Privacy Policy
The short version
There are two different things covered by this policy, and they work very differently:
- This website (
innerbloomnotes.com) collects a small amount of information — what you type into the waitlist form, ordinary server logs, and cookies from Google Ads that let us measure whether our advertising leads to signups. That is described in Part One. - The Innerbloom Therapy Notes application does its clinical work entirely on your own Mac. We do not receive your recordings, transcripts, notes, client records, or any protected health information (PHI). We have no ability to access them. The Application does contact servers for a few narrow purposes — downloading its models and, only if you switch them on, reporting crashes and counting which features you use — and Part Two lists exactly what each one sends. That is described in Part Two.
If you only read one sentence: we collect your name and email if you give them to us, plus — only if you turn them on — crash reports and anonymous feature counts, and never anything from your sessions or about your clients.
Who we are
Innerbloom Network LLC ("Innerbloom," "we," "us," "our") is a California limited liability company. We publish the website at innerbloomnotes.com and develop the macOS application Innerbloom Therapy Notes (the "Application").
Part One — The Website
1. Information you give us
Waitlist signups
When you join the launch waitlist, we ask for and store:
| Field | Source | Why |
|---|---|---|
| First name | You | To address you correctly in launch emails |
| Last name | You | To identify duplicate signups and address you correctly |
| Email address | You | To notify you when the Application is available |
| Country code | Derived from your network connection by our hosting provider | To gauge geographic demand and anticipate regional requirements |
| Date and time of signup | Automatic | Record-keeping and ordering the list |
The waitlist form includes a hidden anti-spam field. If it is filled in — which only automated bots do — the submission is silently discarded and nothing is stored.
We do not ask for your license number, practice name, client information, NPI, or any other professional or health-related detail on this website. Please do not send us any of it.
Email you send us
If you email us at any address published on this site, we receive and retain that message and your email address so we can respond. Do not include protected health information, client identifiers, session content, transcripts, or clinical notes in any message to us. See Section 8.
2. Information collected automatically
Server and security logs. Our hosting provider records ordinary request data when you visit — IP address, approximate location derived from it, browser and device type, requested pages, referring page, and timestamps. These logs exist to deliver the site, defend against attacks and abuse, and diagnose errors. We do not use them to build a profile of you.
Advertising cookies (Google Ads). We advertise the launch through Google Ads, and we use Google's advertising tag (gtag.js, ID AW-11503396442) to measure whether those ads lead to waitlist signups — and, depending on our Google Ads configuration, to build remarketing audiences. The tag loads on every page from Google's servers and sets Google advertising and conversion cookies in your browser (for example _gcl_au, which by default expires about 90 days after your last visit). Through it, Google receives your IP address, the pages you view on this site, and related ad-interaction data, and may associate that activity with your Google advertising profile. You can limit or block this — see Do Not Track and your choices below and Section 10.
What we don't use. Apart from Google Ads, the website sets no analytics or profiling cookies. We do not use Google Analytics, Meta pixels, session-replay tools, or any other advertising or analytics service. Our hosting and security provider may set strictly necessary cookies for bot mitigation and traffic security.
Your cookie choices. On your first visit a banner lets you Accept or Reject the advertising cookies, or open Cookie settings to choose. You can change your choice anytime through the Cookie Settings link in the footer of every page, or on the Do Not Sell or Share My Personal Information page. Your choice is remembered in a small first-party cookie. Strictly necessary cookies are always on; advertising cookies are on by default and turn off the moment you reject them or send a Global Privacy Control signal.
