Saltar al contenido principal
Logotipo de Kooth
  • Explore
    CounsellingPara JóvenesPara Líderes ComunitariosPara Universidades
  • Acerca de
    Parents & FamiliesCentro de ContactoCommunity Partners
  • Impacto
    Programa de Embajadores de EducaciónApproachMes de Concienciación sobre la Salud MentalImpact
  • Contact Center
  • ES
    English
    Spanish

Aviso de Privacidad

Actualizado el 11 de junio de 2026

Kooth Digital Health Limited (“Kooth”) offers an easy-to-access online mental health services platform designed to work alongside you, providing compassionate and effective support. Our goal is to create a welcoming space for personalised digital mental healthcare. Note that other Kooth Services may be governed by privacy notices containing different information practices applicable to those sites and Services.

Alcance de este Aviso de Privacidad

Kooth is proud to have developed the Soluna application (“App”), available on iOS, Android and Web (“Soluna”). This Privacy Policy outlines what information we collect about you, how we use it, and when we might share information about you, the service user (the ”Users”) on Soluna. It also details your options for managing your data. We also developed a website, solunaapp.com, in connection with the services we provide (collectively the “Services”).

When you use and access our Services, you accept and agree to the Terms of Use and this Privacy Policy, including that we may share certain data with Third-Party Service Providers. If you do not feel comfortable with any part of this Policy, you must not use or access our Services.

Consentimiento parental

When creating a Soluna account, you will have the option to either use a (“Guest Account”) or a “Full Account”). The type of account you choose directly determines what personal information we collect and store locally on your device. If you choose a Guest Account, you can access Soluna’s self-directed content and resources without providing any directly identifiable personal data. If you choose a Full Account, you unlock all the Soluna features, including 121 practitioner support, participation in the peer community, tracked goal-setting and journalling.

Below is the information we collect:

En Kooth USA, LLC y Kooth Digital Health ("Kooth", "nosotros" o "nuestro"), su privacidad es importante para nosotros. Creamos servicios de salud mental en línea de fácil acceso que colaboran con usted para brindar un apoyo compasivo y efectivo. Creamos un espacio acogedor para la atención de salud mental digital personalizada. Atendemos a usuarios, clientes y partes interesadas ("Clientes").

Kooth tiene más de 20 años de experiencia protegiendo la privacidad de Clientes y usuarios. Kooth se enorgullece de haber desarrollado la aplicación Soluna (“App”), disponible en iOS y Android (“Soluna”). También desarrollamos un sitio web, SolunaApp.com, en relación con los servicios que ofrecemos (colectivamente los “Servicios”).  

Otros Servicios de Kooth pueden tener diferentes políticas de privacidad y diferentes prácticas de información. Este aviso de privacidad le informa cómo recopilamos, usamos y compartimos su información cuando utiliza nuestros Servicios.

La Información de Identificación Personal (“PII”) son sus datos personales. La PII incluye cualquier información utilizada para identificar o contactar a un Usuario del Servicio Soluna (“Usuario”). Solo solicitamos la menor cantidad de información necesaria para proporcionar nuestros Servicios. Le informaremos qué información utilizamos. Al utilizar nuestros Servicios, usted acepta haber leído nuestros Términos de Uso. Usted acepta permitirnos usar su información como se describe en este aviso de privacidad y en los Términos de Uso. Si no está de acuerdo con estos términos, no utilice los Servicios ni proporcione ningún dato personal.

Este aviso de privacidad se aplica a todos los Servicios a los que se vincula. Su PII puede cumplir la definición de Información de Salud Protegida ("PHI") según la Ley de Portabilidad y Responsabilidad del Seguro Médico en ciertas circunstancias. Cuando estas circunstancias se aplican, la Notificación de Prácticas de Privacidad de Kooth describe sus derechos bajo HIPAA. Incluso si su información no es PHI, usted puede tener ciertos derechos bajo la Ley de Privacidad del Consumidor de California (“CCPA”) y otras leyes estatales. Los derechos de privacidad se describen en este aviso de privacidad.

Nos comprometemos a proteger la privacidad de los niños. En los casos en que se requiera el consentimiento de los padres para los Servicios de asesoramiento según la ley estatal, nos pondremos en contacto con un padre o tutor desde parentalconsent@solunaapp.com para obtener el consentimiento de los padres antes de interactuar con un Usuario con fines terapéuticos. .

