Data Controller

MPF App Oy
Laajalahdentie 16, 00330 Helsinki, Finland
Business ID (Y-tunnus) 3541877-3 · VAT FI35418773 · Domicile: Helsinki · Finnish Trade Register
info@ciaerampf.com

Ciaera is a registered auxiliary business name of MPF App Oy. The app is called Ciaera; the company you are contracting with, and the one answerable for your data, is MPF App Oy.

Data protection contact. Questions about your personal data and requests to exercise your rights go to info@ciaerampf.com.

1 Who we are

Ciaera is a workplace wellbeing app made by MPF App Oy, a company registered in Finland. Employees use it to check in on how they are doing and to talk things through privately with an AI companion. HR leaders get an anonymous, aggregated read on how the team is doing — and nothing else.

MPF App Oy is the data controller for the personal data described here. If you want to exercise a right, or you just want to know what we hold about you, write to info@ciaerampf.com.

2 What this policy covers

This policy covers the Ciaera iOS and Android apps, the HR dashboard at hr.ciaerampf.com, this website at ciaerampf.com, and the backend that serves all three.

It does not cover what your employer does with its own HR records, its own systems, or anything you tell a manager outside Ciaera. Your employer is a separate data controller for all of that — see Section 8.

3 What we collect, and why

3.1 Account data

When your account is created we store your email address, your password as a one-way bcrypt hash (we cannot read it, and we cannot recover it for you), your role — employee or HR leader — and which company account you belong to. We record the time you gave consent and the version of this policy you agreed to.

Alongside that, the app stores a few small settings so it behaves correctly: your interface language, your time zone (sent by the app so that "this morning" means your morning and not UTC), the time of your last sign-in, and — if your company uses departments — which department you are in.

An email address is a contractual requirement: without one we cannot create an account or provide the service. Everything in 3.2 to 3.6 rests on your consent instead, and you can withdraw it at any time.

3.2 Mood check-ins

When you log a mood we store the emoji and label you picked and the time you picked it. Encrypted at rest under a key derived for your account alone.

3.3 Chat conversations

We store the messages you send and the replies you get back, encrypted at rest under your account's key. To produce a reply, the message is sent to Anthropic's Claude — Section 7 sets out what Anthropic may and may not do with it.

3.4 AI memory notes and summaries

So that the companion picks up where you left off instead of meeting you fresh every time, Ciaera keeps a short encrypted note of recurring themes and context from your past conversations, plus brief per-day and per-week summaries used to give the AI a sense of your timeline. None of it is visible to your HR leader or your employer, ever. You can wipe the note yourself by telling Ciaera to forget everything about you, in any language it speaks.

3.5 Journal entries

If you save a conversation to your journal, we store a reference to that session and the mood you had at the time. Encrypted at rest, and private to you.

3.6 Anonymous feedback

Feedback you send through the app is stored against your company, never against you. The text carries no user ID and no timestamp that could place it. We separately record the bare fact that you have submitted at some point, with no link to any text, purely so the dashboard can count distinct contributors and enforce the five-person minimum. Deleting your account or withdrawing consent removes that participation record; the anonymous text stays, because by then nothing connects it to you.

3.7 Technical, security and abuse-prevention data

Some data exists only to keep the service standing up:

  • IP addresses are used as short-lived rate-limiting keys, so one client cannot flood the API. They live in an in-memory cache with a short expiry and are not written to the database.
  • Server logs record request errors and operational events. We do not build behavioural profiles from them.
  • Error diagnostics are sent to Sentry when something breaks, so we can fix it. The integration is configured never to attach request bodies, headers or user identifiers.
  • HR session fingerprints. For HR accounts only, each request records an irreversible 16-character hash of the session identifier, so we can spot one HR login being shared between several people. No IP address and no device or browser details are collected for this. The record expires after 25 hours. Employee accounts are not fingerprinted.
  • AI usage counters record how many tokens a request consumed, for billing and for the caps described in Section 4. They contain no message content.

3.8 Reports on AI replies

You can report a reply from Ciaera by long-pressing it. A report always contains the reason you picked, the app language and the AI model. It never contains your name, your account or your employer.

If you tick "Share this reply with Ciaera so we can review it", the report also carries that reply, and your message before it if you tick that box too. Only Ciaera's review team can read it, to find and fix problems with the AI. Your employer never sees it. It is encrypted and deleted after 30 days. The shared text is not linked to your account, so we cannot find it again to delete it earlier (Art. 11 GDPR). Leave the box unticked if you do not want to share it.

3.9 Records of rights requests

When you exercise a right — withdrawing consent, deleting your account — we log that it happened, when, and who asked for it. GDPR Art. 5(2) requires us to be able to demonstrate that we honoured it. The log holds no wellbeing data.

