Innuro
Get launch updates
Menu

Legal · Privacy

Privacy Policy

Publication review in progress

What information Innuro currently processes, how it is used, and which controls are available today.

Policy summary

The short version

Four current facts. The complete policy and its boundaries remain below.

  1. Processed during a session

    Voice audio is processed while an active voice session is running.

  2. Records that may be stored

    Transcript text and other supported session records.

  3. Personal information is not sold

    Innuro does not sell personal information.

  4. Available requests

    Request export or deletion for supported data classes and privacy flows.

Clear boundaries for sensitive information

This policy describes what Innuro currently processes and the controls currently available. It does not claim that every system is risk-free or that every data class follows the same export, deletion, or retention path.

Current implementation

Three current privacy boundaries.

These limits stay in view before the complete policy continues below.

  1. What you share

    Content you submit remains yours, subject to the Terms. Innuro processes it to provide supported features.

    Current boundary

    Transport security + storage controls

    • Selected reflections and session text can be used to produce responses and possible connections for you to review.
    • Voice audio is processed during active sessions so Innuro can generate transcript text and emotion signals.
    • Innuro does not sell personal information. Service providers may process information needed to operate the service.
  2. Supported deletion controls

    You can request session or account deletion through the flows available today. Coverage varies by data class.

    Current boundary

    Coverage varies by data class

    • Supported deletion flows remove the currently implemented account and session data classes.
    • Some operational, data-handling, and legal-acknowledgment records have separate retention paths.
    • The current implementation does not guarantee automatic session deletion after a fixed period.
  3. Policy versions and consent

    Policy versions are tracked, and account flows can store versioned legal acknowledgments.

    Current boundary

    Versioned consent records

    • Consent records can include the version, choice, source, and date recorded.
    • Account flows may require acceptance of a current legal acknowledgment.
    • Review the current text on this page; this policy does not promise advance notice through a particular channel.

What information we collect

Things you give us directly

Your contact and account information
Email submitted for launch updates; account identifiers and authentication data if you create an account
Your sessions
Text you submit and transcript text created from voice input
Your voice input
Voice audio is processed during active sessions to generate transcript text and emotion signals.

Things we collect automatically

Product usage
When you use the app, features used, session length
Device basics
Device type, operating system, app version
Product analytics
Privacy-screened usage events; some events may use hashed identifiers. This is not a claim that all analytics are anonymous.

How we use your information

To make Innuro work for you
Produce session responses, compare selected reflections over time, and offer possible connections for you to review
To show crisis resources during a session
Innuro is not an emergency service. It does not monitor you or guarantee it will recognize a crisis. If you mention a crisis during an active session, Innuro may show support resources. It does not contact a service or another person for you. If you might be in immediate danger, contact local emergency services or a crisis line now.
To make Innuro better
Use privacy-screened product analytics. Some events may use hashed identifiers, and optional marketing-site analytics are controlled by your consent choice. On this website, turning on site analytics also turns on session replay, which records your visit with form inputs masked. Turning on campaign measurement stores the campaign source, referrer, and landing page that brought you here for 30 days, refreshed each visit.
To stay in touch
Send launch and availability updates you requested, plus important account and privacy notices.

Current security boundaries

Transport and storage controls
Transport security and hosted storage controls are used; field-level encryption for transcripts and derived records is not yet complete
Operational access
Access controls are used for operational systems. This is not a claim that staff cannot access data.
No blanket security guarantee
Security controls reduce risk but do not make any system risk-free. This policy does not claim an independent certification.
Redacted support bundles
Support bundles currently available default to minimal or redacted files and are designed to exclude transcript and message content; this does not describe every operational record

Controls currently available

Depending on the data class and available flow, you can:

  • See supported account and session metadata
  • Request export for implemented data classes
  • Correct information through supported flows
  • Request deletion for the implemented scope
  • Change optional consent choices

Who we share data with

Innuro does not sell personal information.

Information may be processed or disclosed in these categories:

  1. Service providers

    Providers that support hosting, storage, communications, AI-assisted features, and product operations may use information needed for those services

  2. Legal requirements

    When disclosure is required by applicable law or valid legal process

  3. Your direction

    When you ask Innuro to process or share information for a supported action

The companies that receive your data

This list names each company, its role, what it does, and what reaches it. A processor acts only on Innuro's instructions. A joint controller also decides some of its own uses of the data — for those, your consent choice is the control, and you can change it at any time.

  • Vercel

    processor

    Hosts and delivers this website, and measures how fast pages load.

    Requests to this site, including IP address and browser details. Load-speed and site-usage measurement stays off until you turn on site analytics.

  • Render

    processor

    Runs the Innuro service, its main database, and its job queue.

    Account records, session text and transcript text, and the records the service derives from them.

  • Neo4j

    processor

    Provides the hosted database that holds the connection records Innuro builds from your sessions.

    Records derived from session content, held against your account.

  • Qdrant

    processor

    Provides the hosted search index that lets Innuro find related reflections.

    Numeric representations of session text, held against your account.

  • Hume AI

    processor

    Runs the voice conversation and turns speech into transcript text and tone signals.

    Voice audio during an active session, and the transcript text and emotion signals returned from it.

  • OpenAI

    processor

    Generates session responses and the numeric representations used for search.

    Session text and transcript text sent to it to generate a response.

  • Anthropic

    processor

    Generates session responses.

    Session text and transcript text sent to it to generate a response.

  • Resend

    processor

    Sends the emails you asked for, plus account and privacy notices.

    Your email address and the content of the message.

  • Expo

    processor

    Delivers push notifications to the app.

    The push token for your app installation and the notification text.

  • Cloudflare

    processor

    Checks that the update-request form was submitted by a person rather than a script.

    A challenge token and the technical signals used to score it.

  • PostHog

    processor

    Site analytics and session replay: records how this site was used, including a replay of your visit.

    Site usage events and a recorded replay of your visit with form inputs masked. Off until you turn on site analytics.

  • Google Analytics

    joint controller

    Measures how this site is used.

    Site usage events such as page views. Off until you turn on site analytics.

  • Google Ads

    joint controller

    Measures ad conversions for Innuro's campaigns.

    Ad conversion events. Off until you turn on campaign measurement.

  • Meta

    joint controller

    Measures ad conversions for Innuro's campaigns on Facebook and Instagram.

    Ad conversion events. Off until you turn on campaign measurement.

  • RevenueCat

    processor

    Manages entitlement and access state — not billing. No public purchase is currently offered; this determines which features an account may access.

    An app-user identifier: your Innuro account id once you are signed in, or an anonymous identifier before that.

  • Sentry

    processor

    Records application errors so engineers can find and fix them.

    Error reports and the technical context attached to them.

  • Grafana Labs

    processor

    Receives the service's operational logs and metrics.

    Operational log and metric records from the service.

  • Google (gstatic)

    recipient

    Serves the 3D file decoders your browser needs to show the World preview.

    Your IP address, browser details, and the page you came from, sent by your browser when it requests those files.

  • jsDelivr

    recipient

    Serves a second 3D file decoder your browser needs to show the World preview.

    Your IP address, browser details, and the page you came from, sent by your browser when it requests that file.

Privacy control

Ask about your data.

Use the privacy address for export, correction, deletion, and questions about how information is handled.

Email privacy