Privacy Policy

How Ask Sheldon protects your information

Effective Date: October 5, 2026

Last updated October 5, 2026 — clarified optional first-party journey measurement and corrected retention and deletion descriptions.

🏥

Are you a clinician using SheldonDx?

The SheldonDx clinician platform has its own dedicated privacy policy covering session recordings, clinical data retention, and GDPR/DPDP compliance. View SheldonDx Privacy Policy →

This policy covers AskSheldon (patient-facing neurodiversity platform at asksheldon.app), operated by ZEBRA HEALTH LTD (Company No. 16588391), 128 City Road, London, United Kingdom, EC1V 2NX. For privacy requests, withdrawal of consent or complaints, contact hi@asksheldon.app. For the clinician platform, see SheldonDx Privacy Policy.

Privacy First

Built by and for the neurodivergent community, with privacy as a core value. Questions or concerns? Email us at hi@asksheldon.app

🛡️ Privacy-First, Neurodivergent-First

We understand digital privacy concerns, especially for neurodivergent individuals who may be more vulnerable to data misuse. Ask Sheldon is built by and for the neurodivergent community, with privacy as a core value, not an afterthought.

Current Privacy Features

  • • Data encrypted in transit and at rest
  • • Automatic 30-day data cleanup
  • • Download your data anytime
  • • Complete account deletion

Roadmap

  • • Shorter retention options (7-day)
  • • Enhanced data anonymization
  • • Advanced export tooling
  • • Audit log for clinician data access

🌟 Let's Be Honest About Data

Data is the oil of the digital industry. Unlike most apps, we're upfront about this reality.

🧠 Our Difference

We're neurodivergent people building for neurodivergent people. Every resource and all proceeds go toward community goals. This isn't just an app—it's part of building the self-help destination for neurodivergent individuals.

  • • Chat conversations → Improve Sheldon's understanding of neurodivergent needs
  • • Screening responses → Better assessment recommendations
  • • App usage patterns → Build features that actually help

🔒 Privacy Mode Default

Supported chat and screening records use your retention setting. See the retention section below for deletion timing and limits.

🌟 Community Contributor Opt-in

Choose to contribute anonymized data to help improve the product for everyone. Coming soon.

🤝 Our Commitment

All our efforts and resources will go towards neurodivergent community goals. That's our promise. We're in this together.

Hello! This privacy policy explains how Ask Sheldon ("we", "us", or "our") handles your information. We offer this Application as a Freemium service designed specifically for neurodivergent individuals seeking mental health support.

💡 The Personalization Balance

Just like a human guide can only help you as much as they know you,Sheldon can only provide personalized support based on what you share. We collect minimal data to make your experience meaningful.

You're in control: You can delete your data anytime, use the app with minimal sharing, or go full-anonymous mode for basic features.

We care deeply about your privacy. This policy uses plain language to tell you exactly what information we collect, why we collect it, and how we protect it. By using Ask Sheldon, you agree to the practices described here.

Stored Only on Your Device (Never Leaves Your Computer)

  • • App preferences and settings
  • • Daily journal entries and notes
  • • Mood tracking patterns and insights
  • • Custom neurotype configurations
  • • Offline AI conversation processing
  • • Crisis support resource favorites

This data is only accessible to you and stays private on your device.

Information We Store (For Cross-Device Sync & Personalization)

  • Account Details: Your email and optional username to set up your account
  • Profile Information: Optional details like your neurotype, interests, and preferences to personalize your experience
  • Chat History with Sheldon: Conversations to maintain context and generate responses (see retention settings and limits below)
  • Screening Test Results: Assessment responses to provide appropriate support recommendations (see retention settings and limits below)
  • Support Messages: Information you send when contacting us for help

Information We Collect Automatically (Minimal & Purpose-Driven)

  • App Usage: Which features you use and how you navigate the app (to improve your experience)
  • Device Information: Device type, operating system, and IP address (to ensure compatibility)
  • Generic Location (IP-based): Very general location (city/region) for weather updates and relevant local resources
  • Cookies: Small files to remember your preferences and improve app performance

🗺️ About Location Data

IP Address Location: We use your IP address to get a very general location (like "San Francisco, CA") for weather info and local Google search results.
Therapist Finder: Uses precise GPS through Google Maps for nearby therapists, but we never collect or store this precise location.
You Control It: You can disable location features entirely in settings.

