Privacy Policy

Innerbloom Network LLC
Effective date: July 18, 2026 · Last updated: July 18, 2026

The short version

There are two different things covered by this policy, and they work very differently:

  1. This website (innerbloomnotes.com) collects a small amount of information — what you type into the waitlist form, ordinary server logs, and cookies from Google Ads that let us measure whether our advertising leads to signups. That is described in Part One.
  2. The Innerbloom Therapy Notes application runs entirely on your own Mac. We do not operate a server for it. We do not receive your recordings, transcripts, notes, client records, or any protected health information (PHI). We have no ability to access them. That is described in Part Two.

If you only read one sentence: we collect your name and email if you give them to us, and nothing from inside the app.

Who we are

Innerbloom Network LLC ("Innerbloom," "we," "us," "our") is a California limited liability company. We publish the website at innerbloomnotes.com and develop the macOS application Innerbloom Therapy Notes (the "Application").

Contact for privacy questions:
legal@innerbloomnotes.com
Innerbloom Network LLC

Part One — The Website

1. Information you give us

Waitlist signups

When you join the launch waitlist, we ask for and store:

FieldSourceWhy
First nameYouTo address you correctly in launch emails
Last nameYouTo identify duplicate signups and address you correctly
Email addressYouTo notify you when the Application is available
Country codeDerived from your network connection by our hosting providerTo gauge geographic demand and anticipate regional requirements
Date and time of signupAutomaticRecord-keeping and ordering the list

The waitlist form includes a hidden anti-spam field. If it is filled in — which only automated bots do — the submission is silently discarded and nothing is stored.

We do not ask for your license number, practice name, client information, NPI, or any other professional or health-related detail on this website. Please do not send us any of it.

Email you send us

If you email us at any address published on this site, we receive and retain that message and your email address so we can respond. Do not include protected health information, client identifiers, session content, transcripts, or clinical notes in any message to us. See Section 8.

2. Information collected automatically

Server and security logs. Our hosting provider records ordinary request data when you visit — IP address, approximate location derived from it, browser and device type, requested pages, referring page, and timestamps. These logs exist to deliver the site, defend against attacks and abuse, and diagnose errors. We do not use them to build a profile of you.

Advertising cookies (Google Ads). We advertise the launch through Google Ads, and we use Google's advertising tag (gtag.js, ID AW-11503396442) to measure whether those ads lead to waitlist signups — and, depending on our Google Ads configuration, to build remarketing audiences. The tag loads on every page from Google's servers and sets Google advertising and conversion cookies in your browser (for example _gcl_au, which by default expires about 90 days after your last visit). Through it, Google receives your IP address, the pages you view on this site, and related ad-interaction data, and may associate that activity with your Google advertising profile. You can limit or block this — see Do Not Track and your choices below and Section 10.

What we don't use. Apart from Google Ads, the website sets no analytics or profiling cookies. We do not use Google Analytics, Meta pixels, session-replay tools, or any other advertising or analytics service. Our hosting and security provider may set strictly necessary cookies for bot mitigation and traffic security.

Your cookie choices. On your first visit a banner lets you Accept or Reject the advertising cookies, or open Cookie settings to choose. You can change your choice anytime through the Cookie Settings link in the footer of every page, or on the Do Not Sell or Share My Personal Information page. Your choice is remembered in a small first-party cookie. Strictly necessary cookies are always on; advertising cookies are on by default and turn off the moment you reject them or send a Global Privacy Control signal.

The cookies and similar storage this site uses:

NameSet byPurposeCategoryExpiry
ibn_consentInnerbloom (first-party)Remembers your cookie choiceStrictly necessary180 days
ibn-theme (local storage)Innerbloom (first-party)Remembers your light/dark themeStrictly necessaryUntil you clear it
_gcl_au and related _gcl_* / _gac_*Google AdsMeasure whether our ads lead to signups; remarketingAdvertising~90 days
Cloudflare security cookiesCloudflareBot mitigation and traffic security (may be set)Strictly necessaryVaries

Fonts. The site currently loads typefaces from Google Fonts. When it does, your browser makes a request to Google's servers, and Google therefore receives your IP address and basic request headers. This happens on page load, before you interact with anything. If you prefer to avoid it, use a browser extension that blocks third-party font requests — the site remains fully usable with fallback fonts.

