Skip to main content
Skip to main content

Privacy Policy

Your privacy and the security of your mental health conversations are our highest priorities. This policy explains how we collect, use, and protect your information.

Last Updated: January 18, 2025

Effective Date: January 18, 2025

Important Legal Notice

This privacy policy is a template for informational purposes only. It should be reviewed and customized by a qualified attorney to ensure compliance with all applicable laws and regulations specific to your jurisdiction and business operations. Ophie makes no representations or warranties regarding the legal sufficiency of this document.

1. Introduction

Welcome to Ophie, a voice-first AI mental health companion operated by Ophie ("Ophie," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application, mobile applications, and related services (collectively, the "Service").

We understand that the information you share with Ophie is deeply personal and sensitive. Mental health conversations require the highest level of trust and confidentiality. We have designed our Service with privacy as a foundational principle, not an afterthought.

By accessing or using our Service, you agree to this Privacy Policy. If you do not agree with our policies and practices, do not use our Service.

1.1 Our Privacy Commitments

  • Transparency: We clearly explain what data we collect and why
  • User Control: You choose your privacy mode and have full control over your data
  • Security: We employ industry-standard encryption and security measures
  • Minimization: We collect only the data necessary to provide our Service
  • No Data Sales: We never sell your personal information to third parties

2. Information We Collect

We collect information in several ways: directly from you, automatically through your use of the Service, and from third-party sources. Below is a comprehensive list of the information we may collect.

2.1 Information You Provide Directly

Account Information

  • Full name
  • Email address
  • Age range (18-24, 25-34, 35-44, 45-54, 55-64, 65+)
  • Display name (optional)
  • Pronouns (optional)
  • Bio (optional, max 500 characters)
  • Avatar/profile image
  • Timezone

Preferences & Context

  • Privacy mode selection (Memory or Ephemeral)
  • Communication style preferences
  • Response length preferences
  • Empathy level settings
  • Voice tone preferences
  • Personal goals from onboarding
  • Life stage and concerns

2.2 Conversation and Session Data

When you use Ophie, we process the content of your conversations to provide our Service. The extent of data storage depends on your selected privacy mode:

Session Data

  • Session start and end timestamps
  • Session duration
  • Message count per session
  • Session type (voice, web, mobile, API)
  • LiveKit room and session identifiers
  • Full conversation transcripts (in Memory Mode)
  • AI-generated session summaries
  • Key moments from sessions
  • Memory items for personalization

Message Content

  • Text of your messages
  • AI assistant responses
  • System prompts and context
  • Message timestamps
  • Message role (user/assistant/system)
  • Voice track identifiers
  • Participant identity markers

2.3 Therapeutic and Emotional Data

To provide personalized mental health support, we may collect and analyze the following sensitive information:

Emotional Analysis

  • Sentiment scores and emotional valence
  • Dominant emotions detected
  • Emotional trajectory over sessions
  • Arousal levels during conversations
  • Crisis indicators (for safety purposes)
  • Therapeutic notes generated by AI

Therapeutic Profile

  • Primary mental health concerns
  • Therapeutic goals and progress
  • Identified emotional triggers
  • Effective coping strategies
  • Technique effectiveness ratings
  • Relationships mentioned (with consent)
  • User facts for personalization
  • Learned preferences over time

2.4 Technical and Usage Data

Device Information

  • IP address
  • Browser type and version
  • Operating system
  • Device identifiers
  • User agent string
  • Screen resolution
  • Time zone settings

Usage Analytics

  • Pages visited and features used
  • Session duration and frequency
  • Interaction patterns
  • Error logs and crash reports
  • API token usage statistics
  • Model usage (for cost tracking)
  • Feature engagement metrics

2.5 Goals and Personal Objectives

User Goals

  • Goal titles and descriptions
  • Goal categories (self-care, mindfulness, relationships, movement, other)
  • Priority levels
  • Due dates
  • Completion status and timestamps

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 Service Provision

  • Core Functionality: Processing your voice and text inputs to provide AI-powered mental health companion conversations
  • Personalization: Remembering your preferences, past conversations (in Memory Mode), and adapting responses to your communication style
  • Contextual Awareness: Maintaining conversation context across sessions using our Retrieval-Augmented Generation (RAG) system
  • Dynamic Tools: Providing personalized breathing exercises, journaling prompts, and wellness activities through our Dynamic Island feature

