Trust Center
How Onsen protects your data, who else processes it, and what we are working on.
Onsen holds some of the most personal writing people do. This page sets out how we protect it, who else touches it, and what we are still working on.
How your writing is handled
Encrypted throughout
Encrypted in transit and at rest. Database connections require TLS.
Stored in Ireland
Primary data lives in AWS eu-west-1. Content delivery certificates are in us-east-1.
Never sold
We do not sell personal data, and we do not use your journal entries to train AI models.
Yours to take or delete
Export everything or delete your account from Settings, without asking us.
Your journal entries are health information, and we treat them that way. We ask for your explicit consent before processing them, and we record when you gave it.
Certifications and assessments
| Item | Status | Detail |
|---|---|---|
| Independent penetration test | Complete | April 2026, covering the API, iOS, Android, external attack surface and dark web. Summary available under NDA |
| Data Protection Impact Assessment | Complete | Available to institutional customers on request |
| Record of Processing Activities | Complete | UK GDPR Article 30 |
| Cyber Essentials | In progress | Expected September 2026 |
| Cyber Essentials Plus | Planned | Following Cyber Essentials |
| ISO 27001 | Planned | Timed to customer requirement |
We list only what we hold. Where something is planned rather than achieved, we say so, because a certification claim is the easiest thing in the world for you to check.
Subprocessors
These companies process personal data on our behalf. Institutional customers receive 30 days' notice before we add a new one.
| Company | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, database, storage, authentication | Ireland; US for CDN certificates |
| OpenAI | AI generation for conversation, summaries, images and speech | United States |
| AWS Bedrock | Search reranking over journal embeddings | EU (Germany) |
| OneSignal | Push notifications and email | United States |
| Sentry | Error and crash monitoring | United States |
| Amplitude | Product analytics | United States |
| Adjust | Install attribution | EU / United States |
| Mailchimp | Product update emails | United States |
| Sign-in and app store services | US / EU |
Discourse (our community forum) and Metabase (our analytics tool) are self-hosted on our own infrastructure in Ireland, so neither vendor receives user data.
We are migrating email from Mailchimp to OneSignal, which will remove one processor from this list. We will update this page when it completes.
For institutional customers
If you are deploying Onsen for students or employees, the sponsoring organisation never sees an individual's writing, conversations, questionnaire responses or engagement. Reporting is aggregate only, and is suppressed for cohorts below our minimum size.
We do not provide any organisation with an AI-generated inference about how a named person feels. This is a design commitment, and it is written into our data processing agreement.
Available on request: our DPA, DPIA, Article 30 extract, penetration test summary, and completed security questionnaires. Contact privacy@onsenapp.com.
Reporting a vulnerability
Email security@onsenapp.com. We acknowledge within 3 business days and will not pursue legal action for good-faith research conducted under our disclosure policy.