Last Updated: February 12, 2026
1. Introduction
InnerHeal ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how your personal information is collected, used, and disclosed when you use our mobile application and website (collectively, the "Service").
We understand that your mental wellness journey is deeply personal. That's why we've designed InnerHeal with privacy as a core principle. This policy is meant to help you understand what information we collect, why we collect it, and how you can update, manage, export, and delete your information.
By using InnerHeal, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our Service.
2. Information We Collect
2.1 Information You Provide Directly
Account Information:
• Name (or display name you choose)
• Email address
• Date of birth (to verify age eligibility)
• Profile picture (optional)
• Password (encrypted, if using email registration)
Wellness Data You Enter:
• Mood entries and emotional states you log
• Journal entries and personal reflections
• Sleep duration and quality logs
• Water intake and hydration tracking
• Responses to quizzes and self-assessments
• Goals and wellness objectives you set
• Breathing exercise completion records
• Daily check-in responses
Communication Data:
• Messages you send through AI chat features
• Community posts and comments (if you use community features)
• Support requests and feedback you submit
2.2 Information Collected Automatically
Device Information:
• Device type, model, and manufacturer
• Operating system and version
• Unique device identifiers (for app functionality, not advertising)
• App version installed
• Language and timezone settings
Usage Information:
• Features you use and how often
• Time spent in the app
• Navigation patterns within the app
• Crash logs and performance data
• Error reports for troubleshooting
Technical Information:
• IP address (used for security and approximate location for timezone)
• Browser type (for web access)
• Push notification tokens (if notifications enabled)
2.3 Information from Third-Party Authentication
If you choose to sign in using:
Sign in with Apple:
• Apple User ID (unique identifier)
• Email address (or Apple's private relay email if you choose to hide your email)
• Name (only if you choose to share it)
Sign in with Google:
• Google User ID (unique identifier)
• Email address
• Name
• Profile picture (if available)
We only receive information you authorize these services to share. We do not have access to your passwords for these services.
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 To Provide and Improve the Service
• Create and manage your account
• Deliver personalized wellness insights based on your mood and journal data
• Generate AI-powered recommendations and chat responses
• Track your progress and display wellness trends
• Send reminders for hydration, mood logging, and other features you enable
• Improve app functionality and fix bugs
• Develop new features based on usage patterns
3.2 To Communicate With You
• Send important service announcements
• Respond to your support requests
• Deliver daily affirmations and quotes (if enabled)
• Notify you of significant changes to our Terms or Privacy Policy
3.3 To Ensure Safety and Security
• Detect and prevent fraud or abuse
• Verify user identity and age eligibility
• Monitor for violations of our Terms of Service
• Protect the security of our users and Service
3.4 For Analytics and Research
• Understand how users interact with our features
• Measure the effectiveness of wellness tools
• Conduct aggregated, anonymized research on wellness trends
• Improve our AI models using anonymized data patterns
3.5 Third-Party AI Processing (Google Gemini)
To power InnerHeal's core AI features - including AI Chat, Mood Analysis, Journal Insights, and Personalized Recommendations - certain user data is sent to Google's Gemini AI service (provided by Google LLC).
Specifically:
• Chat messages you send are processed by Google Gemini to generate AI responses
• Mood entries and emotional context are processed to generate personalized insights
• Journal entry context is processed to generate reflection prompts
• Wellness preferences are processed to generate recommendations
Google does not receive your name, email, password, payment information, or device identifiers. We obtain your explicit consent before sharing any data with Google Gemini.
Important: We do NOT use your information for:
• Advertising or marketing by third parties
• Tracking you across other apps or websites
• Selling to data brokers
• Building advertising profiles
4. How We Share Your Information
4.1 We Do NOT Sell Your Data
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. Period.
4.2 Service Providers
We share limited data with trusted service providers who help us operate the Service:
• Cloud Hosting - Store and secure your data (Encrypted account and wellness data)
• Authentication - Verify your identity (Authentication tokens only)
• Analytics - Understand app usage (Anonymized usage patterns)
• Crash Reporting - Fix bugs and improve stability (Device info, crash logs - no personal content)
• AI Processing (Google Gemini, provided by Google LLC) - Power AI chat, mood analysis, journal insights, and personalized recommendations (Chat messages, mood entries, journal context, and wellness preferences are sent to Google's Gemini AI API to generate responses and insights. Your name, email, payment info, and device identifiers are NOT sent.)
Before any data is shared with Google Gemini, we obtain your explicit consent within the app. You can manage your AI data consent at any time in Settings > Security & Privacy > AI Data Consent. Revoking consent will disable AI-powered features but won't affect other app functionality.
