Privacy Policy

    Last updated: March 23, 2026

    1. Who We Are

    This Privacy Policy explains how Inner Shore Pte. Ltd. ("Inner Shore", "we", "us", or "our") collects, uses, discloses, stores, transfers, and otherwise processes personal data in connection with the Inner Shore app, website, and related services (collectively, the "Services").

    For the purposes of Singapore's Personal Data Protection Act 2012 ("PDPA"), Inner Shore is the organisation responsible for personal data under its control.

    If you have questions about this Privacy Policy or our data practices, you may contact our Data Protection Officer at hello@innershore.com. Under the PDPA, organisations are required to appoint a DPO and make the DPO's business contact information publicly available.

    2. Scope

    This Privacy Policy applies to personal data we collect:

    • directly from you; • automatically through your use of the Services; • from authentication and payment partners; • from your interactions with AI-enabled features; and • from other sources you choose to connect or use with the Services.

    3. Personal Data We Collect

    Depending on how you use the Services, we may collect the following categories of personal data.

    **A. Account and Profile Data** email address, display name, profile image or avatar (if provided), date of birth, login method, language and app preferences, notification settings, account-related identifiers and settings.

    **B. Journal and Reflection Data** Journal entries and written reflections, feedback and support messages you submit. We use journal content to provide and store the journaling feature and related user-facing functionality. We do not use private journal content for internal analytics.

    **C. Chat and AI Interaction Data** Messages you send to the AI, conversation history and selected context used to generate responses, AI-generated responses, conversation summaries or titles (where used to support continuity), user choices or interactions related to AI features. Chat content may be included in prompt context so that the Services can generate coherent and personalised responses.

    **D. Voice and Audio Data** If you use voice features, we may process: audio you submit to enable voice interaction, transcripts derived from voice input where needed to provide the feature, AI-generated meditation scripts, and audio generated from those scripts using text-to-speech services. Voice and audio processing is used to operate the voice interaction and guided meditation features. It is not used by us to build internal analytics profiles from private journal content.

    **E. Device, Usage, and Technical Data** Browser type and language settings, device and operating environment information, IP address or approximate location inferred from technical data, timestamps, session activity, and feature usage, app diagnostics, crash data, logs, and performance data, subscription and entitlement status.

    **F. Billing and Transaction Data** We do not store full payment card numbers in our own systems. Payment processing is handled by third-party payment processors such as Stripe. We may receive limited billing-related information such as: customer or subscription identifiers, subscription status, billing period, renewal status, invoice or transaction references, and payment outcome metadata. Stripe states that it is a PCI Level 1 service provider, while also noting that PCI compliance remains a shared responsibility between Stripe and merchants.

    **G. Social Login Data** If you sign in using Google, Apple, or another supported provider, we may receive basic profile information such as your email address, name, and account identifier, depending on the permissions you grant.

    4. How We Collect Personal Data

    We collect personal data when:

    • you create an account or update your profile; • you provide your date of birth during onboarding or registration; • you use chat, journal, meditation, or voice features; • you contact support or send feedback; • you authenticate through a third-party identity provider; • our systems record technical, diagnostic, usage, and security information; and • AI-enabled features generate outputs, summaries, or continuity metadata based on your interactions.

    5. Why We Use Personal Data

    Under the PDPA, organisations generally collect, use, and disclose personal data with consent, or where an exception under the PDPA applies. The PDPA also requires organisations to notify individuals of the purposes for which personal data will be collected, used, or disclosed, unless an exception applies.

    We use personal data for the following purposes:

    **A. To provide the Services** — creating and managing your account, authenticating you, applying age and eligibility checks, storing journals and settings, providing AI conversations, supporting conversation continuity, generating meditation scripts, generating text-to-speech audio for meditation guidance, operating subscription features, and providing customer support.

    **B. To personalise your experience** — tailoring prompts, reflections, and recommendations, remembering your settings and preferences, and providing continuity across sessions.

    **C. To maintain safety, integrity, and security** — detecting misuse, fraud, abuse, or suspicious activity, investigating incidents, enforcing our Terms, surfacing safety notices or crisis resources where appropriate, and protecting users, personnel, and the Services.

    **D. To improve and develop the Services** — debugging, service quality review, performance optimisation, feature testing, product development, and aggregate or de-identified reporting. Where reasonably possible, we use aggregated, de-identified, or minimised data for improvement work.

    **E. To communicate with you** — transactional emails, account notices, subscription and billing notices, service announcements, safety-related notices, and reminders or notifications you choose to enable.

    **F. To comply with law** — complying with legal obligations, responding to lawful requests, meeting tax, accounting, regulatory, and audit requirements, handling disputes, and establishing or defending legal claims.

    6. AI Processing and Model Providers

    The Services use AI systems provided by us and by third-party providers.

    **How AI processing works** When you send a message or request an AI-enabled feature, we may send the minimum reasonably necessary input and context to a model provider so that the feature can function. We may then store the prompt, response, and related continuity information in our own systems.

    **Current AI-related providers** Depending on the feature, we may use providers such as: OpenAI, Google, text-to-speech providers such as ElevenLabs or MiniMax.

    **Data use by AI providers** As of the date of this Privacy Policy: • OpenAI states that data sent through its API is not used to train or improve OpenAI models by default unless the customer explicitly opts in. • Google's Gemini API documentation states that where data is logged for abuse monitoring, it is used solely for policy enforcement and not to train or fine-tune AI or ML models.

    Our own use of these providers may vary by feature, service configuration, vendor terms, and future operational changes. Where required by law, we will provide notice or obtain consent before materially expanding such uses.

