Privacy Policy - Copl
Version 4.1 - effective from 2026-08-11
This policy explains what Copl does with the data you and your partner enter in the app. We've tried to write it in plain language - if anything is unclear, get in touch.
Note: this is an English translation of the Swedish original. The Swedish version is the authoritative one in case of any discrepancy. Synchronize both files when updating the policy.
Who is responsible
Pontus Brunzell, sole trader (enskild näringsidkare), is the data controller for Copl. (Business registration number available on request.)
Contact: copl-app@outlook.com
Note during development: when the app moves to a company structure, this section will be updated with company name, registration number, and contact details.
Summary for the impatient
- You and your partner are the only ones who see your content. Not us.
- No ad SDKs, no analytics, no trackers. None.
- All database content is stored in Sweden. Region: Stockholm (Supabase). Push notifications pass through Apple/Google on the way to your phone (see section 3).
- You can at any time view all data about you, export it, or delete your account.
- Sensitive data is end-to-end encrypted since 2026-05-23 - intimacy, family notes, agreements, appreciations, notes, chat messages, relationship questions, reminders and mood check-ins - and since 2026-08-29 the weekly pulse as well. Not even we as operators can read the content.
- The training module is private but not end-to-end encrypted. Your workouts and body measurements are never shared with your partner, but they are protected by database access control rather than by encryption. See section 6.
- The AI help is optional and frugal. The app has three AI features: list suggestions, the meal assistant and the training assistant. They run only when you press them yourself, and what is sent to Anthropic is what you typed in the box - never your lists, your meal plan, your chat or anything about your relationship. The meal assistant is a conversation, so there your messages and the assistant's earlier replies are sent. See section 1.5.
1. What we collect
1.0 When you visit coplapp.com
The website counts page views and button clicks - for example how many people continue to the App Store. What is stored is the page address, which button was clicked, which domain you came from and the language your browser is set to. No cookies, no IP address and nothing that can be linked to you. Nothing is shared with any third party - the numbers go to our own database in Sweden, and they do not follow you between websites.
1.1 When you create an account
| Item | What it is | Why we need it |
|---|---|---|
| Email address | Your email | Login via magic link. We send only a link there. |
| Nickname | What your partner sees | So the app can say "Eva added a task" instead of an ID number |
| Anonymous account ID | Random UUID | Internal - links you to your data |
We never ask for:
- Real first or last name
- Phone number
- Address
- Date of birth or age
- Gender
- Profile photo (an optional avatar is possible but not required)
1.2 When you use the app
The content you and your partner enter:
- Tasks, to-do lists, shopping lists
- Calendar events
- Family information (children's names, shoe sizes, doctors, allergies)
- Meal planning, and recipes you save - including links, images or notes you attach to them
- Training plans, logged workouts and the sets you record
- Body measurements you choose to enter yourself: weight, height and optionally body fat percentage. BMI is calculated in the app when shown and is never stored in the database.
- Training challenges and the sub-goals you set
- Homework
- Budget (income, expenses)
- Agreements between you
- Appreciations you send each other, plus whether an appreciation has received a reaction or been saved to your book
- Daily and weekly mood check-ins
- Intimacy data (logs, preferences, goals) - only if you actively enable the module
- Reminders you send each other
- Short messages, plus images and clips you send in chat
- A shared chat draft, if you start writing a message together
- That a message has been marked as handled, and which to-do or event a chat thread belongs to
- Notes, shared with your partner or private
- Questions and answers in Your relationship
- Suggestions and bug reports you send via "Feedback"
We don't ask for any of this - you choose what to enter.
If you enter information about someone else (e.g. your partner or your children in the family module), you are responsible for having the right to do so. Our legal basis for storing it is to perform the contract with you (Art. 6.1.b); for sensitive data (e.g. allergies), your explicit consent (Art. 9.2.a).
1.3 Technical data
- Push token for the device (so we can send notifications to that device)
- Device type and app version (iOS/Android, for debugging)
- Timestamps on your actions (when you logged in, when a row was created)
1.4 What we do not collect
- Location (GPS, IP-based geolocation)
- Contacts / address book from your phone
- Behavioral tracking or analytics
- Advertising identifiers (IDFA, GAID)
- Cookies (neither the app nor the website uses cookies or tracking)
- Bank transactions or card details
- Health data beyond what you yourself choose to enter in the intimacy and training modules (see 1.2). We pull nothing from Apple Health, Google Fit, Health Connect or any wearable device.
About the website (coplapp.com): it sets no cookies and has no analytics or tracking. The only thing stored is your language choice (Swedish/English), saved locally in your browser (localStorage). This is a functional setting, not tracking, and therefore requires no consent.
Waitlist: if you voluntarily submit your email to the waitlist, we store it (with your consent, GDPR Art. 6.1.a) only to notify you when Copl launches. We send no other emails, and the list is deleted after launch. You can ask us to remove your address at any time (copl-app@outlook.com).
1.5 The AI assistants
The app has three features that use a language model at Anthropic. All three run only when you actively press them. There is no background analysis of your content, and none of them has access to the app's database.
You are always talking to an AI system, never to a human. The assistants are labelled as assistants in the app.
1. List suggestions - suggests rows for a shopping list or a to-do list.
Sent: the text you typed, at most 400 characters, plus which kind of list it is and your language choice. If you pasted a recipe link, the text content of that page is sent too, fetched by our server. If you picked a photo of a recipe, that image is sent, compressed and at most 5 MB.
2. The meal assistant - a conversation about what to eat, which can produce a recipe or a suggestion for a whole week of dinners.
Because it is a conversation, sending the latest question alone is not enough - the assistant has to see what you have already discussed to answer "halve the recipe" or "swap Wednesday". So the most recent turns are sent: at most 14 turns, your messages at most 600 characters each and the assistant's earlier replies at most 2000 characters each. The conversation starts from zero every time you close the assistant - nothing is kept between sessions, neither by us nor by Anthropic. Here too you can add a recipe link or a photo.
When you press a button inside the assistant, such as "swap dish" or "plan the whole week", a ready-made sentence is sent, and you see it in the conversation. It never contains anything from the app.
3. The training assistant - suggests a training plan based on how you describe the way you want to train.
Sent: the text you typed, at most 400 characters, plus the app's own exercise catalogue (name, muscle group and equipment for up to 200 exercises). The catalogue is the same for every user and contains nothing about you. It comes along so the assistant can pick real exercises that the app can then connect to your own weight curve.
What is never sent, in any of the three:
- Your or your partner's content in the app: the meal plan, the shopping lists, the recipes, the calendar, the chat, the budget, the family details or anything from Our relationship
- Anything about your partner or your relationship at all
- Your workouts, your body measurements or your history
- Your email address, your account ID or any identifier pointing to you
The rule is simple and applies everywhere: the assistants only ever see what you typed in the box.
About photos of recipes. You can photograph a recipe in a magazine or cookbook, or pick a screenshot from your phone's library. The image is sent to Anthropic the moment you press the button, and we do not store it. You pick the image yourself every time, and the screen tells you it will be sent before it is. Only pick images you are comfortable sending.
The suggestions in chat are not AI. When the app notices that you have written about an expense, a piece of homework or a time, and offers to add it, that recognition happens on your phone. No message leaves the device for it, and nothing is sent to Anthropic.
The request is therefore made anonymously from our server - Anthropic receives no information about who asked.
What we store about it: only that a generation happened. The table holds your account ID, which kind it was, and the timestamp. Neither your text nor the conversation is stored. The purpose is to be able to rate-limit requests per user so the service is not abused.
Recipe links: when you paste a link, the page is fetched by our server, not by your phone. The recipe site therefore sees our server address and never your IP address.
Anthropic processes the data as a data processor and does not use it to train models. The transfer is to the USA - see section 3.
1.6 When you connect the calendar to something outside Copl
The calendar module has three ways of letting your events appear somewhere else. All three are optional, off by default, and switched on by you. Private events never travel with any of them.
Your phone calendar. The app creates a calendar named Copl on your phone and writes the events there. No third party is involved - the data never leaves the device through us. What happens next is up to the phone: if you have connected your phone calendar to iCloud, Google or a work account, the events follow along according to the settings you made yourself.
Connect Outlook. If you choose to connect your Microsoft account, the app sends your shared events straight to your Outlook calendar: title, time, place and description. Microsoft then becomes a recipient of that information, and processes it under its own terms, which we do not control. The transfer goes from your phone to Microsoft, never through our servers, and it only goes one way. If you disconnect Outlook, the events Copl added are removed again.
