Back to app

Privacy Policy

Last updated: August 3, 2026

Internalcalm collects sensitive mental health and wellness data. This policy explains what we collect, how we use it, and the controls you have — including the ability to delete everything at any time.

Table of Contents

1. Overview & Effective Date

This Privacy Policy describes how Internalcalm (“Internalcalm,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal information — including sensitive mental health and wellness data — when you use the Internalcalm application, website, and related services (collectively, the “Service”).

We understand that the information you share with Internalcalm — journal entries, mood check-ins, self-care logs, and conversations with the AI companion — is deeply personal. Protecting your privacy is central to our mission. This policy explains in plain language what we collect, why, and the choices you have.

This Privacy Policy is effective as of the “Last updated” date above and applies to all users. By using the Service, you consent to the practices described here.

2. Data Safety — App Privacy Nutrition Label

The table below mirrors Apple's App Privacy Nutrition Label and declares the categories of data Internalcalm collects, whether each is linked to your identity, and the purpose for which it is used.

“Linked to Identity” means the data is associated with your account. “Not Linked” means the data is stored under a pseudonymous identifier and is not directly tied to your account identity.

Health & Fitness

Mood entries & emotional check-insLinked to IdentityApp Functionality
Journal entries & gratitude logsLinked to IdentityApp Functionality
Self-care & sleep logsLinked to IdentityApp Functionality

Identifiers

User ID (account)Linked to IdentityApp Functionality
Pseudonymous journal IDNot LinkedApp Functionality

Usage Data

Exercise & skills practice logsLinked to IdentityApp Functionality
Progress & insights summariesLinked to IdentityApp Functionality

Contact Info

Email (account & subscription)Linked to IdentityAccount, Billing

Financial Info

Payment method (via Stripe)Linked to IdentityBilling

Audio Data

Voice input (AI companion, optional)Not LinkedApp Functionality

User Content

Feedback & feature requestsLinked to IdentityApp Functionality

Our Data Practices

Encryption in transit

All data is transmitted over encrypted (HTTPS/TLS) connections.

Pseudonymous journaling

Journal entries are tagged with a pseudonymous identifier alongside your account, providing an extra layer of separation for your private reflections.

No data selling

We do not sell your personal or emotional data to third parties.

Delete anytime

You can permanently delete your account and all associated data from within the app at any time.

No third-party tracking

We do not use third-party ad networks or behavioral tracking SDKs. Only first-party operational analytics may be collected to maintain and improve the Service.

Stored securely

Health and wellness data is stored using industry-standard security measures.

3. Information We Collect

We collect the following categories of information:

  • Account information: email address and authentication credentials when you create an account. Passwords are hashed and never stored in plain text.
  • Emotional & wellness data: journal entries, gratitude logs, mood check-ins and scores, self-care logs, sleep logs, and exercise/skills practice logs that you voluntarily enter. These records are linked to your account so you can access your personal history; journal entries also carry a pseudonymous identifier.
  • AI companion conversations: text and optional voice input you send to the AI companion, along with the responses generated.
  • Feedback & suggestions: feedback, feature requests, and improvement ideas you submit through the in-app feedback forum, linked to your account.
  • Usage data: which features you use, exercise completion, and progress summaries derived from your activity. The platform infrastructure may also collect basic first-party operational analytics (such as page views and API call metrics) to provide and maintain the Service; we do not use third-party ad networks or behavioral tracking SDKs.
  • Payment information: subscription billing is processed by Stripe. We do not store your full card number — Stripe handles payment data securely.
  • Device & technical data: limited device type and operating system information needed to provide and maintain the Service.

We do not collect data from third parties, and we do not use third-party advertising or behavioral tracking networks.

4. How We Use Your Information

We use your information solely to provide, operate, maintain, and improve the Service for you, including:

  • Storing and displaying your journal entries, mood history, self-care logs, and progress so you can review them.
  • Generating AI companion responses to your messages.
  • Creating progress insights, weekly and monthly summaries, and trend visualizations from your own data.
  • Managing your account, authentication, and subscription billing.
  • Detecting potential crisis language so we can surface emergency resources — we do not use this to diagnose or share your data.
  • Improving the Service, fixing bugs, and developing new features in aggregate, de-identified form.

We do not use your personal or emotional data to build advertising profiles, and we do not sell your data to third parties.