🎯 Why Each Piece of Data Matters

Every piece of information we collect serves a specific purpose in making Sheldon more helpful to you. Without this data, Sheldon would be like talking to a stranger every time.

Core Functions

  • • Chat History: Maintains conversation context so Sheldon remembers what you've discussed
  • • Profile Data: Personalizes responses to your specific neurotype and needs
  • • Mood Patterns: Helps identify trends and suggest appropriate resources
  • • Account Security: Keeps your data safe and accessible only to you

Improvements & Features

  • • Usage Analytics: Optional first-party journey measurement runs only after you choose it. We record broad page areas, fixed action categories, active time, broad entry source and error categories; event payloads exclude message text, answers, notes, clinical text, raw query values and screen recordings. The choice is stored for this browser origin and can be changed here or in Settings. Third-party product analytics and session replay remain disabled. Our service may separately retain operational usage and security records; these are not necessarily anonymous.
  • • AI Responses: Information you choose to provide is processed to generate responses, not to train our own AI models. We ask for explicit health-data consent before onboarding questions.
  • • Bug Fixes: Technical data helps us fix issues faster
  • • Session replay: PostHog and LogRocket session recording are disabled, including in native patient builds.
  • • Weather/Local Info: Generic location enables contextual daily planning
Learn more

If you opt in, we record broad areas visited, actions, time spent, entry source and error counts. We never record your messages, answers, notes or screen video. You can change this in Settings.

🔒 Security Measures

  • • Encryption in transit: All data sent between your device and our servers uses TLS/HTTPS
  • • Encryption at rest: Data stored in Firebase Firestore is encrypted by Google Cloud
  • • Data Minimization: We only collect what is necessary for the features you use
  • • Retention settings: Supported chat and screening records are marked to expire after 30 days by default, or 7 days when selected. Deletion relies on the server cleanup configuration and is not instantaneous.
  • • Server-side token storage: OAuth tokens (e.g. Google Calendar) are stored server-side only — never in the browser
  • • Access controls: Firebase security rules restrict data access to the authenticated account owner only

🤖 How the Sheldon AI Works

Conversations with Sheldon are processed server-side using Google Gemini or Amazon Bedrock, depending on the configured service. Your messages are sent to the selected AI service to generate responses. The applicable service terms and processing agreement govern that use. Voice transcription uses Deepgram. See the separate SheldonDx policy for clinical processing. We do not use your conversations to train custom AI models.

We will NEVER sell your personal information to anyone.

Our Service Providers

We work with trusted companies that help us run Ask Sheldon and SheldonDx:

  • Firebase (Google LLC): Secure authentication, database storage, and cloud hosting. Data stored in Google Cloud.
  • Google LLC (Calendar API): When clinicians on SheldonDx connect their Google Calendar, we use the Google Calendar API solely to create appointment events with Google Meet links. See the section below for full details.
  • Google Gemini / Amazon Web Services: AI responses use Google Gemini or Amazon Bedrock, depending on the configured service. Conversation inputs are processed to generate responses under the applicable service terms.
  • Deepgram: Real-time voice transcription for voice-based assessment sessions. Audio is transcribed and not retained by Deepgram beyond the session.
  • Razorpay: Payment processing for assessment fees on the SheldonDx clinician platform. Card and payment data is handled entirely by Razorpay; we do not store payment card details.
  • Recall.ai: Session recording and transcription for clinical consultation sessions on SheldonDx, when enabled by the clinician.
  • Vercel: Application hosting and deployment infrastructure. Processes request data in transit.
  • WhatsApp / Meta: Used to deliver intake notifications and onboarding messages. Patient PHI is not included in WhatsApp messages — clinicians receive a deep-link to the secure SheldonDx portal instead.
  • mem0: Stores conversation context (memory) for linked-account users of the AskSheldon assistant, enabling personalised responses across sessions. This context can include personal details you choose to share; it is not anonymised, is linked to your account, and is removed when you delete your data or account.
  • Brevo: Transactional email delivery (appointment confirmations, account notifications). Receives email addresses only.

