
Compliance built into the platform
How Acolher supports privacy rights, responsible AI, fair employment practices, accessibility and enterprise audit needs in the United States — and how that architecture extends to new countries.
Core principles
Ten commitments that shape how the product is architected, not only how it is described.
Privacy by design
Personal content is scoped to the person by default at the database layer, not by application convention.
Compliance by design
Access, correction, deletion, portability and consent are product surfaces, not manual back-office tickets.
Responsible AI
Inviolable rules sit above every prompt: no diagnosis, no fabrication, no manipulation.
Human oversight
Safety, governance and knowledge changes require explicit human approval before release.
Transparency
We publish what is live, what is in progress and what is only planned.
Security
Encryption in transit and at rest, row-level access rules, role separation and append-only audit logs.
Accountability
Administrative and analytics access is logged and attributable.
Accessibility
WCAG-oriented design is part of the definition of done for every screen.
Ethics
No dark patterns, no engagement manipulation, no use of wellbeing data against a person.
Continuous improvement
Policies, reviews and controls are re-examined on a schedule and after any finding.
Legal architecture
Not every customer is subject to the same rules. Compliance capabilities are configurable by customer, industry and jurisdiction rather than hard-coded to one regime.
Person layer
Consent scopes, retention window, personalization level and memory switches live on the individual's own record and always win over organizational settings.
Organization layer
Roles (employee, manager, HR admin), campaign participation, notification policy and access permissions are configured per organization.
Jurisdiction layer
Locale, crisis resources, terminology and privacy-request handling adapt by region; new countries are added as configuration, not as a rewrite.
Enforcement layer
Database row-level rules, security-definer aggregate functions and a 5-person minimum cohort enforce the boundaries regardless of which UI is used.
Because enforcement lives in the database rather than in a screen, an organization cannot configure its way into seeing an individual's content.
Privacy compliance
The mechanics expected by CCPA/CPRA and the Colorado, Virginia, Connecticut and Utah statutes are built into the product. Contractual and notice obligations are handled per customer agreement.
Consent management
Six independent scopes — long-term memory, personalization, pattern analysis, conversation history, progress tracking and connected services — all off by default.
Privacy preferences
Personalization level, response style and memory behavior configurable per person.
Cookie preferences
No advertising or cross-site tracking cookies are used, so there is nothing to opt out of.
Access requests
Self-service view of everything stored about the person.
Correction requests
Profile fields and stored memories are directly editable.
Deletion requests
Scoped erasure — memories, conversations, pattern data or everything at once.
Portability requests
One-click structured export in a machine-readable format.
Retention controls
Per-person retention window; data past the window is removed.
Processing restrictions
Withdrawing a scope stops that processing and removes the data it depended on.
Children's privacy
Acolher is not directed to children; age confirmation is required and accounts under the supported age are not intended users.
Privacy request audit trail
Consent changes and privacy events are recorded with policy version and timestamp.
Sale and sharing
Personal information is not sold or shared for cross-context behavioral advertising.
Employment compliance
Wellbeing data must never become an employment instrument. This is enforced technically, not only contractually.
Wellbeing information is never used for
- Hiring decisions
- Termination decisions
- Promotion decisions
- Compensation decisions
- Performance evaluation
- Disciplinary action
- Individual ranking, scoring or comparison of employees
Anonymous analytics are used only to
- Understand aggregated wellbeing trends across a team or organization
- Identify workload, recovery and psychological-safety pressures at group level
- Design campaigns, learning and support that address those pressures
- Measure whether an organizational initiative helped, in aggregate
Accessibility
Employee experiences are designed against WCAG 2.2 AA expectations and evaluated during development.
Keyboard navigation
Every interactive control is reachable and operable by keyboard with a visible focus state.
Screen readers
Semantic landmarks, labeled controls and accessible names on icon-only actions.
Color contrast
Text and interface colors are drawn from a token palette designed to meet AA contrast.
