Listen in Deep
This policy covers everything I do with personal information, across all of my work — including one-to-one therapy and coaching.
My Terms of Service are narrower: they're the contract for the app, the Academy and collaborative tools only, because one-to-one work is governed by its own separate client agreement. Different documents, different jobs. If the two ever seem to disagree about personal data, this policy is the one that governs it.
Your privacy matters, and in this work it matters more than most. This policy explains how I, Gareth Willett, collect, use, store and protect your personal information across everything I offer: my websites, one-to-one therapy and coaching, the Academy, and the Listen in Deep app. It also explains your rights under UK data protection law.
I've tried to write it as something you could actually read rather than something you'd scroll past. Where I've had to be technical, I've explained why. If anything here is unclear, email me and I'll explain it properly.
I'm Gareth Willett, a sole trader trading as Listen in Deep. I'm the data controller for everything described here.
Address: 32 St Aidan's Road, London SE22 0RP
Email: [email protected]
ICO registration: ZB948922
I'm an accredited member of the British Association for Behavioural and Cognitive Psychotherapies (BABCP), membership number 160104, and a self-discovery coach, trained through a programme aligned with ICF's core competencies. I'm not required to appoint a Data Protection Officer, so questions about your data come to me directly.
I work as an independent practitioner offering psychotherapy, coaching, a membership platform, and a self-guided self-discovery app.
Each collects somewhat different information, set out below. The app in particular works differently from everything else, which is why it gets its own section.
If I've missed anything, the export in Settings is the honest answer. It's deliberately built to sweep up everything of yours the app holds — your writing, your conversations, your progress — rather than working from a list I have to remember to update, so a new feature can't quietly escape it and neither can a gap in this policy. (It doesn't include settings like dark mode or your chosen voice; those live on the device and aren't about you.) Export your data at any time and you'll see exactly what's there.
About voice input. When you use the microphone, your browser handles the speech recognition, not me — I never receive or store the audio. But most browsers do this by sending the audio to their own provider; Chrome, for example, sends it to Google. That happens between you and your browser maker, under their privacy policy, outside my systems entirely. If you'd rather it didn't happen at all, type instead.
This section is specific to the app, because it works differently from the rest of my services.
By default, and always on the free tier, everything the app holds about you — your journal entries, your conversations with the Inner Guide, your insights, your embodiments, your Story So Far, your practice records and your progress — is stored locally on your own device — not on a central server. I don't have access to this content, and it isn't backed up or synced anywhere unless you choose otherwise. If you clear your browser data, switch devices, or uninstall the app while using local storage only, this content is gone unless you've exported it yourself.
What this means if you stay local-only: the responsibility for keeping your content safe sits with you. I can't recover it if your device is lost, damaged, reset, or the app is uninstalled without a backup — I never had a copy to restore from. You can export a full backup to a file at any time from Settings and re-import it on a new device, and I'd recommend doing so before switching devices, or periodically if your content matters to you. This isn't meant to alarm you. It's the honest trade-off of a service that never holds your data unless you ask it to.
That's the complete list as far as your content goes. Everything else stays put — including the Journey Card, the keepsake image summarising your 90 days. It's assembled entirely on your device from content that's already there. Nothing is sent anywhere to build it, even though you can share the finished image if you want to. The one thing that isn't content but does travel is your device ID, which accompanies requests to the parts of the app that have fair-use limits — Section 4 sets out what it is and how long it lasts.
Cloud storage is switched off by default, including for Plus subscribers. Subscribing to Plus doesn't switch it on and doesn't imply you've agreed to it. You turn it on yourself, in Settings, whenever you like — and you can turn it off again the same way, in the same number of taps.
Journal entries, insights, embodiments, your Story So Far and conversations with the Inner Guide can reveal how you're feeling, what you're struggling with, and matters relating to your mental health. UK GDPR calls this special category data and sets a higher bar for handling it — rightly. So for cloud storage I rely on two things at once:
This is the only place in this policy where I rely on both. Accepting this privacy policy in general does not amount to that consent, and I don't treat it as if it does.
