Effective date: July 11, 2026
1. Data Controller
Myend B.V. is the controller of your personal data within the meaning of the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (Uitvoeringswet AVG / UAVG). Myend B.V., Hofmeyrstraat 26-2, 1091 NA Amsterdam, The Netherlands. Chamber of Commerce (KvK): 73864455. Contact: support@myend.com.
2. What We Collect
We collect the following categories of personal data: Account data, meaning your name, email address, and date of birth, provided during registration. Planning data: contacts, directives (last will, healthcare, funeral, euthanasia, donor), checklists, memories, belongings, and messages you create within the app. Health-related data, namely healthcare directives and euthanasia wishes you choose to record, which may constitute special category data under GDPR Article 9. Vault data: sensitive documents and information you store in the encrypted vault, which we cannot access due to AES-256 encryption. AI conversation data, meaning your conversations with Justine (our AI assistant), including any agent memories you allow Justine to retain. Device and usage data: app version, platform (iOS, Android, web), and basic usage analytics for service improvement. We do not collect data from third-party sources or social media profiles.
3. Legal Basis for Processing
We process your personal data on the following legal bases under GDPR Article 6: Contract performance (Art. 6(1)(b)): processing necessary to provide the Myend Service you signed up for, including storing your plans, enabling Legacy Contacts, and generating documents. Legitimate interest (Art. 6(1)(f)): service improvement, security monitoring, and fraud prevention, where our interests do not override your rights. Consent (Art. 6(1)(a)): for optional features like AI conversation memory retention, which you can toggle on or off in Privacy & AI settings. For health-related data (healthcare directives, euthanasia wishes), we rely on your explicit consent under GDPR Article 9(2)(a). You provide this consent by voluntarily entering this information into the app, and you may withdraw consent at any time by deleting this data.
4. How We Use Your Data
We use your data exclusively to: provide and operate the Myend Service, including AI-assisted planning; store your directives, legacy plans, and vault items securely; enable the Legacy Contact and Proof of Life systems; generate planning documents (wills, directives); deliver service communications (account verification, security alerts, policy updates); improve the Service through anonymized, aggregated analytics; and respond to your support requests. We do not sell your data. We do not use your data for advertising or marketing profiling. We do not use your content to train AI models.
5. AI Data Processing
Myend uses AI to power Justine, your planning assistant. Here is exactly what happens with your data: What Justine can see: your name, location, family composition, contacts, existing plans, and conversation history. You control this through the AI access toggles in Privacy & AI settings. What goes to AI providers: conversation messages are sent to Anthropic (Claude) for text responses, routed through OpenRouter as a failover path when needed under the same privacy constraints, voice recordings are sent to OpenAI (Whisper) for transcription only, and Justine’s spoken replies are synthesized by ElevenLabs (text of the reply only, on paid plans). What stays local: your vault contents (encrypted), message content ("last goodbyes"), and any data you disable in AI access toggles. No training on your data: neither Anthropic nor OpenAI use your data to train their models. Our agreements with these providers explicitly prohibit this. Automated decisions: Justine provides suggestions and guidance only. No automated decisions with legal or similarly significant effects are made about you. You always have final control over all content in your plans.
AI tools on the myend.com website. The public website offers a few AI helpers that work without an account: the Justine chat window, and the writing helpers on some articles (such as the sympathy message writer and the obituary writer). What you type into them (your question, or the details you give the writer) is sent to Anthropic (Claude) to generate the reply or drafts, and for no other purpose. Myend does not store these conversations or drafts, does not link them to any account, and they are never used to train AI models. Please do not enter sensitive personal data (yours or anyone else's) into the website tools; they do not need it to help you. If a message suggests someone may be in crisis, the tools respond with crisis-line information (988 in the US, findahelpline.com elsewhere) instead of an AI-generated answer.
6. Local-First Architecture
Myend is built with a local-first architecture, which means your data is stored primarily on your device in a local database. This provides significant privacy advantages: your data is available offline without an internet connection; you maintain physical possession of your information; syncing to cloud storage happens in the background and can function without it; and if our servers were ever compromised, the attacker would not gain access to data that only exists on your device. When you do sync, data is encrypted in transit (TLS 1.3) and at rest on our cloud infrastructure. Vault items receive additional AES-256 encryption that we cannot decrypt.
7. Data Sharing & Sub-Processors
We share your data only with the following sub-processors, under strict data processing agreements: Supabase Inc. (United States): cloud database, authentication, and file storage. Processes: account data, synced planning data. Anthropic PBC (United States): AI text generation for Justine. Processes: conversation messages, user context (name, plans, contacts per your settings). OpenRouter Inc. (United States): AI request routing, used as a failover path to reach Claude models when needed. Processes: the same conversation context sent to Anthropic, under the same privacy constraints. OpenAI Inc. (United States): voice-to-text transcription. Processes: voice recordings only, not stored after transcription. ElevenLabs Inc. (United States): voice synthesis for Justine’s spoken replies (paid plans). Processes: the text of Justine’s replies only, never your messages or vault contents. Resend Inc. (United States): transactional email delivery. Processes: email address, email content. Stripe, Inc. (United States): payment processing for one-time purchases and the maintenance subscription. Processes: payment card data (Stripe receives this directly; we never store your card numbers), billing name, and email address. PowerSync (South Africa): local-to-cloud data synchronization. Processes: synced planning data. We do not share your data with any other third parties, advertisers, or data brokers.
