Privacy Policy.

Last updated: 2026-07-08

1. Introduction

Innersights (part of ADHD Harmony B.V.) (“Innersights,” “we,” “us”) provides a platform that lets practitioners build branded AI assessments and AI twins for the people they work with. Innersights is a trading name of ADHD Harmony B.V., registered in the Netherlands. This Privacy Policy explains how we collect and use personal data when you use the Innersights platform at innersights.ioor any associated surface, including assessment funnels, public AI twin pages, and the embeddable chat widget (the “Service”).

This Policy applies worldwide and is written to align with the EU General Data Protection Regulation (“GDPR”), the UK GDPR, the Swiss FADP, and equivalent regimes, including United States state privacy laws (Section 13). Where local law gives you stronger rights, we honour those.

2. Who controls your data

Innersights (part of ADHD Harmony B.V.)

Registered: KVK 99768070 · the Netherlands

Address: Communicatieweg Oost 12, 1566 PK Assendelft, the Netherlands

Privacy contact: privacy@innersights.io

Website: innersights.io

3. Two roles, two relationships

Innersights is a multi-tenant platform with two kinds of user, and our role under data-protection law differs depending on whose data we're handling and why.

Practitioner
A coach, therapist, consultant, educator, or similar professional who creates a workspace on Innersights to deliver assessments, AI twins, and reports to the people they work with.
Client
An individual who completes an assessment, receives a report, or chats with an AI Twin inside a Practitioner's workspace.
Website visitor
Anyone who browses our marketing site at innersights.io without signing in or completing an assessment.

Three distinct relationships follow:

  • Account data (we are controller). When a Practitioner or a Client signs up to use Innersights (names, email addresses, authentication credentials, profile information, the workspace they create, billing data once we charge), we are the controller. This Policy applies directly to that processing, including the communications we send account holders about Innersights itself (Section 7.2).
  • Practitioner's Client data (we are processor). When a Practitioner uses Innersights to collect, store, and process information from their Clients (assessment answers, chats with the AI Twin, knowledge a Practitioner uploads about a Client), the Practitioner is the controller and Innersights is the processor acting on the Practitioner's instructions, under a Data Processing Agreement (DPA). The Practitioner decides why and how that data is used in their practice and is responsible for it as controller. Clients with questions about that data, or about the Practitioner's services, should contact the Practitioner whose workspace they used; we will help where we can.
  • Website-visitor data (we are controller). When someone browses our marketing site without an account, we are the controller for any cookies, analytics, or contact-form submissions collected there. Inside the app and the assessment flow we run our own privacy-lean product analytics (Section 4.6) but no third-party advertising trackers, with one exception: an advertising pixel can be connected to an assessment funnel (for example a Meta Pixel). When a Practitioner connects their own pixel, it runs on their funnel under their control and the Practitioner is the controller for it (Section 14).
  • Our own workspaces (we are controller). We also operate workspaces of our own on the platform, for example the Innersights and ADHD Harmony programs. For those workspaces, ADHD Harmony B.V. is both the platform and the Practitioner, so we are the controller end to end, including for assessment answers, reports, AI twin chats, purchases, and any advertising pixel we connect to our own funnels.

4. Data we collect

4.1 Account information

Email address, password (hashed), display name, profile picture if provided, OAuth identifiers if you sign in with Google, and the workspace slug created from your name.

4.2 Practitioner workspace data

Assessment definitions you create, AI twin instructions and tone settings, knowledge-base documents you upload, member invitations, and submissions/reports retained inside your workspace.

4.3 Client assessment data

When you complete an assessment, we collect the data the Practitioner asked for, which typically includes:

  • Your first name and email address (so the Practitioner can identify you and we can deliver your report).
  • Your written or transcribed-voice answers to each question.
  • Any feedback you give on a category or report.
  • The consent records you agreed to before submitting.

4.4 AI Twin chat data and memory

Messages you send to an AI Twin and the AI responses you receive, retained so the conversation persists across sessions and so Practitioners can review chat history when their workspace is configured for that. To make conversations useful over time, the AI Twin also keeps a memory: short factual notes derived from your chats and assessment answers (for example your goals or what you are working on). You can see what the AI Twin remembers about you from inside the chat, and you can ask us or your Practitioner to correct or delete it.

