Privacy Policy.
Last updated: 2026-07-08
1. Introduction
Innersights (part of ADHD Harmony B.V.) (“Innersights,” “we,” “us”) provides a platform that lets practitioners build branded AI assessments and AI twins for the people they work with. Innersights is a trading name of ADHD Harmony B.V., registered in the Netherlands. This Privacy Policy explains how we collect and use personal data when you use the Innersights platform at innersights.ioor any associated surface, including assessment funnels, public AI twin pages, and the embeddable chat widget (the “Service”).
This Policy applies worldwide and is written to align with the EU General Data Protection Regulation (“GDPR”), the UK GDPR, the Swiss FADP, and equivalent regimes, including United States state privacy laws (Section 13). Where local law gives you stronger rights, we honour those.
2. Who controls your data
Innersights (part of ADHD Harmony B.V.)
Registered: KVK 99768070 · the Netherlands
Address: Communicatieweg Oost 12, 1566 PK Assendelft, the Netherlands
Privacy contact: privacy@innersights.io
Website: innersights.io
3. Two roles, two relationships
Innersights is a multi-tenant platform with two kinds of user, and our role under data-protection law differs depending on whose data we're handling and why.
- Practitioner
- A coach, therapist, consultant, educator, or similar professional who creates a workspace on Innersights to deliver assessments, AI twins, and reports to the people they work with.
- Client
- An individual who completes an assessment, receives a report, or chats with an AI Twin inside a Practitioner's workspace.
- Website visitor
- Anyone who browses our marketing site at innersights.io without signing in or completing an assessment.
Three distinct relationships follow:
- Account data (we are controller). When a Practitioner or a Client signs up to use Innersights (names, email addresses, authentication credentials, profile information, the workspace they create, billing data once we charge), we are the controller. This Policy applies directly to that processing, including the communications we send account holders about Innersights itself (Section 7.2).
- Practitioner's Client data (we are processor). When a Practitioner uses Innersights to collect, store, and process information from their Clients (assessment answers, chats with the AI Twin, knowledge a Practitioner uploads about a Client), the Practitioner is the controller and Innersights is the processor acting on the Practitioner's instructions, under a Data Processing Agreement (DPA). The Practitioner decides why and how that data is used in their practice and is responsible for it as controller. Clients with questions about that data, or about the Practitioner's services, should contact the Practitioner whose workspace they used; we will help where we can.
- Website-visitor data (we are controller). When someone browses our marketing site without an account, we are the controller for any cookies, analytics, or contact-form submissions collected there. Inside the app and the assessment flow we run our own privacy-lean product analytics (Section 4.6) but no third-party advertising trackers, with one exception: an advertising pixel can be connected to an assessment funnel (for example a Meta Pixel). When a Practitioner connects their own pixel, it runs on their funnel under their control and the Practitioner is the controller for it (Section 14).
- Our own workspaces (we are controller). We also operate workspaces of our own on the platform, for example the Innersights and ADHD Harmony programs. For those workspaces, ADHD Harmony B.V. is both the platform and the Practitioner, so we are the controller end to end, including for assessment answers, reports, AI twin chats, purchases, and any advertising pixel we connect to our own funnels.
4. Data we collect
4.1 Account information
Email address, password (hashed), display name, profile picture if provided, OAuth identifiers if you sign in with Google, and the workspace slug created from your name.
4.2 Practitioner workspace data
Assessment definitions you create, AI twin instructions and tone settings, knowledge-base documents you upload, member invitations, and submissions/reports retained inside your workspace.
4.3 Client assessment data
When you complete an assessment, we collect the data the Practitioner asked for, which typically includes:
- Your first name and email address (so the Practitioner can identify you and we can deliver your report).
- Your written or transcribed-voice answers to each question.
- Any feedback you give on a category or report.
- The consent records you agreed to before submitting.
4.4 AI Twin chat data and memory
Messages you send to an AI Twin and the AI responses you receive, retained so the conversation persists across sessions and so Practitioners can review chat history when their workspace is configured for that. To make conversations useful over time, the AI Twin also keeps a memory: short factual notes derived from your chats and assessment answers (for example your goals or what you are working on). You can see what the AI Twin remembers about you from inside the chat, and you can ask us or your Practitioner to correct or delete it.
