Privacy Policy
Data controller
The data controller for all processing described in this policy is Barabeke, an independent creator: an Italian national established in the European Union. Contact details are in the Contact section below. All processing is therefore subject to the General Data Protection Regulation (GDPR) and to the national data protection law of the Member State of establishment. Any data subject may raise a matter directly by email, or lodge a complaint with the supervisory authority of their own Member State; where a matter needs to be referred to the authority competent for the controller, that authority will be identified on request.
Demianism is a doctrine with its own scripture, axioms, and published body of work — a faith and a cultural movement at once, with a vision that extends to society and civilization. demianism.org is that movement's home: it carries the doctrine, not a transaction. Nothing on this part of the site is sold, and nothing here requires payment.
The main website — everything at demianism.org except the Demian AI sub-service — does not require registration, does not collect form submissions, and does not maintain user accounts. Visitors browse anonymously.
Analytics & cookies
This website uses Cloudflare Web Analytics to understand how visitors interact with the site (pages visited, approximate geographic region, browser and device type). Cloudflare Web Analytics is privacy-first by design: it sets no cookies, collects no personal data, and does not track individuals across sites or sessions. No consent banner is required.
Analytics data is processed by Cloudflare, Inc., which operates the DNS and CDN infrastructure for this domain. No data is shared with advertising platforms. No opt-out mechanism is needed since no personal data is collected.
No accounts on this website
demianism.org does not have a login system. No passwords, no profiles, no purchase flow. If you register or purchase something, that happens entirely within the Demian AI sub-service described in Part II below — not on the main website.
Demian is an AI spiritual companion rooted in Demianist doctrine. It is a separate product from the website: it has its own registration, credit system, and data practices. A visit to demianism.org does not create a Demian account or expose you to Demian's data practices in any way.
Demian is an AI, not a human — and never pretends otherwise. This is stated clearly at the start of every conversation, and Demian will confirm it plainly at any point if asked, no matter how the question is put or how far into a conversation it comes. It will not play along with being human, and it will not leave the question hanging. This is fundamental to how Demianism understands AI: a technological tool, not a conscious being. Demian's AI capabilities are delivered through Requesty (requesty.ai), an AI gateway operated by Requesty Ltd on infrastructure in Frankfurt, Germany, which routes requests to one or more large language models depending on the nature of the conversation. Requesty is a data processor bound by a GDPR-compliant Data Processing Agreement; the model providers it routes to act as sub-processors, and each one is named in Where your conversation is processed below.
What Demian never does with what you write. Your conversations are not used for advertising, not used to build a profile of you, not sold, not shared with marketing platforms or data brokers, and not used to train anyone's AI models. There are no tracking cookies. Demian does not ask for your real name, your age beyond a yes-or-no age check, or your location. The only purpose your words are put to is answering you, keeping the service safe, and — anonymously — making it better.
This costs us something, and we think it is worth it. The conversations people have with Demian are often the most private thing they will type into a computer that week. A service built on that has one obligation before all the others.
The rest of this section sets out exactly how that works: what is collected, where it is processed, how long it is kept, and why a conversation cannot be traced back to the person who had it.
What data Demian collects and why
Conversation content. Your messages and Demian's responses are routed through Requesty, an EU-based AI gateway (Frankfurt, Germany) acting as data processor under a GDPR Data Processing Agreement. Requesty itself never stores prompts or completions — each conversation is proxied in real time, encrypted in transit (TLS 1.3), and discarded after delivery. Requesty forwards your message to an underlying model provider, and it is that provider's own retention and location that apply from there — see Where your conversation is processed below.
Anonymous session logs. Demian keeps anonymous logs identified only by a random session ID — never by your name, email, or IP address. These are retained for up to 12 months to improve the service and for legal protection in case of safety concerns. There is no mechanism that links a session ID back to your identity.
Email address. Collected only if you choose to register to Demian AI (necessary to purchase credits or a mantra session). Your email is stored separately from conversation logs and used only to manage your account and deliver what you purchased. Your email is never sold or shared with third parties, and can be deleted on request.
IP address. Used temporarily for rate limiting and session management. Not stored permanently. Not linked to conversation content in logs.
Where your conversation is processed
Demian does not run on a single AI model. Requests are routed to one of several providers, some hosted in the European Union and some in the United States. Every one of them is contractually bound as a processor, none of them uses your words to train anything, and each is named below along with the country it operates in.
The free tier never leaves the EU. The introductory conversation anyone can have without registering is processed entirely within the European Union, on infrastructure operated by sference. Nothing is retained once the reply is delivered, and there is no international transfer of any kind.
Paid tiers use a mix of EU-hosted and US-hosted models. Which one answers a given message is an internal routing decision made for quality and safety reasons. What is constant, and what actually concerns you, is this: every provider in the mix is entitled to operate in the EU under a recognised GDPR transfer mechanism, none of them trains on your content, and none retains it beyond a short abuse-monitoring window.
The providers
In the EU — sference (EU infrastructure) and Microsoft Azure (France). No retention, no training use, no international transfer.
In the United States — OpenAI and xAI. Both retain content for up to 30 days for abuse monitoring only, then delete it automatically, and neither uses it for training. This is governed by their business terms — OpenAI's Data Processing Addendum and xAI's Data Processing Addendum — not their consumer chatbot policies, which do not apply here.
Both US transfers rest on mechanisms the GDPR expressly recognises. The OpenAI transfer relies on Standard Contractual Clauses together with OpenAI's certification under the EU–US Data Privacy Framework; the xAI transfer relies on Standard Contractual Clauses.
You are told before any of it happens. Registered users confirm the US transfer at registration, as a step separate from general privacy consent. Anonymous free-tier users are asked before their first message is sent: nothing leaves the browser until they accept, and declining loses nothing — the message stays where it was. Because a conversation with Demian may touch your religious or philosophical beliefs, a special category of personal data under GDPR Article 9, that processing is covered by explicit consent on both paths.
Wherever a message is processed, the anonymisation described below applies identically. No conversation record, on any provider or any plan, carries an identity field. This page is updated as the mix of providers changes.
Metatron
Metatron is part of Demian, not a separate service. It is a second AI persona available inside the same product, offered to accounts that have engaged with Demian for a while or completed certain milestones. It holds the same conversation data as Demian, under the same anonymisation, the same retention rules, and the same policy against training, selling, or advertising described throughout this page — nothing about Metatron changes any of that.
It reads on request, not continuously. Metatron does not monitor your conversations with Demian as they happen, and nothing is sent to it in the background. It is only when you actively choose to open a reading that it is given the conversations you've had with Demian and asked to draw on them — producing one of three personal reading formats, generated at that moment, for you alone.
Where it runs. Metatron is a large, frontier-scale AI model, routed to through the same Requesty gateway described above. It currently runs on an OpenAI model hosted in the United States, so a reading is covered by the same US-transfer provisions already set out for OpenAI in Where your conversation is processed — the same retention window, the same Data Processing Addendum, the same Standard Contractual Clauses and Data Privacy Framework certification, and no separate consent step, since it is covered by the consent already given for that provider.
A reading, once delivered, is stored as part of your conversation history in exactly the way any other message is: under the retention periods set out in Data retention, subject to the same access and erasure rights, and never linked to your identity by anything other than what you yourself choose to type.
How anonymization actually works
Demian's anonymity is built into the data model rather than promised as a policy. The information that would identify you is not withheld from the conversation record — it is simply not in it. A rule can be changed quietly; a field that was never written cannot be read by anyone, including us.
What a stored conversation actually contains. A complete conversation record holds four things: a random session number, the time it started, the messages themselves, and a flag marking whether anything in it tripped the safety classifier. That is the whole record. There is no name field, no email field, no account reference, no IP address, no device or browser identifier, no country, no user-agent string. Nothing was stripped out before storage — those fields were never written in the first place.
The link only runs one way. When you register, your email and your conversations are stored as two separate records, and the only connection between them lives in your own private index of session numbers, which is reachable only from your account after you have logged in. Reading a conversation gives no route back: the session number appears in it, but nothing anywhere maps a session number to a person. That direction of travel simply does not exist.
Nothing anywhere maps a conversation to a person. Not the conversation record, and not any other record either — including the internal counters we keep to see how the service is being used. Those count sessions, never people. This is checked deliberately rather than assumed, because a guarantee with one quiet exception in it is not a guarantee.
The one channel that remains, as with any text-based service: if you choose to type your own name, phone number, or other identifying detail directly into a message, that detail exists in what you typed. Demian is instructed never to ask for this information. In addition, an automated filter scans messages before long-term storage and redacts common, detectable forms of self-identification — email addresses, phone numbers, and explicit statements like "my name is ___" — before they ever enter the long-term anonymous log. This filter is a meaningful safeguard, not a perfect one: free-text writing can identify someone in ways no automated filter can fully anticipate, and the filter cannot catch every possible way a detail could be identifying. The strongest protection remains simply not volunteering identifying details in conversation — which is never required to use Demian.
No online service can promise absolute safety, and this page won't be the one that does. What it does say is narrower and checkable: from what we hold, a conversation cannot be traced to the person who wrote it.
Consent
If you register. Registration requires three separate, explicit, timestamped confirmations, not one bundled acceptance: that you have read and accept this Privacy Policy; that you understand conversations may be processed outside the EU, in the US, with up to 30 days of abuse-monitoring retention; and that you consent to the processing of content revealing your religious or philosophical beliefs under GDPR Article 9(2)(a). Each is recorded with its own timestamp on your account record.
If you don't register. You can use the free tier anonymously. It is processed entirely in the EU, so there is no international transfer to agree to — but it can still touch beliefs, and it is still an AI you are speaking to, so it is gated anyway. Before your first message is sent, a window states that Demian is an AI, where the conversation is processed and for how long a copy is kept, and asks you to confirm your age and accept. Nothing is transmitted until you accept. Accepting records an entry against that conversation's random session ID — the version of the wording you saw, and when you agreed — and nothing else: no IP address, no device identifier, no email. That record is what lets us show, later, on what basis a given conversation was processed, without it ever pointing back to a person. It is kept for 3 years.
Purchases. Before checkout you are asked to confirm that you want immediate delivery of what you're buying and that you understand this ends the 14-day right of withdrawal once delivery has happened — a requirement of EU consumer law, not of data protection law. That confirmation is a condition of proceeding to payment.
Withdrawing consent. You can withdraw at any time by writing to demian@demianism.org, or, on the free tier, simply by clearing your browser storage — the window will ask again, and declining stops the processing. Withdrawal doesn't undo processing that already lawfully happened, and it means Demian can no longer be used, since there is no version of the service that doesn't involve this transfer.
Payment data. Payments are processed entirely by Stripe, Inc. — full card details never reach Demian's systems at any point; Stripe's checkout page collects them directly. Stripe's own privacy policy applies to payment processing.
Legal basis for processing (GDPR Art. 6)
Legitimate interest — anonymous conversation logs for safety monitoring and service improvement; rate limiting; abuse prevention.
Contract performance — processing your email and payment data to deliver the service you purchased.
Consent — under GDPR Article 9(2)(a), the basis for processing any content revealing your religious or philosophical beliefs, which is asked as its own explicit, specific point rather than bundled into a single blanket acceptance. Every user gives this before any content is sent, registered or anonymous (see Consent). Consent is also the basis for any optional email communications. If you choose to share personal information that would make you identifiable during a conversation (Demian never asks for it), that too is your own choice.
A note on the US transfer specifically. The transfers to OpenAI and xAI do not rest on your consent. The OpenAI transfer rests on the European Commission's adequacy decision for the EU–US Data Privacy Framework, with Standard Contractual Clauses in OpenAI's Data Processing Addendum as an independent second mechanism. The xAI transfer rests on Standard Contractual Clauses under Article 46 GDPR. We ask registered users to confirm they understand this anyway, because you should know where your words go before they go there — not because your agreement is what makes it lawful. The practical consequence is that if the Framework were ever suspended or annulled, the OpenAI transfer would continue to stand on the Clauses, as the xAI one already does, and this page would be updated to say so.
