Circles — Privacy Policy
Effective date: 10 September 2026 Last updated: 10 September 2026
1. Who we are
Circles is operated by Carlos Puigjaner, an individual developer established in Spain (the “we”, “us”, or “controller” in this policy).
Contact for privacy matters: carlospv@gmail.com
Supervisory authority: Agencia Española de Protección de Datos (AEPD, aepd.es) — you can lodge a complaint with the AEPD or with your local EU data protection authority at any time.
2. What Circles is
Circles is a personal relationship app: it helps you stay in meaningful, regular contact with the people who matter to you. You create entries for your own contacts, organize them into circles of closeness, set how often you’d like to reach out, log your interactions, and receive AI-generated suggestions to make each contact more thoughtful.
This has an important consequence: most of the data in Circles is data you write about other people (your contacts). Section 5 explains your role and responsibilities for that data.
3. Data we process
3.1 Your account
- Email address and name — from your sign-up method (email, Google, or Apple).
- Password — only if you sign up with email; stored as a bcrypt hash, never in plain text.
- Social sign-in identifiers — the stable account ID Google or Apple provides (not your password).
- Preferences — daily reminder time, timezone, push notification token (if you enable reminders).
- Away periods — date ranges you mark as time away (vacation mode), used to pause reminders and contact schedules.
- Consent records — the timestamp when you acknowledged the notes privacy notice.
3.2 Your contacts (data about third parties)
For each contact you choose to add, you may store:
- Name, last name, nickname, relationship type.
- Important dates (birthdays, anniversaries, other dates you add).
- Timezone.
- Free-text notes — anything you write about them.
- Interaction history — channel (call / message / in person), dates, status, and optional per-interaction notes.
- Contact frequency preferences (how often you want to reach out, per channel).
3.3 Technical and service data
- IP address — processed transiently for rate limiting (abuse protection); not stored in application data.
- Error diagnostics — technical error reports (error type, stack trace, endpoint) sent to our EU-hosted error monitoring service, explicitly configured to exclude personal data (no notes, no emails, no request bodies, no local variables).
- Payment data — subscriptions are processed by Apple through In-App Purchase. Apple is the merchant for your purchase; we never receive or store your card details.
4. What we use data for, and on what legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing the service (accounts, contact schedules, reminders, history) | Account data, contacts data | Performance of a contract (Art. 6(1)(b) GDPR) |
| AI-generated contact suggestions and note summarization (see §6) | Contact notes, relationship type, important dates, days since last contact — never the contact’s name | Performance of a contract — these features are a core part of the service you sign up for |
| Daily reminder push notification | Push token, timezone, reminder time, count of people due | Performance of a contract |
| Security (rate limiting, authentication, session revocation) | IP (transient), credentials | Legitimate interest (Art. 6(1)(f)) — keeping the service secure |
| Error monitoring | Technical diagnostics (no personal data) | Legitimate interest — service reliability |
| Payments | Handled by Apple as merchant | Performance of a contract |
Data about your contacts is processed on the basis of legitimate interest (Art. 6(1)(f)): your interest in maintaining your own personal relationships — the same interest that has always justified a personal address book or diary. That interest is balanced by strict limits we build into the product: your contacts’ data is private to your account, is never shared with other users or third parties, is never used for advertising, profiling, or any purpose other than providing the service to you, and is deleted the moment you delete it or your account.
5. Data about your contacts — your role
The people you add to Circles are your contacts: they are not users of the app and Circles has no relationship with them. You decide what to record about them, and you are responsible for that content.
- Write only what you’d be comfortable with them reading. Notes are private to your account, but they are personal data about real people.
- Sensitive information. Do not record special-category data about others (health, religion, political opinions, sexual orientation, etc.) unless you have a genuine personal reason tied to caring for that relationship. Such notes stay private to your account and are used for nothing beyond providing the service to you. Recording data about others in ways that harm them is prohibited by our Terms of Service.
- Their rights. If someone whose data a user stored in Circles contacts us to exercise their rights, here is what we do: we verify the request, and where the requester can be identified in the data at issue, we will delete or anonymize the data referring to them, informing the account holder where appropriate. Requests: carlospv@gmail.com. We respond within one month.
