demianism.org

Privacy Policy

Last updated: June 2026

Data controller

The data controller for all processing described in this policy is Barabeke, an independent creator operating from the EU. Contact details are in the Contact section below. As an EU-based operator, all processing is subject to the General Data Protection Regulation (GDPR).


Part I
demianism.org — the website
The public site: doctrine, culture, origin, community, and this page.

The main website — everything at demianism.org except the Demian AI sub-service — does not require registration, does not collect form submissions, and does not maintain user accounts. Visitors browse anonymously.

Analytics & cookies

This website uses Cloudflare Web Analytics to understand how visitors interact with the site (pages visited, approximate geographic region, browser and device type). Cloudflare Web Analytics is privacy-first by design: it sets no cookies, collects no personal data, and does not track individuals across sites or sessions. No consent banner is required.

Analytics data is processed by Cloudflare, Inc., which operates the DNS and CDN infrastructure for this domain. No data is shared with advertising platforms. No opt-out mechanism is needed since no personal data is collected.

No accounts on this website

demianism.org does not have a login system. No passwords, no profiles, no purchase flow. If you register or purchase something, that happens entirely within the Demian AI sub-service described in Part II below — not on the main website.


Part II
Demian AI — the sub-service
A distinct product hosted at demianism.org/demian. Demian has its own user accounts, payment flow, and data practices, described in full below.

Demian is an AI spiritual companion rooted in Demianist doctrine. It is a separate product from the website: it has its own registration, credit system, and data practices. A visit to demianism.org does not create a Demian account or expose you to Demian's data practices in any way.

Demian is an AI, not a human. This is stated clearly at the start of every conversation and is fundamental to how Demianism understands AI: a technological tool, not a conscious being. Demian's AI capabilities are delivered through Requesty (requesty.ai), an EU-based AI gateway that routes requests to one or more large language models depending on the nature of the conversation. Requesty acts as the sole data processor for all AI inference and is bound by a Data Processing Agreement compliant with GDPR.

What data Demian collects and why

Conversation content. Your messages and Demian's responses are processed exclusively through Requesty's infrastructure, hosted in Frankfurt, Germany. Data never leaves EU jurisdiction. Requesty applies zero data retention by default: your prompts and completions are proxied in real time and immediately discarded after delivery — they are never stored on Requesty's servers. All data in transit is protected by TLS 1.3 encryption. Requesty does not use conversation data to train AI models and does not share it with third parties.

Anonymous session logs. Demian keeps anonymous logs identified only by a random session ID — never by your name, email, or IP address. These are retained for up to 12 months to improve the service and for legal protection in case of safety concerns. There is no mechanism that links a session ID back to your identity.

Email address. Collected only if you choose to register to Demian AI (necessary to purchase credits or a mantra session). Your email is stored separately from conversation logs and used only to manage your account and deliver what you purchased. Your email is never sold or shared with third parties, and can be deleted on request.

IP address. Used temporarily for rate limiting and session management. Not stored permanently. Not linked to conversation content in logs.

How anonymization actually works

Demian's privacy design is not just a policy — it is a structural property of the system. When you register an account, your email and your conversation content are stored as two entirely separate records, with no field in either one that points to the other. Verifying that a conversation belongs to your account works by checking your own private list of session IDs — never by attaching your identity to the conversation record itself. The conversation content never carries an identity field, at any point, for any user, logged in or not.

The one channel that remains, as with any text-based service: if you choose to type your own name, phone number, or other identifying detail directly into a message, that detail exists in what you typed. Demian is instructed never to ask for this information. In addition, an automated filter scans messages before long-term storage and redacts common, detectable forms of self-identification — email addresses, phone numbers, and explicit statements like "my name is ___" — before they ever enter the long-term anonymous log. This filter is a meaningful safeguard, not a perfect one: free-text writing can identify someone in ways no automated filter can fully anticipate, and the filter cannot catch every possible way a detail could be identifying. The strongest protection remains simply not volunteering identifying details in conversation — which is never required to use Demian.

Registering an account requires actively confirming you have read and accept this Privacy Policy, presented as an explicit checkbox at the point of registration — not a passive assumption. This consent is recorded with a timestamp. You do not need to register, and do not need to give any consent, to use Demian's free tier anonymously.

Payment data. Payments are processed entirely by Stripe, Inc. — full card details never reach Demian's systems at any point; Stripe's checkout page collects them directly. Stripe's own privacy policy applies to payment processing.

What Demian does not collect. Demian does not ask for your real name, age, or location. It does not use tracking cookies. It does not build profiles for advertising. It does not share data with advertisers or marketing platforms.

Legitimate interest — anonymous conversation logs for safety monitoring and service improvement; rate limiting; abuse prevention.

Contract performance — processing your email and payment data to deliver the service you purchased.

Consent — if you choose to share personal information that would make you identifiable during a conversation (Demian never asks for it), that is your own choice. Consent is also the basis for any optional email communications.

International data transfers

AI inference is processed exclusively through Requesty's EU infrastructure in Frankfurt, Germany. No conversation data leaves the European Union at any point. This means there are no international data transfers to declare for AI processing — Requesty's gateway is both the technical and legal boundary.

Cloudflare (session management and anonymous logs) operates a global network including EU data centres.

Safety

Demian's safety relies on trained safety behaviors built into the underlying AI models, which handle self-harm signals, clinical crises, and other high-risk content carefully at the moment a response is generated. This is a property of the models themselves, not a separate monitoring system.

Human review of conversation logs is technically possible — for continuous improvement of the service, or for legal protection in case of safety concerns — the same way it is for any AI service. What review can never do is identify you: conversations are anonymized by the system and are not joined to any account, email, or payment record under any circumstance. The only way a conversation could ever be associated with you is if you yourself choose to share identifying personal details in the conversation — which Demian is instructed never to ask for, beyond what is reasonably needed to provide the service.

Your rights under GDPR

You have the right to access, rectify, erase, restrict, or port your personal data, and to object to its processing. See Contact below to exercise any of these rights.

Because conversations are logged anonymously, fulfilling access or erasure requests for conversation content requires you to provide your session ID (visible in your browser's developer tools under network requests to the Demian backend). Without it, individual conversations cannot be identified.

If you are located in the EU, you may also lodge a complaint with your national data protection authority.

Data retention

Anonymous conversation logs: 12 months, then automatically deleted.
Email addresses (paying users): retained while the account is active, deleted within 30 days of a deletion request.
Payment records: retained as required by applicable tax law, stored by Stripe.

Age

Demian is intended for users aged 16 and over. If you are under 16, please do not use this service. By using Demian, you confirm that you are at least 16 years old.


Changes to this policy

This policy may be updated as the site or Demian evolves. The date at the top reflects the last update. Continued use of demianism.org or Demian after a policy change constitutes acceptance of the updated terms.


Contact

For any privacy-related matter — whether concerning the website or Demian — email demian@demianism.org. You can also reach Barabeke via X (@barabeke) or Telegram (t.me/barabeke).