Acolher
Enterprise
Trust Center

Trust, security and privacy at Acolher

How we protect people's data, how our AI behaves, and what we are — and are not — able to claim today.

This page is maintained by the Acolher team to answer common security, privacy and responsible-AI questions about Acolher. It is app-owned content, not an independent assessment.
Acolher is not currently certified under SOC 2, ISO 27001, ISO 27701 or HIPAA. Where a framework is mentioned, it describes how our architecture is designed to support a future assessment — not a completed audit or a compliance guarantee.

Shared responsibility

Security and privacy outcomes depend on three parties. We describe each one plainly instead of blending them together.

Lovable Cloud (platform)

  • Managed hosting, managed Postgres database and managed authentication
  • TLS for data in transit and encryption at rest for managed storage
  • Platform-level patching and infrastructure operations

Acolher (app owner)

  • Row-level access rules so each person can only read their own records
  • Aggregation with a minimum cohort of 5 people for every organizational view
  • Responsible-AI behavior, safety handling and content governance
  • Consent, retention, export and deletion controls inside the product

Customer (your organization)

  • Deciding who receives manager and HR-admin roles
  • Communicating to employees that participation is voluntary
  • Keeping account access, devices and offboarding under control

Security overview

Controls that are enabled in the product today, described without exaggeration.

Encryption in transit

All traffic is served over HTTPS/TLS.

Live in product

Encryption at rest

Application data is stored in managed cloud storage with encryption at rest.

Live in product

Authentication

Email and password plus Google sign-in, handled by the managed auth provider.

Live in product

Row-level access control

Every personal table enforces per-user access rules at the database layer, so one person's records cannot be read by another.

Live in product

Role-based access

Employee, manager and HR-admin roles are stored separately from profiles and checked server-side on every organizational query.

Live in product

Least privilege

Organizational analytics run through security-definer functions that return aggregates only — never rows tied to a person.

Live in product

Audit logging

HR and executive dashboard access is recorded in an append-only log that cannot be edited or deleted through the app.

Live in product

SSO, SAML, OIDC and SCIM

SAML SSO can be enabled per enterprise customer. SCIM user provisioning is not available yet.

In progress

Multi-factor authentication

MFA for administrator accounts is on our roadmap and not available today.

Planned

Vulnerability management

Dependencies and application code are reviewed as part of our release process; we do not publish scan results.

In progress

Backups and recovery

Managed database backups are provided by the hosting platform. We have not published tested RTO/RPO targets yet.

In progress

Privacy overview

Privacy is a product surface, not only a policy. Each control below is reachable in the app.

Consent management

Six independent scopes — long-term memory, personalization, pattern analysis, conversation history, progress tracking and connected services — all off by default and withdrawable individually.

Live in product

Access requests

People can see everything stored about them in the in-app Privacy Center.

Live in product

Portability

One-click structured export of profile, consents, memories, conversations and history.

Live in product

Deletion

Scoped erasure: memories, conversations, pattern data, or everything at once. Withdrawing memory consent deletes stored memory immediately.

Live in product

Retention

Each person chooses a retention window; data past that window is removed.

Live in product

Data minimization

The assistant is instructed never to fish for health, sexuality, religion, political or financial details, and sensitive patterns are filtered before memory is stored.

Live in product

US state privacy laws

The access, correction, deletion, portability and opt-out mechanics expected by CCPA/CPRA, Colorado, Virginia, Connecticut and Utah are built into the product. Contractual and notice obligations are handled per customer agreement.

Live in product

Cookie preferences

Acolher does not use advertising or cross-site tracking cookies.

Live in product

Responsible AI principles

These rules sit at the top of the assistant's instructions and take precedence over anything else, including user requests.

Always identifiable as AI

The assistant never pretends to be human and answers honestly when asked.

Live in product

No invented evidence

No fabricated studies, statistics, sources or credentials; uncertainty is stated in plain language.

Live in product

No diagnosis

Never diagnoses, never prescribes and never implies licensed clinical authority.

Live in product

No legal or financial advice

Directs people to qualified professionals instead.

Live in product

No manipulation

No guilt, fear, artificial urgency or engagement tactics.

Live in product

No dependency

Strengthens the person's own capacity and real-life relationships and support.

Live in product

No discrimination

No stereotyping by race, gender, sexuality, religion, disability, age, nationality, body, income or diagnosis.

Live in product

Continuous quality evaluation

Each reply passes an internal quality gate before it is sent, and routing quality signals are recorded without message content.

Live in product

NIST AI RMF alignment

Our governance, safety and measurement design follows the govern/map/measure/manage structure. This is a design choice, not an assessment.

In progress

AI transparency

People should never have to guess how the system works.

How AI is used

Listening, reflection, structured exercises and learning content — never treatment.

Live in product

How recommendations appear

Suggested next steps come from what the person shared in the conversation plus their own activity in the app; each one can be dismissed.

Live in product

How memory works

Only durable facts the person shared, visible and editable, and switchable off at any time.

Live in product

What stays private

Message content, journal entries, check-ins and memories are never exposed to managers, HR or executives.

Live in product

What is shared with an employer

Only aggregated indicators, and only when at least 5 people are in the cohort. Below that threshold the view is suppressed entirely.

Live in product

AI safety

Continuous evaluation of the conversation for signals that need a different response.

Risk signals

Emotional crisis, possible self-harm, severe distress, escalating suffering, violence risk and abuse indicators are evaluated on every turn.

