Privacy Policy
Last updated: 3 June 2026
Attunia (“Attunia”, “we”, “us”) is a voice-first clinical assistant for mental-health practitioners. This policy explains what information we handle across the two parts of Attunia: this website at attunia.care (including the practitioner portal) and the Attunia Desktop application that runs on your own computer. Attunia is built local-first: your clients’ clinical information stays on your device by default.
Information that stays on your device
The desktop app stores your clients, appointments, session notes, and any audio recordings and transcripts in a database on your own computer. Speech-to-text and the on-device assistant run locally. This clinical and patient information is not uploaded to us by default, and we never receive it in readable form.
Information that leaves your device
- Practitioner account (optional). If you create an Attunia portal account we store your name, email address, and a securely hashed password. When you sign in online, your password is sent over an encrypted connection so it can be verified.
- Diagnostic data (closed beta). During the beta the desktop app sends a device identifier and technical logs that exclude your clients’ clinical and personal data, so we can keep the app working and help you if something breaks. Beta participants are told this in writing; it will become opt-in before any wider release.
- Information you choose to publish. If you opt in, your public professional profile and availability are published to the website directory.
- Team/clinic sharing and multi-device sync (optional). If you enable sharing with colleagues or syncing across your own devices, the relevant client and appointment information leaves your device only as end-to-end-encrypted data. Our servers relay that data but cannot read it — the decryption keys never leave your devices.
Google Calendar data
Connecting Google Calendar is optional. If you connect it, Attunia requests the following access:
calendar.readonly— to list your calendars (so you can choose which to sync) and read events to keep appointments in sync and detect scheduling conflicts.calendar.events— to create, update, and delete the appointments you schedule in Attunia so they stay in sync with your Google Calendar.userinfo.email/userinfo.profile— to identify which Google account is connected.
Where it is stored. The Google authorization tokens are stored encrypted (AES-256-GCM) on your own device. Your Google Calendar data is processed locally on your device to mirror appointments; we do not store your Google Calendar data on our servers.
Limited Use. Attunia’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell your Google data, use it for advertising, or share it with third parties.
Revoking access. You can disconnect Google Calendar from within Attunia’s settings at any time, or remove Attunia’s access at myaccount.google.com/permissions. Disconnecting stops further sync and deletes the stored tokens from your device.
The website
- Hosting. The website is hosted on Vercel and its backend on Fly.io (EU region). Standard server logs may be processed to operate and secure the service.
- Performance metrics. We use Vercel Speed Insights to collect anonymous performance measurements (such as page-load timings). It does not identify you and we do not run advertising or cross-site tracking.
- Cookies. The marketing pages do not use tracking cookies. The practitioner portal uses a strictly necessary, HttpOnly session cookie to keep you signed in.
- Email. We use Brevo to send transactional emails (email verification, password reset, team invitations, and security notices). We do not send marketing email.
How we protect information
Data in transit is protected with TLS. Sensitive secrets and OAuth tokens are encrypted at rest on your device (AES-256-GCM). Client and appointment data shared across devices or colleagues is end-to-end encrypted so that our relay servers cannot read it.
Service providers
We use a small number of processors to run the service: Vercel (website hosting), Fly.io (backend hosting, EU), Brevo (transactional email), and Google (Calendar — only when you connect it). We do not sell personal information.
Your role and your rights
As a practitioner you are the controller of your clients’ information; Attunia is the tool you use to process it, and where we process personal data on your behalf we act as your processor. Subject to applicable law (including the GDPR), you may request access to, correction of, or deletion of the personal data we hold about your account. You can delete clinical data directly in the app; removing your local data store erases it from your device, and disconnecting opt-in sync removes the encrypted copies we relay. To exercise your rights, contact privacy@attunia.care.
Data retention
Account data is kept while your account is active. Diagnostic logs are kept only for a short period and then automatically deleted. Clinical data is retained on your device under your control until you delete it.
Children
Attunia is intended for qualified professionals and is not directed at children. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. We will revise the “last updated” date above and, for material changes, provide a more prominent notice.
Contact
Questions about this policy or your data? Email privacy@attunia.care.