Do Not Track, Global Privacy Control, and your choices. You can opt out of these advertising cookies at any time through the Cookie Settings link in any page footer, on our Do Not Sell or Share My Personal Information page, or by blocking them with your browser's cookie controls, a tracker-blocking or ad-blocking extension, or Google's own Ads Settings at adssettings.google.com; the rest of the site keeps working. We honor the Global Privacy Control (GPC) signal as a valid opt-out of the sale or sharing of your personal information — if your browser sends GPC, we do not enable the advertising cookies. Because browsers do not send a uniform Do Not Track signal and there is no agreed standard for honoring one, we do not separately respond to Do Not Track. See Section 10 for the rights and choices available to residents of specific regions.

3. How we use website information

We use it only to:

We do not use the name and email you give us for automated decision-making, profiling, or credit or insurance decisions, and we do not disclose them to advertisers. Our advertising measurement and any remarketing rely on the Google Ads cookies described in Section 2 — not on your waitlist details.

4. What we never do

One exception up front, so the rest is unambiguous: we use Google Ads advertising cookies to measure and target our own advertising (Section 2), and under California law that use may be treated as "sharing" — or even a "sale" — of personal information for cross-context behavioral advertising (see Section 10). That is the only advertising-related sharing we do. With that stated, the following remain firm:

5. Who processes website data on our behalf

We use a small number of service providers. Cloudflare and Resend are bound by contract to process data only on our instructions and not for their own purposes. Google Ads is different: Google acts as an independent advertising business and also uses the data its tag collects for its own purposes, governed by Google's own privacy policy.

ProviderRoleWhat it handles
Cloudflare, Inc.Website hosting, DNS, CDN, security, and the waitlist databaseRequest logs, IP addresses, and stored waitlist records
Resend (Plus Five Five, Inc.)Transactional and notification email deliveryYour name and email address when a signup notification or launch email is sent
Google LLC — Google FontsWeb font deliveryYour IP address and request headers at page load
Google LLC — Google AdsMeasuring our advertising and (depending on configuration) remarketingAdvertising and conversion cookie identifiers, your IP address, and the pages you view on this site

We will update this list if it changes. We do not disclose personal information to any other third party except as described in Section 6.

6. When we may disclose information

We may disclose information if we reasonably believe it is required to:

7. How long we keep website data

DataRetention
Waitlist recordsUntil the Application launches and launch communications conclude, until you unsubscribe or ask us to delete, or 24 months after signup — whichever comes first
Email correspondence24 months after the conversation closes, unless a longer period is needed for a legal or business record
Server and security logsAs retained by our hosting provider under its standard retention schedule, typically a short rolling window
Google Ads advertising cookiesStored in your browser for Google's cookie lifetimes (the conversion-linker cookie expires about 90 days after your last visit) and retained by Google under its own schedule; clearing your cookies removes them

When a retention period ends, records are deleted from the live database. Backups age out on their own schedule.

8. Please do not send us PHI

Innerbloom Network LLC is not a HIPAA covered entity, and — because the Application runs entirely on your own machine and we operate no service that receives clinical data — we are not your Business Associate. No Business Associate Agreement is required for you to use the Application, because we do not create, receive, maintain, or transmit protected health information on your behalf.

That arrangement only holds if you do not send us PHI. Do not include client names, initials, dates of birth, session recordings, transcripts, clinical notes, screenshots containing client information, or any other identifiable client data in emails, support requests, bug reports, or web forms. If you need to send us a log or a screenshot, redact it first.

If we receive PHI we did not ask for, we will delete it and ask you to resend a redacted version. We cannot sign a Business Associate Agreement covering the Application, and none is needed.

Part Two — The Application

9. What the Application does with your data

Innerbloom Therapy Notes runs locally on your Mac. It has no user account, no login, no cloud sync, and no server operated by us. There is no mechanism by which we could retrieve your data even if compelled to, because we never hold it.

Where your data lives

All of it stays on your machine, in a location you control:

No telemetry

The Application contains no analytics, no usage tracking, no crash reporting, no phone-home check, and no license-server call-back. Application diagnostic logs are written to the macOS system log and contain no client content — only non-identifying counts, model names, and file paths.

