1Introduction and Scope
Who We Are and What This Policy Covers
Welcome to Mentalyze. This Privacy Policy explains how Sueta FZE LLC, a United Arab Emirates entity (“Company”, “we”, “us”, or “our”), collects, uses, secures, and discloses your personal data when you access or use our mobile applications, website, and AI-powered conversational services (collectively, the “Services”).
Not a Healthcare Provider and Not HIPAA Compliant
It is critical to understand that Mentalyze is designed solely as a space to talk through and reflect on your own thoughts and for general wellness.
No Professional or Therapeutic Relationship. The Services are not psychotherapy, counseling, psychological or psychiatric care, diagnosis, treatment planning, or crisis intervention, and are not a substitute for care provided by a licensed professional. The AI is not a licensed physician, psychologist, therapist, counselor, or other health professional, and neither the AI, its responses, its interface, its branding, nor its tone is intended to state or imply that you are interacting with, or receiving services from, a licensed human professional. Using the Services does not create a therapist-patient, physician-patient, or any other professional relationship between you and the Company or any human specialist.
Consequently, Company is NOT a “Covered Entity” or “Business Associate” under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The Services are not designed to securely store or transmit Protected Health Information (PHI). You should never use the Services for medical emergencies or to share official medical records.
Scope of Application
This Privacy Policy applies exclusively to individual consumers who download, access, and use the Services directly (B2C relationship). In this context, Company acts as the Data Controller of your personal information. If you are accessing the Services through an enterprise program, employer, school, or healthcare institution (B2B relationship), our processing of your data may be governed by a separate Data Processing Agreement (DPA) with that organization, which will take precedence over this Privacy Policy in the event of a conflict.
Geographic Availability; Restricted Jurisdictions
The Services are offered only where permitted by law. We do not offer or make the Services available to residents of jurisdictions that prohibit AI-based mental-health, psychological, therapy, or counseling support tools, which currently include Nevada, Illinois, Maine, and Rhode Island, and we apply technical geolocation controls to restrict access from those jurisdictions. We monitor legislative developments and update this list as additional restrictions take effect.
Interacting With Artificial Intelligence
You are always interacting with an automated artificial-intelligence system, not with a human being. We provide a clear and conspicuous notice of this fact within the interface itself: on your first use of the Services, again when you return after a break of seven (7) days or more, whenever you ask, and by means of a persistent or periodic in-session reminder. A statement in this Policy or in our Terms of Service alone is not treated by us as sufficient disclosure.
Consent and Agreement
2Information We Collect
We believe in data minimization and collect only the information necessary to provide, secure, and improve our Services. Depending on how you interact with Mentalyze, we collect the following categories of information:
Information You Provide to Us Directly
- Account Information: When you register for an account, we collect identifiers such as your nickname or name, email address, password, age confirmation, and basic profile preferences (e.g., timezone, pronouns).
- Conversation Data (Inputs):We collect the text, voice recordings, audio messages, text messages, mood check-ins, reflections, and any other content you submit to our conversational AI (“Inputs”). We do not create voiceprints or other biometric identifiers from your voice, and we do not use your voice to identify or authenticate you. We process voice recordings solely to transcribe them into text so the AI can respond.
- Processing of Sensitive Information:We do not actively solicit Protected Health Information (PHI). However, if you choose to share sensitive information within your Conversation Data, any such data classified as “Consumer Health Data” under applicable state laws will be processed ONLY based on the separate, affirmative consent you provided during the onboarding process or prior to your first interaction with our AI.
Information We Collect Automatically
- Device and Network Data: When you access the Services, we automatically collect technical data, including your IP address, device type, operating system, browser type, mobile device identifiers (e.g., IDFA or Android Ad ID), and general geographic location (e.g., city or state level, not precise GPS tracking).
- App Event and Usage Data: We collect information about how you interact with the Services to ensure they function properly and securely. This includes session duration, features utilized, screens visited, crash reports, and system error logs.
