Effective Date: 23 January 2026 | Last updated: 6 February 2026
We believe in transparency and minimal tracking. This policy explains what technologies we use, why we use them, and how you can control them.
This Cookie & Tracking Policy forms part of our Privacy & Data Protection Policy and should be read alongside our Terms of Service.
We use only essential cookies and technologies required to operate the Service. We do NOT use:
Required for the Service to function. Without these, you cannot log in or use core features.
| Technology | Provider | Purpose | Duration |
|---|---|---|---|
| Auth Session | Supabase | Keeps you logged in | Until logout/expiry |
| Secure Token | Supabase | API authentication | Session |
| Local Storage | Browser/App | App preferences, cached data | Until cleared |
Used to deliver push notifications to your device (if enabled).
| Technology | Provider | Purpose | Duration |
|---|---|---|---|
| Expo Push Token | Expo (650 Industries) | Push notification delivery | Until app uninstall |
| APNs Token | Apple Inc. | iOS push delivery | Until app uninstall |
| FCM Token | Google LLC | Android push delivery | Until app uninstall |
Used to identify and fix bugs. You can opt out of this.
| Technology | Provider | Purpose | Duration |
|---|---|---|---|
| Error Reports | Sentry (Functional Software) | Crash and error tracking | 90 days |
| Session Replay | Sentry (Functional Software) | Masked screen recordings for bug diagnosis — all text, images, and input fields are hidden | 90 days |
Technologies used when you visit our website (doxa.app).
| Technology | Provider | Purpose | Duration |
|---|---|---|---|
| CDN/Edge | Vercel Inc. | Website hosting and delivery | Session |
| Access Logs | Vercel Inc. | Security and performance | 30 days |
We use Google Analytics (GA4) on our website to understand basic traffic patterns. This is NOT used in the mobile app.
| Technology | Provider | Purpose | Duration |
|---|---|---|---|
| Google Analytics 4 | Google LLC | Page views, traffic sources, basic usage patterns (anonymized) | 14 months |
Google Analytics uses cookies to distinguish users. We have enabled IP anonymization and do not use it for advertising, remarketing, or cross-site tracking. For EU visitors, analytics are loaded only with consent where required by law.
When you use AI-powered features, your content is processed by our AI partners:
| Feature | Provider | Data Processed | Retention |
|---|---|---|---|
| Audio Transcription | AssemblyAI | Audio files | Deleted after processing |
| Title Generation | Anthropic (Claude) | Text content | 7-day retention, then deleted |
| Content Synthesis | Google (Gemini) | Text content | Not used for training per API terms |
| Content Review | Anthropic (Claude) | Text content | 7-day retention, then deleted |
| Voice Chat (Engage) | ElevenLabs | Voice audio (streamed) | Real-time only, not stored |
| AI-Generated Images | AI Image Generation | Text prompts (testimony content) | Prompts not stored by provider |
These are optional features. Your content is processed transiently and is not used to train AI models per our agreements with these providers.
When you use the Engage voice chat feature, here's exactly what happens with your data:
You can use text-only mode if you prefer not to use voice features.
You have control over how we use tracking technologies. Here are your options:
You can disable push notifications at any time through your device settings (Settings → Notifications → Doxa). Disabling notifications does not affect other app functionality.
Sentry error reporting helps us fix bugs and improve reliability. You can:
When using our website, you can manage cookies through your browser settings:
We do not use cookie consent banners because we only use essential cookies that are strictly necessary for the Service to function. Under UK GDPR/PECR, consent is not required for such cookies.
AI features (transcription, title generation, voice chat, recommendations) are optional enhancements. You can use the core app without these features if you prefer not to have your content processed by AI. Opting out of AI features does not affect your ability to record and store content.
We honour "Do Not Track" browser signals. However, since we don't track you for advertising purposes anyway, there is no practical difference whether this setting is enabled or not.
For more information about how our partners handle data:
We may update this policy from time to time. Material changes will be communicated via the app or this page. The "Last updated" date at the top indicates when this policy was revised.
Under UK GDPR, ePrivacy Directive, and PECR, we rely on the following legal bases:
While we take measures to limit tracking and protect your privacy, you acknowledge that:
For questions about cookies or tracking technologies:
Email: privacy@doxa.app
Address: The Doxa Way Ltd, 108 Kings Road, New Haw, Addlestone, KT15 3BH, United Kingdom
See also our Privacy & Data Protection Policy and Terms of Service.
Our Commitment to Your Privacy
No advertising cookies. No behavioural tracking. No data selling. Your privacy matters.