Privacy Notice
This notice explains which personal data narcissus.black processes, why we process it, who receives it, and which rights you have.
1. Controller
moorph UG (haftungsbeschränkt)
Loewenichstr. 7
91054 Erlangen
Germany
Represented by Managing Director Jennifer Marsmann
Email: [email protected]
Phone: 015254265537
Further mandatory company details are available in our imprint.
2. Data we process
- Access and security data: IP address, time, requested URL, referrer where supplied, browser and device information, HTTP status, security events, and error events.
- Account data: email address, name if provided, verification status, plan, sign-in times, and a one-way password hash. We do not store the plain-text password.
- App and case data: profiles, relationship and situation details, message history, messages extracted from screenshots, notes, goals, analysis results, simulations, saved cases, and other app state. The image files themselves are processed only for the extraction you request and are not stored as files in your case.
- Contract data: plan, trial, subscription status, Stripe customer and subscription IDs, term and cancellation details, and necessary billing data.
- Communication data: verification and reset emails, support correspondence, and details submitted through cancellation and withdrawal forms. Depending on the form, these include name, email address, timestamp, reference, requested end date or timing, contract date, and an optional comment.
- Operational usage data: daily number of AI actions and the feature category used, linked to the account for quota enforcement. These counters contain no messages, screenshots, prompts, or analysis results. We also derive aggregate counts from account, case, trial, subscription, and usage records already required for the service, for example registrations or active accounts per period.
- Consent-based analytics data: only after consent, the pseudonymous browser usage and event data described in section 10.
Content you provide may contain personal data about other people. Use only content you are lawfully entitled to process, remove names and other identifiers wherever possible, and do not submit special-category data (for example health, sex life, sexual orientation, religion, or political beliefs), intimate material, or content concerning minors. The service is not intended to process such content.
Information for other conversation participants: If a narcissus.black user imports a conversation in which your messages or information appear, we receive that data from the user rather than directly from you. It may include message text, dates and timing, identifiers the user has not removed, relationship context, and model-generated assessments of communication patterns. We use it only to provide the user's private case analysis, keep the service secure, and respond to data-protection requests. It is not used to contact you, advertise to you, publish a profile about you, or make a legal or similarly significant decision about you. The recipients and retention periods described below also apply. You may exercise the rights in section 13 by contacting us; please provide enough context for us to locate the relevant case without sending unnecessary additional sensitive data.
3. Purposes and legal bases
- Providing accounts, saved cases, AI features, and contract and payment processing for the account holder: Art. 6(1)(b) GDPR.
- Where user-provided conversation content concerns another participant, Art. 6(1)(f) GDPR. The legitimate interests are those of the user and the controller in providing a private communication-analysis and reflection tool. We limit this processing through purpose limitation, access control, encryption of saved content, deletion controls, data-minimization instructions, no public profiles, and no automated decisions about the other participant. The other participant may object on grounds relating to their particular situation.
- Meeting commercial and tax-law obligations and processing legally relevant declarations: Art. 6(1)(c) GDPR.
- Service security, error diagnosis, protection against abuse, fraud and bots, and establishing or defending legal claims: Art. 6(1)(f) GDPR. Our legitimate interests are the secure and reliable operation of the service.
- Enforcing the daily usage allowance and showing the remaining allowance: Art. 6(1)(b) GDPR. Preparing aggregate product and business metrics from data already required for accounts and contracts: Art. 6(1)(f) GDPR. Our legitimate interests are understanding whether the service works and improving its economic operation. These internal reports show counts, not chat content or individual account profiles.
- Google Analytics 4: your consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG, the German Telecommunications-Digital-Services Data Protection Act.
Information marked as necessary for an account or contract is required to provide that feature. Without it, the relevant feature cannot be used.
4. Hosting, server logs, and email
The website, database, and transactional email are provided through shared-hosting and cPanel infrastructure operated by Namecheap, Inc., 4600 East Washington Street, Suite 300, Phoenix, AZ 85034, USA. This involves processing website and database content, IP addresses and server logs, and the sender, recipient, time, subject, and content of emails. Namecheap processes hosted customer data under a data processing agreement; further information is available in its hosting-specific notice.
This processing is necessary to provide the service and its email functions (Art. 6(1)(b) GDPR) and to maintain availability and security (Art. 6(1)(f) GDPR).
5. Cloudflare: CDN, security, and Turnstile
We use Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, for DNS, CDN, TLS, WAF, and DDoS protection. Requests therefore generally pass through Cloudflare. Cloudflare processes data including the IP address, timestamp, requested URL, HTTP headers, device and network characteristics, and security events. This supports fast and secure delivery and protection against attacks (Art. 6(1)(f) GDPR).