- Cookies and Tracking Technologies: We may use essential and analytical cookies (or similar local storage technologies) to maintain your session state, remember your preferences, and analyze platform performance. We do not use tracking technologies to monitor your behavior across third-party websites for targeted advertising purposes based on the contents of your Conversation Data for advertising. The only exception is mobile measurement and attribution, described below, which we use solely to understand how users discover our app and to measure the performance of our own marketing campaigns.
- Mobile Measurement and Attribution:We work with a third-party mobile measurement partner (AppsFlyer) to understand how users discover our app and to measure the effectiveness of our marketing campaigns. For this purpose, we and AppsFlyer process device identifiers (such as IDFA, where permitted) and attribution data. On iOS, this processing occurs only after you grant permission through Apple's App Tracking Transparency (ATT) prompt. If you decline, we do not use these identifiers for tracking. You can change this preference at any time in your device settings.
Information from Third Parties
Single Sign-On (SSO): If you choose to log in using a third-party service (such as Google or Apple), we receive limited information from that service (such as your email address, name, or a unique encrypted identifier) as permitted by your account settings with that third party. We do not receive or store your passwords for these third-party services.
3How We Use Your Information
We use the information we collect strictly for legitimate business purposes, ensuring your privacy and safety remain our top priorities.
To Provide and Maintain the Services
- To operate the conversational AI interface and generate real-time, context-aware responses to your Inputs.
- To securely sync your chat history across your authorized devices.
- To manage your account, process payments or subscriptions, and provide essential customer support.
Technical Support, Troubleshooting, and Reasonable Security Access
We implement a Reasonable Security architecture to protect your highly personal data while maintaining the functionality of the Services.
- Encryption at Rest: Your Conversation Data is encrypted at rest within our databases. The decryption keys are stored in a separate, highly secure environment isolated from general database access.
- Strictly Controlled Access: We do not engage in routine, unauthorized, or curiosity-driven browsing of user chats. However, authorized personnel (e.g., senior engineering staff or customer support leads) may be granted temporary, strictly controlled access to decrypt and review specific conversation logs only when absolutely necessary to: (a) resolve complex technical bugs or crashes; (b) investigate user complaints, safety flags, or Terms of Service violations; or (c) comply with valid legal obligations.
- Immutable Audit Trail: Every instance of manual decryption and data access by our team is automatically recorded in an immutable audit log. This log tracks who accessed the data, when, for which user account, the specific business justification, and the exact volume of data viewed.
Safety and Emergency Response
To detect, assess, and respond to imminent threats of self-harm, suicide, or violence, in accordance with our Acceptable Use Policy and Emergency Protocols.
To operate a crisis-response protocol that detects expressions of suicidal ideation, self-harm, disordered eating, or threats of violence and directs you to appropriate crisis resources, including the 988 Suicide and Crisis Lifeline, while preventing the generation of content that encourages such harm. Where required by applicable law, we publish a summary of these safety protocols and periodic, aggregated, non-identifying statistics on crisis referrals on our website.
Analytics and Service Improvement (Non-Content Data)
To analyze aggregated, de-identified metadata (such as app crash rates, feature usage frequency, and session lengths) to improve our application's performance. We do not read or analyze the actual text of your Conversation Data for general marketing or product analytics.
4AI Processing and Data Training Limitations
We are transparent about how Artificial Intelligence interacts with your data to provide and improve our Services.
Internal AI Training (Our Ecosystem)
To continuously improve the empathy, safety, and effectiveness of Mentalyze, we utilize your Conversation Data strictly in an irreversibly de-identified and aggregated format to train, fine-tune, and enhance our proprietary, internal artificial intelligence models and machine learning algorithms. This learning process occurs strictly within our secure ecosystem. To protect your privacy, we implement strict de-identification and anonymization techniques before utilizing your Conversation Data for internal model training. We never use explicitly identifiable personal information (such as your email or real name) to train our models. Regarding any data that we de-identify for internal model training, we: (i) take reasonable measures to ensure the data cannot be associated with you or any individual; (ii) publicly commit to maintain and use the information in de-identified form and will not attempt to re-identify the information; and (iii) contractually obligate any recipients of such data to comply with these same requirements.