4.5 Voice recordings

When you answer a question by voice, the audio is sent to OpenAI Whisper for transcription, then discarded. Only the resulting text is stored as your answer. Audio is not retained on our servers.

4.6 Technical data and product analytics

IP address, user-agent, device and browser information, language and time-zone preferences, and basic usage telemetry (which page you opened, when, and how the Service responded). Operational logs and error reports are processed to keep the Service reliable.

We also measure how the product is used with a small, fixed set of product-analytics events (for example “assessment started” or “report viewed”), processed by PostHog on EU servers. This analytics is deliberately privacy-lean: it sets no cookies, records no sessions, captures no page content and none of your answers or messages, and is never used for advertising. You can object to it at any time (Section 13).

4.7 Communications

Emails you send to our support addresses, and emails we send you (transactional confirmations, reports, follow-ups, and waitlist replies via Resend), including basic delivery and engagement metadata. Follow-up emails always include a working unsubscribe link.

4.8 Purchase data

When you buy a paid assessment or product, we record what you bought, when, for how much, and the resulting access rights on your account. Payment itself is handled by Stripe; we never see or store your full card details. When a Practitioner sells through their own connected payment or booking tools (for example their own Stripe account or Cal.com), we receive the purchase or booking event on their behalf so they can track conversions.

4.9 Records your Practitioner keeps about you

A Practitioner can add context about a Client inside their workspace: notes, documents, and call preparation material. That content is controlled by the Practitioner (Section 3) and is only visible inside their workspace.

4.10 Website chat widget

When you chat with an AI Twin through the widget on a Practitioner's own website, we store your messages and a random visitor token in your browser so the conversation can continue when you return. You do not need an account, and we do not know who you are unless you choose to share it in the chat.

5. Sensitive data

Practitioners may design assessments that ask about feelings, well-being, or health. Some of these answers can qualify as special category data under GDPR Article 9.

Innersights does not require Practitioners to collect health data, and we do not infer it. When a Practitioner builds an assessment, it is the Practitioner's responsibility to:

  • Decide whether their assessment will collect special-category data.
  • Establish the lawful basis for that processing under Article 9 GDPR (typically the Client's explicit consent).
  • Communicate that to the Client clearly before they submit.

As Clients submitting an assessment, we ask you to confirm consent before your answers are sent. You can withdraw that consent later by contacting the Practitioner whose workspace you used, or by deleting your Innersights account (Section 13).

7. How we use data

7.1 Provide the Service

  • Authenticate you and serve the right workspace.
  • Run assessments end-to-end: questions, voice transcription, AI follow-up checks, AI report generation, email delivery.
  • Power AI Twin chat with retrieval over the Practitioner's knowledge base.
  • Show Practitioners their workspace's submissions, reports, and members.
  • Show Practitioners anonymised, aggregated patterns in what respondents across their workspace write and ask (for example a recurring struggle, or a question many people put to their AI twin), so they can understand their audience. These patterns are only visible to the Practitioner whose assessment or AI twin you used, are drawn from many responses together, and never identify you.

7.2 Communicate

  • Send transactional emails (account confirmation, password reset, report delivery, member invitations).
  • Reply to support requests and operational notices.
  • Send updates about new features or product changes (you can opt out).
  • Tell account holders about Innersights itself: what you can do with your account, our own offerings, and, if it fits how you use the platform, the option to create a workspace of your own. We send these using your account details only, based on your consent where the law requires it and on our legitimate interest otherwise, and every message carries a working unsubscribe link.

When we email you about Innersights, we use your account details, never the content of your assessments, reports, or chats, and we never pass your details to third parties for their marketing.

7.3 Process payments and track conversions

  • Process purchases of paid assessments and products through Stripe, and grant the access you paid for.
  • Receive purchase and booking events from tools a Practitioner has connected (their own Stripe, Cal.com, or Zapier) so the Practitioner can see which Clients converted.
  • Keep purchase records for tax and accounting law.

