Privacy Policy
Last updated: 9 July 2026
This policy explains what personal data iloc collects, how we use it, who processes it on our behalf and the rights you hold under the UK GDPR and the Data Protection Act 2018. Any questions? Please reach us via the contact page.
1. Data controller
iloc is the controller of the personal data described in this policy. We determine the purposes and means of its processing.
2. What we collect
- Account data: email, hashed password (or OAuth identifier), display name, subscription tier.
- Session data: intake answers, Change Wave scripts, SUDs ratings, reflections and integration notes.
- Biometric vocal data: audio recordings and derived acoustic features (see §3).
- Safeguarding data: anonymised excerpts flagged by our safeguarding layer, retained only where necessary.
- Technical data: device type, browser, and minimal analytics used to keep the service running.
3. Biometric data — vocal capture & Vocal Delta
When you speak during a session, iloc captures your voice as biometric data. It is processed for two purposes:
- Transcription — converting your speech to text so the agents can respond in context.
- Vocal Delta & emotional markers — measuring acoustic features (pitch, pace, energy, prosody) to track your state shift across a session and to tailor the therapeutic experience. Derived markers are used exclusively to personalise your journey.
Your audio, transcripts and reflections are never used to train third-party foundation models. Vocal recordings are transmitted over TLS, stored in an access-controlled bucket, and are never made publicly accessible.
4. Legal bases
- Contract: to provide the account and sessions you request.
- Explicit consent: for the processing of biometric vocal data — confirmed at sign-up and revocable at any time by deleting your account.
- Legitimate interests: service security, fraud prevention, and product improvement using aggregated, non-identifying signals.
- Legal obligation: where we must retain limited records to comply with the law.
5. Sub-processors
We share a strictly limited slice of data with a small number of processors, only as necessary to deliver the service:
- Supabase — managed database, authentication and storage. Processes account, session and vocal data on our behalf; hosted within the EEA.
- ElevenLabs — text-to-speech generation for guided voice sessions. We send only the script text to be voiced; no account identifiers, reflections or recordings are shared.
- Stripe — payment processing. Card details are entered directly into Stripe’s hosted checkout and never touch our servers.
- Lovable AI Gateway — routed access to language models used for script generation and syntheses. Prompts are sent per-request and are not used to train models.
Each processor is bound by a data-processing agreement and appropriate transfer safeguards where data leaves the UK or EEA.
6. Data sovereignty & security
Data is encrypted in transit using TLS and at rest on our provider’s infrastructure. Access to your account data is protected by row-level security: the database enforces, on every request, that only you (or an explicitly authorised administrator acting on a safeguarding matter) can read or modify records tied to your identity.
7. Retention
Session and vocal data are retained for the life of your account. When you delete your account, production copies are removed within 30 days and backup copies are purged on our standard rolling schedule (no longer than 35 days).
8. Your rights — Right to Erasure
You have the right to erasure (the “right to be forgotten”). You can delete your entire account and all associated data — Library items, sessions, reflections, safeguarding logs and vocal recordings — from the Profile tab of your dashboard, under “Data Management”. Deletion is permanent and cannot be undone.
9. Your rights — Data Portability
You have the right to data portability. From the Profile tab of your dashboard you can download a JSON export of your account data, including your profile, sessions, progress logs and psychometric results.
10. Other rights
Under UK GDPR you also have the right to access, rectify, restrict, and object to the processing of your personal data, and to lodge a complaint with the Information Commissioner’s Office (ico.org.uk). We will respond to any such request within one calendar month.
11. Cookies & analytics
We use only the cookies strictly necessary to keep you signed in and to remember your session preferences. We do not use advertising cookies or cross-site tracking.
12. Clinical disclaimer
iloc is a self-development tool. It is not a medical device, a diagnostic service, a substitute for professional therapy, or a crisis-intervention service. If you are in immediate distress or at risk of harm, please contact your local emergency services or a recognised crisis line (in the UK: Samaritans on 116 123).
Safety & Usage Restrictions
Change Waves induce a state of deep relaxation that significantly reduces your awareness of your environment. Do not listen while driving, operating machinery, or performing any task that requires your full attention.
- Listen only in a stationary, safe location where you can close your eyes.
- Do not use Change Waves with headphones while walking or cycling in public.
- If you have any medical condition affected by relaxation or trance states, consult a qualified clinician before use.
A safety confirmation is required before every Change Wave session, and the same notice is always accessible via the “Safety Warning” link in the app footer.
13. Changes
We may update this policy from time to time. Material changes will be surfaced in the app before they take effect. The “last updated” date at the top of this page always reflects the current version.