The cookies and similar storage this site uses:
| Name | Set by | Purpose | Category | Expiry |
|---|---|---|---|---|
ibn_consent | Innerbloom (first-party) | Remembers your cookie choice | Strictly necessary | 180 days |
ibn-theme (local storage) | Innerbloom (first-party) | Remembers your light/dark theme | Strictly necessary | Until you clear it |
_gcl_au and related _gcl_* / _gac_* | Google Ads | Measure whether our ads lead to signups; remarketing | Advertising | ~90 days |
| Cloudflare security cookies | Cloudflare | Bot mitigation and traffic security (may be set) | Strictly necessary | Varies |
Fonts. The site currently loads typefaces from Google Fonts. When it does, your browser makes a request to Google's servers, and Google therefore receives your IP address and basic request headers. This happens on page load, before you interact with anything. If you prefer to avoid it, use a browser extension that blocks third-party font requests — the site remains fully usable with fallback fonts.
Product tour video. The homepage carries a short product-tour video hosted on YouTube. Nothing is requested from YouTube when the page loads: the player is not placed on the page until you click to play it, so if you never play the video, your browser never contacts YouTube at all. When you do play it, the player loads from youtube-nocookie.com — Google's privacy-enhanced embed domain, which does not use cookies to build an advertising profile from what you watch — and Google receives your IP address, basic request headers, and the fact that this video was played. The player stores a small amount of playback state in your browser's local storage under Google's own domain; your browser's site-data controls will clear it. Because the player loads only when you ask for it and is not part of our advertising measurement, it sits outside the advertising toggle described above. We receive no report of who watched, and playing the video is not linked to your waitlist signup or to anything else you enter on this site.
Do Not Track, Global Privacy Control, and your choices. You can opt out of these advertising cookies at any time through the Cookie Settings link in any page footer, on our Do Not Sell or Share My Personal Information page, or by blocking them with your browser's cookie controls, a tracker-blocking or ad-blocking extension, or Google's own Ads Settings at adssettings.google.com; the rest of the site keeps working. We honor the Global Privacy Control (GPC) signal as a valid opt-out of the sale or sharing of your personal information — if your browser sends GPC, we do not enable the advertising cookies. Because browsers do not send a uniform Do Not Track signal and there is no agreed standard for honoring one, we do not separately respond to Do Not Track. See Section 10 for the rights and choices available to residents of specific regions.
3. How we use website information
We use it only to:
- Send you a notification when the Application launches, and occasional related product updates
- Reply to messages you send us
- Understand how many people are interested and roughly where they are
- Keep the site available, secure, and working
- Comply with legal obligations
We do not use the name and email you give us for automated decision-making, profiling, or credit or insurance decisions, and we do not disclose them to advertisers. Our advertising measurement and any remarketing rely on the Google Ads cookies described in Section 2 — not on your waitlist details.
4. What we never do
One exception up front, so the rest is unambiguous: we use Google Ads advertising cookies to measure and target our own advertising (Section 2), and under California law that use may be treated as "sharing" — or even a "sale" — of personal information for cross-context behavioral advertising (see Section 10). That is the only advertising-related sharing we do. With that stated, the following remain firm:
- We do not sell your personal information for money.
- We do not rent, trade, or license your email address to data brokers, list vendors, marketing partners, or anyone else. (The Google Ads tag described in Section 2 receives cookie identifiers and IP address, not the name or email you type into the form.)
- We do not send you marketing for other companies' products.
- On the website, we use no analytics or tracking beyond the Google Ads conversion measurement in Section 2 — no Google Analytics, no Meta pixels, no session-replay. The product-tour video in Section 2 loads from YouTube only if you press play, and reports nothing back to us. What the Application itself sends is listed in Sections 9a through 9c.
5. Who processes website data on our behalf
We use a small number of service providers. Cloudflare and Resend are bound by contract to process data only on our instructions and not for their own purposes. Google Ads is different: Google acts as an independent advertising business and also uses the data its tag collects for its own purposes, governed by Google's own privacy policy.
| Provider | Role | What it handles |
|---|---|---|
| Cloudflare, Inc. | Website hosting, DNS, CDN, security, and the waitlist database | Request logs, IP addresses, and stored waitlist records |
| Resend (Plus Five Five, Inc.) | Transactional and notification email delivery | Your name and email address when a signup notification or launch email is sent |
| Google LLC — Google Fonts | Web font delivery | Your IP address and request headers at page load |
| Google LLC — YouTube | Playing the homepage product-tour video, in privacy-enhanced (youtube-nocookie.com) mode | Your IP address, request headers, and which video was played — only if you click to play it |
| Google LLC — Google Ads | Measuring our advertising and (depending on configuration) remarketing | Advertising and conversion cookie identifiers, your IP address, and the pages you view on this site |
We will update this list if it changes. We do not disclose personal information to any other third party except as described in Section 6.
