Privacy Policy
Effective date: 17 June 2026 · Version: 1.1
1. Who we are
HEYLINA AI LTD (“HeyLina”, “we”, “us”) is the “controller” of personal data processed via the Service. Registered office: 96 Gilbert Road, Chafford Hundred, Grays, England RM16 6NJ. Contact: team@heylina.ai.
2. What this policy covers
This policy explains how we collect, use, store, and share personal data when you use our App or Website. Use of the Service is also subject to our Terms of Service.
3. How we collect your data
We collect personal data through the following channels:
- Directly from you: when you sign up, complete onboarding, send messages to Lina, record audio, log a mood check-in, contact support, or complete any in-app or Website form.
- Automatically via SDKs in the App: Firebase (authentication, database, file storage, push notifications, crash reporting), Google Sign-In, and PostHog product analytics.
- Server logs: when our backend (Firebase Cloud Functions) processes a request, we generate logs containing request metadata, identifiers, and timestamps.
- Push notification services: when you enable notifications, we receive a device push token from Apple Push Notification service or Firebase Cloud Messaging.
- Cookies and similar technologies on the Website: see our Cookie Policy for the full list.
- App stores and payment platforms: Apple App Store, Google Play, and RevenueCat send us limited subscription and purchase events.
4. Data we collect
We collect the following categories of personal data:
A. Account and identity
- Email address (used for sign-in and account recovery).
- Password (stored only by Firebase Auth, in hashed form; we never see your password).
- Google sign-in credential, if you choose to sign in with Google.
- A unique account identifier we generate for your account.
- Profile fields you provide during onboarding: full name, gender, birth date.
B. Conversation content
- The text of messages you send to Lina.
- Audio recordings you submit when you choose to speak to Lina.
- Transcripts of those audio recordings.
- Conversation metadata (message IDs, timestamps, session identifiers).
- Your onboarding responses and the personal growth plans you choose to set.
C. App usage and behavioural data
- Daily mood check-ins and mood nuance selections.
- Streak and badge events.
- Subscription state and purchase events.
- Screen views and feature interactions.
- Account lifecycle events (sign-in, sign-out, data deletion, account deletion).
- Authentication events, including error codes when sign-in fails.
- Profile change events (which field was updated).
D. Device and technical data
- Device model, operating system and version, app version, language, and timezone.
- Push notification tokens, where you have enabled notifications.
- Crash reports and stack traces (via Firebase Crashlytics).
E. Website data (cookies and similar technologies)
- Pages viewed, clicks, referral sources, cookie identifiers, and advertising/analytics signals (where enabled). See our Cookie Policy.
F. Subscription and transaction data
- Subscription status received from Apple App Store, Google Play, and RevenueCat.
- We do not receive your full card details from Apple, Google, or any payment provider.
G. Support and feedback
- Messages you send to support, bug reports, and survey responses.
5. Sensitive information
Your messages may contain highly sensitive content (for example, information about your sex life, sexual orientation, emotional state, or relationship circumstances). Please consider carefully what you share.
We use this information only to provide the Service and, where applicable, to improve safety and quality, in line with this policy and your settings/choices.
6. How we use your data
We use your data to:
- Provide the Service — create and manage your account; generate Lina responses and deliver features; customer support and troubleshooting.
- Safety and trust — detect and respond to high-risk signals (for example, self-harm language) and apply safety behaviours.
- Improve and develop — monitor performance, fix bugs, and improve features; analyse aggregated usage patterns.
- Marketing (optional) — send product updates or newsletters if you opt in; measure marketing performance on the Website using cookies/pixels, where you consent.
7. Our lawful bases (UK GDPR)
We rely on the following lawful bases, depending on the activity:
- Contract: to provide the Service you request.
- Legitimate interests: to secure and improve the Service, prevent fraud/abuse, and understand product performance (balanced against your rights).
- Consent: for non-essential cookies/pixels and, where required, for certain marketing communications.
- Legal obligation: where we must comply with law.
8. Automated processing and AI
HeyLina is an AI-powered service. When you message Lina, your input is processed by automated systems to generate a response.
Specifically:
- Your text (or the transcript of your voice message) is sent to OpenAI to generate Lina’s reply.
- Voice recordings are sent to OpenAI Whisper for speech-to-text and, where used, to ElevenLabs for text-to-speech.
- A vector representation of your conversation is stored with Pinecone so Lina can refer back to relevant context in future sessions.
We do not train AI models on your data. Our third-party AI processors (OpenAI, ElevenLabs, Pinecone) are contractually prohibited from training their models on your data and operate on enterprise/API tiers that exclude customer data from training.
The Service does not make decisions about you that produce legal or similarly significant effects within the meaning of UK GDPR Article 22. Lina’s responses are conversational guidance only; you remain responsible for your decisions and actions. See our Terms of Service for the full AI output disclaimer.
