Privacy & Terms
Privacy Policy Terms of Service

About Wysa and Our Contact Details

What Information We Collect and Use

How We Use Your Information

How We Protect Your Information

Who We Share Information With

Sharing Information Outside Your Country

Your Data Protection Rights

How To Complain

Supplementary Privacy Notices

Changes To This Policy

Change Log

Wysa Privacy Policy

Initial Effective Date: June 30, 2017(GMT)
Latest Revised Date: March 27, 2025 (GMT)
Version: 6.1.0

Our privacy policy explains what Wysa (“we”, “our”, “us” or “Wysa”) does with your provided information when you use our website or web pages (wysa.com), web-based or mobile-based software (“Wysa app” or “app”) and its services. If you are using our UK specific applications, namely, Everyday Mental Health by Wysa mobile app or Digital Referral Assistant application then you need to read this notice.

You may try out one or more services made available to you. These include:

  • A text or voice-based digital coach powered by an Artificial Intelligence chatbot (“AI Coach”).
  • Clinically verified tools delivered over text or voice (“Digital tools”).
  • Text or audio-video chats with a human mental health and well-being expert (“Wysa Coach”).
  • Text or audio-video chats with a healthcare professional (“Wysa Medical Assistant”).
  • Use our Digital Front Door and get access to different Institutional services (“e-triage”).
  • Use the AI Coach powered by Generative AI (“Wysa+”).

The aim of the app is to provide emotional wellbeing support in the form of an AI coach and the provision of a range of digital self-help tools and exercises. By showing you ways to improve your wellbeing and emotional resilience. The app does not tell you if you have a disease or condition, nor does it provide any medical advice or treatment. The app gives general advice for your mental health and well-being. The AI Coach is an AI technology powered software, not a real person, so it is restricted in the means of response. If you need medical advice, it will suggest that you see a local professional.

We will work with your public institution, healthcare institution, educational institution or other organization to offer our services. These are called Institutional services. Before you can use these Institutional services, you will need to agree to our notices and to the notices of your Institution.

By using our website, web pages, app and services, you agree that we can use your information as described in this privacy policy and any other related terms and policies ("notices").

1. About Wysa and Our Contact Details :

Touchkin eServices Pvt. Ltd. (“Wysa”) are the makers of the Wysa app and its services. Wysa is a company with offices in the UK, India, and the USA. The app and services are available in native English. Select services are available in Spanish and in certain languages of India.

Where Wysa decides the purpose of personal data processing, we will be the “data controller or data fiduciary”. Where we perform personal data processing at the direction of your Institution, we will be “data processors”.

If you have any questions, comments, complaints, or requests about our app and services, you can email us at [email protected].


2. What Information We Collect and Use

Depending on how you interact with us, we may collect minimal personal data that you're suggesting identify you. Notably personal data does not include publicly available information from or anonymised or aggregated information.

When you use our app and services.

When you use the app and services, we collect the following information. You control the information you share with us. We design our app to collect as little personal data as possible to keep your data safe and protect your privacy. This means there is less risk of your information being misused. When you share information with us, we are responsible for taking care of it.

Information provided by you.

  • Information about you. This includes things like your nickname, age-range, gender, pronouns, or identifiers you may voluntarily reveal about yourself. Contact information shared with Wysa Coach or Wysa Medical Assistant or as required for your Institution.

  • Conversation data. This covers what you type in messages, your challenges, preferences, feelings, moods, thoughts, task lists, and safety information. It also includes answers to surveys or questionnaires from us or your Institution, and how you respond to the tools and exercises that we offer. This includes everything you type in messages or say in voice or video calls with your Wysa Coach or Wysa Medical Assistant.

  • Correspondence data. If you email us, you might share personal data like your name, email address, home address, the company you are part of, your job title, and what you talk about in the message.

  • Feedback data. When we ask for your thoughts on our app and services, we gather your contact info and some basic details about you.

Information collected via automated means or by third parties.

  • Information sharing with your Institution. Sometimes, your Institutions or their appointed representatives might share or ask you to share your personal data with the app, like your contact details, so we can offer you our services. Where required by your Institution, and without affecting your rights, We may also share your usage and safety data with them.

  • App event data. We collect information about what you do in the app, like where you tap, what actions you take, your settings, notifications you get, and the screens you visit.

  • Device data. When you install the app, we get an ID for your device from the Google Play Store. We also collect information about your device, like the type of phone, its time zone, and its operating system. A service provider that helps us deliver content might also get your IP address to provide our services.

  • Cookie Information. We and our third-party providers collect information about your app use via cookies or similar technologies. We use mandatory or necessary cookies to provide our services.

When you use the Digital Front Door (e-triage) Service

The service helps your Institution guide you and your dependents to the right care and support. The following additional information gets used.

  • Information from your Institution.. You can use the service by logging in through your Institution’s Single Sign-On (SSO) web page. This means you can use your usual Institution login details to access the e-triage service. The first time you use the e-triage service, it will take you to your Institution's login page to verify your identity. Wysa does not collect and use your personal login details. Instead, Wysa gets a unique, encrypted code to create a random identifier for you.

  • Information about you. This may include but not limited to pronouns, country, service group.

When you use the AI Coach over WhatsApp.

Where, you directly use the AI Coach on WhatsApp, the focus is on helping you sleep better. The service does not give medical advice and always suggests seeing a doctor if needed. Wysa will not use your WhatsApp messages to send you marketing material. We do collect and use the additional information to provide you with our service.

  • Information about you. This may include but not limited to your mobile number, whatsapp profile name, city, interests, language.

Where your Institution provides access to the AI Coach on WhatsApp, they do not give us any of your personal information. They only share a unique identifier to help us connect with your Institution systems and offer our AI Coach service to you. This unique identifier cannot be used to identify you.

When you use the Wysa Medical Assistant Service.

When you use this service, you or your healthcare provider may additionally share protected health information with our app and with our Wysa Medical Assistants. These may include a patient referral form that contains your name, your current or past medication details, your clinical assessments and evaluation details. We will process this information on behalf of your Institution to provide healthcare service.

When you participate in a Wysa research study.

