This notice is written to meet the notice requirements of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the DPDP Rules, 2025. It is not legal advice, and this version has not yet been reviewed by a lawyer.
Canonical URL: https://therapy-bro.com/privacy/. The in-app profile, Play Console, and App Store Connect listings should all point to this URL.
See also our Terms of Service, Refund & Cancellation Policy, Shipping & Delivery Policy, Listener Agreement, and Community Guidelines.
1. Who we are
TherapyBro (also styled “Therapy Bro”) is a companionship and peer-support product — an AI companion (Adam or Eve) and human Listener Bro chat — offered in India. TherapyBro is not a clinic, hospital, or registered medical, psychiatric, or psychological practice, and nothing in the product should be read as changing that.
TherapyBro is operated as a sole proprietorship, registered under Udyam (MSME) and holding a Sanstha Aadhaar number, by its founder. It is not currently a registered private limited company or LLP. Because it is a sole proprietorship, there is no separate corporate legal entity distinct from the proprietor — the proprietor is personally the Data Fiduciary under the DPDP Act and the contracting party under these terms.
Privacy and DPDP-related requests can be sent to our Grievance Officer — see Section 12.
2. Scope
This policy covers personal data processed when you:
- create or use a TherapyBro account in the mobile app;
- chat with an AI companion (Adam or Eve);
- chat with a Listener Bro;
- write a journal entry, log your mood, set reminders, or view in-app activity;
- pay for wallet top-up or a subscription;
- apply to become a Listener Bro;
- contact us, or visit the marketing website.
3. This is not medical care
TherapyBro is a companionship and peer-support product, not a clinic, hospital, crisis line, or registered medical or clinical psychological practice. Listener Bros are not licensed clinical psychologists and do not diagnose, prescribe, or provide treatment — a Listener Bro’s educational background (where shown) does not change this. Chat, journal, mood, and onboarding answers may still be health-adjacent personal data, and we process that data to run the product you asked for, not to diagnose or treat you.
Crisis helpline numbers (including Tele-MANAS 14416 and emergency services at 112) may be shown in-product. Showing those numbers does not make TherapyBro an emergency or crisis-intervention service, and does not guarantee that every instance of risk will be detected. See our Terms of Service for the full acknowledgment you agree to regarding crisis situations.
4. What we collect
We collect what the product actually stores, transmits, or generates. We do not collect Aadhaar numbers or other government ID numbers from users.
Account and authentication
- Login identifier, optional password hash (Argon2), name, phone number, date of birth.
- Email, Google account ID, optional Google profile photo URL, and sign-in provider if you use Google Sign-In.
- Preferred AI persona (Adam or Eve), timezone, account status, role, last-seen time.
- Session token stored on-device in secure storage (default lifetime 24 hours).
Onboarding (health-adjacent)
Optional questionnaire answers (reasons for using the app, current state of mind, prior therapy experience, goals, referral source, preferred time to talk), an initial mood score, and a record that you accepted these terms (version and timestamp).
AI chat
Message text you and the AI companion exchange, optional image/audio URLs and transcripts, conversation summaries, usage minutes, and timestamps. Message content is stored in our database associated with your account identifier. We do not currently apply message-level encryption within the application layer; database-level access is restricted through separate, access-controlled systems described in Section 8. Our AI providers (see Section 8) must receive message text to generate a reply.
Listener Bro chat
Message text and optional media, delivery/read status, session requests, Listener Bro profile details you view, reviews, reports, and blocks. Messages you send to a Listener Bro are visible to that Listener Bro.
Journal, mood, habits, reminders
- Journal entries (text, optional mood tag, optional image/audio and transcript).
- Mood logs and daily activity summaries used for in-app insights (your own data — not shared with a third-party advertising SDK).
- Reminders and reminder preferences; push notifications may include the reminder title and body.
Voice
Journal and chat audio you record is uploaded to object storage and transcribed (via a speech-to-text provider); the transcript is stored with the message or journal entry. Microphone access is requested only when you choose to record. We do not run continuous or always-on audio recording.
