Privacy Policy
1. Information We Collect
1.1 Information You Provide
When you create an account and use the Service, you may provide:
- Account information: name, email address, and password
- Profile information: age range, wellness goals, and preferences set during onboarding
- Journal entries and mood logs: text or other content you submit through the app
- Conversation data: messages exchanged with Therma’s wellness companion
- Payment information: processed by our third-party payment provider (we do not store full card details)
1.2 Information Collected Automatically
When you use the Service, we may automatically collect:
- Device identifiers, operating system version, and app version
- Usage data: features accessed, session duration, and interaction patterns
- Crash reports and diagnostic logs (anonymised where possible)
- IP address and approximate location (country/region level only)
1.3 Health and Wellness Data
Therma is designed as a personal emotional wellness tool. The emotional and mood data you enter is treated with the highest level of privacy protection. We do not sell, rent, or monetise your personal health or wellness data. If you choose to connect Apple Health or other integrations, that data is processed locally to generate insights and is not shared with third parties.
If you choose to connect Apple Health, Therma syncs relevant health data automatically in the background on a daily basis — no manual action is required from you. We access only the specific HealthKit data types necessary for the features you use (such as sleep data, heart rate, or mindful minutes) and do not request access to unrelated data types. HealthKit data is never used for marketing, advertising, or data mining, and is never shared with third parties for these purposes. Your health data is stored on HIPAA-eligible Google Cloud Platform servers and is not stored in iCloud or Apple’s iCloud backup. Any third party that receives HealthKit data does so only to provide health or fitness services and is subject to equivalent data protection obligations.
1.4 Companion Feature Data Processing
When you use Therma’s companion features — including mood check-ins, journaling, and guided conversations — the content of your interactions is transmitted to Google Vertex AI (Gemini), a third-party cloud processing service operated by Google LLC. This transmission is necessary to generate personalised responses and insights. Specifically, the following data types may be sent:
- Your journal entries and mood logs (when you engage with companion features)
- Messages you send within the companion experience
- Contextual mood and wellness patterns used to personalise responses
Google processes this data solely to generate your responses and does not use it to train general models or for advertising purposes, pursuant to our Data Processing Agreement with Google. For more information, see Google’s Privacy Policy at policies.google.com/privacy.
Before your data is first transmitted, we will ask for your explicit consent within the app. You may withdraw this consent at any time through your in-app privacy settings. Withdrawing consent will disable companion features but will not affect your ability to use journaling and mood tracking independently.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Therma Service
- Personalise your experience and deliver insights through the companion features
- Send you notifications and reminders you have opted into
- Respond to your support requests and enquiries
- Analyse usage trends to improve app performance and features
- Comply with legal obligations and enforce our Terms of Service
- Detect and prevent fraud, abuse, or unauthorised access
We do not use your journal entries or mood data to train general language models or sell insights to third parties.
3. How We Share Your Information
We do not sell your personal information. We may share your information only in the following limited circumstances:
3.1 Service Providers
We work with trusted third-party service providers who assist in operating the Service, including:
- Cloud infrastructure and data storage (Google Cloud Platform)
- Cloud processing services powering the in-app companion (Google Vertex AI / Gemini)
- Payment processing (Apple App Store)
- Anonymised analytics and crash reporting
- Email and notification delivery
These providers are contractually required to use your information only to provide services to us, to maintain appropriate security measures, and to provide the same or equivalent level of protection for your personal data as described in this Privacy Policy.
3.2 Legal Requirements
We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe disclosure is necessary to protect the rights, property, or safety of Therma, our users, or the public.
3.3 Business Transfers
If Therma is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and your choices regarding your data.
4. Data Retention
We retain your personal information for as long as your account is active or as necessary to provide the Service. You may request deletion of your account and associated data at any time by contacting support@gettherma.ai. Upon deletion, we will remove or anonymise your personal data within a reasonable timeframe, unless we are required to retain it by law.
5. Data Security
We implement industry-standard security measures to protect your information:
- Encryption of data in transit (TLS/HTTPS)
- Encryption of data at rest (AES-256 or equivalent)
- Access controls limiting internal access to your data
- HIPAA-eligible cloud services for storage
No method of transmission over the internet is 100% secure. While we use commercially acceptable means to protect your personal information, we cannot guarantee absolute security.
6. Your Rights and Choices
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Request deletion of your personal information
- Object to or restrict certain processing of your data
- Export your data in a portable format
To exercise any of these rights, contact support@gettherma.ai. We will respond within a reasonable timeframe.
You can also manage your data and consent preferences directly within the app. From your in-app privacy and account settings you can:
- Review and manage companion feature processing consent
- Export your data
- Request deletion of your account and all associated data
We collect only the minimum data necessary for each feature you use. If you do not use a particular feature, we do not collect data associated with it.
6.1 California Residents (CCPA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete your personal information, and the right to opt out of the sale of your personal information. We do not sell personal information. To submit a CCPA request, contact support@gettherma.ai.
6.2 Canadian Residents (PIPEDA and Quebec Law 25)
Automated Decision-Making (Quebec Law 25): Therma uses automated processing to generate personalised mood insights, pattern recognition, and wellness suggestions. These outputs are informational only and do not constitute decisions with legal or significant effects. No solely automated decisions are made about you that produce legal effects or similarly significant impacts. If you are a Quebec resident and wish to know more about how our automated processing works, request human review of any output, or object to automated processing, contact support@gettherma.ai.
Electronic Messages (CASL): If you are a Canadian resident and receive marketing emails or promotional push notifications from Therma, we will only send these with your express consent. You may withdraw consent to marketing communications at any time through your in-app notification settings or by contacting support@gettherma.ai. Transactional messages (such as account confirmations and billing notices) are not subject to this opt-out.
Language: We are working to make this Privacy Policy available in French for our Quebec users. If you require a French version, please contact support@gettherma.ai.
If you are a resident of Canada, your personal information is also governed by Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and, if you reside in Quebec, by Quebec’s Act Respecting the Protection of Personal Information in the Private Sector (Law 25), which sets the highest provincial standard in Canada.
As a Canadian resident, you have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Withdraw consent to our collection or use of your personal information at any time, subject to legal or contractual restrictions — note that withdrawing consent may affect your ability to use some or all of the Service
- Request deletion of your personal information (subject to legal retention obligations)
- File a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca, or with the Commission d’accès à l’information (CAI) if you are in Quebec
We collect, use, and disclose your personal information only with your knowledge and consent, except where otherwise permitted or required by law. We designate Omar Rantisi (support@gettherma.ai) as our accountable privacy officer for Canadian privacy matters.
To exercise any of these rights or to withdraw consent, contact support@gettherma.ai. We will respond within 30 days as required under PIPEDA.
7. Children’s Privacy
The Service is not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected information from a child under 13, please contact support@gettherma.ai immediately and we will take steps to delete that information.
8. Third-Party Links and Services
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information.
9. International Data Transfers
Get Therma Inc. is based in the United States. If you access the Service from outside the United States — including from Canada — your information may be transferred to and processed in the United States, where data protection laws may differ from those in your country or province.
Canadian users should be aware that their personal information may be subject to access by US courts, law enforcement, and national security authorities under US law. By using the Service, you consent to this transfer. Where required by applicable law, we take steps to ensure that your information receives a comparable level of protection wherever it is processed.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new Policy in the app and, where required by law, obtaining your consent. The effective date at the top of this Policy indicates when it was last revised. Your continued use of the Service after any changes constitutes your acceptance of the updated Policy.
11. Contact Us
Get Therma Inc.
support@gettherma.ai
Get Therma Inc. · Privacy Policy v1.1 · March 2026