You can choose to sign up and join any of our or our research partner run studies. When you volunteer, we will collect some information from you. These include:

  • Information about you. . This may include but not limited to your contact details, country, gender, socio-economic details, age-range.

  • Health and Wellness data. This may include but not limited to ethnicity, alcohol/substance use concerns, use of medication, any mental disorder diagnosis or treatment, about hallucination, validated assessment responses.

When you visit our website or social media accounts or our web pages.

When you visit our website or web pages or just reach out to us for business purposes, we will collect the following information from you.

  • Correspondence data:. If you contact us, you might share personal data like your name, email address, home address, the company you are part of, your job title, business contact details and what you talk about in the message.

  • Cookie Information. We and our third-party providers collect information about your website use via cookies or similar technologies. Information could include but not limited to browser type, browser language, operating System, language settings, web page views and the link clicks, campaign clicks, IP address.

You can follow us on Instagram through the Wysa app settings. If you do not have an Instagram account, you can create one and follow us at @wysa_buddy. Your Instagram account will not be linked to your Wysa app account. We will know your personal information when you interact with us on our social media channels.

When you use the Wysa+ Service

Wysa+ provides an improved experience of the AI Coach service. It allows us to provide you with high-quality, and safe responses. Wysa+ uses third-party Generative AI and our own AI to chat with you. This helps the AI Coach talk about varied conversations and provide responses that are more suited to you. Where provided, Wysa+ allows you to chat in native English and specific Indian languages. Your conversation data is processed and part of the input to the Gen AI to provide this service. The input to and the output from the Gen AI passes through our safety guardrails and quality checks before we use it. Our clinical staff check the appropriateness of the Gen AI response at frequent intervals to make sure they are safe, and work well.

Generated Insights within Weekly Report:
Where you use weekly reports, we use third-party Gen AI to create generated insights. These reports give you personalized and useful information based on how you use the app. This can help you learn more about yourself and improve your mental health and well-being.

We share only derived and anonymous data with the Gen AI. The data we use each week comes from the information you provide and your choices while using the app. Here is what we collect each week:

  • Mood Description: This is taken from the smiley face you choose at the start of a session. It tells us if you are feeling not great, mostly low, somewhere in the middle, pretty good, or in high spirits.

  • Topics and feelings: These are keywords from your conversations with the AI Coach at the beginning of a session. For example, feelings could be sad, calm, confused, happy, numb, confident. Topics could be work or education.

  • Tools Used: This is the list of Wysa tools you used during your time on the app.

Important Note: We do not share any of your personal details, including device identifiers with the third-party service provider.

When you participate in online group well-being sessions.

Where required by your Institution, and without affecting your rights, We may also share your usage and safety data with them.

We may collect limited personal information such as your name and contact details, When you participate in group wellness sessions or webinars conducted by our Wysa Coach or Wysa staff.

When you participate in our campaigns or promotions or marketing events.

Any promotions, campaigns, or surveys you participate in will not be connected to your app account. Instead, this information will be stored securely in our Google Workspace or marketing tool accounts. We may collect and process the following information as part of these promotions.

  • Promotion event data: If you participate in our promotional activities, we may collect your name and contact details.

We may put ads online to see how many people are interested in our service or to promote it. We use only trusted ad managers. We do not collect any personal information when you see or click on our ads.

When you apply for a role at Wysa

We may process personal information you may provide us when you apply for an open position or attend our hiring interviews.

  • Recruitment data: This may include but not limited to your name, contact details, resume, references, credentials, transcripts, government provided identification, compensation information, race or ethnic origin, opinions and beliefs, physical or mental health or condition, sexual orientation.

Sources of personal data

We get your personal data either from you or your Institution, or service providers your Institution asks us to work with.


3. How We Use Your Information

Legal grounds

We need to follow data protection laws that make sure we look after your personal data properly. Here is how and why we might use it:

  1. Consent: Sometimes, we ask you if it is okay to use your personal data. You can always change your mind later if you decide you do not want us to use it anymore by writing to us

  2. Contract Performance: When you use our app or services, we might need some of your personal data to provide our services and make sure everything works properly.

  3. Legitimate Interests: We or someone we trust, might use your personal data to keep our services safe from fraud or security problems. We might also use it to make our services better.

  4. Legal Obligation: Sometimes, we need to use your personal data to follow the law or to protect our company and the people who provide the services.

Sometimes, we need to use sensitive data that you share, like how you feel, your mood, or other things about your emotional health. We will only do this if we follow the law and have a good reason, such as:

  1. Reasons for substantial public interest: Helping you with advice or support like counselling, or keeping you safe while you use our app and services.

  2. Health Care: Acting on behalf of your Institution to provide healthcare and redirect you to care resources.

Uses of your Information

We might use the information you give us on our app and services for these reasons.

  1. Information about you
    1. To provide and manage app and services: Here is how we use your information:

      1. To recognize which institution you are part of.

      2. To recognize whether you are a new or existing user to the app and service.

      3. When needed, we will ask for your permission to turn on your device's microphone and camera.

      4. We collect, move, save, and use your provided information to make our services work.

      5. We set up and keep track of your chats and use of our services.

      6. We let you change your nickname.

      7. Where needed, we will connect with your Institution's approved systems to handle your information.

      8. If your Institution offers the Wysa Coach service, we will connect you with a human mental health and well-being professional.

      9. If your Institution offers the Wysa Medical Assistant service, we will connect you with a human healthcare professional.

      10. If there is an emergency, Wysa Coach or Wysa Medical Assistant can call you or someone you trust.

      11. We keep a record of any permissions you give us.

      12. We let you know if we change our rules or privacy notice in the app.

      Legal grounds: contract performance, legitimate interests and consent.
  2. Use of Conversation data
    1. To provide and manage app and services: We do the following with your information:

      1. We come up with ideas and create AI programs, stories, and ways to talk for our AI Coach.

      2. The AI coach translates your preferred language to English and the other way around. This helps us understand each other and keep chatting with the AI Coach.

      3. The AI coach remembers the text messages you send and choices you make while using the app.

      4. The AI coach figures out if you are feeling happy, sad, or have any problems or questions. This helps us chat with you safely and give you required resources.

