WisemindApp Privacy Policy

Version 1.3. The current version is published in the app.

Effective from 26 September 2026.

This Policy explains how Digital Vanguard LLC processes personal data when you use the wisemindapp.com website and the WisemindApp web and mobile applications (the “Service”).

1. Who Is Responsible for Your Data

The operator or controller responsible for the principal functions of the Service is:

Digital Vanguard LLC
Date of incorporation: 8 January 2026

Registration number: 56381280

Tax identification number: 08313488

Address: Premises 239, 2/2 Anastas Mikoyan Street, Yerevan, Republic of Armenia

Privacy email: [email protected]

Additional email: [email protected]

Referred to below as the “Company” or “we”.

The EU GDPR applies to the processing described in this Policy where the Company offers the Service to people in the EEA or monitors their behaviour there. The UK GDPR applies on the equivalent basis where the Company offers the Service to people in the United Kingdom or monitors their behaviour there.

2. Roles of the Company and Therapists

2.1. The Company determines the design of the Service, its data fields and the principal purposes of processing required to operate WisemindApp.

2.2. A Therapist receives access to a Client’s records only after a separate action by the Client. When using that information in their own professional practice, the Therapist may be a separate data controller and is responsible for their own privacy information, lawful bases and professional obligations.

2.3. The Company does not determine diagnoses, treatment, clinical decisions or the Therapist’s external records. Questions about a Therapist’s use of information outside WisemindApp should be directed to that Therapist.

2.4. Where, in a particular situation, the Company processes data solely on a Therapist’s instructions, the data-processing provisions of the Terms of Use form part of the parties’ arrangement to the extent permitted by law.

3. Age

The Service is intended only for people aged 18 or over. We do not knowingly collect children’s data. If we learn that an account belongs to a minor, we will restrict it and take steps to delete the data unless the law requires otherwise.

4. Personal Data We Process

The data involved depends on your role and the features you use.

4.1. Account and Profile

4.2. Psychological Health and DBT Practice Data

This information may constitute health data and other special-category or sensitive personal data:

4.3. Contacts Added to a Safety Plan

The User may add a person’s name, relationship, telephone number and other available fields concerning a family member, friend or professional. This information relates to a third party. It is used for display in the User’s personal safety plan and is not made public.

The Company does not contact that person merely because their details have been added to the plan. If a separate feature for messaging a contact is introduced, the User will first be shown who will receive what information.

4.4. Interaction with a Therapist

4.5. DBT Groups

Through a Group, participants do not receive access to another participant’s diary card, worksheets, safety plan, email address or telephone number. Trainer contact details may be visible to participants.

4.6. Subscription and Payments

The Company does not receive a full payment-card number or security code. From Polar, Boosty or another provider identified at purchase, we may receive:

The payment platform independently processes data entered by the User directly on its page.

4.7. Technical and Security Data

4.8. Analytics

Amplitude and Google Analytics receive an internal account identifier (not the User’s email address or name), IP address, browser data and approximate location, usage events, screens opened and session parameters. The current implementation enables analytics from registration and treats it as part of the Service.

We do not send analytics systems the text of worksheets or the content of a diary card, safety plan, notes or messages; the names of target behaviours; scale values; a calculated state level; or other clinical values. Events connected with the crisis pathway (opening the “I’m overwhelmed” screen, sending an alert to a Therapist, or opening the safety plan) are sent only to Amplitude and not to Google Analytics. The transmitted events are controlled by an allow-list; an event not on that list is not sent.

A crisis-path event may itself reveal or permit an inference about mental health even where no clinical text or value is sent.

4.9. Emails and Enquiries

4.10. Update Notifications

If the User gives separate optional consent to update notifications, we use the email address and name from the account and, where delivery diagnostics are enabled for a particular mailing, information about email opens and link activity.

The content of records — the diary card, worksheets, safety plan, “I’m overwhelmed” alerts and messages — is never used for a mailing and does not affect its content. Consent is optional and does not affect access to the Service. The User may withdraw by using the “Unsubscribe” link in any such email.

Service messages — email verification, password recovery, invitations and responses, notices about access to records, payment messages and account-status messages — are not update mailings and are sent irrespective of this consent.

