Back to Home
Legal Center

🔐 Privacy Policy

Version: 3.0 • Effective Date: July 13, 2026 • Last Updated: July 13, 2026

1. Introduction

FaceofMind is a mental wellness platform that helps you track your mood, journal your thoughts, and connect with professional psychologists. This privacy policy explains how we collect, use, protect, and share your information.

Important DisclaimerFaceofMind is a wellness companion, not a replacement for therapy. It is designed to help you track your mental health between professional therapy sessions.

2. Who We Are

Platform NameFaceofMind
HeadquartersCebu City, Philippines
Data Protection Officerprivacy@faceofmind.com
Mobile App AvailabilityiOS (Apple App Store) & Android (Google Play Store)

3. What Data We Collect

3.1Information You Provide Directly

Wellness Seeker Account Registration & Profile Setup:

  • Name (optional for wellness use)
  • Email address & securely hashed password
  • Date of birth (age verification)
  • Phone number (with country dial code)
  • Gender (or Prefer Not to Say)
  • Location (Country, Region, City, Barangay)
  • Timezone & UTC offset

Professional Account Registration (Psychologists & Therapists):

  • Full name
  • Professional email address
  • Password (securely hashed)
  • Professional license number
  • Clinic, organization, or employer
  • Practice location & clinic coordinates (GPS)
  • Specialization and years of experience

Professional information is collected solely to verify eligibility, operate professional accounts, and facilitate clinical services on the platform.

Wellness Features:

  • Daily mood logs (Excellent, Good, Okay, Bad, Terrible)
  • Mood triggers (stress, loneliness, relationships, etc.)
  • Journal entries (encrypted, you control sharing)
  • Sleep quality ratings & physical energy levels
  • Social connection feelings & self-confidence
  • Future optimism ratings
Voice & Audio Data
  • Recordings during AI sessions
  • Transcriptions (on-device or server)
  • Pitch, tempo, shakiness, loudness
Consultation Data
  • Booking history via QR connection
  • Psychologist session notes
  • Consultation feedback

3.2Information We Collect Automatically

App Usage Data

Sessions, timestamps, feature interaction patterns (mood tracking, journaling, AI conversations), and duration of use.

Device Information

Device model (iPhone, Android), operating system version, app version, performance metrics, and crash logs.

Network & Location

IP address, network connection type (WiFi, cellular), and coarse geolocation (country or region level only).

3.3Data From Psychologists (If You Connect)

If you scan your psychologist's unique QR code to link your accounts, your psychologist will be able to review:

  • Daily mood logs
  • Voice analysis summaries
  • Emotion detection results
  • Journal insights (themes, cognitive distortions)
  • AI session summaries
  • Consultation history
🔒 Your raw journal text is NOT shared with your psychologist unless you explicitly enable it.

4. What Data We DON'T Collect

To ensure complete digital security and privacy, we explicitly state that we **do NOT** collect or access:

Precise GPS location data (except for registered practice coordinates provided by psychologists)
Contact lists or phone book directories
Calendar items or external email accounts
Browsing histories across other platforms
Device tracking identifiers (IDFA, GAID)
Biometric profiles (beyond dynamic emotion values)
Payment details (handled entirely by Stripe)

Do Not Track (DNT) Signals: We respect Do Not Track signals. However, our platform does not use tracking cookies or behavioral advertising, so DNT is automatically honored.

Cookie Usage: FaceofMind does not use cookies for tracking or advertising. We only use essential technical cookies/storage for account session maintenance. Read our full Cookie Policy.

5. How We Encrypt Your Data

5.1 Encryption at Rest (Storage)

All personal data stored on our servers is encrypted using AES-256-GCM encryption, an industry-standard authenticated encryption algorithm used to protect sensitive data.

• Encryption Standard: AES-256-GCM

• Key Management: Managed Key Management Service (KMS)

• Key Rotation: Industry-standard rotation protocols

What this means: Even in the event of an infrastructure breach, data remains unreadable. Access to decrypted records is restricted to authorized users with appropriate permissions and patient authorization.

5.2 Encryption in Transit (Network)

All communications between your mobile application and our secure servers utilize secure pathways:

TLS 1.3: Modern high-security cipher suites only
Certificate Pinning: Hardcoded certificates prevent man-in-the-middle exploits

5.3 Mood Data Isolation

Mood logs, journals, and notes use distinct keys per patient. Compromising a single key will not affect any other patient's data.

5.4 Voice Data Processing Safeties

Voice Analysis:

Voice recordings are transmitted over encrypted connections and encrypted immediately upon upload. Audio files are retained for 12 months for voice analysis, and text transcriptions for 24 months. You can request instant deletion at any time.

