Skip to main content
Legal

Privacy Policy

epRegulate Mobile Application · Effective date: July 24, 2026

What epRegulate never does

  • epRegulate is local-first: your logs stay on your device and nothing is sent to us unless you turn on caregiver sharing.
  • We never show advertising of any kind.
  • We never sell, rent, or share your data with third parties.
  • We never use your data to train AI models.
  • epRegulate is a well-being companion, not a medical device, and does not diagnose or treat any condition.

EnrichPoint (“we,” “us,” or “our”) operates the epRegulate mobile application (the “App”). epRegulate is a calm, offline-first companion for emotional and sensory regulation: you log how you feel on a simple mood meter, note what triggered a hard moment, and run short calming exercises. This Privacy Policy explains how we collect, use, store, and protect information when you or someone in your care uses the App.

For the EnrichPoint corporate-level legal terms (account auth, billing, dispute resolution) that apply across every EnrichPoint app, see our site-wide Privacy Policy. This document is the epRegulate-specific addendum and takes precedence for matters specific to this app.

1. Local-first by design

epRegulate is built to work fully offline. By default, everything you log — mood check-ins, triggers, notes, and coping-tool sessions — is stored only on your device. We do not receive it, and it is not backed up to our servers, unless you explicitly turn on caregiver sharing (see §4).

2. Who uses epRegulate

  • End users — the person doing the check-ins, aged 13 or older. An end user can use the App entirely on their own device without an account. A younger child may use the App only under a caregiver's account and responsibility (see §5).
  • Caregivers — a parent, family member, or supporter who may set up the App and, with the end user's participation, receive shared regulation data. Caregivers hold an EnrichPoint account.

3. Information We Collect

On the device (not sent to us by default)

  • Mood check-ins (a 1–5 state), and whether a moment was a “hard moment.”
  • Optional trigger tags and a short free-text note attached to a check-in.
  • Coping-tool sessions (which tool, how long, and the before/after state).
  • Rule-based weekly summaries computed on the device.
  • App settings and preferences (display name, language, default logger).

If you create an account / enable sharing

  • Email address and display name (from sign-up, or from Google/Apple if you use those providers).
  • The regulation data above, once you turn on caregiver sharing, so a caregiver can see it.

What we do NOT collect

  • Audio recordings, video, or photos.
  • Location data of any kind.
  • Contacts, calendar, or other device data outside the app.
  • Biometric data.
  • Behavioral profiles for advertising or third-party sharing.

4. Caregiver sharing (opt-in and revocable)

epRegulate exists to help a caregiver support someone — not to surveil them. Sharing is off until someone turns it on.

  • When “Share with my caregiver” is enabled, your regulation data is synced to EnrichPoint's systems so a caregiver in your household can see it, and normalized signals (e.g. a count of hard moments per day) are added to the cross-app epCaregiver Insights hub.
  • You can turn sharing off at any time. When you do, the cloud copy of your shared data is deleted — turning it off retracts the data, not just future updates.

AI Insights (a separate, explicit opt-in)

A caregiver may separately choose to enable AI Insights, which uses a server-side AI model to turn derived aggregates (trends and counts — never your raw notes) into a plain-language summary. This requires its own explicit, revocable consent. AI-generated summaries are informational, are not medical, clinical, or diagnostic advice, and your data is never used to train AI models.

5. Age Requirement and Children's Privacy

epRegulate is intended for users aged 13 and older, and for the caregivers who set it up and support them. The App is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

  • A child who uses epRegulate does so under a caregiver's account and responsibility. The caregiver decides whether any data is shared, and can clear or delete it at any time.
  • By default nothing leaves the device (see §1), so absent caregiver sharing no check-in data is transmitted to us, whatever the user's age.
  • We do not sell, share, or use anyone's data for advertising or profiling.
  • A caregiver can clear shared data at enrichpoint.com/epregulate/delete-data or close the account at /epregulate/delete-account.

If you are a parent or guardian and believe a child under 13 has provided information to us without your involvement, contact support@enrichpoint.com and we will delete it promptly.

6. How We Use Information

  • Provide the service: store and sync shared regulation data so a caregiver can see it, and (with separate consent) generate AI summaries.
  • Improve the product: aggregated, non-identifying analytics about which features are used and where bugs occur. We do not read individual logs for product decisions.
  • Support requests: when you contact support, we look at your account data only as needed to resolve the issue.
  • Security and abuse: we may log auth events (sign-in, sign-out) to detect fraud or compromised accounts.

7. How We Store and Protect Information

  • On-device data is stored in the App's local storage on your device.
  • Shared data is stored on Google Firebase (Firestore, Authentication) within Google Cloud's US infrastructure.
  • Data in transit uses TLS 1.2+; data at rest is encrypted by Firebase using AES-256.
  • Access to production data is restricted to a small number of EnrichPoint engineers, with audit logging on administrative actions.

8. Third-Party Services

epRegulate uses a small set of third-party services purely for app function:

  • Firebase (Google): authentication and database for shared data.
  • Apple / Google: if you sign in with Apple or Google, your name, email, and provider identifier are shared with us per their respective terms.
  • Anthropic (Claude): only when AI Insights is explicitly enabled, derived aggregates are sent to Anthropic's API to generate a summary. This data is not used to train models.

We do not include any third-party advertising SDKs, third-party analytics SDKs, or social-media tracking libraries in the App.

9. Data Retention

  • On-device data: kept until you delete it in the app or uninstall the App.
  • Shared account data: retained while the account is active and sharing is on; turning sharing off deletes the cloud copy.
  • Deleted account / data: removed from production systems within 30 days; backup copies are purged on the next backup rotation cycle (up to 90 days).

10. Your Rights

You may at any time:

11. International Users

epRegulate is operated from the United States. If you use the App from outside the US, you consent to processing your shared data in the US. EU and UK users have additional rights under GDPR and UK GDPR — contact support@enrichpoint.com to exercise them.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced in the App and on this page. The “Effective date” at the top reflects the most recent version. Continued use of the App after the effective date constitutes acceptance.

13. Contact

Privacy questions, data requests, or COPPA concerns: support@enrichpoint.com.