When you turn cloud storage on, the app generates a Secret Key on your own device — a long random code that only you ever hold. Everything the app holds — your journal entries, your conversations with the Inner Guide, your insights, your embodiments and your progress — is encrypted with it here, on your device, before anything is sent. What reaches my servers is a block of ciphertext.
I can't read it. Supabase can't read it. There's no master key, no administrative override and no support process that can open it, because none of those things exists to build. That isn't a promise about my intentions — it's a fact about how it's made.
The Secret Key is shown to you once, when you switch cloud storage on. It's never sent to my servers, so I have no copy of it and no way to get one. It's designed to be saved in a password manager rather than memorised.
Signing in and decrypting are two different things. Someone who got into your email could sign in to your account — but without your Secret Key, they'd find nothing readable in the cloud copy.
There's no recovery path, and that's deliberate. A recovery path is a second way in, and a second way in is a way in for someone who isn't you.
What losing it actually costs you is smaller than it sounds. Your journal is on your device, untouched, exactly as it was — you haven't lost your writing, you've lost the backup. You can turn cloud storage on again with a new Secret Key and start a fresh encrypted copy whenever you like. When you do, the previous copy, which nobody can now read, is deleted.
To run your account at all, a few things sit beside your encrypted content in readable form: your email address; whether cloud storage is switched on; when you switched it on, and which version of this policy you were shown at the time; whether your Plus access has lapsed, and when; the date your cloud copy is due to be deleted, where one is set; and when your backup was last updated. That last one means I can see that you saved something on a Tuesday evening — not a single word of what you wrote, but the timing itself. I'd rather name that than let "end-to-end encrypted" imply I can see nothing whatsoever.
Your device ID isn't one of them. Your cloud copy is filed against your email address and nothing else, so there's no record here of which device it came from.
What it does: it protects you against losing what's on your device right now. If your phone is lost or damaged beyond use, if you reinstall, or if you move to a new device — your journal comes back.
What it doesn't do: it doesn't keep anything for longer than your device does. Cloud storage mirrors what's on your device at each sync rather than keeping a separate archive, so when your Inner Guide conversations clear at 120 days, the next sync removes them from the cloud copy too. It isn't permanent history and it isn't unlimited history. It's a safety net under the history you already have.
Cloud copies are held with Supabase, a database and cloud-storage provider, on a project hosted in London, United Kingdom, on Supabase's Pro plan. I use the Pro plan specifically because, unlike the free plan, it's never automatically paused for inactivity. Supabase Inc. is a US company, so although your data sits in the UK, some support access may come from outside it — Section 14 sets out the safeguards I have in place for that.
You can withdraw your consent at any time, from Settings, as easily as you gave it. There are two buttons there, and they do different things:
Withdrawing consent doesn't make the earlier storage unlawful — it was lawful while you consented to it — but it stops it going forward, and it gets your data deleted on whichever timetable you chose.
The law requires me to be able to show that you consented, so when you turn cloud storage on I record the date and time, and which version of this wording you were shown. That's all — it's a record about the consent, not about what you wrote.
There's a real difference between the app and my other work, and it's worth being direct about it.
In therapy or coaching, I'm a person in the room with you. I keep records, I notice things, and I carry professional duties — including, in rare and serious circumstances, a duty to break confidentiality if I believe someone is at risk of significant harm. If that ever became necessary I would tell you, wherever it was safe to do so.
The app doesn't work like that. On the free tier, and on Plus without cloud storage, nothing you write in the app reaches me at all. With cloud storage on, what reaches me is encrypted with a key only you hold, so I couldn't read it even if I wanted to. There's no review, no alerting, no monitoring, and no dashboard where your entries appear. Nobody is checking on you through the app.
Which means: I cannot act on anything you write in the app. If you write about being in danger, or about someone else being in danger, no one will see it and no one will respond. That's a deliberate design choice — your journal is genuinely private — but it has this consequence, and you should know it before you rely on it.