7.4 Operate, secure, and improve

  • Detect and respond to abuse or fraud, and enforce usage limits.
  • Diagnose and fix bugs, monitor uptime, keep operational logs, and maintain backups.
  • Improve the Service via the privacy-lean product analytics described in Section 4.6 and aggregate, de-identified usage signals. We do not use your content to train AI models (Section 8).
We do not sell personal data, and we never use your assessment answers, reports, or chats for advertising. The only advertising tracking on the Service is a pixel connected to a specific assessment funnel: ours on our own funnels, or a Practitioner's on theirs (Section 14). Advertising platforms never see what happens inside the authenticated app.

8. AI and automated processing

8.1 What we use AI for

The Service uses AI to:

  • Generate the personalised report from your assessment answers (Anthropic Claude).
  • Decide whether a follow-up question would deepen your reflection (currently OpenAI models).
  • Transcribe voice answers and voice notes (OpenAI Whisper).
  • Power AI Twin chat and its memory with retrieval over the Practitioner's knowledge base, using vector embeddings (OpenAI embeddings) and chat completion (Anthropic Claude).
  • Help Practitioners draft and edit their own content, such as assessments, landing pages, follow-up emails they review before sending, call preparation notes, and advertising creative including generated images (Anthropic Claude and OpenAI image models).

8.2 No training on your data

We do not use your messages, answers, knowledge-base content, or uploaded files to train, fine-tune, or improve foundation models. Our agreements with Anthropic and OpenAI prohibit training on data sent through their APIs, and we opt into zero-data-retention configurations with these providers where available. AI providers do not gain ownership of any content submitted to or generated by their models on your behalf. Your content is processed only to deliver the Service to you.

8.3 Human oversight and limits

AI prompts, frameworks, and safety guardrails are designed and maintained by humans. AI output may be wrong, incomplete, or out-of-date. See Section 15 of our Terms of Service.

8.4 No automated decisions with legal effect

The Service does not make decisions about you that produce legal effects or similarly significant effects within the meaning of GDPR Article 22. AI outputs are reflective material; any decision is made by you or by your Practitioner.

8.5 AI transparency

In line with EU AI transparency rules, you always know when you are dealing with AI on the Service: AI twins are presented as AI assistants and reports as AI-generated. We do not use AI to impersonate humans.

9. Sharing and subprocessors

We share personal data with a small number of vendors that operate parts of the Service for us (“subprocessors”). Each is bound by a data-processing agreement and is allowed to process data only as instructed by us.

Vercel· USA / global edge

Purpose: Application hosting, edge runtime, AI Gateway, deployment platform.

Data shared: All data flowing through the Service.

Supabase· European Union

Purpose: Database, authentication, file storage, RLS-protected APIs.

Data shared: All data at rest, including assessments, submissions, knowledge-base files, and account records.

Anthropic (Claude)· USA (with DPA, no training)

Purpose: AI inference: report generation, follow-up checks, AI twin chat.

Data shared: Question prompts, your answers (in transit), AI twin chat messages, retrieved knowledge-base snippets.

OpenAI· USA (with DPA, no training)

Purpose: AI inference: voice transcription (Whisper), embeddings for retrieval, occasional auxiliary generation (e.g. follow-up checks).

Data shared: Voice audio (transient), text snippets for embedding, occasional question prompts.

Stripe· USA / EU (DPF certified)

Purpose: Payment processing for paid assessments and products, including fraud prevention.

Data shared: Name, email, payment details (held by Stripe, not by us), purchase amount and history.

Resend· USA (DPF certified)

Purpose: Transactional email delivery, including auth emails routed through Supabase's send-email hook.

Data shared: Email addresses, email body content.

PostHog· European Union

Purpose: Privacy-lean product analytics: a fixed set of funnel events, no cookies, no session recording, no autocapture.

Data shared: Pseudonymous user id, workspace and assessment identifiers, event timestamps.

Better Stack· European Union

Purpose: Operational logging and alerting so we can detect and fix failures.

Data shared: Technical log data, which can include IP addresses and account identifiers.

Google· Global

Purpose: OAuth identity (sign-in only). We do not access Gmail, Drive, Tasks, or Calendar.

Data shared: Email address, name, profile picture, Google account ID.

Cloudflare· Global

Purpose: Bot protection and edge-network protection where deployed.

Data shared: IP address, request metadata.

Langfuse· European Union

Purpose: Prompt-quality monitoring and AI-output observability so we can debug bad responses and improve safety guardrails.

Data shared: Anonymised prompt/response pairs and metadata for quality assurance.