4.5 Voice recordings
When you answer a question by voice, the audio is sent to OpenAI Whisper for transcription, then discarded. Only the resulting text is stored as your answer. Audio is not retained on our servers.
4.6 Technical data and product analytics
IP address, user-agent, device and browser information, language and time-zone preferences, and basic usage telemetry (which page you opened, when, and how the Service responded). Operational logs and error reports are processed to keep the Service reliable.
We also measure how the product is used with a small, fixed set of product-analytics events (for example “assessment started” or “report viewed”), processed by PostHog on EU servers. This analytics is deliberately privacy-lean: it sets no cookies, records no sessions, captures no page content and none of your answers or messages, and is never used for advertising. You can object to it at any time (Section 13).
4.7 Communications
Emails you send to our support addresses, and emails we send you (transactional confirmations, reports, follow-ups, and waitlist replies via Resend), including basic delivery and engagement metadata. Follow-up emails always include a working unsubscribe link.
4.8 Purchase data
When you buy a paid assessment or product, we record what you bought, when, for how much, and the resulting access rights on your account. Payment itself is handled by Stripe; we never see or store your full card details. When a Practitioner sells through their own connected payment or booking tools (for example their own Stripe account or Cal.com), we receive the purchase or booking event on their behalf so they can track conversions.
4.9 Records your Practitioner keeps about you
A Practitioner can add context about a Client inside their workspace: notes, documents, and call preparation material. That content is controlled by the Practitioner (Section 3) and is only visible inside their workspace.
4.10 Website chat widget
When you chat with an AI Twin through the widget on a Practitioner's own website, we store your messages and a random visitor token in your browser so the conversation can continue when you return. You do not need an account, and we do not know who you are unless you choose to share it in the chat.
5. Sensitive data
Innersights does not require Practitioners to collect health data, and we do not infer it. When a Practitioner builds an assessment, it is the Practitioner's responsibility to:
- Decide whether their assessment will collect special-category data.
- Establish the lawful basis for that processing under Article 9 GDPR (typically the Client's explicit consent).
- Communicate that to the Client clearly before they submit.
As Clients submitting an assessment, we ask you to confirm consent before your answers are sent. You can withdraw that consent later by contacting the Practitioner whose workspace you used, or by deleting your Innersights account (Section 13).
6. Legal basis for processing
Where we are the controller (Section 3), we rely on the following GDPR Article 6 legal bases:
- Contract (Art. 6(1)(b))
- Creating and maintaining your account, providing the Service, processing your assessments, delivering your report, and operating your workspace.
- Legitimate interests (Art. 6(1)(f))
- Keeping the Service secure, preventing abuse, debugging, improving how the Service works, limited transactional communications, and telling account holders about our own services where the law allows it, always with an easy opt-out. We balance these interests against your privacy and you can object at any time.
- Consent (Art. 6(1)(a) and 9(2)(a))
- Special-category data submitted via assessments, optional marketing communications, and any feature that explicitly asks for it.
- Legal obligation (Art. 6(1)(c))
- Tax, accounting, fraud prevention, and responses to lawful requests from authorities.
7. How we use data
7.1 Provide the Service
- Authenticate you and serve the right workspace.
- Run assessments end-to-end: questions, voice transcription, AI follow-up checks, AI report generation, email delivery.
- Power AI Twin chat with retrieval over the Practitioner's knowledge base.
- Show Practitioners their workspace's submissions, reports, and members.
- Show Practitioners anonymised, aggregated patterns in what respondents across their workspace write and ask (for example a recurring struggle, or a question many people put to their AI twin), so they can understand their audience. These patterns are only visible to the Practitioner whose assessment or AI twin you used, are drawn from many responses together, and never identify you.
7.2 Communicate
- Send transactional emails (account confirmation, password reset, report delivery, member invitations).
- Reply to support requests and operational notices.