5. Where We Obtain Data

We obtain data:

6. Why We Process Data and Our Lawful Bases

6.1. Contract Performance and Provision of the Service

We use account data, settings, records, messages, connections, assignments and subscription metadata to register the User, provide features, synchronise records, manage access, deliver service messages and maintain a paid subscription.

For Users in the EEA, the lawful basis is taking steps at the User’s request before entering into a contract and performance of the contract under Article 6(1)(b) GDPR. The equivalent Article 6(1)(b) UK GDPR basis applies to Users in the United Kingdom. Where health data is involved, the additional Article 9 condition in section 6.2 is required.

6.2. Special-Category Data

We process psychological health and DBT practice data on the basis of the User’s separate explicit consent under Article 9(2)(a) GDPR or UK GDPR. The corresponding Article 6 basis for processing based on that consent is Article 6(1)(a). Account administration that is objectively necessary to provide the requested Service also relies on Article 6(1)(b). We do not use contract performance or legitimate interests to avoid the separate Article 9 condition.

Without this processing, we cannot provide the diary card, worksheets, state tracking, safety plan and related features.

For Users to whom Russian law applies, the required written or valid electronic form of consent must also be observed.

6.3. Therapist Access

Access by a particular Therapist is enabled through a separate action by the Client and is covered by the Client’s explicit consent to processing health data. The Client may withdraw access within the Service. Group membership is not consent to access individual records.

6.4. Security and Protection of Rights

We process limited technical, audit and legal records to prevent misuse, investigate incidents, evidence consent, protect Users, and establish, exercise or defend legal claims.

The Article 6 basis is performance of the contract where the processing is objectively necessary for security, the Company’s and Users’ legitimate interests in a secure Service under Article 6(1)(f), or compliance with a legal obligation under Article 6(1)(c), as applicable. We must balance legitimate interests against the User’s rights and freedoms. Where health data is strictly necessary for legal claims, Article 9(2)(f) may apply. We do not use legitimate interests as a substitute for explicit consent to ordinary processing of health data.

6.5. Analytics

Product analytics that does not involve special-category data may rely on the Company’s legitimate interests in developing, maintaining and protecting the Service under Article 6(1)(f), subject to a documented balancing assessment and the right to object, where the applicable ePrivacy/storage-and-access rule does not require consent. Where that rule requires consent, the associated personal-data processing relies on Article 6(1)(a). Acceptance of this Policy is not consent, and withdrawal cannot be made conditional on account deletion. Legitimate interests alone cannot justify analytics processing of crisis-path events that constitute or reveal health data; that processing also requires a specific Article 9 condition.

For EEA Users, the Company must assess the ePrivacy implementation and any narrowly available audience-measurement exception in each target country. For UK Users, analytics may avoid PECR consent only if the configured use falls fully within an applicable exception, including the statistical-purposes exception and its information and simple-objection conditions. Otherwise, analytics must be blocked until consent. The present product behaviour described in section 4.8 must be changed or the affected analytics disabled wherever the required consent or objection mechanism is absent.

6.6. Legal and Financial Obligations

We may retain limited contractual, payment and consent records for accounting and tax compliance, regulatory requirements, disputes and evidence of compliance. Depending on the purpose, the Article 6 basis is compliance with a legal obligation under Article 6(1)(c) or legitimate interests in establishing, exercising or defending legal claims under Article 6(1)(f). Where a legal claim necessarily involves health data, Article 9(2)(f) may apply.

6.7. Update Notifications

Information and promotional emails are sent only on the basis of separate consent under Article 6(1)(a) GDPR or UK GDPR, together with compliance with applicable electronic-marketing rules. Withdrawal ends the mailing and does not affect access to the Service or service messages.

7. Automated Decisions, Advertising and Artificial Intelligence

7.1. As at the effective date of this version, the Company does not use artificial intelligence to analyse User records and does not train models on User Content.

7.2. We do not make decisions based solely on automated processing that produce legal or similarly significant effects for the User.

7.3. We do not sell personal data, use clinical records for advertising or disclose them to advertising networks.

8. Who May Access Data

8.1. The User and Their Chosen Therapist

The Client sees their own records. A connected Therapist sees only the categories allowed by the Service’s access model. Individual Company personnel with administrative privileges may obtain access where necessary for support, security, incident investigation or legal compliance. Such access must be limited, logged and granted on a need-to-know basis.