Información que recopilamos

Solo recopilamos información sobre usted si es necesario para que pueda utilizar nuestros Servicios. Esto incluye 1) la información que usted proporciona a Kooth y 2) la información que recopilamos automáticamente. Esta información hace que su experiencia sea única para usted.

La siguiente sección describe los tipos de Información de Identificación Personal (PII) que podemos recopilar, cómo obtenemos la información y cómo la utilizamos.

Información que un Usuario puede proporcionar al crear una cuenta o actualizar su perfil:

Información que los Usuarios pueden proporcionar voluntariamente al usar el Sitio web o la Aplicación:

Kooth y sus Proveedores de Servicios recopilan información automáticamente cuando usted accede o utiliza los Servicios. Esto puede incluir la dirección IP, el identificador del dispositivo, el tipo de navegador, el sistema operativo, información sobre el uso del Servicio y datos sobre el hardware conectado (por ejemplo, ordenador o dispositivo móvil).

Ejemplos de cómo recopilamos información automáticamente:

Cómo utilizamos su información

Además de los fines mencionados anteriormente, podemos utilizar su información por las siguientes razones:

Procesamos su información para los siguientes fines comerciales legítimos:

Podemos utilizar su información de una manera que no le identifique. Podemos combinar esta información con la información de otras personas que utilizan nuestros Servicios. Esto se denomina datos agregados.  Podemos utilizar datos agregados para fines operativos. Estos fines incluyen el mantenimiento, la gestión y la mejora de nuestros Servicios. Podemos compartir datos agregados para análisis y otros fines comerciales. Estos fines pueden incluir la descripción de nuestros Servicios a Clientes y terceros; y el intercambio con clientes, proveedores contratados y agentes, según lo permitan las regulaciones y acuerdos aplicables.

En Soluna, siempre estamos buscando formas de brindarle un mejor apoyo. Para ello, estudiamos cómo se utilizan nuestros servicios y buscamos maneras de mejorarlos aún más.

Cómo protegemos su privacidad:

Usted decide: Puede elegir si su información se utiliza para investigación. Independientemente de si dice sí o no, seguirá recibiendo el mismo apoyo de Soluna. Si cambia de opinión, puede desactivar esta opción en cualquier momento en su Configuración. Si retira su consentimiento, su información en la aplicación no se incluirá en proyectos de investigación posteriores. Es posible que no se pueda retirar su información de investigaciones en curso, por ejemplo, si la información ya ha sido anonimizada.

Utilizamos su información de contacto y la información sobre el uso que hace de nuestros Servicios para:

Tiene derecho a "optar por no recibir" comunicaciones promocionales en cualquier momento. Sin embargo, hay algunas comunicaciones que debemos enviarle, como informarle cuando se actualice este aviso de privacidad.

Cómo protegemos sus datos personales

Implementamos medidas de seguridad técnicas, administrativas y físicas apropiadas y centradas en el riesgo, diseñadas para salvaguardar sus datos contra alteraciones, pérdidas, distribución o divulgación accidentales o no autorizadas. Estas medidas se evalúan continuamente para garantizar la seguridad, integridad, accesibilidad y el rendimiento robusto de nuestros servicios, datos y sistemas subyacentes. El acceso a los datos personales está estrictamente limitado al personal autorizado y a los socios externos cuyas funciones requieren dicha información para cumplir con los fines comerciales descritos en este aviso de privacidad.

Nuestra plataforma cifra todos los datos de los clientes, independientemente de su clasificación, como buena práctica utilizando cifrado AES de 256 bits. Todos los datos de los usuarios del servicio enviados a la plataforma se almacenan en un servidor de base de datos principal con un clúster activo para una mayor disponibilidad. La rotación de las claves utilizadas para el cifrado de datos o para acceder a los servicios está configurada para garantizar que solo se utilicen claves autorizadas.

Si se niega a proporcionar datos

Tiene derecho a negarse a proporcionar sus datos personales o a oponerse al procesamiento de sus datos de cualquier forma o en su totalidad.

Si se niega a proporcionar sus datos personales u objeta el procesamiento de sus datos, aún podrá acceder a los servicios de coaching y al contenido digital.

Si se niega a proporcionar sus datos personales u objeta el procesamiento de sus datos en un mercado que ofrece servicios de asesoramiento, no podrá utilizar dichos servicios. Esto es por su seguridad.