Sharing with Third-Party Large Language Models (LLMs)
To power our core conversational capabilities and generate real-time responses, we share your Inputs (prompts) with trusted third-party Large Language Model providers (e.g., OpenAI, Google) via secure APIs. We enforce strict contractual agreements with these providers to ensure your privacy:
- No Third-Party Training: These external LLM providers are strictly contractually prohibited from using your Conversation Data to train, retrain, or improve their own generalized AI models.
- Data Minimization: We transmit only the data necessary to generate a response and do not send persistent account identifiers to these external providers.
AI Use Disclosure
We disclose, clearly and within the interface, that the Services are powered by artificial intelligence and that you are not interacting with a human. Where a specific U.S. state law (such as the Texas Responsible Artificial Intelligence Governance Act) requires it, we will maintain and make available to the competent regulatory authority, upon request, internal documentation describing the AI system, its intended uses, and its limitations.
5Data Security and Retention
Commitment to Reasonable Security
We employ commercially reasonable administrative, technical, and physical safeguards designed to protect your personal information against accidental, unlawful, or unauthorized destruction, loss, alteration, access, disclosure, or use. Our security architecture is explicitly designed to balance the highest standards of user privacy with the operational necessity of providing a seamless, synchronized user experience.
International Data Transfers
The Company is established in the United Arab Emirates, and we provide the Services to users in the United States and other countries. Your personal data, including Conversation Data, is processed and stored on servers located in the United States and may be transferred to, and processed in, countries other than the one in which you reside — including by our third-party service providers and LLM providers (e.g., OpenAI, Google). These countries may have data-protection laws that differ from those of your jurisdiction. Where we transfer personal data across borders, we take reasonable steps to keep it protected consistent with this Privacy Policy and applicable law, including through contractual safeguards with our service providers.
Encryption and Key Management
- In Transit: All communications between your device and our servers, including your Conversation Data, are securely encrypted in transit using industry-standard cryptographic protocols (e.g., TLS/SSL).
- At Rest: Your Conversation Data is stored in encrypted databases. To prevent unauthorized mass data extraction, the cryptographic keys required to decrypt this data are isolated and maintained in a secure, separate key management system, independent of the primary databases.
Internal Access Controls and Immutable Audit Trails
We enforce the principle of least privilege. General staff members do not have access to your readable Conversation Data. In the rare and exceptional event that senior technical personnel require access to decrypt specific chat logs (e.g., for critical bug resolution, safety interventions, or legal compliance), such access is strictly governed by internal confidentiality agreements and operational protocols.
To ensure absolute accountability and prevent unauthorized or curiosity-driven browsing of user data, our systems automatically generate an immutable (non-erasable) audit log for every decryption event. This log permanently records the identity of the personnel, the precise timestamp, the business justification, and the exact scope of the data accessed.
Data Retention and Deletion
We retain your personal information and Conversation Data only for as long as your account is active, or as reasonably necessary to fulfill the operational and legal purposes outlined in this Privacy Policy.
- Account Deletion: You may request the deletion of your account and associated data at any time through the in-app settings or by contacting our support team. Upon receiving a valid deletion request, your active account and Conversation Data will be permanently deleted or irreversibly anonymized in our production systems within thirty (30) days.
- System Backups: Please note that for disaster recovery and business continuity purposes, encrypted residual copies of your deleted data may temporarily remain in secure, isolated routine system backups for an additional period (typically up to 30 days) before being fully overwritten. These backups are strictly isolated and are not accessible for regular business operations.
Notwithstanding the foregoing, where you request deletion of Consumer Health Data, we delete or irreversibly de-identify that data across our production systems and ensure it is removed from, or overwritten in, our archived and backup systems on the next scheduled backup cycle, consistent with the Washington My Health My Data Act.
Our retention periods for each category of collected data are determined as follows:
- Account Information, Conversation Data (Inputs), and Voluntary Sensitive Information: Retained only for as long as your account is active to securely sync your chat history and provide the Services.
- Device and Network Data & App Event and Usage Data: Retained for a limited period strictly as necessary to ensure security, debug errors, and analyze platform performance, after which it is securely deleted or irreversibly aggregated.
Inherent Risks
While we implement robust, industry-standard security protocols, no method of transmission over the Internet or electronic storage is entirely secure. Therefore, we cannot guarantee the absolute security of your data. You are equally responsible for safeguarding your account credentials and maintaining the physical and digital security of your own devices.
6Information Sharing and Disclosure
We treat your highly personal information with the utmost confidentiality.
The term “sell” is used here as defined under applicable state privacy law, which may include disclosures made in exchange for monetary or other valuable consideration; we do not engage in such disclosures of the categories above. Consistent with the mental-data protections recognized in states such as Vermont, we do not sell identifiable transcripts of your conversations, and we will not do so under any circumstances without your separate, explicit written consent.
We do not share the contents of your Conversation Data, your messages, your moods, or the topics of your conversations with advertising networks or data brokers. However, to measure and optimize our advertising campaigns, we share limited identifiers (such as your advertising/device identifier) and certain non-content engagement events (such as app installs, registrations, purchases, onboarding completion, and the fact that a chat session was completed, identified only by a sequential session number) with our advertising partners. Under California and certain other state laws, this activity may be considered “sharing” for cross-context behavioral advertising. We never share the substance, text, mood data, or subject matter of your conversations for this purpose. You have the right to opt out of this sharing, as described in the “Right to Opt-Out” section below.
Because our Services relate to emotional well-being, we treat the fact that a person uses the Services as potentially sensitive. Accordingly, for residents of states with consumer-health-data or AI-chatbot laws (including Washington, Nevada, Connecticut, and others), we do not engage in any advertising-related sharing of device identifiers, installs, registrations, or session-completion events unless you have given separate, affirmative opt-in consent, and this sharing is disabled by default for such residents. We never share the substance, text, mood data, or subject matter of your conversations for advertising under any circumstances.
Sharing with Service Providers
To operate our Services, we share your personal data with trusted third-party vendors, consultants, and contractors who perform critical operational services on our behalf. They are bound by strict written agreements that explicitly prohibit them from retaining, using, or disclosing your personal information for any purpose other than performing the specific services outlined in our agreement. Our Service Providers include:
- Cloud Hosting and Infrastructure Providers (e.g., secure database hosting, server infrastructure).
- Third-Party AI Language Models (LLMs): As detailed in Section 4, we transmit necessary data to API providers solely to generate conversational responses, under strict Zero Data Retention and No Training contractual obligations.
- Payment Processors: To securely manage subscription billing and process transactions. We do not process or store your full credit card information on our servers.
- Customer Support and Analytics Tools: To provide technical support and analyze aggregated, non-identifiable app performance metrics.
- Mobile Measurement and Attribution Providers: We use a mobile measurement partner (AppsFlyer) to attribute app installs to our marketing campaigns and measure their performance. This partner processes device identifiers under strict contractual restrictions and, on iOS, subject to your App Tracking Transparency (ATT) permission. This partner is prohibited from using your data for its own purposes.
Legal Compliance and Harm Prevention
We may access, preserve, and disclose your personal information, including Conversation Data, to external parties if we have a good-faith belief that such disclosure is reasonably necessary to:
- Comply with a valid legal process, such as a court order, subpoena, search warrant, or other lawful requests by public authorities, including meeting national security or law enforcement requirements.
- Protect and defend the legal rights, property, or safety of Sueta FZE LLC, our users, our employees, or the public.
- Enforce our Terms of Service, Acceptable Use Policy, and other agreements, including investigating potential violations.
- Emergency Situations: Detect, prevent, or otherwise address imminent, severe threats to life or physical safety (e.g., credible threats of suicide, self-harm, or violence against others). While we are not mandatory reporters under applicable laws, we reserve the right to proactively notify emergency services or appropriate authorities if our systems or personnel detect an imminent risk of fatal harm.
Business Transfers and Corporate Reorganization
If the Company is involved in a merger, acquisition, bankruptcy, reorganization, dissolution, or sale of all or a portion of its assets, your personal information may be shared or transferred as part of that transaction. In such an event, we will notify you via email and/or a prominent notice within the Services of any change in ownership or the governing privacy policies, and your data will remain subject to the promises made in the pre-existing Privacy Policy until you agree otherwise.
Safety-Related Refunds
Notwithstanding Section 6, if your access to the Services is restricted or suspended pursuant to the Safety Protocols (Section 4.3) for your own well-being, you may be eligible for a pro-rata refund for the unused portion of your subscription. Such refunds are granted at our sole discretion upon a written request to our support team, as we encourage you to prioritize professional clinical care over the use of our AI tools.
7U.S. State Privacy Rights
Applicability to U.S. Residents: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Texas, Utah, Virginia, or other states with comprehensive consumer privacy laws, you are granted specific rights regarding your personal information.
California Notice at Collection:This Section 7, together with Section 2 ('INFORMATION WE COLLECT') and Section 3 ('HOW WE USE YOUR INFORMATION'), serves as our Notice at Collection for California residents under the CCPA/CPRA.
Information Collected and Disclosed in the Preceding 12 Months:In accordance with the CCPA, we disclose that within the preceding 12 months, we have collected the following statutory categories of personal information: Identifiers (e.g., nickname, email address, IP address), Internet or other electronic network activity information (e.g., app usage and interaction data), and Sensitive Personal Information (e.g., health-related data voluntarily disclosed in your Conversation Data). We collect these categories of personal information from the following categories of sources: (i) directly from you when you provide information to us; (ii) automatically through your device and your interactions with our Services; and (iii) from third-party Single Sign-On (SSO) providers, such as Google or Apple, if you choose to register using those services. We collect and use this information for the business purposes described in Section 3 of this Policy. In the preceding 12 months, we have disclosed these categories of personal information for business purposes to the following categories of third parties: cloud hosting and infrastructure providers, third-party AI language model (LLM) providers, payment processors, and customer support and analytics tool providers. We have not sold any personal information for money in the preceding 12 months. In the preceding 12 months, we have shared (for cross-context behavioral advertising, as defined under the CCPA) the following categories with our advertising partners: Identifiers (advertising/device identifiers) and Internet or other electronic network activity information (non-content engagement events, such as installs, registrations, purchases, and session-completion events identified only by a sequential number). We do not share Sensitive Personal Information, the contents of your Conversation Data, your mood data, or the subject matter of your conversations for cross-context behavioral advertising. We do not have actual knowledge that we sell or share the personal information of consumers under 18 years of age. You may opt out of this sharing as described in the “Right to Opt-Out” section below.
Your Privacy Rights
Depending on your state of residence, you have the right to request the following regarding your personal data:
- Right to Know and Access: You have the right to request confirmation of whether we are processing your personal data and to access such data. You may request a portable copy of the specific pieces of personal information we have collected about you, including information collected beyond the 12-month period preceding your request (covering the entire period since we began collecting your personal information), unless providing it proves impossible or would involve a disproportionate effort, provided in a format that is easily understandable, and to the extent technically feasible, in a structured, commonly used, machine-readable format that may also be transmitted to another entity at your request. We will provide this information in a portable and, to the extent technically feasible, in a readily usable, structured, machine-readable format that allows you to transmit the data to another entity without hindrance. In accordance with applicable law, we are not required to provide information to the same consumer more than twice in a 12-month period. Additionally, if you are a resident of Delaware, Massachusetts, or Minnesota, you have the right to obtain a list of the specific third parties (other than natural persons) to whom we have disclosed your personal data. In addition to your right to a portable copy of your data, specifically for residents of Indiana, we reserve the right to provide either a full copy of your personal data or a representative summary of such data, as permitted by Indiana law (IC 24-15-3-1), depending on the nature and volume of the information processed.