6. Data Retention & Deletion

6.1 How Long We Keep Your Data

Data TypeRetention PeriodWhy
Mood logs24 months (or deletion request)Clinical reference for therapy
Journal entries24 months (or deletion request)Your personal records
AI session summaries24 months (or deletion request)Trend analysis
Voice recordings12 monthsVoice tone analysis
Voice transcriptions24 monthsReference for therapy
Emotion detection results24 monthsTrend analysis
Consultation records7 yearsLegal/compliance requirement
Activity logs24 monthsSecurity audit trails
Device/usage data12 monthsPerformance optimization

6.2 Deleting Your Account

If you choose to delete your account:

  • All mood logs, journal entries, voice recordings, and activity logs are permanently purged from all backups within 30 days.
  • Consultation records are legally required to be retained for 7 years.
  • Disconnecting from a psychologist stops new sharing, but past shared data remains visible for clinical care continuity.

6.3 Requesting Deletion

To request manual purging or export of your account details, you may reach out directly via:

Email Address: privacy@faceofmind.com

Subject Line: "Data Deletion Request"

Timeline: Acknowledged within 10 days; deletion finalized in 30 days.

7. Access Logging & Audit Trails

7.1 What We Log

FaceofMind maintains comprehensive audit logs of all patient data access. Every time a psychologist accesses your mental health data, we record:

  • WHO: Psychologist name & UUID
  • WHEN: Exact timestamp (ms precision)
  • WHAT: Data accessed (mood, journals, etc)
  • HOW: Consent Status (GRANTED or DENIED)
  • WHERE: Network IP Address & Device details
  • WHY: Purpose code (clinical review, emergency, etc.)

7.2 Your Consent Controls

You control exactly what data each psychologist can access. You can enable or disable access to any data type at any time in the app settings:

Mood Survey Data
Journal Insights (encrypted summaries only)
AI Session Transcripts
Voice Tone Analysis
Emotion Detection Data

7.3 Audit Trail Transparency

You can view your complete data access audit log anytime. This transparency allows you to see every psychologist who accessed your data, see exactly what they accessed, check when access was GRANTED or DENIED, and revoke access immediately if needed.

7.4 Write-Once, Read-Many (WORM) Storage

Our audit logs are stored in WORM-compliant storage, meaning:

  • Logs cannot be modified after creation
  • Logs cannot be deleted (until retention period)
  • Logs are cryptographically sealed
  • Logs are court-admissible as evidence

7.5 Denied Access Logging

If a psychologist tries to access data you have not granted consent for, the platform immediately blocks the access, logs the attempt with a DENIED status, displays it in your audit trail, and issues a real-time notification alert.

7.6 Medical Records Retention

Your clinical notes, diagnoses, and treatment records are retained by your psychologist per medical records retention laws (typically 7 years minimum).

Right to Be Forgotten

Your wellness data (mood logs, journals, AI sessions) can be deleted by you anytime.

Independent Records

Your psychologist's clinical notes remain independent and are not automatically deleted.

Revoking Consent

You can revoke future access without affecting historical medical records.

7.7 HIPAA Compliance

All data access is logged in compliance with HIPAA Audit Log requirements. We maintain complete user identification for all access events, date and time, type of data, successful/denied outcome, and IP address locations.

7.8 Data Breach Notification

In the unlikely event of unauthorized access or data breach, we will notify all affected users and relevant regulatory bodies within 60 days, as strictly required by HIPAA and GDPR.

7.9 Your Privacy Rights

Right to Access

View your complete, real-time audit log anytime.

Right to Revoke

Disable psychologist data access permissions instantly.

Right to Be Forgotten

Permanently delete your personal wellness data from the app.

Right to Transparency

See exactly who has accessed what records, and why.

7.10 Access to Audit Logs (Administrative Controls)

To ensure maximum security and maintain HIPAA and GDPR compliance, access to our audit logs is protected by strict administrative controls. We enforce the principle of "Who audits the auditors?" to prevent unauthorized internal snooping.

Authorized Personnel
  • Security Administrators: For security monitoring
  • Compliance Officers: For regulatory audits
  • Data Protection Officer (DPO): For privacy investigations
  • Authorized Support Staff: With explicit compliance approval
Prohibited Personnel
  • ❌ Regular platform staff / employees
  • ❌ Developers (without explicit security clearance)
  • ❌ Interns or junior personnel
  • ❌ Contractors without signed Business Associate Agreement (BAA)
1. Justification Required

Admins must submit a valid clinical, legal, or security reason before accessing any log data containing patient metadata.

