WisemindApp Privacy Policy
Version 1.3. The current version is published in the app.
Effective from 26 September 2026.
This Policy explains how Digital Vanguard LLC processes personal data when you use the wisemindapp.com website and the WisemindApp web and mobile applications (the “Service”).
1. Who Is Responsible for Your Data
The operator or controller responsible for the principal functions of the Service is:
Digital Vanguard LLC
Date of incorporation: 8 January 2026
Registration number: 56381280
Tax identification number: 08313488
Address: Premises 239, 2/2 Anastas Mikoyan Street, Yerevan, Republic of Armenia
Privacy email: [email protected]
Additional email: [email protected]
Referred to below as the “Company” or “we”.
The EU GDPR applies to the processing described in this Policy where the Company offers the Service to people in the EEA or monitors their behaviour there. The UK GDPR applies on the equivalent basis where the Company offers the Service to people in the United Kingdom or monitors their behaviour there.
2. Roles of the Company and Therapists
2.1. The Company determines the design of the Service, its data fields and the principal purposes of processing required to operate WisemindApp.
2.2. A Therapist receives access to a Client’s records only after a separate action by the Client. When using that information in their own professional practice, the Therapist may be a separate data controller and is responsible for their own privacy information, lawful bases and professional obligations.
2.3. The Company does not determine diagnoses, treatment, clinical decisions or the Therapist’s external records. Questions about a Therapist’s use of information outside WisemindApp should be directed to that Therapist.
2.4. Where, in a particular situation, the Company processes data solely on a Therapist’s instructions, the data-processing provisions of the Terms of Use form part of the parties’ arrangement to the extent permitted by law.
3. Age
The Service is intended only for people aged 18 or over. We do not knowingly collect children’s data. If we learn that an account belongs to a minor, we will restrict it and take steps to delete the data unless the law requires otherwise.
4. Personal Data We Process
The data involved depends on your role and the features you use.
4.1. Account and Profile
- email address and email verification status;
- a cryptographically protected representation of the password, managed by the authentication system;
- name, display name or pseudonym;
- date of birth, if provided by the User;
- country, region, language and time zone;
- Client or Therapist role;
- profile photograph, if added by the User;
- dates of registration, last activity, deactivation and deletion;
- interface and notification settings.
4.2. Psychological Health and DBT Practice Data
This information may constitute health data and other special-category or sensitive personal data:
- diary card, emotional state, impulses, urges and intensity of experiences;
- target behaviours and entries about them;
- recorded skills, exercises and practice history;
- answers in worksheets and other free-text entries;
- homework, assignments, completion status and comments;
- safety plan, warning signs, reasons for living, distractions and safety measures;
- the fact, time, recipient, status and withdrawal of an “I’m overwhelmed” alert;
- Therapist notes about a Client, where that feature is used;
- history of granting and withdrawing a Therapist’s access.
4.3. Contacts Added to a Safety Plan
The User may add a person’s name, relationship, telephone number and other available fields concerning a family member, friend or professional. This information relates to a third party. It is used for display in the User’s personal safety plan and is not made public.
The Company does not contact that person merely because their details have been added to the plan. If a separate feature for messaging a contact is introduced, the User will first be shown who will receive what information.
4.4. Interaction with a Therapist
- invitations, access requests and responses;
- Client–Therapist connections and their duration;
- assigned work, schedule and events;
- direct messages and technical read-status data;
- notifications of access changes and other events.
4.5. DBT Groups
- Group name and settings;
- participant’s name or pseudonym and role;
- membership and dates of joining and leaving;
- messages, edit information and read status;
- session schedule, attendance and homework;
- internal records of Group participation payments, if the Therapist uses this feature;
- trainer and facilitator information.
Through a Group, participants do not receive access to another participant’s diary card, worksheets, safety plan, email address or telephone number. Trainer contact details may be visible to participants.
4.6. Subscription and Payments
The Company does not receive a full payment-card number or security code. From Polar, Boosty or another provider identified at purchase, we may receive:
- purchaser, order and subscription identifiers;
- plan, currency and amount;
- payment, trial and paid-period status;
- start, renewal, cancellation and access-end dates;
- information about a refund, dispute or payment error;
- limited payment and tax metadata required for support and accounting.
The payment platform independently processes data entered by the User directly on its page.
