Privacy Policy
Prefer to see it rather than read it? Most of this we can show, not just promise. See how your privacy works, and check it yourself →
Short version. Dodecave is designed to keep your data on your device. The free core requires no account; a paid membership adds only the limited account and billing information described in §2.9. The app does not use advertising cookies and does not sell data to anyone. The only data that leaves your device is (1) pseudonymous usage analytics, and only if you opt in, (2) a diagnostic report only if you explicitly send one.
You can use Dodecave's core practice with analytics turned off. You can export or delete your data at any time from Settings.
1. Who we are
Dodecave is an independent project operated by A.G. LYON LLC, a US limited liability company. There are no investors, no parent companies, and no data-monetization partners.
Data controller contact: [email protected]
2. What we collect (and don't)
2.1 Data stored locally on your device only
When you use Dodecave, the app stores the following on your device (browser local storage, session storage, and the service-worker cache). This data never leaves your device unless you explicitly trigger an export or send a diagnostic report.
- Session history: shield activations, dimensional readings, breath cycle timing
- Preferences: language, activation depth, contrast, saved profile
- Session snapshot: active shield state (so a page reload doesn't interrupt a practice)
- Correction log: the last 100 frequency-correction events for self-review
- Safety & Terms acknowledgments: accepted Terms version, acceptance timestamp
- Offline audio: voice guidance clips cached by the service worker so the app works without internet
2.2 Usage analytics: only with your consent
If you opt in to Usage Analytics via the consent banner or Settings → Privacy, the app periodically sends a small payload containing:
- A pseudonymous identifier, a short one-way cryptographic hash derived from your IP address (never the IP itself). Because the same IP produces the same hash, this value can recognize repeat visits, so we describe it as pseudonymous rather than anonymous, it is never linked to your name or an account
- Device and browser family (for example "iPhone / Safari"), plus screen dimensions and device pixel ratio, used to diagnose layout and rendering issues; never a persistent device identifier
- App build version
- Aggregate counts: how many sessions you've completed, which features are active, current language
- Country code from our edge network (a two-letter ISO code only, never the raw IP, never sub-country geolocation, never GPS)
- The hostname of the page that linked you to the app (just the hostname, never the full URL or query string)
- Campaign attribution tags (
?utm_source=…style) if present in the URL you arrived from; stored only in session storage, so attribution clears the moment you close the tab - The Terms version you accepted and your acceptance timestamp, so we can see how quickly updated terms reach users
- If a client-side error or performance metric is captured during your session, a pseudonymized record of that event (no direct identifiers such as your name, email, or the words you seek; capped per-session) so we can detect and fix bugs
This payload never includes your name, email, address, precise GPS coordinates, microphone audio, camera frames, the contents of your session history, or anything that could identify you personally.
2.3 Diagnostic reports: opt-in, per-report
If you tap "Send diagnostic report" in Settings, the app uploads a one-time snapshot containing: your device info (including your browser's user-agent string, platform, and screen metrics), recent errors, your current settings, a session summary, and an audio-processing log. Manual reports require an explicit click; in addition, if you have opted into analytics, the app may send pseudonymized crash reports automatically so we can detect broken releases. Diagnostic reports are retained for up to 90 days and then automatically deleted.
2.4 AI Companion (retired)
The AI Companion has been retired and removed from every build. Nothing is sent to any third-party AI service. This section is kept only to record that the feature, and the data handling it once involved, no longer exist.
2.5 Vision Deep Scan: optional, per-frame (private build only)
Dodecave's Vision Analyzer processes camera frames entirely on your device: no imagery is transmitted. The optional "Deep Scan" feature, which sends a single camera frame to a third-party AI service, is available only in our private/VPN build; it is not present in the public app at dodecave.com. Where it is available and you explicitly invoke it, the frame is processed and discarded; it is not retained beyond the analysis request. Live (non-Deep-Scan) vision analysis is always entirely local.
2.6 Rest tracks: including audio for children
The Rest player streams audio tracks from our servers when you press play. We do not collect any data identifying who is listening, including for tracks intended to be played by an adult for a child during sleep. We cannot distinguish kids-track playback from adult playback at the server level, and we do not try to.
