For DPOs, practice owners and HR
Health data is the first question a DPO asks, not the last. This page is built to be forwarded: where the data lives, who can reach it, how it is protected, and what we deliberately do not claim.
Where your data lives
"In Europe" is only an answer once it holds per data type. This is the list as it stands in production.
| Data | Where | Protection |
|---|---|---|
| Accounts, profiles, matchesClients, coaches, psychologists, practices | PostgreSQL, Railway EU West (Amsterdam) EU | Encrypted in transit (TLS), encrypted disk, Row-Level Security inside the database itself |
| Messages between client and professional | Same database, Amsterdam EU | AES-256-GCM per message, envelope encryption (data, key-encryption and master keys), versioned keys with rotation |
| Mood journal and intakesHealth data, GDPR Art. 9 | Same database, Amsterdam EU | Only after explicit consent; notes encrypted; withdrawal starts a 30-day erasure process |
| AI conversations and summariesOnly if the client subscribes to the AI chat | Stored in Amsterdam EU; processed by OpenAI via OpenAI Ireland Ltd. EU contract, US transfer possible | DPA with SCCs; no training on API data; 50 messages/day cap; crisis detection routes to helplines |
| Profile photos and diplomas | Cloudinary US, SCCs | Only what the professional uploads themselves; diplomas show as a verified badge, never as a document |
| Product analyticsWhich screens, which buttons | PostHog Cloud EU, Frankfurt EU | No message content, no mood data; on the website only after cookie consent |
| Error reporting | Sentry US, SCCs | Technical stack traces, no message content; real errors only, no behavioural data |
| EmailConfirmations, notifications, password reset | Resend US, SCCs | Transactional; no health data in emails, not even in the internal alerts sent to us |
| Payments | Stripe (web), Apple and Google (app) | Card data never touches our servers; we store only the subscription status |
EU stored and processed inside the EEA · US, SCCs US processor under the European Commission's Standard Contractual Clauses. This is the same list as in our privacy policy, section 5.2; if the two ever diverge, the privacy policy prevails.
Security
Concrete enough to test. No "bank-grade", just what it is.
Every message gets its own data key (AES-256-GCM). That data key is itself encrypted with a key-encryption key, which is encrypted with a master key held outside the database. Keys are versioned and rotated without old messages becoming unreadable.
Row-Level Security in PostgreSQL: the application reads through a database role that, per request, only sees the rows of the signed-in user. A bug in application code therefore cannot expose someone else's record. Administration runs through a separate, audited role.
The mood journal and intakes are Art. 9 data. They are only processed after a separate, explicit consent in the app, independent of the terms of service. Withdrawal is a single action; a reminder follows after 20 days, and after 30 days the data is erased or anonymised.
AI insights about a client reach a coach only if the client enables that for that coach. The default is off: no setting means no sharing. An organisation never sees which of its people has a coach or what is discussed.
Sessions use RS256-signed tokens and rotating refresh tokens with reuse detection. The web platform for professionals keeps no token in the browser: everything runs through httpOnly cookies and a server-side proxy. Administration requires two-factor authentication and IP allow-listing, and leaves an audit trail.
An account can be deleted inside the app, without emailing us. Inactive accounts and withdrawn consents are cleaned up by scheduled jobs, not by hand. Sessions expire after 24 hours.
Content Security Policy enforced, HSTS with preload, rate limiting on every public form and on the chat, Cloudflare at the edge. The website loads no tracker at all for visitors who decline cookies, not even a Google tag in "anonymised" mode.
Mentranova earns from a professional subscription and one optional AI feature for clients. Not from data. There is no retargeting inside the platform and no resale, and the terms say so.
What we do not claim
Four things that pages like this one usually keep vague.
Data processing agreement
We sign a data processing agreement with every practice or employer before anything runs. The sub-processor list on this page is the annex; if it changes, you hear about it beforehand. Security questions from your DPO are answered in writing, even when it is a forty-page questionnaire.
Questions from DPOs
Last reviewed: September 2026. Something no longer accurate? Email [email protected]; we change the page, not the answer.