The short version
- The AI that guides you never receives your email or account identity. It sees only your dialogue and the name you choose to present, which can be made up.
- Your login, payment details, and account identity never leave our servers.
- No person at QuestionsHeal reads your dialogues unless you opt in. When a clinician does, it is under a random label, not your name.
- Delete a session and it is gone from Q's memory.
- The AI reads everything you type to choose its next question, so please do not share military secrets or anything classified, or sensitive personal or financial information such as bank accounts, card numbers, or your phone number.
1. Information We Collect
When you create an account or use QuestionsHeal, we may collect:
- Email address: used for login, account recovery, and essential communications
- Name: the display name you choose, used to personalize your sessions. It can be a nickname or an invented name (see Section 3)
- Password: stored only as a salted, one-way hash. We never store or have access to your plaintext password
- Session dialogues: your answers and reflections during guided sessions (see Sections 3 through 5)
- Phone number (optional): used only for session reminder SMS if you opt in. It is entered on a form and is never sent to the AI
- Usage data: basic information about how you interact with the service, such as features used and timestamps
Your email, password, and payment details are account information. They stay on our servers and are never sent to the AI that guides your sessions. Section 3 explains that wall in detail.
2. Your Session Data
QuestionsHeal is a deeply personal experience. Your session dialogues, the answers you give, the reflections you share, the beliefs you explore, are treated with the highest level of confidentiality.
- Session data is encrypted at rest using industry-standard encryption
- Your dialogues are never sold and never used for advertising
- You can delete your session history at any time from within the application (see Section 6)
Who and what your dialogues are shared with is set out precisely in Sections 3 through 5: the AI that generates your session, whether they help improve Q, and whether a person ever reads them.
3. What the AI Sees
QuestionsHeal is guided by an AI that reads your dialogue to choose each next question. We built a wall between who you are and what you say.
- The request sent to the AI carries your dialogue text, the clinical context of the session, and the display name you choose. It carries no email, no username, no account identifier, and no device address (IP). For typed dialogue, the call is made from our servers, so your device is never exposed to the AI provider.
- The only name the AI ever sees is the name you choose to present. You can make it up. A nickname works. Your login email and account identity never leave our servers.
- We cannot remove what you volunteer. If you type your real name, your job, or a detail that identifies you, that text reaches the AI as part of the dialogue.
Please keep sensitive information out of the dialogue. The AI reads everything you type to choose its next question, so do not share military secrets or anything classified, or sensitive personal or financial information such as bank accounts, card numbers, or your phone number. (The phone number you may give for SMS reminders is a separate account field, entered on a form, and is never sent to the AI.)
4. How Your Dialogues Help Improve Q
We improve Q by studying anonymized dialogues. Anonymized means the study copy carries no account identity: no email, no name, no account link.
- If you joined before August 18, 2026: nothing changes for you. Your dialogues are used to improve Q only if you choose to share them by turning on that option in Settings.
- If you join on or after August 18, 2026: anonymized copies of your dialogues help improve Q by default, and you can turn that off at any time in Settings.
- This applies only going forward. Dialogues you never shared are not in the improvement store and cannot be added to it after the fact.
5. When a Person Reads a Dialogue
A person at QuestionsHeal reads a dialogue only if you say yes.
- A QuestionsHeal clinician may read your dialogues only if you tick the consent box that says a clinician may review them to improve Q. This is off by default. If you never tick it, no person at QuestionsHeal reads your dialogues.
- When a clinician reads a consented dialogue, it appears under a random label. The reviewer does not see your email, your display name, or your account. Your account identity is hidden. The dialogue text itself may contain whatever you chose to write.
- A session you delete never enters the review pool. Every read is logged.
- If you consented under an older version that mentioned review by AI only, that consent does not permit a person to read your dialogues. Human reading requires the new consent.
Three narrow exceptions apply regardless of the settings above. Staff may view account or session content when:
- Safety: our safety system flags content suggesting a risk of harm, and a person reviews it.
- Support you ask for: you ask us to fix a problem with your account, a payment, or a session, and resolving it requires staff to view your account and, when needed, the session.
- Legal compulsion: we are legally required to.
6. Q's Memory and Deleting Sessions
Q keeps a memory of your past sessions, a short summary built only from your dialogues, so it can pick up where you left off. It carries no account information.
Deleting a session removes it from Q's memory. Deleting all sessions clears that memory entirely. If a session was already added to the anonymized improvement pool (Section 4), those copies carry no identity and cannot be linked back to you, so deletion does not remove them from that pool. We may also keep a restricted copy of a deleted session for a limited time where needed for safety, for support you have asked for, or for legal compliance.
7. Voice Mode
In voice mode, your speech streams to our transcription service and becomes text in real time. We never save your audio. It is not stored on our servers and is not part of your session record. From the moment it becomes text, it is treated exactly like typed dialogue, including deletion. Our transcription provider does not retain your audio beyond the time needed to process it, and does not use it to train its models.