2. Logs of Logs (Audited Admins)

Every administrative view or export request is permanently written into a separate admin_audit_log_access WORM database table.

3. Time-Limited Access

Authorized sessions generate tokens that automatically expire within 60 minutes, preventing session hijacking.

[ADMIN ACCESS LOG]WORM SECURE
Admin: John Smith (UUID: admin-123)
Action: VIEWED PATIENT AUDIT LOG
Patient: p***d***@example.com (UUID: 69**...**fcb)
Reason: Investigating potential unauthorized access attempt
Approved By: Mary Johnson (Compliance Officer)
Timestamp: Jul 13, 2026, 08:15:22 PM
IP/Client: 203.0.113.195 | Chrome/MacOS
Violations & Policy Enforcement

Unauthorized access or viewing of audit logs without approval is subject to a zero-tolerance policy. Violations result in immediate termination, permanent documentation on employment record, legal action, and mandatory reporting to regulatory authorities.

7.11 Visual Audit Proof (Live System Screenshots)

To demonstrate full compliance, below are verified visual proofs of our live log databases, depicting active WORM security feeds and therapist access ledger entries.

8. Voice Analysis & Affect Congruence

8.1 Acoustic Indicators Analyzed

We analyze pitch, pitch variability, speech tempo, voice volume, tremors/jitter, rhythm, and pauses to track:

  • Affect Congruence: Do voice cues match journal sentiments?
  • Emotional States: Indication of anxiety, calm, or stress indicators.
  • Burnout Risk: Vocal depletion markers.

8.2 & 8.3 Practical Limits

Acoustic evaluation helps identify trends and flag severe indicators (e.g. crisis levels) to clinical providers. AI-generated observations are subject to error and should not be interpreted as medical diagnoses. Your provider is responsible for validating these indicators.

8.4 Personalized Voice Baselines

Your first 5 voice session values build your vocal baseline. We evaluate future sessions relative to your baseline, preventing false positives for unique voice patterns or accents.

9. Psychologist Integration (QR Handshake)

Connecting your data with a therapist is **completely optional**. If you decide to link accounts via their office QR code:

9.2 Shared Details

  • • Daily mood values & triggers
  • • 30-day summary trends
  • • Voice distress indicators
  • • AI chat summarizations
  • • Journal themes & distortions

9.3 Kept Encrypted & Private

  • • Raw journal writing text
  • • Raw audio recordings
  • • Credentials & system identifiers

9.4 Revocable Sharing Permissions

You maintain full control of the connection. You can disconnect or pause data sharing in the app settings (Settings → Therapist Access). When you disconnect, no new updates are sent. Past shared data remains accessible to your provider for clinical continuity.

10. How We Use Your Data

10.1 Wellness FeaturesDisplaying your mood calendar, identifying trends, making AI companion chat relative to your state, and suggesting coping mechanisms.
10.2 Clinical SupportUpdating provider portal dashboards, triggering risk warnings for your therapist, and documenting inter-session progress.
10.3 Research & ImprovementWe use aggregated, de-identified data to improve our own models, validate voice analysis algorithms, and train our AI companion. Your individual data is NOT identified.
10.4 What We Do NOT Use Your Data For:
  • Selling details to advertisers
  • Creating behavioral marketing files
  • Commercial LLM training
  • Tracking activities across third-party websites
  • Disclosing to health insurance brokers
  • Profiling for employee wellness checks
10.5 Lawful Basis for Processing (GDPR):

Depending on your location and the nature of the processing, FaceofMind processes personal data based on one or more of the following legal bases:

  • Your consent: For processing specific data types (such as recording voice journals or sharing logs with your psychologist) where you have explicitly opted in.
  • Performance of a contract: To operate our application, maintain your seeker or professional account, and deliver wellness features requested by you.
  • Compliance with legal obligations: Where we must retain or share records to comply with applicable statutory or regulatory requirements.
  • Legitimate interests: For optimizing application performance, protecting against fraud, securing our systems, and refining clinical analytical algorithms where those interests are balanced against your rights and privacy expectations.

11. Data Security & Encryption Standards

HIPAA-Aligned Security (US)

HIPAA Readiness Program

FaceofMind implements technical, administrative, and organizational safeguards designed to protect ePHI. Business Associate Agreements (BAAs) will be made available for selected enterprise deployments once operational requirements are met.

GDPR-Aligned Protection (EU)

EU Data Residency

EU customer data stored in eu-west1. Supports data rights, portability, standard SCC safeguards, and EU-regulated sub-processor controls.

ISO 27001 Information Security

Certification Goal: 2027

Fully documented security policies, KMS encryption guidelines, incident plans, risk checks, and isolation rules in preparation for ISO audit.

RA 10173 (Philippines DPA)

NPC Alignment

Maintains designated DPO, consent-based wellness data models, data retention restrictions, and local regulatory alignment. Formal NPC registration will be finalized when operationally required.

12. Breach Notification & Incident Response

A data breach means unauthorized access, disclosure, or loss of personal data (e.g. system compromise, administrative leakage, or device theft).

12.2 Breach Reporting Timelines

  • Philippines (RA 10173): Affected users notified via email and in-app alert within 72 hours. NPC reported immediately.
  • EU (GDPR): Users notified within 72 hours. GDPR authorities reported.
  • US (HIPAA-aligned): Notifications dispatched without unreasonable delay. HHS reported if 500+ records affected.

12.4 Incident Response Stages

1. DetectionImmediate Isolation
2. InvestigationDay 1–3 Assess
3. NotificationDay 1–3 Dispatches
4. RemediationDay 3–30 Resolution
5. Post-IncidentAudit & Updates

13. International Data Transfers

GCP Philippines (asia-southeast1)Primary secure database host for mood log indicators and encrypted journal details.
GCP EU West (eu-west1)Designated regional host for European users, keeping data compliant with GDPR residency mandates.
Local Processing (On-Device)Speech-to-text transcription is executed locally on your device where supported. No raw audio recordings are transferred internationally except to our secure cloud storage.

14. Children's Privacy

FaceofMind is NOT designed for or targeted to children under 13.

If we discover an account belongs to a child under 13, it will be deactivated and all records deleted within 30 days. Parents/guardians can report collection concerns to privacy@faceofmind.com (subject: "Child Data Report").

15. Your Data Rights

15.1 Right to Access

Request a printable or JSON copy of your personal datasets.

Timeline: 30 days • Free
15.2 Right to Deletion

Request permanent deletion of database logs (excluding consultation records).

Timeline: 30 days • Free
15.3 Right to Correction

Request modifications of inaccurate wellness settings or account parameters.

Timeline: 10 days review • Free
15.4 Right to Portability

Request export of details in structured JSON or CSV format.

Timeline: 30 days • Free
15.5 Right to Restrict Processing

Pause active data analysis while resolving details.

Timeline: 30 days • Free
15.6 Right to Object

Object to research usage, profiling actions, or automated evaluations.

Timeline: 30 days • Free

16. Third-Party Services & Sub-Processors

Service NamePurposeData Shared
Google Cloud PlatformData storage, encryption, KMS key managementEncrypted mood logs, journals, voice transcriptions
StripePayment processing & subscriptionsName, email, payment card indicators
SendGridSystem notifications & alertsUser email addresses
SentryCrash logging & debug auditsSystem details, non-identifiable crash summaries
16.2 Sub-Processor Reviews: Hospitals and enterprise customers can approve or reject sub-processors. Changes to the sub-processor list require 30-day notice.

18. Enterprise & Hospital Data Processing

For hospitals and healthcare providers utilizing our platform, we establish formal Data Processing Agreements (DPA) for GDPR and are preparing to execute Business Associate Agreements (BAA) for HIPAA deployments. Enterprise accounts feature SSO integration, custom database localization (PH, EU, US), and security reporting. Contact us at enterprise@faceofmind.com.

19. California, Texas & State-Specific Rights

19.1 California (CCPA/CPRA)

California residents hold rights to know what data is collected, correct inaccuracies, delete profiles, opt-out of marketing, and receive equal service when exercising rights. Contact privacy@faceofmind.com with subject "California Privacy Request".

19.2 Texas (TDPSA)

Texas residents retain corresponding rights to delete datasets, inspect records, correct errors, and refuse the sale of information. Contact privacy@faceofmind.com with subject "Texas Privacy Request".

20. Policy Updates & Contact

Policy UpdatesMaterial changes are communicated with a 30-day notice via email or in-app alerts. Non-material changes are posted directly here.
Privacy & DPO contact

Privacy: privacy@faceofmind.com

DPO: dpo@faceofmind.com

Mailing address: FaceofMind, Cebu City, 6000, Philippines

Regulatory Complaints

PH (NPC): privacy.gov.ph

EU (GDPR): Local DPA Authority

US (HIPAA): HHS OCR Privacy Portal

21. Terms & Conditions

This Privacy Policy is an integral part of FaceofMind's Terms of Service. You can review the full terms in our Terms of Service.