6. When we may disclose information
We may disclose information if we reasonably believe it is required to:
- Comply with a valid law, subpoena, court order, or other legal process
- Enforce our Terms of Service or investigate suspected fraud, abuse, or security incidents
- Protect the rights, property, or safety of Innerbloom, our users, or the public
- Complete a merger, acquisition, financing, or sale of assets — in which case you will be notified before your information becomes subject to a materially different privacy policy, and you will have the opportunity to delete your data first
7. How long we keep website data
| Data | Retention |
|---|---|
| Waitlist records | Until the Application launches and launch communications conclude, until you unsubscribe or ask us to delete, or 24 months after signup — whichever comes first |
| Email correspondence | 24 months after the conversation closes, unless a longer period is needed for a legal or business record |
| Server and security logs | As retained by our hosting provider under its standard retention schedule, typically a short rolling window |
| Google Ads advertising cookies | Stored in your browser for Google's cookie lifetimes (the conversion-linker cookie expires about 90 days after your last visit) and retained by Google under its own schedule; clearing your cookies removes them |
When a retention period ends, records are deleted from the live database. Backups age out on their own schedule.
8. Please do not send us PHI
Innerbloom Network LLC is not a HIPAA covered entity, and — because the Application runs entirely on your own machine and we operate no service that receives clinical data — we are not your Business Associate. No Business Associate Agreement is required for you to use the Application, because we do not create, receive, maintain, or transmit protected health information on your behalf.
That arrangement only holds if you do not send us PHI. Do not include client names, initials, dates of birth, session recordings, transcripts, clinical notes, screenshots containing client information, or any other identifiable client data in emails, support requests, bug reports, or web forms. If you need to send us a log or a screenshot, redact it first.
If we receive PHI we did not ask for, we will delete it and ask you to resend a redacted version. We cannot sign a Business Associate Agreement covering the Application, and none is needed.
Part Two — The Application
9. What the Application does with your data
Innerbloom Therapy Notes runs locally on your Mac. It has no user account, no login, and no cloud sync. Recording, transcription, and note generation all happen on your machine, using models the Application downloads once — most of them while you set it up, and the rest the first time you use a feature that needs one. Once a model is on your Mac, the work it does requires no network connection and sends nothing anywhere.
We do operate servers, and the rest of this section, together with Sections 9a through 9c, describes exactly what reaches them: model files you download and, only if you switch them on, crash reports and anonymous counts of which features you use. The Application makes no license check. None of them receives your client data. There is no mechanism by which we could retrieve that data even if compelled to, because we never hold it.
Where your data lives
All of it stays on your machine, in a location you control:
- Client records, session metadata, generated notes, and carryover data are stored in an encrypted SQLCipher database (AES-256) protected by a passphrase you create.
- Session audio, transcripts, and waveform data are stored as individually encrypted files (AES-256-GCM) in a data folder you choose.
- Your own voiceprint, if you choose to enroll one, is stored in that same encrypted database. It is a mathematical summary of your voice rather than a recording of it, and the Application uses it for exactly one thing: working out which speaker is you on an in-person session captured through a single microphone, so the transcript can label the two of you correctly. There is deliberately no client voiceprint — the Application identifies your client only as the person who is not you — so it never becomes a store of your clients' biometric identifiers. Like everything else in this list, it stays on your Mac.
- Preferences (audio device selection, default note template, idle-lock timeout, data folder path) are stored unencrypted on your Mac and contain no client information.
- Your database passphrase is not stored anywhere. It is not written to disk, to the keychain, or to the database. The database is encrypted with a random key of its own, sealed in a key file beside it under both your passphrase and the recovery key the Application issues during setup. Your macOS login keychain holds a copy of that sealed key file, marked device-only and non-syncing, so that the file and the keychain copy can restore one another. That copy opens nothing on its own; it needs one of your two credentials.
What we do and don't collect
The Application sends us two kinds of information about how it is running, both described in full in Sections 9b and 9c, and neither of which can contain client data:
- Crash diagnostics. When the Application crashes, it can send a technical report so we can fix the fault. This is off unless you turn it on. We ask once during setup, and you can change it at any time.
- Feature usage. Anonymous counts of which parts of the Application you use, so we know what to build and what to fix. This is off unless you turn it on. We ask once during setup and never ask again.
There is no advertising, no profiling, and no third-party analytics service. Application diagnostic logs written to the macOS system log stay on your Mac and contain no client content — only non-identifying counts, model names, and file paths.
The Application's only network activity
Once its models are on your Mac, transcription and note generation run entirely offline on your own machine. The Application makes network requests only in these cases:
- Model downloads. The Application's models are downloaded rather than built in, and the first language model is required before it can write a note. They come from three places. The language model, the embedding model, and the audio encoder are served from our own storage. The speech-recognition and speaker-separation models are downloaded from
huggingface.co, a public model repository. And if you select macOS's own speech recognition, macOS downloads that model from Apple — a transfer your operating system makes, not one the Application makes, which is why we name Apple rather than a hostname we have not verified. Every one of them is a one-way download of a public file: no account, no credentials, and nothing about you in the request. Note that we do not extend to these the promise made in Sections 9a through 9c that we store no IP address. Those are endpoints we run end to end; model files are served from ordinary storage that keeps ordinary server logs, and we would rather say so than make a commitment we would have to configure our way into. - Crash diagnostics. See Section 9b. Off by default; sends nothing unless you switch it on.
- Feature usage. See Section 9c. Off by default; sends nothing unless you switch it on.
No session audio, transcript, or note ever leaves your Mac. That claim carries no exception. The Application has no setting that points it at a language model or embedding service other than the one running on your own machine, so a transcript, a note, or an instruction you type while refining one has nowhere else to go. The language model and the embedding model that builds the searchable index behind refine-by-chat both run locally, and every request in the list above is either a one-way download of a public file or a payload described in Sections 9a through 9c, none of which can carry client content.
Your responsibilities as the data custodian
Because we never hold your data, the safeguards around it are yours to maintain:
- Enable FileVault full-disk encryption on your Mac
- Choose a strong database passphrase, store it somewhere safe, and keep the recovery key the Application issues at setup somewhere separate from your Mac. We hold neither credential and can reset neither. If you lose the passphrase, the recovery key is the only way back in; if you lose both, nobody can recover your records
- Do not place your data folder inside a cloud-sync folder (iCloud Drive, Dropbox, Google Drive, OneDrive) unless you accept that encrypted copies of your files will be replicated off your machine, and you have a Business Associate Agreement with that provider
- Maintain your own encrypted backups and test that you can restore them
- Obtain informed consent from clients before recording, and comply with the recording-consent laws of your jurisdiction and your clients'
- Review every generated note before it enters a clinical record
9a. License validation
There is none. Innerbloom Therapy Notes is sold through the Mac App Store. Apple handles your purchase when you install the Application, and the Application makes no license check of its own: it contacts no license server, and it sends no license key and nothing that identifies your Mac.
The only network activity involved is installation. When macOS installs an App Store application, the operating system verifies the purchase with Apple and may ask you to sign in with your Apple Account. That is macOS talking to Apple as part of installing software, not the Application contacting a server, and we receive nothing from it.