Legal Requirements

We may share information only if required by law or to protect safety — such as court orders or emergency situations.

What we access and why

Clinicians using the SheldonDx platform can optionally connect their Google Calendar to enable automatic creation of Google Meet links when booking video consultations with patients. This integration uses the Google Calendar API with the calendar.events OAuth scope.

Exactly what we do with Calendar access

  • We create new calendar events on the clinician's primary Google Calendar when an appointment is booked. Each event includes a Google Meet link auto-generated by Google.
  • We add the patient as an attendee (if their email is provided) so they receive a calendar invitation.
  • We do NOT read, list, search, or modify any of the clinician's existing calendar events. We never access the clinician's calendar history or other appointments.

Token storage and security

OAuth access tokens and refresh tokens are stored server-side in Firebase Firestore, encrypted in transit and at rest. Tokens are never exposed to the browser or shared with any third party. They are used exclusively to create calendar events on behalf of the connected clinician.

How to disconnect

Clinicians can disconnect their Google Calendar at any time from SheldonDx → Settings → Google Calendar → Disconnect. Disconnecting immediately deletes the stored access token and refresh token from our database. Google Calendar access is also revocable at any time from your Google Account at myaccount.google.com/permissions.

Who this applies to

This integration is available only to verified clinicians on the SheldonDx platform. Patient users of AskSheldon do not have access to the Google Calendar integration and their Google sign-in (via Firebase Auth) uses only standard identity scopes: openid, email, and profile.

What You Can Do

  • View and update your profile anytime
  • Unsubscribe from promotional emails
  • Request deletion of your data

Contact Us

For data requests or questions:

hi@asksheldon.app

📅 Chat and Screening Retention

  • • Chat messages and screening results: Supported records receive a 30-day expiry by default, with a 7-day option in Settings. Server cleanup must be enabled to remove expired records; this notice does not promise deletion at an exact time or across every stored copy.
  • • Profile data: Kept until you delete your account

Active accounts: Core profile data is kept as long as you use Ask Sheldon. Chat and screening expiry settings apply to supported records; contact us for a deletion request covering other stored information.

Inactive accounts: After 24 months of inactivity, accounts may be anonymized.

Deletion requests: Use Settings or our account deletion page. Deletion can require verification and cleanup across services. We do not promise immediate removal of every copy; legally required records and backups may have separate retention periods, which we will explain when handling your request.

💾 Download Your Data: You can download all your data anytime from Settings → Account → Download My Data.

AskSheldon account holders must be 18 or older. We ask for the account holder's date of birth as an age eligibility check; this is self-reported and is not identity verification. We do not knowingly permit anyone under 18 to hold an account.

A parent or guardian (18+) can create an account to understand and support a child or young person. The account holder is the adult, but information they provide about a child can still be the child's personal or health information. Only provide information you have authority to share, and contact us for privacy or deletion requests concerning a child.

If we learn that an account belongs to someone under 18, we will delete it and its data. If you believe a young person has created an account or shared information with us, please contact us at hi@asksheldon.app

We use TLS encryption in transit and Google Cloud at-rest encryption, role-based access controls, and ongoing security improvements. External security audits have not yet been completed. We will update this section when they are.

However, no system is 100% secure. Please keep your password safe and contact us immediately if you suspect unauthorized access.

We may update this policy as Ask Sheldon evolves. We'll notify you of important changes through the app or email.

Continued use of Ask Sheldon after changes means you accept the updated policy.

Delete your AskSheldon account

You can permanently delete your AskSheldon account and associated data. This cannot be undone.

Delete your AskSheldon account

Questions? We're Here to Help

Ask Sheldon is built with neurodivergent users in mind. We welcome your feedback and questions.

Contact Us