1 What is stored, and where

Ciaera stores mood check-ins, chat messages, journal entries and account data. Everything is stored in the EU. The current hosting provider and region are listed under sub-processors in the privacy policy.

2 Encryption

Mood labels, chat messages, journal entries and AI memory notes are encrypted at rest with AES-256-GCM, under keys derived per user from a server-side secret. The keys themselves are never stored anywhere; they are derived on demand and discarded.

In transit, everything runs over TLS 1.2 or better. Both mobile apps also use certificate pinning.

3 Who can see what

Employees see only their own data. HR sees aggregated trends for the team, and only once at least five people have responded in the period; below five, the dashboard shows nothing at all.

Row-level security in the database keeps each company's data separate. Administrative access requires two-factor authentication, and changing a password, changing a role or withdrawing consent signs out every existing session.

4 AI processing

Replies are generated by Anthropic's Claude. Anthropic receives the message text only, never your name or email. Under Anthropic's commercial terms, inputs and outputs sent through that API are not used to train its models. Transfers to Anthropic rely on Standard Contractual Clauses approved by the European Commission under Art. 46 GDPR.

Ciaera provisions and pays for a separate Anthropic API key for each customer company, so one customer's conversations are never mixed into another's usage.

5 Your rights, in the app

Employees can export their data, erase their account, withdraw consent and change their email address directly in the app, without contacting support. Details and the exact menu paths are in Section 10 of the privacy policy.

6 Incidents

If a breach happens that is likely to put your rights at risk, the Finnish supervisory authority is notified within 72 hours of finding out (Art. 33 GDPR), and if the risk to you personally is high, you are told directly and without delay (Art. 34 GDPR).

Backend error diagnostics are collected so faults get fixed, configured to never attach request bodies or user identifiers.

7 For DPOs and works councils

A data processing agreement is available on request. Retention periods for every kind of data are listed at privacy policy §9, and every sub-processor is named at privacy policy §7.

Questions go to info@ciaerampf.com.