Privacy Policy
We collect only what's necessary to make Aemote work. Your emotional data is yours.
1. Data We Collect
When you use Aemote, we collect the following categories of information:
- Account data — Your email address, used for authentication, account recovery, and essential security notifications.
- Health & wellbeing data — Your maps, emotion logs, intensity ratings, context notes, and body sensation records. This data is linked to your account and used solely to provide the Aemote service.
- Onboarding preferences — Your role (e.g. individual, therapist), how you heard about Aemote, and your reason for signing up. Stored in your profile and linked to your account. Used solely to personalise your experience and improve the app.
- Referral data — If you sign up using a referral link, we record which user referred you in your profile in order to credit them. This information is not shared beyond processing the referral.
- Push notification token — If you enable daily check-in reminders, your device's push notification token is stored in association with your account to deliver those reminders. You can disable this at any time in Settings.
- Crash diagnostics — Anonymous technical crash and performance data collected via Sentry when the app errors or crashes, including device model, OS version, and app version. These logs are not linked to your identity and contain no personal or health data. We do not track which screens you visit or how you use the app.
- Connection data — When the clinician connection feature is available, if you choose to connect with a mental health professional, we store the connection record (your email address, the professional's email address, the connection status, and timestamps) so the connection can function. We also keep limited, anonymised audit metadata about connection-code attempts (the result of each attempt and when it occurred) to prevent abuse and throttle invalid attempts.
We do not collect location data, microphone input, camera data, or contacts.
2. How We Use Your Data
We use the data we collect to:
- Provide, maintain, and improve the Aemote service
- Authenticate your account and keep it secure
- Send essential account-related notifications (not marketing without your consent)
- Deliver daily check-in reminders if you opt in
- Diagnose and fix technical issues via anonymous crash reporting
We do not use your health or wellbeing data for advertising, profiling, or any purpose other than delivering the service you signed up for.
3. Legal Basis for Processing
If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data under the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR) — Processing your account data and basic profile information is necessary to provide the Aemote service you signed up for.
- Explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) — Your health and wellbeing data (maps, emotion logs) is special category data under GDPR. We process it only on the basis of your explicit consent, given when you create your first record in the app. You may withdraw consent at any time by deleting your account — this will not affect the lawfulness of processing before withdrawal.
- Consent (Art. 6(1)(a) GDPR) — Push notification delivery is processed only after you actively enable reminders in Settings.
- Explicit consent (Art. 9(2)(a) GDPR) — Sharing your health and wellbeing entries with a connected mental health professional happens only on your explicit instruction. You choose to establish the connection and you control which entries are visible. You may revoke the connection at any time.
- Legitimate interests (Art. 6(1)(f) GDPR) — Anonymous crash diagnostics are processed under our legitimate interest in maintaining a stable service. These do not override your fundamental rights because they are anonymous and not linked to your identity.
4. Data Sharing
We do not sell, trade, or rent your personal information to third parties.
Service providers
We share data only with the following service providers, and only as strictly necessary to operate Aemote:
- Supabase — Our database and authentication provider. Your account data and emotional records are stored on Supabase's encrypted servers under a data processing agreement. See Section 9 (International Transfers) for details on where this data is stored.
- Sentry — Crash reporting. Receives anonymous technical crash data only (device model, OS version, app version). No personal or health data is included. Authentication headers are explicitly stripped before any data is sent to Sentry.
- Expo — Push notification delivery. When you enable daily reminders, your device's push token is shared with Expo to route notifications to your device. Expo does not have access to the content of your notifications or any other personal data.
- Resend — Email delivery for account emails (e.g. magic links, password resets), support and feedback messages (your name, email address, and message), and—when the clinician connection feature is available—therapist invite emails (clinician email and your first name or display name). Messages are transmitted only to deliver the email.
- Cloudflare — Infrastructure provider for the Aemote website and API. Cloudflare processes IP addresses and request metadata for all traffic to aemote.app. The support contact form passes through a Cloudflare Worker before email delivery.
Sharing with a connected professional
Note: Optional connection with a mental health professional is documented here for transparency. This feature is not yet available in the Aemote mobile app; when it launches, the practices below will apply.
Aemote lets you optionally connect with a mental health professional of your choosing. This sharing is entirely under your control:
- Private by default — Your logs and maps are private by default. A connected professional can only see the entries you have explicitly marked as visible.
- Initiated by you — A connection is established only when you take action: either by entering a 6-character connection code from your clinician, or by inviting your clinician by email. You are never connected without doing one of these yourself.
- Revocable at any time — You or the professional can revoke the connection at any time. Revocation immediately stops any further sharing of your entries.