The Application's only network activity

By default, transcription and note generation run entirely offline using models that ship inside the Application. The Application makes network requests only in these cases, none of which reach us:

  1. Optional model downloads. If you choose to download an additional speech or language model, the Application fetches it over HTTPS from Hugging Face. These requests carry no client data.
  2. Optional external language model endpoint. If you deliberately configure the Application to use a language model server other than the one on your own machine, session transcripts are sent to whatever address you specify. The Application blocks this by default and requires an explicit, per-configuration confirmation before any non-local address is used, and revokes that permission automatically when you return the setting to your local machine.

If you enable option 2, that is a disclosure of PHI to a third party under HIPAA, and it is your responsibility — you need a Business Associate Agreement with that provider and encryption in transit. We can warn you and gate the feature; we cannot sign that agreement for you and are not a party to it. If you cannot obtain a BAA, keep the Application on its local, offline configuration.

Your responsibilities as the data custodian

Because we never hold your data, the safeguards around it are yours to maintain:

Part Three — Your rights and other terms

10. Your privacy rights

Everyone, regardless of where you live. You may ask us to:

Email legal@innerbloomnotes.com and we will respond within 30 days (or sooner if the law requires). We may need to verify your identity — usually by confirming you control the email address in question. We will not discriminate against you for exercising these rights.

Every marketing email we send includes a one-click unsubscribe link. Unsubscribing removes you from the list entirely.

California residents. The California Consumer Privacy Act, as amended, gives residents rights to know, delete, correct, and opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information. Our use of Google Ads advertising cookies (Section 2) may be considered "sharing" — and, under some interpretations, a "sale" — of personal information for cross-context behavioral advertising. We do not collect sensitive personal information through this website. The categories described in Sections 1 and 2 correspond to the CCPA categories of identifiers and internet or network activity. To opt out of this sharing, use our Do Not Sell or Share My Personal Information page, turn on Global Privacy Control in your browser (which we honor automatically as an opt-out), or email legal@innerbloomnotes.com and we will honor your request. You may also exercise your rights to know, delete, and correct using that address; an authorized agent may act on your behalf with proof of authorization; and you have the right not to receive discriminatory treatment for exercising these rights.

European Economic Area, United Kingdom, and Switzerland. Where the GDPR or UK GDPR applies, our legal bases are: consent for waitlist signup and marketing email (withdrawable at any time, with no effect on processing already carried out); legitimate interests for site security, abuse prevention, and responding to your correspondence; and legal obligation where applicable. You additionally have the right to object to processing, to request restriction, to data portability, and to lodge a complaint with your national supervisory authority. Our processing operations take place in the United States, and data transfers to our service providers are made under Standard Contractual Clauses or an equivalent transfer mechanism where required. The Google Ads cookies in Section 2 are not essential to using the site; where your local law requires your consent before such cookies are set, you can withhold it by blocking them as described in Section 2.

Other jurisdictions. If you live somewhere with comparable rights, we will honor an equivalent request. Just ask.

11. Children

The website and the Application are intended for licensed mental health professionals and are not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has submitted information to us, contact legal@innerbloomnotes.com and we will delete it.

Note: this concerns your information, not your clients'. Clinical records about minor clients live entirely on your machine and never reach us.

12. Security

Waitlist data is stored in a managed database with access restricted to authorized personnel, and is transmitted over TLS. Our email and hosting accounts are protected by multi-factor authentication. The Application's own security architecture is described in Section 9 and in the security documentation distributed with the Application.

No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any required regulator within the timeframes the law prescribes.

The website may link to third-party sites, including those of software companies and open-source projects. We do not control them and are not responsible for their privacy practices. Read their policies before providing information to them.

14. Changes to this policy

If we make material changes, we will update the effective date above, post the revised policy here, and — for changes that materially affect how we handle information you have already given us — email everyone on the waitlist before the changes take effect. Continuing to use the website after the effective date means you accept the revised policy.

15. Contact

Privacy questions, requests, or complaints:
legal@innerbloomnotes.com
Innerbloom Network LLC

Innerbloom Therapy Notes is a documentation aid for licensed clinicians. It does not provide medical advice and does not replace professional clinical judgment. Innerbloom Network LLC is not a HIPAA covered entity; responsibility for HIPAA compliance and safeguarding protected health information remains with the practitioner.