Two categories sit outside this table. First, when we advertise our own programs, we connect Meta (Facebook) advertising tools to our own assessment funnels: the Meta Pixel and Conversions API receive funnel events (page view, assessment started, purchase) with your IP address, browser information, and a hashed email address, so we can measure our ads. This runs only on our own funnels, never inside the authenticated app. Second, when a Practitioner connects their own tools to their workspace (their advertising pixel, Stripe account, Cal.com, or Zapier), those tools are engaged by the Practitioner, and the Practitioner is the controller for them.

9.1 What we never do

  • We never sell personal data.
  • We never use Client assessment data, AI Twin chat content, or knowledge-base content for advertising, profiling, or look-alike modelling.
  • We never share your content with third parties for their own marketing purposes.
  • We never use your data to train AI models.

9.2 Other disclosures

  • We may disclose personal data to comply with valid legal process or to protect our rights, your safety, or the safety of others.
  • If we are involved in a merger, acquisition, or asset sale, personal data may transfer as part of that transaction; we will notify you and ensure the new entity is bound by terms at least as protective as this Policy.
  • We may publish anonymised, aggregated metrics that cannot identify any individual.

10. International transfers

Some of our subprocessors are based outside the EU/EEA, including in the United States. When we transfer personal data internationally we rely on:

  • EU-US Data Privacy Framework (DPF) where the recipient is certified.
  • EU Standard Contractual Clauses (SCCs) for transfers to other countries that lack an adequacy decision.
  • Supplementary measures, including encryption in transit (TLS) and at rest, and contractual prohibitions on training and onward transfers.

You can request a copy of the relevant transfer mechanism from privacy@innersights.io.

11. Security

We take security seriously and apply technical and organisational measures appropriate to the risk, including:

  • TLS encryption for data in transit and at-rest encryption for the database, file storage, and backups.
  • Row-level security (RLS) on every workspace data table, so a workspace's content is only accessible to that workspace's members.
  • Hashed passwords (industry-standard algorithms via Supabase Auth).
  • Role-based access controls for staff, audit logging, and least-privilege service-role keys.
  • Continuous dependency, runtime, and vulnerability monitoring.
  • Subprocessor due diligence and contractual security obligations.

No system is perfectly secure. If we become aware of a personal-data breach that creates risk for you, we will notify the relevant authorities and affected users as required by law.

12. Retention

Account profile data
While your account is active, then deleted within 30 days of account deletion (subject to legal-hold exceptions below).
Assessment submissions and reports
While the owning workspace exists. Practitioners can delete individual submissions; Clients can request deletion through us or the Practitioner.
AI Twin chat history and memory
Until you delete it or ask us to, or until the workspace is deleted.
Purchase and entitlement records
As long as needed for your access and for tax and accounting law (typically 7 years in the EU).
Product-analytics events
Pseudonymous events retained under PostHog's standard retention, then deleted or aggregated.
Operational logs
Short-lived rolling windows, typically 30 days or less.
Knowledge-base documents and embeddings
Until the Practitioner deletes them or the workspace is deleted.
Voice audio
Not stored. Used only for transcription and discarded immediately afterwards.
Email logs (Resend)
Standard provider retention windows for delivery analytics.
Authentication logs
Up to 12 months for security and abuse-detection purposes.
Tax / accounting records
As long as required by applicable law (typically 7 years in the EU).

Where law requires us to keep specific records, we limit access to those records and delete them as soon as the legal obligation expires.

12.1 Deletion timelines

  • Client deletion request. A Client can ask their Practitioner or email us at privacy@innersights.io to delete their submission and account. Confirmed deletions are permanent within 14 days.
  • Practitioner deletion request. A Practitioner can request deletion of their account and workspace. We will first offer to export their workspace data; the account and any remaining data are then permanently removed within 30 days, subject to legal-hold exceptions.

13. Your rights

Where we are the controller, you have the following rights, subject to local-law conditions:

Access
Get a copy of the personal data we hold about you.
Rectification
Correct inaccurate or incomplete data.
Erasure (right to be forgotten)
Ask us to delete your personal data, subject to limited exceptions.
Portability
Receive your data in a structured, machine-readable format.
Restriction
Limit how we use your data while a question about it is being resolved.
Objection
Object to processing based on legitimate interests, including any limited operational analytics.
Withdraw consent
Withdraw consent for processing based on consent, without affecting the lawfulness of earlier processing.
Right not to be subject to automated decisions
We do not make automated decisions with legal effect (Section 8.4).