5. Sensitive Health & Emotional Data

Mood entries, journal content, and self-care logs constitute sensitive mental health and wellness information. We apply heightened protections to this data:

  • Journal entries are tagged with a pseudonymous identifier alongside your account, providing an additional layer of separation for your private reflections.
  • Emotional data is used only to provide the features you interact with — never sold, never shared for advertising.
  • You can delete individual entries or your entire account and all associated data at any time from within the app.

Because this data is sensitive, we encourage you to review this policy carefully and only enter information you are comfortable storing.

7. How We Share Your Information

We do not sell your personal data. We share information only as described here:

  • Service providers: we use Stripe for payment processing and cloud infrastructure providers for data storage. These providers process data on our behalf under contractual obligations and do not use it for their own purposes.
  • AI providers: messages you send to the AI companion are processed by our AI model provider to generate responses. We do not use your conversations to train third-party models.
  • Legal requirements: we may disclose information if required by law, court order, or to protect the safety of you or others, including crisis situations where emergency services may be engaged.

We do not share your emotional or wellness data with advertisers, data brokers, or social networks.

8. AI Services & Data Processing

Internalcalm uses artificial intelligence to power the AI companion feature. When you send messages, voice input, or journal prompts to the AI companion, the content of your input — including any emotional or wellness information you choose to share — is transmitted to our third-party AI model provider to generate a response.

The following data may be sent to AI services when you use the AI companion:

  • Text messages and conversation history you submit to the AI companion.
  • Optional voice input (audio data) when you use voice mode, which is transcribed and processed.
  • Context such as your selected therapist persona and language preference, used to tailor the conversation.
  • Any personal or emotional details you voluntarily include in your messages.

We take the following measures to protect your data when using AI services:

  • Your AI conversations are transmitted over encrypted (HTTPS/TLS) connections.
  • We do not use your conversations, journal entries, or personal data to train third-party AI models.
  • Our AI provider processes data on our behalf under contractual obligations and is prohibited from using your data for its own purposes.
  • AI conversation data is retained only as needed to provide the feature and is deleted in accordance with our retention policy when you delete your account.

The AI companion is not a medical device and does not provide diagnosis or treatment. Any responses generated are for informational and supportive purposes only. If you are in crisis, please contact emergency services or a crisis helpline immediately.

9. Data Storage & Security

Your data is stored securely using industry-standard measures. All data is transmitted over encrypted (HTTPS/TLS) connections. Access to personal data is restricted to authorized personnel who need it to operate the Service.

File uploads (journal attachments, profile photos) and downloads are transmitted over HTTPS using time-limited signed URLs, and files are encrypted at rest using AWS KMS server-side encryption (SSE-KMS) in HIPAA-eligible S3 buckets.

No method of transmission or storage is completely secure, but we work to protect your information using reasonable technical and organizational safeguards.

Journal attachments are stored in encrypted object storage (HIPAA-eligible AWS S3 buckets) when applicable.

10. Data Retention & Deletion

We retain your data for as long as your account is active or as needed to provide the Service. You can delete individual journal entries, mood logs, and other records at any time from within the app.

You can permanently delete your account and all associated data — including journal entries, mood history, self-care logs, sleep logs, and exercise logs — at any time from the Home screen using the “Delete account” button. Deletion is irreversible.

After deletion, residual copies may exist in secure backups for a limited time before being permanently removed.

11. Your Privacy Rights

Depending on your location, you may have rights under privacy laws such as the CCPA (California), GDPR (EU/UK), or other local regulations. These rights may include:

  • Access: request a copy of the personal data we hold about you.
  • Deletion: request that we delete your personal data (you can also do this instantly in-app).
  • Correction: request that we correct inaccurate or incomplete data.
  • Opt-out: object to certain processing or withdraw consent.
  • Portability: request your data in a structured, machine-readable format.

To exercise these rights, contact Internalcalm support through the app. We will respond within the timeframe required by applicable law.

12. Children's Privacy

This Service is intended for users 13 years of age or older. The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 in accordance with COPPA. If we learn we have collected such information, we will delete it promptly.

Teens aged 13–17 may use the Service with parental consent as described in our Terms & Conditions. Parents may manage, restrict, or delete a Teen's account at any time.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the “Last updated” date and, for material changes, provide notice within the Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy or how your data is handled, contact Internalcalm support through the app's Contact page.

View our Terms & Conditions →

© 2026 Internalcalm. This Privacy Policy is provided for informational purposes and does not constitute legal advice.