KERN
Deutsch

Privacy Policy

Last updated: May 27, 2026
KERN is an app for inner work - and this is first and foremost about personal things. So we handle your data the way we'd want ours handled: respectfully. This policy tells you in plain language what we store, where it goes, and what we deliberately don't do.

Quick read - you're safe here

Before the details, here's in plain language what happens in the background.

The rest of this page explains it in detail, if you want to look deeper.


1. Who is responsible?

The data controller for this app is:

Dennis Lisk
Brunnenstr. 28
10119 Berlin
Germany

Email: hello@getkern.app

For privacy questions, write directly to: datenschutz@getkern.app

2. What we store

KERN works with three layers of data:

a) What you do in the app (local on your device)

This data always lives on your iPhone - regardless of which backup option you choose:

You don't give us any identifiers - no email, no name, no phone number. The profile is anonymous on your device.

b) What our servers see in any case - even without cloud backup

For KERN to work at all (e.g. to generate AI responses, check rate limits), we need a technical identity for you. So on first app launch, KERN automatically creates an anonymous user UUID on our servers in Frankfurt. This UUID:

c) Cloud backup (only if you want it)

During onboarding you additionally choose whether KERN mirrors your content (reflections, insights, vision, history) on our servers. You can change this choice anytime in settings.

When cloud backup is on, we additionally process:

d) AI responses (when you reflect)

When KERN responds to a reflection or summarizes an insight, the text of your reflection is sent to Anthropic (the company behind the Claude AI model) - without your identity. Anthropic does not learn who writes, only what. Anthropic does not train on your content (contractually excluded) and stores API inputs for at most 30 days as an operations log, then deletes them. Transmission runs TLS-encrypted. More details in section 4.

3. What we use this data for

We don't use your data for advertising. We don't sell it. We don't train AI on your content.

Legal basis: Art. 6(1)(b) GDPR (contract - you use the app, we provide the function) and Art. 6(1)(a) GDPR (your consent for the cloud choice).

4. Who sees your data?

We work with two processors. These are the only external parties that technically process your data:

Supabase (EU)

Supabase is always active (for your anonymous UUID, see section 2.b). Your content (reflections, insights, etc.) only goes to Supabase if you've enabled cloud backup or when KERN is fetching an AI response for you.

Anthropic (USA)

If the US transfer feels too uncertain despite SCC, you can continue to use the app, but AI features (Mirror, automatic insight extraction, affirmation generation) won't be available. We're currently building an option to route all AI calls through EU-hosted models - update to follow.

Apple (USA)

If you sign in with Apple Sign-In, Apple handles the login. Apple sees only that you use KERN, not what you input. Details: apple.com/legal/privacy.

5. What we anonymously measure - and what not

🔍 These statements are auditable. Schema, code-of-conduct and all relevant database migrations live in the public kern-legal-docs repository - with full version history and commit reasoning. If anything is different from what's described here, you can see it yourself.

So you know exactly what happens:

What we measure in numbers (anonymous, no content):

These numbers help us improve the app (e.g., "is the character cap too tight?", "where do users drop off?"). They land in a separate database table usage_events that by design has no text columns for content. Your user ID is hashed with a secret key before saving - we see "Hash-User-abc had 5 reflections", not "Anna had 5 reflections".

Schema publicly visible in our Legal repo: migrations/0005_usage_events.sql (Repo: kern-legal-docs)

What we deliberately don't do:

6. How long we keep your data

7. Your rights (GDPR)

You have the right, anytime, to:

For all of these: send a short email to datenschutz@getkern.app. We respond within 30 days. Usually much faster.

Inside the app:

8. Right to lodge a complaint

If you believe we're not handling your data properly, you can complain to the data protection authority. For KERN, the responsible authority is:

Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI)
Friedrichstr. 219, 10969 Berlin, Germany
Phone: +49 30 13889-0
Email: mailbox@datenschutz-berlin.de

9. Government requests

We only disclose data to authorities when legally required - i.e. when a German court or competent German authority compels us under valid law. In that case we notify you, to the extent legally permitted.

We do not disclose data to US authorities on US requests, because our data is in the EU and we are not subject to US jurisdiction.

10. Push notifications

If you enable push notifications (optional), they run entirely locally on your iPhone. Content and timing are decided on your device - no server watches along, not even Apple's. Apple sees neither that you use notifications, nor when, nor with what content.

11. Changes to this policy

If processing changes, we update this page and show you a note on the next app start. The date at the top tells you when the policy was last changed.

12. Contact

Questions? Concerns? Write us: hello@getkern.app

For formal privacy requests: datenschutz@getkern.app