1. Who is responsible
The data controller is:
Sitepoint Systems ApS
CVR 39299739
Rådhusstræde 15, 1466 København K, Danmark
E-mail: support@teenmood.eu
TeenMood is a free project. We do not make money from the app and have no plans to do so.
2. What is end-to-end encrypted
End-to-end encryption means that content is locked on your phone and only unlocked on the recipient's phone. The keys exist only on the phones. Our server forwards and stores the content in encrypted form, but is technically unable to read it. This applies to:
- Chat: text, images, voice messages, stickers and links, in crews and 1:1.
- Check-ins: all sliders, vibe, music link, text and talk flag.
- Reactions, barometer votes and votes.
- Your Code, when you share it with a crew.
- The crew's name, emoji, colour and settings.
- What you share with a parent.
We use the open Matrix protocol on our own server. We did not invent the encryption ourselves.
3. What our server can see
No messaging service can function without knowing certain information about who should receive what. This is what our server can see, and therefore what we can in principle also see:
- Your account: a user ID, your display name and your language choice.
- That you have confirmed you are 15 years or older. We do not store your date of birth.
- Which crews and conversations you are part of, and who else is in them. Crews do not have a name on the server.
- When something is sent, by whom, and how large the encrypted content is.
- Your devices with a neutral name and their public encryption keys.
- Your IP address when the app connects to the server.
- Invitation links and QR codes, for as long as they are valid.
- One push token per phone, if you have agreed to notifications.
We only use this information to make the app work, to keep it secure and to handle reports. We do not build profiles of you from it.
4. Your mood is health data
Mood, energy, stress and similar information can say something about how you are doing. We therefore treat all check-ins as health data under Article 9 of the General Data Protection Regulation, even though our server cannot read them. This means:
- We ask for your explicit consent in the app before you can share check-ins.
- You decide for each check-in who can see it.
- You can withdraw your consent at any time by stopping sharing check-ins or deleting your account. What you have already shared with others cannot be retrieved from their phones.
5. Age
TeenMood is only for those who are 15 years or older. This is because the app is about your mood, and mood counts as health data (section 4). We may only process this with your own explicit consent, and we want to be sure that you yourself are giving it. When creating an account, you confirm that you are at least 15. If we discover that an account belongs to someone under 15, we will delete the account.
6. The parent link
- Only you can invite a parent. A parent cannot request access themselves.
- The parent only sees your mood (and your energy, if you enable it), a graph of the last 7 days, the text you write to parents, and your talk flag for parents.
- The connection is its own encrypted channel, which only receives those fields. Your crews, friends, chats and conversations with Bestie are never sent to the parent.
- You can remove a parent at any time. The parent will then not receive anything new, but what has already been displayed on the parent's phone remains there.
- A parent has their own account, which is treated like any other account.
7. Bestie and AI
- Bestie runs on your phone. Nothing you write to Bestie, and nothing Bestie replies, is sent to us or to others for processing.
- We do not use any AI services from other companies over the internet.
- On iPhones that support it, Bestie uses Apple's built-in language model, which runs on the phone itself. On other phones, you can choose to download a language model (see section 8). Otherwise, Bestie runs in a simpler, text-based version.
- Bestie only sees the conversation on your own phone, your own Code and the Codes others have shared with you. Never other people's check-ins or chats.
- Conversations with Bestie are not stored on our server.
- Bestie is not a human, not a therapist and cannot call for help. See Help.
8. Downloading a language model
On phones without Apple's built-in model, you can choose to download a language model of 1 to 3 GB. This only happens if you agree, and by default only over Wi-Fi. The model is downloaded from our own server in the EU. The server sees your IP address and that you have downloaded the file, just as with any other download. The app verifies that the file is unaltered, and you can delete the model again in settings.
