Acolher
Trust Center
Legal & Regulatory

Compliance built into the platform

How Acolher supports privacy rights, responsible AI, fair employment practices, accessibility and enterprise audit needs in the United States — and how that architecture extends to new countries.

This page is maintained by the Acolher team to answer common legal, privacy and compliance questions about Acolher. It is app-owned content, not an independent legal assessment or certification.
This page is not legal advice and does not create contractual obligations. Compliance obligations depend on your industry, jurisdiction and the agreement between your organization and Acolher. Acolher is not currently certified under SOC 2, ISO 27001, ISO 27701 or HIPAA.

Core principles

Ten commitments that shape how the product is architected, not only how it is described.

Privacy by design

Personal content is scoped to the person by default at the database layer, not by application convention.

Compliance by design

Access, correction, deletion, portability and consent are product surfaces, not manual back-office tickets.

Responsible AI

Inviolable rules sit above every prompt: no diagnosis, no fabrication, no manipulation.

Human oversight

Safety, governance and knowledge changes require explicit human approval before release.

Transparency

We publish what is live, what is in progress and what is only planned.

Security

Encryption in transit and at rest, row-level access rules, role separation and append-only audit logs.

Accountability

Administrative and analytics access is logged and attributable.

Accessibility

WCAG-oriented design is part of the definition of done for every screen.

Ethics

No dark patterns, no engagement manipulation, no use of wellbeing data against a person.

Continuous improvement

Policies, reviews and controls are re-examined on a schedule and after any finding.

Legal architecture

Not every customer is subject to the same rules. Compliance capabilities are configurable by customer, industry and jurisdiction rather than hard-coded to one regime.

Person layer

Consent scopes, retention window, personalization level and memory switches live on the individual's own record and always win over organizational settings.

Organization layer

Roles (employee, manager, HR admin), campaign participation, notification policy and access permissions are configured per organization.

Jurisdiction layer

Locale, crisis resources, terminology and privacy-request handling adapt by region; new countries are added as configuration, not as a rewrite.

Enforcement layer

Database row-level rules, security-definer aggregate functions and a 5-person minimum cohort enforce the boundaries regardless of which UI is used.

Because enforcement lives in the database rather than in a screen, an organization cannot configure its way into seeing an individual's content.

Privacy compliance

The mechanics expected by CCPA/CPRA and the Colorado, Virginia, Connecticut and Utah statutes are built into the product. Contractual and notice obligations are handled per customer agreement.

Consent management

Six independent scopes — long-term memory, personalization, pattern analysis, conversation history, progress tracking and connected services — all off by default.

Live in product

Privacy preferences

Personalization level, response style and memory behavior configurable per person.

Live in product

Cookie preferences

No advertising or cross-site tracking cookies are used, so there is nothing to opt out of.

Live in product

Access requests

Self-service view of everything stored about the person.

Live in product

Correction requests

Profile fields and stored memories are directly editable.

Live in product

Deletion requests

Scoped erasure — memories, conversations, pattern data or everything at once.

Live in product

Portability requests

One-click structured export in a machine-readable format.

Live in product

Retention controls

Per-person retention window; data past the window is removed.

Live in product

Processing restrictions

Withdrawing a scope stops that processing and removes the data it depended on.

Live in product

Children's privacy

Acolher is not directed to children; age confirmation is required and accounts under the supported age are not intended users.

Live in product

Privacy request audit trail

Consent changes and privacy events are recorded with policy version and timestamp.

Live in product

Sale and sharing

Personal information is not sold or shared for cross-context behavioral advertising.

Live in product

Employment compliance

Wellbeing data must never become an employment instrument. This is enforced technically, not only contractually.

Wellbeing information is never used for

  • Hiring decisions
  • Termination decisions
  • Promotion decisions
  • Compensation decisions
  • Performance evaluation
  • Disciplinary action
  • Individual ranking, scoring or comparison of employees

Anonymous analytics are used only to

  • Understand aggregated wellbeing trends across a team or organization
  • Identify workload, recovery and psychological-safety pressures at group level
  • Design campaigns, learning and support that address those pressures
  • Measure whether an organizational initiative helped, in aggregate
Technically: message content, journal entries, check-in notes and memories are never exposed to managers, HR or executives. Every organizational view is an aggregate computed server-side and suppressed entirely when fewer than 5 people are in the cohort — there is no partial number, no rounding and no 'small sample' fallback. Access to HR and executive dashboards is written to an append-only audit log.

Accessibility

Employee experiences are designed against WCAG 2.2 AA expectations and evaluated during development.

