
Trust, security and privacy at Acolher
How we protect people's data, how our AI behaves, and what we are — and are not — able to claim today.
Shared responsibility
Security and privacy outcomes depend on three parties. We describe each one plainly instead of blending them together.
Lovable Cloud (platform)
- Managed hosting, managed Postgres database and managed authentication
- TLS for data in transit and encryption at rest for managed storage
- Platform-level patching and infrastructure operations
Acolher (app owner)
- Row-level access rules so each person can only read their own records
- Aggregation with a minimum cohort of 5 people for every organizational view
- Responsible-AI behavior, safety handling and content governance
- Consent, retention, export and deletion controls inside the product
Customer (your organization)
- Deciding who receives manager and HR-admin roles
- Communicating to employees that participation is voluntary
- Keeping account access, devices and offboarding under control
Security overview
Controls that are enabled in the product today, described without exaggeration.
Encryption in transit
All traffic is served over HTTPS/TLS.
Encryption at rest
Application data is stored in managed cloud storage with encryption at rest.
Authentication
Email and password plus Google sign-in, handled by the managed auth provider.
Row-level access control
Every personal table enforces per-user access rules at the database layer, so one person's records cannot be read by another.
Role-based access
Employee, manager and HR-admin roles are stored separately from profiles and checked server-side on every organizational query.
Least privilege
Organizational analytics run through security-definer functions that return aggregates only — never rows tied to a person.
Audit logging
HR and executive dashboard access is recorded in an append-only log that cannot be edited or deleted through the app.
SSO, SAML, OIDC and SCIM
SAML SSO can be enabled per enterprise customer. SCIM user provisioning is not available yet.
Multi-factor authentication
MFA for administrator accounts is on our roadmap and not available today.
Vulnerability management
Dependencies and application code are reviewed as part of our release process; we do not publish scan results.
Backups and recovery
Managed database backups are provided by the hosting platform. We have not published tested RTO/RPO targets yet.
Privacy overview
Privacy is a product surface, not only a policy. Each control below is reachable in the app.
Consent management
Six independent scopes — long-term memory, personalization, pattern analysis, conversation history, progress tracking and connected services — all off by default and withdrawable individually.
Access requests
People can see everything stored about them in the in-app Privacy Center.
Portability
One-click structured export of profile, consents, memories, conversations and history.
Deletion
Scoped erasure: memories, conversations, pattern data, or everything at once. Withdrawing memory consent deletes stored memory immediately.
Retention
Each person chooses a retention window; data past that window is removed.
Data minimization
The assistant is instructed never to fish for health, sexuality, religion, political or financial details, and sensitive patterns are filtered before memory is stored.
US state privacy laws
The access, correction, deletion, portability and opt-out mechanics expected by CCPA/CPRA, Colorado, Virginia, Connecticut and Utah are built into the product. Contractual and notice obligations are handled per customer agreement.
Cookie preferences
Acolher does not use advertising or cross-site tracking cookies.
Responsible AI principles
These rules sit at the top of the assistant's instructions and take precedence over anything else, including user requests.
Always identifiable as AI
The assistant never pretends to be human and answers honestly when asked.
No invented evidence
No fabricated studies, statistics, sources or credentials; uncertainty is stated in plain language.
No diagnosis
Never diagnoses, never prescribes and never implies licensed clinical authority.
No legal or financial advice
Directs people to qualified professionals instead.
No manipulation
No guilt, fear, artificial urgency or engagement tactics.
No dependency
Strengthens the person's own capacity and real-life relationships and support.
No discrimination
No stereotyping by race, gender, sexuality, religion, disability, age, nationality, body, income or diagnosis.
Continuous quality evaluation
Each reply passes an internal quality gate before it is sent, and routing quality signals are recorded without message content.
NIST AI RMF alignment
Our governance, safety and measurement design follows the govern/map/measure/manage structure. This is a design choice, not an assessment.
AI transparency
People should never have to guess how the system works.
How AI is used
Listening, reflection, structured exercises and learning content — never treatment.
How recommendations appear
Suggested next steps come from what the person shared in the conversation plus their own activity in the app; each one can be dismissed.
How memory works
Only durable facts the person shared, visible and editable, and switchable off at any time.
What stays private
Message content, journal entries, check-ins and memories are never exposed to managers, HR or executives.
What is shared with an employer
Only aggregated indicators, and only when at least 5 people are in the cohort. Below that threshold the view is suppressed entirely.
AI safety
Continuous evaluation of the conversation for signals that need a different response.
Risk signals
Emotional crisis, possible self-harm, severe distress, escalating suffering, violence risk and abuse indicators are evaluated on every turn.
Safety-first responses
When risk is elevated, exercises and reframing are suppressed in favor of presence, validation and a real human path forward.
Human escalation
Crisis resources are surfaced for the person's region; in the US the 988 Suicide & Crisis Lifeline, and 911 for emergencies.