If we ever sell the Application another way that needs a license check, we will describe that check on this page, and tell you inside the Application, before a version that makes it ships. Whatever form it takes, it will never stop you reading, decrypting, exporting, or printing anything already on your Mac. Your clinical records are yours and you are legally required to be able to produce them.
9b. Crash diagnostics
If you turn crash reports on, then when the Application stops unexpectedly it sends us a technical report so we can find and fix the fault. This is off unless you turn it on. We ask once, during setup; you can change it at any time under Privacy in the Application's settings, and the Application works identically either way. Turning it off also discards any report still waiting to be sent.
What a crash report contains
There are two kinds of report.
Every report contains:
- The Application version and build number
- Your macOS version and your Mac's model identifier (for example, "Mac16,10")
- A random identifier for this installation, so we can tell whether one person hit the same crash forty times or forty people hit it once
The simplest report is only that: it says a run of the Application ended without shutting down properly, which can mean a crash but also a force quit or a power cut.
When macOS provides the crash report it recorded itself, the report also contains:
- The call stack of the part of the Application that crashed: for each step, the name of the program file it was in (the Application itself, or a part of macOS), that file's unique build identifier, and a position within that file. We turn those positions into function names and line numbers on our side, using records we keep of each version we build.
- The type of fault macOS recorded, as numbers (an exception type, a signal, and a code), and, for one particular kind of fault, its standard name (for example, "NSRangeException")
macOS decides whether to provide that report; the Application does not install anything of its own to capture crashes.
What a crash report never contains
This list is exhaustive:
- No memory contents. A call stack is a list of positions in program code, not the data the code was working on. The report does not capture the Application's working memory, which is where transcripts and notes exist while the Application is running. This is the single most important line in this section, and it is why we do not use an off-the-shelf crash reporting service — most of them capture memory by default.
- No message text. macOS's crash report can include a written reason for the crash and a description of the memory involved. The Application never reads those, and never reads the message attached to an internal error, because any of them could quote data the Application was handling.
- No file contents and no file names. The only names in a report are the names of program files, such as the Application itself and parts of macOS.
- No client names, initials, or identifiers.
- No transcripts, summaries, notes, or carryover content.
- No text you have written — not template names you create, not custom instructions, not edits you make to a note.
We keep crash reports for 90 days and then delete them. We do not store the IP address a report was sent from.
Separately, macOS collects its own crash reports for every application on your Mac and forwards them to developers only if you turned on "Share with App Developers" when you set up your Mac. That is a macOS setting, not ours; you can change it in System Settings → Privacy & Security → Analytics & Improvements.
9c. Feature usage
This is off. It stays off unless you deliberately turn it on. We ask once, during setup, and we do not ask again. You can switch it back off at any time, and doing so stops all transmission immediately.
We ask because we are one clinician building a tool for other clinicians, and we would rather build what you actually use than guess. If you would rather not help with that, decline — nothing about the Application changes.
What is sent, if you turn it on
Each event is a name from the fixed list below, plus the values shown. There are no free-text fields anywhere in this system, so there is no field into which your data could accidentally end up.
| Event | Values sent with it |
|---|---|
app_launched | Application version, macOS version, memory tier (under 16GB / 16GB / 24GB / 32GB+) |
session_started | Source: a live recording, a written write-up, or an imported recording |
session_completed | Recording length as a range (for example, 45–60 minutes; left out for a written write-up); transcription time in seconds; note generation time in seconds; the date, never the time of day |
session_abandoned | Which stage it was abandoned at |
template_used | The built-in note format's identifier, and whether you have edited its instructions — never the instructions themselves |
note_regenerated | Nothing further |
note_exported | Format only |
feature_opened | Which screen (preferences, client list, audit log, and so on) |
error_nonfatal | An error code from a fixed list |
Every event also carries a random identifier for this installation. That identifier is generated on your Mac, is not derived from your hardware, is not linked to your name, email, or purchase, and is regenerated if you reset the Application.