      5. The AI coach makes sure it understands you so that the conversations make sense.

      6. The apps show you safe tools and techniques that can help you.

      7. We make sure any personal details you accidentally share in your messages are removed and cannot be traced back to you.

      8. The AI coach looks for any medical or emergency words in your messages to help keep you safe.

      9. If the AI coach detects something that seems like an emergency, we may inform your Institution.

      10. We might use some anonymous chats to help our AI learn better.

      Legal basis: contract performance, legitimate interests, and consent. Use of appropriate additional conditions for any sensitive data.
    2. To perform well-being assessments: We do the following with your responses:

      1. The AI coach will ask you about how you feel and your mental well-being from time to time.

      2. The AI coach recognises if you inform any emergencies and may let your Institution know to provide support.

      3. The AI coach guides you to helpful hotlines and support resources if you need them.

      4. The AI coach recommends tools, tips, and resources to help you to manage your mood and improve your wellbeing.

      Legal basis: contract performance, legitimate interests. Use of appropriate additional conditions for any sensitive data.
    3. To Provide Wysa Coach services:We do the following with your information:

      1. You can send text messages and have video or audio calls with your Wysa Coach.

      2. The service gives you information and resources shared by your Wysa Coach.

      3. The service shares your AI Coach conversation data with your Wysa Coach to help with your care. You can stop this sharing anytime from the app settings.

      4. Some of the messages you send to your Wysa Coach are checked for quality. This helps make the service better and safer.

      Legal basis: contract performance, legitimate interests and consent. Use of appropriate additional conditions for any sensitive data.
    4. To provide in-app notifications and reminders: We will send you alerts if you choose to set reminders and notifications. We will send appropriate Wysa Coach session reminders.

      Legal basis: consent.
    5. For research, analytics, and compliance reporting: We might remove details that show who you are so that no one can tell the information is about you. We will use this changed information to check how well our app is working and to see if it is safe and useful. Sometimes, we also share this information with regulators to make sure we are following the laws.

      Legal basis: legitimate interests, legal obligations.
  3. Use of Correspondence data
    1. To communicate effectively with you:We do the following with your responses:

      1. We answer your questions, requests, complaints, and other feedback.

      2. We fix any problems with our services.

      3. We send you important service updates.

      4. We keep track of our conversations with you to make sure we are doing a good job and following the rules, and also to help train our team.

      Legal basis: contract performance, legitimate interests.
  4. Use of Feedbacks
    1. To improve our app and services: We do the following with your information:

      1. To invite you to join activities like sharing your thoughts about our product, or helping us test it.
      2. To understand your feedback so we can make our product and services safer and better.
      3. To use your personal details to make sure everyone has a fair chance to join in and that we test our product with the right groups of people.
      Legal basis: consent and legitimate interest.
  5. Regarding Information sharing with your Institution
    1. To provide and manage app and services: We do the following for your Institution:

      1. We may send you links or allow you to use codes so you can use the App.
      2. The apps may check to make sure you are part of your Institution.
      3. We share required reports and statistics with your Institution.
      Legal basis: contract performance. Use of appropriate additional conditions for any sensitive data.
  6. Use of app event and device data
    1. To understand app and service usage: We do the following with your information:

      1. We remove any identifiers from your information before using it to check how well our app works and to make sure your information is safe.
      2. We check and record the safety and performance of the app so we can report to your Institution or meet our legal requirements.
      3. We confirm sessions with your Wysa Coach.
      4. We share data that cannot identify you about your usage of the app with trusted analytics providers. This helps us make the app and their services better.
      5. We use the Information to create new services, technologies, and products.
      Legal basis: contract performance, legitimate interests, legal obligation. Use of appropriate additional conditions for any sensitive data.
    2. For marketing purposes: We do the following with your information:

      1. Sometimes, we create and run campaigns, send out surveys, and give updates about our programs.
      2. We also use anonymous data to understand how well we are doing, make marketing materials, and benchmark ourselves with others.
      Legal basis: legitimate interests, consent.
    3. To ensure availability and security: We do the following with your information:

      1. To make sure the content on our app works well.
      2. To keep your information safe from hackers and online threats.
      Legal basis: contract performance, legitimate interests.
    4. For fraud prevention: To prevent fraud or misuse of our services and to secure our systems.

      Legal basis: legitimate interests.
  7. Use of Cookie Information

    We need to use some necessary cookies to make sure our website and app works properly. Here is a simple guide to the kinds of cookies we might use:

    • Essential cookies. These are very important and are needed for the website and app to work. They help make sure everything runs smoothly, like when you chat on the app. These cookies do not collect any information about you. We handle these cookies ourselves.

    • Analytical cookies. We also use these cookies to see how well our website and app is doing. They help us understand what is working and what needs fixing. Sometimes, we use our own cookies for this, and sometimes we use Google Analytics. If you want to know what Google Analytics does with the information, you can visit their website. https://www.google.com/policies/privacy/partners/. You can opt out from Google’s cookies by downloading the Google Analytics Opt-out Browser Add-on Download Page. We do not use special Google tools to show you ads or test features on the website and the app. We do not use Google signals, which means we do not collect information about you or what you like.

    "Do Not Track" (DNT) is something you can turn on in your web browser to keep your online activities more private. However, even if you turn DNT on, we do not collect those signals today.

    Legal basis: legitimate interests.

Additional processing for Digital Front Door (e-triage) Service

  1. To process Institution provided data: We do the following

    1. Where applicable, to redirect you to your Institution’s SSO web page when you access the app.
    2. Collect, store and use the Institution provided identifier to provide access to the app and service.
    Legal basis: contract performance and as defined by your Institution.

    If you have any questions about your use of SSO please contact your Institution directly.

  2. To process your provided data: We do the following;

    1. Direct you to approved support resources based on your provided information, the language you prefer, the kind of support you need, and how you are feeling. These resources may include the Institution's Employee Assistance Program (EAP), the Wysa apps, and other services provided by your Institution.
    2. Share population-level and aggregated analytics on app and service engagement and use with your Institution. You can delete your data at any time by selecting the “Reset my data” option available within the app.
    Legal basis: contract performance and as defined by your Institution.

Additional processing for AI Coach over WhatsApp.

  1. To process your provided Information. We do the following

    • Recognize you as a new or existing user on whatsapp.
    • If needed, we will connect with your Institution's approved systems to handle your information.
    • Associate users to their provided data to provide uninterrupted services.
    • Use whatsapp profile name to personalize the communication with you.
    • Process data for addressing your data rights.
    • Respond to your inquiries, requests and feedback.
    • Troubleshoot any issues.
    Legal basis: contract performance and legitimate interests.

    Note: Your messages on WhatsApp Business are always end-to-end encrypted. According to WhatsApp's Privacy Policy, your messages are usually stored on your device(s) and not on WhatsApp's global servers. WhatsApp will keep your messages in encrypted form temporarily while they are being delivered. Once delivered, your messages are deleted from WhatsApp's global servers. You can protect your information on WhatsApp by using its privacy and security features. Find out more about WhatsApp’s end-to-end encryption and how it keeps business messages safe. WhatsApp allows you to send attachments or voice messages, but we do not need them to provide our service. Please avoid sharing such information with us.

Additional processing for Wysa Medical Assistant Service.

  1. To process Institution provided data: We do the following

    1. For Wysa Medical Assistant to contact you for healthcare and associated services within the app on behalf of your healthcare provider.
    2. To encourage and support you for medication adherence and for your care.
    3. To summarize and record health notes.
    4. To assist you with appropriate support resources and guidance.
    5. To share your case notes and information with your healthcare provider.
    Legal basis: contract performance and as defined by your Institution.

Additional Processing When you use the Wysa+ service

  1. Use of Conversation data

    1. To provide the Wysa+ Service: We do the following with your information:

      1. We share your relevant conversation messages to Gen AI (“Input”) for classification purposes or to receive controlled Gen AI responses.
      2. We design prompts to guide Gen AI to respond appropriately to the Input. The prompts include your message, summaries of your chats over a period and our validated instructions.
      3. Detect personal identifiers that you might have shared by mistake. If there are any, the AI coach will ask you to change your conversation message before sending it to Gen AI.
      4. We have safety guardrails to keep your chats with Gen AI safe. All Inputs go through these guardrails. If your message does not clear the guardrails, we do not send it to Gen AI. When Gen AI responds (“Output”), it also has to pass the safety rules. If it does not, we do not release the Output, instead providing a pre-defined safe response.
      Legal basis: contract performance, legitimate interests.
    2. To provide the Generated Insights within Weekly Report: We do the following with your information:

      1. Find topics and feelings through Wysa’s programs.
      2. Derive mood values from your choices during check-ins.
      3. Record how you use Wysa’s tools.
      4. Prepare an anonymous dataset.
      5. Share this anonymous dataset with the third-party service provider.
      6. Get and store the output received from Gen AI.
      7. Ensure everything is safe, private, and secure through proper precautions.
      8. Create useful insights from the results and add them to the weekly report.
      9. Talk with you, answer your questions, and provide help.
      10. Follow the law and protect your rights and interests.
      Legal basis: contract performance, legitimate interests. Use of appropriate additional conditions for any sensitive data.

Additional processing during participation in research studies.

  1. To process the information shared by you during participation. We do the following

    1. Inform about the study purposes.
    2. Understand your eligibility for the study.
    3. Manage your joining process.
    4. Send study related information and reminders.
    5. Contact you during the study for research purposes and respond to requests.
    6. Seek your feedback and clarify any questions.
    7. Perform analysis using the information provided.
    Legal basis: your consent and legitimate interests.

    Note: You can stop participating in the research at any time after it starts. You can do this by changing the settings in the app or sending an email to [email protected] with the subject "opt out of Wysa Study". Once you opt out, we will delete your enrollment data within one year. However, the data you provided while using the app will be kept according to our data retention policy, which you can read about here. Your study data will always be kept safe. You can learn more about how we protect your data here.

Additional processing when you visit our website or social media accounts or our web pages.

  1. To process your correspondence data: We do the following

    1. We collect, store, and use business data when you contact us.
    2. We respond and provide support for your questions.
    3. We talk to customers to find new leads, help our business grow, manage accounts, or for marketing purposes.
    4. Monitor, enforce and comply with unsolicited communication laws prior to any marketing and business development reach outs.
    Legal basis: your consent and legitimate interests.
  2. To process cookie information during your visit. To find out how we manage cookie data, please look at Use of Cookie Information section.

Additional processing during online group well-being sessions.

  1. To process your provided information: We do the following

    1. We collect, store and use your information to enroll and connect you to the well-being sessions.
    2. Contact you regarding the session and future sessions.
    3. Send session related materials and resources.
    Legal basis: your consent, legitimate interests and as defined by your Institution.

Additional processing during campaigns or promotions or marketing events.

  1. To process the promotion event data: We do the following

    1. Sign you up and get you started on the promotion or campaign.
    2. Contact you about campaigns and promotions.
    3. Send you information about promotions, newsletters, webinar invites, and reminders.
    4. Make sure we follow the rules about not sending unwanted messages before we contact you for marketing or business reasons.
    Legal basis: your consent, legitimate interests and as defined by your Institution.

Note: If you want to leave the promotion or campaign, you can email us at [email protected]. We will reply within 3 business days. Your information will stay private.

We use Meta Ads Manager to make ads about our service, to send these ads, and to see how well they are doing. We also group users together for anonymous cohort analysis. We use Google Analytics to see how much people use this service, but no personal data is collected or shared with them.

Additional processing when you apply for a role at Wysa

  1. To process recruitment data: We do the following

    1. Gather, save, and organize recruitment data from external recruitment sources.
    2. Review your application.
    3. Make a job offer.
    4. Sign a work contract with you.
    5. Run background and reference checks.
    6. Inform you of your application status.
    7. Consider you for other job opportunities.
    8. Make our hiring process better.
    Legal basis: your consent and legitimate interest.

We do not share or sell your information, messages, or how you use our apps to advertisers or companies that buy data.