Clear limits
Acolher never diagnoses, never replaces emergency services and never replaces licensed healthcare professionals.
Human oversight
Automated systems do not get the last word on content or safety behavior.
Safety review
Safety instructions and crisis pathways are reviewed by the Acolher team before release.
Prompt and model evaluation
Prompt and model changes are versioned and reviewed before they reach production.
Clinical review
Review of wellbeing content by qualified mental-health professionals is being formalized; we do not yet publish reviewer credentials or review dates.
Approval for critical updates
Changes to safety, governance and knowledge content require explicit human approval.
Clinical governance
Scientific integrity is tracked as a first-class property of the content.
Evidence levels
Wellbeing knowledge entries carry an explicit evidence level, and the assistant separates what is well established from what is a hypothesis.
Version history
Governance, prompt and knowledge versions are recorded with every generated reply.
Reviewer records
Named reviewer credentials, review dates and public reference lists are planned.
Auditability
What we can reconstruct after the fact.
Administrative access trail
HR and executive analytics access is logged with actor, area and action.
Tamper resistance
Access logs are append-only: the application grants no update or delete path.
AI decision trail
Model, routing model, risk level, safety intervention and consent state are recorded per reply, without message content.
Configuration and permission change history
A customer-visible admin change log is planned.
Availability, continuity and recovery
What we can say honestly today about uptime and resilience.
Infrastructure
Acolher runs on Lovable Cloud's managed edge hosting and managed Postgres.
Incident history
No customer-impacting security incidents have been reported to date. Confirmed incidents will be published here.
Status page
A public availability/status page is planned.
Disaster recovery and business continuity
Recovery relies on managed platform backups. Documented and tested RTO/RPO targets are in progress.
Compliance readiness
Design targets, stated as design targets. None of the frameworks below represents a completed audit or certification.
SOC 2 Type II
Architecture designed to support a future assessment. Not certified.
ISO 27001
Architecture designed to support a future assessment. Not certified.
ISO 27701
Privacy controls designed with this structure in mind. Not certified.
NIST Cybersecurity Framework
Used as an internal reference model for security practices.
NIST AI Risk Management Framework
Used as an internal reference model for AI governance and measurement.
HIPAA
Acolher is not a covered entity, does not offer treatment and does not currently sign BAAs.
Vendor and data-processing risk
How we keep the supply chain understandable.
Vendor inventory
We maintain an internal inventory covering purpose, country, data categories and contract status for every vendor with access to production data.
Data residency
Production data is stored in United States regions of our managed cloud provider.
Change notification
Enterprise customers are notified before a new subprocessor with access to customer data is introduced.
Subprocessors
Third parties that may process customer data on our behalf. Ask us for the current signed list if you need it for a vendor review.
| Subprocessor | Purpose | Region | Data categories |
|---|---|---|---|
| Lovable Cloud | Application hosting, database, authentication, storage | United States | Account data, app content |
| Google (Gemini via Lovable AI Gateway) | AI model inference for conversations and transcription | United States | Conversation content submitted at request time |
Frequently asked questions
Can a manager or HR see what an employee wrote?
No. Message content, journal entries, check-in notes and memories are never exposed to managers, HR or executives — only aggregated indicators, and only for cohorts of at least 5 people.
What happens below the 5-person threshold?
The entire view is suppressed. There is no partial number, no rounding and no 'small sample' fallback.
Is Acolher a healthcare service?
No. Acolher offers emotional support, reflection and evidence-informed wellbeing content. It does not diagnose, does not treat and does not replace licensed professionals or emergency services.
Is my data used to train AI models?
No. Conversations are sent to the model provider only to generate the reply in that moment; we do not use customer content to train models.
Can employees opt out entirely?
Yes. Participation is voluntary, every consent scope is off by default, and any of them can be withdrawn at any time.
Are you SOC 2 or ISO certified?
Not today. The architecture is designed to support future assessments, and we will publish reports here when they exist.
Contact and documentation
Security researchers and enterprise reviewers can reach the right team directly.
Security
security@acolher.liveVulnerability reports and security questionnaires. Please do not include exploit payloads against production.
Privacy and compliance
privacy@acolher.livePrivacy requests, DPAs, subprocessor lists and compliance reviews.
Data requests
In-app Privacy CenterAccess, export, correction and deletion, available to every person from their account.
Documentation library
Available on request under NDA where noted; planned items are not yet written.
Privacy and consent overview
How consent scopes, retention and deletion work
Responsible AI overview
Governance rules, safety protocol and quality gate
Security architecture summary
Access model, data flows and platform boundaries
Incident response plan
Detection, escalation and customer notification
Business continuity and disaster recovery plan
Recovery objectives and tested procedures
Administrator and employee guides
Rollout, roles and day-to-day usage
Running a vendor review? Send us your questionnaire and we will answer it with the same honesty you see on this page.
Contact security