One exception, and it's entirely your choice. If we're working together 1:1, I might suggest during a session that something you've written in the app could be useful for our work — and if you agree, you can forward it to me by email yourself, using the share option in the app. That's the only way anything from the app reaches me, and it only happens because you've chosen to send it. Once you do, I treat it as part of our session work, kept under the same retention as your other clinical or coaching records (Section 11).
If you need someone to know, please tell a person:
Two small things do reach my side, and I'd rather name them than let the claim sound broader than it is. My server counts how many Inner Guide messages a device has sent in the current hour, so the fair-use limit can be applied — it sees that a request happened, not what was in it. And my hosting provider keeps ordinary technical logs of those requests, including IP address and time. Neither contains a word you wrote. "Nothing reaches me" is a claim about your content, and it holds.
One further exception: your messages to the Inner Guide pass through Anthropic to generate a reply. Anthropic operates its own automated safety systems on what passes through its service, under its own policies. That isn't me reading your conversation, and it isn't a safety net — but it isn't nothing either, and you should know it happens.
I never sell or rent your personal information to anyone, and I never will.
Under UK GDPR, the lawful bases I rely on are:
For clinical records, I also rely on Article 9(2)(h) — processing necessary for the provision of health care and treatment by a professional bound by a duty of confidentiality.
You can withdraw consent at any time by contacting me, or — for app notifications, microphone access and cloud storage — through your device, browser or app settings.
I take appropriate technical and organisational measures to keep your information secure — including encryption in transit and at rest, access controls, and other appropriate safeguards on the systems that hold personal data. No system can be completely secure, and I won't pretend otherwise, but I take this seriously and I'll tell you promptly if something goes wrong.
Where a breach is likely to result in a risk to your rights and freedoms, I'll report it to the ICO within 72 hours of becoming aware of it, and tell you directly where the risk is high.
Clinical notes and contact details for 1:1 clients are held together on uk.Tacklit.com, operated by Tacklit UK Ltd, a UK-based encrypted platform built for healthcare professionals. Tacklit keeps UK/EU client data hosted and processed regionally, separate from its Australian infrastructure.
Academy and membership data is held on my membership platform, provided by Content Creator Machine, built on the GoHighLevel platform.
App content is stored on your own device, as explained in Section 6. Sign-in is handled through encrypted, time-limited tokens.
Shared Trello boards are stored on Trello's own platform, under access you've granted me and can revoke at any time.
| What | How long | Why |
|---|---|---|
| Clinical records (1:1 therapy) | 7 years after your last session | Professional standards and insurance requirements |
| Coaching notes | 7 years after our work ends | The same period as clinical records. My coaching and my psychotherapy overlap, and people often move between the two, so holding them to different standards wouldn't reflect the work |
| App journal entries (Reflections and Dream Journal) | Until you delete them — no automatic clearing | They're yours and they're on your device |
| Inner Guide conversations | Cleared from the device after 120 days, on both Free and Plus | Keeps stored history proportionate |
| Everything else the app stores — insights, embodiments, daily intentions, session summaries, your Story So Far, end-of-journey reflections, breathwork and meditation records, progress | Until you delete it, or until you delete your account | It's yours and it's on your device |
| App cloud copy (Plus, opt-in) | Mirrors the device, so the same windows apply. The whole copy is deleted 30 days after cloud storage is switched off or Plus access ends — Section 6 | A grace period against accidental loss |
| App account record | Until you delete your account, then 30 days | To let you sign in |
| Signup and consent records | As long as your account exists, then 6 years | Proof that you agreed, if it's ever questioned. Six years is the time limit for bringing a contract claim in England and Wales |
| Fair-use counters (one per device ID, per rate-limited part of the app) | Kept only to apply the limit, and overwritten the next time that device makes a request. Nothing actively deletes the entry, so it persists indefinitely if the device never comes back | To apply the 80-messages-per-hour limit and the other fair-use limits |
| Server logs | My hosting provider's standard period — a short one | Security and troubleshooting |
| Academy membership and course access | While you're a member, then 2 years | So you can rejoin without losing your progress |
| Community posts | Until you delete them or your account | They're part of the conversation |
| Newsletter and marketing contacts | Until you unsubscribe, then the unsubscribe record is kept 12 months; removed automatically after 3 years with nothing opened, whichever happens first | So an unsubscribe stays honoured, and so I'm not still emailing people who've gone quiet |
| Payment and tax records | 6 years from the end of the tax year | Required by HMRC |
| Testimonials | Until you ask me to take it down | You gave it to be shared, and you can change your mind |
| Enquiries that don't become work | 12 months | In case you come back |
| Shared Trello boards | Until you revoke my access or delete the board | It's your board |
Conversations sent to Anthropic and text sent to Cartesia are retained by them under their own terms — briefly, for safety and abuse monitoring — and are not used to train their models. See Section 13.
