myessem — Privacy Policy
Effective date: [DATE — set at launch] Operator / Data controller: Chanducate LLC, a Wyoming limited liability company Contact: support@myessem.com
DRAFT — for founder and attorney review. Not yet published. Washington and Nevada residents: our separate Consumer Health Data Privacy Policy also applies to you and is linked distinctly from our homepage.
myessem is a self-reflection and wellbeing tool. The data you entrust to it — how you feel, day by day, and what you write to MIRRA — is exactly the kind of data that deserves the strictest handling. This policy explains, in plain language, what we collect, why, and the rights you have. Three commitments up front:
- We never sell your personal information, and we never share it for advertising. There are no ads in myessem and no ad-tech on our pages.
- Your reflections are yours. We use your content only to run the Service for you — never to train AI foundation models, never for marketing.
- You can leave whole. You can erase your conversations in the app, and delete your account and its data entirely.
1. Scope; not a HIPAA notice
This policy covers the myessem app and website. Chanducate LLC is not a HIPAA covered entity or business associate, and this policy is not a HIPAA notice of privacy practices; we make no claim of HIPAA compliance. Separate federal and state consumer-protection laws govern our handling of your information, including the FTC Act and the FTC Health Breach Notification Rule, and we honor them as described here.
2. What we collect
Information you provide:
- Account data: your email address and sign-in identity, handled by our authentication provider (Clerk). We do not see or store your password when you sign in with Google.
- Check-in data: the dimension values you record in daily check-ins and any notes you attach. This is emotional-wellbeing data and we treat it as sensitive consumer health data in every state, regardless of local definitions.
- MIRRA content: the reflections shown to you, anything you write beneath them, and your conversations with MIRRA — including the automated safety classification attached to each of your chat messages (safe / distress / danger). Conversations are private to your account and erasable by you.
- Introduction answers (optional): if you choose to answer MIRRA's introduction questions, we store your answers — your everyday world, your preferred speaking style, and anything you add about your world in your own words. The open answer is free text under your control; if you choose to include details such as culture, faith, or origin, we treat them as sensitive data with the same protections as everything above. The introduction is entirely optional, editable, and erasable in the app at any time, and is used only to shape how MIRRA speaks with you.
- Payment data: if you subscribe, payments are processed by Stripe. We receive subscription status and billing metadata; we never receive or store your full card number.
Information collected automatically:
- Essential technical data needed to operate and secure the Service: authentication tokens/cookies (Clerk), timestamps, and server logs that may include IP addresses, retained briefly for security. We use essential cookies only — no advertising or cross-site tracking cookies, no third-party ad pixels or SDKs, and no sale or sharing of data for targeted advertising.
- We honor deletion by deleting; we do not maintain shadow profiles.
What we deliberately do not collect: precise geolocation, contacts, biometric identifiers, or browsing history outside the Service.
3. How we use your information
Only for:
- Providing the Service: computing your patterns, composing MIRRA's founder-written reflections, generating MIRRA's responses, and syncing your data to your account.
- Safety: screening each chat message with an automated classifier so that expressions of suicidal ideation or self-harm pause the conversation and surface crisis resources (988; in Israel ERAN 1201; findahelpline.com elsewhere). Safety classifications are stored with your messages; a content-free record of a safety pause (date and count only) is kept so the pause works even if you erase the conversation.
- Billing and account management (subscriptions, receipts, renewal reminders required by law).
- Security, debugging, and abuse prevention (including enforcing daily message limits).
- Legal compliance.
We do not use your information for advertising, we do not build marketing profiles, and we do not make automated decisions about you with legal or similarly significant effects.
4. AI processing
MIRRA's replies and safety screening are generated by AI models operated by our AI service provider, Anthropic. To do this, the relevant content (for example, your chat messages and the conversation context) is transmitted securely to the provider's API for processing and is subject to contractual confidentiality. Per the provider's API terms, content submitted through the API is not used to train their models. No human at myessem or the provider reviews your conversations in the ordinary course; access could occur only where required for safety, security, or law.
Voice features (optional). If you choose to use voice dictation or to have MIRRA's replies read aloud, the audio is processed transiently: your microphone is used only while you hold a recording open, the recording is transmitted securely to our speech service provider (OpenAI) solely to convert it to text (or to convert MIRRA's reply text to audio), and we do not store the audio — no recording is saved on our servers or in our database. The resulting dictated text becomes a chat message only if you choose to send it, and is then handled like any other message under this policy. Per the provider's API terms, content submitted through the API is not used to train their models; the provider may retain API content briefly for abuse monitoring under its own policy. If you never use the voice features, no audio is ever captured.