Subscription link. You can create a secret address and add it to any calendar you like - Outlook, Google, Apple, private or work. The calendar then fetches a file from our server with your shared events, 90 days back and a little over a year ahead. The calendar service you paste the address into becomes a recipient of that information, and which one it is, is up to you.
About the address: it works like a password. Anyone holding it can read your shared events without signing in. That is why it is random and impossible to guess, and why you can remove it at any time in Settings - it stops working immediately. Do not share it with anyone you would not want seeing your calendar.
We store when a calendar last fetched the file, so we can answer the question of whether the subscription is working. Nothing else about the fetches is logged.
2. Why we process data - legal basis
Per purpose:
| Purpose | Legal basis (GDPR) |
|---|---|
| Create account, log in | Contract (Art. 6.1.b) - you enter into an agreement with us to use the app |
| Store your entries and show them to your partner | Contract |
| Send push notifications about tasks and events | Legitimate interest (Art. 6.1.f) - the app would be meaningless without notifications; minimal impact on you |
| Store intimacy data | Explicit consent (Art. 9.2.a) - you actively enable the module and can disable it at any time |
| Store body measurements (weight, height, optional body fat) | Explicit consent (Art. 9.2.a) - you choose to enter them yourself, nothing is imported automatically, and you can delete them at any time |
| Using the AI assistants (lists, meals, training) | Contract (Art. 6.1.b) - the features are part of the app and run only when you actively request them |
| Error reporting (when Sentry is active) | Legitimate interest - technical crash reports without personal data |
Intimacy data is a special category of personal data under GDPR Art. 9. We handle it with extra care: opt-in, optional PIN lock, and end-to-end encryption (implemented 2026-05-23 - only you and your partner hold the decryption key).
3. Where data is stored
| Where | What | Geography |
|---|---|---|
| Supabase | All database content, authentication, files | Sweden (Stockholm) - EU region. Supabase data never leaves the EU. |
| Apple Push Notification Service (APNS) | Push token + notification content in transit | Apple's global infrastructure |
| Google Firebase Cloud Messaging (FCM) | Push token + notification content in transit | Google's global infrastructure |
| Expo | App builds, OTA updates (no user data) | USA |
| Sentry (when active) | Crash reports | EU region (configured) |
| Anthropic Ireland, Limited | What you typed to an AI assistant. For list suggestions and training plans your text of at most 400 characters; for the meal assistant the most recent turns of the conversation. Plus the recipe link's page content or a photo of a recipe if you add one, and the app's own exercise catalogue for training plans. Without identifiers (see 1.5) | Contracting party inside the EU (Ireland). Processing takes place in the USA, with Anthropic PBC as sub-processor. |
| Microsoft | Title, time, place and description of your shared events - only if you connect Outlook yourself. Sent from your phone, never through our servers (see 1.6) | Microsoft's own infrastructure |
| The calendar you subscribe from | The same information, if you add the subscription link to a calendar service yourself. Which service that is, is up to you (see 1.6) | Depends on the service you chose |
| App Store and Google Play | That you downloaded the app, and any future in-app purchases | Apple's and Google's own infrastructure |
No other third party has access to data.
About the transfer to the USA: it happens only at the moment you press an AI feature yourself, and covers what you typed to the assistant - in the meal assistant also the most recent turns of the conversation - plus the recipe link's page content or a photo of a recipe if you choose to add one. Our contracting party is Anthropic Ireland, Limited, a company inside the EU, because Copl is run from Sweden. Anthropic acts as a data processor under a data processing agreement, and the transfer to the USA rests on the EU Standard Contractual Clauses, module two (controller to processor). Anthropic does not use the data for model training. Because the request is made from our server without an account ID, the data cannot be linked to you at Anthropic. If you don't want any text to leave the EU: don't use the AI suggestions, write your lists manually. Everything else in the app works exactly the same.
About the stores: Copl is distributed through the App Store and Google Play. They see that you downloaded the app and process that under their own terms, which we do not control. If paid features are introduced in the future, purchases are handled by the store and not by us, and we never receive your card or payment details.
4. How long data is kept
- Active accounts: No automatic deletion. Data lives as long as you use the app.
- Inactive accounts: If you haven't logged in for 3 years we contact you first, then close the account - your data is deleted within 30 days.
- Ended relationships (where both partners have ended or you deleted your account): Soft delete first. Hard deletion within 30 days.
- Closed accounts: All your data is deleted within 30 days.
- Backups: We take manual backups with limited retention. Backups older than 3 months are deleted.
