Privacy Policy
Last updated: September 22, 2026
1. What we collect
When you create an account, we collect your name and email address. If you choose Continue with Google, Google shares your name, email address and profile picture with us instead; we use the name and email, and the picture is kept only with your sign-in record. During onboarding, you answer a series of questions about your identity, values, aspirations, and personal history. These responses are considered sensitive personal information and are handled with the highest level of care.
Your answers are used to generate a Future Self persona, stored securely, and used to power your conversations. We also store the conversations you have with your Future Self, your Dreams and Goals, your progress logs, and any breakthrough tags you create.
By completing onboarding, you explicitly consent to us collecting and processing this information to deliver the core service.
2. How we use your data
Your data is used exclusively to operate and personalize your DGFari AI experience. Specifically:
- Your onboarding responses and persona document are injected into every Future Self conversation so the AI speaks as a consistent, coherent version of you.
- Your Dreams, Goals, and progress logs give your Future Self context, so it can speak to what you are actually working on rather than in generalities.
- On the Covenant tier, that same history is used once a month to write you a letter about what changed and what you avoided.
- Your email is used for account-related notifications only. We do not send re-engagement or marketing emails.
- We keep simple usage records in our own database: which parts of the product are opened, where you are in onboarding, when plans are shown or chosen, how long replies take, and the country and site you first arrived from. We use them, mostly as totals, to see what works and to improve DGFari AI. They never contain what you write, they are never shared or sold, and they are deleted with your account. Visits before you sign in are counted without any identifier.
- If you contact us through Help, or send feedback or a report, we keep that conversation with your account so we can answer you and see what was said before. It is part of your data export and is deleted with your account. To help you, our support team can see your account details, such as your plan, usage and dates, but never your conversations with your Future Self; we see only what you send us. We also keep a record of each action our team takes on an account, which holds only the account's identifier and remains after the account is deleted.
We do not sell your data. We do not sell or share your personal information for cross-context behavioral advertising. We do not use your data to train AI models. Your identity work belongs to you.
Legal basis for processing (where applicable): processing of account and product data is necessary to perform our contract with you. Processing of your persona and conversation data is based on your explicit consent given during onboarding.
3. Age restriction
DGFari AI is not intended for users under the age of 18. The product engages deeply with identity, personal history, and psychological reflection. We do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, contact us and we will delete it promptly.
4. Third-party services
DGFari AI uses the following third-party services to operate. We disclose these because each one receives some portion of your data in order to function:
- SupabaseDatabase, authentication, and file storage. Your data is stored in Supabase infrastructure. See Supabase Privacy Policy.
- AnthropicAI model provider. Your persona document and conversation context are sent to Anthropic's API to generate responses. Anthropic does not use API inputs to train its models by default. See Anthropic Privacy Policy and Usage Policy.
- ResendTransactional email delivery. Used for account notifications such as sign-in confirmation, password reset, and messages your Future Self sends you. Your email address and the contents of those messages are processed by Resend. See Resend Privacy Policy.
- GoogleSign-in, if you choose Continue with Google. Google confirms who you are and shares your name, email address and profile picture with us. We never receive your Google password or any other access to your Google account. See Google Privacy Policy.
- PaymentsPaddle acts as merchant of record and handles card details directly. We never see or store a card number, and what reaches us is only what Paddle reports: that a subscription started, renewed, lapsed or was cancelled. What you enter at the checkout is handled under the Paddle Privacy Policy. If you subscribe in our Android app, the payment is taken by Google Play instead, which handles your payment details directly under the Google Privacy Policy; what reaches us is the same kind of report, that a subscription started, renewed, lapsed or was cancelled. DGFari AI does not store card numbers.
- RailwayApplication hosting. The servers that run DGFari AI are operated by Railway, so anything you send to or receive from the product passes through their infrastructure in transit. See Railway Privacy Policy.
