⚠️ DRAFT TEMPLATE — NOT LEGAL ADVICE. This document is a first-pass template prepared for internal use only. It has not been reviewed by a licensed attorney and does not constitute legal advice. Every factual and legal statement below — including all descriptions of data flows, processors, retention practices, and security controls — must be independently verified by qualified engineering and legal personnel and finalized by a licensed attorney admitted in the applicable jurisdiction before publication. All [BRACKETED PLACEHOLDERS] must be completed. Delete this notice before publishing only on the advice of counsel.
Privacy Policy for Talk Therapy AI
Effective Date: [EFFECTIVE DATE] Last Updated: [LAST UPDATED DATE]
This Privacy Policy explains how [COMPANY LEGAL ENTITY NAME] ("Company," "we," "us," or "our") collects, uses, discloses, and protects information when you use Talk Therapy AI, our general-wellness web application available at talktherapy.ai (the "Service"), including our AI companion "Aria."
Please read this Policy together with our [TERMS OF SERVICE / TERMS OF USE — LINK]. By using the Service, you acknowledge that you have read and understood this Policy.
1. Important Notice About What Talk Therapy AI Is
Talk Therapy AI is a general-wellness and self-reflection tool. It is NOT therapy, counseling, medical care, or mental-health treatment, and it is NOT a medical device.
- Aria is an artificial-intelligence companion — not a human, and not a licensed therapist, counselor, physician, or other professional. Using the Service creates no therapist-client, doctor-patient, or other professional relationship.
- Aria does not diagnose, treat, or cure any condition and does not give medical or medication advice.
- The Service is not a substitute for professional care. Please consult a qualified professional for any medical or mental-health needs.
- The Service is NOT a crisis or emergency service. It cannot and does not monitor for emergencies, intervene, or dispatch help. If you or someone else may be in danger or crisis, call 911 or contact the 988 Suicide & Crisis Lifeline (call or text 988) immediately.
We describe this here because it affects how your information is handled: we cannot and do not act on the contents of your conversations to intervene in an emergency. See Section 9 (Sensitive Information and Limits of Confidentiality).
2. Who This Policy Applies To — Adults Only, U.S. Only
- You must be 18 years of age or older to use the Service. The Service is intended solely for adults.
- The Service is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided us information, please contact us at [CONTACT EMAIL] and we will take reasonable steps to delete it. See Section 10 (No Users Under 18).
- The Service is currently offered only to users located in the United States. It is not intended for use outside the United States, and we make no representation that the Service is appropriate or available for use in other locations. See Section 14 (U.S.-Only; International Users).
3. Information We Collect
We collect the following categories of information.
3.1 Information You Provide to Us
- Account email address. Used to create and secure your account, authenticate you, and communicate with you about the Service.
- Date of birth. Collected for the purpose of age verification — to confirm you are 18 or older. [CONFIRM whether full date of birth is stored, or only a derived "18+" flag / age. Minimizing to a boolean or age is a recommended practice — verify actual implementation.]
- Conversation content. The messages, prompts, reflections, and other text you send to Aria, and Aria's responses. This may include sensitive information you choose to share. See Section 9.
- Communications and support requests. Information you provide when you contact us, request support, or respond to surveys. [CONFIRM which channels exist.]
3.2 Information Collected Automatically (Technical & Usage Data)
- Device and technical data, such as IP address, browser type, operating system, and device identifiers. [CONFIRM exact fields collected.]
- Usage data, such as pages viewed, features used, session timestamps, and interactions with the Service. [CONFIRM.]
- Log data, such as diagnostic and error logs generated when you use the Service. [CONFIRM retention and content of logs — logs must not inadvertently store conversation content unless intended.]
3.3 Cookies and Similar Technologies
We use cookies and similar technologies as needed to operate, secure, and understand use of the Service. [COOKIES / ANALYTICS PLACEHOLDER — Engineering and legal must confirm exactly which cookies and analytics providers (if any) are used, their purposes (strictly necessary, functional, analytics), retention periods, and whether any third-party analytics or advertising SDKs are present. If analytics are used, name the provider(s) here and describe opt-out mechanisms. Insert a cookie table and, if required, a link to a Cookie Policy or cookie-consent tool.] See Section 15.
4. How We Use Your Information
We use the information above for the following purposes:
- To provide the Service — to operate your account, authenticate you, and enable your conversations with Aria. Your conversation content is processed to generate Aria's responses (see Section 6).
- To verify eligibility — to confirm that you are 18 or older.
- To maintain, improve, and develop the Service — including debugging, measuring performance, understanding usage, and improving the quality and safety of the Service. [CONFIRM the scope of any human review of conversation content used for improvement, and describe it accurately — e.g., whether content is de-identified, who may access it, and whether you offer an opt-out.]
- For safety and integrity — to detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms, and to enforce our agreements.
- For security — to protect the Service, our users, and our systems.