2.7 Custom meditation words: matched on your device, or resolved without a trace
When you name a word for a custom guided meditation, through the "name what you seek" field, or a ?seek=… link someone shared with you, one of two things happens. If it is a free word, it is matched to a dimension of the field entirely on your device, using a dictionary the app already carries offline; it is never transmitted. If it is a member word (part of the membership library), the app sends only that single word to our resolver, which returns its field and does not log, store, or link the word to you or your account: the word is processed in memory for that one request and nothing about it is kept. In neither case is the word included in usage analytics or diagnostic reports, and even where a shared link's address contains the word, the app strips the query string before any analytics event. If you have opted into analytics, the app may record which features were active during a session (see §2.2), never the word itself. We keep no record of which words you name.
2.8 What we do not collect
- If you use Dodecave without a membership, there is no account, and we collect no email, name, phone, or payment information. If you take out a membership, we collect what is listed in §2.9 and nothing beyond it.
- No advertising cookies, no ad-network tracking pixels, no third-party analytics SDKs (Google Analytics, Meta Pixel, etc.).
- No microphone audio leaves your device. The microphone is used locally for frequency analysis only.
- No camera imagery leaves your device unless you explicitly invoke Vision Deep Scan (see §2.5).
- No GPS or precise geolocation in the public app, no contacts, no saved passwords, no browser history. (The private/VPN build has an optional local-grid feature that, only when you tap it, uses your device location to name your area via OpenStreetMap; like Vision Deep Scan, it is not present in the public app at dodecave.com, which makes no third-party network requests at all.)
- No data is collected from or about children playing the Rest kids' tracks (see §2.6).
2.9 Membership and billing
Dodecave is free to use, and most people will never touch this section. It applies only if you take out a paid membership.
- What we collect when you subscribe: your email address (so we can reach you about your membership); an account identifier we generate (a random string, not derived from your name); your membership status (which plan, whether it is active, when the current period ends); and a record that you agreed to the Terms and to automatic renewal, with the date and time.
- What we never see: your card number, expiry, and security code go directly to our payment processor, Stripe. They do not pass through Dodecave. We do not store them, we cannot charge a card on our own, and a breach of our systems could not expose one.
- How little the entitlement service knows: the service that decides whether your membership is active stores your account identifier, the identifier Stripe uses for you, a one-way hash of your email address, your plan, and the date your access ends. It does not store your name, your email in readable form, your card, or anything about what you seek, listen to, or do in the app.
- What membership does not change: free words are still matched on your device, and a member word is sent only to compute its field and is never logged, stored, or linked to you (see §2.7). Usage analytics stay opt-in and stay off unless you turn them on (see §2.2). Membership adds no new tracking.
2.10 Echo household membership
An Echo membership lets one person (the plan manager) pay and invite up to five other people, six memberships in total.
- Invitations. The plan manager sends a single-use invite code that expires seven days after it is issued. To accept, the invited person creates or signs in to their own Dodecave account and provides an email address.
- What the plan manager can and cannot see. The plan manager can see the email addresses they have invited and whether each seat is filled or empty, and can remove a seat. The plan manager cannot see any member's words, seeking, guided journeys, listening history, or on-device practice data. As described in §2.7, words are matched on your device or resolved without being logged, stored, or linked to anyone, so there is no member word-history for the plan manager, or anyone else, to see.
- What we store per member. Account email, a random account identifier, membership status and expiration, an auto-renewal consent record (for the plan manager), payment identifiers (plan manager only, held by Stripe), and entitlement records. Nothing about what any member seeks or does in the app.
- Leaving or ending Echo. A member may leave at any time; the plan manager may remove a member or end the Echo membership. When a member leaves, is removed, or the membership lapses, that account reverts to the free tier and keeps only the data associated with a free account.
- Age. Echo is intended for adults (18 and over); a member may be younger where the plan manager confirms they meet the minimum age and accepts responsibility for them, but no member may be under 13. A member aged 13–17 is the responsibility of the plan manager who invited them; we do not knowingly collect a child's personal information (see §6), collect no geolocation from a known minor, and direct no targeted advertising to one.
- Retention of invitation records. Expired or used invite codes and their records are deleted within 90 days. Lapsed-membership and entitlement records are retained for the limited period tax and consumer-protection law require (see §3), then deleted or de-identified.
