Privacy Policy — Invincible You INSEE Coaching Chatbot Service

AI-Powered Behavioural Coaching Feature, operated by Vedanga Solutions Private Limited

1. Definitions

  • AI / LLM: Artificial intelligence and large language model technology used to generate conversational coaching responses and derive behavioural insights.
  • Behavioural Pattern: An AI-identified recurring pattern in a user’s conversational behaviour, including its description, supporting evidence, and observation frequency.
  • Episodic Memory: A user-shared story or memory extracted from conversation and used to preserve long-term coaching context.
  • Known Fact: A factual data point about the user extracted from conversation and confidence-scored by the AI system.
  • Language Signal: A linguistic marker identified in user text and used to measure aspects of coaching effectiveness.
  • Risk Signal: An AI-evaluated indicator within a conversation suggesting a wellbeing concern, which may be flagged for human review.
  • Growth Synthesis: A periodic AI-generated narrative summarizing development, pattern status, and evolution of the coaching approach.
  • INSEE Coaching Bot / Chatbot Service: The backend API service that powers conversational coaching within the InvincibleYOU Mobile Application.
  • Langfuse: A third-party LLM observability platform used for session-level technical monitoring and response-quality metrics. For purposes of this Policy, it does not receive full user conversation content.

2. Introduction

This Privacy Policy (“Policy”) describes how the InvincibleYOU INSEE Coaching Bot (“Chatbot Service”), operated by Vedanga Solutions Private Limited (“InvincibleYOU,” “Company,” “We,” “Us,” or “Our”), collects, processes, stores, and discloses information in connection with the AI-powered behavioural coaching feature offered through the authenticated InvincibleYOU Mobile Application. This Policy applies to all individuals who access or use the Chatbot Service.

The Chatbot Service is a backend API accessed through the authenticated Mobile Application chat interface. This Policy should be read together with the applicable InvincibleYOU Privacy Policy and Terms governing the broader platform.

3. How the Chatbot Service Works

When a user sends a message through the Mobile Application’s coaching chat interface, the message is transmitted through an authenticated HTTPS request to the INSEE Chatbot API. The API processes the message using Claude AI (Anthropic) as the primary language model, with Google Gemini available as a fallback on applicable model-processing calls. The AI-generated response and relevant derived coaching data are stored in the shared Supabase database and returned to the user through the Mobile Application.

The Chatbot Service does not maintain an independent user login. It identifies users through the authenticated Mobile Application session and restricts access to the user’s own coaching sessions.

4. Information We Process

  • Full conversation transcripts, turn sequences, and session metadata.
  • AI-derived behavioural patterns, including supporting evidence and frequency.
  • Episodic memories and relevant conversational context, including vector embeddings.
  • Language signal analysis derived from user text.
  • AI-generated insights and associated vector embeddings.
  • Known facts extracted from conversation and their confidence scores.
  • User-stated goals, their type, status, and commitment strength.
  • Behavioural experiments, including status, outcomes, and learnings.
  • Periodic growth synthesis narratives.
  • AI-evaluated risk signals and human-review escalation indicators.
  • AI-generated session plans, topic stacks, coaching challenges, and coach review notes.

5. Sensitive Nature of Coaching Data

Conversations with the Chatbot Service may involve sensitive personal narratives, emotional content, behavioural patterns, and psychologically relevant information. We process such information with heightened care and apply data minimization, access-control, and security principles appropriate to the nature of the data.

6. Purpose of Processing

  • Generate personalized, contextually relevant AI coaching responses.
  • Maintain continuity of coaching across sessions through conversational context, episodic memory, and known facts.
  • Identify behavioural patterns and language trends to measure coaching effectiveness.
  • Support user-directed goal setting, behavioural experiments, and progress tracking.
  • Generate periodic growth synthesis for the user’s own development review.
  • Monitor for wellbeing-related risk signals for user safety purposes.
  • Maintain security, troubleshoot the Service, improve quality, and comply with applicable law.

7. Legal Basis and Grounds of Processing (DPDP / GDPR)

Under the Digital Personal Data Protection Act, 2023 (India), processing of coaching conversation data that is based on consent is carried out on the basis of the user’s clear affirmative consent provided at onboarding through a distinct consent mechanism covering the relevant coaching processing. Sending individual messages is treated as use of the Service and is not, by itself, treated as a separate consent mechanism for special-category processing.

Where the GDPR applies, processing may rely on performance of a contract under Article 6(1)(b) for delivery of the coaching service, explicit consent under Article 9(2)(a) where special-category data is processed on that basis, and other applicable Article 6 and Article 9 grounds where legally available. Risk-signal processing will be conducted only on a lawful basis applicable to the particular processing activity; where vital interests are relied upon for special-category data, the applicable Article 9 condition will also be satisfied.

Users may withdraw consent at any time through an accessible mechanism provided within the Mobile Application or by contacting the Grievance Officer. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

8. AI Usage, Automated Processing, and Disclaimers

The Chatbot Service generates coaching responses, behavioural insights, and recommendations using AI/LLM technology. AI-generated outputs are assistive and probabilistic and may contain inaccuracies, omissions, or biases. AI-generated behavioural insights and personality-related characterizations do not constitute conclusive factual determinations and do not constitute medical, psychological, psychiatric, legal, or other professional advice.