- Send updates about new features or product changes (you can opt out).
- Tell account holders about Innersights itself: what you can do with your account, our own offerings, and, if it fits how you use the platform, the option to create a workspace of your own. We send these using your account details only, based on your consent where the law requires it and on our legitimate interest otherwise, and every message carries a working unsubscribe link.
When we email you about Innersights, we use your account details, never the content of your assessments, reports, or chats, and we never pass your details to third parties for their marketing.
7.3 Process payments and track conversions
- Process purchases of paid assessments and products through Stripe, and grant the access you paid for.
- Receive purchase and booking events from tools a Practitioner has connected (their own Stripe, Cal.com, or Zapier) so the Practitioner can see which Clients converted.
- Keep purchase records for tax and accounting law.
7.4 Operate, secure, and improve
- Detect and respond to abuse or fraud, and enforce usage limits.
- Diagnose and fix bugs, monitor uptime, keep operational logs, and maintain backups.
- Improve the Service via the privacy-lean product analytics described in Section 4.6 and aggregate, de-identified usage signals. We do not use your content to train AI models (Section 8).
8. AI and automated processing
8.1 What we use AI for
The Service uses AI to:
- Generate the personalised report from your assessment answers (Anthropic Claude).
- Decide whether a follow-up question would deepen your reflection (currently OpenAI models).
- Transcribe voice answers and voice notes (OpenAI Whisper).
- Power AI Twin chat and its memory with retrieval over the Practitioner's knowledge base, using vector embeddings (OpenAI embeddings) and chat completion (Anthropic Claude).
- Help Practitioners draft and edit their own content, such as assessments, landing pages, follow-up emails they review before sending, call preparation notes, and advertising creative including generated images (Anthropic Claude and OpenAI image models).
8.2 No training on your data
8.3 Human oversight and limits
AI prompts, frameworks, and safety guardrails are designed and maintained by humans. AI output may be wrong, incomplete, or out-of-date. See Section 15 of our Terms of Service.
8.4 No automated decisions with legal effect
The Service does not make decisions about you that produce legal effects or similarly significant effects within the meaning of GDPR Article 22. AI outputs are reflective material; any decision is made by you or by your Practitioner.
8.5 AI transparency
In line with EU AI transparency rules, you always know when you are dealing with AI on the Service: AI twins are presented as AI assistants and reports as AI-generated. We do not use AI to impersonate humans.
10. International transfers
Some of our subprocessors are based outside the EU/EEA, including in the United States. When we transfer personal data internationally we rely on:
- EU-US Data Privacy Framework (DPF) where the recipient is certified.
- EU Standard Contractual Clauses (SCCs) for transfers to other countries that lack an adequacy decision.
- Supplementary measures, including encryption in transit (TLS) and at rest, and contractual prohibitions on training and onward transfers.
You can request a copy of the relevant transfer mechanism from privacy@innersights.io.
11. Security
We take security seriously and apply technical and organisational measures appropriate to the risk, including:
- TLS encryption for data in transit and at-rest encryption for the database, file storage, and backups.
- Row-level security (RLS) on every workspace data table, so a workspace's content is only accessible to that workspace's members.
- Hashed passwords (industry-standard algorithms via Supabase Auth).
- Role-based access controls for staff, audit logging, and least-privilege service-role keys.
- Continuous dependency, runtime, and vulnerability monitoring.
- Subprocessor due diligence and contractual security obligations.
No system is perfectly secure. If we become aware of a personal-data breach that creates risk for you, we will notify the relevant authorities and affected users as required by law.
12. Retention
- Account profile data
- While your account is active, then deleted within 30 days of account deletion (subject to legal-hold exceptions below).
- Assessment submissions and reports
- While the owning workspace exists. Practitioners can delete individual submissions; Clients can request deletion through us or the Practitioner.
- AI Twin chat history and memory
- Until you delete it or ask us to, or until the workspace is deleted.
- Purchase and entitlement records
- As long as needed for your access and for tax and accounting law (typically 7 years in the EU).