8.2. Group Participants

Participants see names or pseudonyms and messages in the relevant Group. Trainers see information needed to run the Group, including membership, schedule, attendance, assignments and internal payment records. Access to individual health information is granted separately.

8.3. Providers

We engage providers only to the extent required for their function:

Providers may use their own sub-processors. Before sharing special-category data, the Company must enter into the necessary agreements, apply Article 28 GDPR/UK GDPR requirements where applicable, and verify that the transfer is lawful.

8.4. External Resources

Service materials may link to external websites or repositories. When the User follows a link, the browser sends ordinary technical information to that resource. The external resource operates under its own policy.

8.5. Public Authorities and Protection of Rights

We may disclose data where required by applicable law or a binding request from a competent authority, to protect life, to investigate an incident, or to protect the rights of the Company and Users. We assess the lawfulness of a request and, where possible, limit the disclosure.

9. International Transfers

9.1. The Company is established in Armenia, the principal database is hosted in Germany, and some providers are located or process data in the United States and other countries. Use of the Service may therefore involve international transfers.

9.2. For transfers from Armenia, the Company uses consent or necessity for the stated purposes, a country recognised as providing an adequate level of protection, or obtains authorisation from the competent authority and implements contractual safeguards where required.

9.3. A restricted transfer from the EEA must rely on a valid Chapter V GDPR mechanism. Where there is no applicable adequacy decision, this may require the European Commission’s Standard Contractual Clauses, an assessment of the law and practices of the destination country, and supplementary technical, contractual or organisational measures. A restricted transfer from the United Kingdom must similarly rely on UK adequacy regulations or an appropriate safeguard, such as the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs, together with a transfer risk assessment/data protection test and supplementary measures where required.

9.4. Before processing data of Russian citizens, the Company must meet applicable requirements on localisation, notice of processing and separate notice of international transfer. Publishing this Policy does not itself satisfy those steps.

9.5. The User may request general information about an applicable transfer mechanism at [email protected] and, where required by law, a copy or description of the relevant safeguards, with redactions necessary to protect security, confidential information and the rights of others.

10. Retention Periods

We retain data no longer than necessary for the stated purpose, performance of the contract, security and mandatory legal requirements.

10.1. Active Account

Profile data, settings, practice records, connections, assignments and messages are retained while the account is active and the relevant feature is used.

10.2. Account Deletion

Following a deletion request, the account is deactivated for 30 calendar days. During that period, the data remains in place and the User may cancel deletion using a dedicated button. Merely signing in does not cancel the request.

At the end of the period, the profile and individual data are deleted or anonymised except for the categories described below.

10.3. Data That May Remain After Deletion

Retention may be extended only for the duration of a specific dispute, mandatory retention period or lawful requirement. Data is then deleted or irreversibly anonymised.

10.4. Crisis Alerts and Notifications

An unanswered alert is shown as active for no more than 24 hours. A notification of a crisis event may be retained for up to 180 days and is then deleted under the technical deletion cycle. The fact that the event occurred may remain in the Client’s history until account deletion or be deleted earlier following a lawful request.

10.5. Backups

Our database provider, Supabase, creates backups to the extent included in the project’s active plan. Where backups are created, deleted data may remain in an isolated copy until scheduled overwriting — normally up to 7, 14 or 30 days depending on the plan. Backups are used only for disaster recovery and are not returned to ordinary processing except where system restoration is required.

10.6. Analytics

User and event data in Amplitude and Google Analytics is retained for the period configured for the relevant project and no longer than necessary for the analytics purpose. Irreversibly aggregated reports that no longer relate to an identifiable User may be kept longer.

10.7. Copy on Your Device

If you use the WisemindApp mobile application, an encrypted copy of your safety plan and the texts of skills from the library is stored on your device so that the plan is available offline. The encryption key is kept in the device’s secure storage, is not included in backups and does not leave the device: a copy transferred to another telephone through a backup cannot be opened and is deleted on the first attempt to read it.

This copy is stored only on your device. It is not sent to us, our providers or third parties, is not used for analytics, and is used only to display the plan and skills without an internet connection.

The copy is deleted when you sign out of the account, sign in to a different account in the app, request account deletion, or uninstall the app from the device. Loss of connectivity and session expiry do not delete the copy; otherwise the safety plan could be unavailable precisely when it is needed.

