Privacy Policy
Last updated: 2026-06-15 (Version v2.2.0)
1. Who We Are
Essentiafoundation.app is operated by:
Stichting Essentia Foundation
Langbroekerdijk 8-a, 3972 ND Driebergen-Rijsenburg
KvK 77870999
Netherlands
For any privacy-related questions or requests, please contact us at support@essentiafoundation.org. We aim to respond within 30 days.
We are the data controller for the personal data described in this policy. Where we use third-party services to process data on our behalf, those services act as data processors and are listed in Section 5.
Data Protection Officer: Stichting Essentia Foundation has not appointed a Data Protection Officer (DPO). We are not required to do so under GDPR Article 37 — we are not a public authority and we do not carry out large-scale systematic monitoring of individuals or large-scale processing of special category data. All privacy inquiries are handled directly by us at support@essentiafoundation.org.
2. What This Policy Covers
This Privacy Policy applies to:
- The Essentiafoundation.app website and web application
- Your account and all features available to registered users (video and podcast playback, collections, community comments, search, personal notes)
- Transactional emails we send you (email verification, password reset, newsletter)
This policy does not cover:
- Third-party websites linked from Essentiafoundation.app — those sites have their own privacy policies
- Content uploaded to Essentiafoundation.app by the platform operators — this policy covers how we handle your personal data as a user
By creating an account, you acknowledge that you have read and understood this policy. If you do not agree with it, you should not create an account.
3. What Data We Collect and Why
We collect four types of data: data you give us directly, data we collect automatically when you use the platform, data that third-party services collect when you interact with certain features, and data processed transiently by AI features to power search and recommendations.
3.1 Data You Give Us Directly
When you register an account
| Data | Why we collect it | Legal basis | Retention |
|---|---|---|---|
| Email address | To create your account and send you account-related emails | Contract (GDPR Art. 6.1b) | Until you delete your account |
| Username | To identify you in community features (e.g., comments) | Contract (GDPR Art. 6.1b) | Until you delete your account; your username remains visible on public comments after account deletion |
| Password | To authenticate you. Your password is hashed (bcrypt) — we never store your raw password. | Contract (GDPR Art. 6.1b) | Until you delete your account |
| IP address (at signup) | To record where consent was given (GDPR compliance) | Legal obligation (GDPR Art. 6.1c) | 7 years |
| Browser/device information (user agent, at signup) | To record the device used to give consent (GDPR compliance) | Legal obligation (GDPR Art. 6.1c) | 7 years |
Providing your email address, username, and password is required to create an account. Without them, you cannot use the authenticated features of Essentiafoundation.app.
When you update your profile
| Data | Why we collect it | Legal basis | Retention |
|---|---|---|---|
| Profile picture (avatar) | To display your profile | Contract (GDPR Art. 6.1b) | Until you remove it or delete your account |
Uploading a profile picture is optional.
When you create content
| Data | Why we collect it | Legal basis | Retention |
|---|---|---|---|
| Comments | To enable community discussion | Contract (GDPR Art. 6.1b) | Comment text is retained indefinitely; if you delete your account, your username is removed but the comment text remains (attributed to "Deleted User") |
| Collections and collection names | To let you organise content | Contract (GDPR Art. 6.1b) | Deleted when you delete your account |
| Personal notes | Private notes on content | Contract (GDPR Art. 6.1b) | Deleted when you delete your account |
| Bookmarks | Saved content links | Contract (GDPR Art. 6.1b) | Deleted when you delete your account |
| Feedback submissions | Your product feedback and feature requests | Contract (GDPR Art. 6.1b) | Submission text is retained; if you delete your account, your name is removed (attributed to "Deleted User") |
When you accept our terms
| Data | Why we collect it | Legal basis | Retention |
|---|---|---|---|
| Timestamp of acceptance | To record when you agreed to our Terms of Service and this Privacy Policy | Legal obligation (GDPR Art. 6.1c) | 7 years |
| Version of document accepted | To track which version you accepted | Legal obligation (GDPR Art. 6.1c) | 7 years |
| IP address at acceptance | To demonstrate that valid consent was given | Legal obligation (GDPR Art. 6.1c) | 7 years |
| Browser/device information at acceptance | To demonstrate that valid consent was given | Legal obligation (GDPR Art. 6.1c) | 7 years |
If you subscribe to our newsletter
| Data | Why we collect it | Legal basis | Retention |
|---|---|---|---|
| Email address | To send you the newsletter | Consent (GDPR Art. 6.1a) | Until you unsubscribe |
| Subscription timestamp | To record when you gave consent | Consent (GDPR Art. 6.1a) | Until you unsubscribe |
Newsletter subscription is optional and separate from your account. You can unsubscribe at any time from your account settings.
