You typed the whole thing out. The resentment you have never said in those words, the part you are ashamed of, the name. Then you sat looking at it with your thumb over the send button, running a different calculation entirely: where does this go, and who could ever read it?
That is the right question and most apps answer it with a reassuring sentence rather than an accurate one. This page is the accurate version, which means it includes the parts that are not flattering to us.
Clinical confidentiality and a privacy policy are not the same thing
When you talk to a licensed therapist, you are inside a professional and legal structure. They are bound by clinical confidentiality, their records are subject to health privacy law, and in many contexts your communications carry legal privilege. Breaching it risks their licence. There are defined exceptions — imminent danger, certain mandatory reporting duties — but the default is a protected relationship.
When you talk to a consumer app, you are inside a contract. A privacy policy is a company's commitment about how it collects, uses, and shares your data, enforceable mainly through consumer protection and state privacy law. That is real and it is not the same protection.
So, said plainly: Innermost is not a HIPAA-covered clinical service and your conversations with a guide are not legally privileged. HIPAA applies to healthcare providers and their business associates; we are a consumer wellness app. If you need clinical-grade confidentiality — because of a custody matter, employment situation, security clearance, or anything else with legal weight — that is a strong reason to talk to a licensed professional instead.
What actually happens when you send a message
Worth knowing mechanically, because it is true of every product in this category and most of them do not spell it out.
Your message is encrypted in transit and stored encrypted at rest. To produce a reply, the content needed to generate it is sent to a third-party AI provider — we use Anthropic, OpenAI, and Google for conversation, and ElevenLabs for voice. Those are API services, and under our agreements with them your data is not used to train their general-purpose models. Only what is necessary to generate a response is transmitted: your account information, email, and identity are not shared with them.
On our side, we do not sell your conversations and we do not use them to train general-purpose AI models. Your conversation content, check-in data, and wellness information are not used for advertising, and we do not share wellness data with employers, insurers, or data brokers.
The honest exception: if content is flagged for safety review, it may be reviewed to enforce our policies and improve our safety systems, and flagged content may be retained. Nobody browses user conversations for interest — but "no human could ever see anything under any circumstances" is not a true statement about any service that has a safety process, and we are not going to make it. The complete detail is in our privacy policy, which is worth reading rather than taking our summary for.
How this differs from typing your feelings into a general AI account
The models are broadly similar. The context around them is not, and the differences are practical rather than technical.
A general-purpose assistant account is one account for your whole life. Your marriage sits in the sidebar next to a cover letter and a formula you were debugging. If that account is signed in on a work machine, or provisioned through an employer plan, the boundary between your private thinking and your professional life is a UI detail rather than a real separation. Consumer assistants also change their history and training settings periodically, which means the answer to "is this used for training?" is whatever you last configured — worth checking directly in your own settings.
A purpose-built app is a separate place with one job. That does not make it magically safer, and the point is not that we are more trustworthy by nature — it is that a single-purpose product has a narrower surface, a policy written for this kind of data, and no incentive to put your emotional history next to your work. One reviewer summed up what they valued in four words in a review title: "insights, privacy, and a wonderful tool for mental health."
If privacy is what has been holding you back, read the policy first — then decide. The free tier needs no card.
Five questions to ask about any AI mental health app
Use these on us too. Each one is answerable from a privacy policy in a couple of minutes, and the answers differ enormously between apps that look identical in the App Store.
- 1.Which AI providers get my messages, and on what terms? Every app in this category sends your text somewhere. A policy that names its providers and states the training terms is being straight with you. A policy that never mentions providers is describing a pipeline that does not exist.
- 2.Is my content used to train models? Look for the distinction between the app's own models and the providers' general-purpose models, and for whether you can opt out.
- 3.Can a human read it, and when? Any honest answer includes a safety exception. The absence of one means the policy has not been written carefully, not that no human can read it.
- 4.What happens when I delete? Deleted from your view, or from the company's systems? Within what period? What survives — backups, de-identified analytics, safety-flagged content?
- 5.Does it claim HIPAA coverage or "complete confidentiality"? A consumer wellness app is generally not HIPAA-covered. An app implying otherwise is either confused about the law or hoping you are, and that should inform how much weight you give the rest of its promises.
If an app fails question five, do not bother with the other four.
What no privacy policy can protect you from
Two things worth naming because they are about your situation rather than any company's practices.
Your device. The most likely way anyone reads your conversations is that they pick up your unlocked phone. If you share a device, or someone has your passcode, no server-side commitment helps. Use a passcode nobody else knows.
Legal process. Any company can be compelled to produce data by lawful subpoena or regulatory obligation, ours included, and our policy says so. This matters most in situations where a written record could be used against you — custody disputes, employment matters, and above all unsafe relationships. If you are in an abusive situation, a detailed private record on a shared or monitored device is a genuine risk, and a human advocate is the safer route. The AI therapist guide covers the other situations where an app is the wrong tool.
In a crisis, please use these instead. Innermost is not for emergencies. If you are in the US, call or text the 988 Suicide & Crisis Lifeline, or text HOME to 741741 to reach the Crisis Text Line. Both are free and staffed by trained humans, 24 hours a day. If you are in immediate danger, call 911 or go to your nearest emergency room.
Not therapy: Innermost is an AI guide for self-reflection and emotional support. It is not therapy, not a licensed therapist, and not a substitute for professional mental health care. It does not diagnose or treat any condition.