If someone else can access your device, they may be able to see your safety plan in the app while offline and without signing in. Protect your device with a passcode or biometrics.

11. User Rights

Where the GDPR or UK GDPR applies, the User has the right, subject to the conditions and exceptions in the law, to:

These rights are not absolute. For example, erasure does not apply to data that must be retained to comply with a legal obligation or that is required to establish, exercise or defend legal claims.

An export feature may not be available within the Service. A request may be sent to [email protected]. We may request reasonable proof of identity and will not disclose another person’s data.

For requests governed by the GDPR or UK GDPR, we respond without undue delay and in any event within one month of receiving the request. Where permitted because of the complexity or number of requests, this period may be extended by up to two further months; we will tell the User within the first month and explain the reason. If we do not act on a request, we will explain why and describe the available complaint and judicial-remedy routes. The shorter applicable deadline is followed where another applicable law requires it. Under Armenian law, access is generally provided within five working days after a valid written request.

12. Withdrawal of Consent for Health Data

12.1. Consent may be withdrawn by deleting the account or by emailing [email protected]. Access for a particular Therapist is withdrawn separately in the access settings.

12.2. Following withdrawal, the Company stops processing based solely on consent and deletes the relevant data within the period required by applicable law unless there is another mandatory basis for limited retention.

12.3. Withdrawal of consent to health-data processing makes the diary card, worksheets, state tracking, safety plan and related features unavailable. It does not affect the lawfulness of processing before withdrawal.

13. Cookies and Analytics

13.1. Necessary cookies are used for sign-in, security, session continuity, language selection and interface operation. The Service may not work without them.

13.2. Amplitude and Google Analytics use cookies or similar identifiers for analytics. The current implementation enables analytics at registration and does not offer a separate on/off choice. This factual description is not a claim that the design satisfies EEA or UK storage-and-access rules; section 4.8 identifies the country-by-country assessment and the consent or simple-objection mechanism required before the relevant analytics is used there.

13.3. The User may restrict or delete cookies using browser or device controls; this may affect the Service but does not disable server-side analytics. Following account deletion, no new events are sent to analytics systems. Event data already transmitted is not retrospectively deleted or altered: it is linked only to an internal identifier, which after account deletion is no longer mapped to a person, and is retained for the configured period of the relevant analytics project.

13.4. We do not use advertising cookies and do not send clinical content to analytics providers (section 4.8).

14. Security

We use measures appropriate to the sensitive nature of the data, including:

No system can provide absolute security. The User must also protect their device, email account and password.

15. Incidents

Following a confirmed personal-data breach or other incident, the Company assesses the risk, takes steps to contain the effects, and notifies competent authorities and Users in the form and within the periods required by applicable law. Where the GDPR or UK GDPR requires notification to a supervisory authority, it must be made without undue delay and, where feasible, within 72 hours after the Company becomes aware of the breach. Affected Users must be informed without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

16. Users in the EEA and United Kingdom

16.1. The Company intentionally offers the Service to people in the EEA and United Kingdom. Accordingly, GDPR and UK GDPR obligations apply to the relevant processing by reason of territorial scope; they are not applied merely by contractual choice.

16.2. Health data is processed on the basis of explicit consent under Article 9(2)(a) GDPR or UK GDPR together with the applicable Article 6 basis described in section 6. The rights described in section 11 apply.

16.3. Before beginning the intended high-risk processing, the Company must complete and document a data protection impact assessment under Article 35 GDPR/UK GDPR, including the processing of health data, crisis-pathway events, Therapist access, analytics and international transfers.

16.4. The Article 27 representatives identified in section 1 must be appointed and their contact details published before the relevant targeted offering begins. The DPO assessment described in section 1 must also be completed and documented.

17. Changes to This Policy

We may update this Policy when features, providers or the law change. We notify Users of material changes in the Service or by email. Fresh, separate consent is requested where the law requires it because of a new purpose, data category or recipient.

Previous versions are retained to the extent required to establish which version applied at a particular time.

18. Complaints and Authorities

You may contact us first at [email protected], but doing so is not a condition of making a complaint directly to an authority where the law gives that right.

Depending on the applicable law, a complaint may be made to:

© 2026 Digital Vanguard LLC