Inwork
AboutEventsToolsDownload
Sign inGet the app

Legal

Privacy Policy

Version 2.3 · Effective April 2026 · Last updated April 2026

Privacy PolicyTerms of ServiceAI Coach TermsCookie PolicyEULACommunity GuidelinesAcceptable UseConsumer Health PrivacyTrademark & brand use

On this page

1. Introduction2. Information We Collect3. Legal Bases for Processing (GDPR)4. How We Use Your Information5. AI Data Processing6. Health-Adjacent Data Protection7. Third-Party Services8. Data Sharing and Disclosure9. International Data Transfers10. Data Retention11. Your Rights (GDPR)12. Your Rights (CCPA/CPRA)13. Children's Privacy and Age Restriction14. Push Notifications and Email Updates15. Content Moderation & Community Safety16. Data Retention for Reports17. Security Measures18. Data Breach Notification19. Automated Decision-Making and Profiling (GDPR Article 22)20. Cookie Policy21. Changes to This Policy22. Contact Information
In short: we do not sell your personal data, and journal entries are encrypted on your device before they are stored — see section 6 for when AI features read them.

1. Introduction

Welcome to Inwork ("we," "us," or "our"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform and services (collectively, the "Service").

Data Controller: The data controller responsible for your personal data is Eivolv AB (org. nr 559459-6560), registered at c/o Benjamin Raki, Fredriksdalsgatan 7 C, 412 62 Gothenburg, Sweden. For privacy-related inquiries, contact our Data Protection Officer at support@inworkcenter.com.

This policy applies to all users of Inwork, including the mobile app (iOS and Android), web application, and any related services. By using the Service, you consent to the data practices described in this policy.

2. Information We Collect

We collect information in the following categories:

Account Information

  • Email address, name, and profile details
  • Authentication data (password hash, OAuth provider tokens)
  • Account preferences and settings

User-Created Content

  • Journal entries and reflections
  • Habit tracking data (habits, completions, streaks)
  • Mood ratings and self-assessments
  • Meditation session data (duration, frequency)

AI Interaction Data

  • Conversations with the AI Coach
  • AI-generated meditation scripts and coaching responses
  • Habit optimization suggestions and user selections

Community Data

  • Posts, comments, and messages in Social
  • Reactions and interactions with other users
  • Uploaded images and media

Facilitator Application Data

If you apply to host in-person events, we ask you to identify yourself so that we know who is responsible for an event and can reach you about it. We collect:

  • A photograph of yourself
  • Your full name
  • An email address and a phone number
  • A description of the events you intend to host
  • The date and time you accepted our community guidelines

Your photograph and name may be shown publicly alongside events you host. Your email address and phone number are never shown publicly — they are visible only to Inwork administrators, who use them to contact you about your events or your conduct on the platform. Hosting online sessions does not require an application and none of this data is collected for them.

Usage and Device Data

  • Device type, operating system, and browser information
  • IP address and approximate location (country/region)
  • App usage patterns, feature interactions, and session duration
  • Push notification tokens (when notifications are enabled)
  • Timezone information

3. Legal Bases for Processing (GDPR)

For users in the European Economic Area (EEA) and UK, we process your personal data on the following legal bases:

  • Contract performance (Art. 6(1)(b)): Processing necessary to provide the Service you signed up for — account management, habit tracking, journaling, AI coaching
  • Legitimate interests (Art. 6(1)(f)): Service improvement, security, fraud prevention, and analytics — balanced against your privacy rights
  • Consent (Art. 6(1)(a)): Push notifications, optional marketing communications, and cookie-based analytics. You may withdraw consent at any time
  • Legal obligation (Art. 6(1)(c)): Compliance with applicable laws, responding to legal requests, and mandatory reporting obligations

Special Category Data (GDPR Article 9)

Certain data collected by Inwork — including mood ratings, mental wellness journal entries, meditation activity, and health-related habit data — may qualify as data concerning health under GDPR Article 9. We process this data on the basis of your explicit consent (Art. 9(2)(a)), which you provide when you accept the Terms of Service and Privacy Policy during account creation. You may withdraw this consent at any time by deleting your account or contacting support@inworkcenter.com. Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal.

For detailed information about how we handle health-adjacent data, see our separate Consumer Health Data Privacy Policy.

4. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Power AI coaching, meditation generation, and habit optimization features
  • Personalize your experience based on your goals and activity
  • Moderate community content and enforce guidelines
  • Send push notifications you have opted into (habit reminders, messages)
  • Detect and prevent fraud, abuse, and security threats
  • Analyze usage patterns to improve features and user experience
  • Comply with legal obligations

5. AI Data Processing

Inwork uses third-party artificial intelligence models to power its coaching, meditation, and optimization features. We are transparent about how your data interacts with AI systems:

  • What AI sees: When you use AI features, relevant context (such as your habit name, journal excerpts, or conversation history) is sent to the AI model to generate a response
  • Conversation logging: AI conversations may be logged to improve service quality, debug issues, and ensure safety. Logs are stored securely and access is restricted
  • NOT used for AI training: Your personal data, journal entries, and AI conversations are NOT used to train or fine-tune third-party AI models
  • NEVER shared with advertisers: Your AI interaction data is never sold to or shared with advertising networks or data brokers
  • Third-party AI providers: We use the following AI services, each operating under data processing agreements:
    • OpenAI (GPT-5.4 Mini, text-embedding-3-small) — AI Coach agent, journal reflection feedback, NVC language translation, NVC roleplay practice, habit coaching suggestions, meditation script generation, and semantic memory embeddings. Data is not used to train OpenAI models per our API terms
    • ElevenLabs (Turbo v2.5 TTS, Scribe v2 STT, voice cloning) — text-to-speech for meditation and roleplay audio, speech-to-text transcription for voice input, and reusable voice model creation when you explicitly clone your own voice. Audio may be sent to ElevenLabs for processing, and raw voice samples are not stored in Supabase after processing. ElevenLabs stores the reusable voice model needed to provide the feature
    • Google Gemini (Gemini 3.5/3.7 Flash, Gemini 3.5 Pro, Imagen 4) — transcription and analysis of meeting and workshop recordings, meeting preparation and summaries, task suggestions, facilitation session analysis, live session coaching, portrait image generation, and event imports. We use Google's paid API tier, under which your prompts and responses are not used to train Google models. This processing runs on Google's global infrastructure and is not restricted to the EU; transfers are covered by Google's Cloud Data Processing Addendum together with the EU-US Data Privacy Framework and Standard Contractual Clauses

For questions about AI data processing, contact support@inworkcenter.com.

6. Health-Adjacent Data Protection

While Inwork is not a healthcare service, we recognize that journal entries, mood ratings, habit data, and wellness reflections are personal and sensitive. We treat this data with the highest level of care:

  • NEVER sold: Your journal entries, mood data, habit information, and wellness content are never sold to any third party — for any reason, at any price
  • NEVER used for advertising: Health-adjacent data is never shared with advertisers, data brokers, or used for targeted advertising purposes
  • NEVER shared with employers or insurers: We do not share your data with employers, insurance companies, or any entity that could use it to make decisions about you
  • Encrypted storage: Journal entries are encrypted on your device before they are stored, and Inwork staff do not read them. Some AI features send journal text to our servers and our AI provider when you use them: Reflect sends the entry you choose, and in the mobile app the AI coach, while its Journal access is on, receives the opening lines of your latest entries and can look up short passages from any of your entries
  • Minimal access: Inwork staff do not routinely access your journal entries or personal wellness data. Access occurs only for critical security investigations or when required by law

7. Third-Party Services

We use the following third-party services to operate the platform:

  • Supabase: Database hosting, authentication, file storage, and real-time features. Data is stored in Supabase-managed infrastructure with row-level security
  • OpenAI (San Francisco, USA): AI text generation for coaching and meditation. See OpenAI's Terms
  • ElevenLabs (New York, USA): Text-to-speech and speech-to-text services. See ElevenLabs' Privacy Policy
  • Google OAuth: If you sign in with Google, we receive your name, email, and profile picture. See Google's Privacy Policy
  • Facebook/Meta OAuth: If you sign in with Facebook, we receive your name and email. See Meta's Privacy Policy
  • Apple Push Notification Service (APNs): For delivering push notifications on iOS devices
  • Google Gemini: (USA): AI processing of meeting and workshop recordings, transcripts and summaries, facilitation sessions, live session coaching, task suggestions, portrait generation, and event imports. See Google's Privacy Policy
  • Resend: (USA): Sending transactional and account emails on our behalf. See Resend's Privacy Policy
  • Twilio: (USA): Real-time connection (TURN) relay for live sessions; processes connection metadata and IP addresses. See Twilio's Privacy Notice
  • Agora: (USA): Real-time audio/video and connection relay for live sessions; processes connection metadata and IP addresses. See Agora's Privacy Policy

8. Data Sharing and Disclosure

We do not sell your personal data.

