Your privacy and the security of your mental health conversations are our highest priorities. This policy explains how we collect, use, and protect your information.
Last Updated: January 18, 2025
Effective Date: January 18, 2025
This privacy policy is a template for informational purposes only. It should be reviewed and customized by a qualified attorney to ensure compliance with all applicable laws and regulations specific to your jurisdiction and business operations. Ophie makes no representations or warranties regarding the legal sufficiency of this document.
Welcome to Ophie, a voice-first AI mental health companion operated by Ophie ("Ophie," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application, mobile applications, and related services (collectively, the "Service").
We understand that the information you share with Ophie is deeply personal and sensitive. Mental health conversations require the highest level of trust and confidentiality. We have designed our Service with privacy as a foundational principle, not an afterthought.
By accessing or using our Service, you agree to this Privacy Policy. If you do not agree with our policies and practices, do not use our Service.
We collect information in several ways: directly from you, automatically through your use of the Service, and from third-party sources. Below is a comprehensive list of the information we may collect.
When you use Ophie, we process the content of your conversations to provide our Service. The extent of data storage depends on your selected privacy mode:
To provide personalized mental health support, we may collect and analyze the following sensitive information:
We use the information we collect for the following purposes:
For users in the European Economic Area (EEA), we process your data under the following legal bases:
Ophie is a voice-first application that processes audio data. We take special care with voice data due to its sensitive nature and potential biometric implications.
To comply with state biometric privacy laws, including the Illinois Biometric Information Privacy Act (BIPA) and Texas Capture or Use of Biometric Identifier Act (CUBI), we have implemented the following measures:
Before you can use voice features, you must:
You may withdraw consent at any time by switching to text-only mode in your settings, though this will limit your ability to use voice features.
We share your information only as described below. We do not sell your personal information to third parties.
We use the following third-party service providers who process data on our behalf:
Database hosting, authentication, and storage
Data shared: Account data, session data, transcripts, user preferences
Large language model processing for AI conversations
Data shared: Conversation text, system prompts, context
Speech-to-text transcription
Data shared: Voice audio streams (real-time, not stored)
Text-to-speech voice synthesis
Data shared: AI response text for audio generation
WebRTC real-time voice communication
Data shared: Voice/video streams, session identifiers
LLM processing for memory trigger detection
Data shared: Conversation snippets for analysis
IP-based geolocation for biometric compliance
Data shared: IP address only
All service providers are bound by data processing agreements that require them to protect your data and use it only for the purposes we specify.
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency). This includes:
If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our Service before your information is transferred and becomes subject to a different privacy policy.
We may share aggregated, anonymized data that cannot reasonably be used to identify you for research, analytics, or industry benchmarking purposes. This data contains no personally identifiable information.
| Data Type | Retention Period |
|---|---|
| Account Information | Until account deletion requested |
| Session Data (Memory Mode) | 30 days, then automatically deleted |
| Session Data (Ephemeral Mode) | Not stored beyond the active session |
| Active Sessions | Automatically ended after 24 hours of inactivity |
| Therapeutic Profiles | Until account deletion requested |
| User Goals | Until deleted by user or account deletion |
| Token Usage Logs | 90 days for billing purposes |
| Consent Records | 7 years (legal compliance requirement) |
We have implemented automatic data deletion mechanisms:
Depending on your location, you may have certain rights regarding your personal information. We provide these rights to all users regardless of location.
Request a copy of all personal data we hold about you in a portable, machine-readable format (JSON export).
Update or correct inaccurate personal information through your account settings or by contacting us.
Request deletion of your personal data. We provide a comprehensive data deletion function with audit trail.
Export your data including profile, sessions, conversations, messages, and goals in a structured format.
Request that we limit how we use your data in certain circumstances.
Object to processing of your data for certain purposes, including direct marketing.
You can exercise your rights in the following ways:
To protect your privacy, we may need to verify your identity before processing your request. This may include:
We will respond to your request within:
We implement comprehensive security measures to protect your data:
In the event of a data breach that poses a risk to your rights and freedoms, we will:
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country.
When we transfer personal data outside the European Economic Area (EEA) or other jurisdictions with data transfer restrictions, we use the following safeguards:
Our primary data processing occurs in the United States. Your data may also be processed in the European Union depending on the services used and your location.
Our Service is intended for users 18 years of age and older. We do not knowingly collect personal information from children under 18. If you are under 18, please do not use our Service or provide any information to us.
If we learn that we have collected personal information from a child under 18, we will take steps to delete that information as quickly as possible. If you believe we may have collected information from a child under 18, please contact us at founders@ophie.app.
We comply with the Children's Online Privacy Protection Act (COPPA) by:
Ophie uses artificial intelligence to:
We engage in profiling to personalize your experience:
This profiling is designed to improve your experience and is not used for any decisions that have legal or similarly significant effects on you.
You have the right to:
We may update this Privacy Policy from time to time. We will notify you of any changes by:
You are advised to review this Privacy Policy periodically for any changes. Changes are effective when they are posted on this page. Your continued use of the Service after any changes indicates your acceptance of the modified Privacy Policy.
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
founders@ophie.app
Data Protection Officer
founders@ophie.app
Mailing Address
Ophie
founders@ophie.app
For users in the European Union, our EU representative can be contacted at:
If we expand our services to the European Union, we will appoint an EU representative pursuant to Article 27 of the GDPR and update this section accordingly. Please contact founders@ophie.app for any inquiries.
If you are in the EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local supervisory authority.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Categories of Personal Information Collected: Identifiers, personal information under Cal. Civ. Code 1798.80, protected characteristics (age), internet activity, geolocation data, audio information, professional information, inferences drawn from the above.
Sensitive Personal Information: We collect mental health information and voice recordings, which are considered sensitive under CPRA. This data is used only to provide our Service and is not sold or shared for cross-context behavioral advertising.
If you are in the European Economic Area, you have rights under the General Data Protection Regulation (GDPR) as described in Section 7. Additionally:
If you are in Brazil, you have rights under the Lei Geral de Protecao de Dados (LGPD) including:
If you are in Canada, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). You have the right to:
Our Service does not currently respond to "Do Not Track" (DNT) signals. We will update this policy if we implement DNT response in the future.
This Privacy Policy is a template for informational purposes only. Consult with a qualified attorney for legal advice specific to your situation. Ophie recommends having this document reviewed by legal counsel before implementation to ensure compliance with all applicable laws and regulations in your jurisdiction.