3.2 Data We Collect Automatically
Viewing and playback history
When you watch a video or listen to a podcast while logged in, we record your progress:
| Data | Why we collect it | Legal basis | Retention |
|---|---|---|---|
| Content ID | To identify what you watched | Contract (GDPR Art. 6.1b) | Until you delete your account |
| Playback position | To allow you to resume where you left off | Contract (GDPR Art. 6.1b) | Until you delete your account |
| Completion status | To help you track what you have finished | Contract (GDPR Art. 6.1b) | Until you delete your account |
| Content type (video/podcast/essay) | To categorise your history | Contract (GDPR Art. 6.1b) | Until you delete your account |
Your viewing history is private — it is only visible to you and is not shared with other users.
Search queries
When you use the search feature, your search query is sent to Mistral AI to generate a semantic search embedding. Search queries are not stored. After the search results are returned, the query is discarded. See Section 3.4 for more about AI-assisted features.
Security and authentication data
| Data | Why we collect it | Legal basis | Retention |
|---|---|---|---|
| IP address (at login) | To protect against unauthorised access and detect suspicious activity. Logged to our hosting provider's server logs. | Legitimate interest (GDPR Art. 6.1f) — securing our platform | 30 days (Vercel log retention) |
| Failed login attempts (client-side) | To decide when to show a CAPTCHA. Stored locally in your browser only — never sent to our servers. | Legitimate interest (GDPR Art. 6.1f) — protecting against brute-force attacks | 1 hour, then automatically cleared |
Note: Failed login attempt counts are stored in your browser's local storage using your email address as part of the storage key. This data never leaves your device and is automatically deleted after 1 hour.
Error monitoring and performance (Sentry)
We use Sentry to monitor application errors and performance. Sentry may collect:
- Error messages and stack traces when something goes wrong
- Page load timing and API performance data
- Session replays: Anonymised recordings of your interactions (clicks and scrolls) to help us diagnose problems. Text you enter is masked; images and video are blocked. Approximately 10% of sessions are recorded normally; 100% of sessions where an error occurs are recorded.
Sentry is configured with privacy protections: your IP address is not sent to Sentry, and all text is masked in session replays.
| Data | Legal basis | Retention |
|---|---|---|
| Error events and performance data | Legitimate interest (GDPR Art. 6.1f) — maintaining service quality | 90 days |
| Session replay recordings | Legitimate interest (GDPR Art. 6.1f) — diagnosing user-facing problems | 30 days |
3.3 Data from Third-Party Services
When you watch videos — Mux
Essentiafoundation.app uses Mux to deliver video and podcast content. When you watch a video, Mux's player automatically collects viewer analytics:
| Data | Why Mux collects it | Retention |
|---|---|---|
| IP address | To measure geographic reach and diagnose delivery issues | 30 days |
| Device type, operating system, browser | To optimise video quality for your device | 30 days |
| Playback events (play, pause, buffering, quality changes) | To measure playback quality | 30 days |
| Watch duration | To measure content engagement | 30 days |
Mux analytics data is sent directly from your browser to Mux's servers (ingest.litix.io). Your Essentiafoundation.app account email or username is not sent to Mux.
When you sign in or register — Cloudflare Turnstile
To protect against bots and automated attacks, we use Cloudflare Turnstile as a CAPTCHA service. Turnstile is triggered on the signup page and after three consecutive failed login attempts. When the CAPTCHA activates, Cloudflare receives:
| Data | Why Cloudflare collects it | Retention |
|---|---|---|
| Browser signals (capabilities, interaction patterns) | To determine if you are a human | Short-lived (hours) |
| IP address | To assess risk | Short-lived |
| User agent | To assess browser context | Short-lived |
Cloudflare Turnstile is specifically designed to be less invasive than traditional CAPTCHAs. It does not track you across other websites.
3.4 AI-Assisted Features
Several features on Essentiafoundation.app are powered by artificial intelligence. In all cases, AI is used purely to improve content discovery — it does not make decisions about your account or access rights.
| Feature | What data is processed | Who processes it | Is it stored? |
|---|---|---|---|
| Semantic search | The text of your search query | Mistral AI (France, EU) | No — the query is sent transiently and discarded after results are returned. We do not store your search history. |
| Discussion thread categorisation | The text of a comment you post (up to 500 words) | Mistral AI (France, EU) | No — processed once to suggest a thread type and title. The suggestion is shown to you; the raw text is not retained by Mistral AI. |
| Content recommendations ("related content") | The content you are currently viewing | Supabase (vector similarity search, Germany, EU) | No personal data is sent — recommendations are based on the content ID, not on your identity or history. |
No automated decision-making: None of these AI features make decisions that produce legal or similarly significant effects on you (GDPR Art. 22). They are content discovery tools only. You can ignore or dismiss any AI-generated suggestion (e.g., a thread title) without consequence.