3.2 Safety and Crisis Detection

  • Detecting potential crisis situations (e.g., expressions of self-harm or suicidal ideation) to surface appropriate professional resources
  • Enforcing safety guardrails to prevent harmful or inappropriate responses
  • Maintaining content safety boundaries that cannot be circumvented through conversation framing

3.3 Service Improvement

  • Analyzing aggregated, anonymized usage patterns to improve our Service
  • Training and improving our AI models (only with explicit consent and using anonymized data)
  • Debugging technical issues and ensuring Service reliability
  • Conducting research to enhance mental health support methodologies (with appropriate ethical oversight)

3.4 Communication

  • Sending essential service communications (account verification, security alerts, policy updates)
  • Providing customer support and responding to inquiries
  • Sending optional wellness reminders (if enabled in your settings)

3.5 Legal Bases for Processing (GDPR)

For users in the European Economic Area (EEA), we process your data under the following legal bases:

  • Contract Performance: Processing necessary to provide our Service to you
  • Legitimate Interests: Service improvement, security, and fraud prevention
  • Consent: For voice data processing, marketing communications, and optional features
  • Legal Obligation: Compliance with applicable laws and regulations
  • Vital Interests: Crisis detection and intervention to protect life

4. Voice and Biometric Data

Special Notice: Voice Data Processing

Ophie is a voice-first application that processes audio data. We take special care with voice data due to its sensitive nature and potential biometric implications.

4.1 How We Process Voice Data

  • Speech-to-Text Conversion: Your voice input is converted to text using third-party speech recognition services (Deepgram) to enable conversation processing
  • Text-to-Speech Response: AI responses are converted to audio using text-to-speech services (Cartesia) for voice output
  • Real-Time Processing: Voice data is processed in real-time via WebRTC (LiveKit) and is not stored in raw audio format after transcription
  • Transcript Storage: Only the text transcription is stored (if in Memory Mode), not the original audio recordings

4.2 Biometric Privacy Compliance

State Biometric Privacy Laws

To comply with state biometric privacy laws, including the Illinois Biometric Information Privacy Act (BIPA) and Texas Capture or Use of Biometric Identifier Act (CUBI), we have implemented the following measures:

  • Geographic Restrictions: Users located in Illinois and Texas are currently unable to access voice features of our Service to ensure compliance with BIPA and CUBI requirements
  • Location Verification: We verify user location via IP geolocation before enabling voice features
  • Explicit Consent: All users must provide explicit, informed consent for voice data processing before using voice features
  • Consent Timestamp: We maintain records of when voice data consent was provided

4.3 Voice Data Consent

Before you can use voice features, you must:

  1. Acknowledge that your voice will be processed by our Service and third-party providers
  2. Consent to the transcription and storage of text derived from your voice input
  3. Understand that voice data processing is essential for the voice-first functionality of our Service

You may withdraw consent at any time by switching to text-only mode in your settings, though this will limit your ability to use voice features.

5. Data Sharing and Third Parties

We share your information only as described below. We do not sell your personal information to third parties.

5.1 Service Providers (Data Processors)

We use the following third-party service providers who process data on our behalf:

Supabase

US/EU

Database hosting, authentication, and storage

Data shared: Account data, session data, transcripts, user preferences

OpenAI

US

Large language model processing for AI conversations

Data shared: Conversation text, system prompts, context

Deepgram

US

Speech-to-text transcription

Data shared: Voice audio streams (real-time, not stored)

Cartesia

US

Text-to-speech voice synthesis

Data shared: AI response text for audio generation

LiveKit

US

WebRTC real-time voice communication

Data shared: Voice/video streams, session identifiers

Groq

US

LLM processing for memory trigger detection

Data shared: Conversation snippets for analysis

ipapi.co

US

IP-based geolocation for biometric compliance

Data shared: IP address only

All service providers are bound by data processing agreements that require them to protect your data and use it only for the purposes we specify.

5.2 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency). This includes:

  • Complying with a legal obligation
  • Protecting and defending our rights or property
  • Preventing or investigating possible wrongdoing in connection with the Service
  • Protecting the personal safety of users of the Service or the public
  • Protecting against legal liability

5.3 Business Transfers

If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our Service before your information is transferred and becomes subject to a different privacy policy.

5.4 Aggregated and Anonymized Data

We may share aggregated, anonymized data that cannot reasonably be used to identify you for research, analytics, or industry benchmarking purposes. This data contains no personally identifiable information.

