Privacy Statement
Last Updated: January 10, 2026
This Privacy Statement explains how EmoBay Limited ("EmoBay", "we", "us", or "our") collects, uses, shares, and protects personal data when you use our websites and apps, including `emobay.org` (the website), `chat.emobay.org` (the web app), and the EmoBay iOS app (collectively, the "Service").
By using the Service, you understand that we may process your personal data as described below. This policy is intended to align with Hong Kong’s Personal Data (Privacy) Ordinance (PDPO) and, where applicable, other privacy laws in the regions where we operate.
1. Key Definitions
- Personal Data: data that identifies you or can reasonably be linked to you (e.g., email address).
- Sensitive Data: categories that require additional protection under law (e.g., health or mental-health related data).
- Content: information you submit to the Service such as chat messages, journal entries, check-ins, and uploads.
2. What We Collect
2.1 Account and Profile Data
- Email address and login/verification information (e.g., one-time codes).
- Profile information you provide (e.g., preferred name, “about” text, preferences).
- Guest mode identifiers: if you use the EmoBay iOS app without creating an account, we create a pseudonymous identifier to operate the Service (for example, to maintain a session and store your Content and subscription entitlements). You can choose to create an account later to sync across devices.
- Optional verification data for promotions or eligibility checks (e.g., university email, institution name).
- Subscription status and plan metadata. For App Store purchases, we process receipt and transaction identifiers (for example, subscription product IDs and original transaction identifiers) to verify purchases, restore access, and prevent fraud. We do not receive your Apple ID password or full payment card details for App Store purchases.
2.2 Content You Provide
- Chat conversations (messages and timestamps) and conversation titles.
- Call transcripts (text) and other in-app notes or entries (e.g., journals, daily check-ins).
- Uploads such as profile avatars and photos you attach to timeline entries or chats.
- Support requests and communications you send to us.
2.3 Device, Usage, and Log Data
- Device and browser/app information (e.g., operating system, app version, basic diagnostics).
- IP address and approximate location (e.g., country) inferred from IP for safety resources and features.
- Cookies or similar technologies used for authentication and preferences.
2.4 Optional Health Data (iOS)
If you enable Apple Health access in the iOS app, EmoBay may read selected HealthKit metrics (e.g., sleep, steps, workouts, certain heart metrics) to generate an on-device daily summary. EmoBay does not write data to Apple Health.
Apple Health data is processed on your device. We do not upload Apple Health metrics to our servers unless we clearly ask you to and you explicitly choose to share them.
3. How We Use Personal Data
- Provide the Service: authentication, session management, syncing across devices, and core app features (chat, journals, check-ins, call transcripts).
- Personalization: preferences you set (e.g., assistant style) and feature settings (e.g., Memory and Health Trends consent).
- Safety: we may analyze certain content to detect crisis intent and show crisis resources or safer guidance (see Section 4).
- Support and communications: respond to support tickets and send important service messages.
- Billing: manage subscriptions, plan entitlements, and payment-related notifications.
- Fraud prevention: help prevent abuse (including preventing an App Store subscription from being linked to multiple EmoBay accounts).
- Improve and secure the Service: troubleshoot, prevent abuse, and improve reliability using aggregated or de-identified insights where feasible.
- Legal compliance: comply with laws, respond to lawful requests, and enforce our terms.
4. AI, Voice, and Safety Processing
EmoBay uses AI to generate responses and power features such as summaries, Memory, Health Trends, and voice calling. This means your Content may be processed by our AI service providers to return results to you.
- Text chat: your messages and relevant context may be sent to an AI provider to generate responses.
- Voice calls: when you enable voice features, audio may be transmitted for speech-to-text, real-time conversation, and/or text-to-speech. We generally store transcripts (text) rather than raw audio.
- Safety supervisor: we may send a short excerpt of a message for risk classification (e.g., self-harm/violence risk) to support escalation UX and crisis resources. We design these classifiers to return reason codes and not to echo your text.
We configure providers to process data to deliver the Service and, where available, not to use your Content to train public models. Provider processing and retention may still occur for security and abuse prevention under their policies.
5. Cookies, Analytics, and Similar Technologies
We use cookies (and similar technologies like localStorage) for authentication, security, and preferences. With your consent on `emobay.org`, we may also enable analytics to understand website usage and improve our content.
See our Cookie Policy for details and how to manage your choices.
6. How We Share Data
We may share personal data with:
- Service providers that help us run the Service (e.g., hosting, email delivery, analytics, customer support tooling).
- AI and speech providers to generate responses, transcribe speech, and synthesize voice.
- Payment providers (e.g., payment processors and app stores) to process payments and manage subscriptions (for App Store purchases, Apple processes payment and receipt verification).
- Security providers (e.g., bot protection) to prevent abuse and fraud.
- Legal or regulatory authorities when required by law, or to protect rights and safety.
We may use a range of third-party providers depending on the features you use. Examples of provider categories include:
- Cloud hosting and storage (including storage for certain uploads).
- AI and speech processing (to generate responses, transcribe speech, and synthesize voice).
- Email delivery (transactional emails such as sign-in codes and billing notices).
- Push notifications (to deliver app notifications).
- Abuse prevention (e.g., bot detection / challenges).
- Website analytics (where enabled with your consent).
- Newsletter tools (where enabled).
- IP-based geolocation (used to infer approximate country for features like regional resources).
We do not sell your personal data.
7. Data Retention
We retain personal data only as long as necessary for the purposes described in this policy, including to provide the Service, comply with legal obligations, and resolve disputes.
- Account data: retained while your account is active and for a reasonable period thereafter unless you request deletion (subject to legal requirements).
- OTP codes: short-lived and expire (typically within minutes).
- Content: retained to provide history and features; you may be able to delete certain content or request deletion of your account.
8. Security
We use appropriate technical and organizational measures to protect personal data, including access controls and encryption in transit. No method of transmission or storage is completely secure; you use the Service at your own risk.
9. International Transfers
The Service may involve transferring and processing data in jurisdictions outside of your own. Where required, we take steps to ensure appropriate safeguards are in place.
10. Your Rights and Choices
Depending on your location, you may have rights to access, correct, delete, or object to certain processing of your personal data. You can also manage some settings directly in the Service (e.g., consent toggles for optional features).
To make a request, contact us at legal@emobay.org.
11. Children
The Service is intended for adults (18+). We do not knowingly collect Personal Data from individuals under 18. If you believe a minor has provided Personal Data, contact us and we will take appropriate steps, including deletion where applicable.
12. Changes to This Policy
We may update this Privacy Statement from time to time. We will post the updated version on this page with a revised "Last Updated" date.
13. Contact
Questions or requests about privacy can be sent to legal@emobay.org.