Cloudflare Turnstile may also be used during registration, sign-in, and password reset. Turnstile evaluates necessary browser, device, and interaction signals to distinguish people from automated requests; Cloudflare states that it does not access form entries or communication content. The legal basis is Art. 6(1)(f) GDPR; necessary access to the device is based on section 25(2)(2) TDDDG. Further information: Turnstile documentation and the Cloudflare Privacy Policy.
6. Account, sign-in, and Google OAuth
When you sign in by email, we store the account details and a password hash. Password-reset tokens are stored only as hashes, remain valid for one hour, and cannot be reused after use; email verification links remain valid for 24 hours. Your sign-in session may remain active for up to 30 days through a technically necessary cookie protected with Secure, HttpOnly, and SameSite=Lax.
Alternatively, you may voluntarily choose “Continue with Google”. We then redirect you to Google and receive from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, a Google identifier, email address, verification status, and, where present in your Google profile, your name and profile picture. Google learns that you intend to sign in to narcissus.black. Our legal basis is Art. 6(1)(b) GDPR. If you prefer not to use Google, choose email sign-in. Google's own processing is additionally governed by the Google Privacy Policy.
7. App storage and protection of content data
Saved cases and app state are held in our database. Content-bearing state data is encrypted there at application level using AES-256-GCM; account, plan, and operational metadata are not all covered by that encryption. Content needed for a requested feature is briefly decrypted for processing.
The app also stores a working copy and any snapshots you create in your browser's local storage. They remain on that device until the app removes them at sign-out or account deletion, you use the relevant deletion control, or you clear them in your browser settings. A person with access to your unlocked device or browser profile may be able to read this copy. On shared devices, use a separate protected browser profile.
If you leave setup unfinished, we store the profile values, relationship history, goals, and manually added messages entered there as an account-specific draft in this browser's local storage. Passwords, payment data, screenshot files, and complete import files are not part of this draft. The draft remains valid for 30 days after the most recent change and is removed after setup is successfully completed or skipped; an expired draft is deleted the next time setup is opened.
Technically necessary browser storage provides the app function you requested (section 25(2)(2) TDDDG); the processing is based on Art. 6(1)(b) GDPR.
8. AI processing by Anthropic
Only when you invoke an AI feature do we send the messages, details, instructions, and, where applicable, screenshot content needed for that request to the commercial API of Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA. Anthropic uses them to generate the requested response. We do not send your internal account ID, email address, or payment data as such, but these may be present in free text or images if you include them yourself.
The transfer is necessary for the AI service you request (Art. 6(1)(b) GDPR); where a request contains another participant's data, the basis described in section 3 applies. Anthropic acts as a processor for commercial API data. We do not participate in Anthropic's Development Partner Program, submit API content as feedback, or otherwise opt that content into model training. Anthropic states that commercial API chats are not used for model training without such an opt-in; see its training information.
Under Anthropic's current API retention policy, standard API inputs and outputs are deleted from its backend within 30 days. If automated systems flag content as a potential Usage Policy violation, Anthropic may retain the input and output for up to two years and related trust-and-safety classification scores for up to seven years. Longer or different periods may also apply where required by law, agreed separately, or when optional services with their own retention (such as a Files API) are used; narcissus.black does not currently use the Files API or submit feedback through the API workflow.
9. Payments, cancellation, and withdrawal
Payments and subscriptions are handled by Stripe Payments Europe, Limited, Ireland. At checkout we send data including your email address, selected plan, and an internal reference; Stripe processes payment method information, customer ID, amount, status, and transaction data. We do not receive complete card or bank-account details. Depending on the activity, Stripe may act as our processor or as an independent controller. The legal bases are Art. 6(1)(b) GDPR and, for mandatory accounting records, Art. 6(1)(c) GDPR. Further information: Stripe Privacy Policy.
When you cancel or withdraw, we record your declaration, receipt time, and the details you submit in a non-public log and match it to the contract. Immediately after submission, we provide a downloadable acknowledgement; we normally also send it by email. This supports contract administration and proof of receipt (Art. 6(1)(b) and (f) GDPR). An optional reason is used only to process the request.
10. Consent, analytics, and advertising measurement
The operational quota counters and aggregate internal reports described in sections 2 and 3 are separate from Google Analytics. They use service and contract records on our server, do not access your device for analytics, and are not controlled by the Google Analytics consent choice.
We use Google Analytics 4 from Google Ireland Limited for audience and product measurement. It is activated only after you explicitly agree. Before then, the Google Analytics script is not loaded, analytics cookies and counters are not stored, and events are not queued for later transmission. A local consent record stores your choice, its version, the providers covered, and the decision time for no longer than 180 days or until you change or remove it. We then ask again. A refusal is stored for the same period so that we can honor your choice.
