Inner Belief← Home

Inner Belief Privacy Policy

Privacy Policy

Effective / last updated: 31 July 2026

Inner Belief is operated by RTT Lifestyle Coaching LLC and Brave Life LLC (together, "we", "us", "our"). This policy should be read together with our group-level privacy policy, available at https://www.iubenda.com/privacy-policy/77289164. The sections below describe how the Inner Belief website, platform, and mobile apps specifically collect and handle your information — including sensitive health information — and take precedence where they give more detail than the group policy.

1. Who this policy covers

This policy applies to everyone who uses Inner Belief: clients receiving therapy and coaching, practitioners providing it, and visitors to our website. It covers our website, our web application, and our iOS and Android mobile apps (the "Platform"). It does not change the separate User Agreement that governs your use of the Platform.

2. Information we collect

2.1. Account & identity

Your name, email address, and account role. If you sign in with Sign in with Apple or Google, we receive the basic profile information those services share; where you use Apple's Private Relay, we receive a relay email address rather than your personal one, and we treat it the same way. We capture your device time zone automatically on first launch so that session times, reminders, and bookings display correctly for you.

2.2. Health & clinical information

Because Inner Belief supports therapy, much of what you enter is sensitive health information. Depending on how you use the Platform, this can include:

  • Journal entries, including any you choose to share with your practitioner
  • Mood and wellness logs — mood, energy, sleep quality, anxiety, and free-text notes
  • Clinical questionnaires (PHQ-9 and GAD-7), including your answers, scores, and severity bands
  • Pre- and post-session check-ins, and check-ins around audio listening
  • Intake and matching answers used to match you with a suitable practitioner
  • Session notes written by your practitioner (some kept private to them, some shared with you)

2.3. Video sessions & recordings

Sessions take place over encrypted live video (provided by LiveKit). A session is only recorded when both you and your practitioner have consented in the session beforehand; you can decline, and unrecorded sessions are the default until consent is given. Where a session is recorded, the recording may be transcribed (using Deepgram) and used to generate an AI-assisted session summary to support your care. We describe how long these are kept in section 6.

2.4. Audio & content activity

Personalised audio that a practitioner records or uploads for you, and audio in our library. We log plays and completions so that features such as listening streaks work.

2.5. Messaging & community

Messages between you and your practitioner, and — if you take part — posts, replies, and @-mentions in community spaces. Community content is visible to other members of that space.

2.6. Payments & purchases

Card payments are processed by Stripe; we receive confirmation and limited details (such as the amount, date, and the last digits of the card) but not your full card number. In-app purchases made through the Apple App Store are processed by Apple, which shares a purchase confirmation with us; Apple's own handling of your payment details is governed by Apple's privacy policy.

2.7. Device & technical information

  • Push-notification device tokens (Apple Push Notification service / APNs and equivalents) so we can send you notifications — see section 5 for what notifications contain
  • On your device, our apps store your authentication tokens in the operating system's secure storage (SecureStore / Keychain) and remember your theme preference locally
  • Standard technical and usage data (such as log and diagnostic information) needed to operate and secure the Platform

3. How we use your information

  • To provide the Platform — accounts, matching, booking, sessions, messaging, audio, and self-tracking
  • To support your care — session summaries, shared notes, and progress tracking, available to you and your practitioner
  • To take payment and manage purchases, subscriptions, and refunds
  • To send you service and reminder notifications (see section 5)
  • To keep the Platform safe, prevent misuse, and meet our legal and regulatory obligations
  • To improve the Platform, using aggregated or de-identified data where possible

We do not sell your personal information, and we do not use your health information for advertising.

4. Keeping you safe: automated safety monitoring

Because we support people through therapy, your safety comes first. To help us respond if someone may be at risk of harm, certain information you enter — including journal entries, messages to your practitioner, wellbeing check-ins, and answers to clinical questionnaires (such as the self-harm question in the PHQ-9) — is automatically scanned for language that may indicate a crisis or a risk of harm to yourself or others.

Where the system flags a possible concern, it may be reviewed by our team and/or your practitioner, and you may be shown crisis-support resources. This is a deliberate duty-of-care measure: in this specific situation we prioritise your safety over the privacy of that content. We do not use this scanning for marketing, and it does not otherwise change how your information is protected under this policy. It is not a monitored emergency service — if you are in immediate danger, contact your local emergency number.

5. Health information, HIPAA, and our processors

We treat clinical information described in section 2.2–2.3 as protected health information and hold it to a HIPAA-aligned standard. Where a third party processes that information on our behalf, we put a Business Associate Agreement (BAA) or equivalent data-protection terms in place before relying on them. For example, our transcription provider (Deepgram) operates under an executed BAA.

Our email provider (Resend) is deliberately not given access to health information: for that reason, our emails and push notifications never contain the contents of your therapy, notes, or clinical data — they simply let you know something is waiting and link you back into the Platform, where the information stays protected behind your login.

6. Notifications and communications

We may contact you by in-app notification, email, and — if you allow it — push notification. As a standing rule, no health information ever leaves the Platform in a notification or email. A message might say, for instance, that you have a new message or a session reminder, and link you into the app; it will not include the content itself. You can adjust most notification preferences in your account settings, and control push notifications through your device settings.

7. How long we keep your information

We keep your account information for as long as your account is active, and personal and health information for as long as needed to provide the Platform and to meet legal, clinical-record, and regulatory obligations. Session recordings are retained for a limited period (currently around 90 days) and transcripts and summaries for longer (currently around 12 months), after which they are deleted automatically unless a longer period is required by law or clinical-record obligations. When information is no longer needed, we delete or de-identify it.

8. Who we share information with

We share information with your practitioner (or, for practitioners, with the clients they work with) as needed to deliver care, and with service providers who process data on our behalf under appropriate contracts. Our main processors are:

  • Stripe — card payments
  • Apple — Sign in with Apple, push notifications, and in-app purchases
  • Google — Google sign-in
  • LiveKit — live video sessions
  • Deepgram — transcription of recorded sessions (under a BAA)
  • Google Cloud — hosting and our database
  • Vercel — hosting of the web application
  • Resend — transactional email (no health information; see section 4)

Some of these providers are based outside your country, including in the United States. Where information is transferred internationally, we rely on appropriate safeguards (such as standard contractual clauses or equivalent mechanisms). We may also disclose information where required by law, to protect safety, or in connection with a business transfer.

9. How we protect your information

We use encryption in transit, access controls, and other technical and organisational measures appropriate to the sensitivity of the information. No system can be guaranteed perfectly secure, but we work to protect your information and to detect and respond to incidents. If a breach affects your personal data, we will notify you and any regulator as required by law.

10. Your rights

Depending on where you live, you may have rights to access, correct, export, restrict, object to the processing of, or delete your personal information, and to withdraw consent where we rely on it. You can exercise many of these directly in your account settings — including requesting deletion of your account and data — or by contacting us using the details in section 12. We will respond in line with applicable data protection laws.

11. Children

Inner Belief is not intended for children. You must be at least 18 years old to create an account and use the Platform. We do not knowingly collect information from anyone under 18; if you believe a minor has provided us information, please contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "last updated" date above and, where appropriate, notify you through the Platform. Your continued use of the Platform after an update means you accept the revised policy.

13. Contact us

If you have questions about this policy or how we handle your information, contact us at support@marisapeer.com. This policy is provided by RTT Lifestyle Coaching LLC and Brave Life LLC and is governed by the laws of England and Wales.

Inner Belief