- To communicate with you — to send service-related messages (e.g., account, security, and transactional notices) and, where permitted, other communications you can opt out of. [CONFIRM marketing practices, if any.]
- To comply with law — to meet legal obligations and respond to lawful requests. See Section 9 and Section 7.
We do not use your information for purposes incompatible with those described here without providing notice or, where required, obtaining your consent.
5. Legal Bases and Purposes for Processing
Depending on the framework that applies to you, we rely on the following bases/purposes for processing:
- Performance of a contract — to provide the Service you request under our Terms.
- Our legitimate interests — to secure, maintain, improve, and develop the Service, and to prevent fraud and abuse, in ways that do not override your rights.
- Your consent — where we ask for it (for example, certain cookies/analytics or optional communications). You may withdraw consent at any time where processing is based on consent.
- Compliance with legal obligations — where processing is necessary to comply with applicable law.
[Legal to confirm which frameworks apply for a U.S.-only launch and adjust this section accordingly. The bases above are drafted in a portable style; U.S. state-privacy-law framing (purpose-based) may be used in place of the EU-style "legal bases" language where appropriate.]
6. How Conversations Are Processed — Service Providers and Sub-Processors
To generate Aria's responses and operate the Service, we use trusted service providers (also called processors and sub-processors) who process information on our behalf and under contract.
- Amazon Web Services (AWS) — cloud infrastructure hosting for the Service (compute, storage, networking, and related services).
- Amazon Bedrock — the AWS managed service through which we access the underlying AI model(s) used to power Aria.
When you send a message to Aria, your conversation content is transmitted to and processed by Amazon Bedrock in order to generate Aria's response. This processing is necessary to provide the core functionality of the Service.
[Engineering and legal must confirm and complete: (a) the full list of service providers and sub-processors, including any analytics, email/communications, error-monitoring, authentication, or customer-support vendors; (b) the AWS region(s) in which data is processed and stored; (c) the specific underlying model provider and model(s) accessed via Bedrock; and (d) that the contractual terms with each provider match the commitments in Section 7 (no sale, no third-party ad targeting, no third-party foundation-model training). Consider publishing or linking a maintained sub-processor list.]
7. What We Do NOT Do With Your Data
We want to be clear and direct about limits on how your information is used. Subject to engineering confirmation of each statement below:
- We do NOT sell your personal information.
- We do NOT use your information for third-party advertising or ad targeting, and we do not share your conversation content with advertisers.
- We do NOT use your conversations to train third-party foundation models. Your conversation content is used to provide the Service to you and is processed via AWS / Amazon Bedrock for that purpose; it is not made available to third parties to train their foundation models. [CONFIRM this reflects your contractual arrangements with AWS/Amazon Bedrock and the underlying model provider, and confirm your own internal use of conversation data for "improving the Service" in Section 4, so the two sections are consistent.]
[IMPORTANT — each claim in this Section is a factual representation that engineering and legal MUST verify against actual contracts and configurations before publishing. Do not publish any statement here that cannot be substantiated.]
8. How We Share Information
We share information only as described in this Policy, including:
- With service providers and sub-processors who process information on our behalf to operate, secure, and improve the Service (see Section 6), under contracts that restrict their use of the information.
- For legal reasons — to comply with applicable law, regulation, legal process, or enforceable governmental request; to enforce our Terms; or to protect the rights, property, or safety of the Company, our users, or others (see Section 9).
- In a business transfer — in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate protections and notice where required.
- With your direction or consent — when you ask us to share information or otherwise consent.
We do not share your information with third parties for their own independent purposes except as described here. See also Section 7.
9. Sensitive Information and the Limits of Confidentiality
Because Aria invites open, reflective conversation, you may choose to share sensitive information — including information about your emotions, mental or physical health, relationships, or experiences. We treat conversation content as private to your account and protect it with the safeguards described in Section 11. Please keep the following in mind:
- You control what you share. You are not required to provide any particular information, and we encourage you not to share details you would prefer to keep private (including precise identifiers of yourself or others).
- Aria is not a confidential professional relationship. Because the Service is not therapy or medical care, communications with Aria are not protected by therapist-patient, doctor-patient, or similar legal privilege or confidentiality. See Section 1.
- The Service is not a crisis service. We do not monitor conversations in real time for emergencies and cannot intervene, contact emergency services on your behalf, or dispatch help. In a crisis, call 911 or the 988 Suicide & Crisis Lifeline (call or text 988).
- Limited disclosures for safety and law. We may access, preserve, or disclose conversation content where we reasonably believe it is necessary to comply with law or legal process, or to protect the rights, property, or safety of you, our users, the public, or the Company. [Legal to confirm the precise standard and any mandatory-reporting considerations applicable to a general-wellness product.]
10. No Users Under 18; Not Directed to Children
The Service is intended only for adults 18 and older and is not directed to children. We do not knowingly collect or solicit personal information from anyone under 18. If we learn that we have collected personal information from a person under 18, we will take reasonable steps to delete it. If you believe a minor has provided us with information, contact [CONTACT EMAIL].
