Legal
Privacy Policy
Last updated: 24 August 2026
1. Who we are
Therapica ("we", "us") is an AI-guided psychological self-help platform. This policy explains how we handle your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable national law. For data-protection enquiries contact us via the contact form or directly by email at hello@therapica.app.
2. Data we collect
- Account data: username, email, display name, native language, avatar, bio.
- Assessment data: answers to validated scales (PHQ-9, GAD-7, PSS-10, C-SSRS, Rosenberg, WHO-5) and optional interview text.
- Therapy data: therapy plans, session progress, journaling entries, cards, conversations with Caelia, voice transcripts, and therapist notes.
- Technical data: IP address (for rate limiting), device and browser information, and strictly necessary cookies.
- Payment data: when Stripe is enabled, billing is handled entirely by Stripe — we do not store card numbers.
3. Legal bases (Art. 6 GDPR)
- Contract — to provide the self-therapy service you requested.
- Consent — for optional features (e.g., email notifications, voice processing) where you have opted in.
- Legitimate interest — to secure the service, prevent abuse, and improve reliability.
- Legal obligation — where we must retain data to comply with law.
4. How we use your data
To create and deliver your personalised therapy plan, generate sessions and cards, enable conversations with Caelia (text and voice), track progress, and provide safety resources when risk indicators are detected. We do not use your data for advertising and we do not sell it.
5. AI processing
Content generation and therapist conversations are processed by the configured LLM provider (e.g., OpenAI, Anthropic, or a self-hosted Ollama instance). Voice transcription and synthesis use the configured STT/TTS providers. Self-hosted deployments keep all processing on your own infrastructure.
6. Retention
We retain your data for as long as your account is active. You may delete your account at any time from Settings — this permanently removes your personal data from our servers. Backups are purged within 30 days.
7. Your rights (GDPR)
You have the right to access, rectify, erase, restrict, object to processing, and data portability. You can exercise these rights by:
- Using Settings → Privacy & GDPR → Download data (JSON) to export all your data.
- Using Settings → Delete account to erase your data.
- Contacting us via the contact form or at hello@therapica.app for any other request. We respond within 30 days.
You also have the right to lodge a complaint with your national supervisory authority.
8. Security
Data is encrypted in transit (TLS) and at rest where applicable. Access tokens are short-lived (15 min) and refresh tokens are stored as httpOnly cookies with Redis-backed rotation. We apply rate limiting and HMAC verification for webhooks.
9. International transfers
If you use the hosted service, data may be processed by sub-processors (e.g., LLM, Stripe, email) outside the EEA under Standard Contractual Clauses or adequacy decisions. Self-hosted deployments do not transfer data outside your infrastructure unless you configure external providers.
10. Changes
We will notify you of material changes via the app or email and update the "Last updated" date above.