Calls (voice and video)
When you place or receive a 1:1 voice or video call in the app, we store a record of the call itself: who the two participants were, when it started and ended, how long it lasted, whether it was voice or video, and how it finished (answered, declined, missed, or disconnected). Duration is what your wallet is charged against, so this record is also a billing record and is kept for the period described in Section 7.
To connect a call, the two devices must exchange the network information needed to reach one another, which includes their IP addresses. That exchange passes through our servers. Where the two devices cannot establish a direct connection between themselves, the audio and video are routed through a relay operated by Cloudflare (Section 8), which sees the participants’ IP addresses, the timing of the connection, and how much data passes through it.
We do not record, store, or transcribe call audio or video. Call media travels between the two devices and is encrypted in transit; it does not pass through, and is not stored on, our servers. There is no call-recording feature in the app, and the Cloudflare relay described above forwards encrypted data that it holds no key for. Camera and microphone access is requested before a call begins, and only when you choose to place or answer one.
Payments and wallet
Wallet balance and transaction ledger, subscription records, and payment records (provider, amount, currency, status). Our payment processor (Razorpay) receives your customer ID, email, phone number, and name to create a payment order. Wallet withdrawal is not available at launch; we do not collect payout bank or UPI details while that feature is inactive.
Device / push notifications
Push-notification token, platform, device ID, and app version, used to deliver notifications to your device.
Memory used to personalise AI chat
From your AI chat conversations, we extract account-scoped entities (for example, people, places, jobs, goals, concerns you’ve mentioned, health-related context, and hobbies) and conversation summaries with vector embeddings, stored in a knowledge graph linked to your account, so that Adam or Eve can recall relevant context in later conversations. Deleting your account begins removal of this stored memory after the 30-day recovery window described in Section 9.
Listener Bro applications
Name, email, phone number, date of birth, a short bio, and narrative answers about your background, motivation, and suitability. We do not collect Aadhaar or other government ID as part of this application. Listener Bro terms of engagement are in our Listener Agreement.
5. Why we process it
- To create and secure your account.
- To provide AI companion chat and Listener Bro chat.
- To support journaling, mood tracking, habits, reminders, and in-app activity.
- To process payment for wallet top-ups and subscriptions.
- To prevent abuse (handling reports, blocks, and account suspensions).
- To route AI replies appropriately, including identifying when a conversation may involve risk to safety, so it can be handled with extra care.
- To keep payment and revenue records for tax record-keeping after account deletion (see Section 7).
- To operate, secure, and improve the service.
We do not sell your personal data to advertisers, data brokers, or insurers.
6. Consent
Under the DPDP Act, we rely on your consent, given when you create an account, accept these terms, and use each feature. You can withdraw consent for the service as a whole at any time by deleting your account (Section 9). You can turn off AI-generated reminder notifications from within reminder preferences. We do not currently offer a feature-by-feature consent management dashboard beyond these controls.
7. How long we keep data
- Account, chats, journal, mood logs, devices, memory, media, reminders, subscriptions, wallet, and Listener Bro threads you are part of: retained until you delete your account. We do not currently auto-delete or auto-purge this data on a fixed schedule while your account remains open. When you delete your account, it is deactivated immediately and this data is retained during a 30-day recovery window before hard-deletion — see Section 9.
- Payment and platform-revenue records: retained after account deletion with your user identifier removed. Those retained records still include amount, currency, timestamps, provider payment ID, and related metadata. Our systems currently target an eight-year retention period for tax record-keeping. An automated end-of-period purge is not currently running.
- Password-reset OTP: expires in 10 minutes.
- App session token: default lifetime 24 hours.
- Signed URLs used to serve images/audio expire on a rolling basis (profile photos: 1 year; message media: 90 days; journal media: 30 days) — this is the lifetime of the access link, not deletion of the underlying file. The underlying file is retained until account deletion, or until you delete the specific journal entry it belongs to.
8. Who else receives personal data
We share personal data with the service providers (“processors”) needed to run the product:
- Our hosting provider — hosts the production API in Singapore (Fly.io region
sin). Legacy Mumbai (bom) compute is deprecated. - Our database and storage provider — production database and object storage, hosted in the Mumbai (ap-south-1) region.
- Our knowledge-graph provider — stores AI-chat memory described in Section 4, hosted in Mumbai, India.
- Our AI model provider(s), currently Sarvam AI — used for live AI chat and related processing. Message and journal content you share with Adam or Eve is sent to this provider to generate a response. We may in future route some conversations to additional or alternative model providers; if we do, we will update this section to name them specifically before they go live, rather than describing them generically.
- Our speech-to-text provider — used to transcribe voice notes and journal audio you choose to record.
- Our payment processor (Razorpay) — for wallet top-up and subscription checkout (receives customer ID, name, email, phone, and amount).
- Google — for Sign-In; Firebase / FCM — for push notification delivery.
- Our email provider — for password-reset email, where applicable.
- Our SMS/OTP provider — for phone-number verification.
- Our website hosting provider — serves the marketing website (collects visitor IPs for the marketing site only, not in-app chat).
- Cloudflare — provides the relay that connects voice and video calls when the two devices cannot reach each other directly. It receives connection metadata: the participants’ IP addresses, the timing of the connection, and the volume of data relayed. It does not receive call content in readable form — the audio and video are encrypted between the two devices, and the relay forwards data it holds no key for.
Listener Bros see the content of messages you choose to send them during a chat — this is inherent to how peer chat works and is disclosed to you before you start a chat with a Listener Bro.
Access to conversation data for safety and dispute resolution
Conversations are stored in our database, associated with your account identifier rather than directly with your name. A separate, access-controlled dataset maps account identifiers to personal details (name, phone, email, etc.), and access to that mapping is limited to specific TherapyBro roles that need it to operate the service (for example, payment and support functions).
We do not access or read the content of your conversations as a matter of routine. Where a user or Listener Bro files a report alleging harassment, abuse, or a violation of our Community Guidelines, a designated member of our Trust & Safety function may access the specific conversation(s) relevant to that report, solely to investigate and resolve it. Such access is logged internally, limited to the scope of the report, and the content accessed is not used for any other purpose — including marketing, model training, or general monitoring.
We do not describe this storage as “end-to-end encrypted,” and you should not assume it is — TherapyBro, as the service operator, is technically able to access conversation content through the mechanism above.
9. Account deletion
In-app path: Profile → Delete Account.
When you confirm account deletion, your account is deactivated immediately and you lose access to the platform. Your data enters a 30-day recovery window, during which reinstatement is possible by contacting support@therapy-bro.com. After 30 days, if reinstatement is not requested or granted, your data is hard-deleted and cannot be recovered.
Termination of your account by TherapyBro for a Terms violation follows the same deactivation and recovery process, except that reinstatement during the recovery window is at our discretion — see our Terms of Service, Section 12.
After the recovery window ends, we:
- delete your media (profile, journal, and message images/audio) from object storage;
- delete your knowledge-graph entities, conversation memory, and associated account node, and attempt to remove corresponding vector-store entries;
- delete your account and related application data — chats you own, journal entries, mood logs, reminders, registered devices, your Listener Bro application (if any), wallet ledger entries, and Listener Bro chat threads you are part of.
We retain payment and platform-revenue records after account deletion with your user identifier removed. Those retained records still include amount, currency, timestamps, provider payment ID, and related metadata. Our systems currently target an eight-year retention period for tax record-keeping. An automated end-of-period purge is not currently running (see Section 7). We do not claim that all data is deleted everywhere: our third-party processors (AI provider, payment processor, Google/FCM, and others) and backups may retain copies for their own retention periods, until those separately expire or are erased.
If deactivation fails for a technical reason when you confirm deletion, your account is not marked as deleted and the app will show an error rather than falsely confirming success.
10. Security
What we can state plainly about our current security practices:
- The production API requires HTTPS.
- Passwords are hashed using Argon2.
- App session tokens are stored in on-device secure storage.
- Object storage uses time-limited signed URLs rather than permanent public links.
- All API access requires a valid, signed-in user.