Información que compartimos

Nunca venderemos su información con fines de lucro*. Solo compartimos la información según se describe en este aviso de privacidad y en el Aviso de Prácticas de Privacidad, según corresponda. Además de los fines enumerados en la sección "Cómo usamos su información" y en la tabla de la sección "Información que recopilamos", podemos compartir su información con su consentimiento y para los siguientes fines.

Como muchas empresas, contratamos a otras compañías para que realicen ciertos servicios relacionados con el negocio (nuestros "Proveedores de Servicios"). Podemos compartir su información personal, información agregada o desidentificada, con Proveedores de Servicios externos con los que celebramos contratos por escrito. Estos pueden incluir servicios relacionados con el almacenamiento de datos, el alojamiento de información y la recuperación ante desastres. Los Proveedores de Servicios actúan como nuestros agentes, realizando servicios bajo nuestras instrucciones y en nuestro nombre. Solo compartimos la cantidad mínima de información necesaria para que los Proveedores de Servicios realicen los servicios contratados.

Podemos compartir su información con nuestras filiales o empresa matriz para respaldar el Servicio. La información personal puede ser divulgada legalmente entre organizaciones afiliadas, subsidiarias y matrices de Kooth, según lo permitido. Los empleados y contratistas de Kooth tienen acceso a su información solo cuando es estrictamente necesario.

Kooth puede compartir su información personal en relación con una reorganización o combinación de nuestra organización con otra organización.

Podemos compartir su información si así lo exige la ley o la normativa aplicable. En determinadas circunstancias, podemos compartir su información para cumplir con un procedimiento judicial, una orden judicial u otra obligación legal, o una investigación reglamentaria o gubernamental.

Información que los usuarios comparten públicamente

Se le puede permitir enviar Contenido Generado por el Usuario ("CGU") incluyendo, sin limitación, contenido escrito, perfiles de Usuario, grabaciones de audio o visuales, gráficos por ordenador, imágenes, datos u otro contenido, incluida información personal. Todo el contenido es moderado. Si su CGU enviado es aprobado, se publicará en cualquier área pública del Servicio. Cuando se publica información, su CGU será "público" y podrá ser accedido por cualquier persona, incluyendo Kooth y nuestros Clientes. La información personal que pueda incluirse en el CGU no está sujeta a este aviso de privacidad. El CGU puede ser utilizado y compartido por Kooth, Clientes y terceros. Los Usuarios deben tener precaución al enviar CGU para su revisión de moderación y publicación. Para obtener más información sobre el CGU, consulte los Términos de Uso del Servicio.

Cookies y otras tecnologías de seguimiento

Kooth y sus Proveedores de Servicios recopilan automáticamente cierta información sobre usted, tal como se describe en la sección "Información que recopilamos". Esto puede incluir la dirección IP, el identificador del dispositivo, el tipo de dispositivo y navegador, el sistema operativo, la ubicación geográfica y otra información técnica. También recopilamos información sobre cómo interactúa su dispositivo con nuestros Servicios, como las funciones a las que se accedió, la URL, la hora en que visitó el sitio y los enlaces en los que hizo clic. Utilizamos esta información para comprender mejor qué contenido interesa a nuestros Usuarios y de dónde provienen. Recopilamos esta información mediante el uso de cookies y balizas web, como se describe a continuación.

Kooth puede colocar anuncios en sitios web de terceros. En un esfuerzo por supervisar el éxito de nuestra publicidad, podemos utilizar tecnología de seguimiento de identificación de visitantes, como las balizas web. Las balizas web cuentan los visitantes que llegan a los sitios web de Kooth después de ver un anuncio o banner en un sitio de terceros. A diferencia de las cookies, que se almacenan en el dispositivo del Usuario, las balizas web suelen estar incrustadas en las páginas web. Las balizas web no supervisan a los Usuarios una vez que han iniciado sesión en los Servicios.

Una cookie es un pequeño archivo que contiene una cadena de caracteres que se envía a su ordenador cuando visita un sitio web. Cuando vuelve a visitar el sitio, la cookie permite que ese sitio reconozca su navegador. Las cookies pueden almacenar las preferencias del usuario y otra información. Las cookies ofrecen la comodidad de ahorrarle tiempo o de indicar al servidor web que ha vuelto a una página específica.

