Inner Belief Privacy Policy
Privacy Policy
Version 2026-08 · Effective / last updated 19 August 2026
1. About this Policy
This Privacy Policy explains how personal information is handled through the Inner Belief website, web application and mobile applications.
Inner Belief is operated through RTT Lifestyle Coaching LLC and Brave Life LLC.
The particular legal role of Inner Belief depends on why information is being processed.
For some activities, Inner Belief determines its own purposes and acts as a controller.
For some Practitioner professional-record activities, a Practitioner may determine the professional purpose of the processing and Inner Belief may process the information on that Practitioner's behalf.
Practitioners may also act as independent controllers in relation to professional information they are legally or professionally responsible for maintaining.
This Policy should be read with any applicable Practitioner–Client Agreement and Practitioner privacy information.
2. Who this Policy covers
This Policy applies to:
- Clients;
- Practitioners;
- account holders;
- website visitors;
- purchasers; and
- other people whose information is processed through the Platform.
You must be at least 18 years old to create an Inner Belief account.
3. Information we collect
3.1 Account and identity information
This may include:
- name;
- email address;
- account role;
- login and authentication information;
- profile information;
- device time zone; and
- information received through approved sign-in providers.
Where you use Apple's Private Relay, we may receive a relay email rather than your personal email address.
3.2 Practitioner information
For Practitioners this may include:
- identity information;
- qualifications and Credentials;
- insurance information;
- licences or professional registrations;
- biography and profile information;
- availability;
- payment and tax information;
- complaints or professional-conduct information; and
- information reasonably required to verify eligibility to use the Platform.
3.3 Health, wellbeing and professional information
Depending on how you use Inner Belief, information may include:
- journal entries;
- mood and wellness information;
- sleep, energy or anxiety information;
- free-text wellbeing notes;
- clinical or wellbeing questionnaires, including PHQ-9 or GAD-7 responses and scores;
- intake and matching information;
- pre- and post-Session check-ins;
- information concerning audio use;
- Practitioner notes;
- Session summaries;
- information you send to your Practitioner; and
- other information relating to your wellbeing or Practitioner Services.
Some of this may constitute sensitive or special-category personal data.
3.4 Sessions, recordings and transcripts
Live Sessions may be provided using an authorised video provider.
Where you expressly agree to recording through the Platform:
- audio and/or video may be recorded;
- a transcript may be produced;
- approved technology may generate an AI-assisted draft summary; and
- your Practitioner may review those materials to create or confirm the final professional record.
Recording is optional for Clients unless clearly stated otherwise and lawfully required for a specific service.
Declining recording does not ordinarily prevent you from joining the Session.
3.5 Audio and content activity
We may process:
- personalised audio uploaded or created for you;
- library audio;
- playback information;
- completions;
- listening activity; and
- related feature-use information.
3.6 Messaging and community information
This may include:
- messages between Clients and Practitioners;
- community posts;
- replies;
- mentions; and
- moderation or complaint information.
Content posted in a community area may be visible to other participants in that area.
3.7 Payments
Payments may be processed through Stripe, Apple or another authorised payment provider.
Inner Belief ordinarily receives transaction information such as:
- amount;
- date;
- currency;
- transaction status;
- limited payment-method information; and
- transaction or subscription identifiers.
We do not ordinarily receive your complete card number from the payment processor.
3.8 Device and technical information
This may include:
- device identifiers;
- push-notification tokens;
- IP address;
- log and diagnostic information;
- browser or application information;
- security events;
- authentication information; and
- usage information reasonably required to operate, secure and improve the Platform.
4. Why we use information
Depending on the circumstances, we use information to:
- create and administer accounts;
- operate the Platform;
- match Clients and Practitioners;
- facilitate booking and Sessions;
- process and administer payments;
- provide messaging and content features;
- enable Practitioners to maintain professional records;
- support safeguarding and safety;
- manage complaints;
- prevent fraud and misuse;
- maintain security;
- meet legal and regulatory requirements;
- respond to individual-rights requests;
- provide notifications;
- maintain and improve Platform functionality; and
- establish, exercise or defend legal claims.