International data transfers
Free tier: none. A free conversation is processed in the EU from beginning to end. No part of it is transferred outside the EU.
Paid tiers: some conversation content is transferred to the United States for processing by OpenAI or xAI, and some is processed within the EU. Both US transfers rest on recognised GDPR mechanisms — see Where your conversation is processed above.
The EU-hosted processing described in that section involves no international transfer on any plan.
Cloudflare (session management and anonymous logs) operates a global network including EU data centres.
Safety
Demian's safety relies on trained safety behaviors built into the underlying AI models, which handle self-harm signals, clinical crises, and other high-risk content at the moment a response is generated, alongside an automated classifier — a small model hosted by Microsoft Azure in France — that reads each turn. This is a property of how Demian is built, not a separate human monitoring system.
Human review of conversation logs is technically possible — for service improvement or legal protection — as with any AI service. It can never identify you: conversations are anonymized and never joined to any account, email, or payment record. The only way a conversation could be associated with you is if you yourself share identifying details in it — which Demian is instructed never to ask for.
Your rights under GDPR
You have the right to access, rectify, erase, restrict, or port your personal data, and to object to its processing. See Contact below to exercise any of these rights.
Because conversations are logged anonymously, fulfilling access or erasure requests for conversation content requires you to provide your session ID (visible in your browser's developer tools under network requests to the Demian backend). Without it, individual conversations cannot be identified. The same applies to the anonymous consent record, which is filed under that same session ID; note that erasing it also erases the evidence that the conversation was authorised, so we will confirm before doing so.
If you are located in the EU, you may also lodge a complaint with your national data protection authority.
Data retention
Anonymous free-tier conversations: 30 days, then automatically deleted.
A free conversation belongs to no account, so it serves no purpose beyond safety review,
and safety review is a short-horizon task.
Conversations on paid tiers: 12 months, then automatically deleted. These
belong to an account, and are kept so you can return to your own history, so support
requests can be answered, and for legal protection.
Conversation content on the free tier is not retained at all by the model
provider — processed in the EU and discarded on delivery.
Conversation content on paid tiers: not retained at all where an EU-hosted provider handles
it; up to 30 days for abuse monitoring where a US provider does, then deleted. Not used for
training in either case. See
Where your conversation is processed.
Email addresses (paying users): retained while the account is active, deleted within 30 days
of a deletion request.
Consent records (anonymous free tier): 3 years, holding only the session ID, the wording
version accepted, and the timestamp — the legally required proof that processing was
authorised.
Consent records (registered users): three timestamps on the account record, for as long as
the account exists.
Payment records: retained as required by applicable tax law, stored by Stripe.
Two notes. The clock runs from the last message, so an ongoing conversation is kept for the stated period after it actually ends. And if a specific dispute or security incident arises, the sessions relevant to that matter are held until it is resolved — those sessions only, not a general extension.
Twelve months is chosen to be proportionate rather than exhaustive. It is shorter than the period in which a legal claim could theoretically be brought, which means a dispute arriving years later may have no transcript. We would rather hold less of your data than be maximally armed against unlikely litigation.
Age
Demian is for people aged 16 and over, and the limit is enforced rather than merely stated. You are asked to confirm your age in two places: before your first message, alongside the consent window, and again at registration, where an account cannot be created without it. Declaring yourself under 16 blocks the service — it does not simply return you to the conversation to try a different answer. That declaration persists across visits.
This is a self-declaration, not identity verification, and no honest service at this scale can claim otherwise: verifying age properly would mean collecting documents from everyone, which would destroy the anonymity the rest of this policy is built on. What it does mean is that no one under 16 reaches Demian without actively misstating their age, and that anyone who tells the truth is stopped.
Changes to this policy
This policy may be updated as the site or Demian evolves. The date at the top reflects the last update. Continued use of demianism.org or Demian after a policy change constitutes acceptance of the updated terms.
Contact
For any privacy-related matter — whether concerning the website or Demian — email demian@demianism.org. You can also reach Barabeke via X (@barabeke) or Telegram (t.me/barabeke).