Política de privacidad
Recovery Trauma™ respects and protects your privacy. Your recovery is personal — your information is treated with the same care. This notice explains what we collect, why, how long we keep it, who it is shared with, and the rights you have.
Last updated: Septiembre 2026
1. Who we are (data controller)
RECOVERY TRAUMA LTD (Company No. 16340718), registered in England and Wales, is the controller of personal data processed through the Recovery Trauma™ website and iOS app, except where this notice says otherwise. “Recovery Trauma™” is the platform and brand name; RECOVERY TRAUMA LTD is the company behind it.
Privacy contact: info@recoverytrauma.com
We have not appointed a statutory Data Protection Officer; privacy matters are handled by the Founder & Product Compliance Lead, whose responsibilities are set out in our governance documentation.
2. Information we collect
Account information
- Name or display name
- Correo electrónico
- Account identifier (user ID) and authentication information handled by our authentication provider
- Account status, membership status and tier
- Preferences and in-app settings (including notification and email preferences)
- Consent records — for example cookie choices, AI feature consent, marketing consent, and acceptance of Terms and this policy
- Optionally, how you heard about us, if you choose to answer
Membership and transaction information
- Membership plan, subscription status, renewal and cancellation status
- Payment provider used (Stripe or PayPal), subscription and transaction references, payment dates and amounts
- Billing and invoice history
Recovery Trauma™ does not receive or store full payment-card details. Card and account details are entered directly with Stripe or PayPal, who act as independent controllers for the payment itself.
Content you create
- Journal entries, guided journal answers and reflections
- Dream Journal entries, including voice recordings you choose to transcribe
- Trigger Journal, Abuse Journal, Music Journal, Shadow Work, Inner Child, process-work and creative entries
- Artwork, images and files you upload
- Community posts, comments, hearts and reports you submit
- Support messages and correspondence with us
Wellbeing and self-assessment information
- Self-assessment responses and results
- Mood check-ins and Emotion Wheel / “How are you feeling?” selections
- Exercise, practice and progress records (for example completed sessions, favourites, toolkit items)
- Anything you type into self-help tools
Information you enter into these features may reveal sensitive details about you. See section 3.
Therapist applicants and directory
- Name, email, website, professional title and short biography
- Qualifications, professional body, registration or licence details and licensing jurisdiction
- Insurance confirmation, certificates and supporting documents you upload
- Photograph, country, region, languages, approaches, specialisms and availability
- Application responses, verification status and a consent audit record (date and time, policy version accepted, marketing consent, account identifier and, where lawful, IP address)
Technical and usage information
- A session identifier and a visitor identifier stored in your browser
- Pages or screens viewed, features used, referring site and campaign parameters (utm tags)
- Coarse device information derived from your browser user-agent: device type, operating system, browser and screen size, and whether you are inside an in-app browser
- Authentication events and security events (for example failed sign-ins, admin access logs)
- Error and diagnostic records when something goes wrong
- IP address — processed transiently by our hosting and security layer, and by rate-limiting protections. We do not store IP addresses in our analytics records; we do record IP address where you submit a therapist application and where legally permitted
App permissions (iOS)
The app asks for a permission only at the moment a feature needs it, and you can refuse or withdraw it in iOS Settings:
- Microphone — only when you choose to record a voice note; the recording is sent to our transcription provider to turn it into text (see section 6)
- Camera and Photos — only when you choose to take or select an image for your profile, a journal entry or a community post
- Notifications — only if you turn notifications on; we then store a device push token so we can send the notifications you asked for
The app does not request location, contacts, health data or advertising tracking, and contains no advertising or tracking SDKs.
3. Sensitive (special-category) information
Recovery Trauma™ is a wellbeing, education and self-help platform. We do not diagnose, assess or treat anyone, and we do not create medical records. However, what you voluntarily write into journals, assessments, reflections, support messages or community areas may reveal sensitive information — for example about physical or mental health, trauma experiences, sexual life or orientation, religious or philosophical beliefs, race or ethnicity, or other personal circumstances.
Where information you provide amounts to special-category data under UK GDPR Article 9, we rely on your explicit consent (Article 9(2)(a)), given when you choose to enter that information into an optional feature, together with contract as the Article 6 basis for providing the feature to you. You are never required to enter sensitive information in order to use your membership, and you can delete individual entries at any time.