8. AI and Supporting Services
To generate your session, your dialogue is processed by a leading third-party AI provider. A small number of supporting services assist: one matches your words against our example library to find relevant material, and, in voice mode, one converts your speech to text and another gives Q a spoken voice.
These providers process your data to deliver the service and do not use it to train their models. We describe these services by function rather than by name to protect proprietary details of how QuestionsHeal works. The specific vendors behind each function are available on legitimate request.
9. Cookies and Website Analytics
QuestionsHeal has two sides, and they collect different things.
Inside the app, where you have your dialogues, we use a single session cookie to keep you logged in. That cookie is essential for the app to function. The app itself does not run analytics tools, advertising cookies, or cross-site tracking.
On the marketing website, meaning the public pages at questionsheal.com that describe the app and let you sign up, we run standard analytics so we can see how people find us, whether the pages are useful, and whether the ads we run are working. Specifically:
- Google Analytics 4, for aggregate visit metrics such as page views, referral source, time on page, country, and device. We run it in a privacy-hardened configuration: IP addresses are anonymized, Google Signals is off, and ad personalization is off.
- Meta Pixel, so ads we run on Facebook and Instagram can tell us who ended up on the page, watched the video, or started the signup form. Without it we would be running those ads blind.
- Microsoft Clarity, which records anonymized session recordings and heatmaps of the public pages so we can see where visitors get stuck and fix layout problems. Form fields are masked by default.
- Metricool, so our team can see how social posts translate into visits.
These tools set their own cookies (for example _ga, _fbp, and Clarity's) and, in the case of Meta Pixel, share the fact that a visit happened with Meta. When you arrive from an ad or a tagged link, we also capture the campaign parameters in the URL, such as utm_source, utm_campaign, gclid, and fbclid, so the visit can be attributed correctly.
None of this runs inside the app. Your dialogues, your account name, and anything that happens in your account are never sent to any of these marketing tools.
If you would rather not be measured, use an ad or tracker blocker such as uBlock Origin, Brave Shields, or Firefox Enhanced Tracking Protection. These block GA4, Meta Pixel, and Clarity by default. You can also opt out of Google Analytics with the Google Analytics opt-out extension, or manage Meta's use of activity data in your Meta ad preferences.
10. Payment Processing
All payment processing is handled by Stripe. Your card details are entered directly into Stripe's secure payment form. We never see, receive, or store your credit card number, CVV, or full card details.
11. Other Services
Alongside the AI and supporting services in Section 8, QuestionsHeal relies on:
- Cloud hosting and infrastructure, to run the service
- Stripe, for payment processing
- Twilio, for SMS session reminders (opt-in only)
- Venmo, to pay commissions to Partner program members (Partners only)
Each service operates under its own privacy policy and data handling terms.
12. SMS Communications
If you schedule a session, you may opt in to receive a one-time SMS reminder approximately one hour before your session.
- Message and data rates may apply
- You can opt out at any time by replying STOP
- We do not share your phone number with third parties
- SMS is provided via Twilio
- Maximum one message per scheduled session
13. Gift and Referral Data
When you buy a gift, or arrive through a referral or Partner link, we collect and process:
- The recipient's email address, which you provide, used only to deliver the gift email and the single-use claim link
- An optional personal message from you to the recipient
- Delivery preferences, such as whether to send the gift now or on a scheduled date, and whether to send it anonymously
- Payment confirmation details from our payment processor
- Referral attribution, the referral code stored when you arrive through a referral or Partner link, used to attribute a later subscription or purchase to the referrer
A recipient's email address is used to deliver the gift and is associated with the gift record. By entering a recipient's address, you confirm you have permission to send a gift and a message to it.
14. Partner Program Data
When you apply to or participate in the Partner program, we collect and process the information you submit and that the program generates:
- Name, email address, and Venmo handle, used to evaluate your application and to pay commissions
- Application details, which vary by partner type and may include your profession, practice, or website; your platform, handle, or audience size; or your list type, size, and topic, along with any note you add
- Referral and commission records, including which members were referred through your code and the resulting commissions
This information is used to evaluate applications, operate and pay the program, prevent abuse, and meet tax and legal obligations. Payout information is shared with the payment service (Venmo) to pay you.
15. Data Retention
- Account data (email, name, hashed password) is retained until you delete your account
- Session data is retained until you delete it or delete your account
- Usage logs (anonymized) are retained for 90 days and then automatically purged
16. Your Rights
You have the right to:
- Delete your account: removes all associated data, including session history
- Delete session data: remove individual sessions or all session history
- Export your data: request a copy of your stored data
- Modify your data: update your name, email, or password
To exercise any of these rights, use the in-app settings or contact us at support@questionsheal.com.
17. Children's Privacy
QuestionsHeal is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will promptly delete it.
18. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data at rest and in transit
- Secure password hashing (PBKDF2)
- HTTPS-only connections
- Regular security reviews and audits
19. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected on this page with an updated date. We encourage you to review this page periodically.
20. Contact Us
If you have any questions about this Privacy Policy or your data, contact us at support@questionsheal.com.