13.1 How to exercise your rights

  • Use account settings to update your profile, and delete individual submissions or chats from within the Service.
  • To delete your entire account and workspace, email us (below) and we will process it within 30 days. Practitioners can also request deletion of a specific Client's data.
  • Email us at privacy@innersights.io and we will respond within 30 days (extendable by 60 days for complex requests). We may need to verify your identity.
  • If your data is held inside a Practitioner's workspace and they are the controller, we will help route your request to that Practitioner.

13.2 United States state privacy laws

If you live in a US state with a comprehensive privacy law (for example California, Virginia, Colorado, Connecticut, Texas, or Oregon), you also have the right to:

  • Know what personal information we collect, use, disclose, and (if applicable) sell.
  • Confirm we do not sell personal information and do not share it for cross-context behavioural advertising. We don't.
  • Opt out of any future sale, sharing, or targeted advertising, and of profiling that produces legal or similarly significant effects (we do neither).
  • Request access, correction, deletion, and a portable copy of your personal information.
  • Be free from discrimination for exercising your privacy rights, and appeal a refused request.

Some assessment answers can relate to your wellbeing. Where a state law treats that as consumer health data (for example Washington's My Health My Data Act), we collect it only with your consent, use it only to deliver the Service, never sell it, and never use it for advertising.

To exercise any of these rights, contact us at privacy@innersights.io.

13.3 Right to complain

You can lodge a complaint with your local supervisory authority. In the Netherlands, that is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), autoriteitpersoonsgegevens.nl.

14. Cookies and similar technologies

We use only what we need to run the Service. Advertising tracking appears in exactly one place: assessment funnels where a pixel has been connected, described in the last two rows below. It never runs inside the authenticated app.

Essential
Authentication cookies (managed by Supabase Auth), session cookies, sidebar-state cookie, and theme cookie. Cannot be disabled without breaking the Service.
Local storage
Used to persist UI preferences, partial assessment state, our cookieless analytics identifier (Section 4.6), and, for the website widget, a visitor token so your conversation can continue when you return.
Payments (Stripe)
During checkout, Stripe sets cookies needed to process your payment and prevent fraud. These are set only when the checkout is open.
Bot protection
Our edge network may set a short-lived cookie to verify a browser is not automated.
Our advertising pixel (own funnels only)
On funnels for our own programs, we connect the Meta Pixel and its server-side Conversions API to measure our advertising. It sends funnel events (page view, assessment started, purchase) with IP address, browser information, and a hashed email address to Meta. We are the controller for this tracking.
Practitioner advertising pixel (optional)
If a Practitioner connects an advertising pixel (for example a Meta Pixel) to their assessment funnel, that pixel (and its server-side equivalent) sends funnel events to the advertising platform. It runs only on funnels where the Practitioner has enabled it, and the Practitioner is the controller for that tracking.

Our product analytics (Section 4.6) is cookieless by design: it uses local storage only, runs on EU servers, and is never used for advertising.

We do not run advertising or behavioural-tracking cookies inside the app, and we never use Client assessment content for advertising. Advertising pixels appear only on assessment funnels where they have been deliberately connected: by us on our own funnels, or by a Practitioner on theirs.

15. Age requirement

The Service is intended for people aged 18 and over. We do not knowingly collect personal data from individuals under 16, and a Practitioner who runs assessments with anyone under 18 is responsible for obtaining parental or guardian consent under their own regulatory framework. If you believe a minor has provided us personal data, contact privacy@innersights.io and we will delete it.

16. Changes to this Policy

We may update this Policy as the Service evolves or the law changes. We will:

  • Update the date at the top of this page.
  • For material changes affecting account holders, send notice via the Service or email at least 14 days before the change takes effect.
  • Where new processing requires it, ask for your consent before relying on it.

17. Contact

Innersights (part of ADHD Harmony B.V.)

Privacy: privacy@innersights.io

Legal: legal@innersights.io

General: hello@innersights.io

By using Innersights, you acknowledge that you have read and understood this Privacy Policy.