Separately, where we need to act on a serious safety concern — for example a report suggesting a risk of serious harm — we may process relevant information on the basis of substantial public interest or vital interests, following the procedures in our escalation pathway. This is a platform-governance process, not clinical care.
4. Purposes and lawful bases
| Purpose | Typical data | UK GDPR lawful basis |
|---|---|---|
| Create and manage your account | Account data | Contract |
| Provide membership features and save your content | Account, membership, content you create | Contract |
| Process payments and manage subscriptions | Transaction and billing information | Contract; legal obligation for accounting records |
| Platform security, abuse and fraud prevention | Technical, authentication and security data | Legitimate interests — keeping the platform and its members safe and secure; legal obligation where applicable |
| Customer support | Account data and your messages to us | Contract; legitimate interests in answering enquiries |
| Community moderation and handling reports | Posts, comments, reports, moderation records | Contract (our Community Guidelines); legitimate interests — member safety |
| Governance, safeguarding, incident and compliance records | Case records, decisions and actions | Legal obligation; legitimate interests — accountability and audit readiness |
| Service and transactional emails | Email address, account and membership status | Contract |
| Marketing emails and updates | Email address and contact preferences | Consent (withdrawable at any time), or soft opt-in under PECR for our own similar services |
| Optional analytics to understand how the platform is used | Usage and coarse device information, session/visitor identifier | Consent (cookie banner) |
| Essential operational measurement (sign-up and payment funnel diagnostics) | Event type, session identifier, page | Legitimate interests — making sure sign-up and payment actually work; not used for advertising |
| Optional AI features (reflections, guided chat, transcription) | The text or audio you submit for that feature | Consent for the feature; contract for providing it |
| Sensitive wellbeing information you choose to enter | Journals, reflections, assessments | Article 6: contract · Article 9: explicit consent |
Where we rely on consent, you can withdraw it at any time — that does not affect processing already carried out. Where we rely on legitimate interests, we have considered your rights and interests, and you can object (see section 14).
5. How we use information
- Creating and administering accounts and memberships
- Saving your journals, reflections, assessments and progress so they are there when you return
- Operating community features and the therapist directory
- Processing therapist applications and verifying required documentation
- Running seminars and events and managing reservations
- Managing subscriptions, renewals, cancellations and invoices
- Providing customer support and answering your messages
- Sending service and account emails, and marketing emails where permitted
- Maintaining platform security, preventing fraud and abuse
- Moderating content and investigating reports
- Meeting legal, accounting and compliance obligations
- Fixing bugs, monitoring reliability and improving the platform
Recovery Trauma™ does not sell your personal information, and does not use your content to advertise to you.
6. AI and automated processing
Some optional features use AI. Where they do, your text or audio is sent from our servers to the provider below, processed to return a result, and the result is shown to you. Our providers are engaged on terms that do not permit your content to be used to train their models.
| Feature | What is sent | Provider | Consent |
|---|---|---|---|
| Journal reflection | The prompt, title, text and mood of that entry | Lovable AI Gateway (routing to Google Gemini models) | Yes — a consent screen explains this before the first reflection; declining still saves your entry |
| Dream reflection | The dream text and mood of that entry | Lovable AI Gateway (Google Gemini) | Yes — same consent screen |
| Voice note transcription | The audio you recorded | ElevenLabs (speech-to-text) | You choose to record and transcribe; audio is sent only when you do |
| Guided audio (spoken practices) | Recovery Trauma™ script text only — no personal information | ElevenLabs; Lovable AI Gateway as fallback | Not applicable |
| Support chat and in-app guide | The messages you type in that conversation | Lovable AI Gateway (Google Gemini) | You choose to use it; please do not enter details you do not want processed |
| Safety screening | Short extracts of text you submit where wording suggests a risk of serious harm | Lovable AI Gateway (Google Gemini) | Not optional — this is a safety measure. It flags for human review and signposting only |
| Interface translation | Recovery Trauma™ interface text only — never your entries | Lovable AI Gateway | Not applicable |
Safety screening flags content for human review and signposting to crisis resources. It does not diagnose, and it does not take automated action against your account.
We do not carry out automated decision-making that produces legal or similarly significant effects about you, and we do not profile you for advertising.
See our AI Disclaimer for what AI features can and cannot do.