- Personal-identity data is held in an access-restricted dataset separate from conversation content, as described in Section 8.
- Voice and video call media is encrypted between the two participants’ devices and never reaches our servers. Where a direct connection is not possible it passes through a Cloudflare relay, which carries only encrypted data. No recording or transcript of a call is made or kept (Sections 4 and 8).
We do not currently claim end-to-end encryption of chat content, formal ISO/SOC security certification, or that no TherapyBro staff can access message content under any circumstance — Section 8 describes the specific, limited circumstances in which access occurs.
The call encryption described above is a narrower claim than it may appear, and we would rather state its limit than let you assume more. The messages that set a call up pass through our servers, so we do not claim that it is technically impossible for TherapyBro, as the operator, to interpose itself in that setup. What we do state is that no call is recorded or transcribed, that we hold no copy of call media, and that our current design gives us none to hold.
11. Your rights
- Access: your profile and in-app screens show most of your stored records. We do not currently offer a one-click “download everything” export; for a fuller copy of your data, email support@therapy-bro.com.
- Correction: you can update your name, phone number, and date of birth from your profile, and edit journal entries, reminders, and your chosen AI persona from their respective screens.
- Erasure: delete your account as described in Section 9. Your account is deactivated immediately; hard-deletion of your data follows after the 30-day recovery window unless you request and receive reinstatement within that period. You can also delete individual journal entries at any time — those are removed immediately.
- Withdraw consent: delete your account, or use the in-app toggle to turn off AI-generated reminders.
- Grievance: see Section 12.
12. Grievance Officer
- Name
- Sudhir Bala
- Designation
- Grievance Officer
- sudhir@therapy-bro.com
- Phone
- +91-9460407590
- Postal address
- 37, GP Colony, Sumer Nagar, Mansarovar, Jaipur, Rajasthan 302020
- Acknowledgement / closure timeline
- Complaints are acknowledged and resolved within 15 days of receipt. For example, a complaint raised on 27 August before 11:59 PM will be resolved by 11 September before 11:59 PM.
If you are not satisfied with the resolution, you may approach the Data Protection Board of India as provided under the DPDP Act.
13. Cross-border transfer
Our production API is hosted in Singapore (Fly.io region sin). Our database, object storage, and knowledge graph are hosted in Mumbai, India. Personal data is sent outside India for API compute in Singapore and when our AI model provider, speech-to-text provider, or other integrated third-party APIs are called to process your requests as part of using the product. We do not claim that all personal data is stored exclusively within India.
14. Children
TherapyBro is intended for users aged 18 and over. We rely on the age/date-of-birth information provided at sign-up (including via Google Sign-In) to assess this; we do not currently perform independent age verification beyond self-declared information. If we become aware that an account belongs to a user under 18, we will delete the account.
15. Child Safety and Zero-Tolerance CSAE/CSAM Policy
TherapyBro maintains a strict, absolute zero-tolerance policy toward Child Sexual Abuse Material (CSAM) and Child Sexual Abuse and Exploitation (CSAE).
- Prohibited Content: Users and human Listeners are strictly prohibited from generating, sharing, requesting, or transmitting any text, audio, images, or media that exploits, harms, or endangers minors.
- Safeguarding and Monitoring: In accordance with our safety protocols, all chat logs and system data are retained and actively investigated upon any report of harassment or policy violations to ensure user safety.
- Reporting and Enforcement: We provide clear, prominent in-app reporting tools for users to flag safety concerns immediately. Any account found violating these standards will be permanently terminated immediately without a recovery window.
- Legal Compliance: TherapyBro complies fully with all regional and national child safety laws. We will proactively report any instance of child exploitation or abuse material to the appropriate law enforcement agencies and national authorities.
16. Changes to this policy
We will post updates at this same URL. The version number and date appear at the top of this document. We may also highlight significant changes in-app or by email. Any short in-app summary of this policy must not contradict this full document.
17. How to contact us
- Support and general enquiries: support@therapy-bro.com
- Account deletion: in-app, via Delete Account (requires sign-in)
- Grievance Officer: Sudhir Bala — see Section 12