After consent, Google Analytics processes a random client identifier in first-party cookies (particularly _ga), the IP address during transmission, approximate location, device and browser characteristics, page path without URL query parameters, language, page type, visit and session counters, time spent, and interactions. We also measure tightly limited funnel events such as registration, onboarding, checkout, or reaching a usage limit, together with short values such as plan, language, or source. For learning analysis, only the number and categories of findings and size brackets are sent, not their substance. Google Signals and personalized advertising are disabled.
We do not send an internal user ID, email address, names, message text, screenshots, profiles, specific analysis results, or predictions. General click tracking is disabled inside the app so that labels containing sensitive content cannot be captured.
After consent, we also use Microsoft Clarity to understand page use and interaction patterns. On the app page, visible text is configured to be masked before transmission. Clarity may process browser and device information, page and interaction data, the IP address during transmission, and first-party identifiers such as _clck and _clsk. Further information: Microsoft Privacy Statement.
After consent, we use the Meta Pixel from Meta Platforms Ireland Limited to measure page views and whether a Meta ad is followed by registration, a trial, or a subscription. The browser connects directly to Meta and may transmit the page address, the IP address during transmission, browser and device information, Meta cookie identifiers such as _fbp and _fbc, and the relevant event. Our Meta event calls do not include message content, screenshots, names, email addresses, internal user IDs, analysis results, or prediction text. Further information: Meta Privacy Policy.
The sole legal basis for Google Analytics, Microsoft Clarity, and Meta Pixel is your consent under Art. 6(1)(a) GDPR and section 25(1) TDDDG. Google Analytics cookies and our local content-free visit counters may remain for up to two years; user- and event-level data in a standard GA4 property is retained for no longer than 14 months, depending on the property setting. Aggregated reports may remain for longer. Provider-side retention otherwise follows the relevant account settings and provider policies. Google, Microsoft, and Meta may also process data in the United States.
Google Ads conversion tracking is not currently active.
You may change or withdraw consent at any time with effect for the future. This also removes accessible first-party analytics cookies and local analytics counters:
11. Recipients and international transfers
Recipients are limited to the providers named above where necessary for the relevant feature, and public authorities or professional advisers where we are legally required to disclose data or must establish or defend rights. We do not sell personal data.
Namecheap, Cloudflare, and Anthropic are based in the United States; Google, Microsoft, Meta, and Stripe may also transfer data to group companies or subprocessors outside the European Economic Area. Depending on the provider, these transfers rely on an adequacy decision, particularly a valid certification under the EU-U.S. Data Privacy Framework, and/or the EU Standard Contractual Clauses with supplementary safeguards. Current details and subprocessors are available in the linked provider notices and data processing agreements.
12. Retention and deletion
- We retain account, profile, and case data until you delete it in the app or delete the account. Account deletion removes associated records from the active database; technically necessary backups disappear through the hosting provider's ordinary overwrite cycle.
- A local draft of unfinished setup remains valid for 30 days after the most recent change. It is removed immediately after setup is successfully completed or skipped; an expired draft is deleted the next time setup is opened.
- Password-reset tokens are valid for one hour and verification tokens for 24 hours; expired and used tokens are cleaned up during token processing. Application rate-limit records are routinely removed after approximately two days.
- Daily account and feature counters used for the usage allowance and aggregate activity figures are routinely deleted once they are more than 120 days old. They contain no message content. Aggregate reports are generated from the then-current records and are not stored as separate user profiles.
- We retain cancellation, withdrawal, and support records only while needed to handle the matter and potential legal claims, generally until the regular three-year civil limitation period has expired.
- Contract and payment records relevant under tax or commercial law are generally retained for six, eight, or ten years, depending on the document.
- The periods in sections 8 and 10 apply to Anthropic and Google Analytics. Technical logs and backups held by Namecheap and Cloudflare are deleted under their contractual settings and retention rules.
Statutory retention duties, security incidents, or specific legal claims may require longer retention. In that case, processing is restricted to that purpose.
13. Your rights
Subject to the statutory requirements, you have rights of access, rectification, erasure, restriction, data portability, and objection. You may withdraw consent at any time with effect for the future. Where processing is based on Art. 6(1)(f) GDPR, you may object on grounds relating to your particular situation.
To exercise your rights, email [email protected]. You may also lodge a complaint with a data protection supervisory authority. The authority normally competent for our establishment is the Bavarian State Office for Data Protection Supervision (BayLDA): complaint or regulatory submission.
AI output is guidance for your own assessment. We do not make decisions based solely on automated processing that produce legal or similarly significant effects within the meaning of Art. 22 GDPR.
14. Date and changes
Last updated: 4 September 2026. We update this notice when data flows, providers, or legal requirements change. If a material change affects consent-based processing, we will ask for consent again.