- Product-analytics events
- Pseudonymous events retained under PostHog's standard retention, then deleted or aggregated.
- Operational logs
- Short-lived rolling windows, typically 30 days or less.
- Knowledge-base documents and embeddings
- Until the Practitioner deletes them or the workspace is deleted.
- Voice audio
- Not stored. Used only for transcription and discarded immediately afterwards.
- Email logs (Resend)
- Standard provider retention windows for delivery analytics.
- Authentication logs
- Up to 12 months for security and abuse-detection purposes.
- Tax / accounting records
- As long as required by applicable law (typically 7 years in the EU).
Where law requires us to keep specific records, we limit access to those records and delete them as soon as the legal obligation expires.
12.1 Deletion timelines
- Client deletion request. A Client can ask their Practitioner or email us at privacy@innersights.io to delete their submission and account. Confirmed deletions are permanent within 14 days.
- Practitioner deletion request. A Practitioner can request deletion of their account and workspace. We will first offer to export their workspace data; the account and any remaining data are then permanently removed within 30 days, subject to legal-hold exceptions.
13. Your rights
Where we are the controller, you have the following rights, subject to local-law conditions:
- Access
- Get a copy of the personal data we hold about you.
- Rectification
- Correct inaccurate or incomplete data.
- Erasure (right to be forgotten)
- Ask us to delete your personal data, subject to limited exceptions.
- Portability
- Receive your data in a structured, machine-readable format.
- Restriction
- Limit how we use your data while a question about it is being resolved.
- Objection
- Object to processing based on legitimate interests, including any limited operational analytics.
- Withdraw consent
- Withdraw consent for processing based on consent, without affecting the lawfulness of earlier processing.
- Right not to be subject to automated decisions
- We do not make automated decisions with legal effect (Section 8.4).
13.1 How to exercise your rights
- Use account settings to update your profile, and delete individual submissions or chats from within the Service.
- To delete your entire account and workspace, email us (below) and we will process it within 30 days. Practitioners can also request deletion of a specific Client's data.
- Email us at privacy@innersights.io and we will respond within 30 days (extendable by 60 days for complex requests). We may need to verify your identity.
- If your data is held inside a Practitioner's workspace and they are the controller, we will help route your request to that Practitioner.
13.2 United States state privacy laws
If you live in a US state with a comprehensive privacy law (for example California, Virginia, Colorado, Connecticut, Texas, or Oregon), you also have the right to:
- Know what personal information we collect, use, disclose, and (if applicable) sell.
- Confirm we do not sell personal information and do not share it for cross-context behavioural advertising. We don't.
- Opt out of any future sale, sharing, or targeted advertising, and of profiling that produces legal or similarly significant effects (we do neither).
- Request access, correction, deletion, and a portable copy of your personal information.
- Be free from discrimination for exercising your privacy rights, and appeal a refused request.
Some assessment answers can relate to your wellbeing. Where a state law treats that as consumer health data (for example Washington's My Health My Data Act), we collect it only with your consent, use it only to deliver the Service, never sell it, and never use it for advertising.
To exercise any of these rights, contact us at privacy@innersights.io.
13.3 Right to complain
You can lodge a complaint with your local supervisory authority. In the Netherlands, that is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), autoriteitpersoonsgegevens.nl.
15. Age requirement
The Service is intended for people aged 18 and over. We do not knowingly collect personal data from individuals under 16, and a Practitioner who runs assessments with anyone under 18 is responsible for obtaining parental or guardian consent under their own regulatory framework. If you believe a minor has provided us personal data, contact privacy@innersights.io and we will delete it.
16. Changes to this Policy
We may update this Policy as the Service evolves or the law changes. We will:
- Update the date at the top of this page.
- For material changes affecting account holders, send notice via the Service or email at least 14 days before the change takes effect.
- Where new processing requires it, ask for your consent before relying on it.
17. Contact
Innersights (part of ADHD Harmony B.V.)
Privacy: privacy@innersights.io
Legal: legal@innersights.io
General: hello@innersights.io
By using Innersights, you acknowledge that you have read and understood this Privacy Policy.