Las cookies pueden caducar después de una sesión o durar más tiempo. Las fechas de caducidad se establecen en las propias cookies; algunas pueden caducar después de unos minutos, mientras que otras pueden hacerlo después de varios años. Las cookies instaladas por el sitio web que está visitando, es decir, Kooth, se denominan "cookies de origen". Las cookies de terceros se proporcionan en sitios web que no son de Kooth.

Existen varios tipos de cookies.

Podemos proporcionar enlaces a sitios web, plataformas, servicios y aplicaciones de terceros a través de los Servicios. Cuando hace clic en un enlace, el tercero puede utilizar sus propias cookies y tecnología de seguimiento para recopilar información suya. Una vez que se enlaza a otro sitio web desde los Servicios, está sujeto a los términos y condiciones de ese sitio web, incluyendo, entre otros, su aviso de privacidad en internet. La información recopilada, almacenada y compartida por terceros sigue estando sujeta a sus políticas y prácticas de privacidad, incluyendo si continúan compartiendo información con Kooth, los tipos de información compartida y sus elecciones sobre lo que es visible cuando interactúa con el sitio web de terceros. Kooth no es responsable de, y no hace ninguna declaración con respecto a, las políticas o prácticas comerciales de terceros.

No reconocemos las señales de "No rastrear" del navegador.

La mayoría de los navegadores le permiten controlar las cookies. Si prefiere no recibir cookies mientras navega por nuestro sitio web, puede configurar su navegador para que le avise antes de aceptar cookies y rechazar la cookie cuando su navegador le alerte de su presencia. Esto le permitirá decidir si desea aceptarla o no. Sin embargo, si limita la capacidad de los sitios web para establecer cookies, es posible que algunas funcionalidades no estén disponibles. Los fabricantes de navegadores proporcionan páginas de ayuda relacionadas con la gestión de cookies. Para obtener más información sobre cómo controlar y/o eliminar las cookies, consulte https://aboutcookies.org. Puede eliminar todas las cookies que ya están en su ordenador y configurar la mayoría de los navegadores para evitar que se instalen.

Acuity Ads

Google Tag Manager

Google Analytics

Seguimiento de conversiones de Google

Seguimiento de conversiones de Meta  

Microsoft Advertising

Pixel de Snapchat

Seguimiento de conversiones de TikTok

Remarketing de TikTok

CloudFare

Contentful

Hubspot CRM

Microsoft Advertising

Microsoft Clarity

Sentry

Meta Events Manager

Pinterest

Derechos de los Niños y de los Padres

Kooth realizará esfuerzos razonables para salvaguardar la confidencialidad de la información personal que procesamos. Utilizamos una combinación de controles de seguridad físicos, técnicos y administrativos para mantener la seguridad e integridad de la información de nuestros Usuarios. Esto ayuda a proteger contra cualquier amenaza a la confidencialidad, integridad y disponibilidad de su información. Los controles que tenemos implementados protegen contra el acceso o uso no autorizado de su información en nuestra posesión, lo que podría dañar o incomodar a nuestros Usuarios. Sin embargo, las transmisiones protegidas por tecnología de seguridad estándar de la industria e implementadas por seres humanos no pueden ser absolutamente seguras, y Kooth no garantiza la seguridad de su información recopilada a través del Servicio.

Este aviso de privacidad entra en vigor a partir de la fecha indicada en la parte superior del mismo. Podemos modificar este aviso de privacidad ocasionalmente y le informaremos de cualquier cambio sustancial a través del Servicio. Al acceder a nuestro Servicio después de que realicemos cualquier cambio en este aviso de privacidad, se considerará que ha aceptado dichos cambios. Consulte este aviso de privacidad regularmente para revisar cualquier actualización.

Recopilamos la información que nos proporciona cuando utiliza nuestros Servicios, tal como se describe en este aviso de privacidad. Parte de la PII puede eliminarla usted mismo dentro de los Servicios. Conservaremos otra PII mientras tenga una cuenta de Usuario. Debemos proteger y conservar estos datos para cumplir con la ley y los requisitos contractuales. El tiempo que conservamos la PII depende del tipo de PII y de la ley aplicable. Conservamos la PII durante el tiempo que sea necesario para cumplir el propósito para el que fue recopilada, a menos que la ley exija lo contrario o sea necesario para un fin comercial legítimo descrito en este aviso de privacidad. Al final del período de retención, eliminaremos la PII de nuestras bases de datos y solicitaremos a nuestros Socios Comerciales que eliminen la PII del Usuario de sus bases de datos, si corresponde. Si hay algún dato que no podamos eliminar completamente de nuestros sistemas por razones técnicas, continuaremos protegiendo su información según nuestros más altos estándares y evitaremos cualquier procesamiento posterior de sus datos. Podemos conservar los datos anonimizados indefinidamente.

Leyes de Privacidad Estatales

Residentes de California

*No vendemos su información personal por dinero. Contratamos con socios de confianza para servicios que nos ayudan a operar nuestro sitio web. Nuestros socios reciben información web básica (dirección IP, ID de dispositivo, etc.). La ley de California aplica el término 'venta' a este tipo de intercambio rutinario de datos, independientemente de si se realiza una transacción financiera. Por contrato, nuestros socios están estrictamente limitados a usar sus datos solo para realizar su trabajo específico para nosotros.

Sección 1798.140(ad) del Código Civil de California

‍

Residentes de Nueva Jersey

*No vendemos su información personal por dinero. Contratamos con socios de confianza para servicios que nos ayudan a operar nuestro sitio web. Nuestros socios reciben información web básica (dirección IP, ID de dispositivo, etc.). La ley de Nueva Jersey puede aplicar el término "venta" a este tipo de intercambio rutinario de datos, independientemente de si se produce una transacción financiera. Por contrato, nuestros socios están estrictamente limitados a usar sus datos solo para realizar su trabajo específico para nosotros.

NJ Rev Stat § 56:8-166.4

Ejercicio de sus derechos

Para solicitar la desactivación de la cuenta, vaya a Mi cuenta en la Configuración de la aplicación Soluna y seleccione Desactivar mi cuenta. Tenga en cuenta que la desactivación de su cuenta puede tardar hasta 30 días en procesarse.

Para enviar una solicitud para acceder a su información, los Usuarios del Servicio pueden ponerse en contacto con nosotros en privacy@kooth.com.

Para ejercer su derecho a oponerse al procesamiento de su información o cualquier otro derecho no mencionado en esta sección, puede ponerse en contacto con nosotros en privacy@kooth.com.

Acceso y cambio de información

Kooth puede ofrecerle formas de eliminar, corregir o actualizar parte de su información personal. Kooth hará esfuerzos de buena fe para realizar los cambios solicitados en las bases de datos de Kooth tan pronto como sea posible, pero no siempre es posible cambiar, eliminar o suprimir completamente toda su información o publicaciones públicas de las bases de datos de Kooth (los menores de California pueden consultar la sección de privacidad de los niños y controles parentales). Además, nos reservamos el derecho de conservar los datos (a) según lo exija la ley aplicable; y (b) durante el tiempo que sea razonablemente necesario para cumplir los fines para los que se conservan los datos, salvo en la medida en que lo prohíba la ley aplicable.

Responsabilidad

Si tiene alguna pregunta sobre este aviso de privacidad, puede ponerse en contacto con nuestra Oficial de Privacidad, Rachel Thompson, escribiendo a Kooth: A la atención de: Rachel Thompson 1 South Dearborn Street Chicago, IL, 60607, llamando sin cargo al (844) 582-2111, o por correo electrónico a privacy@kooth.com.

Si un Cliente elige utilizar los servicios de Kooth, la acción del Cliente se considera por la presente como una aceptación de las prácticas de Kooth descritas en este aviso y en los Términos de Uso.

1. Guest Account

Data CollectedPurposeLegal BasisRequired
Terms of ServiceTo confirm your eligibility to access the Service (example: a region or employer).Contractual Necessity: Processing is necessary to deliver the service you sign up for.Yes
Your Location or ProviderTo confirm your eligibility to access the Service, we collect your Town and/or City.Contractual Necessity: Processing is necessary to deliver the service you sign up for.Yes
Full Date of BirthTo confirm you are within the age range is a critical safety and governance requirement (Day/Month/Year).Contractual Necessity: For service delivery and Legitimate Interests for internal safeguarding.Yes
Research ConsentTo allow anonymised, aggregated user behaviour and trend data to be used by Kooth's research teams to publish academic insights and improve systemic mental health frameworks.Explicit Consent: Completely optional and freely given, users can decline or change your mind at a later date without restrictions on app features.No
Heard AboutTo track the efficacy of our marketing campaigns and understand which outreach paths are successfully connecting vulnerable populations to the service.Legitimate InterestsNo
MarketingTo measure the effectiveness of our paid marketing campaigns and track how users discover and install the app.Explicit ConsentNo
Analytics and PerformanceTo monitor how the app performs for real users, record crashes and errors so our engineers can fix them, and collect anonymous data to inform future feature development.Explicit ConsentNo