Conversations may be processed by Anthropic’s Claude AI as the primary model and Google Gemini where used as a fallback. The applicable API configurations are intended to ensure that user content submitted for inference is not used by those providers to train their general-purpose foundation models, subject to the providers’ applicable API terms and configurations.

Langfuse is used for technical observability and response-quality monitoring. Under the current configuration, Langfuse receives session-level technical traces, token counts, latency metrics, and related observability information, but not full conversation transcript content.

Users may request human review of an automated output or profiling result that materially affects them, subject to the applicable process described in this Policy.

9. Risk Signals, Wellbeing Monitoring, and Human Review

The Chatbot Service may employ automated risk assessment to identify conversational indicators that may suggest a wellbeing concern. Where such indicators are identified, the relevant session may be flagged for review by authorized personnel in accordance with internal access controls and applicable procedures.

Risk monitoring is not real-time and human review is not guaranteed to occur immediately. The Chatbot Service is not a crisis service, emergency response system, or substitute for professional mental health support. Users experiencing a medical or mental health emergency should contact appropriate emergency or crisis support rather than relying on the Chatbot Service.

10. Third-Party AI Sub-Processors

  • Anthropic (Claude AI) – receives user messages and conversation context to generate primary coaching responses, subject to applicable contractual and data-protection safeguards.
  • Google (Gemini) – receives user messages and conversation context only when Gemini is used for applicable fallback processing, subject to applicable contractual and data-protection safeguards.
  • Langfuse – receives technical observability information such as session traces, token counts, and latency metrics, without full conversation transcript content under the current configuration.
  • Render.com – hosts the stateless Chatbot API infrastructure and does not persistently store conversation content.
  • Supabase – stores conversation transcripts and derived coaching data in the relevant database infrastructure, hosted in India (ap-south-1, Mumbai) for purposes of this Policy.

We do not sell coaching data to third parties for monetary consideration or commercial exploitation.

11. Data Storage

Coaching data is stored in the relevant Supabase database in tables and records used for conversation transcripts, session metadata, behavioural patterns, episodic memories, known facts, language signals, insights, goals, behavioural experiments, growth synthesis, risk signals, coaching challenges, and coach review notes.

12. Data Retention and Deletion

Conversation transcripts and derived coaching data are retained only for as long as necessary for the delivery and continuity of the coaching service, security, legal compliance, and applicable employer engagement requirements.

Upon account deletion or the end of the relevant employer engagement, identifiable coaching records will be deleted or irreversibly de-identified within the applicable retention period, subject to legal requirements and the need to preserve information necessary to establish, exercise, or defend legal claims.

Where technical de-identification cannot reasonably remove identifying information from free-text content or embeddings, the relevant identifiable content will be deleted rather than treated as anonymized.

De-identified and anonymized information that is no longer reasonably attributable to an identifiable individual may be retained for product improvement, statistical analysis, or research in accordance with applicable law.

13. Authentication and Access Control

The Chatbot Service has no independent login. Requests are authenticated using the authenticated Mobile Application session. Access controls are designed to restrict users to their own coaching sessions and to limit administrative access to authorized personnel with a legitimate operational need.

14. Data Principal / Data Subject Rights

Subject to applicable law, users may exercise rights including access, correction/rectification, erasure, withdrawal of consent, grievance redressal, and the right to nominate another individual to exercise specified rights in the event of death or incapacity where provided by law.

Where the GDPR applies, users may additionally exercise rights including restriction of processing, data portability, and objection, as applicable.

Requests may be submitted to the Grievance Officer. We will provide a response within the period required by applicable law. Users may pursue applicable escalation or complaint mechanisms, including before the Data Protection Board where available.

15. Children’s Data

The Chatbot Service is not intended for individuals below 18 years of age. Where the Company becomes aware that a child’s data has been processed without appropriate consent or another lawful basis, it will take reasonable steps to delete the data and address the processing in accordance with applicable law.

16. International Data Transfers

Coaching data may be processed or transferred outside a user’s country of residence, including jurisdictions where AI and infrastructure providers maintain facilities. Under the Digital Personal Data Protection Act, 2023, transfers are permitted except to countries or territories notified as restricted by the Government of India. Where the GDPR applies, transfers are subject to Standard Contractual Clauses, adequacy decisions, or equivalent lawful safeguards, as applicable.

17. Data Protection, Security, Logging and Breach Response

We maintain commercially reasonable administrative, technical, and organizational safeguards, including HTTPS/TLS encryption in transit, encryption at rest where supported, authentication and access controls, logging, and security monitoring.

Technical and security logs are retained only for as long as reasonably necessary for security, troubleshooting, fraud prevention, and compliance purposes and as required by applicable law.

Where a personal data breach occurs, InvincibleYOU will assess and respond to the incident in accordance with applicable law and will provide required notifications to the Data Protection Board and affected Data Principals within applicable statutory timelines and in the manner prescribed by law.

18. Policy Modifications and Updates

We may amend this Policy to reflect legal, operational, technological, or AI-provider developments. Where an amendment introduces a new purpose or materially changes consent-based processing, the Company will obtain any additional consent required by applicable law rather than relying solely on continued use.

19. Contact Information

InvincibleYOU Privacy, Security, and Compliance Department

This notice is intended to be made available in English and, where required by applicable law, in any of the languages specified in the Eighth Schedule to the Constitution of India.

Last Updated: 13 July 2026

Version: 1.1

Effective Date: 13 July 2026

© Invincible-YOU | All rights reserved