( § Privacy )
Privacy.
We process personal data under the Swiss Federal Act on Data Protection (FADP) and, where it applies, the EU GDPR. Here's what we process, why, for how long, with whom — and what you can do yourself at any time.
§ 01
Controller
BloomDigital GmbH (brand OwnMore) · Langenthalstrasse 8A · 4932 Lotzwil · BE · Switzerland
privacy@ownmore.world
We have not appointed a data protection officer; Art. 10 FADP leaves this optional for private controllers. Whether we need to appoint a representative in the EU under Art. 27 GDPR is something we're clarifying before launch on 1 October 2026, and we'll name them here once decided.
§ 02
Website and waitlist
When you visit the website, our hosting provider (Vercel) processes technical data such as IP address, browser and the page requested in access logs, to deliver the page and protect against abuse (legitimate interest in secure operation, Art. 31 para. 1 FADP; where the GDPR applies, Art. 6(1)(f) GDPR). We remember your language choice and light/dark setting locally in your browser (om-lang, om-theme) and as the NEXT_LOCALE cookie — solely so the page opens the way you left it (Art. 45c let. b of the Telecommunications Act). On the homepage we set no advertising cookies and no cross-site tracking.
When you join the waitlist, we keep your email address, chosen language and the time as an email in our inbox (Google Workspace) and in the delivery log of our email provider (Resend). In addition, our tamper-proof audit chain records that and when we wrote to you — with your address. It is our proof that the commitment and the opt-out were honoured, and it is never used to contact you. We send you a confirmation and, once the account is ready, one further message; nothing else. You can unsubscribe with one click in every message we send you about the waitlist; after that we strike the address from our inbox; until that runs automatically, we do it by hand. The basis is your request — processing directly connected with the conclusion of a contract (Art. 31 para. 2 let. a FADP; where the GDPR applies, Art. 6(1)(b) GDPR).
For enquiries through forms (contact, access, demo), our server automatically records IP address, browser identifier and referrer to guard against abuse; campaign parameters, landing page and time on site come from your visit. We keep them together with the enquiry and delete them with it.
In the signed-in area, we set cookies that carry the operation: the session (Clerk), your language choice, your decision to set up multi-factor authentication later (180 days), and the usage measurement PostHog on European servers. We set no advertising cookies anywhere. You can delete them at any time in your browser (Art. 45c let. b of the Telecommunications Act).
§ 03
Ankunft — the capture tool
Data capture goes live on 1 October 2026; until then, this section describes what will apply.
In the capture tool («Ankunft») you record what's eating your day: notes, figures, images, voice recordings with transcription. This data sits first on your device (in browser storage). With an account, it is transferred to your account encrypted and stored there, so you have it on every device.
What you record can include personal data warranting special protection — such as details about sleep, weight or wellbeing. We process it solely to provide the service you request through the capture tool: processing directly connected to our contract (Art. 31 para. 2 let. a FADP; where the GDPR applies, Art. 6(1)(b) GDPR). You can withdraw it at any time by deleting it. We do not evaluate this data for advertising and do not pass it on to third parties.
The transcription while speaking is produced by your browser's speech recognition. In Chrome and Edge the browser sends that audio to Google and Microsoft respectively; in Safari, to Apple — that happens outside OwnMore, and we only see the finished text. If you don't want that, type instead of speaking. You store the audio recording itself as a file in your account.
Profile details from the intake questions (form of address, what's eating your time, when your head is free) serve only to tailor the interface to you and to reach you at the right time.
Because what you capture may contain sensitive personal data, we ask explicitly before the first entry: «Ich bin einverstanden, dass OwnMore (BloomDigital GmbH) bearbeitet, was ich hier erfasse — auch Gesundheitliches wie Schlaf, Gewicht oder Befinden, und meine Stimme als Aufnahme, auf diesem Gerät und in meinem Konto bei Supabase (Datenbank und Dateispeicher, Rechenzentrum in der EU).» (I agree that OwnMore (BloomDigital GmbH) processes what I capture here — including health-related things such as sleep, weight or how I feel, and my voice as a recording, on this device and in my account with Supabase (database and file storage, data centre in the EU).) This consent (Art. 6 para. 7 let. a FADP; where the GDPR applies, Art. 9(2)(a) GDPR) comes in addition to the contractual basis; we keep the time of consent on your device. You can withdraw it at any time by deleting — «Alles löschen» ("Delete everything") also removes the consent.
§ 04
Account and sign-in
For the capture tool, you sign in with your email address and a link (no password). Account, database and file storage run on Supabase; in the capture tool, every row and every file is bound to your account at database level (row-level security), so no one but you and the operational processes we commission can access it.
For the investment platform, sign-in runs through Clerk (email, Google sign-in). Multi-factor authentication is available to you there at any time; once a contract is concluded, we expressly recommend it and actively ask about it.
An account is set up by whoever has capacity to judge. In the household account, the parents or legal guardians set up the spaces for children and decide what is recorded there; we never evaluate this data and never show advertising there. Where the GDPR applies, we follow Art. 8 GDPR.