3. Legal basis and purpose (GDPR)
| Purpose | Basis | Retention |
|---|---|---|
| Operating the app (offline cache, preferences) | Necessary for performance of the service, stored on your device only | Until you clear browser storage or use "Delete my data" |
| Usage analytics (§2.2) | Consent (opt-in) | 90 days, then automatically purged |
| Diagnostic reports (§2.3) | Consent (per-report) | 90 days, then automatically purged |
| Vision Deep Scan (§2.5) | Consent (per-invocation) | Not retained, processed and discarded |
| Membership and billing (§2.9) | Necessary to perform the membership contract, and to meet tax and consumer-protection record-keeping duties | Held by Stripe for the period those laws require |
| Entitlement record (§2.9) | Necessary to perform the membership contract | While the membership is active, then a limited period afterwards, then deleted |
| Consent to automatic renewal (§2.9) | Consent, recorded by Stripe | At least three years, or one year after the membership ends, whichever is longer |
| Echo invite records (§2.10) | Necessary to operate the household plan | Expired or used invite codes deleted within 90 days |
4. Your rights
Regardless of where you live, you can:
- Export everything Dodecave has stored about you: open the app, go to Settings → Privacy → "Export my data." You'll get a JSON file with all on-device data.
- Delete your data: Settings → Privacy → "Delete my data." This permanently clears all storage on your device and cannot be undone. Opt-in analytics carry only the pseudonymous identifier described in §2.2 and auto-expire; a diagnostic report you filed can be purged by emailing [email protected] with its support code. If you have or had a membership, two things survive that button, and we would rather say so than let you find out later: your billing records (your email address, your invoices, and the record that you agreed to automatic renewal) are held by Stripe, and our own entitlement record (see §2.9) is kept while your membership is active and for a limited period afterwards, because tax and consumer-protection law require it. Neither contains anything about what you seek or do in the app. When those periods end, the records are deleted. To ask exactly what is held about you, write to [email protected].
- Opt out of analytics at any time: Settings → Privacy → "Usage Analytics" toggle.
- Write to us at [email protected] with any question or request about your data. We respond to data subject requests within 30 days (for U.S. state-law requests, within 45 days, as those laws permit). Under GDPR you additionally have the right to lodge a complaint with your national data protection authority.
5. Where your data lives
Local data stays on your device. The limited data that does leave, pseudonymous usage analytics and diagnostic reports (only if you use them), is processed on infrastructure we operate, protected in transit by TLS and at rest by access controls, perimeter firewalling, and encryption for sensitive categories. An edge content-delivery network serves static traffic for dodecave.com; the edge sees your IP address transiently in order to route the request, but our origin server does not retain your raw IP. We do not use any third-party advertising network, marketing analytics service, or adtech vendor. Payments are handled by Stripe, which holds your card details and billing records on its own systems under its own privacy policy; we do not receive your card details from it. Sign-in links, if you use them, are sent by Scaleway Transactional Email (region fr-par, EU); it handles your email address in transit only, for that message.
6. Children
Dodecave's main app is not directed to children under 13, and the Terms of Use require that you are 18 or older (or have the verifiable consent and supervision of a parent or legal guardian).
The Rest player includes audio tracks intended to be played by an adult for a child during sleep (see §2.6). These tracks are operated by the adult; we do not collect any data identifying the child, and the parental confirmation gate in the player documents that the adult is responsible for placement, volume, and supervision.
7. Security
Data in transit is protected by TLS encryption (HTTPS). Data at rest on infrastructure we operate is protected by access controls, perimeter firewalling, and at-rest encryption for sensitive categories.
Security researchers can report vulnerabilities to [email protected]; we operate under safe-harbor terms for good-faith research.
8. Changes to this policy
When we change this policy we update the version and date at the bottom of this page and, for material changes affecting data handling, we surface a re-consent prompt in the app summarizing what changed.
9. California residents (CCPA / CPRA)
If you are a California resident: in the preceding 12 months we collect, at most, the limited categories described above: a pseudonymous identifier, device and browser information, and (only if you opt in) pseudonymous usage analytics. We treat the pseudonymous identifier as personal information and afford it the rights below. We do not sell or share your personal information, and we do not use it for cross-context behavioral advertising or targeted advertising. You have the right to know, access, delete, and correct your personal information, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. To exercise any of these rights, use Settings → Privacy (Export / Delete) or email [email protected]; we will respond within 45 days.