No account identifiers sent to AI: Your email address, username, and user ID are never sent to Mistral AI alongside your content. Queries and comments are processed without attribution to your account.
4. How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Providing the service — creating and managing your account, authentication, delivering content, saving your progress | Account data, playback history, collections, notes | Contract (GDPR Art. 6.1b) |
| Community features — displaying your comments and content contributions | Username, comment text, feedback text | Contract (GDPR Art. 6.1b) |
| Security — protecting against unauthorised access, brute-force attacks, and abuse | IP address (login), failed attempt counts (browser-local) | Legitimate interest (GDPR Art. 6.1f) |
| Legal compliance — maintaining records of consent, responding to data subject requests | Consent records, account deletion records | Legal obligation (GDPR Art. 6.1c) |
| Transactional email — sending account verification, password reset, and other account-related emails | Email address | Contract (GDPR Art. 6.1b) |
| Newsletter — sending our newsletter to subscribers | Email address, subscription status | Consent (GDPR Art. 6.1a) |
| AI-powered search — processing your search query to find relevant content | Search query text (transient — not stored) | Contract (GDPR Art. 6.1b) |
| AI-powered discussion threads — categorising the type of comment you post and suggesting a thread title | Comment text you submit (transient — processed once) | Contract (GDPR Art. 6.1b) |
| Error monitoring and performance — identifying and fixing bugs, measuring service performance | Error data, session replays (masked) | Legitimate interest (GDPR Art. 6.1f) |
| Account deletion audit trail — maintaining records of deletion requests for legal purposes | Deletion timestamp, deletion type, email address | Legal obligation (GDPR Art. 6.1c) |
| Payment processing — processing one-time donations and subscription billing via Stripe's hosted checkout | Payment amount; for subscriptions, email address passed to Stripe to create a customer record. Card details are entered directly with Stripe — we never receive them. | Contract (GDPR Art. 6.1b) / Legitimate interest (GDPR Art. 6.1f) — for donations |
What We Do Not Do
- We do not sell your personal data to anyone.
- We do not share your data for advertising or marketing purposes.
- We do not use your data to build advertising profiles.
- We do not use automated decision-making that produces legal or similarly significant effects on you. Our AI features (search and thread categorisation) are content discovery tools only — they do not make decisions about your account or access (GDPR Art. 22).
6. International Data Transfers
Essentiafoundation.app stores all application data in the European Union (Frankfurt, Germany via Supabase). However, some third-party services are based in the United States and process data there:
| Processor | Location | Transfer Mechanism |
|---|---|---|
| Stripe | United States | Standard Contractual Clauses (EU Commission 2021) |
| Supabase | EU (Frankfurt) | No transfer |
| Vercel | Global (including US) | Standard Contractual Clauses (EU Commission 2021) |
| Mux | United States | Standard Contractual Clauses (EU Commission 2021) |
| Resend | United States | Standard Contractual Clauses (EU Commission 2021) |
| Mistral AI | France (EU) | No transfer |
| Sentry | EU (Germany) — parent company US | Standard Contractual Clauses (included in Sentry DPA) |
| Cloudflare Turnstile | Global (including US) | Standard Contractual Clauses |
Standard Contractual Clauses (SCCs) are pre-approved model contracts from the European Commission that provide appropriate safeguards for data transferred outside the EU. You can request copies of the SCCs in place by contacting support@essentiafoundation.org.
For transfers to the United Kingdom: The EU–UK adequacy decision remains in effect. UK users' data is protected under UK GDPR, which is substantively equivalent to EU GDPR.
8. Data Retention
We keep your data for as long as necessary to provide the service and meet our legal obligations:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account data (email, username, profile) | Until you delete your account | Contract — required to provide the service |
| Viewing and playback history | Until you delete your account | Contract — required to provide resume-watching feature |
| Comments | Comment text retained indefinitely; author identity removed on hard account deletion | Legitimate interest — community record integrity |
| Collections, notes, bookmarks | Deleted when you hard-delete your account | Contract |
| Feedback submissions | Submission text retained; author identity removed on hard account deletion | Legitimate interest — product improvement |
| Consent records (timestamps, IP, user agent, version) | 7 years | Legal obligation — GDPR compliance evidence |
| Account deletion records (deletion timestamp, type) | 7 years | Legal obligation |
| Server logs (IP address at login/request) | 30 days (Vercel default) | Legitimate interest — security |
| Failed login attempts (browser-local) | 1 hour, then automatically cleared | Legitimate interest — security |
| Mux video analytics | 30 days (Mux's retention policy) | Third-party service |
| Sentry error data | 90 days | Legitimate interest — service quality |
| Sentry session replays | 30 days | Legitimate interest — service quality |
| Resend email delivery logs | 30 days (Resend's retention policy) | Third-party service |
| Stripe payment records | Retained by Stripe per their policies (typically 7 years for financial records). We hold only a Stripe session/customer ID — no card data. | Legal obligation — financial record-keeping |
When retention periods expire, data is deleted or anonymised. For data that cannot be immediately deleted due to legal obligations (e.g., consent records), we retain only the minimum necessary.
