Privacy Policy
This page explains what data we hold, what we do not, and what happens to what you write in the app. It is written in plain words, because you are the one who has to read it, not only a lawyer.
Last changed: 1 September 2026. Contact: hello@epimelea.com.
The short version
Epimelea has no accounts in the usual sense: no email address, no phone number, no name, no "sign in with Google". What you get instead is a key. Everything you write is encrypted on your device before it goes anywhere. What the server stores is encrypted data we cannot read.
There is one exception, and we say it plainly: the therapist is a language model running on another company’s servers, and the text of a meeting reaches it unencrypted. So the promise is not "your text never leaves your device". It is narrower: your text goes only to your device and to the servers of the company providing the model, where it is kept for up to thirty days.
What data we hold
Nothing that identifies you. We do not have your email, phone number, name, or card number. Our database has no fields for them, deliberately, so that nobody can fill them in one day "just in case".
Your account is a three-word archive name such as quiet-harbor-cedar. The server does not store the name itself. It keeps a fingerprint of it, a value for checking your password, and copies of your encryption key in sealed wrappers. Only your password, your recovery code, or your device can open those wrappers. Your password never reaches us: the app derives two different values from it, sends one as proof, and keeps the one that opens the key.
Your archive is encrypted data to us. Meetings, notebook entries, materials you bring, the therapist’s own notes: all of it is encrypted on your device with a key we do not have. We cannot read it, hand it over, or restore it. If you lose both the password and the recovery code, the archive is lost. Nobody can help with that. It follows from how the product is built, not from a decision we take case by case.
Why we store it. So that years of work do not depend on a single device. The primary copy of the archive is with us; the device holds a working one. A phone can be lost, drowned, or traded for one on another platform, and the history stays. That is the only purpose of the storage: we keep ciphertext to give it back to you when you sign in with the archive name and the password.
Operational records, with no content of conversations. We keep a few working records, to run the service and to stop it being used endlessly for free. They sit alongside the fingerprint of your archive name, never alongside your text:
- usage and cost per request, the platform (web, iOS, Android) and app version;
- the language you use and which therapist profile answered;
- crisis-check events: a severity level, the country used to choose which helpline to show, and whether it was shown, but not a word from the conversation;
- your ratings of the work: three numbers from 0 to 10 and internal marks, again with no words from the conversation;
- subscription state: what is paid for and until when.
Cloudflare, which hosts the service, sees the IP addresses of incoming requests, as any web infrastructure does. We do not connect them to your archive.
Crash reports. When the app or the server hits an error, a report goes to Sentry, a service that collects crashes. The report holds the kind of error, the place in the code, the app version, and the shape of the failed request: the route with all identifiers stripped out. It carries no text of yours, no screenshots, no recording of the screen, no archive name, and no IP address. The reports are not tied to your archive: there is no field in them for who you are.
Where the encryption stops
To answer you, the model has to read you. During a meeting the server assembles the recent part of your conversation, sends it to OpenAI, and returns the reply. Your archive on disk stays encrypted, but the text that is sent is readable in transit and on OpenAI’s side.
What we do about it: history storage is switched off in our OpenAI account, and every request is marked not to be stored. What we cannot change: OpenAI keeps a copy for up to thirty days to monitor for abuse. Those are the thirty days in the promise above. We intend to sign terms that remove this retention entirely. We will not claim them until they are signed.
If you use voice, your speech and the therapist’s spoken replies pass through ElevenLabs. They never go there straight from your device: access to that service stays on our server. The app deletes every transcription and every spoken reply from ElevenLabs’ history in the same request that created it, and repeats the deletion if the record has not appeared there yet. ElevenLabs’ own backups are outside our reach.
Quality review
We check the quality of the therapy in a way that does not turn into reading your conversations.
Automatic assessment. Shortly after a meeting, a separate model assesses, against a rubric, how the therapist conducted the conversation. The text for this goes to the same model provider that conducted the meeting, so no new recipient appears, and it is marked the same way: not to be stored. What remains in our database from that assessment is scores, marks and versions, not one word from the conversation.
Reading by a person happens only with your consent. It is off by default. You switch it on, and you can switch it off at any time. We say it plainly: a therapeutic conversation cannot be made fully anonymous. Names can be removed; the circumstances of a life cannot. Withdrawing consent closes off further access, but what has already been read cannot be unread.
Your conversations do not go towards training models, not with your consent and not without it. We do not use them for training and do not pass them to anyone for it. With the model providers we work in a mode where request data is not used for training and is not kept in any history. The thirty-day copy described above is not used for training either: it sits there in case of an abuse check and is then deleted.
Payment
Payment and content are kept apart by design: the payment side knows who paid and knows not one line of your therapy.
Your archive name is never sent to a payment service. Before a purchase, the app asks us for a one-time code. That code travels with the payment and comes back with the receipt, and only we can connect it to your archive. Apple, Google, or Paddle knows what it needs for the payment itself. With Paddle that includes your email address, which never reaches us. Buying through the App Store or Google Play is the most private route: your email is not visible to us at all. We do not store the full contents of payment notifications.
Deletion
Deleting a conversation, a meeting, or your whole account destroys the keys and the data themselves. Nothing is merely marked as hidden. Once the key is destroyed, what remains on disk cannot be decrypted by anyone, including us. The operational records listed above may outlive the account, but only in anonymous form, with no way back to a person.
Before deleting anything, you can export your archive as a folder of ordinary text files that open in any editor. Years of work should survive a new phone, a move to another platform, and the end of this project.
Who answers for your data
Your data is held by Întreprinzător Individual CLIMANOVA NICOLETA (IDNO 1024602013816), str. Feodor Dostoievski 16, of. 20, MD-3100 Bălți, Republic of Moldova. Write to hello@epimelea.com; the full details are on the legal notice page.
We process the little that is listed above in order to run the service you came for. The legal ground for that is our contract with you.
The text of a meeting says something about your health, so we process it only with your explicit consent. You give that consent when you start a meeting, and you withdraw it by deleting the meeting or the whole archive. Withdrawal counts from the moment you say so.
The companies named above are in the United States and in other countries outside the European Union; we are in the Republic of Moldova. If your data reaches them, it is because the meeting could not happen otherwise, and because you explicitly agreed to it.
You can ask for a copy of your data, correct it, delete it, restrict or object to what we do with it, and take back your consent. Most of it you do yourself: export, delete a meeting, delete the archive. For the rest, write to us. One limit is built in: the archive is encrypted with your key, so without your password we can neither show it to you nor correct it.
If you are in the European Union and think we have broken your rights, you can complain to the data protection authority where you live.
Not a medical service
Epimelea is not a medical service, and it does not replace a psychiatrist, a diagnosis, or treatment. It is not emergency help. If you are in danger right now, call your local emergency number or a crisis line; the numbers for your country are in the app.
Children
The service is not intended for people under 18.
Changes
This policy may change. We will announce any significant change in the app itself and on the site. We cannot write to you, because we do not have your email address. The date of the last change is always shown at the top of this page.