The professional you connect with is your own provider. Aemote facilitates the connection but is not a party to your relationship with them and does not supervise or endorse any professional.
Legal disclosure
We may disclose data if required by law, regulation, or valid legal process — but we will notify you where permitted to do so.
5. Security
We take reasonable and appropriate measures to protect your data, including:
- All data transmitted between the app and our servers is encrypted via TLS/HTTPS
- Data stored on Supabase is encrypted at rest
- You can enable biometric lock (Face ID / Touch ID) to protect access to the app on your device
- Authentication tokens are stored in your device's secure enclave (iOS Secure Enclave / Android Keystore) rather than plain storage
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security, but we treat your data with the seriousness it deserves.
In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify affected users without undue delay and report to the relevant supervisory authority within 72 hours, as required by law.
6. Analytics & Crash Reporting
Aemote uses Sentry to collect crash reports and error diagnostics. This data helps us identify and fix technical issues quickly. Crash reports include technical metadata (device model, OS version, app version) but do not include your name, email address, or any content from your logs or maps. We do not call setUser in our Sentry configuration, so crashes are not linked to individual accounts.
We do not use advertising networks, third-party analytics SDKs, or data brokers.
7. Data Retention
We retain your data for as long as your account is active:
- Account and health data — Kept until you delete your account. When you delete your account (via Profile → Delete Account or by contacting us), all personal data — including your maps, emotion logs, profile, and push tokens — is permanently deleted from our systems within 30 days.
- Connection records — Records of any professional connection are kept while your account is active and are deleted when you delete your account.
- Connection security logs — Anonymised audit metadata about connection-code attempts and connection-management actions is automatically purged after 90 days.
- Crash reports (Sentry) — Automatically purged after 90 days per Sentry's default retention policy.
- Support emails — Retained for up to 2 years to allow us to follow up on open issues, then deleted.
8. International Data Transfers
Aemote is operated by an individual based in Australia. Our service providers may store or process your data outside your country of residence:
- Supabase stores data on Amazon Web Services infrastructure, which may be located in the United States or European Union depending on your project region. These transfers are covered by Standard Contractual Clauses (SCCs) as set out in Supabase's Data Processing Agreement.
- Sentry processes data in the United States. Sentry participates in EU–US Data Privacy Framework mechanisms.
- Expo processes push tokens in the United States.
By using Aemote, you acknowledge that your data may be transferred to and processed in countries outside your own. Where required by law, we ensure that appropriate safeguards (such as SCCs) are in place for such transfers.
9. Children
Aemote is intended for users aged 18 and over. We do not knowingly collect personal information from anyone under the age of 18. If you believe we have inadvertently collected data from a minor, please contact us and we will delete it promptly.
10. Your Rights
Depending on your jurisdiction, you have the following rights over your personal data:
- Access — Request a copy of the personal data we hold about you. Contact us at [email protected].
- Correct — Update inaccurate information directly from within the app (Profile screen).
- Export — Download your emotion logs as CSV or JSON from within the app (Settings → Data Export) at any time, at no cost. To request a full export of all data categories we hold about you (including profile data, maps, and feedback), contact us at [email protected].
- Delete — Delete your account and all associated data directly within the app (Profile → Delete Account). This is immediate and irreversible. You can also request deletion by contacting us.
- Restrict — Request that we limit processing of your data in certain circumstances (for example, while you contest its accuracy).
- Object — Object to processing carried out under our legitimate interests (such as anonymous crash analytics).
- Portability — Receive your data in a structured, machine-readable format. Use the in-app export, or contact us for a full data export.
- Withdraw consent — Where processing is based on your consent (including your health data), you may withdraw that consent at any time by deleting your account. Withdrawal does not affect the lawfulness of prior processing.
To exercise any of the above rights, email [email protected]. We will respond within 30 days.
If you are located in the EEA or UK and believe your data has been handled unlawfully, you have the right to lodge a complaint with your local data protection authority. In the UK this is the Information Commissioner's Office (ICO). In the EU, contact the supervisory authority in your member state.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or an in-app notification before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.
Continued use of Aemote after changes take effect constitutes your acceptance of the updated policy.
12. Contact Us
A Data Protection Officer (DPO) is not currently designated. Under GDPR Article 37, a DPO is required only where: (a) processing is carried out by a public authority; (b) core activities consist of large-scale systematic monitoring of individuals; or (c) core activities consist of large-scale processing of special category data. None of these conditions currently apply to Aemote. If the user base grows to a scale where condition (b) or (c) is triggered, or if features involving explicit medical data or systematic behavioural tracking are introduced, this policy will be updated and a DPO appointed accordingly.
If you have any questions about this Privacy Policy or how we handle your data, email us at [email protected] or get in touch via our support form.