11. Data Storage and Security
We use reasonable technical and organizational measures designed to protect your information, including:
- Encryption in transit (e.g., TLS) for data moving between you and the Service. [CONFIRM.]
- Encryption at rest for stored data, including account information and conversation content. [CONFIRM encryption implementation and key management, e.g., AWS KMS.]
- Access controls limiting access to personal information to authorized personnel and systems with a need to access it. [CONFIRM access-control model and logging.]
- Operational safeguards such as monitoring, logging, and vendor security commitments. [CONFIRM.]
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. [Legal/engineering to confirm the specific controls represented above and to add a breach-notification statement consistent with applicable law.]
12. Data Retention and Deletion
We retain personal information only for as long as necessary to provide the Service and for the purposes described in this Policy, unless a longer retention period is required or permitted by law.
- Account information is retained while your account is active. [CONFIRM retention period after account closure.]
- Conversation content is retained [CONFIRM: e.g., until you delete it, until your account is deleted, or for a defined period]. [CONFIRM whether users can delete individual conversations and how deletion propagates to backups and to sub-processors such as AWS/Amazon Bedrock.]
- Technical/usage and log data is retained for [CONFIRM PERIOD].
When we no longer need information, we take reasonable steps to delete or de-identify it. [CONFIRM backup-deletion timelines and any legally required retention.]
You may request deletion of your information as described in Section 13.
13. Your Privacy Rights and Choices
Subject to applicable law, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate personal information;
- Delete your personal information;
- Export / obtain a portable copy of certain information you provided to us;
- Opt out of certain communications or, where applicable, certain cookies/analytics;
- Withdraw consent where processing is based on consent.
How to exercise your rights. Contact us at [CONTACT EMAIL / DATA-REQUEST EMAIL] [or use in-app settings / a data-request form — CONFIRM available mechanisms]. We will verify your identity before acting on your request and will respond within the timeframe required by applicable law. You may authorize an agent to make a request on your behalf where the law permits. We will not discriminate against you for exercising your rights.
13.1 California Privacy Notice (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), provides additional rights:
- Right to know the categories and specific pieces of personal information we have collected, the sources, the business/commercial purposes for collecting it, and the categories of third parties with whom we share it;
- Right to delete personal information we have collected from you, subject to exceptions;
- Right to correct inaccurate personal information;
- Right to opt out of the "sale" or "sharing" of personal information and to limit the use of "sensitive personal information" — note: as described in Section 7, we do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we use sensitive personal information only to provide and support the Service; and
- Right to non-discrimination for exercising your rights.
Conversation content may include "sensitive personal information" under California law (for example, information you choose to share about your health or state of mind). We use such information only for the purposes of providing and maintaining the Service and as otherwise permitted without triggering the right to limit. [Legal to confirm the CCPA/CPRA categorization, the "categories collected/disclosed" disclosures required, the 12-month lookback statement, and metrics/verification requirements. Add other U.S. state disclosures (e.g., Virginia, Colorado, Connecticut, Utah, Texas) as applicable to your launch footprint.]
To exercise your California rights, contact [CONTACT EMAIL / DATA-REQUEST EMAIL] [or CONFIRM toll-free/other required method]. You may use an authorized agent as permitted by law.
14. U.S.-Only Service; International Users
The Service is intended for use only within the United States, and your information is processed and stored in the United States [CONFIRM AWS region(s)]. If you access the Service from outside the United States, you do so on your own initiative and are responsible for compliance with local laws; we do not represent that the Service or this Policy complies with laws outside the United States. [Legal to confirm whether any non-U.S. access is anticipated and whether additional disclosures are needed.]
15. Cookies and Analytics
We use cookies and similar technologies as described in Section 3.3. [COOKIES / ANALYTICS PLACEHOLDER — insert a full description of the cookies and analytics technologies actually used, their purposes and durations, any third-party analytics providers, and how users can manage or opt out (including consent-management tooling if required). Confirm no advertising/tracking technologies are present, consistent with Section 7.]
16. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify you (for example, by posting a notice in the Service or updating the "Effective Date" above) before the changes take effect, where required by law. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy, to the extent permitted by law.
17. Contact Us and Data Requests
If you have questions about this Policy or wish to exercise your privacy rights, contact us at:
[COMPANY LEGAL ENTITY NAME] [COMPANY MAILING ADDRESS] Email: [CONTACT EMAIL] Data / privacy requests: [DATA-REQUEST EMAIL — may be same as above]
This Policy is governed by the laws of the State of [GOVERNING-LAW STATE], without regard to its conflict-of-laws principles, to the extent permitted by applicable law. [Legal to confirm governing-law and any required regulator-contact disclosures.]
End of draft template. All [BRACKETED PLACEHOLDERS] must be completed and every factual claim verified by engineering and finalized by a licensed attorney before publication.