Keyboard navigation

Every interactive control is reachable and operable by keyboard with a visible focus state.

Live in product

Screen readers

Semantic landmarks, labeled controls and accessible names on icon-only actions.

Live in product

Color contrast

Text and interface colors are drawn from a token palette designed to meet AA contrast.

Live in product

Resizable text

Relative units throughout, so browser and OS text scaling does not break layouts.

Live in product

Reduced motion

Animations respect the operating system's reduced-motion preference.

Live in product

Accessible forms

Associated labels, described errors and status messages that are not color-only.

Live in product

Responsive layouts

Mobile-first layouts with tap targets sized for touch.

Live in product

Captions and media alternatives

Audio and video practices will ship with captions and transcripts as that content is added.

Planned

Continuous evaluation

Accessibility checks are part of the review before a screen ships; we have not commissioned an external VPAT/ACR yet.

In progress

Workplace wellbeing

The platform supports healthier work environments through education and support. It does not replace employer responsibilities for workplace safety and employee wellbeing.

Burnout prevention

Early-signal education, recovery routines and workload-boundary practices.

Live in product

Psychological safety

Team-level indicators and manager guidance on speaking up and error tolerance.

Live in product

Healthy leadership

An AI leadership coach with themes grounded in organizational psychology.

Live in product

Stress reduction

Guided practices from 1 to 10 minutes in the wellbeing center.

Live in product

Healthy communication

Difficult conversations, feedback and boundary-setting modules.

Live in product

Resilience

Support networks, meaning-making and recovery habit design.

Live in product

Work-life balance

Break reminders, quiet hours and disconnection practices.

Live in product

Healthy workplace culture

Voluntary campaigns and team goals, with participation never individually reported.

Live in product

Responsible AI governance

What we document and evaluate for every AI system in the platform.

Model documentation

Which models are used, for what purpose and with which limits.

In progress

Prompt documentation

Governance, safety, specialist and quality instructions kept as reviewable source.

Live in product

Model version history

Model changes are versioned and reviewed before production.

Live in product

Knowledge version history

Knowledge entries carry evidence levels and versioned changes.

Live in product

Testing history

Behavioral checks before prompt and model changes reach production.

In progress

Quality metrics

An internal quality gate runs before each reply; routing and quality scores are recorded without message content.

Live in product

Safety evaluations

Risk detection, escalation and crisis-resource behavior evaluated per release.

Live in product

Bias evaluations

Structured testing for demographic and cultural bias in responses is being built; we do not publish results yet.

In progress

Human review history

Approvals for safety, governance and knowledge changes are recorded.

Live in product

NIST AI RMF alignment

Governance, safety and measurement design follows govern/map/measure/manage. A design choice, not an assessment.

In progress

Enterprise administration

What an administrator can configure for their organization today, and what is still on the roadmap.

Access permissions

Employee, manager and HR-admin roles stored separately from profiles and enforced server-side.

Live in product

Organization policies

Campaigns, team goals, action plans and communications scoped to the organization.

Live in product

Notification policies

Nudge types, frequency and quiet hours, with the individual keeping final control.

Live in product

Audit settings

HR and executive access recorded in an append-only log that cannot be edited or deleted through the app.

Live in product

AI features

Per-organization enablement of assistant capabilities.

In progress

Retention periods

Organization-level retention defaults, with the individual's own window taking precedence.

In progress

Consent flows

Customizable onboarding consent text per organization and policy version.

Planned

Privacy policies

Customer-specific privacy notice surfaced inside the app.

Planned

Regional compliance settings

Region-specific defaults for resources, terminology and request handling.

In progress

Audit

Administrative and privacy events are recorded so an organization can reconstruct what happened. Audit records are protected from modification through the app.

Administrative access

HR and executive dashboard access is logged with the area, action and timestamp.

Live in product

Consent changes

Every grant and withdrawal is stored with its policy version.

Live in product

Data export requests

Export events are recorded as privacy events.

Live in product

Data deletion requests

Scope and time of each erasure are recorded.

Live in product

Tamper resistance

Audit tables deny update and delete through the application's access rules.

Live in product

Permission changes

Role grants and revocations recorded in the audit trail.

In progress

Configuration changes

Organization policy and setting changes recorded with the actor.

In progress

Security events

Authentication anomalies and suspicious access surfaced to administrators.

Planned

Log export

Customer-initiated export of their own audit trail.

Planned

Global expansion

Country-specific requirements are configuration, not architecture. Adding a jurisdiction should not require rebuilding the platform.