7. Service providers we share information with
| Provider | Purpose | Information | Role |
|---|---|---|---|
| Lovable / Supabase (database, authentication, file storage, hosting) | Runs the platform and stores its data | All account, content and technical data described above | Processor |
| Stripe | Card payments and subscriptions | Email, name, subscription and payment data | Independent controller for payment processing |
| PayPal | PayPal payments and subscriptions | PayPal account identifiers, subscription and payment data | Independent controller for payment processing |
| Resend (email delivery) | Sends service and marketing emails | Email address and message content | Processor |
| Lovable AI Gateway (routing to Google and OpenAI models) | Optional AI features and safety screening | Only the text sent for that feature (see section 6) | Processor |
| ElevenLabs | Voice transcription and guided-audio narration | Audio you record; script text | Processor |
| Apple | App distribution and push notification delivery (APNs) | Device push token and notification content | Independent controller / processor as applicable |
| Apple iTunes Search API | Song search in the Music Journal | Your search words only — not your account or entry | Independent controller |
| Spotify (embedded player) | Shows a Spotify player if you paste a Spotify link | Your IP address and browser data, by Spotify, when the embed loads | Independent controller |
| Google Fonts | Loads the site typefaces | IP address and browser data when fonts are requested | Independent controller |
| Trustpilot | Displays reviews of Recovery Trauma™ | IP address and browser data when the review widget loads | Independent controller |
| Zoom | Live seminars and workshops you choose to join | Whatever you provide to Zoom when joining a session | Independent controller |
We require our processors to act only on our instructions, to keep information confidential and secure, and to provide protection consistent with applicable data-protection requirements and our contractual arrangements with them. We may also disclose information where we are legally required to, or to establish or defend legal claims.
We do not currently use Google Analytics, advertising pixels or third-party error-tracking services. Usage analytics and error records are stored in our own database.
8. International data transfers
Our production database, authentication system and file storage are hosted in the European Union (Frankfurt, Germany), including provider-managed backups.
Some of our providers are based in, or may access data from, the United States or other countries — this includes Stripe, PayPal, Resend, ElevenLabs, Apple, Google and the AI gateway. Where personal data is transferred outside the UK, the transfer is made under a lawful transfer mechanism — UK adequacy regulations where the country is covered by them (including the EU and the UK Extension to the EU–US Data Privacy Framework where a provider is certified), or the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as provided in that provider's data processing terms.
9. How long we keep information
| Information | Retention |
|---|---|
| Account and profile information | While your account is open; removed when you delete your account |
| Journals, reflections, assessments, mood and progress records | Until you delete the entry, or until you delete your account |
| Uploaded images and files | Until you delete the item. Files in storage are removed on request — tell us if you want uploads purged when you close your account |
| Community posts and comments | Until you delete them, or until you delete your account. Copies may persist briefly in operational backups |
| Moderation and report records | Kept while needed to investigate and to show a consistent moderation history; reviewed at least annually |
| Support correspondence | Up to 2 years after the matter is closed, unless needed for a legal claim |
| Safeguarding and crisis-alert records | Retained after account deletion where needed for safeguarding accountability, and reviewed at least annually |
| Transaction, invoice and accounting records | 6 years plus the current financial year (UK accounting and tax requirements) |
| Marketing consent and unsubscribe records | Kept as a suppression record after account deletion so we do not email you again |
| Analytics and usage events | Retained in aggregate-usable form; reviewed and pruned periodically |
| Security, authentication and admin access logs | Retained for security monitoring and reviewed periodically |
| Therapist applications and verification documents | Kept while the listing is active. Unsuccessful or withdrawn applications are removed on request — see section 16 |
| Provider backups | Encrypted backups are kept by our hosting provider on a rolling schedule and overwritten in the normal cycle; deleted content disappears from backups as they roll |
Where a fixed period is not given, we keep information only as long as needed for the purpose it was collected for, taking into account the sensitivity of the information, the risk of harm from unauthorised use, whether the purpose can be achieved another way, and our legal, accounting, safeguarding and evidential obligations.
We are honest about the limits: deleting your content removes it from the live platform immediately, but a small number of records — financial records, safeguarding records, suppression records and rolling backups — may lawfully remain for longer.
10. Deleting your account
You can delete your account yourself, from the website and from inside the iOS app: go to Account → Privacy & Data and choose “Delete my account”. You can also email info@recoverytrauma.com.
What happens
- Deletion runs immediately once you confirm — it is not queued for 30 days.
- Your profile, journals, dream entries, mood check-ins, assessment responses, saved practice records, community posts, comments and hearts, and your sign-in account are deleted.
- Your marketing record is anonymised and kept only as a suppression entry so you are not emailed again.
- Financial records (invoices and payment records) and safeguarding records are retained as described in section 9.
- Files you uploaded (images, artwork, evidence attachments) are not automatically purged from storage by the self-service flow — email us and we will remove them.
- Deletion is permanent. We cannot restore an account or its content afterwards.
Subscriptions are separate
Deleting your account does not cancel a paid subscription, and we do not cancel it silently on your behalf. If you have an active subscription, the platform will ask you to cancel it first:
- Stripe subscriptions — cancel from My Membership → Membership & Billing.
- PayPal subscriptions — cancel in My Membership, or in your PayPal account under automatic payments.
- If Apple in-app purchases are offered in future, those subscriptions would be managed in your Apple ID settings and could only be cancelled by you through Apple.
11. Journals and private reflections
Journals, dream entries, trigger and abuse journals, shadow work, inner child work, music journal entries and assessment responses are private to your account under normal platform operation. They are not shown to other members, not published, and not used for advertising or for training AI models.
- Access controls in the database restrict each entry to the account that created it.
- Administrator access is technically possible. Authorised Recovery Trauma™ administrators can retrieve a member's records through secure administrative tools — for example to fulfil a data-access request, investigate a support issue or respond to a legal or safeguarding obligation. We do not read journals for curiosity, analytics or marketing, and administrator actions are logged.
- Entries are stored in plain text in our database. They are encrypted in transit (TLS) and the database and file storage are encrypted at rest by our infrastructure provider. They are not end-to-end encrypted — we do not claim that we cannot technically read them.
- Entry content is not included in usage analytics. Only that an action happened (for example “journal saved”) may be recorded.
- Entry content is sent to an AI provider only when you ask for a reflection, and only after the AI consent screen — see section 6.
- Entries are included in encrypted provider backups.
- Deleting an entry removes it from the live platform; deleting your account removes your entries as described in section 10.
If you write a journal entry before creating an account, it is stored only in your own browser until you sign up.
12. Community areas
The community is a shared space, not a private journal. Anything you post — including posts, comments and any image you attach — is visible to other members according to that feature's settings, even if you post anonymously to other members. Please do not post anything you would not want other members to see.
- Reports you submit, and moderation records, are reviewed by authorised Recovery Trauma™ administrators.
- Content may be retained temporarily where needed to investigate abuse, safety incidents, policy violations or legal claims, even after it is removed from view.
- You can delete your own posts and comments at any time, and you can block another member.
13. Cookies, local storage and analytics
We use very few cookies. Most of what we store sits in your browser's local storage rather than in cookies:
- Essential — your sign-in session (stored by our authentication provider in local storage), sign-in flow state, your cookie choices, and safety acknowledgements. These cannot be switched off without breaking the platform.
- Preferences — things you chose, such as theme, audio volume and speed, recently used tools, favourites and saved drafts. Stored on your device only.
- Analytics — optional and off until you agree. If you agree, we record a session and visitor identifier with the pages you view, features used, referrer and campaign tags, and coarse device information, in our own database. If you decline, those events are not recorded.
- Essential operational measurement — a small number of sign-up and payment diagnostics that run regardless of the analytics choice, so we can tell whether joining and paying are working. These are never used for advertising.
- Marketing — the banner offers this category, but we do not currently run any marketing cookies or pixels, so the choice has no effect today.
Embedded content from Spotify, Trustpilot or Google Fonts may set its own cookies or receive your IP address when it loads. You can change your choices at any time on our Política de Cookies página.
14. Marketing communications
We send two different kinds of email, and we keep them separate:
- Service and account emails — sign-up confirmation, password resets, payment and renewal notices, event details, and important service notices. These are part of your membership and are not marketing; you cannot opt out of them while your account is open.
- Marketing and community updates — news, new content, offers and event invitations. These are sent on the basis of your consent, or the PECR soft opt-in where you are an existing member and we are telling you about our own similar services.
