Privacy Notice
1. About this notice
This notice explains how The 1am Room Ltd (“we”, “us”, “our”) collects, uses and protects your personal data when you use The 1am Room (the “Service”), our website at 1amroom.com, and our account area at app.1amroom.com.
We are the data controller responsible for your personal data. We are a company registered in England and Wales (company number 17261757), with our registered office at C/O GLX, 69–75 Thorpe Road, Norwich, Norfolk, NR1 1UA.
This notice explains what we do with your personal data, and what we do not do.
2. Summary
- We do not use your conversations to train AI models.
- We do not sell your personal data.
- We do not share your individual conversations with anyone, except the service providers we need to run the Service (listed in section 6) and where the law requires.
- Authorised members of our team may review conversations to keep the Service safe and to improve how it performs. Access is limited and controlled (see section 11).
- Material generated from your conversations — such as summaries and recurring themes — is shown back to you in your account area. It is not shown to other users.
- We analyse patterns across users in aggregate, for example common themes, to improve the Service. Aggregate analysis is not used to build profiles of individual users.
- You can ask us to delete your data, from your account or by contacting us.
3. The personal data we collect
Account information. When you sign up, we use a third-party sign-in provider (Clerk) to create and secure your account. This gives us your email address and the authentication information needed to keep your account secure. We do not receive or store passwords. We do not collect your name.
Your phone number. The Service is delivered through WhatsApp. We collect and store the phone number you use to message the Service, so that we can deliver the Service to you and connect your messages to your account.
Your conversations. We collect and store the messages you send to the Service and the responses it generates, including any voice notes you send, which we transcribe to text so that the Service can respond.
Payment information. Payments are handled by Onelink as merchant of record, using Stripe’s payment infrastructure. We do not receive or store your card details. We receive confirmation of your purchases, and the limited information we need to manage your access and keep our financial records.
Usage and technical data. We collect basic information about how the Service is used, and technical data such as device and connection information, needed to operate, secure and troubleshoot it.
4. Sensitive information within your conversations
The Service invites you to reflect on things that matter to you. Your conversations may therefore contain personal and sensitive information, for example about your feelings, relationships, or circumstances. Some of this may count as “special category” data under data protection law.
We do not require you to share anything, and we ask that you do not share more sensitive information than you are comfortable with.
Where your conversations contain special category data, we rely on your explicit consent to handle it for the purposes described in this notice. You give that consent by a separate, affirmative step when you set up your account. You can withdraw it at any time by contacting us. Withdrawing consent means we can no longer provide the Service, and your account will be closed.
To be clear about what the Service is: it is a reflection and self-awareness tool. It is not a health or medical service, it does not provide therapy or treatment, and we do not use your data to make any medical or clinical assessment of you.
5. How we use your data, and our legal basis
Material shown back to you. The Service generates summaries, recurring themes and related material from your own conversations, and displays these to you in your account area. This material is derived from your conversations only. It is not shown to other users.
Review. Authorised team members may read conversations to check that the Service is responding safely and appropriately, and to identify where responses can be improved. This review is retrospective and at the level of the Service. It is not monitoring of any individual user’s welfare, and it is not a commitment to detect or act on any individual’s risk of harm.
Aggregate analysis. We look at patterns across many users, such as which themes arise often, to guide improvements to the Service. Aggregate analysis is not used to build profiles of individual users.
Automated decision-making. The Service generates responses automatically, but we do not use your data to make any decision about you, based solely on automated processing, that has legal or similarly significant effects on you.
What we never do. We do not use your conversations to train artificial-intelligence models. We do not sell your personal data. We do not use your conversations for advertising.
6. Who we share your data with
We share personal data only with the service providers we need to run the Service, and only for that purpose. These act as our processors or sub-processors under contract, and are not permitted to use your data for their own purposes:
- Anthropic — provides the AI model that generates responses. Your messages are sent to Anthropic solely to generate a response for you. Under our commercial agreement, Anthropic does not use this content to train its models.
- OpenAI — provides supporting AI functions, including transcribing your voice notes to text and generating the technical representations of text the Service uses to work. Content is sent only to provide these functions.
- Clerk — provides account creation, sign-in and authentication.
- Meta — delivers the Service through WhatsApp. The messages you send and the responses you receive are processed by Meta through the WhatsApp Business Platform on our behalf. Messages exchanged with a business through this platform are not end-to-end encrypted in the way personal WhatsApp chats are: we receive the content of your messages, and Meta processes that content in order to deliver them. Your use of WhatsApp is also governed by Meta’s own terms.
- Our hosting and infrastructure providers — host the Service and store data securely.
Payments work differently. Your purchase is made from Sold through Link, LLC (trading as Onelink), which sells the Service to you as merchant of record, using payment infrastructure provided by Stripe. Because Onelink is the seller rather than our supplier, it is a separate data controller in its own right: it decides how it handles the personal data it collects to take your payment, issue your receipt, manage your subscription and answer your billing questions. That handling is governed by its own privacy policy, not by this notice.
We receive confirmation of your purchase and limited billing information, and we handle that under this notice.
We may also disclose personal data where we are legally required to, to protect our rights or the safety of others, or in connection with a business sale or reorganisation, in which case your data would remain protected under terms consistent with this notice.
7. International transfers
Several of the recipients listed in section 6 are based outside the UK, including in the United States.
Where your personal data is transferred outside the UK, we make sure it is protected by appropriate safeguards recognised under UK data protection law, such as the International Data Transfer Agreement or equivalent contractual protections.
8. Cookies
We use only cookies and similar technologies that are strictly necessary to provide the Service you have asked for. These are:
- Sign-in and session cookies, set by Clerk, which keep you signed in and keep your account secure.
- Security technologies, used on the sign-in page to distinguish real people from automated abuse.
- Checkout cookies, set by Stripe and Onelink during payment, which allow the checkout to function and help prevent fraud.
Cookies that are strictly necessary to a service you have requested do not require your consent, but we tell you about them here.
We do not use cookies for analytics, advertising, or tracking you across other websites. Our website analytics do not use cookies and do not identify you individually.
You can block or delete cookies through your browser settings, but the Service will not work correctly if you block the cookies listed above.
9. How long we keep your data
We keep your personal data for as long as you have an account and use the Service.
When you close your account, or when you ask us to delete your data, we delete or anonymise your conversations and the material generated from them within one month.
Some limited information is kept for longer where the law requires it, for example transaction records we must keep for tax and accounting purposes, or where it has been aggregated or anonymised so that it no longer identifies you.
10. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you;
- ask us to correct inaccurate data;
- ask us to delete your data (“right to erasure”);
- object to or ask us to restrict certain processing;
- withdraw consent where we rely on it;
- ask us to transfer your data (“data portability”); and
- complain to a data protection regulator.
Deleting your data. You can request deletion of your data from within your account, or by contacting us. We will delete your personal data within one month, other than any limited information we are legally required to keep, such as transaction records, or that has been anonymised so that it no longer identifies you.
Withdrawing consent. We rely on your explicit consent to handle special category data within your conversations. If you withdraw that consent, we can no longer provide the Service, and your account will be closed. Withdrawing consent does not affect anything we did lawfully before you withdrew it.
To exercise any of your rights, use the controls in your account or contact us at support@1amroom.com. We will respond within the time required by law, normally one month.
If you are unhappy with how we have handled your data, you can complain to the UK’s Information Commissioner’s Office (ICO) at ico.org.uk. We would ask that you contact us first so that we can try to put things right.
11. How we protect your data
We use appropriate technical and organisational measures to protect your personal data, including access controls that limit who on our team can view conversations. Access to review conversations is restricted to authorised personnel who are bound by confidentiality obligations. No system can be guaranteed completely secure, but we take reasonable steps to protect your information.
12. Children
The Service is for adults and is not intended for anyone under 18. We do not knowingly collect data from under-18s. If you believe someone under 18 is using the Service, please contact us.
13. Changes to this notice
We may update this notice from time to time. Where a change is significant, we will let you know, for example by email or through the Service. The “last updated” date at the top shows when it was last changed.
14. Contact us
For anything about your privacy or this notice, contact: