Effective date: September 23, 2026
1. Introduction and Scope
Deepn LLC (“Deepn,” “we,” “us,” or “our”) provides this Privacy Policy (“Policy”) to explain how we collect, use, disclose, and protect personal information when you visit www.deepnapp.com, use app.deepnapp.com, or otherwise use our platform, content, and services (collectively, the “Services”).
This Policy applies to Members, prospective Members, website visitors, and live-session participants. It forms part of, and should be read together with, our Terms of Service. On matters of privacy and personal information, this Policy controls; on matters of billing and contractual use, the Terms of Service control.
By using the Services, you acknowledge that you have read and understood this Policy. Where applicable law requires consent (for example, for sensitive or special-category data, as described in Section 7), we obtain that consent separately at signup.
The Services are offered worldwide. Deepn LLC is based in the United States, and US law is the primary framework governing this Policy. Where the EU General Data Protection Regulation (GDPR), the UK GDPR, or another local data-protection law applies to you, we comply with that law as described in this Policy (see Sections 16 and 19).
2. Important Notices — Please Read First
(a) We are not a HIPAA-covered entity. Deepn is not a “covered entity” or “business associate” under the U.S. Health Insurance Portability and Accountability Act (“HIPAA”), and HIPAA does not apply to the information we collect. The behavioral, psychological, wellness, and faith-related information you provide is not “protected health information” under HIPAA. It is, however, protected under this Policy and under the consumer-privacy and consumer-health-data laws described below.
(b) Not medical or professional advice. The Services — including all AI features and any coaching — provide self-improvement, educational, and faith-based content only. They are not medical, psychological, psychiatric, or professional therapeutic advice and are not a substitute for licensed care. See our Terms of Service for the full disclaimer and crisis resources.
(c) AI processing is intrinsic to the Services. Personalized AI processing is a core, inseparable part of how the Services work. You cannot use the Services without AI processing of your information as described in Section 8. If you do not want your information processed by AI in this way, please do not use the Services; you may delete your account at any time, which serves as your mechanism to withdraw from this processing.
3. Definitions
Capitalized terms have the meanings given below or where defined elsewhere in this Policy.
- “Account Data” — your name, email address, and authentication credentials.
- “Assessment Data” — your responses to self-assessments, including IAT-style assessments, weekly behavioral assessments, and relationship/attachment profiles.
- “Consumer Health Data” — personal information that identifies your past, present, or future physical or mental health status, as defined by laws such as the Washington My Health My Data Act (“MHMDA”) and Nevada SB 370. For Deepn, this can include Assessment Data, Faith Data, and certain inputs to AI features.
- “Faith Data” — information about your religious or spiritual beliefs and practices, including devotions, commitments, scripture interactions, and related content. This is special-category data under the GDPR.
- “Member” — an individual who holds a Deepn account.
- “Personal Information” / “Personal Data” — information that identifies, relates to, or could reasonably be linked with a particular individual or household. Used interchangeably, including “personal data” under the GDPR.
- “Sensitive Personal Information” — the subset of Personal Information treated as sensitive under U.S. state laws (e.g., CCPA/CPRA) and “special category data” under the GDPR, including Faith Data, Assessment Data revealing mental or behavioral health, and account-linked health-adjacent information.
- “12-week Journey” / “Journey” — a guided program offered through the Services.
- “Services” — as defined in Section 1.
- “Subprocessor” — a third-party service provider that processes Personal Information on our behalf, listed in Section 9 and at deepnapp.com/subprocessors.
4. Who We Are and How to Contact Us
Data controller: Deepn LLC, a California limited liability company.
Legal-notice / business address: 6789 Quail Hill Pkwy, Unit #1008, Irvine, CA 92603, USA.
Privacy requests: support@deepnapp.com and the
privacy request webform.
General contact: support@deepnapp.com.
Where you access the Services. The Services are offered worldwide and are operated from the United States. If you are in the EU/EEA or UK, you may contact us at support@deepnapp.com — or through the EU or UK representative listed in Section 19 — to exercise your data-protection rights.
5. Information We Collect (Notice at Collection)
We collect the following categories of Personal Information, grouped to also serve as our Notice at Collection under California and similar laws. We collect this information directly from you, automatically through your use of the Services, and from our Subprocessors (for example, payment processors confirming a transaction).
| Category | Examples | Source | Purpose (see §7) |
|---|---|---|---|
| Account Data | Name, email, password (via Supabase Auth) | You | Account creation, authentication, service delivery |
| Assessment Data (Sensitive / Consumer Health Data) | IAT-style and weekly behavioral assessment responses; relationship/attachment profiles | You | Personalized guidance, AI Insights, Journeys |
| Faith Data (Special category / Sensitive) | Devotions, commitments, scripture interactions | You | Faith-based content and features |
| User-Generated Content | Community posts; private journal and Journey entries | You | Community features; your personal record |
| AI Inputs and Outputs | Text you submit to AI features; AI-generated insights and content | You / generated | Delivering and operating AI features |
| Payment Data | Billing contact, transaction records, subscription status (full card numbers not stored by us) | Whop | Billing, fraud prevention, recordkeeping |
| Partner Seat Invitations | The email address a paying member gives us for their partner, invitation status, seat status, and dates | The paying member | Sending the invitation, attaching the seat to the partner's own account, billing the seat to the paying member |
| Live-Session Data | Participation; video recordings of coaching calls (captured via Zoom, hosted by Cloudflare Stream) | You / Zoom / Cloudflare | Delivering and providing access to sessions |
| Usage, Device, and Log Data | IP address, device/browser type, pages viewed, timestamps, server logs | Automatic | Security, debugging, service operation |
| Communications Data | Emails and messages you exchange with us (via Resend and WhatsApp/Meta) | You | Support, transactional and marketing communications |
The retention period for each category of Personal Information is set out in Section 13 (Data Retention), which is incorporated into, and forms part of, this Notice at Collection.
We do not intentionally collect government identifiers, precise geolocation, or biometric identifiers.
6. Sensitive and Consumer Health Data
We treat Assessment Data, Faith Data, and related AI inputs as Sensitive Personal Information and, where applicable, as Consumer Health Data.
- We collect and process this data only with your consent, obtained at signup, and only to provide the personalized Services you request (delivering insights, guidance, Journeys, and faith-based features).
- We do not sell this data, do not share it for cross-context behavioral advertising, and do not use it to infer characteristics for advertising.
- Where required by consumer-health-data laws (e.g., MHMDA, Nevada SB 370), we obtain separate consent before collecting Consumer Health Data and a separate authorization before sharing it (we do not share it for our own benefit, and would not do so without your authorization). See Section 18 for your consumer-health-data rights.
7. How We Use Your Information and Our Legal Bases
We use Personal Information to:
- Create and secure your account and authenticate you;
- Provide the Services, including assessments, Journeys, AI Insights, faith-based features, community, and live sessions;
- Personalize content and guidance through AI processing (see Section 8);
- Process payments, manage subscriptions, prevent fraud, and keep financial records;
- Communicate with you (transactional messages, renewal reminders, support, and — with the controls in Section 22 — marketing);
- Operate, debug, secure, and improve the Services, including through aggregated and de-identified analysis;
- Comply with law and enforce our Terms of Service.
Legal bases under the GDPR/UK GDPR. Where the GDPR or UK GDPR applies to our processing of your Personal Information, we rely on the following bases:
- Performance of a contract (Art. 6(1)(b)) — to provide the Services you sign up for, including the AI processing that is intrinsic to them;
- Explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) — for special-category data (Faith Data) and other Sensitive Personal Information, captured at signup; you may withdraw consent at any time by deleting your account, which is the withdrawal mechanism for AI processing that is inseparable from the Services;
- Legitimate interests (Art. 6(1)(f)) — for security, fraud prevention, and service improvement, balanced against your rights;
- Legal obligation (Art. 6(1)(c)) — for tax, accounting, and compliance recordkeeping.
8. AI Features, Profiling, and Automated Processing
What our AI features do. We use AI to generate personalized “AI Insights,” guidance, reflections, and content recommendations, and to power assistive tools (for example, scenario practice, habit/trigger tools, ideal-self vision, and faith features such as devotion, worship, and conversation features). Some video content is AI-generated.
How AI processing works.
- Your inputs (which may include Assessment Data and Faith Data) are processed by third-party large-language-model providers — Anthropic (Claude) and OpenAI — and AI-generated video is produced via HeyGen.
- Training. Based on the providers’ current developer/commercial terms, your inputs and outputs are not used to train their models. We do not train, fine-tune, or build our own AI models. We may use aggregated and de-identified data to analyze and improve the quality of the Services, but we do not use identifiable Member data to train any model.
- De-identified data commitment. Where we rely on de-identified data, we maintain and use it solely in de-identified form, we do not attempt to re-identify it (except as permitted by law solely to test whether our de-identification processes are effective), and we contractually require any recipients to comply with the same commitments.
- Retention by providers. Our AI providers apply their own limited retention windows (approximately 30 days) for abuse-monitoring and operational purposes.
- Accuracy. AI outputs may be inaccurate, incomplete, or unsuitable for your situation. They are informational only and are not professional advice. You are responsible for how you use them.
Profiling and automated decision-making. Our AI Insights profile you psychologically from your Assessment Data to generate personalized guidance. This profiling is:
- Purely advisory and informational. It does not gate access, set pricing, determine eligibility, or produce any legal or similarly significant effect. Accordingly, this processing is not “automated decision-making” of the kind restricted by GDPR Article 22, because it does not produce legal or similarly significant effects.
- Intrinsic to the Services. Because AI processing is core and inseparable, it cannot be disabled separately while continuing to use the Services. Your opt-out / withdrawal mechanism is to delete your account.
For U.S. state profiling rights, see Section 17.
8A. Partner Seats and Linked Accounts
Two accounts, kept apart. A membership can cover two people: the paying member and a partner. Each has a separate account with its own login. We do not show one person's answers, journal entries, assessments, results, or activity to the other. The paying member can see only the email address they entered for the partner and whether the seat has been claimed. The partner has no access to the paying member's billing details.
The partner's email. When a member adds a partner, they give us that person's email address. We use it only to send the invitation, to attach the seat when that person signs up with the same address, and to send the seat's service emails (invitation, seat activated, seat ending). We do not add a partner to marketing lists on the strength of an invitation. We keep the address only while the seat is held for them; it is deleted when the member removes the seat or the membership ends. The member confirms they have the partner's permission before sharing the address.
Who controls the seat. The paying member can remove the partner seat, and the seat also ends when the member's plan ends, including for non-payment. We tell the partner when their seat is ending. The partner's own content stays in the partner's account and remains theirs to export or delete under Section 13 and Section 17.
Linking accounts is separate and mutual. Two members may choose to connect their accounts through the Connections feature. This only happens when one person invites the other from within their account and the other accepts with a confirmed email. While a link is active we share a limited set of self-declared outcomes between the two accounts: attachment style, core wounds, and needs. We never share journal entries, individual answers, check-ins, or conversations. Either person can end the link at any time from Settings; what was already shared stays in the other account as a dated snapshot and nothing new is shared. Holding a partner seat does not link accounts by itself.
Age. A partner must meet the same age and eligibility requirements as any other user (Section 21).
9. Disclosures to Third Parties and Subprocessors
We disclose Personal Information only to service providers and Subprocessors that process it on our behalf, under contract and for the purposes described above. We maintain a current public list at deepnapp.com/subprocessors and update that list when we add or replace Subprocessors. Our current Subprocessors are:
- Supabase — authentication, database, and storage hosting;
- Vercel — application hosting and cookieless Web Analytics;
- PostHog — product analytics, run in cookieless mode (no tracking cookie; visits are counted from a short-lived server-side hash, and signed-in activity is keyed by a one-way hash of the account email, never the address or name);
- Whop — subscription, renewal, and coaching-package payment processing (PCI-DSS compliant);
- Zoom — live calls and the temporary recording of a call (deleted once our copy exists);
- Cloudflare — hosting and streaming of call recordings (Cloudflare Stream);
- Anthropic and OpenAI — AI/LLM processing;
- HeyGen — AI-generated video;
- Vimeo — video hosting;
- Resend — transactional and marketing email and renewal reminders;
- GoHighLevel (HighLevel Inc.) — marketing platform: checkout follow-up, waitlists, and (with your express consent) text messages;
- WhatsApp / Meta — lead and Member communications.
We may also disclose Personal Information: (a) to comply with law, legal process, or lawful requests; (b) to protect the rights, safety, and property of Deepn, our Members, or the public; and (c) in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honor this Policy or notify you of any material change.
10. We Do Not Sell or “Share” Your Personal Information
We do not sell Personal Information for money or other valuable consideration, and we do not “share” it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA and similar laws. We do not use advertising pixels or ad-tech and do not engage in targeted advertising. We honor Global Privacy Control (GPC) browser signals as a valid opt-out of sale/sharing, even though we do not sell or share.
11. Cookies and Tracking Technologies
We use essential/functional cookies only — primarily an authentication session cookie that keeps you signed in. Our analytics (Vercel Web Analytics and PostHog) are cookieless and does not set tracking cookies or collect directly identifying information. Because we use essential-only cookies and cookieless analytics, no cookie consent banner is required, and this Section serves as our cookie notice. You can control cookies through your browser settings, but disabling the authentication cookie will prevent you from signing in.
12. Live Sessions and Recordings
Our weekly group coaching calls are recorded by video. Q&A calls and one-on-one (1:1) coaching sessions are not recorded. You will be notified that a call is being recorded when you join it, and joining is how you consent; if you do not want to be recorded, do not join the live call and watch the recording afterwards instead. After a call, the recording is copied to Cloudflare Stream, our video hosting provider, and the temporary copy Zoom made is deleted. We do not keep transcripts. Recordings can be watched only inside the Deepn platform by Members whose access includes that call, including those who were eligible to attend but did not; they cannot be downloaded, and each viewing link expires within an hour. Every recording is permanently deleted 90 days after the call it captures (Section 13). See our Terms of Service for recording-consent terms, including one-/two-party-consent considerations.
13. Data Retention
We retain Personal Information only as long as needed for the purposes described in this Policy, then delete or de-identify it. Our standard periods:
| Data type | Retention |
|---|---|
| Account Data | Life of the account; deleted within 30 days of account deletion, except where retention is required to resolve a dispute or comply with law |
| Assessment Data (sensitive / consumer-health) | While the account is active; purged within 30 days of account deletion |
| Faith Data (special category) | While the account is active; purged within 30 days of account deletion |
| Private journal / Journey entries | Deleted upon account deletion |
| Community posts | Anonymized and retained after account deletion — content remains to preserve community discussions but is disassociated from you and attributed to a “Former member,” with personal identifiers removed |
| AI inputs/outputs logs | Up to 30 days for operations, debugging, abuse-prevention, and safety, then deleted or de-identified (providers apply ~30-day windows; no model training) |
| Call recordings | 90 days after the call, then permanently deleted (Zoom's temporary copy is deleted as soon as ours is ready; no transcripts are kept) |
| Payment/billing records | Approximately 7 years for tax, accounting, and financial-recordkeeping laws (no full card numbers stored) |
| Server/access logs | Identifiable logs up to 90 days; aggregated/de-identified analytics may be kept longer |
| Backups | Deleted data may persist in encrypted backups up to 30 days before purge in the normal rotation |
Account-deletion turnaround. We complete deletion of personal data within 30 days of a verified deletion request. For complex requests, this may be extended to the extent permitted by law (e.g., up to 45 or 90 days), and we will notify you if an extension is needed.
De-identified data. Where this Policy refers to retaining data in aggregated or de-identified form, the de-identification commitment in Section 8 applies: we maintain such data solely in de-identified form and do not attempt to re-identify it.
14. Data Security
We maintain reasonable technical and organizational measures designed to protect Personal Information, including encryption in transit and at rest and access controls. No system is perfectly secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
15. Data Breach Notification
If a breach affecting your Personal Information occurs, we will notify affected Members and applicable regulators without undue delay and as required by applicable law, consistent with the GDPR’s 72-hour supervisory-authority notification timeline.
16. International Data Transfers
We are based in the United States and operate the Services from the United States, where your Personal Information is stored and processed. Because we offer the Services worldwide, if you use them from outside the United States your information will be transferred to and processed in the United States and in other countries where our Subprocessors operate, which may have different data-protection laws than your country. Where we transfer Personal Information from the EU/EEA, UK, or another region whose laws require transfer safeguards, we rely on appropriate mechanisms such as the EU Standard Contractual Clauses, supplemented where applicable by the UK International Data Transfer Addendum. You may request more information about these safeguards at support@deepnapp.com.
17. Your Privacy Rights (U.S. State Laws)
Depending on your state of residence (including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Texas, and other states with comprehensive privacy laws), you may have the right to:
- Know / Access the categories and specific pieces of Personal Information we have collected;
- Correct inaccurate Personal Information;
- Delete your Personal Information;
- Portability — receive a copy in a portable format;
- Opt out of the sale or sharing of Personal Information (we do not sell or share);
- Opt out of targeted advertising (we do not conduct it);
- Opt out of profiling that produces legal or similarly significant effects (our profiling is advisory only and does not produce such effects; you may withdraw from all AI processing by deleting your account);
- Limit use of Sensitive Personal Information (we already limit it to providing the Services);
- Non-discrimination for exercising your rights.
How to exercise your rights. Submit a request through our privacy request webform or by emailing support@deepnapp.com. We will verify your identity before responding. You may use an authorized agent where the law allows. We respond within the timelines required by applicable law (generally 45 days, extendable by an additional 45 days for complex requests, with notice).
Right to appeal. If we deny your request, you may appeal by replying to our decision or emailing support@deepnapp.com with “Appeal” in the subject line. We will respond to your appeal within the timeframe required by your state’s law (generally 45–60 days). If we deny your appeal, you may contact your state Attorney General.
18. Consumer Health Data Privacy Notice (Washington MHMDA, Nevada SB 370, and Similar)
This Section is our Consumer Health Data Privacy Notice for laws such as the Washington My Health My Data Act and Nevada SB 370.
- What we collect: Assessment Data, Faith Data, and certain AI inputs that may reveal mental, behavioral, or wellness status (see Sections 5–6).
- Sources and purposes: Collected from you, with consent, to provide the personalized Services.
- Consent and authorization: We obtain your consent before collecting Consumer Health Data and would obtain a separate written authorization before sharing it (we do not share it for our own benefit).
- No sale: We do not sell Consumer Health Data and will not do so absent valid authorization.
- Your rights: You may access, withdraw consent, and delete your Consumer Health Data by emailing support@deepnapp.com or using our webform. We honor deletion across our systems and instruct our Subprocessors to do the same, subject to the retention exceptions in Section 13.
- List of recipients: You may also request a list of all third parties and affiliates with whom we have shared Consumer Health Data, together with an active contact email address for each. (Our current recipients are the Subprocessors listed in Section 9, acting on our behalf.)