Processing for Legitimate Interests

We may need to use your personal information for important reasons. Before doing this, we will always protect your rights and privacy. Here are the reasons we might use your data:

  1. To follow our agreements with your school or Institution.

  2. If the law requires us to use or share it.

  3. For court cases or legal orders.

  4. For law enforcement or national security needs.

  5. To help investigate or stop illegal activities.

  6. To freeze data for legal reasons so that it cannot be changed or deleted.

  7. To report public health information.

  8. To prevent serious risks to health or safety.

  9. To do basic research and understand how people use our services.

  10. To communicate with you about using our app and services.

  11. To fix and protect the app’s security and operations.

  12. To stop fraud or misuse of our service.

  13. To keep your data secure and private.

  14. To make sure the app and services work well and are easy to use.

  15. To protect your fundamental rights, and safety.

  16. To use anonymous data for benchmarking and marketing.

  17. To create new services, technologies, and products.

  18. To answer your questions and requests.


4. How We Protect Your Information

Where is your information stored
The information we collect is saved and kept safe in our cloud servers managed by Amazon Web Services (AWS). Some of your information might be shared and stored with our third-party service providers to provide our services.

How long do we keep your information

When you use our app and Services including Institutional Services

When you send us text messages, any personal identifier you share is removed and saved in a way that cannot be undone. We keep this information only for as long as we need to follow the law or our Institutional contracts. If there is no specific time limit mentioned, we keep your information for up to 10 years from the last time you updated it. You can also choose to delete all your conversation data forever by using the 'reset my data' option in the app settings.

Your correspondence data

When you email us, we use the information you give to help you. We keep your emails safe in our Google Workspace account, and only certain staff can look at them. We will keep your email for up to 10 years from the last time you contacted us.

When you use Wysa+ service

We keep your personal and derived information in our and third-party service provider systems only for as long as needed to meet the purposes stated in our privacy policy or as required by law. Where available, we enable "no storage of data" controls with the service providers.

Information received from your Institution

We keep your information for the time your Institution has decided. After that time, we delete your information forever. Once you send us your information, we cannot change it. If you need to fix something or have any questions, please talk to your Institution.

When you join our research initiatives

You can stop participating in the research at any time after it starts. You can do this by using any of the suggested opt-out features or by sending an email to [email protected] with the subject "opt out of research study". Once you opt out, we will delete your study data within one year. However, the data you provided during research study will be kept according to our data retention policy. We will keep this information only for as long as we need. If there is no specific time limit mentioned, we keep your information for up to 10 years from the last time you updated it. After that, we delete your data from our system. Where required, we may retain one copy of your anonymised data for a longer duration for any future audit or verification purposes.

Data Security

We use physical, organizational, and technical safeguards to keep your information safe. Here are some ways we do that:

Protecting your privacy

  1. You do not need to register to use the app.
  2. Just give us a nickname so our chatbot knows what to call you.
  3. We use masked identifiers to keep your data and identity safe.
  4. No real people can listen to what you are talking about with the AI Coach.
  5. If you accidentally share personal data, we will make sure to remove it so no one can see it.
  6. As an app user, you can choose "reset my data" to delete your information.
  7. Before we use any personal data about you, we make sure it respects your rights.

Protecting your security

  1. We use strong encryption to protect your data when it is being sent or stored.
  2. Only authorised people can access your data. They have to use strong passwords and an additional access code.
  3. All our staff computers have extra security.
  4. We maintain contracts with companies we work with to keep your data safe.
  5. We carefully check the background of new staff before hiring them.
  6. We train our staff on how to handle your information securely.
  7. We have experts from outside our company check if we are following the rules every year.
  8. We regularly test our app and systems for any weaknesses.
  9. We fix any problems in our computer code to make sure it is safe.
  10. We often check to make sure we are following our safety plans and rules.

Additional safeguards when you use Wysa+ Services

  1. Every message sent to and from Gen AI is encrypted so no one else can read it.
  2. We check each message you send to make sure it does not have personal identifiers. This helps keep your private details safe from being shared with the Gen AI service provider.
  3. We always check what is sent and received from Gen AI to make sure it is safe and good to use.
  4. We also use safety rules to double-check and make sure everything is safe.
  5. We do not share your device data with Gen AI.
  6. Your conversation messages are never stored at the Gen AI.
  7. Your conversation messages are not used as training data by Gen AI.

Responsible use of Artificial Intelligence

At Wysa, we use artificial intelligence (AI) programs to understand what you type to us. These programs help us talk with you in a way that makes sense and guides you to helpful information. Our programs follow set rules and do not learn new things on their own. We make sure our AI chatbot is fair, safe, and treats your information with care. If you use the Wysa+ service, we use Generative AI technology to assist you. We have safety measures in place to keep our conversations secure and trustworthy. We also have good practices to monitor and check the use of AI at Wysa, making sure your rights are protected. Please contact us at [email protected] if you have any more questions about our use of AI.

While Wysa has put in place reasonable clinical safety and data protection controls, you understand and acknowledge that AI is a developing technology. The potential risks inherent to this technology may not be fully understood and fulsome safeguards may not be fully developed. Due to the nature of the technology, you may sometimes get incorrect responses that do not accurately reflect the action required.

We do our best to keep your personal data safe, but no method is perfect. We cannot promise complete security. You can help keep your data safe too. Please do not share personal identifiers where not asked. Please do not copy and share your chats with people you do not know.

Payment Data

We do not collect, keep, or store your credit card information. Third-party payment companies handle your card processing. We do not get any personal data from app stores after you buy something or from our third-party payment providers. However, we might note the name of the business for our internal purposes. Please read the payment gateway’s terms and privacy policy before you make a payment. We do receive and handle payment confirmations and subscription details. This is to help you with your subscription requests.

Third-Party Sites

The app might have links to other websites or resources. When you click on these links, remember that these other sites have their own rules about privacy. We do not control these other sites and we are not responsible for their privacy rules. It is a good idea to read their privacy rules before you share any personal data on those sites.

Children’s Privacy

The app is intended for anyone who is older than 13 years or where approved by your Institution, follow the age criteria and rules set by your Institution. If you are a child, please ask your parent or guardian to read this policy and the terms of service with you. Wysa does not take responsibility if someone lies about their age to use the app and services.