What is never sent
- Client names, initials, or any client identifier
- How many clients you have
- Transcripts, audio, summaries, notes, or carryover content
- Anything you typed, including template names and custom instructions
- The contents of your database or any file on your Mac
We keep usage events for 90 days and then delete them. We do not store the IP address they were sent from. We do not use a third-party analytics provider, and we do not sell, share, or license this data to anyone.
This list is the whole list
The tables above are complete as of the effective date at the top of this page. We are not reserving the right to collect anything else. If we ever add an event, we will update this page and tell you inside the Application before the version that sends it ships — you will not find out afterwards.
Part Three — Your rights and other terms
10. Your privacy rights
Everyone, regardless of where you live. You may ask us to:
- Tell you what personal information we hold about you
- Give you a copy of it
- Correct anything inaccurate
- Delete it
- Remove you from all marketing email
Email legal@innerbloomnotes.com and we will respond within 30 days (or sooner if the law requires). We may need to verify your identity — usually by confirming you control the email address in question. We will not discriminate against you for exercising these rights.
Every marketing email we send includes a one-click unsubscribe link. Unsubscribing removes you from the list entirely.
California residents. The California Consumer Privacy Act, as amended, gives residents rights to know, delete, correct, and opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information. Our use of Google Ads advertising cookies (Section 2) may be considered "sharing" — and, under some interpretations, a "sale" — of personal information for cross-context behavioral advertising. We do not collect sensitive personal information through this website, and the Application does not collect it either. The categories described in Sections 1 and 2, and the crash and usage data described in Sections 9b and 9c, correspond to the CCPA categories of identifiers and internet or network activity. To opt out of this sharing, use our Do Not Sell or Share My Personal Information page, turn on Global Privacy Control in your browser (which we honor automatically as an opt-out), or email legal@innerbloomnotes.com and we will honor your request. You may also exercise your rights to know, delete, and correct using that address; an authorized agent may act on your behalf with proof of authorization; and you have the right not to receive discriminatory treatment for exercising these rights.
European Economic Area, United Kingdom, and Switzerland. Where the GDPR or UK GDPR applies, our legal bases are: consent for waitlist signup and marketing email (withdrawable at any time, with no effect on processing already carried out); legitimate interests for site security, abuse prevention, and responding to your correspondence; and legal obligation where applicable. You additionally have the right to object to processing, to request restriction, to data portability, and to lodge a complaint with your national supervisory authority. Our processing operations take place in the United States, and data transfers to our service providers are made under Standard Contractual Clauses or an equivalent transfer mechanism where required. The Google Ads cookies in Section 2 are not essential to using the site; where your local law requires your consent before such cookies are set, you can withhold it by blocking them as described in Section 2.
Other jurisdictions. If you live somewhere with comparable rights, we will honor an equivalent request. Just ask.
11. Children
The website and the Application are intended for licensed mental health professionals and are not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has submitted information to us, contact legal@innerbloomnotes.com and we will delete it.
Note: this concerns your information, not your clients'. Clinical records about minor clients live entirely on your machine and never reach us.
12. Security
Waitlist data is stored in a managed database with access restricted to authorized personnel, and is transmitted over TLS. Our email and hosting accounts are protected by multi-factor authentication. The Application's own security architecture is described in Sections 9 through 9c and in the security documentation distributed with the Application.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any required regulator within the timeframes the law prescribes.
13. Links to other sites
The website may link to third-party sites, including those of software companies and open-source projects. We do not control them and are not responsible for their privacy practices. Read their policies before providing information to them.
14. Changes to this policy
If we make material changes, we will update the effective date above, post the revised policy here, and — for changes that materially affect how we handle information you have already given us — email everyone on the waitlist before the changes take effect. Continuing to use the website after the effective date means you accept the revised policy.
15. Contact
Innerbloom Therapy Notes is a documentation aid for licensed clinicians. It does not provide medical advice and does not replace professional clinical judgment. Innerbloom Network LLC is not a HIPAA covered entity; responsibility for HIPAA compliance and safeguarding protected health information remains with the practitioner.