- Right to Delete: You have the right to request the deletion of personal information that we have collected from you, subject to certain legal and operational exceptions (e.g., preserving an immutable audit log for security purposes).
- Right to Correct: You have the right to request the correction of inaccurate personal data that we maintain about you. If we decline a request to correct Consumer Health Data, you have the right to provide a written addendum to your record (not exceeding 250 words per item), which we will maintain and disclose alongside the disputed information as required by law.
- Right to Opt-Out of “Sale” or “Sharing” for Targeted Advertising: You have the right to direct a business that sells or shares your personal information for cross-context behavioral advertising to stop such practices.
- Right to Profiling:you have the right to opt-out of the processing of personal data for purposes of profiling in furtherance of decisions that produce legal or similarly significant effects. While we share certain identifiers and non-content engagement events for advertising optimization (see Sections 6 and 7), we do not engage in profiling that produces legal or similarly significant effects concerning you, and we do not use your conversation content, mood data, or conversation topics for profiling. You may opt out of advertising-related sharing as described in the “Right to Opt-Out” section above.
- Right to Limit Use of Sensitive Personal Information: California residents have the right to limit the use of sensitive personal information to that which is strictly necessary to perform the services. Because we only process any voluntarily provided sensitive information to generate the conversational AI responses you request (and strictly prohibit its use for AI training or marketing), our current processing activities are already strictly limited to these permitted operational purposes.
- Right to Revoke Consent: You have the right to withdraw or revoke any consent previously provided to us for the processing of your personal or sensitive data. We provide a mechanism for revocation that is as easy to use as the mechanism used to provide consent. Upon receiving a valid request, we will cease processing your data for the relevant purposes as soon as feasible, but no later than fifteen (15) days after receipt of your request.
- California 'Shine the Light' Law (Civil Code Section 1798.83): Under California Civil Code Section 1798.83, California residents who provide us with personal information in obtaining products or services for personal, family, or household use are entitled to request and obtain from us, once per calendar year, information about the customer information we shared, if any, with other businesses for their own direct marketing uses. However, as established in Section 6 of this Privacy Policy, we do not disclose your personal information to third parties for their direct marketing purposes. Accordingly, under Section 1798.83(c)(2), we are exempt from these reporting requirements. If you have any questions regarding our data sharing practices, please contact us at the email address provided in Section 11.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights. We will not deny you services, charge you different prices, or provide a different level or quality of services.
You have the right to opt out of this sharing at any time. To opt out, please email us at sueta.llc@gmail.com with the subject line “Do Not Sell or Share My Personal Information.” Upon receipt, we will stop sharing your personal information with advertising partners for cross-context behavioral advertising as soon as feasible. We will never share the contents of your conversations, your mood data, or the subject matter of your conversations for advertising purposes under any circumstances.
In addition, we respond to and abide by opt-out preference signals (such as the Global Privacy Control) sent by your browser. When we receive such a signal, we treat it as a valid request to stop sharing your personal information for cross-context behavioral advertising.
Do Not Track and Opt-Out Signals.Some web browsers transmit “Do Not Track” (DNT) signals. Because there is no common industry standard for interpreting DNT signals, we do not respond to them. On our mobile app, we do not track you across other companies' apps or websites unless you grant permission through Apple's App Tracking Transparency (ATT) prompt; if you decline, we do not use your device identifier for tracking. You can change this choice at any time in your device settings. Where we operate a website that processes opt-out preference signals such as Global Privacy Control (GPC), we honor those signals.
How to Exercise Your Rights
As a business that operates exclusively online and has a direct relationship with you, we provide the following methods to exercise your rights, please submit a request to our privacy team by:
- Emailing us at sueta.llc@gmail.com with the subject line “State Privacy Rights Request.”
- Using the dedicated data management features (e.g., “Delete Account” or “Export Data”) available directly within the application's settings menu.