8. International Data Transfers
Several of our sub-processors are based in the United States, including Supabase, Anthropic, OpenRouter, OpenAI, ElevenLabs, Resend, and Stripe. For transfers of personal data from the European Economic Area (EEA) to the United States, we rely on: the EU-US Data Privacy Framework, where applicable, for processors that are certified; Standard Contractual Clauses (SCCs) approved by the European Commission, as a supplementary safeguard; and technical measures including encryption in transit and at rest. We regularly assess these transfer mechanisms and the data protection practices of our sub-processors to ensure adequate protection of your data.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data: AES-256 encryption for vault items (we cannot access the encrypted content); TLS 1.3 encryption for all data in transit; Supabase Row-Level Security (RLS) ensuring users can only access their own data; secure authentication via Supabase Auth with password hashing; local-first storage reducing cloud exposure; and regular security reviews. No system is 100% secure. In the event of a data breach affecting your personal data, we will notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours as required by GDPR Article 33, and notify you without undue delay if the breach is likely to result in a high risk to your rights and freedoms.
10. Data Retention
We retain your personal data only for as long as necessary: Account and planning data: retained for the duration of your account. When you delete your account, all data is permanently removed from our cloud systems within 30 days. Local data on your device is deleted immediately. AI conversation data: retained for the duration of your account. You may clear AI memories at any time through Privacy & AI settings. Voice recordings: processed by OpenAI for transcription and not stored after processing. Email delivery logs: retained by Resend for up to 30 days for delivery troubleshooting. Anonymized analytics: may be retained indefinitely as they cannot identify you. We do not retain your data after account deletion except where required by applicable law (e.g., tax or accounting obligations).
11. Your Rights
Under the GDPR and Dutch law (UAVG), you have the following rights regarding your personal data: Right of access: request a copy of all data we hold about you. Right to rectification: correct inaccurate or incomplete data. Right to erasure: request deletion of your data ("right to be forgotten"). Right to restrict processing: limit how we use your data. Right to data portability: receive your data in a structured, machine-readable format (available via the Download Data feature in Privacy & AI settings). Right to object: object to processing based on legitimate interest. Right regarding automated decisions: you are not subject to decisions based solely on automated processing with legal effects. Right to withdraw consent: withdraw consent at any time without affecting the lawfulness of prior processing. You can exercise most of these rights directly through the Privacy & AI settings in your account, or by contacting us at support@myend.com. We will respond within 30 days. If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Dutch Data Protection Authority: Autoriteit Persoonsgegevens, Bezuidenhoutseweg 30, 2594 AV Den Haag, https://autoriteitpersoonsgegevens.nl.
12. Cookies & Tracking
Myend is mobile-first, and the native app does not use browser cookies at all. On the website and the web app we use two kinds. Essential cookies do not require consent: they keep you signed in, remember your preferences, and remember the cookie choice you make in the bar at the bottom of the page. Analytics cookies work differently depending on where you are. In the European Union, the EEA and the United Kingdom we ask first, and nothing is stored until you accept. Everywhere else they are set by default, and you can switch them off whenever you like using "Cookie settings" in the footer of any page. Either way the tool is PostHog, we use it to count pageviews and to understand which pages people find useful and where they get stuck, and it stores a randomly generated identifier in your browser for up to 12 months so that several pages read in one visit, or a return visit, are not counted as several different people. If you decline, or switch them off, we still count the page view, but anonymously and with nothing stored on your device. We do not record your IP address on the website; it is used to derive an approximate country and then discarded. We do not use advertising or marketing cookies, we do not sell or share analytics data with third parties for their own purposes, and we do not use fingerprinting or cross-site tracking. PostHog acts as our processor and stores this data on servers in the United States. You can change or withdraw your choice at any time using "Cookie settings" in the footer of any page, or by clearing cookies in your browser.
13. Children
Myend is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child under 18 has provided personal data, we will take immediate steps to delete such information from our systems.
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated at least 30 days in advance via email or in-app notification. The "Last updated" date at the top of this policy will be revised accordingly. Continued use of the Service after the effective date of an updated policy constitutes your acceptance.
15. Contact
For questions about this Privacy Policy, to exercise your data rights, or to raise a privacy concern, contact: Myend B.V., Hofmeyrstraat 26-2, 1091 NA Amsterdam, The Netherlands. Email: support@myend.com. Chamber of Commerce (KvK): 73864455. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at https://autoriteitpersoonsgegevens.nl.