- Server logs: Maximum 7 days.
- Crash reports (when Sentry is active): Technical crash reports without your content, deleted per Sentry's standard retention (approx. 90 days).
5. Who sees data
You and your partner
You see each other's content within your relationship. That is the entire point of the app.
Us (operators)
- Technically, we can reach the database via Supabase administration tools.
- In practice, we don't look at user data - there are no routine tasks that require it.
- When debugging a specific issue, we may need to read individual rows, always with the purpose of fixing the problem and nothing else.
- End-to-end encryption is in place since 2026-05-23. We cannot read intimacy data, family notes, agreements, appreciations, notes, chat messages, relationship questions, reminders, the weekly pulse or mood check-ins - they are encrypted on your device before being stored. Only you and your partner hold the decryption key.
- What is not encrypted, we can technically read. That includes workouts, body measurements, budget entries, shopping lists, calendar events and homework. They are protected by database access control, not by encryption. We do not read them, but we won't claim we are prevented from doing so. See section 6 for the full split.
Third parties
- Supabase stores the data but has no routines that open it. They have their own privacy policy.
- Apple and Google see push notification content on the way to your phone. We send generic notification texts ("Something new from your partner") where possible.
- Anthropic Ireland, Limited sees what you write yourself to an AI assistant, with no link to your account (see 1.5). They never see your content in the app.
- Microsoft sees your shared events if you connected Outlook yourself (see 1.6). Disconnect it and the events are removed again.
- The calendar service you chose sees the same information if you added the subscription link there. Remove the link and it stops working right away.
- The App Store and Google Play see that you downloaded the app. They also handle any future in-app purchases under their own terms. We receive no payment information from them.
- No others.
What we don't do
- We never sell data.
- We never share data with ad networks or data brokers.
- We don't combine your data with external data sources.
6. Security
Row Level Security (RLS) on all database tables - it is technically impossible for a user to read data from a relationship they are not a member of.
HTTPS encrypts all traffic between your phone and our servers.
End-to-end encryption is implemented since 2026-05-23 for intimacy, family notes, agreements, appreciations, notes, chat messages, relationship questions, reminders and mood check-ins, and since 2026-08-29 for the weekly pulse as well. Not even we as operators can read the content - it is encrypted on your device before being stored, with a key that only exists on your and your partner's phones. Algorithm: tweetnacl/XSalsa20-Poly1305 with AAD binding and version prefix. You can verify the encryption via Settings → Encryption Verification (shows your and your partner's fingerprint for verbal comparison).
What is encrypted and what is not. We think you should know the difference rather than having to guess:
Encrypted on your device (we cannot read it) Protected by access control (we can technically read it) Intimacy and closeness Workouts, sets and body measurements Family notes Shopping lists and to-do lists Agreements Calendar events Appreciations Budget, income and expenses Notes Homework Chat messages, images in chat and your shared chat draft Meal planning and saved recipes Relationship questions and answers Nickname and email address Reminders and mood check-ins Feedback via "Feedback" The weekly pulse - all seven scores Access control (Row Level Security) means no other user can reach the data, and that it is stored in Sweden. But it is not encrypted against us who operate the database. We do not read it, and no routine requires it - but we want to be clear about where the line runs.
The training module is mostly your own. Your workouts, your weight and your measurements are tied to your own account and are never shared. The one thing that can leave the module is a goal period you choose to share: your partner then sees the period name, your goal titles and how far along you are in percent - never the numbers behind them. You can stop sharing whenever you want.
PIN lock on the intimacy module can be activated locally on your device.
Discreet mode hides sensitive sections from the app's home screen.
Passwords don't exist - we use magic links via email, which eliminates password leak risks.
7. Your rights under GDPR
You have the following rights and can exercise them at any time:
| Right | How to do it |
|---|---|
| Know what data we have about you | Settings → "Your data" - shows everything stored about you personally |
| Correct inaccurate data | You can change all your own content directly in the app |
| Erasure of your data ("the right to be forgotten") | Settings → Delete my account - all data disappears within 30 days. If you no longer have the app or cannot get into your account: request deletion at coplapp.com/en/delete-account.html |
| Receive your data (portability) | Settings → Export our data - JSON file with all rows |
| Restrict processing | Pause the relationship (Settings → Pause) - data becomes read-only |
| Object to processing | Contact us (see below) |
| Withdraw consent for the intimacy module | Settings → turn off Closeness/Intimacy - the data is deleted |
| Withdraw consent for body measurements | Training → Body and progress - delete the measurements. You can stop entering them at any time without affecting the rest of the app |
We respond to all requests within 30 days, usually much sooner.