    We do not use your private journals or private conversations to train our own general-purpose AI models unless we clearly notify you and obtain any consent required by applicable law.

    7. When We Share Personal Data

    We may disclose personal data to:

    **A. Service Providers and Data Processors** We use third parties to support hosting, infrastructure, authentication, payments, email delivery, text-to-speech, AI processing, and security operations. Examples may include: cloud infrastructure providers such as Supabase, payment processors such as Stripe, email delivery providers such as Resend, authentication providers such as Google or Apple, and AI and audio providers used to power product features.

    **B. Professional Advisers and Corporate Transactions** We may disclose data to lawyers, auditors, insurers, bankers, investors, potential acquirers, or other professional advisers where reasonably necessary for financing, restructuring, merger, acquisition, asset sale, due diligence, or insurance-related purposes, subject to appropriate confidentiality protections.

    **C. Legal and Safety Disclosures** We may disclose data where reasonably necessary to: comply with law, regulation, court order, or lawful request; enforce our Terms; protect the rights, safety, and security of users or others; detect, prevent, or investigate fraud, abuse, or unlawful activity; or respond to emergencies, where permitted by law.

    We do not sell personal data for advertising purposes.

    8. International Transfers

    Your personal data may be stored or processed outside Singapore, including in jurisdictions where our vendors, cloud infrastructure, AI providers, or support operations are located.

    Under the PDPA's transfer limitation obligation, an organisation transferring personal data outside Singapore must ensure a standard of protection comparable to the protection under the PDPA, unless an exception applies.

    Where we transfer personal data internationally, we take reasonable steps to implement appropriate safeguards, which may include:

    • contractual data protection clauses, • vendor due diligence and security reviews, • access controls and encryption, • internal policies and restricted handling requirements, and • other measures reasonably designed to ensure comparable protection.

    9. Data Retention

    We retain personal data only for as long as it is reasonably needed for the purposes for which it was collected, or as required or permitted by law.

    PDPC guidance states that organisations must cease to retain documents containing personal data, or remove the means by which the personal data can be associated with particular individuals, as soon as it is reasonable to assume that the purpose for which that data was collected is no longer being served by retention and retention is no longer necessary for legal or business purposes.

    In practice: • account and profile data are retained while your account is active; • journal and chat data are retained while needed to provide the Services, maintain continuity, support your settings, and address legitimate support, safety, dispute, or compliance needs; • technical logs, diagnostics, and security records may be retained for a limited period appropriate to security, fraud prevention, audit, and operational needs; • payment, invoicing, tax, and accounting records may be retained for periods required by law or standard business recordkeeping obligations; and • aggregated or de-identified analytics may be retained for product improvement and reporting.

    When you delete your account, we will delete or anonymise personal data from active systems within a reasonable period, except where retention is reasonably necessary for legal, accounting, tax, dispute-resolution, fraud-prevention, security, backup, or other legitimate operational purposes.

    Residual copies may remain in secure backups for a limited period before being overwritten or securely deleted in accordance with our retention schedule.

    10. Security

    We use reasonable technical and organisational measures designed to protect personal data, including measures such as:

    • encryption in transit, • encrypted storage where appropriate, • authentication and session controls, • least-privilege access controls, • logging and monitoring, • environment separation and change controls, • vendor controls and contractual safeguards, and • restricted production access on a need-to-know basis.

    The PDPA imposes a protection obligation requiring organisations to make reasonable security arrangements to protect personal data in their possession or under their control.

    No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

    11. Data Breaches

    We maintain processes intended to detect, assess, contain, investigate, and respond to suspected data incidents.

    Where a data breach is notifiable under Singapore law, we will notify the PDPC as soon as practicable and, in any event, no later than 3 calendar days after determining that the breach is notifiable, and notify affected individuals as required by law.

    12. Your Rights and Choices

    Depending on your location and the circumstances, you may have rights to access, correct, delete, export, or object to certain processing, or to withdraw consent.

    Under the PDPA, individuals generally have rights relating to access, correction, and withdrawal of consent, subject to applicable exceptions.

    You may be able to do some of the following directly through the Services:

    • update profile information and preferences, • disable notifications, • edit or delete certain content, • export certain account data, and • delete your account.

    To exercise rights not available directly in-product, contact us at hello@innershore.com. We may need to verify your identity before processing your request. We will respond within a reasonable time and in accordance with applicable law.

    Please note that withdrawing consent or deleting certain data may limit or prevent the continued operation of some features.

    13. Children and Young Users

    The Services are not intended for children under 13.

    If we learn that we have collected personal data from a child under 13 without appropriate authorisation, we will take reasonable steps to delete that data.

    For users under 18, parental or guardian involvement may be required depending on the circumstances and applicable law.

    PDPC guidance states that a child between 13 and 17 may be able to give valid consent if the relevant notices and consequences are readily understandable to the child, while children below 13 generally require parental or guardian consent.

    14. Third-Party Sites and Services

    The Services may contain links to third-party websites, products, or services. We are not responsible for the privacy practices of third parties, and their handling of your data is governed by their own terms and privacy policies.

    15. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes in our Services, operations, legal requirements, vendors, or risk controls.

    If we make material changes, we will provide notice by posting the updated version in the Services, by email, or by other reasonable means.

    16. Contact Us

    Inner Shore Pte. Ltd. Data Protection Officer: hello@innershore.com General support: hello@innershore.com

    If you are not satisfied with our response to a personal data matter, you may contact the Personal Data Protection Commission of Singapore. PDPC materials state that individuals should generally contact the organisation's DPO first, and that the DPO's contact information can typically be found in the organisation's privacy policy.