All service providers are contractually bound to:
• Use your data only for the specific purpose we've engaged them
• Maintain strict confidentiality
• Implement appropriate security measures
• Delete data when no longer needed
4.3 Legal Requirements
We may disclose your information if required by law, such as:
• To comply with a valid legal process (subpoena, court order)
• To protect the rights, property, or safety of InnerHeal, our users, or others
• To enforce our Terms of Service
• In connection with a merger, acquisition, or sale of assets (with notice to you)
4.4 With Your Consent
We may share your information in other circumstances with your explicit consent, such as:
• When you choose to export your data
• When you share content publicly in community features
• When you connect third-party services you authorize
5. Data Security
We implement industry-standard security measures to protect your data:
5.1 Encryption
• In Transit: All data transmitted between your device and our servers is encrypted using TLS 1.3
• At Rest: Sensitive data including journal entries, mood logs, and personal information is encrypted using AES-256 encryption
• Passwords: Stored using bcrypt hashing (we cannot see your password)
5.2 Access Controls
• Strict access controls limit who can access user data
• Employees access data only on a need-to-know basis
• All access is logged and monitored
• Multi-factor authentication required for administrative access
5.3 Infrastructure Security
• Data hosted on secure, SOC 2 compliant cloud infrastructure
• Regular security audits and penetration testing
• Automated threat detection and monitoring
• Regular backups with encryption
5.4 Your Journal Privacy
Your journal entries are especially sensitive. We take extra precautions:
• Entries are encrypted with keys unique to your account
• AI processing is done without storing identifiable content
• Even our employees cannot read your journal entries
6. Your Rights and Choices
You have control over your personal information:
6.1 Access and Portability
• View all your data within the app's settings
• Request a complete export of your data in a portable format
• Download your journal entries, mood history, and other records
6.2 Correction
• Update your profile information at any time
• Edit or delete individual journal entries
• Correct mood logs and other wellness data
6.3 Deletion
• Delete individual entries (journals, mood logs, etc.)
• Delete your entire account and all associated data
• Upon account deletion, your data is permanently removed within 30 days
• Some anonymized, aggregated data may be retained for research
6.4 Communication Preferences
• Enable or disable push notifications
• Choose which types of reminders you receive
• Opt out of non-essential emails
6.5 Analytics Opt-Out
• Disable analytics data collection in app settings
• This does not affect core app functionality
To exercise these rights, go to Settings > Privacy in the app, or contact us at support@innerheal.app.
7. Data Retention
We retain your personal information for as long as:
• Your account remains active
• Needed to provide you with our services
• Required to comply with legal obligations
• Necessary to resolve disputes and enforce agreements
Specific Retention Periods:
• Account data: Until you delete your account
• Wellness data (moods, journals): Until you delete them or your account
• Usage analytics: 24 months (anonymized)
• Crash logs: 90 days
• Support communications: 3 years
After account deletion:
• Personal data is deleted within 30 days
• Backups are purged within 90 days
• Anonymized, aggregated data may be retained indefinitely
8. Children's Privacy
InnerHeal is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@innerheal.app. We will take steps to delete such information promptly.
Users between 13-17 should use the app under parental guidance. We recommend parents review this Privacy Policy with their teenagers.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws.
When we transfer data internationally, we ensure appropriate safeguards are in place:
• Standard Contractual Clauses approved by relevant authorities
• Data processing agreements with all service providers
• Compliance with applicable data protection regulations
10. Third-Party Links and Services
Our Service may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those third parties. We encourage you to review their privacy policies.
Third-party services we integrate with include:
• Apple (for Sign in with Apple)
• Google (for Sign in with Google)
• Payment processors (through app stores)
11. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights:
• Right to Know: Request information about data we've collected
• Right to Delete: Request deletion of your personal information
• Right to Opt-Out: We do not sell personal information
• Right to Non-Discrimination: We will not discriminate against you for exercising your rights
To exercise these rights, contact us at support@innerheal.app or use the in-app settings.
12. European Privacy Rights (GDPR)
If you are in the European Economic Area, you have rights under GDPR:
• Lawful Basis: We process data based on your consent and legitimate interests
• Right of Access: Obtain a copy of your personal data
• Right to Rectification: Correct inaccurate data
• Right to Erasure: Request deletion of your data
• Right to Restrict Processing: Limit how we use your data
• Right to Data Portability: Receive your data in a portable format
• Right to Object: Object to certain processing activities
• Right to Withdraw Consent: Withdraw consent at any time
To exercise these rights, contact us at support@innerheal.app.
13. App Tracking Transparency (iOS)
InnerHeal does NOT track you across apps and websites owned by other companies for advertising purposes. We do not use Apple's IDFA (Identifier for Advertisers) or participate in ad tracking.
If iOS prompts you about tracking, you can safely deny permission as we do not engage in such tracking.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When we make significant changes:
• We will notify you through the app or email
• We will update the "Last Updated" date at the top
• We may ask for your consent if required by law
Your continued use of the Service after changes become effective constitutes acceptance of the revised Privacy Policy.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: support@innerheal.app
Mailing Address:
InnerHeal
Opticks Tech
India
We aim to respond to all inquiries within 30 days.