Aurelia knows you. The cloud doesn’t.
v0.2 · last updated 19 May 2026 · draft — pending solicitor review
1. Who we are
EmotiVault Ltd (in formation), United Kingdom. We are the data controller for the personal data described in this policy.
Contact: emotivault@gmail.com. Registered office address and ICO registration number are pending and will be published here before public launch.
2. What we collect
- Identity: first name, email address, date of birth (used only for the 16+ age check — we store whether you’re an adult or a 16–17 minor, not your full date of birth), and a public handle for the Echoes surface
- Content you write: journal entries, Echoes posts, mood logs, your conversation history with Aurelia
- Voice (Premium): transcripts of voice journal entries. Audio recordings stay on your device by default; only transcripts sync
- Onboarding answers: preferred Aurelia tone, your first mood + entry, and any goals/triggers you share over time
- Technical telemetry: browser type, device, IP address (truncated for security), and minimal analytics events required to keep the service running
3. What we DON'T collect
- No third-party advertising trackers
- We never sell your data and do not use your private journal entries to train AI models
- No behavioural-profile cookies
4. Lawful basis (UK GDPR)
We rely on the following lawful bases under Article 6(1) of the UK GDPR:
- Consent (Article 6(1)(a)) — for journal content, mood logs, Echoes posts, and conversational data with Aurelia
- Contract (Article 6(1)(b)) — for account management and Premium billing
- Legitimate interests (Article 6(1)(f)) — for security, fraud prevention, and core service operations
Your emotional and mental-wellbeing data is special category data under Article 9. We rely on explicit consent (Article 9(2)(a)) to process it — confirmed during onboarding. You can withdraw it at any time: delete your data or your whole account from /you, or email us (section 13) and we’ll stop processing and erase on request.
5. Where it lives
Encrypted in transit (TLS 1.3) and at rest (AES-256) in Supabase (UK/EU region). End-to-end encryption, where even we cannot decrypt your content, is on the roadmap for journal entries and voice. Until then, our staff have technical access for moderation, debugging, and support, governed by a strict access-control policy.
AI providers (Anthropic and Google) process individual messages on our behalf. Neither retains your content beyond their own technical caches; both are bound by data processing agreements. We pass the minimum context needed for a single reply, not your full history.
6. Sub-processors
The following processors handle your data on our behalf:
- Supabase Inc.: database + authentication (UK/EU region)
- Anthropic PBC: Aurelia’s deep replies (Claude Sonnet)
- Google LLC: Aurelia’s routine replies (Gemini Flash)
- Cloudflare Inc.: edge infrastructure + rate limiting
- Resend (Plus Five Five, Inc.): transactional email — sign-in links, password resets, welcome messages
- Stripe Payments Europe Ltd: billing (Premium only)
- Google Firebase: static-site hosting
Each sub-processor is bound by a Data Processing Agreement. We will publish the full register, with each provider’s DPA reference, before public launch.
7. Sealed entries & shared boards
Sealed (time-capsule) entries in your Vault stay private to your account and are hidden in the app until the unlock date you chose. Sealing is an app-level promise, not extra encryption: like every entry, sealed entries are encrypted in transit and at rest, and the staff-access controls in section 5 apply until end-to-end encryption ships. Once unlocked, an entry remains visible only to you.
If we launch a shared board (such as the Ideas board), posting there will always be a separate, explicit action — nothing you write in your journal is ever shared by default, and this policy will be updated before any shared surface goes live.
8. Retention
- Journal entries: kept indefinitely while your account exists. Yours forever.
- Aurelia memory window: Free tier: rolling 30 days. Premium: unlimited.
- Account deletion: full erasure within 30 days of request (UK GDPR Article 17)
- Backups: held for 30 days then permanently deleted
9. Your rights under UK GDPR
You have the right to:
- Access: request a copy of all data we hold about you
- Rectification: correct anything that’s wrong
- Erasure(“right to be forgotten”) — delete your account and all associated data
- Portability: export your entries as text, or print to PDF,
- Restriction: limit how we use your data
- Objection: object to certain processing
- Withdraw consent: at any time, from
/youor by emailing emotivault@gmail.com - Complainto the Information Commissioner’s Office (ico.org.uk)
10. Children's data
You must be at least 16 years old to use EmotiVault. The age check happens at onboarding (step 02), and a declared under-16 date of birth is blocked. We do not knowingly collect data from anyone under 16. If you believe we have, write to emotivault@gmail.com and we will delete it.
For users aged 16–17, we record minor status at sign-up so that age-appropriate safeguards can apply as they roll out (a more conservative crisis-response setting and reduced data retention are in development). What applies today: the same crisis signposting as every account, the clear position that Aurelia is not a therapist, and the right of parents or guardians to ask for their child’s data to be deleted at any time.
11. International transfers
Your data is primarily stored in the UK/EU. Where data flows to sub-processors outside the UK (Anthropic, Google, Stripe in the US), it is protected by Standard Contractual Clauses (SCCs) or equivalent legal safeguards approved by the ICO.
12. Cookies & local storage
We set no cookies at all. Your sign-in session and preferences (like your theme) live in your browser’s local storage, on your device, and are readable only by this site. No marketing cookies, no analytics, no third-party trackers. One note: our fonts load from Google Fonts, which means your browser requests them from a Google server (a standard web font fetch that shares your IP address with Google, nothing more).
13. Changes to this policy
We will notify you of material changes in-app and by email at least 30 days before they take effect. Your continued use of EmotiVault after the effective date constitutes acceptance.
14. Contact + data protection officer
For privacy questions, exports, deletions, or to exercise any of your rights, write to emotivault@gmail.com.
Our Data Protection Officer is pending formal appointment. Once appointed, their contact details will be published here.
Draft notice. This document is a v0.2 draft pending review by a UK data-protection solicitor. The operating commitments above are sincere and reflect how the product is built; the exact wording (and items marked “pending”) will change before launch.