2. Full Account

A Full Account will require all of the above Data Collections as well as the below:

Data CollectedPurposeLegal BasisRequired
Email Address (Gmail, Apple, or Manual)To uniquely identify the user account, enable secure cross-device synchronisation, facilitate password resets, and provide critical service or safeguarding updates.Contractual Necessity: Essential to create, secure, and maintain the account infrastructure requested by the user.Yes
UsernameTo provide a non-identifiable, pseudononymous handle for the user within the app, protecting their real-world identity during interactions with the platform.Contractual Necessity: Necessary to deliver the core pseudononymous service model defined in our Terms of Service.Yes
PasswordTo securely authenticate the user's identity upon login and protect their sensitive therapeutic history from unauthorised third-party access.Contractual Necessity: Necessary to fulfil our security obligations under the user agreement and enforce account safety.Yes
Your Gender IdentityTo analyse the Service uptake and ensure our digital content and clinical outreach are equal. Is Special Category DataExplicit ConsentYes
Your EthnicityTo measure diversity in service access and outcomes, helping us address potential health inequalities in the communities we serve. Is Special Category DataExplicit ConsentYes

"Special Category Data" is personal information so sensitive that it requires extra legal protection, as mishandling it could lead to discrimination or harm. This includes highly private details like your medical history, genetic info, race, religious beliefs, and sexual orientation. By providing this optional Special Category Data, you are giving us Explicit Consent to process it for the purposes listed above. You may withdraw this consent at any time by following the steps in the "Your Rights" section below.

Referrals to Us from External Services or Third Parties

Sometimes, Users are referred to our service by an external organisation or professional, such as your General Practitioner (GP), a commissioned school, or other health and social care services you may have been working with. These organisations are the source of your data and provide us with limited information to ensure a safe clinical handover.

Categories of Data Received

Upon referral, we receive the following Personal Data and Special Category Data (Health Data) from the referring source:

  1. Identity: Your first name, surname, date of birth, NHS number, ethnicity, and gender.
  2. Source: The name of the specific organisation or User who made the referral.
  3. Context: A brief, high-level summary of the reason for the referral, your history and/or the service you were previously accessing.
  4. Contact: Your contact information (phone and/or email), if explicitly provided for the purpose of initiating contact with Kooth.

Legal Basis and Purposes of Processing

We process this referral data based on our legal and clinical obligations. We use this information to serve your best interests and ensure safety from the moment you access Kooth.

Data TypeLegal BasisPurpose of Use
Special Category Data (Health Data)Provision of Health CareTo ensure the Service is clinically appropriate and safe for your specific needs, and to support continuity of care.
General Personal DataContractual NecessityTo register your account, verify your eligibility under the specific commissioning contract, and manage the administrative record of your joining the service.

Storage and Access

This referral information is treated with the highest level of confidentiality. It is stored in a secure, restricted area of your account and our case management platform, visible only to authorised clinical and safeguarding team members who require this information for clinical and operational purposes. This information is used strictly for:

  • Clinical Handover: Providing our practitioners with the necessary context for the start of your care.
  • Registration and Eligibility: Finalising your sign-up and service confirmation.
  • Safeguarding: Enabling the quick and appropriate response to any immediate risks of harm to yourself or others, as detailed in our dedicated Safeguarding Policy.

What other Personal Data we may hold

This section details how we handle personal information that a SU shares with us beyond the mandatory registration or clinical data.

Loss of Pseudonymous Status

The Service is designed to allow you to engage with us pseudonymously (without revealing your true, real-world identity). Any Personal Data or internal website search queries you provide are stored against your confidential profile within our platform.

For example, when engaging with the community, if you voluntarily or involuntarily disclose your identifiable Personal Data while using the Services, our moderators will ensure this information is not published. They may message you to discuss how to amend the post to protect your privacy. If this happens, you will lose your pseudonymous status, meaning that:

  • Data Storage: This identifiable data remains linked to your profile, even if it is removed from public view.

