Privacy Policy
Last updated: September 2026
This policy explains what personal data we process when you visit cinfold.app, join the waitlist or use the Cinfold app, why we do it, and what rights you have.
1. Who is responsible
Interlace GmbH
Auguststraße 1, 10117 Berlin, Germany
Managing director: Andreas Stefan Peters
Email: info@interlace.software
We have not appointed a data protection officer because we are not legally required to. For all privacy questions, write to the address above.
2. Summary
- We only process the data needed to run the website, the waitlist and the app.
- We don't use analytics, tracking or advertising cookies, and we don't sell data.
- Your goals are private by default. People in your inner circle only see what you actively share with them.
- Our data is hosted in the EU (Frankfurt, Germany).
- You can delete your account and all your personal data at any time in the app.
3. Visiting the website
When you open cinfold.app, our hosting provider automatically processes technical data that your browser sends: IP address, date and time, page requested, referrer, browser and operating system. This is required to deliver the website and keep it secure.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, working website).
- Retention: server logs are deleted automatically after a short period, at most 30 days, unless needed to investigate a security incident.
Fonts and all other website files are served from our own domain. No data is sent to Google or other font providers.
4. Waitlist
If you join the waitlist, we store:
- your email address,
- the email addresses of the friends you enter,
- the time of sign-up and the language of the page.
We use this to invite you (and, together with you, your inner circle) to the test phase and to understand how many people are interested. After you sign up you get one confirmation email; when it's your turn, one invitation email.
- Legal basis for your email: Art. 6(1)(a) GDPR (your consent by submitting the form). You can withdraw consent at any time by emailing us; your entry is then deleted.
- Friends' email addresses: you may only enter people who agree to be contacted about Cinfold. We store their addresses only to group you as an inner circle. We do not send them marketing emails. If we contact them at all, it is a single invitation that you asked us to send, and we delete their address if they don't respond or object. Legal basis: Art. 6(1)(f) GDPR.
- Retention: until the waitlist is closed or you withdraw, at most 12 months after sign-up.
5. Using the app
Account and login
To create an account and log in we process your email address and your password. You log in with your email and password, or with a one-time link sent to your email ("magic link"). Your password is stored only as a secure, irreversible hash by our login provider; we cannot see it.
Profile
Your display name, optionally a profile photo and location. The people in your inner circle see your name and photo.
Goals and check-ins
The goals you enter (vision, 5-year goal, 2-year goal, OKRs and key results), their status, your weekly check-ins (traffic light per OKR) and your archived goals.
Mood
In the weekly check-in you can optionally rate your mood from 1 to 10. This is voluntary. You decide in each check-in and in the settings whether your inner circle can see it.
Inner circle and challenges
Your connections to other users (via invite code or link) and who invited you, the challenges and requests you send (statement, open question and, if you give one, your own score from 1 to 10, which only you can see), and the answers you give (score 1–10 and text). An answer is visible only to you and to the person who asked. You can delete your own answers.
Notifications and usage
In the app you get notifications, e.g. when someone answers you, challenges you or joins your inner circle. They are stored in your account until you delete it. We also store when you last opened the app, and count activity (such as the number of goals, check-ins and answers) to see how Cinfold is used. We look at these numbers only in our own admin overview, never share them, and don't use any tracking or analytics service for this.
What we need this data for
To provide the app features you use: your goal overview, sharing with your inner circle, challenges, answers and notifications. We use the activity counts to run and improve Cinfold (legitimate interest, Art. 6(1)(f) GDPR).
- Legal basis: Art. 6(1)(b) GDPR (performance of the contract of use). Where you share mood data, Art. 6(1)(a) and Art. 9(2)(a) GDPR (your consent, which you can withdraw at any time via the settings).
- Retention: as long as your account exists. When you delete your account, we delete your profile, goals, check-ins, mood data and connections. Answers you gave to other people's challenges are deleted as well. Backups are overwritten within 30 days.
Review report (optional)
If you create a review report, we send the data from the report period (from the day you joined for your first reports, then the past quarter) to our AI provider Anthropic, which writes the report: your display name, your goals and key results, your weekly check-ins including your mood, and the challenges and follow-ups on your goals with the answers from your inner circle. We only do this after you have given your consent in the app, and only when you press the button. Anthropic processes the data only to write the report and does not use it to train its models. The finished report is stored in your account and only you can see and download it. Free reports unlock 24 hours and 7 days after you join, then once per quarter. Mood is only included in quarterly reports.
- Legal basis: Art. 6(1)(a) and Art. 9(2)(a) GDPR (your consent, which you can withdraw at any time by emailing us; withdrawal does not affect reports created before).
- Retention: reports are kept until you delete your account. Anthropic deletes the data sent to it after a short retention period set out in its commercial terms.
Technically necessary storage on your device
The app stores a session token (to keep you logged in) and your language choice in your browser. This is strictly necessary to provide the service you requested (§ 25(2) no. 2 TDDDG). We use no other cookies or similar technologies.
6. Service providers
We use the following processors. Each is bound by a data processing agreement under Art. 28 GDPR.
| Provider | Purpose | Location of processing |
|---|---|---|
| Supabase Inc., USA | Database, login (including login emails), photo storage | EU (Frankfurt, Germany) |
| Vercel Inc., USA | Website and app hosting | EU edge network; possibly USA |
| Anthropic PBC, USA | Writing the optional review report (AI) | USA |
| Resend (Plus Five Five, Inc.), USA | Sending emails: login links, waitlist confirmation and invitation | EU (Ireland) |
Because these providers are US companies, access from the USA cannot be completely ruled out. Such transfers are based on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where the provider is certified, on the EU-US Data Privacy Framework (Art. 45 GDPR).
7. Who else sees your data
- Your inner circle: only what you share. That is your name and photo, the goals you share with specific people, your mood if you share it, and the challenges you send them.
- Us, as operators: in an admin overview we see your name, email, when you joined and last opened the app, and the number of your goals, check-ins and answers – not their content.
- Nobody else. We don't sell or rent data and don't pass it on for advertising. We only disclose data to authorities if we are legally obliged to.
8. Your rights
You have the right to:
- access your data (Art. 15 GDPR),
- rectification (Art. 16),
- erasure (Art. 17), which you can do directly in the app with "Delete account",
- restriction of processing (Art. 18),
- data portability (Art. 20),
- object to processing based on legitimate interest (Art. 21),
- withdraw consent at any time with effect for the future (Art. 7(3)).
To exercise these rights, email info@interlace.software.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, www.datenschutz-berlin.de
9. Minimum age
Cinfold is intended for people aged 16 and over.
10. Security
Data is transmitted encrypted (HTTPS). Access to data in our database is restricted by access rules, so users can only read what they own or what has been shared with them.
11. Changes
We update this policy when the app or the legal situation changes. The current version is always available at cinfold.app/privacy.