Verification Process and Response Time
To protect your privacy and security, we are required by law to take commercially reasonable steps to verify your identity before fulfilling your request. We will verify your request by asking you to send the request from the email address associated with your account or by verifying your logged-in status within the app. We endeavor to respond to verifiable consumer requests within forty-five (45) days of receipt; however, for residents of Iowa, we will respond to such requests within ninety (90) days of receipt as permitted by Iowa law.
Right to Appeal
If you are a resident of Colorado and we decline to take action on your privacy request, you have the right to appeal our decision within a reasonable period. To submit an appeal, please email us at sueta.llc@gmail.com with the subject line 'Privacy Request Appeal.' We will inform you in writing of any action taken or not taken in response to an appeal within the timeframes required by your state's law (typically forty-five (45) days for Colorado residents and sixty (60) days for Connecticut residents). If the appeal is denied, you may contact the Colorado Attorney General (for residents of Colorado) to file a complaint at https://coag.gov/file-complaint/, or the Delaware Department of Justice (for residents of Delaware) at https://attorneygeneral.delaware.gov/contact/.
Authorized Agents
If permitted by your state's laws, you may designate an authorized agent to make a request on your behalf. To exercise your rights through an authorized agent, you must provide the agent with signed, written permission to do so. To protect your security, we may also require you to: (i) verify your own identity directly with us; or (ii) directly confirm with us that you provided the authorized agent permission to submit the request.
8Consumer Health Data Privacy Policy
Certain information you share through the Services may be classified as “Consumer Health Data” under the Washington My Health My Data Act (MHMDA), Nevada SB 370, Connecticut law, and similar state laws. How we collect, use, share, retain, and protect that data — and the rights you have in relation to it — are governed by our separate Consumer Health Data Privacy Policy. That policy is also linked prominently from our homepage and from every page or screen on which Consumer Health Data is collected, as required by applicable law.
9Minors' Privacy
Age Restriction
Our Services are strictly intended for users aged 18 and older. We do not knowingly collect personal information from minors under the age of 18, and such individuals are expressly prohibited from using the Services. If we learn that we have inadvertently collected personal data from a minor under 18, we will immediately deactivate the associated account and permanently delete all personal information and conversation data from our servers in accordance with our Terms of Service.
Age Assurance
Access to the Services is conditioned on confirmation that the user is at least eighteen (18) years old. Where age signals are made available by the app store (such as Apple's Declared Age Range API), we rely on those signals to support this age restriction. Additionally, we use a self-declared checkbox to verify age. We do not knowingly permit minors to use the Services, and if we learn that a user is under 18 we deactivate the account and delete the associated data. This approach is intended to align with the age-assurance expectations of state AI-chatbot and minor-protection laws (including in Colorado, Connecticut, Georgia, and similar states).
Account Deletion for Minors
If we obtain actual knowledge that we have inadvertently collected personal data from a minor under the age of 18, we will immediately take steps to deactivate the associated account and permanently delete that information from our servers. If you are a parent or legal guardian and believe your child has provided us with personal information without your consent, please contact us immediately at sueta.llc@gmail.com.
10Changes to This Privacy Policy
Updates and Revisions
We reserve the right to modify, amend, or update this Privacy Policy at any time to reflect changes in our operational practices, new technology, or evolving legal requirements.
Notification of Changes
If we make material changes to how we process your personal data (particularly regarding the strict No AI Training policy or Conversation Data security), we will notify you by:
- Sending an email to the address associated with your account.
- Posting a prominent notification within the App or on our Website before the changes take effect.
- Updating the Last Updated date at the top of this Privacy Policy.
Your continued use of the Services after the effective date of the revised Privacy Policy constitutes your acknowledgment and agreement to the updated terms.
11Contact Information
If you have any questions, concerns, or legal requests regarding this Privacy Policy, our data security practices, or your consumer rights, please contact our privacy team:
Ajman Boulevard Commercial, Ajman, UAE