Resizable text
Relative units throughout, so browser and OS text scaling does not break layouts.
Reduced motion
Animations respect the operating system's reduced-motion preference.
Accessible forms
Associated labels, described errors and status messages that are not color-only.
Responsive layouts
Mobile-first layouts with tap targets sized for touch.
Captions and media alternatives
Audio and video practices will ship with captions and transcripts as that content is added.
Continuous evaluation
Accessibility checks are part of the review before a screen ships; we have not commissioned an external VPAT/ACR yet.
Workplace wellbeing
The platform supports healthier work environments through education and support. It does not replace employer responsibilities for workplace safety and employee wellbeing.
Burnout prevention
Early-signal education, recovery routines and workload-boundary practices.
Psychological safety
Team-level indicators and manager guidance on speaking up and error tolerance.
Healthy leadership
An AI leadership coach with themes grounded in organizational psychology.
Stress reduction
Guided practices from 1 to 10 minutes in the wellbeing center.
Healthy communication
Difficult conversations, feedback and boundary-setting modules.
Resilience
Support networks, meaning-making and recovery habit design.
Work-life balance
Break reminders, quiet hours and disconnection practices.
Healthy workplace culture
Voluntary campaigns and team goals, with participation never individually reported.
Responsible AI governance
What we document and evaluate for every AI system in the platform.
Model documentation
Which models are used, for what purpose and with which limits.
Prompt documentation
Governance, safety, specialist and quality instructions kept as reviewable source.
Model version history
Model changes are versioned and reviewed before production.
Knowledge version history
Knowledge entries carry evidence levels and versioned changes.
Testing history
Behavioral checks before prompt and model changes reach production.
Quality metrics
An internal quality gate runs before each reply; routing and quality scores are recorded without message content.
Safety evaluations
Risk detection, escalation and crisis-resource behavior evaluated per release.
Bias evaluations
Structured testing for demographic and cultural bias in responses is being built; we do not publish results yet.
Human review history
Approvals for safety, governance and knowledge changes are recorded.
NIST AI RMF alignment
Governance, safety and measurement design follows govern/map/measure/manage. A design choice, not an assessment.
Enterprise administration
What an administrator can configure for their organization today, and what is still on the roadmap.
Access permissions
Employee, manager and HR-admin roles stored separately from profiles and enforced server-side.
Organization policies
Campaigns, team goals, action plans and communications scoped to the organization.
Notification policies
Nudge types, frequency and quiet hours, with the individual keeping final control.
Audit settings
HR and executive access recorded in an append-only log that cannot be edited or deleted through the app.
AI features
Per-organization enablement of assistant capabilities.
Retention periods
Organization-level retention defaults, with the individual's own window taking precedence.
Consent flows
Customizable onboarding consent text per organization and policy version.
Privacy policies
Customer-specific privacy notice surfaced inside the app.
Regional compliance settings
Region-specific defaults for resources, terminology and request handling.
Audit
Administrative and privacy events are recorded so an organization can reconstruct what happened. Audit records are protected from modification through the app.
Administrative access
HR and executive dashboard access is logged with the area, action and timestamp.
Consent changes
Every grant and withdrawal is stored with its policy version.
Data export requests
Export events are recorded as privacy events.
Data deletion requests
Scope and time of each erasure are recorded.
Tamper resistance
Audit tables deny update and delete through the application's access rules.
Permission changes
Role grants and revocations recorded in the audit trail.
Configuration changes
Organization policy and setting changes recorded with the actor.
Security events
Authentication anomalies and suspicious access surfaced to administrators.
Log export
Customer-initiated export of their own audit trail.
Global expansion
Country-specific requirements are configuration, not architecture. Adding a jurisdiction should not require rebuilding the platform.
Locale and language
PT-BR and EN-US written natively, with the assistant thinking and answering in the selected language.
