🔐 Privacy Policy
Version: 3.0 • Effective Date: July 13, 2026 • Last Updated: July 13, 2026
1. Introduction
FaceofMind is a mental wellness platform that helps you track your mood, journal your thoughts, and connect with professional psychologists. This privacy policy explains how we collect, use, protect, and share your information.
2. Who We Are
3. What Data We Collect
3.1Information You Provide Directly
Wellness Seeker Account Registration & Profile Setup:
- Name (optional for wellness use)
- Email address & securely hashed password
- Date of birth (age verification)
- Phone number (with country dial code)
- Gender (or Prefer Not to Say)
- Location (Country, Region, City, Barangay)
- Timezone & UTC offset
Professional Account Registration (Psychologists & Therapists):
- Full name
- Professional email address
- Password (securely hashed)
- Professional license number
- Clinic, organization, or employer
- Practice location & clinic coordinates (GPS)
- Specialization and years of experience
Professional information is collected solely to verify eligibility, operate professional accounts, and facilitate clinical services on the platform.
Wellness Features:
- Daily mood logs (Excellent, Good, Okay, Bad, Terrible)
- Mood triggers (stress, loneliness, relationships, etc.)
- Journal entries (encrypted, you control sharing)
- Sleep quality ratings & physical energy levels
- Social connection feelings & self-confidence
- Future optimism ratings
Voice & Audio Data
- Recordings during AI sessions
- Transcriptions (on-device or server)
- Pitch, tempo, shakiness, loudness
Consultation Data
- Booking history via QR connection
- Psychologist session notes
- Consultation feedback
3.2Information We Collect Automatically
Sessions, timestamps, feature interaction patterns (mood tracking, journaling, AI conversations), and duration of use.
Device model (iPhone, Android), operating system version, app version, performance metrics, and crash logs.
IP address, network connection type (WiFi, cellular), and coarse geolocation (country or region level only).
3.3Data From Psychologists (If You Connect)
If you scan your psychologist's unique QR code to link your accounts, your psychologist will be able to review:
- Daily mood logs
- Voice analysis summaries
- Emotion detection results
- Journal insights (themes, cognitive distortions)
- AI session summaries
- Consultation history
4. What Data We DON'T Collect
To ensure complete digital security and privacy, we explicitly state that we **do NOT** collect or access:
Do Not Track (DNT) Signals: We respect Do Not Track signals. However, our platform does not use tracking cookies or behavioral advertising, so DNT is automatically honored.
Cookie Usage: FaceofMind does not use cookies for tracking or advertising. We only use essential technical cookies/storage for account session maintenance. Read our full Cookie Policy.
5. How We Encrypt Your Data
5.1 Encryption at Rest (Storage)
All personal data stored on our servers is encrypted using AES-256-GCM encryption, an industry-standard authenticated encryption algorithm used to protect sensitive data.
• Encryption Standard: AES-256-GCM
• Key Management: Managed Key Management Service (KMS)
• Key Rotation: Industry-standard rotation protocols
What this means: Even in the event of an infrastructure breach, data remains unreadable. Access to decrypted records is restricted to authorized users with appropriate permissions and patient authorization.
5.2 Encryption in Transit (Network)
All communications between your mobile application and our secure servers utilize secure pathways:
5.3 Mood Data Isolation
Mood logs, journals, and notes use distinct keys per patient. Compromising a single key will not affect any other patient's data.
5.4 Voice Data Processing Safeties
Voice recordings are transmitted over encrypted connections and encrypted immediately upon upload. Audio files are retained for 12 months for voice analysis, and text transcriptions for 24 months. You can request instant deletion at any time.