5. Who we share information with (and who we don't)
We share personal information only with service providers (processors) acting on our instructions under contract:
| Provider | Role | Data involved |
|---|---|---|
| Supabase | Database hosting | Account ID, check-ins, MIRRA content |
| Clerk | Authentication | Email, sign-in identity |
| Anthropic | AI processing | MIRRA conversation content for generation & safety screening |
| OpenAI | Speech processing (optional voice features) | Transient dictation audio → text; MIRRA reply text → audio. Not stored by us |
| Vercel | Application hosting | Technical/server data |
| Stripe | Payments | Billing details (they are an independent controller of card data) |
We do not sell personal information; we do not "share" it for cross-context behavioral advertising (as those terms are defined in the California Consumer Privacy Act); and we have not done either in the preceding 12 months. We disclose information beyond the table above only if required by law or legal process (we will notify you unless legally barred), to protect life or safety, or as part of a merger/acquisition — in which case this policy's protections follow the data and you will be notified.
6. Retention and deletion
- Check-ins and MIRRA content are retained while your account is active, so your mirror has memory.
- You can erase your MIRRA conversations in the app at any time. Erasure removes the messages; a content-free safety-pause record (date and count only) is retained for the day.
- You can delete your account entirely, which deletes your check-ins, conversations, and account data, subject to a short backup-rotation window and records we must keep by law (e.g., billing records).
- Server logs are retained briefly for security and then deleted.
7. Your rights
Wherever you live, we honor these rights — and specific state laws (including California, Colorado, Connecticut, Texas, Virginia and others) may grant them to you as a matter of law:
- Access / portability: get a copy of your data in a usable format.
- Correction: fix inaccurate account data (check-ins are yours to edit in-app).
- Deletion: erase conversations in-app; delete your account and data.
- Consent withdrawal: withdraw consent for the processing of your wellbeing data at any time by deleting the relevant data or your account; because the Service cannot function without processing the check-ins and messages you choose to enter, continued use requires that processing.
- Opt-out of sale / sharing / targeted advertising: nothing to opt out of — we do not sell or share personal information or use it for targeted advertising, and we treat all users as opted out.
- Non-discrimination: exercising rights never degrades your service.
- Appeal: if we decline a request, you may appeal by replying to our decision; we will respond within the time your state's law requires, and you may also contact your state Attorney General.
To exercise any right: use the in-app controls, or email support@myessem.com from your account email. We verify requests through your authenticated account. Authorized agents may submit requests where state law provides, with proof of authorization. We respond within 45 days (extendable as permitted by law).
8. State-specific disclosures
- California: In the last 12 months we collected these categories of personal information: identifiers (email), sensitive personal information (emotional-wellbeing check-ins and conversation content — treated as data concerning health), commercial information (subscription status), and internet activity limited to essential logs. Sources: you; your device. Purposes: Section 3. We disclose only to the service providers in Section 5. We do not sell or share personal information and have no actual knowledge of selling or sharing data of consumers under 16. We use sensitive personal information only to provide the Service and for the purposes permitted by CCPA regulations, so no "Limit the Use of My Sensitive Personal Information" choice is required.
- Washington & Nevada: our Consumer Health Data Privacy Policy (separate link) describes our collection and use of consumer health data, your rights to access, withdraw consent, and delete, and how to appeal.
- Colorado / Connecticut / Virginia / Texas / Oregon and similar: emotional-wellbeing data is "sensitive data"; we process it only with your consent, given when you create an account and accept the health-data consent, and only as described in Section 3.
9. Breach notification
If a breach of security — including any unauthorized acquisition or disclosure of identifiable health information — affects your data, we will notify you without unreasonable delay and within the timelines of the FTC Health Breach Notification Rule and applicable state law, and will notify regulators and media where required.
10. Children
The Service is for adults 18 and older. It is not directed to children, and we do not knowingly collect personal information from anyone under 18 (and never from children under 13). If we learn we have done so, we will delete it and close the account.
11. Security
Your data is protected with industry-standard measures: encryption in transit (TLS) and at rest, database row-level security that isolates each account's rows, least-privilege server keys, and safety-critical code paths enforced server-side. No system is perfectly secure; Section 9 governs our duty if something goes wrong.
12. Where data is processed
We are a U.S. company. Your data is stored and processed on infrastructure in the United States and the European Union (our database is currently hosted in the EU). Wherever it is processed, this policy applies.
13. Changes to this policy
We will notify you of material changes in the app or by email, and material changes will not apply retroactively to previously collected data without your fresh, affirmative consent. The "effective date" above always reflects the current version.
14. Governing language
The English version of this policy is the binding version; translations (including Hebrew) are for convenience only.
15. Contact
Chanducate LLC · Wyoming, USA · support@myessem.com