We record when and how your preference was given. Every marketing email has an unsubscribe link, and you can change your preferences in your account at any time. Withdrawing consent does not affect emails already sent.
15. Your rights
Under UK GDPR you have the right to:
- Access — a copy of the personal information we hold about you
- Rectification — correction of inaccurate or incomplete information
- Erasure — deletion of your information in the circumstances the law provides for
- Restriction — to ask us to pause certain processing
- Portability — to receive information you gave us in a portable format
- Object — to processing based on legitimate interests, and to direct marketing at any time
- Withdraw consent — where processing is based on consent, including AI features and analytics
- Rights relating to automated decision-making — we do not carry out automated decisions with legal or similarly significant effects
Which rights apply depends on the lawful basis and the circumstances. To exercise any right, email info@recoverytrauma.com. We respond within one month, and will tell you if we need longer because a request is complex. We may need to confirm your identity first.
16. Complaints
You have the right to complain to the UK's supervisory authority, the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint · helpline 0303 123 1113.
You can contact the ICO at any time. We would also be glad of the chance to put things right first, if you would like to raise it with us directly.
17. Payments
Payments are handled by Stripe and PayPal, who are PCI-DSS compliant. Your full card details are entered with them and never reach our servers. We receive confirmation of payment, the plan, the amount, the dates and provider references so we can manage your membership and keep accounting records.
18. US privacy rights
Recovery Trauma™ operates as a wellbeing, education, self-help, community and therapist-discovery platform and does not represent itself as a HIPAA-covered healthcare provider. The applicability of HIPAA and other US privacy laws can depend on the nature of the entity, the information and the processing involved. Therapists listed in our directory are independently responsible for their own professional and legal obligations.
If you are a US resident you may have additional rights under state privacy laws, including CCPA/CPRA in California and comparable laws in other states. See our US Privacy Rights Notice. We do not sell personal information and do not share it for cross-context behavioural advertising.
19. Therapist applicants
We collect the information and documents in the therapist application solely to review your eligibility for the Recovery Trauma™ Therapist Directory and to carry out administrative verification of the credentials, registration and insurance you state.
- Access — applications and uploaded documents are held in private storage and are accessible only to authorised Recovery Trauma™ administrators responsible for therapist-directory verification. At present that is the Founder & Product Compliance Lead, who also performs the Platform Administrator role.
- Sharing — your documents are not published and are not shared with other members or third parties, except where we are legally required to disclose them. Only the profile information you agree to list is shown publicly.
- Verification is administrative, not clinical. We check that documentation exists and appears valid; we do not supervise or endorse your practice.
- Lawful basis — steps taken at your request before entering a contract, and our legitimate interest in verifying directory listings. Where documents reveal special-category information, we rely on your explicit consent.
- Audit record — we log the date and time of your consent, the policy and Terms version accepted, your marketing consent status, your account identifier and, where lawful, your IP address.
- Retention — application records and documents are kept while your listing is active. Unsuccessful, withdrawn or ended applications are kept while needed for our records of verification decisions and are deleted on request; email info@recoverytrauma.com and we will remove them.
20. Security
We use appropriate technical and organisational measures designed to protect personal information, including encrypted transmission (TLS), authentication controls, row-level access controls in the database that restrict records to their owner, restricted administrator accounts with access logging, private (non-public) file storage, and the security measures provided by our infrastructure providers, which include encryption of the database and file storage at rest.
No online platform can be completely secure, and we cannot guarantee absolute security. If a personal-data breach occurs, we assess it under our escalation and breach procedures and notify you and the ICO where the law requires it.
21. Age requirement
Recovery Trauma™ is intended for adults. You must be at least 18 to create an account, as set out in our Terms. We do not knowingly collect information from children. If you believe a child has created an account, contact us and we will remove it.
22. Changes to this policy
We review this notice regularly and update it when our processing changes. The date at the top shows when it was last updated. Where a change is material — for example a new purpose or a new category of sharing — we will bring it to your attention before it takes effect, by email or in the app, and will seek your consent where the law requires it.
23. Contact us
For any privacy question, data request or concern, please contact:
Related documents: Terms · Política de Cookies · AI Disclaimer · Disclaimer · Community Guidelines · US Privacy Rights
Last updated: Septiembre 2026