6. Data Retention & Deletion
6.1 How Long We Keep Your Data
| Data Type | Retention Period | Why |
|---|---|---|
| Mood logs | 24 months (or deletion request) | Clinical reference for therapy |
| Journal entries | 24 months (or deletion request) | Your personal records |
| AI session summaries | 24 months (or deletion request) | Trend analysis |
| Voice recordings | 12 months | Voice tone analysis |
| Voice transcriptions | 24 months | Reference for therapy |
| Emotion detection results | 24 months | Trend analysis |
| Consultation records | 7 years | Legal/compliance requirement |
| Activity logs | 24 months | Security audit trails |
| Device/usage data | 12 months | Performance optimization |
6.2 Deleting Your Account
If you choose to delete your account:
- All mood logs, journal entries, voice recordings, and activity logs are permanently purged from all backups within 30 days.
- Consultation records are legally required to be retained for 7 years.
- Disconnecting from a psychologist stops new sharing, but past shared data remains visible for clinical care continuity.
6.3 Requesting Deletion
To request manual purging or export of your account details, you may reach out directly via:
Email Address: privacy@faceofmind.com
Subject Line: "Data Deletion Request"
Timeline: Acknowledged within 10 days; deletion finalized in 30 days.
7. Access Logging & Audit Trails
7.1 What We Log
FaceofMind maintains comprehensive audit logs of all patient data access. Every time a psychologist accesses your mental health data, we record:
- WHO: Psychologist name & UUID
- WHEN: Exact timestamp (ms precision)
- WHAT: Data accessed (mood, journals, etc)
- HOW: Consent Status (GRANTED or DENIED)
- WHERE: Network IP Address & Device details
- WHY: Purpose code (clinical review, emergency, etc.)
7.2 Your Consent Controls
You control exactly what data each psychologist can access. You can enable or disable access to any data type at any time in the app settings:
7.3 Audit Trail Transparency
You can view your complete data access audit log anytime. This transparency allows you to see every psychologist who accessed your data, see exactly what they accessed, check when access was GRANTED or DENIED, and revoke access immediately if needed.
7.4 Write-Once, Read-Many (WORM) Storage
Our audit logs are stored in WORM-compliant storage, meaning:
- Logs cannot be modified after creation
- Logs cannot be deleted (until retention period)
- Logs are cryptographically sealed
- Logs are court-admissible as evidence
7.5 Denied Access Logging
If a psychologist tries to access data you have not granted consent for, the platform immediately blocks the access, logs the attempt with a DENIED status, displays it in your audit trail, and issues a real-time notification alert.
7.6 Medical Records Retention
Your clinical notes, diagnoses, and treatment records are retained by your psychologist per medical records retention laws (typically 7 years minimum).
Your wellness data (mood logs, journals, AI sessions) can be deleted by you anytime.
Your psychologist's clinical notes remain independent and are not automatically deleted.
You can revoke future access without affecting historical medical records.
7.7 HIPAA Compliance
All data access is logged in compliance with HIPAA Audit Log requirements. We maintain complete user identification for all access events, date and time, type of data, successful/denied outcome, and IP address locations.
7.8 Data Breach Notification
In the unlikely event of unauthorized access or data breach, we will notify all affected users and relevant regulatory bodies within 60 days, as strictly required by HIPAA and GDPR.
7.9 Your Privacy Rights
View your complete, real-time audit log anytime.
Disable psychologist data access permissions instantly.
Permanently delete your personal wellness data from the app.
See exactly who has accessed what records, and why.
7.10 Access to Audit Logs (Administrative Controls)
To ensure maximum security and maintain HIPAA and GDPR compliance, access to our audit logs is protected by strict administrative controls. We enforce the principle of "Who audits the auditors?" to prevent unauthorized internal snooping.
- Security Administrators: For security monitoring
- Compliance Officers: For regulatory audits
- Data Protection Officer (DPO): For privacy investigations
- Authorized Support Staff: With explicit compliance approval
- ❌ Regular platform staff / employees
- ❌ Developers (without explicit security clearance)
- ❌ Interns or junior personnel
- ❌ Contractors without signed Business Associate Agreement (BAA)
Admins must submit a valid clinical, legal, or security reason before accessing any log data containing patient metadata.