It is very important for us to protect children's privacy on the app. We do not knowingly collect personal data from children below 13 years of age. If you think we have any personal data of your child, please write to us. We will respond within one month after verifying the information. If we cannot identify the user correctly, we might not be able to address your request. However, if we find we have collected personal data from your child, we will deactivate their account and take steps towards removing relevant data.

We encourage parents and guardians to watch over their children's internet use. Tell your children not to give out personal information without your permission. You should not share your credit/debit card or other payment methods with your child to make in-app purchases.

Best Practices

We want to help you stay safe online. Here are some important tips to stay secure:

  • Always lock your mobile screen with a password. Make sure it is strong and do not share it with anyone. Never leave your device alone.
  • Always update your mobile’s operating system to the latest version.
  • Turn on remote access on your device so you can find and control it if it gets stolen.
  • Install anti-virus software to protect your device from viruses.
  • Be careful with emails. Do not open files, click on links, or download anything from sources you do not know.
  • Be smart about using Wi-Fi. Before sending personal or important data over a public Wi-Fi in places like a coffee shop or airport, check if the network is safe.


5. Who We Share Information With

Service Providers
We work with third party companies that help us run our app, fix any problems, and offer other important services. These companies might use your personal data to provide services for us. For a list of service providers please read here.

Legal
We sometimes need to use your personal data to follow the law. This might mean sharing your information with other people like insurance companies, courts, police, or other important organisations. We might also use your information to stop serious health or safety problems, for public health reports, and to keep information safe during legal situations so it is not changed. Also, we might share your information to help with finding out or stopping fraud or crime. We will make sure your rights and interests are protected.

Reorganization
In situations like when we might sell our business, join up with another company, reorganize, or are facing bankruptcy, we may need to share some of your personal data with others. These third parties will use your information to look at the business deal. After these changes happen, we might also share your information with the new company for the same purposes mentioned in this privacy notice. We will try to let you know by putting a notice on our website, telling your Institution, sending you a notification in the app, or updating this privacy notice.


6. Sharing Information Outside Your Country

Sometimes we need to share, store, and manage your information with our service providers. These service providers might be in countries where data protection is not as strong as it is here. We have agreements with our service provider that include data protection safeguards to keep your data safe.

We only share the necessary data between our Wysa offices to provide you with the best service. We use strong technology to keep your data safe.

If you have any questions about how we send your data to other countries, you can email us at [email protected].


7. Your Data Protection Rights

When you trigger “Reset my data” from app settings

The "Reset my Data" feature is found in the app settings of the app. If you use this feature, all your conversation information, including your ID, past chats, reminders, assessment answers, and settings will be deleted from our system. Once you reset, you cannot get back any of your old conversations and you will be treated like a new user. So, think carefully before using this feature.

Your Privacy Rights

What Can You Do About Your Data?

  • Ask Questions: You can ask us how we are using your personal data.
  • Get a Copy: You can ask for a copy of the personal data we have about you.
  • Fix It: If any personal data about you is wrong or missing, you can ask us to fix it.
  • Delete It: If we do not need your personal data anymore, you can ask us to delete it.
  • Pause It: While we look into any questions you have, you can ask us to stop using your data.
  • Change Your Mind: If you had said yes to something before, you can still say no later.
  • Send It Elsewhere: You can ask us to send your personal data to someone else electronically.
  • Object: You can tell us not to use your personal data for things we think are important.
  • No Marketing: If you do not want to get marketing emails, just click ‘unsubscribe’ in the emails.
  • Be fair: When you use our app, we will not treat you unfairly for using your rights.
  • No Sale: You can choose to stop your personal data from being sold or shared with others who might want to sell it.
  • Automated Decisions: Our service uses AI to help you. We do not use AI to know your identity. We always check with you before making key suggestions. We change our conversation anytime you inform us that the AI is not helping. We and our service providers might use AI to make automated decisions or automatically process information if we need to perform our services or to stop fraud, abuse or misuse of our services. By using our services, you consent to let us use AI for this purpose. We might change the automated approach we use in the future.

How to Exercise Your Rights

You do not usually have to pay anything to use your rights. Sometimes, we might need to check if it is really you asking. Contact us using the details at the top of this privacy notice. We will reply within one month if you ask us for something.

When We Might Say “No”
We might not be able to agree to your request if:

  • The law says we cannot.
  • It affects someone else’s privacy.
  • It could harm you, us, or someone else.
  • If we need to train data to ensure the reliability of our research studies.
  • The request is too much or does not make sense.


8. How To Complain

If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details at the top of this privacy policy. We will get back to you about your complaints within 3 working days. Some might take a bit longer to sort out. We will keep you updated until everything is fixed.

If you are still not happy with how things have been sorted out, you can send an email to our grievance officer at [email protected].


9. Supplementary Privacy Notices

Read supplementary privacy notice for USA states.


10. Changes To This Policy

If we change our Privacy Policy, we will let you know in the app. If you keep using the app after we tell you about the changes, it means you agree with them.


11. Change Log

v6.1.0 | March 27, 2025

  • The Wysa+ privacy policy notice has been discontinued and is now integrated into this main privacy policy.
  • Added handling data when you join research studies or initiatives.
  • Added retention of data provided when you join research initiatives.
  • Added information about limitations of our AI system.
  • Added that we may retain your data longer, if we need to retain data to ensure the reliability of our research studies.
  • Replace references to Chronic Care Management to Healthcare
  • Added “Generated Insights within Weekly Report” in the section When you use the Wysa+ Service.
  • Remove links and reference to Wysa+ Privacy Policy and Terms of Use.
  • Minor corrections, sentence reframing, handling omissions and correction of erroneous links.
  • Changes to “How to exercise your rights”.

v6.0.0 | Oct 1, 2024

Additions
  • Supplementary privacy notices for USA state residents
  • Data collection and processing for our whatsapp based service, voice-enabled services, multi-lingual services, Chronic Care Management services.
Updates
  • Overhaul of the Privacy Policy to make it more readable for ages 13 and above.
  • List of service providers

v5.6.0 | July 23, 2024

Additions
  • Added Wysa+ Generative AI in the list of Services governed by this privacy policy and the additional Wysa+ Generative AI Privacy Policy.
Updates
  • Changed the section “How do we use Generative AI technology?” to “Your use of Wysa+ Generative AI Services.” This section has also been changed to reflect about the service and to provide links to the additional Wysa+ Generative AI terms of use and privacy policy.