9. Who we share data with
We use the following processors to deliver the Service. Each receives only the categories of data needed for its specific purpose.
- Firebase / Google Cloud (Google LLC): authentication, database (Firestore), file storage, push notifications, crash reporting, and server-side processing (Cloud Functions). Receives account credentials, chat metadata, audio files, push tokens, and crash data.
- OpenAI: generates Lina’s text replies (Chat Completions), transcribes your voice (Whisper), and provides fallback text-to-speech. Receives your messages, voice recordings, and conversational context.
- ElevenLabs: synthesises Lina’s voice replies. Receives Lina’s reply text (not your input).
- Pinecone: stores vector representations of your conversations to give Lina long-term memory. Receives conversation embeddings and accompanying text fragments.
- RevenueCat: manages subscription state across Apple App Store and Google Play. Receives your account identifier, email, display name, and purchase events.
- PostHog: product analytics (hosted in the EU). Receives event telemetry, screen views, and feature usage. We do not send conversation content, full names, or sensitive profile fields to PostHog.
- Google Sign-In: optional social sign-in. Receives the OAuth credential only.
- Apple App Store / Google Play: subscription billing and platform-managed purchase events.
- Website advertising and analytics partners: Google (including Google Tag Manager and Google Ads), Meta, Reddit, Spotify, TikTok, and Fathom. See our Cookie Policy for details and opt-out controls.
- Professional advisers: lawyers, accountants, and insurers, where necessary.
- Authorities: where required by law.
For the current full subprocessor list with regions and data categories, see our Subprocessor List.
We do not sell personal data to data brokers, and we do not exchange your conversations or profile information for money. Some advertising and analytics cookies on our Website (see Cookie Policy) involve limited data sharing with marketing partners. Under certain US state privacy laws (for example, the California Consumer Privacy Act/CPRA), this kind of cookie-based sharing may be classified as “selling” or “sharing” personal information. You can opt out at any time via our cookie banner or your browser controls.
10. International transfers
The Service is operated from the United Kingdom. Some of our processors store or process data outside the UK and EU:
- United States: OpenAI, ElevenLabs, Pinecone, RevenueCat, and Google LLC (including Firebase services and Google Sign-In).
- European Union: PostHog (EU-hosted instance).
Where data is transferred outside the UK, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses (SCCs) with our processors, supplemented by appropriate technical and organisational measures.
11. Data retention
We retain personal data for the periods set out below.
- Account and profile data: while your account is active.
- Voice recordings (raw audio you submit): deleted from our storage immediately after transcription is complete.
- Lina’s voice replies (TTS audio): deleted after 7 days.
- Chat text and conversation metadata: kept while your account is active, to provide context for ongoing conversations.
- Long-term conversation memory (Pinecone vectors): kept while your account is active, then deleted on account closure.
- Analytics data (PostHog, Crashlytics): retained per processor defaults and your consent settings.
- Subscription and billing records: retained as required by tax and accounting law (typically 6–7 years in the UK).
Account deletion safety window: when you request account deletion, your account enters a recoverable “pending deletion” state for 3 months. During that period you can restore your account by contacting us at team@heylina.ai. After 3 months, we permanently purge your data across our systems (Firestore, Firebase Storage, Pinecone, PostHog, and RevenueCat where permitted), other than records we are legally required to retain.
12. Security
We apply reasonable technical and organisational measures designed to protect data (access controls, encryption in transit, least-privilege access).
No system is perfectly secure, but we design for minimising access to sensitive data.
13. Your rights
Depending on your situation, you may have rights to:
- access your data
- correct inaccurate data
- delete your data
- restrict or object to certain processing
- data portability
- withdraw consent (where processing is based on consent)
You can exercise these rights by contacting team@heylina.ai.
14. Cookies and tracking choices
On the Website, we use a consent mechanism for non-essential cookies/pixels. You can change your preferences at any time via our Cookie Policy. Cookie consent rules under PECR require consent for non-essential cookies and similar technologies.
15. Marketing preferences
If you opt in to marketing, you can opt out at any time using the unsubscribe link in emails or by contacting us. Rules for electronic mail marketing require appropriate consent in many cases.
16. Children and age requirements
The Service is intended only for users aged 18 and over. We do not knowingly collect personal data from anyone under 18.
When you create an account, you confirm that you are at least 18 years old. If we become aware that an account belongs to someone under 18, we will terminate that account and delete the associated personal data.
The Service is not intended for and should not be used by minors. We do not target our services at children or teenagers under 18.
17. Complaints
If you have concerns, contact us first at team@heylina.ai. You can also complain to the UK regulator, the Information Commissioner’s Office (ICO).
18. Changes
We may update this policy. We will update the effective date above and may notify you if changes are material.