We do not sell health information.
We do not use Client health information for behavioural advertising.
5. Legal bases
The legal basis used depends on the processing activity and applicable law.
Where UK GDPR applies and Inner Belief acts as controller, Article 6 bases may include:
- contract, where processing is necessary to provide requested Platform functionality;
- legitimate interests, where we have a legitimate operational, security, safeguarding, fraud-prevention or service-improvement interest that is not overridden by your rights;
- legal obligation, where processing is required by law; and
- consent, where we ask you to make a genuine choice.
Where information constitutes special-category data under UK GDPR, we also identify an applicable Article 9 condition.
Depending on the particular processing, this may include:
- explicit consent, particularly for optional processing for which we ask you to make a clear choice;
- processing necessary to establish, exercise or defend legal claims;
- processing necessary to protect vital interests in the limited circumstances permitted by law; or
- another applicable condition available under data-protection law.
Where Inner Belief acts only as processor for a Practitioner, the Practitioner is responsible for identifying the controller's lawful basis and applicable special-category condition.
We document the applicable basis for relevant processing activities and do not rely on a single blanket consent for all Platform processing.
This approach reflects the UK requirement to identify both an Article 6 basis and an Article 9 condition for special-category data where UK GDPR applies.
6. Practitioner and Inner Belief data roles
Professional-service data does not always have one controller.
A Practitioner may act as independent controller where they determine what information is professionally necessary to collect, use or retain as part of their practice.
Inner Belief acts as controller where it determines the purpose of processing for activities such as:
- account administration;
- Platform security;
- payment administration;
- fraud prevention;
- Platform-level safeguarding;
- complaints administration;
- legal compliance;
- Platform analytics; and
- Platform operations.
For particular professional-record activities where Inner Belief processes information solely on documented instructions from the Practitioner and has no separate purpose for that processing, Inner Belief may act as processor.
The legal role is determined by the actual processing activity, not merely by the label used in a contract.
7. Automated safety monitoring
Because some users may share information indicating a risk of serious harm, certain information entered into the Platform may be automatically analysed for indicators of a potential safety concern.
This may include:
- journal entries;
- messages to a Practitioner;
- wellbeing check-ins; and
- relevant questionnaire responses.
A flag does not itself constitute a diagnosis or emergency determination.
A flagged item may, where appropriate, be reviewed by authorised personnel and/or the relevant Practitioner and may result in crisis-support information or proportionate safeguarding action.
Inner Belief is not a continuously monitored emergency service, and automated safety tools cannot guarantee that every risk will be detected.
If you are in immediate danger or believe another person may be in immediate danger, contact the emergency or crisis service appropriate to your location.
8. Recording, transcription and AI-assisted summaries
Where you affirmatively agree to a Session being recorded:
- the authorised Platform recording may be stored temporarily;
- an authorised transcription service may process it;
- approved AI technology may generate a draft Session summary;
- your Practitioner may review, correct and approve the record; and
- authorised Inner Belief personnel may access relevant material where reasonably necessary for safeguarding, complaint investigation, an identified service-quality concern, security, fraud prevention, legal claims or legal/regulatory compliance.
AI-generated information may be inaccurate or incomplete.
An AI-assisted draft does not become the final professional record until the Practitioner has reviewed and approved it.
We do not permit Practitioner Session data to be uploaded to unauthorised public or consumer AI systems.
9. HIPAA and health-information safeguards
Where HIPAA applies to a particular processing relationship, we apply the relevant HIPAA requirements.
For service providers that process protected health information on our behalf where a Business Associate Agreement is required, we maintain an executed BAA before relying on that provider for the relevant processing.
Our transcription arrangements with Deepgram include an executed BAA.
More generally, we operate the Platform using security and confidentiality measures designed for sensitive health and wellbeing information.
References to HIPAA do not imply that every Inner Belief user, Practitioner, transaction or processing activity is subject to HIPAA.
10. Communications and notifications
We may communicate through:
- the Platform;
- email; and
- push notifications where enabled.
As an operational rule, sensitive therapy, health, journal or Session content is not placed in ordinary transactional emails or push-notification previews.