We may share your information in the following limited circumstances:

  • Service providers: Third-party vendors who assist us in operating the Service, subject to data processing agreements that limit their use of your data
  • Legal requirements: When required by law, subpoena, court order, or government regulation
  • Safety: When we believe disclosure is necessary to protect the rights, safety, or property of Inwork, our users, or the public — including cases involving potential harm to minors or threats of violence
  • Business transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users
  • With your consent: When you explicitly authorize us to share your information

9. International Data Transfers

Your data may be processed in countries outside your country of residence, including countries that may not provide the same level of data protection. When we transfer data internationally, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data processing agreements with all third-party service providers
  • Technical security measures including encryption in transit and at rest

10. Data Retention

We retain your data for the following periods:

  • Account data: Retained while your account is active, deleted within 30 days of account deletion request
  • Journal entries and habits: Retained while your account is active, deleted with account
  • AI conversation logs: Retained for up to 12 months for service improvement, then anonymized or deleted
  • Community content: Posts and messages retained while account is active. Deleted content may persist in other users' conversation history
  • Usage analytics: Aggregated and anonymized after 24 months
  • Push notification tokens: Deleted when you disable notifications or delete your account
  • Facilitator applications: Retained while your account is active and deleted with your account. If an application is declined, the photograph is deleted at that point, while the name and contact details are kept so administrators can recognise repeat applications from hosts whose access was withdrawn

11. Your Rights (GDPR)

If you are in the European Economic Area (EEA) or UK, you have the following rights under the General Data Protection Regulation:

  • Right of access (Art. 15): Request a copy of the personal data we hold about you
  • Right to rectification (Art. 16): Request correction of inaccurate personal data
  • Right to erasure (Art. 17): Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations
  • Right to restrict processing (Art. 18): Request that we limit how we use your data
  • Right to data portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format
  • Right to object (Art. 21): Object to processing based on legitimate interests
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent

To exercise any of these rights, contact support@inworkcenter.com. We will respond within 30 days.

You also have the right to lodge a complaint with your local data protection supervisory authority.

12. Your Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act and California Privacy Rights Act:

  • Right to know: Request disclosure of the categories and specific pieces of personal information we have collected about you
  • Right to delete: Request deletion of your personal information
  • Right to correct: Request correction of inaccurate personal information
  • Right to opt-out of sale: We do not sell your personal information. If this changes, we will provide a "Do Not Sell My Personal Information" link
  • Right to non-discrimination: We will not discriminate against you for exercising your privacy rights

Categories of Personal Information Collected

CategoryPurpose of Collection/UseSold or Shared for Ads
Identifiers (name, email, user ID)Account creation, authentication, personalizationNo
Internet/Electronic Activity (usage logs, device info)App improvement, analytics, security monitoringNo
Geolocation (timezone)Habit scheduling, time-appropriate featuresNo
Audio Data (voice recordings)Speech-to-text transcription, meditation audio generationNo
Inferences (mood, habit patterns)Personalized AI coaching, content recommendationsNo
Sensitive Personal Info (journal entries, mood data, health reflections)Core service delivery (journaling, habit tracking, AI coaching)No
User-Generated Content (posts, messages, reactions)Community features, content moderationNo

To exercise these rights, contact support@inworkcenter.com.

13. Children's Privacy and Age Restriction

Inwork is exclusively offered to adults aged 18 and older. Use by minors is strictly prohibited. We do not knowingly collect personal information from anyone under the age of 18.

If we become aware that we have collected personal data from a person under 18, we will take steps to delete that information and terminate the associated account promptly. If you believe a minor has created an account or provided us with personal data, please contact support@inworkcenter.com.

14. Push Notifications and Email Updates

If you enable push notifications, we collect and store a device push token to deliver notifications. We use push notifications for:

  • Habit reminders and streak notifications
  • New messages and community activity
  • Important account and security alerts

You can disable push notifications at any time through your device settings or within the app. When disabled, your push token is removed from our systems.

Email updates (optional)

We send one optional email list, "New tools & tips" — an email when we launch new tools, practices and features, no more than about once a month. We send it only if you have opted in, either when creating your account or from your account settings. Our legal basis is your consent (GDPR Article 6(1)(a)). Opting in is never a condition of using Inwork, and we record when you gave or withdrew consent so we can demonstrate it.