6. Data Retention

6.1 Retention Periods

Data TypeRetention Period
Account InformationUntil account deletion requested
Session Data (Memory Mode)30 days, then automatically deleted
Session Data (Ephemeral Mode)Not stored beyond the active session
Active SessionsAutomatically ended after 24 hours of inactivity
Therapeutic ProfilesUntil account deletion requested
User GoalsUntil deleted by user or account deletion
Token Usage Logs90 days for billing purposes
Consent Records7 years (legal compliance requirement)

6.2 Privacy Modes

Memory Mode

  • Conversation transcripts are stored
  • Session summaries and key moments preserved
  • AI remembers context across sessions
  • Therapeutic profile builds over time
  • Data retained for 30 days, then deleted

Ephemeral Mode

  • No conversation transcripts stored
  • No session summaries preserved
  • Each session starts fresh
  • Only account data retained
  • Maximum privacy protection

6.3 Automatic Deletion

We have implemented automatic data deletion mechanisms:

  • Sessions older than 24 hours are automatically marked as ended
  • Session data older than 30 days is automatically deleted
  • Upon account deletion, all associated data is removed within 30 days

7. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information. We provide these rights to all users regardless of location.

Right to Access

Request a copy of all personal data we hold about you in a portable, machine-readable format (JSON export).

Right to Rectification

Update or correct inaccurate personal information through your account settings or by contacting us.

Right to Deletion

Request deletion of your personal data. We provide a comprehensive data deletion function with audit trail.

Right to Portability

Export your data including profile, sessions, conversations, messages, and goals in a structured format.

Right to Restrict Processing

Request that we limit how we use your data in certain circumstances.

Right to Object

Object to processing of your data for certain purposes, including direct marketing.

7.1 How to Exercise Your Rights

You can exercise your rights in the following ways:

  • Account Settings: Update your profile, privacy mode, and preferences directly in the app
  • Data Export: Request a complete export of your data through your account settings
  • Account Deletion: Delete your account and all associated data through settings (requires email confirmation)
  • Contact Us: Email founders@ophie.app for any privacy-related requests

7.2 Verification Requirements

To protect your privacy, we may need to verify your identity before processing your request. This may include:

  • Confirming your email address
  • Answering security questions
  • For account deletion: typing your email address to confirm

7.3 Response Timeframes

We will respond to your request within:

  • GDPR (EEA users): 30 days (may be extended by 2 months for complex requests)
  • CCPA/CPRA (California users): 45 days (may be extended by an additional 45 days)
  • All other users: 30 days

8. Data Security

We implement comprehensive security measures to protect your data:

8.1 Technical Safeguards

  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher
  • Encryption at Rest: Data stored in our databases is encrypted using industry-standard encryption
  • Access Controls: Strict role-based access controls limit who can access your data
  • Row-Level Security: Database policies ensure users can only access their own data
  • Secure Authentication: Multi-factor authentication available, secure password hashing

8.2 Organizational Measures

  • Regular security audits and penetration testing
  • Employee security training and background checks
  • Incident response procedures
  • Data access logging and monitoring
  • Vendor security assessments

8.3 Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify affected users within 72 hours of becoming aware of the breach
  • Report to relevant supervisory authorities as required by law
  • Provide information about the nature of the breach and steps being taken
  • Offer guidance on protective measures you can take

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country.

9.1 Transfer Mechanisms

When we transfer personal data outside the European Economic Area (EEA) or other jurisdictions with data transfer restrictions, we use the following safeguards:

  • Standard Contractual Clauses (SCCs): EU-approved contractual terms with our service providers
  • Adequacy Decisions: Transfers to countries deemed adequate by the European Commission
  • Supplementary Measures: Additional technical and organizational safeguards where necessary

9.2 Data Processing Locations

Our primary data processing occurs in the United States. Your data may also be processed in the European Union depending on the services used and your location.

10. Children's Privacy

Age Restriction

Our Service is intended for users 18 years of age and older. We do not knowingly collect personal information from children under 18. If you are under 18, please do not use our Service or provide any information to us.

If we learn that we have collected personal information from a child under 18, we will take steps to delete that information as quickly as possible. If you believe we may have collected information from a child under 18, please contact us at founders@ophie.app.