4.7. Technical and Security Data
- IP address;
- device type, operating system, browser and app version;
- technical identifiers, cookies, session and device data;
- request, sign-in and action times;
- error, security, notification-delivery and audit logs without intentionally including the content of clinical records;
- information about suspicious activity and attempted unauthorised access.
4.8. Analytics
Amplitude and Google Analytics receive an internal account identifier (not the User’s email address or name), IP address, browser data and approximate location, usage events, screens opened and session parameters. The current implementation enables analytics from registration and treats it as part of the Service.
We do not send analytics systems the text of worksheets or the content of a diary card, safety plan, notes or messages; the names of target behaviours; scale values; a calculated state level; or other clinical values. Events connected with the crisis pathway (opening the “I’m overwhelmed” screen, sending an alert to a Therapist, or opening the safety plan) are sent only to Amplitude and not to Google Analytics. The transmitted events are controlled by an allow-list; an event not on that list is not sent.
A crisis-path event may itself reveal or permit an inference about mental health even where no clinical text or value is sent.
4.9. Emails and Enquiries
- sender address, subject, content and attachments of a support enquiry;
- email delivery and error information;
- the fact and time an email was opened where the email client loads a remote image;
- link activity where that diagnostic feature is enabled.
4.10. Update Notifications
If the User gives separate optional consent to update notifications, we use the email address and name from the account and, where delivery diagnostics are enabled for a particular mailing, information about email opens and link activity.
The content of records — the diary card, worksheets, safety plan, “I’m overwhelmed” alerts and messages — is never used for a mailing and does not affect its content. Consent is optional and does not affect access to the Service. The User may withdraw by using the “Unsubscribe” link in any such email.
Service messages — email verification, password recovery, invitations and responses, notices about access to records, payment messages and account-status messages — are not update mailings and are sent irrespective of this consent.
5. Where We Obtain Data
We obtain data:
- directly from the User;
- from a connected Therapist, for example when they assign work or record schedule, attendance or notes;
- from other participants, for example when they post a message in a shared Group;
- automatically from the device, browser and servers;
- from payment and email providers;
- from directories of emergency numbers used for the selected country.
6. Why We Process Data and Our Lawful Bases
6.1. Contract Performance and Provision of the Service
We use account data, settings, records, messages, connections, assignments and subscription metadata to register the User, provide features, synchronise records, manage access, deliver service messages and maintain a paid subscription.
For Users in the EEA, the lawful basis is taking steps at the User’s request before entering into a contract and performance of the contract under Article 6(1)(b) GDPR. The equivalent Article 6(1)(b) UK GDPR basis applies to Users in the United Kingdom. Where health data is involved, the additional Article 9 condition in section 6.2 is required.
6.2. Special-Category Data
We process psychological health and DBT practice data on the basis of the User’s separate explicit consent under Article 9(2)(a) GDPR or UK GDPR. The corresponding Article 6 basis for processing based on that consent is Article 6(1)(a). Account administration that is objectively necessary to provide the requested Service also relies on Article 6(1)(b). We do not use contract performance or legitimate interests to avoid the separate Article 9 condition.
Without this processing, we cannot provide the diary card, worksheets, state tracking, safety plan and related features.
For Users to whom Russian law applies, the required written or valid electronic form of consent must also be observed.
6.3. Therapist Access
Access by a particular Therapist is enabled through a separate action by the Client and is covered by the Client’s explicit consent to processing health data. The Client may withdraw access within the Service. Group membership is not consent to access individual records.
6.4. Security and Protection of Rights
We process limited technical, audit and legal records to prevent misuse, investigate incidents, evidence consent, protect Users, and establish, exercise or defend legal claims.
The Article 6 basis is performance of the contract where the processing is objectively necessary for security, the Company’s and Users’ legitimate interests in a secure Service under Article 6(1)(f), or compliance with a legal obligation under Article 6(1)(c), as applicable. We must balance legitimate interests against the User’s rights and freedoms. Where health data is strictly necessary for legal claims, Article 9(2)(f) may apply. We do not use legitimate interests as a substitute for explicit consent to ordinary processing of health data.
6.5. Analytics
Product analytics that does not involve special-category data may rely on the Company’s legitimate interests in developing, maintaining and protecting the Service under Article 6(1)(f), subject to a documented balancing assessment and the right to object, where the applicable ePrivacy/storage-and-access rule does not require consent. Where that rule requires consent, the associated personal-data processing relies on Article 6(1)(a). Acceptance of this Policy is not consent, and withdrawal cannot be made conditional on account deletion. Legitimate interests alone cannot justify analytics processing of crisis-path events that constitute or reveal health data; that processing also requires a specific Article 9 condition.