6. AI processing (Anthropic Claude)
Circles uses Anthropic’s Claude API (a commercial AI service) for three things. Each one receives a different, deliberately limited slice of data:
- Contact suggestions — short, thoughtful prompts about how to reach out. To write them, your contact’s notes, relationship type, important dates and timing signals are sent to Anthropic. The contact’s name is deliberately never sent.
- Note summarization — merging your quick post-interaction notes into a contact’s notes. The notes being merged are sent; the name is not.
- The monthly letter — the letter that closes each month’s story. This is the most restricted of the three: Anthropic receives only structural signals — how many conversations you had and on which days, through which channel (call, message, in person), the contact rhythm you chose for each person and whether the month kept it, and whether you had marked time away. No notes, no relationship type, no important-date labels and no names are sent: every person is replaced by a placeholder token before the request leaves our server, and the real names are put back only after the letter comes back. This restriction is enforced by an automated test in our codebase.
For all three:
- Anthropic processes this data as our processor under a Data Processing Agreement and does not use it to train AI models.
- Anthropic processes data on infrastructure outside the EU (including the United States). This is the only international transfer of personal data in Circles — see §8.
7. Who else processes data (sub-processors)
| Provider | Role | Data received | Location |
|---|---|---|---|
| Railway | Hosting + database | All application data | EU (Amsterdam, Netherlands); encrypted at rest |
| Anthropic | AI suggestions & note summarization | Contact notes and context — no names | United States / worldwide (SCCs — see §8) |
| Sentry | Error monitoring | Technical diagnostics only — no personal data | EU |
| Expo | Push notification delivery | Push token + notification text (a count; no contact data) | United States |
| Apple / Google | Sign-in; Apple also payments | Your sign-in identity; payment data (Apple only) | Act as independent controllers under their own privacy policies |
8. International transfers
All application data is stored in the EU. The only personal data leaving the EU goes to Anthropic (§6), safeguarded by the Standard Contractual Clauses included in Anthropic’s Data Processing Agreement, together with supplementary measures: contact names are excluded from what we send, and transport encryption is enforced end-to-end. Expo (push delivery) receives only your device push token and a notification containing a number — no contact data.
9. Retention and deletion
- Your data lives as long as your account does. Everything you store remains available to you until you delete it or delete your account. We do not expire or clean up inactive accounts without notice.
- Account deletion is immediate and complete: deleting your account (Settings → Delete my account) permanently removes your account and all data in cascade — contacts, notes, interactions, schedules, away periods, AI suggestions. There is no soft-delete or recovery.
- Database backups exist solely for disaster recovery and expire automatically on a rolling basis: daily backups are kept for roughly one week, and a point-in-time recovery archive covers approximately the previous four weeks. Deleted data disappears from backups as they expire.
10. Your rights
Under the GDPR you can, at any time:
- Access the data we hold about you (the app itself shows essentially all of it).
- Rectify anything inaccurate (editable directly in the app).
- Erase your data (delete individual contacts, interactions, or your whole account in-app).
- Export / portability — request a machine-readable export of your data by email; we provide it within one month.
- Object to or restrict processing based on legitimate interest.
- Withdraw consent where processing is based on it.
- Complain to the AEPD (aepd.es) or your local data protection authority.
To exercise any right you can’t action directly in the app, email carlospv@gmail.com. We respond within one month.
11. Security
Data is encrypted in transit (HTTPS) and at rest. Passwords are hashed with bcrypt. Access to your data requires your authenticated session; accounts are strictly isolated from each other. We apply rate limiting, input validation, and server-side session revocation. Error monitoring is configured to never receive personal data.
12. Children
Circles is not directed at children, and you must be at least 16 years old (or the minimum age of digital consent in your country, e.g. 14 in Spain) to create an account. We do not knowingly collect data from children as users. If your notes mention minors (e.g., a friend’s children), the responsibilities in §5 apply with special care.
13. Changes to this policy
We’ll post any changes here and update the date at the top. For material changes we’ll notify you in the app before they take effect.