Every administrative view or export request is permanently written into a separate admin_audit_log_access WORM database table.
Authorized sessions generate tokens that automatically expire within 60 minutes, preventing session hijacking.
Unauthorized access or viewing of audit logs without approval is subject to a zero-tolerance policy. Violations result in immediate termination, permanent documentation on employment record, legal action, and mandatory reporting to regulatory authorities.
7.11 Visual Audit Proof (Live System Screenshots)
To demonstrate full compliance, below are verified visual proofs of our live log databases, depicting active WORM security feeds and therapist access ledger entries.
8. Voice Analysis & Affect Congruence
8.1 Acoustic Indicators Analyzed
We analyze pitch, pitch variability, speech tempo, voice volume, tremors/jitter, rhythm, and pauses to track:
- Affect Congruence: Do voice cues match journal sentiments?
- Emotional States: Indication of anxiety, calm, or stress indicators.
- Burnout Risk: Vocal depletion markers.
8.2 & 8.3 Practical Limits
Acoustic evaluation helps identify trends and flag severe indicators (e.g. crisis levels) to clinical providers. AI-generated observations are subject to error and should not be interpreted as medical diagnoses. Your provider is responsible for validating these indicators.
8.4 Personalized Voice Baselines
Your first 5 voice session values build your vocal baseline. We evaluate future sessions relative to your baseline, preventing false positives for unique voice patterns or accents.
9. Psychologist Integration (QR Handshake)
Connecting your data with a therapist is **completely optional**. If you decide to link accounts via their office QR code:
9.2 Shared Details
- • Daily mood values & triggers
- • 30-day summary trends
- • Voice distress indicators
- • AI chat summarizations
- • Journal themes & distortions
9.3 Kept Encrypted & Private
- • Raw journal writing text
- • Raw audio recordings
- • Credentials & system identifiers
9.4 Revocable Sharing Permissions
You maintain full control of the connection. You can disconnect or pause data sharing in the app settings (Settings → Therapist Access). When you disconnect, no new updates are sent. Past shared data remains accessible to your provider for clinical continuity.
10. How We Use Your Data
- Selling details to advertisers
- Creating behavioral marketing files
- Commercial LLM training
- Tracking activities across third-party websites
- Disclosing to health insurance brokers
- Profiling for employee wellness checks
Depending on your location and the nature of the processing, FaceofMind processes personal data based on one or more of the following legal bases:
- Your consent: For processing specific data types (such as recording voice journals or sharing logs with your psychologist) where you have explicitly opted in.
- Performance of a contract: To operate our application, maintain your seeker or professional account, and deliver wellness features requested by you.
- Compliance with legal obligations: Where we must retain or share records to comply with applicable statutory or regulatory requirements.
- Legitimate interests: For optimizing application performance, protecting against fraud, securing our systems, and refining clinical analytical algorithms where those interests are balanced against your rights and privacy expectations.
11. Data Security & Encryption Standards
HIPAA-Aligned Security (US)
HIPAA Readiness ProgramFaceofMind implements technical, administrative, and organizational safeguards designed to protect ePHI. Business Associate Agreements (BAAs) will be made available for selected enterprise deployments once operational requirements are met.
GDPR-Aligned Protection (EU)
EU Data ResidencyEU customer data stored in eu-west1. Supports data rights, portability, standard SCC safeguards, and EU-regulated sub-processor controls.
ISO 27001 Information Security
Certification Goal: 2027Fully documented security policies, KMS encryption guidelines, incident plans, risk checks, and isolation rules in preparation for ISO audit.
RA 10173 (Philippines DPA)
NPC AlignmentMaintains designated DPO, consent-based wellness data models, data retention restrictions, and local regulatory alignment. Formal NPC registration will be finalized when operationally required.
12. Breach Notification & Incident Response
A data breach means unauthorized access, disclosure, or loss of personal data (e.g. system compromise, administrative leakage, or device theft).