For EEA Users, the Company must assess the ePrivacy implementation and any narrowly available audience-measurement exception in each target country. For UK Users, analytics may avoid PECR consent only if the configured use falls fully within an applicable exception, including the statistical-purposes exception and its information and simple-objection conditions. Otherwise, analytics must be blocked until consent. The present product behaviour described in section 4.8 must be changed or the affected analytics disabled wherever the required consent or objection mechanism is absent.
6.6. Legal and Financial Obligations
We may retain limited contractual, payment and consent records for accounting and tax compliance, regulatory requirements, disputes and evidence of compliance. Depending on the purpose, the Article 6 basis is compliance with a legal obligation under Article 6(1)(c) or legitimate interests in establishing, exercising or defending legal claims under Article 6(1)(f). Where a legal claim necessarily involves health data, Article 9(2)(f) may apply.
6.7. Update Notifications
Information and promotional emails are sent only on the basis of separate consent under Article 6(1)(a) GDPR or UK GDPR, together with compliance with applicable electronic-marketing rules. Withdrawal ends the mailing and does not affect access to the Service or service messages.
7. Automated Decisions, Advertising and Artificial Intelligence
7.1. As at the effective date of this version, the Company does not use artificial intelligence to analyse User records and does not train models on User Content.
7.2. We do not make decisions based solely on automated processing that produce legal or similarly significant effects for the User.
7.3. We do not sell personal data, use clinical records for advertising or disclose them to advertising networks.
8. Who May Access Data
8.1. The User and Their Chosen Therapist
The Client sees their own records. A connected Therapist sees only the categories allowed by the Service’s access model. Individual Company personnel with administrative privileges may obtain access where necessary for support, security, incident investigation or legal compliance. Such access must be limited, logged and granted on a need-to-know basis.
8.2. Group Participants
Participants see names or pseudonyms and messages in the relevant Group. Trainers see information needed to run the Group, including membership, schedule, attendance, assignments and internal payment records. Access to individual health information is granted separately.
8.3. Providers
We engage providers only to the extent required for their function:
- Supabase — PostgreSQL database, authentication, storage and related cloud functions; the main selected project region is Frankfurt, Germany;
- Vercel, Inc. — web-application hosting, content delivery, server functions, and network and technical logs; processing may take place in the United States and other locations used by Vercel and its providers;
- Resend — delivery of service emails and delivery information; processing may take place in the United States and through Resend’s providers;
- Sentry — technical error reports in the European Union; reports are retained for 90 days and personal data and record content are removed before submission;
- Amplitude — product analytics; the processing location depends on whether the project is configured for the United States or EU zone;
- Google Analytics — web analytics and cookies; processing is performed by Google group companies and their providers;
- Polar Software, Inc. — international sale of subscriptions as merchant of record, billing, taxes, refunds and related metadata;
- Boosty — processing a payment made available through that platform and related metadata;
- other providers expressly disclosed to the User before a new feature is enabled.
Providers may use their own sub-processors. Before sharing special-category data, the Company must enter into the necessary agreements, apply Article 28 GDPR/UK GDPR requirements where applicable, and verify that the transfer is lawful.
8.4. External Resources
Service materials may link to external websites or repositories. When the User follows a link, the browser sends ordinary technical information to that resource. The external resource operates under its own policy.
8.5. Public Authorities and Protection of Rights
We may disclose data where required by applicable law or a binding request from a competent authority, to protect life, to investigate an incident, or to protect the rights of the Company and Users. We assess the lawfulness of a request and, where possible, limit the disclosure.
9. International Transfers
9.1. The Company is established in Armenia, the principal database is hosted in Germany, and some providers are located or process data in the United States and other countries. Use of the Service may therefore involve international transfers.
9.2. For transfers from Armenia, the Company uses consent or necessity for the stated purposes, a country recognised as providing an adequate level of protection, or obtains authorisation from the competent authority and implements contractual safeguards where required.
9.3. A restricted transfer from the EEA must rely on a valid Chapter V GDPR mechanism. Where there is no applicable adequacy decision, this may require the European Commission’s Standard Contractual Clauses, an assessment of the law and practices of the destination country, and supplementary technical, contractual or organisational measures. A restricted transfer from the United Kingdom must similarly rely on UK adequacy regulations or an appropriate safeguard, such as the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs, together with a transfer risk assessment/data protection test and supplementary measures where required.