Where a period above ends, I delete or securely destroy the information unless I'm legally required to keep it longer.
My websites and the Academy run on Content Creator Machine, built on the GoHighLevel platform. It automatically logs standard technical details — IP address, browser type, and how many times a page is visited — for security and basic traffic statistics. This isn't a tracking cookie and doesn't follow you elsewhere; it's routine server-side logging, the kind almost every website keeps.
Content Creator Machine also sets one cookie — msgsndr_id — when a page loads. It links your visit to my CRM, so that something like a form submission can be matched to the right contact record. It isn't an advertising cookie and doesn't track you across other websites.
It isn't necessary for the site to work, and under UK law it should only be set once you've agreed to it. I've added a cookie consent banner that's meant to hold it back until you do — but in practice, right now, it's set on every visit regardless of what you choose. I'm working to fix that, and this section will be corrected the moment it's genuinely gated rather than just disclosed.
I don't currently use Google Analytics, Meta Pixel, or any other standalone analytics or tracking tool on my websites. If that changes, this section will be updated before any such tool goes live.
The app uses no advertising or tracking cookies at all. It stores two things on your device:
You can clear both at any time through your browser settings — but clearing local storage deletes your app content, so export a backup first.
I use third-party platforms to run my business, sharing only the minimum each one needs. Most are bound by a written data processing agreement requiring them to handle your information only on my instructions and to keep it secure. Two aren't, currently: Content Creator Machine, which runs my website, Academy, forms, newsletter, CRM and live video, has confirmed that GoHighLevel's own data processing agreement isn't contractually passed through to Content Creator Machine customers; and Senja, my testimonials platform, doesn't offer individually signed DPAs either. For both, I limit what I send them and rely on their own published terms and privacy policy instead.
| Purpose | Provider |
|---|---|
| Clinical record management | Tacklit (uk.tacklit.com, UK-hosted) |
| Video conferencing | Zoom, Google Meet |
| Email and scheduling | Google Workspace, Calendly |
| Payments | Stripe, PayPal; some 1:1 clients pay by bank transfer, which isn't run through a third-party payment platform |
| Academy, website, forms, newsletter, CRM and live video | Content Creator Machine, built on the GoHighLevel platform |
| Collaborative boards and templates | Trello (Atlassian) |
| Cloud storage (Plus, opt-in) | Supabase (London, UK project) |
| Account emails (app) | Resend |
| App hosting, and the fair-use counter store | Netlify |
| Inner Guide conversations, Story So Far and Story Card generation (app) | Anthropic (Claude) |
| Voice playback (app, Plus only) | Cartesia |
| Push notifications (app) | OneSignal |
| Sign-in (app) | Google, Apple |
| Testimonials and reviews | Senja (Senja Proof Ltd, London) |
| Client messaging (logistics only — session times and similar, 1:1 work, by agreement) and video calls, where more practical for a client working abroad | WhatsApp (Meta) |
Each has its own privacy statement on its website.