12.2 Breach Reporting Timelines
- • Philippines (RA 10173): Affected users notified via email and in-app alert within 72 hours. NPC reported immediately.
- • EU (GDPR): Users notified within 72 hours. GDPR authorities reported.
- • US (HIPAA-aligned): Notifications dispatched without unreasonable delay. HHS reported if 500+ records affected.
12.4 Incident Response Stages
13. International Data Transfers
14. Children's Privacy
FaceofMind is NOT designed for or targeted to children under 13.
If we discover an account belongs to a child under 13, it will be deactivated and all records deleted within 30 days. Parents/guardians can report collection concerns to privacy@faceofmind.com (subject: "Child Data Report").
15. Your Data Rights
Request a printable or JSON copy of your personal datasets.
Timeline: 30 days • FreeRequest permanent deletion of database logs (excluding consultation records).
Timeline: 30 days • FreeRequest modifications of inaccurate wellness settings or account parameters.
Timeline: 10 days review • FreeRequest export of details in structured JSON or CSV format.
Timeline: 30 days • FreePause active data analysis while resolving details.
Timeline: 30 days • FreeObject to research usage, profiling actions, or automated evaluations.
Timeline: 30 days • Free16. Third-Party Services & Sub-Processors
| Service Name | Purpose | Data Shared |
|---|---|---|
| Google Cloud Platform | Data storage, encryption, KMS key management | Encrypted mood logs, journals, voice transcriptions |
| Stripe | Payment processing & subscriptions | Name, email, payment card indicators |
| SendGrid | System notifications & alerts | User email addresses |
| Sentry | Crash logging & debug audits | System details, non-identifiable crash summaries |
17. Legal Disclosures & Compliance
We may disclose information if legally required under search warrants, court orders, regulatory review, or to prevent imminent physical self-harm. In such instances, we notify you (where legally permitted) and share the absolute minimum dataset required.
Jurisdiction & Conflict Resolution: This Privacy Policy is primarily governed by the laws of the Republic of the Philippines, including the Data Privacy Act of 2012 (RA 10173). For users within the United States, rights and disclosures under state-specific statutes (such as the CCPA/CPRA in California and TDPSA in Texas) are processed in compliance with those respective laws. Following our parent company incorporation in Delaware, USA, disputes concerning US or international users will be resolved under Delaware or federal US data protection regulations, without conflict to the consumer rights guaranteed under local state laws.
We do NOT sell data: FaceofMind categorically does not monetize, rent, sell, or profile patient information for data brokers or insurers.
18. Enterprise & Hospital Data Processing
For hospitals and healthcare providers utilizing our platform, we establish formal Data Processing Agreements (DPA) for GDPR and are preparing to execute Business Associate Agreements (BAA) for HIPAA deployments. Enterprise accounts feature SSO integration, custom database localization (PH, EU, US), and security reporting. Contact us at enterprise@faceofmind.com.
19. California, Texas & State-Specific Rights
19.1 California (CCPA/CPRA)
California residents hold rights to know what data is collected, correct inaccuracies, delete profiles, opt-out of marketing, and receive equal service when exercising rights. Contact privacy@faceofmind.com with subject "California Privacy Request".
19.2 Texas (TDPSA)
Texas residents retain corresponding rights to delete datasets, inspect records, correct errors, and refuse the sale of information. Contact privacy@faceofmind.com with subject "Texas Privacy Request".
20. Policy Updates & Contact
Privacy: privacy@faceofmind.com
DPO: dpo@faceofmind.com
Mailing address: FaceofMind, Cebu City, 6000, Philippines
PH (NPC): privacy.gov.ph
EU (GDPR): Local DPA Authority
US (HIPAA): HHS OCR Privacy Portal
21. Terms & Conditions
This Privacy Policy is an integral part of FaceofMind's Terms of Service. You can review the full terms in our Terms of Service.