3.10 Company updates and reactions

Your HR team can publish short updates — a goal, an action they are taking, or a result — to everyone in your company or to your department. An update may include a snapshot of the same anonymised team statistics HR already sees, such as the share of the team that felt good last week. A snapshot is only available for a period in which at least five people responded, and it never contains anything about an individual. You can read updates in the app; you cannot reply to them.

You can react to an update with one of four emoji. So that you can react only once per update, we store a one-way code made from your account and the update together with a secret key that never leaves our server. The reaction is never stored against your name, your email or your account. Your HR team cannot see who reacted to an update, and Ciaera does not look it up. HR sees only how many people reacted, and only once at least five have. Updates and their reactions are deleted when HR deletes the update or when your company's account is deleted, and your own reactions are deleted when you delete your account or withdraw consent.

3.11 Chat topics (optional)

Your company can ask us to switch on chat topics. It is off unless your company has asked for it, and even then it is off for you until you agree on a separate screen in the app. If you agree, once a night an AI model run by Anthropic reads your messages from a day that has ended, for one purpose: to tick which work topics you talked about, from a fixed list such as workload, deadlines, meetings or recognition. Before it does, we replace the names of people at your company, common first names and surnames, email addresses and phone numbers in those messages with a placeholder. The model is told to ignore anything private or not about work and never to infer a diagnosis, and it can only answer with topics from that fixed list. What we keep is the list of ticked topics for that day, encrypted under your account's key — no message text, no tone, no score.

Your HR leader never sees your ticks, your messages, a number of people, or whether you take part. For the company as a whole, HR sees only which topics came up in the last finished week and a rough share for each — "under half", "half" or "most" of the people taking part — plus whether that share went up or down from the week before. Even that is shown only when all of these hold: your company has at least 16 employees; at least 10 people who agreed were counted that week; and at least 5 different people, but not all of them, mentioned the topic. Otherwise HR sees no topics at all. A week becomes visible four days after it ends, and the first time HR views it the result is frozen, so it does not change afterwards. The same rough shares may be given to the AI that writes HR's aggregated insights (Section 6).

You can turn this off at any time in the app's Settings. Turning it off, withdrawing consent or deleting your account deletes your ticks straight away. Weeks HR has already seen keep their frozen result, which holds no user ID and no count and cannot be traced back to you.

We do not collect anything else. There are no advertising SDKs, no cross-app tracking, no third-party analytics in the mobile apps, and no data brokers anywhere in the picture.

4 Safety check on usage limits

Each account has daily and monthly limits on AI usage. When an account gets close to its daily limit, or a message would be blocked by it, Ciaera automatically checks whether the conversation may describe an acute crisis. If it does, the conversation stays open past the daily limit for a while.

The check runs only near or at the daily limit, on the conversation you are having. No one reads your messages. While a conversation is kept open this way, Ciaera remembers that it is, without any message content, for at most six hours. Keeping a conversation open also creates a record containing your user ID, your company ID and the time, but no message content. Only Ciaera's own staff can see this record, in our internal admin console, to review that the safety check works as intended. Your employer and your company's HR team never see it and are not told that it happened. The record is kept only as set out in Section 9.

5 Health-related data

Mood entries and the content of your conversations can reveal something about your mental health. Under Art. 9 GDPR that makes them special category data, which carries the strictest protection in the regulation, and we treat them accordingly.

We process them on one basis only: your explicit consent under Art. 9(2)(a), given on a dedicated screen before your account exists. You can withdraw it at any time, from inside the app. Withdrawing does not make the processing before it unlawful — it stops it going forward, and erases what was collected. Section 10 explains exactly what happens.

6 What your HR leader can and cannot see

Your HR leader cannot see:

  • Any individual mood entry or any chat message, yours or anyone's
  • Your journal, or the AI's memory notes about you
  • Your name or email next to any wellbeing data
  • Whether you have used the app at all, or how often
  • Whether you reacted to a company update, or how
  • Whether you agreed to chat topics, or which topics you talked about

Your HR leader can see:

  • Aggregated mood trends for the team, and only once at least five people have responded in the period. Below five, the dashboard shows nothing at all — not a smaller number, nothing.
  • Themes and suggested actions written by AI from that same aggregate. It is instructed never to quote or paraphrase an individual message, and it is given aggregates rather than raw text to work from.
  • Anonymous feedback, with no author and no timestamp attached.
  • If your company has switched on chat topics (3.11): which work topics came up in a finished week among the people who agreed, each with only a rough share ("under half", "half" or "most") — never a number of people, never a message, never who. Shown only in companies with at least 16 employees, when at least 10 people who agreed were counted that week, and for topics at least 5 people but not all of them mentioned.
  • For company updates they published: how many people reacted, and with which emoji — only once at least five people have reacted, and never who.

The five-person floor is enforced in the backend, on every query, not in the interface. There is no setting, no admin override and no support request that turns it off, and there is no screen anywhere in the product — including our own admin console — that displays one person's mood history or chat. The one exception is platform-usage counts, not wellbeing data: our internal admin console shows Ciaera staff exact sign-up and app-activation counts, without the five-person floor, so we can operate customer accounts — it never shows mood data, chat content, or anything below the aggregate level.

7 Who else touches your data

These are the third parties that process personal data on our behalf. All of them are bound by data processing agreements with us, and this list is updated if that changes.

Sub-processor What it does Location Transfer safeguard
Anthropic PBCanthropic.com Generates the AI replies, the private memory notes and summaries, and the aggregated HR insights. Receives your chat messages. United States Standard Contractual Clauses — Art. 46 GDPR
Microsoft Ireland Operations Ltd.azure.microsoft.com Runs the backend on Microsoft Azure, together with the PostgreSQL database where everything is stored and the Redis cache used for rate limits and short-lived locks. EU — Sweden Central, Sweden Data stays in the EU/EEA
Resend, Inc.resend.com Delivers transactional email: address verification, password resets, weekly prompts, security notices. United States Standard Contractual Clauses — Art. 46 GDPR
Functional Software, Inc. (Sentry)sentry.io Collects backend error reports so faults get fixed. Configured to send no request bodies, headers or user identifiers. United States Standard Contractual Clauses — Art. 46 GDPR
Vercel Inc.vercel.com Hosts this marketing site and the HR dashboard, including cookieless page-view analytics. United States Standard Contractual Clauses — Art. 46 GDPR
On the AI, specifically

Your messages are sent to Anthropic over the commercial API. Under Anthropic's commercial terms, inputs and outputs sent through that API are not used to train its models. Anthropic deletes them from its systems within 30 days. If Anthropic's automated trust-and-safety systems flag a message as violating its usage policy, that message can be kept for up to two years and the classification scores for up to seven years. Anthropic does not receive your name or email, only the message text and a company API key.

Ciaera provisions and pays for a separate Anthropic API key for each customer company, so one customer's conversations are never mixed into another's usage. Customers do not need their own Anthropic account or key.

Transfers outside the EU

Anthropic, Resend, Sentry and Vercel are US companies. Transfers to them rely on Standard Contractual Clauses approved by the European Commission under Art. 46 GDPR.

Everything at rest — the database, every mood entry, every message — is in Sweden, in Microsoft Azure's Sweden Central region.

We do not sell data, we do not share it for anyone's marketing, and we do not give your employer anything beyond the aggregates in Section 6.

8 Your employer's role, and its limits

Your employer buys Ciaera and decides that its staff may use it. For its own HR and employment records it is a data controller in its own right, under its own privacy notice, and this policy does not reach any of that.

For everything inside Ciaera, MPF App Oy is the controller. Your employer cannot instruct us to disclose your entries or to identify who wrote what.

9 How long we keep things

Personal data is deleted automatically when its retention period ends.

DataKept for
Account dataUntil you delete your account. An employee account with no mood entry and no conversation for 12 months is also deleted automatically, along with everything in it.
Mood check-ins12 months from the entry
Conversations and messages12 months from the session
Journal entries12 months from saving
AI memory notesCleared after 180 days with no conversation, or whenever you ask Ciaera to forget you, or on account deletion — whichever comes first
Per-day AI summaries30 days
Per-week AI summaries13 months
Anonymous feedback12 months from submission
Text you shared when reporting an AI reply30 days from the report
Cached HR overviews13 months
Company updates and their anonymous reactionsUntil HR deletes the update, or your company's account is deleted. Your own reactions also go when you delete your account or withdraw consent
Chat-topic ticks (only if you agreed)35 days from the night they were made — and immediately when you turn chat topics off, withdraw consent or delete your account
Weekly anonymous topic results shown to HR, and HR overviews built with them35 days
AI usage counters (no content)12 months
Password reset tokensStored hashed, single use, valid one hour; the spent record is purged after 7 days
Rate-limiting data and HR session fingerprintsMinutes to 25 hours, in cache only
Error diagnostics at SentryUp to 90 days, then deleted by Sentry
Internal alerts90 days once read, 12 months if never read — and immediately on account deletion or consent withdrawal
Demo requests from this website90 days
Records of rights requests3 years, then purged

You can also delete your data at any time from inside the app, as described in Section 10.

10 Your rights, and how to use them

Some of these rights can be exercised directly in the app. For the others, write to info@ciaerampf.com and we will respond within one month.

Access — Art. 15

Ask for a copy of everything we hold about you. Or take it yourself: the export below is the same data.

Portability — Art. 20

In the app: Settings → Privacy & Data → Export my data. Machine-readable JSON, generated on the spot, yours to keep or move.

Erasure — Art. 17

In the app: Settings → Danger Zone → Delete account. Immediate and irreversible. If you are your company's HR owner, make another HR leader the owner first. If there is no other HR leader, ask us to close the company account instead — otherwise the company would be stranded with no administrator.

Withdraw consent — Art. 7(3)

In the app: Settings → Privacy & Data → Withdraw consent. Detailed below — it erases rather than pauses.

Rectification — Art. 16

Change your email and password in the app. For anything else, write to us and we will correct it.

Restriction — Art. 18

Ask us to freeze processing rather than erase it, in the circumstances the article allows.

Object — Art. 21

Object to anything we do on legitimate-interest grounds — the security and abuse-prevention data in 3.7. We stop unless we can show compelling grounds that override yours.

No automated decisions — Art. 22

Nothing here makes a decision about you with legal or similarly significant effect. The AI writes suggestions from aggregates, for a human to read and judge.

Withdrawing consent

When you withdraw consent:

  • Every mood entry, conversation, memory note, AI summary and chat-topic tick of yours is deleted, and the mood attached to each journal entry is stripped out. Your chat-topics agreement is cleared too.
  • Your session is revoked immediately — the app signs you out and your existing token stops working.
  • Your feedback participation record goes; the anonymous feedback text stays, because nothing links it to you.
  • Any internal alert carrying your user ID is purged.
  • We email you a confirmation that it happened.

What remains for 30 days is an empty account shell — your email address and login, holding no wellbeing data whatsoever. That window exists so you can come back and re-consent without starting over. If you do not, the empty account is removed automatically: employee accounts are deleted and HR accounts are anonymised.

Deleting your account instead of withdrawing consent skips the 30-day window entirely and removes everything at once.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. In Finland, this is the Office of the Data Protection Ombudsman (tietosuoja.fi).

11 How it is protected

Mood labels, chat messages, journal entries and AI memory notes are encrypted at rest with AES-256-GCM, under keys derived per user from a server-side secret. The keys themselves are never stored anywhere — they are derived on demand and discarded.

In transit, everything runs over TLS 1.2 or better. Both mobile apps also use certificate pinning.

Passwords are stored only as bcrypt hashes. Changing a password, changing a role or withdrawing consent signs out every existing session. Administrative access requires two-factor authentication, and row-level security in the database keeps each company's data separate.

If a breach happens that is likely to put your rights at risk, we notify the Finnish supervisory authority within 72 hours of finding out (Art. 33), and if the risk to you personally is high, we tell you directly and without delay (Art. 34).

12 Cookies, storage and this website

The mobile apps

No cookies, no advertising SDKs, no analytics, no cross-app tracking. The apps talk to our API and to nothing else.

This website

No cookies at all. We use Vercel Web Analytics, which is cookieless: it counts page views in aggregate, sets nothing on your device, does not fingerprint your browser and cannot follow you to another site. Your browser's local storage keeps at most two entries: one remembers that you have dismissed the storage notice, so it does not reappear on every visit, and one remembers your light or dark theme if you choose one. Neither is sent to us.

Both typefaces on this site — Poppins and Inter — are served from our own domain. Your browser makes no request to Google Fonts and no IP address of yours reaches a font provider.

The demo form

If you ask for a demo, your email address is used to send you one confirmation and to reach our own inbox so a human can reply. We do not store the address in our database. What is stored is a one-way SHA-256 hash of it, alongside the time you consented, purely so we can count and de-duplicate requests — and that record is deleted after 90 days. You are not added to a mailing list, and there is nothing to unsubscribe from.

The HR dashboard

hr.ciaerampf.com sets no cookies either. It keeps your session token in sessionStorage, which your browser clears the moment the tab closes, and caches your dashboard in localStorage in encrypted form with the key held in sessionStorage — so the cache is unreadable once the tab is gone. Your language choice and whether you have seen the product tour are also stored locally. All of it is strictly necessary to run the dashboard you asked for, and none of it tracks you.

13 Children

Ciaera is a workplace tool and is not meant for anyone under 16. We do not knowingly collect data from minors. If you believe a minor has an account, write to info@ciaerampf.com and we will delete it.

14 When this policy changes

We may update this policy from time to time. The date at the top of this page shows when it last changed.

If a change affects how we use data you have consented to, we will inform you in the app and ask for your consent again where required.