5 · Peaceful World
Privacy Policy
This policy applies to the “5” / Peaceful World Practice web/PWA at 5.peaceful-world.org and to the native “5” apps for Android and iOS with identifier org.peacefulworld.practice.
1. Who is responsible for your data
Mittetulundusühing Peaceful World
Registry number 80657458
Telliskivi tn 57, 10412 Tallinn, Estonia
Email: hello@peaceful-world.org
2. Normal use of the app and progress
You do not need to register for basic use. The app contains no ads and does not require your name or email address to use the five-minute or free practices.
Your device may locally store your selected language, theme, ticking setting, the number of completed guided and free practices, cumulative practice time, and your analytics choice. If you do not enable optional progress backup, these data remain only on that device.
If you voluntarily sign in by email with a one-time code, the app may store in Supabase only aggregate progress: the number of completed five-minute practices, the number of free practices, and cumulative time for each type. We do not create daily streaks, store the dates of individual practices, or build a full practice timeline. Your email address is used for sign-in and for restoring this progress on another device.
The web/PWA browser may also store a technical offline cache. The Android app packages its interface files inside the installed application and uses Android WebView local storage. Android system backup of app data is disabled; optional cloud progress backup is handled separately through Supabase.
3. Aggregate analytics and Google Analytics
The web/PWA version uses Simple Analytics as a separate, minimal aggregate measurement layer. Android builds may use the same layer where it is enabled. Simple Analytics does not set cookies or use localStorage for identification, does not store IP addresses, does not create device identifiers, and does not use fingerprinting. It receives only the aggregate technical data needed for broad statistics: page URL/path, referrer and strict UTM campaign parameters, time zone as a privacy-preserving proxy for country, browser language, browser/device type, and screen/viewport dimensions. These records are not linked to an email address, Supabase account, or practice history and operate independently of the Google Analytics consent choice.
The web/PWA version may use Google Analytics only after separate, voluntary consent. The analytics tag does not load before consent. Advertising personalization and Google Signals are disabled, and we do not use analytics data for advertising or advertising audiences.
The Android app may use Google Analytics for Firebase only after the same separate, voluntary analytics consent. Firebase Analytics collection is disabled by default in the Android build and is enabled only after consent. Collection of the Android Advertising ID is disabled, and advertising storage, advertising user data and advertising personalization remain denied.
You can change your analytics choice through the Privacy link. After consent, Google Analytics may process standard technical events such as page_view, first_open, session_start and user_engagement, as applicable to the platform, as well as product events related to opening the app, starting and completing a practice, feedback, sharing, launching the AI Guide, and the optional progress-backup flow. Web/PWA analytics may also include installation events. Product events may include interface language, app version and launch surface (browser, installed PWA or Android). Practice events may include practice_mode (guided or free), and practice_complete may include a broad completion-number bucket such as 2–3, 6–10 or 21–50 rather than the exact cumulative count. For Free practice, the completion event may also include the duration in seconds of that single completed session. These parameters are used to understand repeat use and feature usefulness; we do not send a dated practice history or cumulative cloud-progress totals to Google Analytics.
After consent, Google Analytics for Firebase may also process an app-instance or installation identifier and standard technical app/device metadata used by Google to provide analytics. We do not set our own user ID for Analytics, and we do not send feedback text, voice recordings, email addresses, one-time sign-in codes, Supabase user identifiers, cumulative cloud-progress totals, or AI Guide conversation content to Google Analytics. Progress-backup analytics events contain only coarse product actions such as opening backup, successful backup/restore, or account deletion.
4. AI Guide and ElevenLabs
In language versions where it is offered, the AI Guide is an optional feature for short questions about the practice. It does not run during the five minutes of the practice itself and is not required to complete the exercise.
If you start a conversation, the text of your messages, your voice input and the agent’s responses are processed by ElevenLabs infrastructure. The microphone is used only after an explicit action from you and permission from your browser or the Android operating system. If you do not start a conversation, the app does not send your voice or conversation text to ElevenLabs.
For the Peaceful World agent, storage of new conversation audio recordings is disabled. Conversation transcripts and related derived data may be kept by ElevenLabs for no more than 30 days. The Peaceful World workspace is opted out of the provider’s use of workspace data for training and improving its models.
Access to the agent is restricted by an allowlist that includes 5.peaceful-world.org, the technical GitHub Pages host peaceful-world-org.github.io, the Android origin android.5.peaceful-world.org, and the iOS origin ios.5.peaceful-world.org.
AI Guide conversations are not sent to Supabase through our feedback form, and the app does not combine them with the local practice counter. Do not share information with the AI Guide that you would not want to send to a third-party AI service. Responses are generated automatically and may contain errors. See the ElevenLabs Privacy Policy for more information.
5. Feedback and voice recordings
Sending feedback is voluntary. The web/PWA and native versions may provide a “Report AI response” path for problematic or offensive generated responses; it uses this same feedback form and appears only after an AI Guide conversation has actually started. A report is sent to Peaceful World only when you choose Send and is not automatically linked by the app to an ElevenLabs conversation transcript.
If you select Send, we may receive:
- the text of your feedback or AI-response report;
- a voice recording, if you record one and choose to send it;
- the language, app version, copy version and identifier of the wording set you were shown;
- the number of the practice you just completed on this device;
- the page URL, a random submission identifier, and technical browser/device information (user-agent);
- your email address, only if you separately agree to help with testing from time to time.
We do not send a list of your previous practices or their dates or times. Your IP address may be technically processed by Supabase infrastructure when a network request is delivered, but we do not add the IP address to the feedback record in our table.
Microphone access for voice feedback is requested only after you start recording. A recording is not sent automatically: until you select Send, it remains local and you can delete it or record again.
6. Why and on what basis we process data
Text feedback, AI-response reports and minimal technical data are used to find errors, review problematic generated responses and improve the exercises, translations and operation of the app. The legal basis is Peaceful World’s legitimate interest in improving and protecting the product.
A voice recording submitted through the feedback form is processed on the basis of your consent, expressed by voluntarily sending the recording. An email address for taking part in testing is used only with separate consent and is not a newsletter subscription.
Simple Analytics is used only for identifier-free aggregate measurement without cookies, user identifiers or profiling and operates independently of the Google Analytics choice. On the web/PWA and Android, Google Analytics is used on the basis of separate consent. The current native iOS build does not include the Google Analytics loader. The AI Guide processes the text or voice you provide in order to give the conversational response you requested.
If you voluntarily enable cloud progress backup, your email address and aggregate practice totals are processed only to provide sign-in, backup and restoration of the progress feature you requested.
7. Where data is stored and how long we keep it
Feedback, AI-response reports and voluntarily backed-up progress are stored in Supabase infrastructure. The project’s primary region is Frankfurt, Germany (EU, eu-central-1). A saved progress record is linked to a Supabase Auth account and contains only aggregate counters and time. Voice feedback recordings are stored in private storage and are not publicly available.
One-time sign-in codes are delivered through Resend. To deliver those messages, Resend technically processes the email address and delivery metadata. No password is required.
We keep feedback only for as long as it is needed for analysis, improving the app and documenting decisions. After that, we delete or anonymize it. Voice recordings may be deleted earlier after analysis is complete. A contact email address is kept until you withdraw consent or while participation in testing remains relevant. A progress-backup account, its email address and aggregate cloud progress are kept while that optional account remains active and are deleted when you use the in-app account-deletion control or make a valid deletion request.
For the AI Guide, storage of new conversation audio recordings is disabled. Transcripts and related derived fields are configured to be kept for no more than 30 days and then deleted.
Simple Analytics aggregate statistics are stored in the provider’s infrastructure in the Netherlands (EU). Simple Analytics does not store IP addresses, cookies or user identifiers for this layer.
Supabase, Resend, ElevenLabs, Simple Analytics and, where a user has allowed analytics in the web/PWA or Android version, Google act as third-party infrastructure providers and may use their own subprocessors. Their processing is governed by their terms and the safeguards required by applicable law.
8. Your rights
Under the GDPR, where applicable, you may request access to your data, ask for it to be corrected or deleted, request restriction of processing, object to processing, receive a portable copy, and withdraw consent you previously gave. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
You can delete the progress-backup account and its cloud progress directly in the app: Home → Manage progress → Delete cloud progress and account. For other requests, contact hello@peaceful-world.org. External deletion instructions are also available on the Data deletion page. If your request concerns an AI Guide conversation, provide the approximate time of the conversation if possible. You also have the right to lodge a complaint with the competent data-protection authority; for our Estonian organization, that authority is Andmekaitse Inspektsioon.
9. Children
The app is not specifically designed for children and does not ask for age. Please do not send personal data about minors through the feedback form or to the AI Guide without an adult being involved where the law requires that involvement.
10. Sale of data and automated decisions
We do not sell personal data or use it for advertising. Peaceful World does not use AI Guide conversations to make automated decisions that have legal or similarly significant effects on you.
11. Changes to this policy
If the way we process data changes significantly, we will update this page and the date below before the new rules start to apply.