V5.6.0 / July 20, 2024

Additions
  • Added Wysa+ Generative AI in the list of Services governed by this privacy policy and the additional Wysa+ Generative AI Privacy Policy.
  • Data collection and processing for our whatsapp based service, voice-enabled services, multi-lingual services, Chronic Care Management services.
Updates
  • Overhaul of the Privacy Policy to make it more readable for ages 13 and above.
  • List of service providers
  • Overhaul of the Privacy Policy to make it more readable for ages 13 and above.

v5.5.0 | Dec 18, 2023

Additions
  • Included “Validated preventative guided programs” in Wysa’s list of Services for Institutional users.
  • Wysa emotional well-being professional service is included in Hindi and Spanish language Apps.
  • Use of 3rd party tools to detect and replace any inadvertent personal identifiers within your text messages for better privacy protection.
  • Details about user level data sharing with Institutional users and about processing health data as a business associate within What personal data do we process and handle as a Processor or Sub-processor?
  • New service provider Turn.io (as a Business Solution Provider for our whatsapp service)
  • New service provider private AI (to redact inadvertent personal identifiers in text messages)
  • New section that provides details on “How do we use Generative AI technology?”
  • Additional privacy and security messages from USA FTC and the Department of Health and Human Services (HHS) about how to protect your information when using digital technologies.
Updates
  • Updated data protection law definition to include India’s DPDP Act 2023
  • Capture pronouns as other information processed on behalf of Institutions
  • The list of Service Providers section to provide clarity on data type, purpose and storage involved in the data processing.
  • Moved the Cloud Service Provider details in the “How do we share your data with third parties?” to the list of Service Providers section.
  • Promotional event data and Business (B2B) data details within the “What data do we process after taking your Consent?” section.
  • Data protection rights to inform our obligation where we require to process rights on behalf of your Institution.

v5.4.0 | June 13, 2023

Additions
  • Wysa App is designed to offer general mental health advice and support and cannot offer condition specific advice for complex medical conditions
  • Data processing when user participates and consents to Wysa commissioned controlled and real-world online research studies. Data processing details provided in “What additional personal data do we process when you participate in the online controlled or real-world studies?”.
Updates
  • Lawful basis of processing has been updated to reflect the most appropriate that applies to the processing.
  • We also provide Hindi and Spanish version apps for users in certain geographies.
  • Event Data processing- to analyse app event data for improving product and service quality.
  • Made minor grammatical corrections.
  • In addition to CCPA also updated for CCPA related privacy requirements
  • Updated the Insights & Involvement data in “What data do we process after taking your Consent?”

v5.3.0 | May 5, 2023

Additions
  • Wysa does not take responsibility for any misrepresentation of age and use by the user.
  • Included Institution data processing in “What personal data do we process and how do we use it?”.
  • Processing of age-range to identify children entering the system and to safeguard in “What personal data do we process and how do we use it?”.
  • Added new processors in “Other Service Providers”
    1. Salesforce / Pardot
    2. Zendesk
    3. Iterable
    4. 6Sense
  • We may capture the Institution name for operational purposes from payment gateways.
  • A copy of user data might be retained in our backup for a definite period of time.
Updates
  • Clearly identify all Services governed by the Privacy policy.
  • Wysa email ID to [email protected].
  • Corrected for grammatical constructs and errors across all sections.
  • Reworded across all sections to ensure readability for younger audiences.
  • Safety Plan data processing in “What personal data do we process and how do we use it?”.
  • Provided additional information about our NLP/NLU algorithm in “How does the Artificial Intelligence chatbot work and is it safe to use?”.
  • Updated data retention section in “How long do we retain your data including personal data?”.
  • Additional information to cover for multilingual apps.
  • Removed two sections “What is Wysa App?” and “Who can use the service?” as already covered in TOS.
  • Kubit.ai has been discontinued as our data processor.

v5.2.0 | January 18, 2023

Additions
  • Added a new section on “What data do we process when you use the Wysa Digital Front Door Service?”
Updates
  • Fix for grammar in “What data do we process after taking your Consent?”

v5.1.0 | December 21, 2022

Updates
  • Included a para on Right to be Informed and deleted a redundant bullet “required to protect our rights and properties” in the “What are your data protection rights?” section.
  • Included Cookie Policy to the line “By using our Apps and services, you agree to the collection and use of information in accordance with this privacy policy and cookie policy”.

v5.0.0 | December 06, 2022

Additions
  • New section "What personal data do we process and handle as a Processor or Sub-processor?" to reflect data processing when Wysa is a data processor.
  • Add details around use of marketing tools in "How do we share your data with third parties?".
  • New additions, bullet 5 and 6, within "Processing of any of your personal data as per our Legitimate Interests".
  • Addition of business data processing within "What data do we process after taking your Consent?".
  • New section to organise details around "International transfer of personal data outside of the country you reside in or are currently located".
  • Include Hindi as a language in use within the app in select geographies.
  • Included details on retention of emergency contact information after the end of subscription in “How long do we retain your data including personal data?” Section.
Updates
  • Reorganisation and reframing of sections to provide clarity, grammatical correctness and improved alignment to our current intent and purposes.
  • Updates made to “Do Note” Section.
  • Our Coach or therapist services are provided by global human well-being professionals. Changes made to reflect this across the policy.
  • Updated paragraph on "Institution version of Wysa App".
  • Minor updates to the table within "What personal data do we process and how do we use it?".
  • Update on our use of ads in "What additional personal data do we process when you use our WhatsApp-based business service?".
  • Replace an archived AWS Security link with the latest, within "How do we share your data with third parties?".
  • Update, bullets 3, 4 and 14, within "Processing of any of your personal data as per our Legitimate Interests"
  • Updates to the row on processing of app usage data and promotion data in "What data do we process after taking your Consent?"
  • Updates made to "How do we secure your data?" section
  • Update to paragraphs of “Right of Access” and “Right in relation to automated decision-making and profiling” within "What is your data protection rights?"
  • Group the “withdraw consent”, “breach notification“ and “concerns and complaints” sections within a separate section "Other important information".
  • Additional information provided within "Do California residents have specific privacy rights?"