A notification may tell you that information is waiting in the Platform and direct you to sign in securely.
You can manage available notification settings through your account or device.
11. Service providers
We use service providers to support the Platform.
These currently include providers for functions such as:
- Stripe — payment processing;
- Apple — Apple sign-in, push notifications and applicable in-app purchases;
- Google — Google authentication and hosting/database services as applicable;
- LiveKit — live video functionality;
- Deepgram — transcription;
- Vercel — web-application hosting; and
- Resend — transactional email.
Providers receive only the information reasonably required for their function and are subject to appropriate contractual and security requirements.
Our transactional email design does not intentionally provide Resend with substantive health or Practitioner-session content.
12. International transfers
Some service providers or infrastructure may process information outside the country in which you are located, including in the United States.
Where applicable law restricts international transfers, we use an appropriate lawful transfer mechanism.
Depending on the jurisdiction and transfer, this may include contractual safeguards, adequacy mechanisms, consent where legally appropriate or another recognised legal mechanism.
For UAE personal data, cross-border processing must comply with the applicable requirements of the UAE Personal Data Protection Law.
13. Security
We use technical and organisational security measures appropriate to the nature and sensitivity of the information we process.
These include measures such as:
- encryption in transit;
- access controls;
- authentication controls;
- secure credential storage;
- least-privilege access where appropriate;
- logging and security monitoring; and
- incident-response processes.
No system can guarantee absolute security.
14. Retention
Our standard retention framework is:
- Raw Session recording: normally approximately 90 days after the Session.
- Full transcript: normally approximately 90 days after the Session, or 30 days after the Practitioner confirms the final professional record, whichever is later.
- Unapproved AI-assisted draft summary: retained for no longer than approximately 12 months and ordinarily deleted sooner once the final professional record has been confirmed.
- Practitioner-approved final summary and human Practitioner notes: may be retained for up to seven years after the last relevant Practitioner Service.
Different periods may apply where:
- applicable law requires a longer or shorter period;
- a Practitioner has a separate lawful professional-record obligation;
- an insurer or regulatory requirement lawfully requires a different period;
- a safeguarding matter exists;
- a complaint is under investigation;
- litigation or a legal claim is anticipated or underway;
- a regulatory investigation is underway; or
- another documented legal hold applies.
When information is no longer required, it is deleted or appropriately de-identified.
15. Legal holds
Normal deletion may be suspended for specific information where reasonably necessary for:
- safeguarding;
- complaint investigation;
- litigation or anticipated litigation;
- regulatory investigation; or
- another documented legal requirement.
A legal hold does not justify indefinite retention of unrelated data.
16. Your rights
Depending on the law applicable to you and the relevant processing, you may have rights to:
- access personal information;
- correct inaccurate information;
- request deletion;
- restrict processing;
- object to particular processing;
- receive portable information;
- withdraw consent where processing depends on consent; and
- complain to an appropriate supervisory authority.
These rights are subject to legal exceptions.
Where the relevant information is controlled independently by a Practitioner, Inner Belief may refer or forward your request to that Practitioner where appropriate.
Requests can be made through available Privacy & Data settings or by contacting us.
17. Children
Inner Belief is intended for adults aged 18 and over.
We do not knowingly permit children under 18 to create accounts for Practitioner Services.
If we become aware that a child has provided information contrary to this restriction, we will take appropriate steps.
18. Business transfers and legal disclosures
We may disclose information where reasonably necessary:
- to comply with law or a lawful authority;
- to protect a person's safety;
- to investigate fraud or serious misuse;
- to establish or defend legal rights; or
- in connection with a genuine corporate reorganisation, financing, acquisition or sale, subject to appropriate confidentiality and data-protection safeguards.
19. Changes to this Policy
We may update this Policy when our processing, technology or legal requirements change.
Where appropriate, we will notify users of material changes through the Platform or another suitable channel.
The current version and effective date will be displayed at the top of the Policy.
20. Contact
Questions and privacy requests may be sent to:
Where required, we will route the request to the relevant privacy or Practitioner contact.