Help Center

Trust Center

How Onsen protects your data, who else processes it, and what we are working on.

Onsen holds some of the most personal writing people do. This page sets out how we protect it, who else touches it, and what we are still working on.

How your writing is handled

Encrypted throughout

Encrypted in transit and at rest. Database connections require TLS.

Stored in Ireland

Primary data lives in AWS eu-west-1. Content delivery certificates are in us-east-1.

Never sold

We do not sell personal data, and we do not use your journal entries to train AI models.

Yours to take or delete

Export everything or delete your account from Settings, without asking us.

Your journal entries are health information, and we treat them that way. We ask for your explicit consent before processing them, and we record when you gave it.

Certifications and assessments

ItemStatusDetail
Independent penetration testCompleteApril 2026, covering the API, iOS, Android, external attack surface and dark web. Summary available under NDA
Data Protection Impact AssessmentCompleteAvailable to institutional customers on request
Record of Processing ActivitiesCompleteUK GDPR Article 30
Cyber EssentialsIn progressExpected September 2026
Cyber Essentials PlusPlannedFollowing Cyber Essentials
ISO 27001PlannedTimed to customer requirement

We list only what we hold. Where something is planned rather than achieved, we say so, because a certification claim is the easiest thing in the world for you to check.

Subprocessors

These companies process personal data on our behalf. Institutional customers receive 30 days' notice before we add a new one.

CompanyPurposeLocation
Amazon Web ServicesHosting, database, storage, authenticationIreland; US for CDN certificates
OpenAIAI generation for conversation, summaries, images and speechUnited States
AWS BedrockSearch reranking over journal embeddingsEU (Germany)
OneSignalPush notifications and emailUnited States
SentryError and crash monitoringUnited States
AmplitudeProduct analyticsUnited States
AdjustInstall attributionEU / United States
MailchimpProduct update emailsUnited States
GoogleSign-in and app store servicesUS / EU

Discourse (our community forum) and Metabase (our analytics tool) are self-hosted on our own infrastructure in Ireland, so neither vendor receives user data.

We are migrating email from Mailchimp to OneSignal, which will remove one processor from this list. We will update this page when it completes.

For institutional customers

If you are deploying Onsen for students or employees, the sponsoring organisation never sees an individual's writing, conversations, questionnaire responses or engagement. Reporting is aggregate only, and is suppressed for cohorts below our minimum size.

We do not provide any organisation with an AI-generated inference about how a named person feels. This is a design commitment, and it is written into our data processing agreement.

Available on request: our DPA, DPIA, Article 30 extract, penetration test summary, and completed security questionnaires. Contact privacy@onsenapp.com.

Reporting a vulnerability

Email security@onsenapp.com. We acknowledge within 3 business days and will not pursue legal action for good-faith research conducted under our disclosure policy.