Privacy
Who we are
Deepdose is a chemistry soul-matching network. We help you understand your rhythm and chemistry, share what you choose, and connect with people on a similar clock. The controller for personal data is the operator of deepdose.org. Contact: privacy@deepdose.org.
What we collect
Account data (email, display name, password credentials via our auth provider). Profile details you enter (rhythm, preferences, optional medications). Optional wearable data you authorise. Chat and Connect content you send. Technical logs for security and reliability. Support and safety reports you submit.
Special category (health) data
Rhythm, sleep, optional medication lists, and wearable biometrics are health-related. We process them only when you provide them or connect a device, to run matching, profile, and related features you request. We do not sell this data. Deepdose is not emergency care or a clinic.
Why we use your data (purposes & legal bases)
Provide and secure the service (contract / legitimate interests). Create your account and authenticate you (contract). Personalise chemistry matching and connection features (contract / consent where required). Optional research contributions only if you opt in (consent). Safety, abuse prevention, and legal compliance (legitimate interests / legal obligation). Product analytics in aggregate or with privacy-preserving methods where possible (legitimate interests; consent for non-essential cookies if used).
Wearables and third parties
If you connect a wearable, we receive data under your OAuth consent with that provider. Their privacy policy also applies. We use infrastructure providers (for example hosting, database, and authentication such as Supabase) as processors under contract. We do not allow processors to use your data for their own marketing.
Chat, Connect, and visibility
Messages and match interactions are visible to people in that conversation and to Deepdose for safety, abuse review, and service operation. Do not share someone else’s private health or identity information without permission.
Cookies and similar tech
We use essential cookies/storage for sign-in and security. If we add analytics or marketing cookies, we will ask for consent where required and list them here. You can control cookies in your browser; blocking essential cookies may break sign-in.
How long we keep data
We keep account and service data while your account is active and for a reasonable period afterward for security, disputes, and legal duties. You may request deletion; we will erase or anonymise unless we must retain something (for example fraud prevention or legal claims). Wearable tokens are removed when you disconnect or delete your account.
Your rights (UK GDPR)
You can request access, correction, erasure, restriction, portability, and object to certain processing. Where we rely on consent, you can withdraw it. You can complain to the UK Information Commissioner’s Office (ICO). To exercise rights, email privacy@deepdose.org. We may need to verify your identity.
International transfers
Our processors may store data outside the UK/EEA. Where that happens, we use appropriate safeguards (such as standard contractual clauses) required by UK GDPR.
Children
Deepdose is for adults 18+. We do not knowingly collect data from anyone under 18. If we learn an account belongs to a minor, we will delete it.
Security
We use industry-standard measures (encryption in transit, access controls, row-level security on user data where applicable). No method is perfect; protect your password and device.
Changes
We may update this policy. Material changes will be posted on this page with a new “Last updated” date. Continued use after changes means you accept the updated policy where permitted by law.