe Payments Europe, Ltd. (Ireland), for subscription payments made on the web. We receive your subscription state and never your card details.
  • Apple Distribution International Ltd. (Ireland), for purchases made through the App Store.
  • Google Ireland Limited (Ireland), for purchases made through Google Play, for push notifications delivered by Firebase Cloud Messaging, and for signing in with Google.
  • Functional Software, Inc. (Sentry) (United States), for crash diagnostics.
  • Hetzner Online GmbH (Germany), for hosting and storage.
  • PostHog, Inc. (product analytics, European Union region), for aggregate usage statistics on the website.

Transfers to processors in the United States are made under the European Commission's standard contractual clauses, and under the EU-US Data Privacy Framework where the processor is certified.

We never sell your personal data, we never share it with data brokers, and we never disclose it to third parties for their own marketing. We disclose data outside this list only where the law requires it.

E-mail We Send You

We send you service e-mail you cannot opt out of while you hold an account: verification, password resets, security notices and billing notices. Where you have asked for them, we also send product update e-mails. Every one of those carries an unsubscribe link, and unsubscribing takes effect immediately.

Cookies

The website sets a session cookie so you can stay signed in, a CSRF cookie that protects forms against forgery, a cookie remembering your answer to the analytics banner, and two small preference cookies remembering your colour scheme and sidebar state. All of them are strictly necessary or set on your own action.

Before you answer the analytics banner we measure usage without storing anything on your device, which means those numbers cannot be tied back to you across visits. Accepting the banner lets our analytics provider store an identifier so repeat visits count as one person, and turns on session recording. Declining stops analytics entirely. We set no advertising cookies and no cross-site tracking cookies.

How Long We Keep Your Data

We keep your account data and journal content for as long as your account exists. When you delete your account, the account and its journal entries, tags and sleep records are deleted. Backups holding a copy roll off within 30 days. We keep invoices and billing records for the period required by Czech accounting and tax law, which is currently ten years.

Your Rights

Under the GDPR you have the right to access your personal data, to have inaccurate data corrected, to have your data erased, to restrict processing, to object to processing based on our legitimate interests, and to data portability.

You can act on most of these yourself: export your full journal as CSV, JSON or PDF from the application at any time, and delete your account and all data associated with it from the account settings, from the deletion page at tensen.app/delete-account, or by writing to [email protected].

To exercise any other right, write to [email protected]. We answer within one month.

If you believe we are handling your personal data unlawfully, you may lodge a complaint with the Office for Personal Data Protection of the Czech Republic (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, www.uoou.cz, or with the supervisory authority of the country you live in.

Children

Tensen is not intended for children under 15. We do not knowingly collect personal data from children under 15. If you believe a child has given us personal data, write to [email protected] and we will delete it.

Security

Your data is stored on servers inside the European Union, protected by firewalls, encrypted in transit with TLS, and accessible only to the small number of people who need it to run the service. Passwords are stored hashed. No system can be guaranteed completely secure, and we will tell you and the supervisory authority about a personal data breach where the law requires it.

Changes to This Policy

We may update this Policy. Material changes are announced in the application and by e-mail before they take effect. The date at the top of this page always shows the current version.

Contact

NewTech Builders s.r.o., Příčná 1892/4, Nové Město (Praha 1), 110 00 Praha, Czech Republic. E-mail: [email protected].

We measure anonymous usage to understand how the app is used. Accept to also allow cookies and session recording. No dream content is ever sent.