10. Texas & other U.S. state residents
Texas. A.G. LYON LLC is a Texas company, and we honor the Texas Data Privacy and Security Act (TDPSA) for Texas residents. We believe we qualify as a small business under the U.S. Small Business Administration's definition; even where that status narrows a company's obligations, we commit, as the TDPSA requires of every business regardless of size, that we will not sell your sensitive personal data without your consent. In practice we do not sell any personal information at all, sensitive or otherwise, and we do not use it for targeted advertising or profiling. "Sensitive data" includes information that reveals a health condition; the words you name for a custom meditation are matched on your device (free words) or sent only to compute a field and never logged, stored, or linked to you (member words), so we hold no record of what you seek (see §2.7), and the microphone is never transmitted (see §2.8), so we do not receive that category of data in a form tied to you.
Other states. If you live in a U.S. state with a comprehensive consumer-privacy law, for example Virginia, Colorado, Connecticut, Oregon, or Montana, among others as they take effect, you have the right to confirm and access, correct, delete, and obtain a portable copy of the personal information we hold, and to opt out of any sale, targeted advertising, or profiling. Because we do none of those last three, there is nothing to opt out of, but you may exercise the access, correction, and deletion rights the same way anyone can:
- in the app, Settings → Privacy → Export my data / Delete my data, or
- by email to [email protected].
We respond within 45 days and do not discriminate against you for exercising a privacy right. Where your state grants a right to appeal a declined request, you may appeal by replying to our decision.
[email protected]
Version 2.4 · Last updated 2026-07-24 · Short-version accuracy: the free core requires no account; a paid membership adds only the limited account and billing information described in §2.9 (the earlier blanket "does not require accounts" predated membership). No change to what we collect. See the change log below for earlier versions.
Earlier version history
v2.5 (2026-07-28): The AI Companion has been retired and removed from every build. §2.4 is now a tombstone; its data-handling disclosures (third-party AI processing, encrypted conversation memory) and the related table row and mentions are deleted. Nothing is sent to a third-party AI service.
v2.4 (2026-07-24): Short-version accuracy only: it now says the free core requires no account, and a paid membership adds only the limited account/billing information in §2.9 (the earlier blanket "does not require accounts" predated membership). No change to what we collect.
v2.3 (2026-07-24): §2.8: the public app makes no third-party network requests; the optional local-grid/location feature (reverse-geocodes via OpenStreetMap) is now private/VPN-build only, like the AI Companion and Vision Deep Scan; the public Content-Security-Policy allows only same-origin connections.
v2.2 (2026-07-24): Added §2.10 (Echo household membership): invitations, the plan manager's visibility limits (no member word-history exists to see), per-member data, leaving/ending, the age floor (18+ recommended, none under 13, 13–17 the plan manager's responsibility), and invite-record retention (§3). No new tracking; no change to what any member's practice reveals to us.
v2.1 (2026-07-24): Accuracy correction only, no change to data practices: §2.7 (and §2.9, §10) now distinguish free words (matched entirely on your device) from member words (sent to the resolver only to compute their field, never logged, stored, or linked to you). The earlier "never transmitted" wording predated the server-side membership library; nothing about what you seek is retained either way.
v1.9 (2026-07-17): Terminology accuracy only: the IP-derived analytics identifier described as pseudonymous rather than "anonymous", the opt-in feature renamed Usage Analytics, and the "Delete my data" description aligned with the server's auto-expiry.
v1.8 (2026-07-15): Two accuracy corrections, no change to data collected: removed an inaccurate "processed in the United States" statement (processing location now described neutrally), and made the "Delete my data" description match the server (no per-user server-side profile; a filed diagnostic is purged by its support code).
v1.7: Added a Texas (TDPSA) + general U.S. state privacy-rights section (§10); documented that custom-meditation words are matched on-device and never transmitted (§2.7). No change to what data is collected.
v1.6: Gated telemetry on analytics consent; scoped the AI Companion and Vision Deep Scan to the private build; corrected the device-data description; harmonized the age floor (18+, not directed to children under 13); added a California (CCPA) section.
Terms v2.5: Strengthened AI Companion safety language (explicit non-human + 988 crisis referral + no users under 18); committed to 60-day breach notification for health-related data (FTC Health Breach Notification Rule, 16 CFR Part 318); narrowed the liability cap to amounts actually paid (carve-outs for indemnification, gross negligence, willful misconduct, confidentiality); narrowed indemnification to user-submitted content + Prohibited-Use; added a 14-day cure period before non-emergency termination; required 60-day informal resolution before arbitration; codified the material-change re-prompt as a Terms obligation; reaffirmed no sale of sensitive personal data. Aligned scaffolding with 2024–2025 developments (Heckman v. Live Nation; FTC HBNR amendments; FTC AI Companion inquiry). Substantive data practices unchanged.