You can withdraw consent at any time — turn off "New tools & tips" in your account settings, or use the unsubscribe link in any of these emails. Withdrawing is as easy as opting in and takes effect immediately. Service emails about your account, such as password resets and security alerts, are not part of this list and continue regardless.

15. Content Moderation & Community Safety

To maintain a safe and supportive community, we implement content moderation practices:

  • Report Review: Community members may report content that violates our guidelines. Our moderation team reviews these reports to determine appropriate action
  • Content Snapshots: When content is reported, we preserve a snapshot of the reported content for review purposes. This ensures fair and accurate moderation decisions
  • Moderation Actions: Based on report reviews, we may take actions including content removal, warnings, or account restrictions
  • Reporter Privacy: The identity of users who submit reports is kept confidential and is never shared with the reported user

16. Data Retention for Reports

We retain report-related data for the following periods to ensure community safety and legal compliance:

  • Pending/In-Review Reports: Retained until resolution
  • Actioned Reports (Standard): Retained for 1 year after resolution
  • Dismissed Reports: Retained for 90 days for potential appeals
  • Reports Involving Illegal Content: Retained for up to 7 years per legal requirements

Reports cannot be deleted by users to preserve evidence integrity for moderation purposes.

17. Security Measures

We implement robust technical and organizational measures to protect your personal information:

  • Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS/HTTPS
  • Encryption at rest: Sensitive data is encrypted at rest in our database
  • Row-Level Security (RLS): Database-level policies ensure users can only access their own data
  • Access controls: Strict role-based access controls limit who can access user data
  • Authentication security: Passwords are hashed using industry-standard algorithms. OAuth tokens are managed securely by our authentication provider

No system is 100% secure. We encourage you to use strong, unique passwords and enable two-factor authentication where available.

18. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the supervisory authority (Swedish Authority for Privacy Protection, IMY) within 72 hours of becoming aware of the breach, as required by GDPR Article 33
  • Notify affected users without undue delay when the breach is likely to result in a high risk to rights and freedoms, as required by GDPR Article 34
  • Notify the U.S. Federal Trade Commission within 60 days for breaches affecting 500 or more U.S. residents, as required by the FTC Health Breach Notification Rule
  • Comply with applicable state breach notification laws in the United States, including but not limited to California, Washington, and other states where our users reside

Breach notifications will include: a description of the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.

We maintain an internal incident response plan that details our procedures for detecting, investigating, containing, and reporting data breaches.

19. Automated Decision-Making and Profiling (GDPR Article 22)

Inwork uses AI systems to personalize your experience. This includes:

  • AI Coach personalization: The AI Coach remembers your conversation history, goals, habits, and preferences to provide contextually relevant guidance
  • Content recommendations: Meditation scripts, habit suggestions, and coaching responses are tailored based on your activity and stated goals
  • Journal reflection feedback: AI-generated feedback on journal entries is personalized based on what you write

These AI features provide suggestions and guidance only — they do not make decisions that produce legal effects or similarly significant effects on you. No automated system determines your access to the Service, your pricing, or any rights.

Under GDPR Article 22, you have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. If you believe any automated processing has significantly affected you, contact support@inworkcenter.com to request human review.

20. Cookie Policy

For detailed information about the cookies and similar technologies we use, please see our Cookie Policy. Essential cookies are used to maintain your session and preferences. Analytics cookies are only used with your consent.

21. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the version number and "Last updated" date at the top of this page
  • Notify you via email or in-app notification at least 30 days before material changes take effect
  • Provide a summary of what changed

Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

22. Contact Information

For questions about this Privacy Policy or to exercise your data rights:

  • Company: Eivolv AB (org. nr 559459-6560)
  • Address: c/o Benjamin Raki, Fredriksdalsgatan 7 C, 412 62 Gothenburg, Sweden
  • Email: support@inworkcenter.com

By creating an account or using Inwork, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

Questions about your data?

Write to us and we will answer.

support@inworkcenter.com
Inwork

Train the mind that trains everything else.

In collaboration with PsychBase — modern education for clinicians working in mental health.

Explore

HabitsJournalMeditationBreathworkUnderstanding MyselfAI CoachAcademyWorkshopsSocial

Company

AboutPricingDownload the App

Connect

Supportsupport@inworkcenter.com

© 2026 Eivolv AB. All rights reserved.

Inwork® is a registered trademark of Eivolv AB in the European Union. EUTM No. 019354115.

Privacy PolicyTerms of ServiceTrademark & brand use