5. Data transfers
Your data may be processed in the United States via Anthropic and Supabase infrastructure. We ensure that such transfers are subject to appropriate safeguards consistent with applicable privacy law, including the Philippines Data Privacy Act, California Consumer Privacy Act, and Singapore Personal Data Protection Act.
Your database is hosted in Singapore. That is where your account, your persona document, your conversations, your Dreams and your progress logs are stored at rest.
Conversation context is sent to Anthropic when your Future Self replies. Email delivery through Resend, hosting through Railway, sign-in through Google, payments through Google Play, and security checks through Cloudflare may also process data outside Singapore. New payment processing is currently disabled.
6. Data retention
Your data is retained while your account exists. If your paid or tester allowance is exhausted, your existing history remains readable, but features requiring an allowance are restricted. During private testing, access also requires a current invitation. We do not delete your data automatically on non-payment.
Deleting your account removes your profile, persona document, conversations, assessments, Dreams, Goals, and progress logs from the active application database. Backup copies and provider records may remain under their retention policies. To prevent repeated free tester grants, we retain a restricted, one-way fingerprint of the email address that received a grant and its grant date. This action cannot be undone.
7. Your rights
While you have account access, you can export your application data as a JSON file or delete your account from Settings. If your private-testing invitation has been removed or you cannot sign in, contact us using the details below for access or deletion requests.
Depending on where you are located, you may also have the following rights:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Request deletion of your personal data
- Withdraw consent for processing at any time. Note: withdrawing consent for processing of your persona and conversation data will result in the termination of your account, as this data is necessary to deliver the core service.
- Limit the use of sensitive personal information (California residents)
- Lodge a complaint with your local supervisory authority
We will respond to rights requests within 15 days for users in the Philippines, and within 30 days for users in the United States and Singapore. If we need more time, we will notify you within the initial window.
8. Cookies
We use cookies and local browser storage for authentication, security, and remembering your progress:
- Signing you in. Cookies set by Supabase keep your session active so you are not asked to sign in again on every page.
- Remembering how you left a page. A cookie records whether your identity profile is expanded or collapsed, and your browser's local storage holds a Dream you have started describing but not yet saved. The identity-panel cookie is also read by our server when rendering the page. Onboarding answers and unfinished Dream drafts are stored in your browser; onboarding drafts expire after seven days. Submitted answers and saved Dreams are sent to DGFari AI.
Your browser's local storage also remembers which site first sent you here, so the sign-up can be counted against it. We do not include third-party advertising or analytics scripts in the application. Cloudflare Turnstile checks authentication requests for automated abuse and processes browser and network signals for that purpose. See the Cloudflare Privacy Policy.
9. Data breach notification
In the event of a data breach affecting your personal information, we will notify affected users by email as soon as reasonably practicable.
We will also notify the relevant supervisory authority within the following timeframes:
- Philippines: Within 72 hours of becoming aware, to the National Privacy Commission (NPC).
- United States: Notification recipients and deadlines depend on the applicable state and federal requirements; there is no single deadline covering every breach.
- Singapore: Where notification is required, we notify the Personal Data Protection Commission (PDPC) as soon as practicable and no later than 3 calendar days after determining that the breach is notifiable.
10. Supervisory authorities
If you believe we have not handled your data in accordance with applicable law, you have the right to lodge a complaint with the relevant authority in your country:
- Philippines: National Privacy Commission (NPC) — privacy.gov.ph
- United States: Federal Trade Commission (FTC) — ftc.gov, or your state attorney general
- Singapore: Personal Data Protection Commission (PDPC) — pdpc.gov.sg
11. Data Protection Officer
DGFari AI is run by its founder, who also serves as its Data Protection Officer. For Singapore users, and for any data protection inquiry from any jurisdiction, the Data Protection Officer can be reached at privacy@dgfariai.com.
12. Changes to this policy
If we make material changes to this policy, we will notify you by email at least 14 days before they take effect. For material changes that affect how we process sensitive personal information, we will request your explicit consent before the changes take effect.
13. Contact
Questions about this policy can be sent to privacy@dgfariai.com.