9.4. Before processing data of Russian citizens, the Company must meet applicable requirements on localisation, notice of processing and separate notice of international transfer. Publishing this Policy does not itself satisfy those steps.
9.5. The User may request general information about an applicable transfer mechanism at [email protected] and, where required by law, a copy or description of the relevant safeguards, with redactions necessary to protect security, confidential information and the rights of others.
10. Retention Periods
We retain data no longer than necessary for the stated purpose, performance of the contract, security and mandatory legal requirements.
10.1. Active Account
Profile data, settings, practice records, connections, assignments and messages are retained while the account is active and the relevant feature is used.
10.2. Account Deletion
Following a deletion request, the account is deactivated for 30 calendar days. During that period, the data remains in place and the User may cancel deletion using a dedicated button. Merely signing in does not cancel the request.
At the end of the period, the profile and individual data are deleted or anonymised except for the categories described below.
10.3. Data That May Remain After Deletion
- records of acceptance of the Terms and the giving or withdrawal of consent — for as long as necessary to establish which version applied, and longer where required by law or an ongoing dispute;
- minimal audit and security records — for a reasonable period required for security and legal obligations;
- accounting, tax and payment information — for the mandatory period and the duration of a payment dispute;
- messages in shared or direct conversations — without an active link to the deleted profile, while required by other participants and for conversation integrity; the User may request earlier deletion, which is assessed against the rights of other participants;
- a Group created by a Therapist, its schedule, attendance records and internal payment log may remain for other participants, while the deleted Therapist’s profile is unlinked;
- information required to establish, exercise or defend a particular legal claim — until that claim is finally resolved.
Retention may be extended only for the duration of a specific dispute, mandatory retention period or lawful requirement. Data is then deleted or irreversibly anonymised.
10.4. Crisis Alerts and Notifications
An unanswered alert is shown as active for no more than 24 hours. A notification of a crisis event may be retained for up to 180 days and is then deleted under the technical deletion cycle. The fact that the event occurred may remain in the Client’s history until account deletion or be deleted earlier following a lawful request.
10.5. Backups
Our database provider, Supabase, creates backups to the extent included in the project’s active plan. Where backups are created, deleted data may remain in an isolated copy until scheduled overwriting — normally up to 7, 14 or 30 days depending on the plan. Backups are used only for disaster recovery and are not returned to ordinary processing except where system restoration is required.
10.6. Analytics
User and event data in Amplitude and Google Analytics is retained for the period configured for the relevant project and no longer than necessary for the analytics purpose. Irreversibly aggregated reports that no longer relate to an identifiable User may be kept longer.
10.7. Copy on Your Device
If you use the WisemindApp mobile application, an encrypted copy of your safety plan and the texts of skills from the library is stored on your device so that the plan is available offline. The encryption key is kept in the device’s secure storage, is not included in backups and does not leave the device: a copy transferred to another telephone through a backup cannot be opened and is deleted on the first attempt to read it.
This copy is stored only on your device. It is not sent to us, our providers or third parties, is not used for analytics, and is used only to display the plan and skills without an internet connection.
The copy is deleted when you sign out of the account, sign in to a different account in the app, request account deletion, or uninstall the app from the device. Loss of connectivity and session expiry do not delete the copy; otherwise the safety plan could be unavailable precisely when it is needed.
If someone else can access your device, they may be able to see your safety plan in the app while offline and without signing in. Protect your device with a passcode or biometrics.
11. User Rights
Where the GDPR or UK GDPR applies, the User has the right, subject to the conditions and exceptions in the law, to:
- obtain confirmation of processing and access to personal data, including a copy;
- have inaccurate data rectified and incomplete data completed;
- have personal data erased;
- restrict processing;
- receive data provided by the User in a structured, commonly used and machine-readable format, and have it transmitted to another controller where technically feasible, when the right to portability applies;
- object to processing based on legitimate interests, including profiling based on those interests;
- withdraw consent at any time, as easily as it was given, without affecting the lawfulness of processing before withdrawal;
- withdraw a particular Therapist’s access;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to the exceptions in law;
- lodge a complaint with a competent supervisory authority and seek a judicial remedy.
These rights are not absolute. For example, erasure does not apply to data that must be retained to comply with a legal obligation or that is required to establish, exercise or defend legal claims.