Locale and language

PT-BR and EN-US written natively, with the assistant thinking and answering in the selected language.

Live in product

Regional crisis resources

Emergency resources adapt to the person's region — 988 and 911 in the US, CVV 188 and 192 in Brazil.

Live in product

Terminology

HR, manager and benefits vocabulary adapts to the market.

Live in product

Data residency options

Today, processing occurs in the United States. Regional residency is a roadmap item, not a current capability.

Planned

GDPR and LGPD readiness

The access, correction, deletion, portability, restriction and consent mechanics generalize to these regimes; contractual instruments are handled per customer.

In progress

EU AI Act watch

We track transparency and risk-classification obligations relevant to wellbeing assistants.

In progress

Continuous compliance

Review cadence across every governance area, plus the triggers that pull a review forward.

Policy reviews

Policies re-examined at least annually and after any material product change.

In progress

Security reviews

Dependencies and application code reviewed as part of the release process.

In progress

Privacy reviews

New data collection requires a purpose, a retention answer and a deletion path before it ships.

Live in product

AI governance reviews

Prompt, model and knowledge changes reviewed and approved by a person.

Live in product

Clinical governance reviews

Evidence checks and clinical review of wellbeing content, described on the Clinical Governance page.

In progress

Internal audits

Periodic self-assessment against the controls published here.

In progress

External audits

Third-party assessment is a roadmap item; no audit has been completed.

Planned

Compliance reporting

Customer-facing reporting on controls, incidents and changes.

Planned

User rights

Every right below is exercisable by the person, in the app, without contacting support.

Understand AI usage

How the assistant works, what it can and cannot do, and how suggestions are produced.

Trust Center and in-conversation transparency

Manage privacy preferences

Six independent consent scopes, all off by default and withdrawable individually.

Privacy Center

Review stored memories

See every durable fact the assistant has kept, with its category and source.

Memory page

Delete stored memories

Delete one memory or all of them; withdrawing memory consent erases them immediately.

Memory page and Privacy Center

Download personal information

Structured export of profile, consents, memories, conversations and history.

Privacy Center

Control personalization

Choose the personalization level, response length, tone and language.

Profile and Privacy Center

Withdraw consent

Any scope, at any time, with the dependent data removed rather than merely hidden.

Privacy Center

Set retention

Choose how long data is kept; anything past the window is removed.

Privacy Center

Third-party governance

Every external service that can process customer data is tracked with the same fields.

VendorPurposeData categoriesLocationRiskReview
Lovable CloudHosting, managed database, authentication and storageAccount data and application contentUnited StatesHigh — core processorAnnual; security review completed, contract active
Google (Gemini via Lovable AI Gateway)AI inference for conversations and transcriptionContent submitted at request time; not used for model trainingUnited StatesHigh — content processorAnnual; security review completed, contract active

No advertising, cross-site tracking or data-broker vendors are used. Adding a vendor requires a purpose, a data-category assessment, a security review and a risk classification before it can process customer data. Subprocessor changes are announced to enterprise customers before they take effect.

Documentation library

Available to enterprise reviewers, under NDA where indicated. Planned items have not been written yet.

Privacy Policy

What is collected, why, for how long and with whom it is shared.

In progress

Terms of Service

Service scope, acceptable use and the explicit non-medical limitation.

In progress

Responsible AI Policy

Inviolable rules, safety behavior, oversight and evaluation.

Live in product

Security Policy

Access control, encryption, logging and release practices.

In progress

Data processing practices

Processing purposes, categories, locations and subprocessors.

In progress

Incident response plan

Detection, triage, containment, notification and post-incident review.

In progress

Business continuity plan

Critical dependencies and continuity of service commitments.

Planned

Disaster recovery plan

Backup, restore procedures and tested RTO/RPO targets.

Planned

Administrator guide

Roles, configuration, audit and privacy request handling.

Planned

Employee guide

What is private, what is aggregated and how to opt out.

In progress

Release notes

Product, prompt and policy changes with dates.

Planned

Legal and compliance contact

Legal, procurement and security review teams talk directly to the right people.

Privacy and compliance

privacy@acolher.live

Privacy requests, DPAs, subprocessors and compliance questionnaires.

Legal

legal@acolher.live

Contracts, terms, notices and regulatory questions.

Security

security@acolher.live

Vulnerability reports and security reviews.

Running a legal or procurement review? Send your questionnaire and we will answer it with the same honesty you see on this page.

Acolher — premium, calm and human by design.

Last updated 2026-07-29