8. Complaints
If you believe we are handling your personal data incorrectly, you can:
- Contact us first - we want to know and would like to fix it.
- File a complaint with the Swedish Authority for Privacy Protection (IMY):
- Web: https://www.imy.se
- Phone: +46 8 657 61 00
- Mail: IMY, Box 8114, 104 20 Stockholm, Sweden
9. Automated decisions and profiling
We use no automated decision-making or profiling. No algorithms draw conclusions about you that affect you.
The AI assistants (section 1.5) are not automated decision-making in the sense of GDPR Article 22. They produce a text suggestion that you choose to keep or discard, they make no decisions about you, and they build no profile of you. The meal assistant remembers the turns within an ongoing conversation so it can answer follow-up questions, but the conversation starts from zero every time you close it, and nothing carries over between sessions.
The statistics in the app - streaks, averages, BMI, "ahead of plan" in training challenges - are simple calculations on numbers you entered yourself. They are shown only to you, are not used for anything else, and are not stored as conclusions about you.
10. Children
Copl is not intended for minors. You must be at least 18 years old to create an account (the app is age-rated 18+ and includes an optional intimacy module). Parents may store information about their children (names, shoe sizes, allergies) as part of the family module - but the children themselves should not create accounts.
Parents are responsible for informing their children about what data is stored about them.
11. Changes to this policy
This policy may be updated as the app evolves or as legislation changes. Major changes are announced in the app and, when needed, via email.
Version history:
| Version | Date | Change |
|---|---|---|
| 1.0 | 2026-05-19 | First published version. |
| 2.0 | 2026-05-24 | End-to-end encryption has been implemented and verified in production on 2026-05-23. Sections that described E2EE as "planned" or "future" updated to present tense. Encryption verification via fingerprint in Settings documented. |
| 4.1 | 2026-08-11 | New section 1.6 on the calendar. The Outlook connection existed in the app but was missing entirely from the policy - Microsoft was a recipient of your events without us saying so. Corrected, and documented together with the new subscription link, which lets you put your events into any calendar and where you choose which service becomes the recipient. Both added as recipients in sections 3 and 5. Documented that the subscription address works like a password and can be revoked at any time, and that private events never travel with any of these routes. |
| 4.0 | 2026-08-11 | Section 1.5 rewritten from scratch. The earlier text described a single AI feature, the help in lists, and stated that at most 400 characters are sent. The app now has three AI features, and the meal assistant sends the most recent turns of a conversation - up to 14 turns, your messages at most 600 characters and the assistant replies at most 2000. The training assistant also sends the app own exercise catalogue, which is the same for everyone and contains nothing about you. Sections 3 and 5 corrected on the same point. Added that you are always talking to an AI system and never to a human, and that the suggestions in chat are recognised on the phone without anything being sent on. New data types in 1.2: shared chat draft, handled markers and chat threads, plus reactions and stars on appreciations. Weekly routines removed as a data type, since the module was absorbed into Remind me. The table in section 6 updated. |
| 3.0 | 2026-07-31 | New modules and features since version 2.0 documented. New section 1.5 on the AI help in lists stating exactly what is sent to Anthropic and what is never sent; Anthropic added as a recipient in sections 3 and 5, including the transfer to the USA. Body measurements (weight, height, optional body fat) added in section 1.2 with explicit consent as the legal basis, and the earlier statement that we collect no health data outside the intimacy module corrected. New table in section 6 showing what is end-to-end encrypted and what is only protected by access control - training and body measurements belong to the latter. Notes, chat, relationship questions, reminders and mood check-ins added to the list of encrypted data, where they were missing. New data types in 1.2: recipes with attachments, training challenges, notes, relationship questions and feedback. Section 9 expanded with why the AI suggestions are not automated decision-making. |
12. Contact
For privacy questions, GDPR requests, or curiosity:
Email: copl-app@outlook.com
Postal address: provided on request
The Swedish version of this policy is authoritative. In case of discrepancy between translations, the Swedish version applies. See PRIVACY.md for the Swedish original.
Internal source document with technical details (for developers): docs/INTEGRITET.md in the codebase.