9. Notifications
If you agree to notifications, we store a push token for your phone. Notifications are sent through Apple (iPhone) or Google (Android). They contain no message text and no mood data, only a technical reference that your phone uses to fetch and unlock the message itself. Apple and Google can see that your phone has received a notification, and when. By default, notifications are silent from 10 pm to 7 am.
10. Reports and blocking
You can block others, leave a crew and report messages. When you report, your phone only sends the messages you yourself select to us in readable form, along with a technical reference to them. This is the only case in which we see content from the app, and we only see what you have chosen to send. We use it to assess the case and whether a user should be removed. We retain reports until the case is closed, and delete them no later than 6 months afterwards. If the matter involves something illegal, we may need to pass it on to the police.
11. GIFs and music links
If you search for GIFs in the app, the search goes directly from your phone to GIPHY, which sees your search term and your IP address. The actual GIF you send is encrypted like everything else. Short links for music links are created on your phone, not on our server.
12. Crash reports
If the app crashes, it may send a crash report to our own server. This contains the phone model, operating system, app version and where in the code the error occurred. It never contains messages, check-ins or other content. We do not use crash reporting or analytics tools from other companies.
13. What we do not do
- We show no advertisements.
- We do not track you, either within the app or across other apps and websites.
- We use no analytics or tracking tools.
- We do not train any AI on your content.
- We do not sell or rent your information to anyone.
14. The website teenmood.eu
The website sets only one cookie, which remembers your language choice. It uses no analytics, no tracking and no advertisements. If you write to us via the contact form, we store what you write on our server and send it to our email so we can reply. We delete the enquiry when the case is closed, and no later than after 12 months.
15. Where your data is stored and who assists us
Our servers are hosted by Hetzner in the EU. We use these types of data processors and other parties:
| Who | What | Where |
|---|---|---|
| Hosting (Hetzner Online GmbH) | Server for accounts, encrypted messages, reports, model downloads and the website | EU |
| Apple and Google | Delivery of notifications (push token and timestamp, no content) | USA and EU |
| App Store and Google Play | Download and update of the app. They are themselves responsible for the information they hold about you as their customer | USA and EU |
| GIPHY | GIF search, only if you use it | USA |
| Email provider | Receipt of enquiries to support@teenmood.eu | EU |
If information is transferred to a country outside the EU/EEA, this is done on the basis of the EU-U.S. Data Privacy Framework or the European Commission's standard contractual clauses.
16. Why we are permitted to (legal basis)
- Providing the app to you: account, crews and delivery of encrypted messages (GDPR Art. 6(1)(b)).
- Check-ins and other mood data: your explicit consent (Art. 9(2)(a) and Art. 6(1)(a)).
- Notifications: your consent, which you give and withdraw in your phone's settings (Art. 6(1)(a)).
- Security, operations and reports: our legitimate interest in keeping the app safe for all users (Art. 6(1)(f)).
- Contact form and email: our legitimate interest in being able to respond to you (Art. 6(1)(f)).
17. How long we retain data
- Account and encrypted messages: for as long as you have an account. Disappearing messages are deleted after the time you have chosen in the chat.
- Technical logs with IP addresses: at most 30 days.
- Reports: until the case is closed, at most 6 months afterwards.
- Enquiries via the website: until the case is closed, at most 12 months.
18. Delete your account
You can delete your account within the app under your profile. We will then delete your account, your profile, your devices and your push token from the server, and we will delete the encrypted messages you have sent from the server. Copies already stored on other people's phones cannot be reached, just as with all other messaging apps. You can also write to support@teenmood.eu and we will delete the account for you.
19. Your rights
You have the right to access the information we hold about you, and to have it corrected, deleted, restricted or transferred. You can also object and withdraw a consent. Write to support@teenmood.eu and we will respond within one month. Please note that we cannot provide encrypted content that we cannot read ourselves. It resides on your phone.
You can lodge a complaint with the Danish Data Protection Agency, Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk.
20. Changes
If we change the policy, we will update the date at the top. For significant changes, we will notify you in the app before they take effect.