Seek within. Our Philosophy
Innate — operated by Lotus Audaz, Lda
Effective date: 28 April 2026
Last updated: 28 April 2026
Contact: hello@innate.love
At Innate we take your privacy seriously. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and what rights you have.
Data Controller
Lotus Audaz, Lda
Rua Cândido dos Reis 112, 8600-681 Lagos, Portugal
This policy applies to users of the Innate mobile application and covers our compliance with:
When you create a recording in Innate we collect:
If you sign in with Google: your Google email address, first name, and last name (we do not receive your Google password)
(GDPR and UK GDPR)
The article references below apply equally to both the EU GDPR and the UK GDPR, which share identical article numbering.
| Data Type | Legal Basis |
|---|---|
| Account information | Performance of contract (Art. 6(1)(b)) |
| Video recordings | Explicit consent (Art. 6(1)(a) + Art. 9(2)(a)) |
| Facial analysis (biometric) | Explicit consent (Art. 6(1)(a) + Art. 9(2)(a)) |
| Emotional health data | Explicit consent (Art. 6(1)(a) + Art. 9(2)(a)) |
| AI emotion analysis | Explicit consent (Art. 6(1)(a) + Art. 9(2)(a)) |
| Push notifications | Consent (Art. 6(1)(a)) |
| Security & error logging | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance | Legal obligation (Art. 6(1)(c)) |
You may withdraw any consent-based processing at any time (see Section 8). Withdrawal will not affect the lawfulness of processing carried out before withdrawal.
This section describes automated processing of special category data. Your explicit consent is required before this processing takes place.
When you record a video entry and consent to AI analysis, your recording is processed through the following pipeline:
You can disable AI processing at any time in your App settings. This will prevent future AI analysis but will not retroactively delete results already generated.
We do not sell your personal data. We share data with the following third-party processors only to the extent necessary to provide the Service:
| Third Party | Purpose | Data Shared | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting, storage, database, AI processing (Rekognition, Transcribe, Bedrock), email (SES), monitoring (CloudWatch) | All data | EU (Ireland, eu-west-1) |
| Sentry (Functional Software Inc.) | Crash reporting and error monitoring | Error logs, app state, limited user context | USA (SCCs / IDTAs apply) |
| Google LLC | Sign-in via Google OAuth | Email, name (if you use Google sign-in) | USA (SCCs / IDTAs apply) |
| Expo (Expo Inc.) | Push notifications | Device push token | USA (SCCs / IDTAs apply) |
All third-party processors are bound by data processing agreements and are required to process data only on our instructions.
Our primary infrastructure is hosted on AWS eu-west-1 (Ireland), within the European Economic Area (EEA).
Some third-party processors (Sentry, Google, Expo) are based in the United States. Where data is transferred outside the EEA or UK, we ensure appropriate safeguards are in place:
For EU users:
For UK users:
The UK has been granted an adequacy decision by the European Commission, meaning transfers of personal data from the EU to the UK are permitted without additional safeguards. Data stored on our EU-based infrastructure (AWS Ireland) is therefore accessible to UK users without restriction.
We retain your personal data only for as long as necessary. Full details are in our Data Retention Policy, summarised here:
| Data Category | Retention Period |
|---|---|
| Account information | Duration of account + 30 days post-deletion |
| Video recordings | Duration of account + 30 days post-deletion |
| AI emotion analysis results | Duration of account + 30 days post-deletion |
| Audio transcripts | Duration of account + 30 days post-deletion |
| Error logs (Sentry) | 90 days |
| Server logs (CloudWatch) | 1 year |
| Anonymised/aggregated analytics | Indefinitely (cannot be linked to you) |
(GDPR and UK GDPR)
If you are located in the EU/EEA or the United Kingdom, you have the following rights:
To exercise any right, contact us at hello@innate.love with the subject line "Data Rights Request". We will respond within 30 days.
You also have the right to lodge a complaint with your local supervisory authority:
(CCPA — California Residents)
If you are a California resident, you have the following rights under the CCPA/CPRA:
Categories of personal information collected (CCPA categories):
We do not sell personal information as defined under the CCPA.
To exercise your CCPA rights, contact us at hello@innate.love with the subject line "CCPA Privacy Request".
Innate is not intended for users under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has created an account, please contact us at hello@innate.love and we will delete the account and all associated data promptly.
We implement appropriate technical and organisational measures to protect your personal data, including:
Despite these measures, no system is completely secure. If you discover a security vulnerability, please disclose it responsibly to hello@innate.love.
We may update this Privacy Policy from time to time. We will notify you of material changes via in-app notification or email at least 14 days before they take effect. The "Last updated" date at the top of this document indicates when the most recent changes were made.
Data Controller
Lotus Audaz, Lda
Rua Cândido dos Reis 112
8600-681 Lagos, Portugal
EU Supervisory Authority
CNPD
Comissão Nacional de Proteção de Dados
Rua de São Bento, 148-3°, 1200-821 Lisboa
UK Supervisory Authority
ICO
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF