Cimpathy �? Home

Privacy Policy

Effective date: 2026-05-26 · Last updated: 2026-06-12 · Version 1.1

Cimpathy is built private-by-default. Your journal, mood, and AI chats live encrypted on your device. We never sell data. This policy explains what we collect, why, how long, and how to exercise your rights under GDPR (EU/UK), CCPA/CPRA (California), and similar laws. See also our Terms of Service.

1. Who is the Controller of Your Data

The data controller for the purposes of GDPR and equivalent laws is:

2. What Information We Collect

We collect only what is necessary to run the Service. Categories:

CategoryExamplesWhere stored
IdentifiersEmail (if you sign up), anonymous device ID, account UUIDOur server
AuthenticationHashed password, refresh tokens. Your BIP-39 recovery phrase is never sent to or stored by us — it stays on your device; only an encrypted key-backup blob you choose to upload is held, which we cannot decrypt (see §7).Our server
Plan / purchasePlan and purchase status, payment dates (no card data — handled by Cashfree or PayPal)Our server
Wellness contentMood entries, journal entries, safety-plan entries, hope-vault items, habits, screenings, AI chat messagesEncrypted on your device. Optionally encrypted-sync to our server if you opt in.
Special-category (sensitive)Self-reported mental-wellness data (the categories above), which may concern your health and is therefore treated as special-category dataSame as above. Processed only with your explicit consent. Never sold or shared for advertising.
Technical/operationalApp version, OS platform, hashed IP, error reports, server logsOur server. Crash reports off by default.
Consent ledgerWhich consents you granted, when, hash of text shownOur server (legal requirement)

What we explicitly do NOT collect: card numbers (Cashfree handles these — they never pass through our servers), biometric data, browsing history outside Cimpathy, contacts, camera, microphone, precise location, or unique device fingerprints beyond an opaque hash.

3. Why We Process Your Data (Lawful Basis)

Under GDPR Article 6 we identify a lawful basis for each processing purpose. For special-category data — your sensitive mental-wellness information, which may concern your health — we additionally rely on your explicit consent under Article 9(2)(a), and we never sell or share it.

PurposeLawful basis
Run the Service (auth, sync, content delivery)Contract — Art. 6(1)(b)
Store mental-wellness content on our serverExplicit consent — Art. 6(1)(a) + Art. 9(2)(a)
Send crisis resources / safety featuresLegitimate interests (safety) — Art. 6(1)(f) + explicit consent for sensitive data
Send transactional emails (password reset, billing, security)Contract performance — Art. 6(1)(b)
Marketing emailsConsent — Art. 6(1)(a) (opt-in only, easy unsubscribe)
Crash & performance reportsConsent — Art. 6(1)(a) (opt-in only)
Comply with legal obligationsLegal obligation — Art. 6(1)(c)
Anonymized analytics for product improvementLegitimate interests — Art. 6(1)(f)

4. How We Use Your Information

We do not use your content to train AI models. We do not sell or rent your personal information to anyone. We do not use cross-app tracking or third-party advertising cookies.

5. Who We Share Your Information With

We share data only with a limited list of vetted processors who operate under contract and only for the purposes listed:

SubprocessorPurposeData receivedLocation
CloudflareCDN, DDoS protection, web hostingIP address, request headersGlobal edge
Fly.ioBackend hosting (FastAPI)Server logs, request headersMumbai (ap-south-1) primary, US/EU edge
SupabaseManaged Postgres databaseAccount record, sync content (E2E-encrypted at rest for sensitive fields)Mumbai (ap-south-1)
HostingerDNS + transactional MX (for unsubscribe / DPO mailboxes)Email envelope metadataEU
Anthropic (Claude API)Premium AI chat generationThe message you typed in the AI chat (Premium tier only)United States
ElevenLabsPre-generated course narration audioNone — narration is generated once, offline, and contains no user dataUnited States
Cashfree PaymentsPayment processing for India (UPI, cards, net-banking)Name, email, phone, plan/order metadata (no card data passes through us)India
PayPalPayment processing for international (non-India) purchasesEmail and order metadata (card/PayPal credentials handled by PayPal — never passed through us)United States
ResendTransactional email (password reset, receipts)Your email address, message bodyUnited States
Sentry (opt-in only)Crash reportsAnonymized error stack tracesUnited States

We will share data with law enforcement only when legally compelled by a valid order in our jurisdiction. We publish a transparency note if we ever receive such a request; gag orders permitting.

6. International Data Transfers

Some of our subprocessors (Anthropic, Resend, Sentry) are located in the United States. For users in the EU/UK we rely on Standard Contractual Clauses (SCC 2021/914) approved by the European Commission, together with a transfer impact assessment ("TIA"). For users in India, transfers are made in accordance with Section 16 of the Digital Personal Data Protection Act, 2023 (the Indian government has not, as of the effective date, restricted transfers to these countries). Payment data for Indian users is processed within India by Cashfree. If you would like a copy of the SCCs or our TIA summary, email help@cimpathy.com.