On Anthropic specifically: conversations with the Inner Guide, and the data used to generate your Story So Far and Story Card, are sent through Anthropic's commercial API. Under those terms, Anthropic does not use what you send to train its models. It retains it briefly for safety and abuse monitoring, then deletes it — see Anthropic's own privacy policy for their current periods.
Some of these services process data outside the UK, mostly in the United States. Where they do, UK GDPR requires me to put a specific legal safeguard in place before the data leaves — it isn't enough for the provider to say they're compliant. I'm putting the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, in place with each provider below, and I'm working through a risk assessment for each transfer. Two exceptions: GoHighLevel itself has a proper transfer safeguard in place, including the UK Transfer Addendum, but Content Creator Machine has confirmed it isn't contractually passed through to me as one of their customers; and Senja doesn't offer this to customers on my plan either. For both, I rely on minimising what's sent and their own published terms instead, rather than a safeguard of my own.
| Provider | What they handle | Where |
|---|---|---|
| Content Creator Machine, built on the GoHighLevel platform | Academy, courses, community, CRM, newsletter, website forms | United States |
| Anthropic | Inner Guide conversations, Story So Far and Story Card generation | United States |
| Supabase | Cloud storage (encrypted) | Data in London; provider US-based |
| Stripe | Payments | United States / Ireland |
| Netlify | App hosting, and the fair-use counter store | United States |
| Cartesia | Read-aloud voice | United States |
| OneSignal | Push notifications | United States |
| Resend | Account emails | United States |
| Atlassian (Trello) | Shared boards and templates | United States / Australia |
| Google, Apple | Sign-in; email and calendar | United States |
| Senja | Testimonials and reviews | UK company; hosts with Google Firebase, Vercel and Railway in the United States |
| Tacklit | Clinical records | United Kingdom — no transfer |
| WhatsApp (Meta) | Logistics messages and occasional video calls, where agreed | United States / Ireland |
Worth noting: because cloud storage is encrypted on your device with a key only you hold, what crosses any border is ciphertext nobody at these companies can read.
If you'd like a copy of the safeguards in place for any of these, email me and I'll send them.
Your information stays confidential. I'll only share it when:
On safeguarding: in one-to-one work, there are rare circumstances where I may need to break confidentiality because someone is at serious risk. Section 7 explains why this cannot apply to anything you write in the app.
The Inner Guide — the AI companion feature inside the app — generates its replies automatically, without a person involved. It's worth being clear about what that does and doesn't amount to.
It doesn't make any decision about you that has a legal or similarly significant effect. It doesn't decide what you're charged, whether you can use the service, what support you're offered, or anything else affecting your rights. It generates text in response to text, and you're free to ignore all of it.
So there's no automated decision-making of the kind Articles 22A–22D of UK GDPR govern, and no profiling: I don't build a profile of you from what you write, and I couldn't, because in the ordinary case it never reaches me (Section 6).
My services, including the app and the Academy, are for adults aged 18 and over. I ask you to confirm this when you create an account, and I don't knowingly collect personal information from anyone under 18. If you believe someone under 18 has given me personal information, please email [email protected] and I'll delete it.
Under UK data protection law you have the right to:
Email [email protected]. I'll respond within one month, and it's free. If a request is unusually complex I may need up to two further months, in which case I'll tell you why within the first month. I may ask you to confirm your identity first, particularly for anything involving clinical records — that's to protect you, not to slow you down.
Some things you can do yourself, faster than I can: app content is on your device and you can delete or export it from Settings; you can revoke my access to a shared Trello board directly in Trello; you can unsubscribe from any email.
Please tell me first — email me and I'll look into it properly. You also have the right to complain to the Information Commissioner's Office at any time, at ico.org.uk or on 0303 123 1113. You don't need my permission and it won't affect anything else.
This policy may be updated from time to time to reflect legal, ethical or operational changes — including as new app features go live. The current version number and effective date are always at the top of this page, and previous versions are available on request.
If a change materially affects how I handle your information, I'll email you rather than relying on you noticing.