An export feature may not be available within the Service. A request may be sent to [email protected]. We may request reasonable proof of identity and will not disclose another person’s data.
For requests governed by the GDPR or UK GDPR, we respond without undue delay and in any event within one month of receiving the request. Where permitted because of the complexity or number of requests, this period may be extended by up to two further months; we will tell the User within the first month and explain the reason. If we do not act on a request, we will explain why and describe the available complaint and judicial-remedy routes. The shorter applicable deadline is followed where another applicable law requires it. Under Armenian law, access is generally provided within five working days after a valid written request.
12. Withdrawal of Consent for Health Data
12.1. Consent may be withdrawn by deleting the account or by emailing [email protected]. Access for a particular Therapist is withdrawn separately in the access settings.
12.2. Following withdrawal, the Company stops processing based solely on consent and deletes the relevant data within the period required by applicable law unless there is another mandatory basis for limited retention.
12.3. Withdrawal of consent to health-data processing makes the diary card, worksheets, state tracking, safety plan and related features unavailable. It does not affect the lawfulness of processing before withdrawal.
13. Cookies and Analytics
13.1. Necessary cookies are used for sign-in, security, session continuity, language selection and interface operation. The Service may not work without them.
13.2. Amplitude and Google Analytics use cookies or similar identifiers for analytics. The current implementation enables analytics at registration and does not offer a separate on/off choice. This factual description is not a claim that the design satisfies EEA or UK storage-and-access rules; section 4.8 identifies the country-by-country assessment and the consent or simple-objection mechanism required before the relevant analytics is used there.
13.3. The User may restrict or delete cookies using browser or device controls; this may affect the Service but does not disable server-side analytics. Following account deletion, no new events are sent to analytics systems. Event data already transmitted is not retrospectively deleted or altered: it is linked only to an internal identifier, which after account deletion is no longer mapped to a person, and is retained for the configured period of the relevant analytics project.
13.4. We do not use advertising cookies and do not send clinical content to analytics providers (section 4.8).
14. Security
We use measures appropriate to the sensitive nature of the data, including:
- encryption in transit and available storage-encryption controls;
- row-level access controls in the database;
- authentication and restricted administrative privileges;
- least-privilege access;
- logging of material actions without intentionally copying clinical content into technical logs;
- backup and recovery procedures;
- updates, access reviews and incident response.
No system can provide absolute security. The User must also protect their device, email account and password.
15. Incidents
Following a confirmed personal-data breach or other incident, the Company assesses the risk, takes steps to contain the effects, and notifies competent authorities and Users in the form and within the periods required by applicable law. Where the GDPR or UK GDPR requires notification to a supervisory authority, it must be made without undue delay and, where feasible, within 72 hours after the Company becomes aware of the breach. Affected Users must be informed without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
16. Users in the EEA and United Kingdom
16.1. The Company intentionally offers the Service to people in the EEA and United Kingdom. Accordingly, GDPR and UK GDPR obligations apply to the relevant processing by reason of territorial scope; they are not applied merely by contractual choice.
16.2. Health data is processed on the basis of explicit consent under Article 9(2)(a) GDPR or UK GDPR together with the applicable Article 6 basis described in section 6. The rights described in section 11 apply.
16.3. Before beginning the intended high-risk processing, the Company must complete and document a data protection impact assessment under Article 35 GDPR/UK GDPR, including the processing of health data, crisis-pathway events, Therapist access, analytics and international transfers.
16.4. The Article 27 representatives identified in section 1 must be appointed and their contact details published before the relevant targeted offering begins. The DPO assessment described in section 1 must also be completed and documented.
17. Changes to This Policy
We may update this Policy when features, providers or the law change. We notify Users of material changes in the Service or by email. Fresh, separate consent is requested where the law requires it because of a new purpose, data category or recipient.
Previous versions are retained to the extent required to establish which version applied at a particular time.
18. Complaints and Authorities
You may contact us first at [email protected], but doing so is not a condition of making a complaint directly to an authority where the law gives that right.
Depending on the applicable law, a complaint may be made to:
- the Personal Data Protection Agency of the Republic of Armenia;
- Roskomnadzor, where Russian law applies;
- for the EEA, a competent supervisory authority, including the authority in the country of the User’s habitual residence, place of work or the place of the alleged infringement;
- for the United Kingdom, the UK data-protection supervisory authority.
© 2026 Digital Vanguard LLC