- Who can access it: Only authorized personnel and the Subprocessors listed in Section 9, as needed to provide the Services.
19. EU/UK Rights and Other Regions
If you are in the EU/EEA or UK, the GDPR or UK GDPR applies to our processing of your Personal Information, and we comply with it. You have the rights to access, rectification, erasure, restriction, portability, objection, and withdrawal of consent, and the right to lodge a complaint with your supervisory authority (in the UK, the Information Commissioner’s Office (ICO)). Please contact us first at support@deepnapp.com. Because AI processing is intrinsic to the Services, account deletion is the mechanism to withdraw consent.
EU representative: [EU REPRESENTATIVE — to be appointed]
UK representative: [UK REPRESENTATIVE — to be appointed]
Other regions.
- Brazil (LGPD): you have the rights provided by the Lei Geral de Proteção de Dados, including confirmation of processing, access, correction, anonymization, and deletion. Submit requests to support@deepnapp.com.
- Canada (PIPEDA / Quebec Law 25): you may access and correct your Personal Information and withdraw consent, and you may complain to the Office of the Privacy Commissioner of Canada or your provincial privacy regulator.
- Australia: we handle Personal Information consistent with the Australian Privacy Principles. You may complain to us first, and then to the Office of the Australian Information Commissioner (OAIC).
20. Additional California Disclosures
The table in Section 5, together with the retention periods in Section 13, serves as our Notice at Collection. We have not sold or shared Personal Information in the preceding 12 months. We disclose Personal Information for business purposes only, to the Subprocessors in Section 9. California’s “Shine the Light” law: because we do not share Personal Information with third parties for their own direct marketing, no Shine the Light disclosure is required.
21. Children’s Privacy
The Services are intended for adults 18 and older, and we do not knowingly collect Personal Information from anyone under 18 — and in no event from children under 16. The Services are not directed to children. If we learn that we have collected information from someone under 18, we will delete it. This Section is consistent with COPPA and GDPR rules on children’s data (“GDPR-K”).
22. Marketing Communications, Email, and Text Messages
We send transactional messages (e.g., account, billing, renewal reminders, and security notices) as part of the Services; you cannot opt out of these while you hold an account. We may also send marketing emails via Resend. You can unsubscribe from marketing at any time using the link in each marketing email or by emailing support@deepnapp.com, consistent with the CAN-SPAM Act. We may also communicate with you via WhatsApp/Meta where you have initiated or agreed to that channel.
Checkout follow-up. When you enter your email at a checkout or offer page and accept these policies, we may send you follow-up emails about that purchase — including reminders if you start but do not complete it — via our marketing platform (GoHighLevel). Every such email includes an unsubscribe link, and unsubscribing never affects your access or transactional messages.
Text messages (SMS). Where you separately provide your phone number and expressly consent — for example, by joining a challenge or waitlist text list — we may send you text messages about that program via our marketing platform (GoHighLevel). Consent to texts is never a condition of purchase. Message and data rates may apply. You can opt out at any time by replying STOP to any message or emailing support@deepnapp.com, consistent with the TCPA.
Checkout and waitlist information. If you begin a checkout or join a waitlist, the email address (and, for waitlists, the name and phone number) you provide may be added to our marketing platform so we can follow up about that purchase or program, subject to the opt-out rights above.
23. Third-Party Links
The Services may link to third-party websites or services we do not control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. Review their policies before providing information.
24. Changes to This Policy
We may update this Policy from time to time. We will revise the “Last Updated” date and, for material changes, notify Members by email and in-app and provide at least 30 days’ advance notice before the change takes effect. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy.
25. Contact Us
Deepn LLC, 6789 Quail Hill Pkwy, Unit #1008, Irvine, CA 92603, USA
Email: support@deepnapp.com ·
Privacy request webform