v4.1.1 | July 5, 2022

Additions
  • Addition of Wysa AI coach over WhatsApp to the list of services.
  • New section “What additional personal data do we process when you use the WhatsApp service?”
  • Addition of new sub-processor, Meta Ads Manager.
Updates
  • Updated Twilio services to include Business Service Provider service to integrate Wysa's AI coach with WhatsApp.
  • Minor grammatical corrections.

v4.1.0 | May 26, 2022

Additions
  • Include Cloudflare among our service providers
  • Include Web-based apps along with website cookies in “What data do we process after taking your Consent?”
  • Update to Disclosure to other third parties with details on reasonable steps
  • Separately call out “Processing as per our Legitimate Interests”
  • Added new definition for AI coach and Special Category data
Updates
  • Definitions: Service provider and Data Processor are interchangeable terms.
  • “What personal data do we process and how do we use it?” updates for clarity and appropriateness.
    1. Integrate wellness information as part of Conversation Data
    2. Conversation data by way of audio-video sessions separately outlined
    3. Included processing related to network data separately
    4. Carved out event data separately
  • Mention DPA with Standard Contractual Clauses (SCCs) with every service provider
  • Update the purpose for Google Workspace and 3rd party payment gateway providers for more clarity.
  • Remove [email protected] email ID
  • Update Privacy by Design measures
  • Updates to point on data stored in databases in the Important Notes section.
  • Update the Privacy by Design section
  • Update purpose of processing in “What personal data do we process and how do we use it” section
  • Updated the “How do we secure your data?” section for certifications and details
  • Clear messaging about Wysa human professional well-being service

v4.0.0 | November 10, 2021

Additions
  • Complete revamp to improve the readability of the Privacy Policy.
  • Include information about the Audio-Video Service provided by Coach or Therapist.
  • Introduction of AI Coach modules and tools for Spanish language users.
  • Included our other applications including Ascension Wysa app in scope of this policy. This Privacy Policy replaces the existing Ascension Wysa's privacy policy.

v3.3.1 | July 16, 2021

Removed
  • Review and remove Suicide helpline link from Important Notice.

v3.3.0 | July 01, 2021

Additions
  • Included our other applications including Sleep by Wysa App in scope of this policy. This Privacy Policy replaces the existing Sleep by Wysa's privacy policy. Updated Important notice for key information about Sleep by Wysa.
  • Add information on transfer of Your Data to regions other than Your resident country/state in the Important Notice section.
  • Added section on data processed from candidates applying to Wysa's open job positions.
  • Added processing of candidates information for current and future employment opportunities as our legitimate interest
  • Added processing of information when using Wysa's video-based service with the Well-being Coach or Therapist
  • Added FTC security and privacy guidance in What are some best practices to follow to keep your device secure?
  • Explicitly added Right to withdraw Consent
  • Provided details to our UK ICO registration
Updates
  • Mention about ISO 27001 (ISMS) and ISO 27701 (PIMS) certifications and adhering to GDPR 7 Principles
  • Minor updates in "What does this Privacy policy apply to?"
  • Renamed GSuite to Google Workspace
  • Mention of Wysa Well-being Coach or Wysa Therapist Services provided outside of the Wysa App for Institutional Users
  • Energy questionnaire included in "How do we handle your responses to screening assessments?"
  • More clarity about your data transmitted and stored
  • Payment gateway related updates in how do we handle your payment data?
  • Updated “Can children under 13 Use Wysa App?” with note of advice to parents and legal guardian.
Removed
  • FB analytics has been discontinued. Added use of 3rd party analytics provided by Kubit AI whose details have been provided in “How do We use any Third Party Analytics tools and softwares?”

v3.2.0 | Apr 16, 2021

Updates
  • Additional clarity on handling data where Wysa App is integrated with Your Institution system
  • Additional clarity on use of minimal and anonymous conversation messages for improving performance of Bot algorithms
  • Additional information around security controls and alignment to ISO 27001: 2013 and ISO 27701: 2019 global standards
  • Additional clarity on anonymized and minimal data shared with third parties
Removed
  • Video Call- based experimental Coach/therapist Service has been currently discontinued. Section “What do we process when You use the Video Call Service?” removed

v3.1.0 | Feb 10, 2021

Updates
  • Additional clarity on the retention of data;
  • Additional data processed from Institution users in section “What additional data do We collect from Institution Users?”

v3.0.0 | Feb 03, 2021


Overall
  • An overall review and necessary updates were made to align Privacy Policy to ISO/IEC 27001:2013 (Information Security Management System) and ISO/IEC 27701:2019 (Privacy Information Management System);
Additions
  • Included “For purposes of servicing You towards Wysa’s Gift Card program” as a Legitimate Interest basis;
  • Three new subsections added at the end of “What Data do We collect and how do We Use it?”

    1. What do we process when You use the Video Call Service? (experimental service for android users only)
    2. How do We handle Your data when used for Research purposes?
    3. What data do we process as part of Gift Card purchase?
Updates
  • Included details on use of branch.io and mailgun third party analytics software services;
  • UK GDPR mentioned as another regulation requirement for this Privacy Policy;
  • Additional items included in “Definition” Section;
  • Additional clarity on need for parental consent for those between 13 and 18 years in “Who can use the Service” Section;
  • Updated link to Wysa Cookie Policy in “Do we use Cookies?” Section;
  • Additional clarity on the retention of data
  • Additional clarity on “Do California residents have specific privacy rights?”
  • Additional clarity on “What are the controls for Do-Not-Track features?”
  • Additional clarity on changes to privacy policy
Removed
  • Section “Governing Law and Dispute Resolution” to align with EU GDPR laws