Privacy Policy – ObsessLess B.V.

Last updated: 11 September 2026

Hi there πŸ‘‹

We're ObsessLess B.V., from here on out refered to as 'ObsessLess', a small Dutch team building a mental-wellness app that helps you build OCD coping skills, practise healthier habits and feel more confident.

Registered address: Lange Beekstraat 2S, Netherlands
E-mail support@obsessless.com.

In GDPR terms, we are the data controller for anything described below.

1. Introduction

1.1 Scope

This policy applies to the ObsessLess iOS and Android apps, obsessless.com, our help-centre, support e-mails and social-media channels. Third-party sites we simply link to are outside our control; check their policies.

1.2 What ObsessLess is, and is not

ObsessLess is not medical treatment, therapy, or medical advice. It does not diagnose, treat, or cure any medical condition. It is a self-help and educational tool that gives daily nudges, short exercises and reflections based on evidence-based approaches. You stay in charge of your wellness journey; we simply provide guidance and support.

2. Data We Collect and Why

2.1 Data you give us directly

We collect your e-mail address (and, optionally, your name) so you can sign in with Apple, Google or e-mail and keep your data safe.

We also store any journal entries, mood logs or intrusive-thought notes you create. These entries may reveal mental-health information and are treated as special-category data under GDPR Article 9. We process them only after you tap "I give explicit consent", and you can withdraw that consent at any time in Settings β†’ Delete Account or by deleting the entries. (note that by doing this, you can experience loss of functionality while using the app)

We may store messages and AI-generated responses from chats you use so we can provide chat features and make your conversation history available. Chats may contain mental-health information, which we process only with your explicit consent.

Legal bases , contract (to deliver the service) and explicit consent (for special-category data).

2.2 Data collected automatically

We receive anonymised usage events (which screens you open, how long sessions last) to improve features, plus device information and crash logs to keep the app stable and secure.

Legal bases , legitimate interest (security, improvement).

Where national law or app-store rules require it, we obtain consent for analytics first.

2.3 Payments

Subscriptions are handled by RevenueCat. They receive Apple/Google receipt IDs and country codes; we never see your card number.

Legal bases , contract (to give you paid features) and legal obligation (tax compliance).

3. Tools We Trust

We use the providers below to operate ObsessLess. Where personal data is transferred outside the EEA, we use a lawful transfer mechanism, such as an adequacy decision or Standard Contractual Clauses (SCCs).

Google (including Firebase, Google Analytics, Google Play and YouTube) β€” account, cloud, analytics, app-store and video services. Privacy Policy

Amazon Web Services (AWS) β€” cloud and infrastructure services. Privacy Notice

OpenAI β€” AI services. Privacy Policy

Anthropic β€” AI services. Privacy Center

ElevenLabs β€” speech and audio services. Privacy Policy

LiveKit β€” real-time communication services. Privacy Policy

RevenueCat β€” subscription services. Privacy Policy

Apple β€” account, app-store and payment services. Privacy Policy

ManyChat β€” social-media messaging services. Privacy Policy

Kit β€” email communication services. Privacy Policy

We keep this list up to date.‍

4. International Transfers

Data is stored primarily in the EU. When personal data is transferred outside the EEA, we use lawful safeguards, such as an adequacy decision or SCCs, together with appropriate security measures.

5. How Long We Keep Your Information

Active-account data stays until you delete your account. Inactive accounts receive a reminder after 12 months of no use; 30 days later we erase journals and profile data. Back-ups roll off after 30 days. Tax-relevant purchase records are kept for seven fiscal years. Crash logs and anonymised analytics are removed after 24 months.

6. Security

All network traffic is protected by TLS 1.2+. Databases are encrypted at rest with AES-256. Internal access is strictly role-based and logged. We run regular penetration tests and vulnerability scans. If a personal-data breach poses a risk to you, we will notify you and the Dutch Data Protection Authority within 72 hours, as GDPR Articles 33-34 require.

7. Your Rights

You may access, correct, delete, export or restrict your data; withdraw consent; or object to certain uses. Exercise these rights in-app (Settings β†’ Privacy) or by e-mailing support@obsessless.com. We reply within 30 days. You can also complain to the Autoriteit Persoonsgegevens at autoriteitpersoonsgegevens.nl.

8. Marketing and Cookies

We send newsletters only if you explicitly opt in. Every message includes an unsubscribe link

Our website loads essential cookies automatically; analytics cookies load only after you click "Accept". Full details are in our Cookie Policy at obsessless.com/cookies.

9. Children

ObsessLess is not for children under 13. Users aged 13-17 must have parental or professional supervision. We delete any under-13 account immediately on discovery.

10. Notice-and-Action (Digital Services Act)

Think something in the app is illegal? E-mail support@obsessless.com with a screenshot/URL, why it is unlawful and your contact details. We will investigate and send a reasoned decision, typically within 72 hours, in line with Article 16 DSA.

11. Changes

If we materially change this policy we'll announce it in-app or by e-mail at least 15 days before it takes effect. An archive of previous versions is kept at obsessless.com/privacy-archive.

12. Contact

Questions? E-mail support@obsessless.com

By creating an account or continuing to use ObsessLess you confirm that you have read and understood this Privacy Policy.‍

‍

Table of Content