Regional crisis resources
Emergency resources adapt to the person's region — 988 and 911 in the US, CVV 188 and 192 in Brazil.
Terminology
HR, manager and benefits vocabulary adapts to the market.
Data residency options
Today, processing occurs in the United States. Regional residency is a roadmap item, not a current capability.
GDPR and LGPD readiness
The access, correction, deletion, portability, restriction and consent mechanics generalize to these regimes; contractual instruments are handled per customer.
EU AI Act watch
We track transparency and risk-classification obligations relevant to wellbeing assistants.
Continuous compliance
Review cadence across every governance area, plus the triggers that pull a review forward.
Policy reviews
Policies re-examined at least annually and after any material product change.
Security reviews
Dependencies and application code reviewed as part of the release process.
Privacy reviews
New data collection requires a purpose, a retention answer and a deletion path before it ships.
AI governance reviews
Prompt, model and knowledge changes reviewed and approved by a person.
Clinical governance reviews
Evidence checks and clinical review of wellbeing content, described on the Clinical Governance page.
Internal audits
Periodic self-assessment against the controls published here.
External audits
Third-party assessment is a roadmap item; no audit has been completed.
Compliance reporting
Customer-facing reporting on controls, incidents and changes.
User rights
Every right below is exercisable by the person, in the app, without contacting support.
Understand AI usage
How the assistant works, what it can and cannot do, and how suggestions are produced.
Trust Center and in-conversation transparency
Manage privacy preferences
Six independent consent scopes, all off by default and withdrawable individually.
Privacy Center
Review stored memories
See every durable fact the assistant has kept, with its category and source.
Memory page
Delete stored memories
Delete one memory or all of them; withdrawing memory consent erases them immediately.
Memory page and Privacy Center
Download personal information
Structured export of profile, consents, memories, conversations and history.
Privacy Center
Control personalization
Choose the personalization level, response length, tone and language.
Profile and Privacy Center
Withdraw consent
Any scope, at any time, with the dependent data removed rather than merely hidden.
Privacy Center
Set retention
Choose how long data is kept; anything past the window is removed.
Privacy Center
Third-party governance
Every external service that can process customer data is tracked with the same fields.
| Vendor | Purpose | Data categories | Location | Risk | Review |
|---|---|---|---|---|---|
| Lovable Cloud | Hosting, managed database, authentication and storage | Account data and application content | United States | High — core processor | Annual; security review completed, contract active |
| Google (Gemini via Lovable AI Gateway) | AI inference for conversations and transcription | Content submitted at request time; not used for model training | United States | High — content processor | Annual; security review completed, contract active |
No advertising, cross-site tracking or data-broker vendors are used. Adding a vendor requires a purpose, a data-category assessment, a security review and a risk classification before it can process customer data. Subprocessor changes are announced to enterprise customers before they take effect.
Documentation library
Available to enterprise reviewers, under NDA where indicated. Planned items have not been written yet.
Privacy Policy
What is collected, why, for how long and with whom it is shared.
Terms of Service
Service scope, acceptable use and the explicit non-medical limitation.
Responsible AI Policy
Inviolable rules, safety behavior, oversight and evaluation.
Security Policy
Access control, encryption, logging and release practices.
Data processing practices
Processing purposes, categories, locations and subprocessors.
Incident response plan
Detection, triage, containment, notification and post-incident review.
Business continuity plan
Critical dependencies and continuity of service commitments.
Disaster recovery plan
Backup, restore procedures and tested RTO/RPO targets.
Administrator guide
Roles, configuration, audit and privacy request handling.
Employee guide
What is private, what is aggregated and how to opt out.
Release notes
Product, prompt and policy changes with dates.
Legal and compliance contact
Legal, procurement and security review teams talk directly to the right people.
Privacy and compliance
privacy@acolher.livePrivacy requests, DPAs, subprocessors and compliance questionnaires.
Running a legal or procurement review? Send your questionnaire and we will answer it with the same honesty you see on this page.