§ 05
Investment platform for qualified investors
On the closed investment platform, we process what's needed for admission, due-diligence duties and documentation: identification and contact data, details on classification as a professional client under Arts. 4–5 FinSA and thus as a qualified investor under Art. 10 para. 3 CISA, identity-verification documents, expressions of interest, reservations and a record of the steps taken. The basis is the platform agreement (Art. 31 para. 2 let. a FADP; where the GDPR applies, Art. 6(1)(b) GDPR) and, for the due-diligence documents, the partner's legal obligation (Art. 6(1)(c) GDPR). The due-diligence duties under AMLA and FinSA rest with the licensed partner who executes the transaction; we collect and keep the documents on their behalf and follow their ten-year retention period (Art. 7 para. 3 AMLA). Once OwnMore itself is supervised, we will say so here.
§ 06
Automated processing and AI
OwnMore uses language models to recognise, summarise and check text. For new features, a model router decides by data class which provider is allowed to see something: personal data goes only to a provider with a data processing agreement (Art. 9 FADP) and a basis for cross-border disclosure (Art. 16 FADP). No provider meets this today — so no model there sees personal data. The older functions of the investment platform do not yet run through this router; there we hold back personal data per function in the code (names and email addresses never reach a model). We provide the corresponding processing register on request.
We state one exception openly: for the investment platform, language models from Anthropic (USA) read property documents from the data room — rent rolls, land register extracts, plans — as well as the questions you yourself ask in the data-room chat; both can contain personal data of third parties. A data processing agreement and a guarantee under Art. 16 FADP with Anthropic have not yet been concluded; until then, we process there only documents that you or the seller side have handed over to us for that purpose, and we close this gap before launch on 1 October 2026.
No automated system alone makes decisions with legal consequences for you (Art. 21 FADP): money, contracts and filings with authorities require your express approval in each individual case.
§ 07
Retention and deletion
What you record stays until you delete it. Deleted entries are marked as deleted immediately — they appear nowhere anymore, and the deletion propagates to all your devices. Final removal from the database, files included, currently happens on request to privacy@ownmore.world; we activate the daily automatic run that does this after thirty days once we launch. «Delete everything» removes profile, entries and files in one go; there is no follow-up question about the reason.
We strike waitlist addresses upon opt-out — today by hand from our inbox — or at the latest six months after launch; the entry in the audit chain (see § 02) remains as proof. We keep data from the investment platform for as long as the contract and the law require (accounting records and due-diligence documents for ten years). Our providers' technical logs expire on each provider's own schedule, at the latest after ninety days (error reports at Sentry).
§ 08
Providers and cross-border disclosure
We use providers who process data on our behalf:
– Vercel (hosting, website delivery; Vercel Inc., USA, with delivery points worldwide)
– Supabase (database, file storage, sign-in for the capture tool; Supabase Inc., USA — data centre in the EU, AWS region eu-central)
– Clerk (sign-in for the investment platform; Clerk Inc., USA)
– Resend (email delivery; Resend Inc., USA)
– Google Workspace (our inbox; Google Ireland Ltd, Ireland — group company Google LLC, USA)
– Anthropic (language models; Anthropic PBC, USA — see § 06)
– Sentry (error reports, personal data masked; Functional Software Inc., USA)
– PostHog (usage measurement without advertising profiles; servers in the EU)
– Vercel Analytics and Speed Insights (page views and load times, no cookies; USA)
– Upstash (abuse protection, per-request counters; USA — where set up)
– GitHub (source code, deployment runs, encrypted database backups; GitHub Inc., USA — the backup is AES-256 encrypted, only BloomDigital holds the key)
For each provider, we record what the cross-border disclosure is based on. Where this basis is not yet in place, we process no personal data there, or we say so explicitly here (§ 06). We provide the status per provider on request. Where the basis is in place, for providers in the USA it is the EU Commission's Standard Contractual Clauses with the Swiss amendments (Art. 16 para. 2 let. d FADP; where the GDPR applies, Art. 46(2)(c) GDPR), or the provider's certification under the Swiss-U.S. Data Privacy Framework.
§ 09
Security
Transmission only encrypted (TLS). Data at rest is encrypted by the respective provider (Supabase, Vercel). In the capture tool, every row and every file is bound to your account at database level. On the investment platform, access control operates within the application; every substantive action is recorded in a tamper-proof audit chain. For operations, the rule is: as few accesses as possible. There is no such thing as absolute security. If something happens, we report it to the FDPIC as soon as possible where there is a high risk to you (Art. 24 para. 1 FADP) — where the GDPR applies, within 72 hours (Art. 33 GDPR) —, and inform you if that is necessary for your protection or the FDPIC requires it (Art. 24 para. 4 FADP).
§ 10
Your rights
You have the right at any time to access (Art. 25 FADP), rectification (Art. 32 FADP), deletion, provision of your data in a common format (Art. 28 FADP) and objection to processing (Art. 30 para. 2 let. b FADP). In the capture tool, you handle provision («Export everything», including images and audio recordings) and deletion («Delete everything») yourself, without asking us. For everything else: privacy@ownmore.world. We reply within thirty days. Complaints are handled by the Federal Data Protection and Information Commissioner (FDPIC).
Where the GDPR applies, you additionally have the rights under Arts. 15–22 GDPR — access, rectification, erasure, restriction, data portability, objection — and the right to lodge a complaint with the supervisory authority of your place of residence (Art. 77 GDPR).
§ 11
Changes
If something changes — a new provider, a data processing agreement with an AI provider, a dedicated company as operator — we update this statement and name the date at the end of this page. We write to you about material changes if you have an account.
7 September 2026: statement fully rewritten for what OwnMore is today; provider list with countries; the earlier statement that providers were located exclusively in Switzerland and the EEA was inaccurate.
Updated · 2026-09-07