9. Your Rights
Under GDPR (and UK GDPR), you have the following rights regarding your personal data:
Right of access: You have the right to receive a copy of the personal data we hold about you.
→ How to exercise: Log in → Settings → Download Your Data. This generates a JSON export of all data we hold. Alternatively, email support@essentiafoundation.org.
Right to rectification: You have the right to correct inaccurate personal data we hold.
→ How to exercise: Log in → Profile → Edit profile (for username, avatar). For other corrections, email support@essentiafoundation.org.
Right to erasure (“right to be forgotten”): You have the right to request deletion of your personal data where there is no longer a legitimate reason to keep it.
→ How to exercise: Log in → Settings → Delete Account → choose Permanent deletion. This removes your account, profile, collections, notes, bookmarks, and voting history. Note: comment text and feedback text you have posted are retained (attributed to “Deleted User”) as part of the community record; consent records are retained for 7 years for legal compliance. Alternatively, email support@essentiafoundation.org.
Right to restriction of processing: You have the right to ask us to pause processing of your data in certain circumstances (e.g., while a dispute is being resolved).
→ How to exercise: Email support@essentiafoundation.org.
Right to data portability: You have the right to receive your data in a structured, machine-readable format.
→ How to exercise: Same as right of access — Settings → Download Your Data provides a JSON export of all your data.
Right to object: You have the right to object to processing based on legitimate interests. You may also object to receiving the newsletter at any time.
→ How to exercise: For newsletter: Settings → Notifications → Unsubscribe. For other objections: email support@essentiafoundation.org.
Right to withdraw consent: Where we process data based on your consent (e.g., newsletter subscription), you can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
→ How to exercise: Settings → Notifications → Unsubscribe (newsletter). For other consent withdrawals, email support@essentiafoundation.org.
Response times
We aim to respond to all rights requests within 30 days. If your request is complex, we may extend this by a further two months — we will notify you if this is necessary. We will not charge you for exercising your rights unless requests are manifestly unfounded or excessive.
Right to complain to a supervisory authority
If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with a data protection supervisory authority:
- For Netherlands residents (lead supervisory authority): Autoriteit Persoonsgegevens (AP) — autoriteitpersoonsgegevens.nl — Tel: +31 (0)70 888 85 00
- For other EU residents: Contact the national data protection authority in your EU member state. A full list is available at edpb.europa.eu.
- For UK residents: Information Commissioner's Office (ICO) — ico.org.uk — Tel: 0303 123 1113
We would appreciate the chance to address your concerns before you contact a supervisory authority. Please email us first at support@essentiafoundation.org.
10. Children's Privacy
Essentiafoundation.app is intended for users aged 16 and over. We do not knowingly collect personal data from children under 16.
If you are under 16, please do not create an account or provide us with any personal data.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us at support@essentiafoundation.org. We will delete the account and associated data promptly on verification.
Note for US users (COPPA): Essentiafoundation.app is not directed at children under 13. We do not knowingly collect personal data from children under 13 in the United States. If we become aware that we have collected data from a child under 13, we will delete it immediately.
11. Security
We take reasonable technical and organisational measures to protect your personal data:
Technical measures
- All data in transit is encrypted using TLS/HTTPS
- All data at rest in our database (Supabase) is encrypted
- Passwords are hashed using bcrypt — we never store or see your raw password
- Row-Level Security (RLS) policies ensure users can only access their own data
- Access to administrative functions is restricted to authorised accounts
What you can do
- Use a strong, unique password for your Essentiafoundation.app account
- Do not share your login credentials with anyone
- Log out when using shared devices
Data breach notification: In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay and within 72 hours of becoming aware of the breach, as required by GDPR.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do:
- Minor updates (e.g., fixing typos, adding clarification): We will update the version number and date at the top of this page.
- Material updates (e.g., new data collection, new third parties, changes to your rights): We will notify you by email and, where required by law, ask for your consent again before the changes take effect. You will be prompted to re-accept the updated policy when you next log in.
13. Contact Us
For any questions about this Privacy Policy, to exercise your data rights, or to report a privacy concern:
- Email: support@essentiafoundation.org
- Response time: We aim to respond within 30 days.
- Postal address: Stichting Essentia Foundation, Langbroekerdijk 8-a, 3972 ND Driebergen-Rijsenburg, Netherlands