Founding rate $15 a monthlocked for as long as you stay subscribed.See both plans

What we can see, and what we can’t.

Everything you write here is encrypted on your device before it is sent, and we do not hold the key. This page is the complete list of what that leaves us able to see; how the sealing works, and where it stops is set out separately.

Written in plain language on purpose, and current as of 30 September 2026. A lawyer will tighten the wording before long; the promises will not get weaker.

The one place your words travel readable.

To generate a reply, your message and the recent conversation are sent to Anthropic, the AI provider, unencrypted - a model cannot read sealed bytes. We do not store, log or keep any of it, and under our zero-data-retention arrangement Anthropic does not retain it after the request completes and does not train on it.

We are telling you this rather than implying it does not happen. Any service running an AI chat has this same step; the difference is whether they say so, and what happens to your words on their side of it. Here: nothing is kept.

If you use voice notes.

In the chat you can hold the microphone and speak instead of typing. Your phone turns what you said into text itself, with a speech model it downloads from us once and keeps on the device. The recording never leaves your phone and is not stored anywhere, by us or on the phone: it exists in memory until the text is ready and is then erased.

Only the text is sent, exactly as if you had typed it: sealed like everything else you write, and read by Anthropic in the one step above. The microphone is asked for only when you first press it, only inside the app, and never on these public pages. You can remove the speech model from a device in Settings, under Storage on this device.

Everything we hold.

This is the whole list, not highlights.

  • Your sign-in email address

    It is how you sign in and how we reach you about your account. This is the one piece of readable personal information we keep on purpose.

  • Scrambled fingerprints of email and IP address

    One-way keyed hashes used to stop abuse of sign-in and safety limits. They cannot be reversed into the original.

  • Your conversations, memory, practice plans, wellness log and questionnaire answers - as sealed bytes

    Encrypted on your device before they are sent. We do not hold the key, so we cannot read them: not for support, not for training, not under pressure.

  • Lesson progress and quiz choices

    Which lessons you finished and which fixed option you picked. Never free text.

  • Which parts of the wellness card you switched on

    Whether the card tracks moving, winding down, regular meals, or none of them, so the dashboard knows what to draw before anything sealed has opened. Which days you marked is in the sealed log above, and we cannot read it.

  • Which language to write to you in

    One of the languages the app is published in, so email arrives in the one you read. The app itself takes it from your device and never asks us. It says nothing about you beyond which language you read.

  • Your time zone

    Taken from your device when you join, or the one you choose in Settings, such as Australia/Sydney. It is how the coach knows what time it is for you, and how the times your limits open again are shown in your time. It says roughly where in the world you are, and nothing else about you.

  • Subscription status

    Whether you are trialling, subscribed or lapsed, kept in sync with Stripe. Card numbers never touch us; they go to Stripe directly.

  • Timestamps, counts and running costs

    When you sign in, how many messages you send and when. We also keep a monthly total of what your replies cost us to generate. That is a length and a price, never what you wrote. Billing and abuse prevention, nothing else - though we say plainly that timing patterns are themselves a signal, and this is the strongest one we can see.

What is not on the list, because it does not exist: third-party advertising trackers, analytics on what you write, profiles of your symptoms, and data sales. There is nothing to sell - we cannot read the only thing that would be worth anything.

Cookies: signing in sets the essential cookies that keep you signed in. Arriving from a link sets one more, a single word for where you came from (a search ad, Instagram, nowhere in particular), chosen from a short fixed list, holding no identifier, and gone after 30 days. We keep it only as a daily count of how many people each source brought, so we know which of them is worth the money; it is never joined to an account. Arriving on somebody’s referral link sets one more, the code from that link, read once when an account is created and then only as a hash - we never store a readable record of who sent whom. Choosing a language sets one more, holding a language and nothing else, so email reaches you in the one you read. The two analytics tools named below set their own first-party cookies on the public pages.

Arriving on a Google ad sets one more, and this is the one worth spelling out. It holds the click identifier Google itself put on the link - nothing we made up about you, and nothing that works on any other site. We use it to tell Google that an ad led somewhere: that an address was confirmed, an account created, a trial started, or a payment made. Four facts, each with a time, each attached to that click and to no name, address or answer. We never send Google your email address or anything you have written or clicked here, and every one of those reports carries an explicit instruction not to use it to personalise advertising to you. It is deleted after 90 days, and if you never came from an ad it is never set at all. This is how we work out which ads are worth paying for; if we could do it without a per-click identifier we would.

If you link to a clinician.

If your clinician uses Maybe Therapist, they can give you a code that links your account to their practice. Linking is your choice, and before anything is shared you choose what they see: your ladders, your urge log, how often you use the app, and whether you opened Get help now. You can change that or unlink at any time.

Your chats are never shared as a whole. A chat reaches your clinician only as a snapshot you choose to send, and one you mark private never does. Practice they set you, and anything you write back, goes to them only when you press send. How often you use the app is counts and days, never what you wrote, and sharing that you opened Get help now tells them only that you did and when.

Everything you share is encrypted on your device under a key your care team holds, and we never hold it. We store it and pass it on, and we cannot read it. The same is true of the practice they set for you and the notes they keep.

What we can see about a link.

To run the link, a few facts about it are readable to us: which practice you are linked to and which of its staff are on your care team; which kinds of record you chose to share, never what is in them; when a shared record changes; that a task exists and who set it, never what it says or whether you did it; when a clinician last opened your page; who pays for your subscription; which parts of the app a practice paying for it has switched off; and a monthly total of what the practice your clinician set cost us to run.

A practice’s name often says what it treats, so being linked to one is itself a fact about your health. We say so plainly because it is the one piece of health information the practice side adds, and we hold it only because access and billing cannot work without it.

If you ask for them, we email you when your care team sends you something. The email says only that, never what, and never names your clinician. If a practice covers your subscription, Stripe bills the practice instead of you.

What the practice does with it.

Once your care team has opened something you shared, it is part of their record of your care, and the practice is responsible for it under its own privacy obligations, which in Australia are the Australian Privacy Principles. It can export what it can see into its own records. Your clinician should give you their practice’s privacy policy; ask for it if they have not.

If you unlink, nothing new reaches them, and what they have already seen stays with the practice, as a note in their own file would. The practice’s manager can see that you are linked and who pays, never what you share.

One step is not sealed, and it is the same step as above. If your clinician sets you a chat practice, the coach reads that conversation to reply and, when you choose to send it, to write the summary your clinician sees. That goes to Anthropic under the same zero data retention, and nothing else you share is read by the AI.

If you work in a practice.

For clinicians and practice staff using Maybe Therapist, we hold your sign-in email; the practice’s name; your role in it; the name you choose to show your patients and colleagues; your photo, if you add one, shown to your patients beside what you set; when you last opened each patient’s page; and the invite that let your practice join, which is deleted once it is used or after 60 days. Each is there because the portal cannot work without it.

Notes you keep and practice you set are sealed on your device like everything a patient writes, and we cannot read them. If you ask the coach to draft a guided exposure from your brief, the brief goes to Anthropic under the same zero data retention. Billing for a practice runs through Stripe: card details go to Stripe and never to us, and we keep how many clinicians and patient seats you pay for. Your practice’s own terms are at/therapists/terms.

Who processes it.

Seven companies touch some part of the list above, each for one job. No advertising partners, no data brokers.

  • Anthropic

    Runs the AI model. The one place your words travel unencrypted - see above. Zero data retention: inputs and outputs are not kept after the request and are not trained on.

  • Stripe

    Payments. Your card details go to Stripe, never to us. A Stripe customer is created with your email address when you register, so billing works the moment you want it - whether or not you ever pay us anything.

  • Resend

    Sends sign-in links, billing emails and, if you ask for them, a note that your care team sent you something. Sees your email address.

  • Vercel

    Hosts the website and holds its server logs, which is where errors are monitored. The AI path is built to log nothing, so what you write does not reach them.

  • MongoDB Atlas

    Stores the data listed above, sealed bytes included.

  • Microsoft Clarity

    Engagement analytics and session replay on the public pages - how visitors move around them. It is switched off on the free check and on any page you open from a link we emailed you, so nobody replays your answers, and it does not run inside the app, nowhere near anything you write.

  • Google Analytics

    Visit counts, traffic sources and which button was pressed, on the public pages - how many people arrive, from where, and whether they went on. Advertising signals and ad personalisation are switched off, the token in a link we emailed you is stripped out before the page is counted, and finishing the free check is never sent to them. It does not run inside the app, and it is nowhere near anything you write.

  • Google Ads

    If you arrived on one of our ads, we tell Google when that click led to a confirmed address, an account, a trial or a payment, so we know which ads are worth paying for. What is sent is Google's own click identifier and a time - never your email address, never anything you wrote or answered - and each report says explicitly that it must not be used to personalise advertising to you. No Google Ads tag runs on any page here.

Most of these companies are based in the United States, so the data each one handles crosses borders: your email address to Stripe and Resend, server logs to Vercel, and the one unencrypted model call to Anthropic. Your sealed conversations cross borders too, and stay exactly as unreadable there as here - the key never travels at all.

Support staff see metadata, never words.

An administrator can look an account up by email and see the same metadata listed above - status, sign-in times, subscription state - to help with billing or access. Every administrative action is logged with who did it and when. An administrator cannot read a conversation, for the same reason nobody else can: the key is not here.

Deleting, and being forgotten.

Resetting your vault destroys every sealed record immediately and keeps your account. Losing every unlock method you enrolled means your conversations are already gone for good - we cannot recover them, and that is the design, not a failure of it.

To delete your account entirely, email hello@usemaybe.app from your sign-in address and it is done, including the email address itself.

Your rights, and the law this runs under.

This service is operated from Australia and handles personal information under the Australian Privacy Principles, including the notifiable data breaches scheme. It is for adults: 18 or over, or younger with a parent or guardian’s knowledge and agreement, as the sign-up asks.

Wherever you are reading this, your account and the ciphertext of your writing are held in Australia and in the United States, so using the app means that data crosses a border. If you are in the European Union or the United Kingdom, the rights the GDPR gives you - to see what we hold, to correct it, to take it with you, to have it erased - are rights we will answer to, and the email below is how to use them. What makes those requests simple to answer honestly is that almost nothing readable exists to hand over: the message content, the conversation titles and the core memory are sealed on your device, and the list further up is the whole of what we can actually see.

If this policy changes in a way that matters, you get an email before the change applies - the same promise the terms make, because a privacy policy edited quietly is not worth the page it sits on.

Questions, complaints, or a request to see what we hold about you: hello@usemaybe.app. If our answer does not settle it, the Office of the Australian Information Commissioner takes complaints at oaic.gov.au. You can also complain to your own supervisory authority: readers in the European Union go to the authority for the country they live in, which in Spain is the Agencia Española de Protección de Datos at aepd.es, and readers in the United Kingdom go to the Information Commissioner at ico.org.uk. The terms of use are at /terms.