Skip to main content

Privacy policy

Version 1.1 · effective 13 July 2026

1. Introduction

Bridget AI Coach ("we", "our", "us") is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws.

2. What we collect

  • Account information: name, email address
  • Coaching session transcripts (encrypted)
  • Consent records with timestamps
  • Technical logs: IP addresses, browser information

3. How we use your data

  • To provide AI coaching services
  • To maintain coaching session continuity
  • To comply with legal obligations
  • To protect our legal interests in the event of disputes

4. AI disclosure and provider processing

Bridget is an artificial intelligence system. She is not a human coach, therapist, or medical professional. Bridget uses a non-directive coaching approach and does not provide advice, recommendations, or strategies.

To generate each reply, the context of your conversation is sent, encrypted in transit, to our AI provider (currently Anthropic) under a data processing agreement. This is automated processing, not human review, and your conversations are never used to train AI models or for advertising.

5. Data storage and security

All coaching session transcripts are encrypted using AES-256-GCM encryption at the application level. Your data is stored in secure, access-controlled databases. The active production encryption key is held in protected platform secret storage, with a separately protected recovery copy used only for controlled recovery.

6. Who can and cannot read your conversations

No one can read your conversations through the product: no employer, no support team member, and no administrator has any screen, report, or export that shows conversation content. Only you, signed in to your own account, can see your transcripts. If you use Bridget through your employer, your employer sees aggregate, privacy-protected numbers only — never content, topics, or any individual's activity.

We do not claim reading content is technically impossible: our systems hold the encryption key in order to show you your own conversations. Access to production infrastructure is restricted and audited, and no routine operational task involves decrypting anyone's conversation.

7. Data retention

  • Active account data: retained while your account is active
  • Session transcripts: retained for 2 years after the session date
  • Audit logs: retained for 3 years
  • Consent records: retained for 3 years after account deletion

8. Your rights

Under GDPR, you have the right to:

  • Access: Request a copy of all your personal data
  • Rectification: Correct inaccurate personal data
  • Erasure: Request deletion of your data (30-day grace period applies)
  • Data portability: Export your data in a machine-readable format
  • Withdraw consent: Revoke any consent at any time via Settings

You can exercise these rights through the Settings page or by contacting our Data Protection Officer.

9. Legal basis for retention

In the event of a legal claim, we may retain your data beyond the standard retention period as permitted under GDPR Article 17(3)(e) for the establishment, exercise, or defence of legal claims. You will be notified if this applies.

10. Contact

For any data protection enquiries, please contact our Data Protection Officer at the email address provided during registration.