Live in product

Safety-first responses

When risk is elevated, exercises and reframing are suppressed in favor of presence, validation and a real human path forward.

Live in product

Human escalation

Crisis resources are surfaced for the person's region; in the US the 988 Suicide & Crisis Lifeline, and 911 for emergencies.

Live in product

Clear limits

Acolher never diagnoses, never replaces emergency services and never replaces licensed healthcare professionals.

Live in product

Human oversight

Automated systems do not get the last word on content or safety behavior.

Safety review

Safety instructions and crisis pathways are reviewed by the Acolher team before release.

Live in product

Prompt and model evaluation

Prompt and model changes are versioned and reviewed before they reach production.

Live in product

Clinical review

Review of wellbeing content by qualified mental-health professionals is being formalized; we do not yet publish reviewer credentials or review dates.

In progress

Approval for critical updates

Changes to safety, governance and knowledge content require explicit human approval.

Live in product

Clinical governance

Scientific integrity is tracked as a first-class property of the content.

Evidence levels

Wellbeing knowledge entries carry an explicit evidence level, and the assistant separates what is well established from what is a hypothesis.

Live in product

Version history

Governance, prompt and knowledge versions are recorded with every generated reply.

Live in product

Reviewer records

Named reviewer credentials, review dates and public reference lists are planned.

Planned

Auditability

What we can reconstruct after the fact.

Administrative access trail

HR and executive analytics access is logged with actor, area and action.

Live in product

Tamper resistance

Access logs are append-only: the application grants no update or delete path.

Live in product

AI decision trail

Model, routing model, risk level, safety intervention and consent state are recorded per reply, without message content.

Live in product

Configuration and permission change history

A customer-visible admin change log is planned.

Planned

Availability, continuity and recovery

What we can say honestly today about uptime and resilience.

Infrastructure

Acolher runs on Lovable Cloud's managed edge hosting and managed Postgres.

Live in product

Incident history

No customer-impacting security incidents have been reported to date. Confirmed incidents will be published here.

Live in product

Status page

A public availability/status page is planned.

Planned

Disaster recovery and business continuity

Recovery relies on managed platform backups. Documented and tested RTO/RPO targets are in progress.

In progress

Compliance readiness

Design targets, stated as design targets. None of the frameworks below represents a completed audit or certification.

SOC 2 Type II

Architecture designed to support a future assessment. Not certified.

Planned

ISO 27001

Architecture designed to support a future assessment. Not certified.

Planned

ISO 27701

Privacy controls designed with this structure in mind. Not certified.

Planned

NIST Cybersecurity Framework

Used as an internal reference model for security practices.

In progress

NIST AI Risk Management Framework

Used as an internal reference model for AI governance and measurement.

In progress

HIPAA

Acolher is not a covered entity, does not offer treatment and does not currently sign BAAs.

Planned

Vendor and data-processing risk

How we keep the supply chain understandable.

Vendor inventory

We maintain an internal inventory covering purpose, country, data categories and contract status for every vendor with access to production data.

Live in product

Data residency

Production data is stored in United States regions of our managed cloud provider.

Live in product

Change notification

Enterprise customers are notified before a new subprocessor with access to customer data is introduced.

In progress

Subprocessors

Third parties that may process customer data on our behalf. Ask us for the current signed list if you need it for a vendor review.

SubprocessorPurposeRegionData categories
Lovable CloudApplication hosting, database, authentication, storageUnited StatesAccount data, app content
Google (Gemini via Lovable AI Gateway)AI model inference for conversations and transcriptionUnited StatesConversation content submitted at request time

Frequently asked questions

Can a manager or HR see what an employee wrote?

No. Message content, journal entries, check-in notes and memories are never exposed to managers, HR or executives — only aggregated indicators, and only for cohorts of at least 5 people.

What happens below the 5-person threshold?

The entire view is suppressed. There is no partial number, no rounding and no 'small sample' fallback.

Is Acolher a healthcare service?

No. Acolher offers emotional support, reflection and evidence-informed wellbeing content. It does not diagnose, does not treat and does not replace licensed professionals or emergency services.

Is my data used to train AI models?

No. Conversations are sent to the model provider only to generate the reply in that moment; we do not use customer content to train models.

Can employees opt out entirely?

Yes. Participation is voluntary, every consent scope is off by default, and any of them can be withdrawn at any time.

Are you SOC 2 or ISO certified?

Not today. The architecture is designed to support future assessments, and we will publish reports here when they exist.

Contact and documentation

Security researchers and enterprise reviewers can reach the right team directly.

Security

security@acolher.live

Vulnerability reports and security questionnaires. Please do not include exploit payloads against production.

Privacy and compliance

privacy@acolher.live

Privacy requests, DPAs, subprocessor lists and compliance reviews.

Data requests

In-app Privacy Center

Access, export, correction and deletion, available to every person from their account.

Documentation library

Available on request under NDA where noted; planned items are not yet written.

Privacy and consent overview

How consent scopes, retention and deletion work

Live in product

Responsible AI overview

Governance rules, safety protocol and quality gate

Live in product

Security architecture summary

Access model, data flows and platform boundaries

In progress

Incident response plan

Detection, escalation and customer notification

In progress

Business continuity and disaster recovery plan

Recovery objectives and tested procedures

Planned

Administrator and employee guides

Rollout, roles and day-to-day usage

In progress

Running a vendor review? Send us your questionnaire and we will answer it with the same honesty you see on this page.

Contact security

Acolher — premium, calm and human by design.

Last updated 2026-07-29