10.1 COPPA Compliance

We comply with the Children's Online Privacy Protection Act (COPPA) by:

  • Requiring age verification during account creation (users must select an age range of 18+)
  • Not knowingly collecting data from users under 18
  • Promptly deleting any data we discover was provided by a minor

11. Cookies and Similar Technologies

11.1 What We Use

We use the following technologies to collect information about your use of our Service:

  • Essential Cookies: Required for authentication and core functionality
  • Session Storage: Temporary storage for active session data
  • Local Storage: Storing user preferences and settings locally

11.2 Cookie Categories

CategoryPurposeRequired
Strictly NecessaryAuthentication, security, basic functionalityYes
FunctionalRemembering preferences and settingsNo (optional)
AnalyticsUnderstanding how users interact with our ServiceNo (optional)

11.3 Managing Cookies

You can control cookies through:

  • Your browser settings (blocking or deleting cookies)
  • Our cookie consent banner (where applicable)
  • Note: Disabling essential cookies may prevent you from using our Service

12. Automated Decision-Making and AI Processing

12.1 How We Use AI

Ophie uses artificial intelligence to:

  • Process and respond to your voice and text inputs
  • Generate personalized conversation responses
  • Analyze sentiment and emotional patterns (with your consent)
  • Detect potential crisis situations for safety purposes
  • Generate session summaries and key moments
  • Recommend therapeutic techniques based on effectiveness

12.2 Profiling

We engage in profiling to personalize your experience:

  • Building a therapeutic profile based on your conversations
  • Learning your communication preferences over time
  • Tracking which techniques work best for you
  • Remembering relationships and facts you share

This profiling is designed to improve your experience and is not used for any decisions that have legal or similarly significant effects on you.

12.3 Your Rights Regarding AI Decisions

You have the right to:

  • Request human review of any AI-generated content or decisions
  • Opt out of automated profiling (by using Ephemeral Mode)
  • Request information about the logic involved in AI processing
  • Delete your therapeutic profile and learned preferences

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

  • Posting the new Privacy Policy on this page with an updated "Last Updated" date
  • Sending an email notification for material changes (to the email address associated with your account)
  • Displaying a prominent notice within the Service

You are advised to review this Privacy Policy periodically for any changes. Changes are effective when they are posted on this page. Your continued use of the Service after any changes indicates your acceptance of the modified Privacy Policy.

14. Contact Us

If you have any questions about this Privacy Policy or our privacy practices, please contact us:

Email

founders@ophie.app

Data Protection Officer

founders@ophie.app

Mailing Address

Ophie
founders@ophie.app

14.1 EU Representative

For users in the European Union, our EU representative can be contacted at:

If we expand our services to the European Union, we will appoint an EU representative pursuant to Article 27 of the GDPR and update this section accordingly. Please contact founders@ophie.app for any inquiries.

14.2 Supervisory Authority

If you are in the EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local supervisory authority.

15. Jurisdiction-Specific Disclosures

15.1 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to Know: What personal information we collect, use, disclose, and sell
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: We do not sell personal information, so this right does not apply
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Limit Use of Sensitive Personal Information: Limit use of sensitive information to providing the Service

Categories of Personal Information Collected: Identifiers, personal information under Cal. Civ. Code 1798.80, protected characteristics (age), internet activity, geolocation data, audio information, professional information, inferences drawn from the above.

Sensitive Personal Information: We collect mental health information and voice recordings, which are considered sensitive under CPRA. This data is used only to provide our Service and is not sold or shared for cross-context behavioral advertising.

15.2 European Union Residents (GDPR)

If you are in the European Economic Area, you have rights under the General Data Protection Regulation (GDPR) as described in Section 7. Additionally:

  • Data Controller: Ophie is the data controller for your personal data
  • Legal Basis: We process your data based on consent, contract performance, legitimate interests, or legal obligation as described in Section 3.5
  • Special Category Data: Mental health information is processed based on your explicit consent

15.3 Brazilian Residents (LGPD)

If you are in Brazil, you have rights under the Lei Geral de Protecao de Dados (LGPD) including:

  • Confirmation of data processing
  • Access to your data
  • Correction of incomplete or inaccurate data
  • Anonymization, blocking, or elimination of unnecessary data
  • Data portability
  • Information about sharing with third parties
  • Revocation of consent

15.4 Canadian Residents (PIPEDA)

If you are in Canada, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). You have the right to:

  • Access your personal information
  • Challenge the accuracy of your information
  • Withdraw consent (subject to legal restrictions)
  • File a complaint with the Privacy Commissioner of Canada

15.5 Do Not Track Signals

Our Service does not currently respond to "Do Not Track" (DNT) signals. We will update this policy if we implement DNT response in the future.

Legal Disclaimer

This Privacy Policy is a template for informational purposes only. Consult with a qualified attorney for legal advice specific to your situation. Ophie recommends having this document reviewed by legal counsel before implementation to ensure compliance with all applicable laws and regulations in your jurisdiction.