7. Encryption & Security

No system is perfectly secure. If you discover a vulnerability, please report it to help@cimpathy.com.

8. How Long We Keep Your Data

CategoryRetention
Account & authenticationUntil you delete your account; soft-deleted 30 days then hard-deleted
Encrypted wellness content (synced)Until you delete the entry or your account
Anonymous local contentLives on your device until you uninstall
Purchase & billing records7 years (tax/audit obligations)
Consent ledger (which consent, when, hash of text shown)7 years after consent withdrawal (regulatory evidence)
Server access logs90 days then deleted
Crash reports30 days
Crisis intercept audit log (no message content, only pattern matched)2 years (safety integrity)

9. Your Rights

Subject to applicable law, you have the right to:

To exercise any right: email help@cimpathy.com with the subject "Data Rights Request" and your registered email. We respond within 30 days (extendable by 60 days for complex requests, with notice). We may ask you to verify your identity to prevent fraud.

You may also delete most data yourself via Settings → Account → Delete account (immediate soft-delete; hard-deleted after 30 days).

10. For California Residents (CCPA/CPRA)

If you reside in California, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by CPRA:

To submit a CCPA request, email help@cimpathy.com with "California Privacy Request" in the subject. An authorized agent may submit on your behalf with written authorization. Verification is required.

11. For Users in India (Digital Personal Data Protection Act, 2023)

If you are in India, the following applies in addition to the rights above. Viprasol Tech Private Limited is the Data Fiduciary for your personal data.

Notice & consent. We process your personal data — including sensitive data about your mental wellbeing — on the basis of the consent you give through the in-app consent flow before any such processing begins. You may withdraw consent at any time in Settings → Privacy, or by writing to our Grievance Officer. Withdrawing consent is as easy as giving it and does not affect processing already lawfully carried out.

Your rights as a Data Principal (DPDP §11–14):

Grievance Officer. In accordance with DPDP §13 and the Information Technology Act, 2000, the Grievance Officer for Cimpathy is:

Deepak — Grievance Officer
Viprasol Tech Private Limited
Email: help@cimpathy.com (subject line: "Grievance")
We acknowledge grievances within 24 hours and aim to resolve them within the period prescribed under applicable law.

You may also lodge a complaint with the Data Protection Board of India once it is constituted.

12. Children

Cimpathy is intended only for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18.

Under DPDP §9 (India), we do not knowingly process a child's personal data (a person under 18 in India) without the verifiable consent of a parent or lawful guardian, and we do not carry out tracking, behavioural monitoring, or targeted advertising directed at children. Under COPPA (US) we do not knowingly collect data from children under 13, and under GDPR (EU) not from children under 16 (or the lower age set by a member state, minimum 13). If you believe a minor has provided us information, contact help@cimpathy.com and we will delete it promptly.

13. Cookies & Similar Technologies

The Cimpathy website uses only strictly necessary cookies (session token, CSRF token, theme preference). We do not use advertising cookies, analytics cookies, or third-party tracking. The mobile/web app uses local storage and IndexedDB to keep your data on your device — this is not a "cookie" in the regulatory sense but functions similarly. You can clear it by uninstalling the app or using your browser's "Clear site data" feature.

14. Marketing vs Transactional Email

Transactional emails (password reset, security alert, payment receipt, material policy change, account verification) are sent regardless of marketing consent and cannot be opted out of while you maintain an account — these are required to deliver the Service safely.

Marketing emails (product updates, tips, surveys) are sent only with your prior, specific, opt-in consent. Every marketing email includes an unsubscribe link that takes effect within 24 hours. You can also opt out at Settings → Notifications.

15. AI Processing & Profiling

The Service uses Anthropic's Claude API for premium AI chat. When you send a message to the AI:

16. Data Breach Notification

If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will:

17. Changes to This Policy

We may update this Privacy Policy. Material changes (new data uses, new subprocessors, expanded retention) will be communicated by email and in-app banner at least 30 days before the effective date. The "Last updated" timestamp at the top reflects the most recent change. Continued use of the Service after the effective date constitutes acceptance.

18. Contact & Complaints

The Cimpathy service is operated by Viprasol Tech Private Limited (CIN: U62090HR2025PTC135188), a company incorporated on 18 August 2025 and registered in Haryana, India.

If you are not satisfied with our response, you have the right to lodge a complaint with your local data-protection authority:

This policy is written in plain English on purpose. If anything is unclear, write to help@cimpathy.com — a human will respond.