Local Data Storage

How we use your local data storage and similar tracking technologies on our digital platforms and website.

Your Consent and Control

We divide this into categories based on their purpose.

CategoryConsent RequirementDefault Setting
Strictly NecessaryNo Consent RequiredAlways Active
Non-EssentialExplicit Consent RequiredOff by Default

Categories Used

Strictly Necessary (Essential for Safety and Service)

These are mandatory for the website to function correctly and securely. They are automatically set when you access the platform and cannot be turned off in our systems.

PackagePurposeLegal Basis
Auth0 (@auth0/auth0-spa-js, react-native-auth0)Enables user sign-in / sign-up and authenticationContractual Necessity (to provide the requested service); Legitimate Interests (to secure the platform)
Expo Updates (expo-updates)Delivers new versions of the app over the air. Required for security updates, etc.Legitimate Interests (maintaining the performance and security of the service)
Contentful (contentful)Delivers app contentContractual Necessity (necessary to deliver the content the user requested)
React Native Encrypted StorageStores app data securely on the device on iOS/AndroidContractual Necessity (necessary to safely provide the core app functionality)
AsyncStorageStores app data securely on the device on iOS/Android (used for non-secret items only)Contractual Necessity (necessary to provide the core app functionality)
@auth0/auth0-spa-js cache on web appHolds the user's sign-in tokens on the webContractual Necessity and Legitimate Interests (platform security)
Expo Device, Application, Localisation, NetworkReads device model, OS version, app version, language, network typeLegitimate Interests (understanding the technical needs of users to maintain performance)
Jail MonkeyDetects if the phone has been jailbroken/rooted (for safety & security)Legitimate Interests (maintaining the security of the app and safeguarding user data)
React Native WebViewRenders interactive tools (breathing exercises, etc.)Contractual Necessity (necessary to deliver the interactive service requested by the user)

Non-Essential (Performance and Analytics)

These track your activity to help us understand how the service is being used so we can improve it. These are only set if you affirmatively provide your consent.

PackagePurposeTypeLegal Basis and Consent Required
AppsFlyer (react-native-appsflyer)Measurement of paid marketing campaign performance and attributionMarketingExplicit Consent — Yes
Braze (@braze/react-native-sdk)Sends push notifications and engagement messages, and in-app notifications displayed in notifications centreFunctional, e.g. appointment reminders and safety messages; Targeting, e.g. promoting new content/featuresExplicit Consent — No, only captures data if the user enables notifications in their device settings
Datadog (@datadog/mobile-react-native, session-replay, expo-datadog)Tells our engineers how the app is performing for real usersPerformance / AnalyticsExplicit Consent — Yes
Sentry (@sentry/react-native, @sentry/browser)Records crashes and errors so we can fix themStrictly necessary — crash reporting; Performance — performance tracingExplicit Consent — Yes, not possible to manage consent at a more granular level to enable crash reporting, but not performance tracing
Expo Calendar (expo-calendar)Adds scheduled chats to the user's calendarFunctionalExplicit Consent — No, optional feature is initiated by the user
Expo Local Authentication (expo-local-authentication)Lets the user unlock the app with Face ID / Touch ID / fingerprintFunctionalExplicit Consent — No, optional feature is initiated by the user
Expo Store ReviewAsks the user to rate the app - enables user feedback (positive and negative)FunctionalExplicit Consent — No, optional feature is initiated by the user

How We Share Your Personal Data

Our primary commitment is to confidentiality. However, as a clinical service, we have a legal and professional Duty of Care to safeguard your wellbeing. This means there are strict, legally defined circumstances where we must break confidentiality.

When a life is at risk, our legal duty allows us to override confidentiality and share your data without your consent. This action is justified under two conditions of the UK GDPR Article 9 (Processing of Special Category Health Data):

  1. Vital Interests (Article 9(2)(c)): Processing necessary to protect your life or the life of another person when you are physically or legally incapable of giving consent.
  2. Substantial Public Interest (Article 9(2)(g)): Processing necessary for reasons of public interest in the area of health and social care, in line with relevant UK legislation.

When Confidentiality Must Be Broken

If, following a clinical assessment, our practitioners determine there is a serious and immediate risk of harm, we will act to ensure appropriate services outside Kooth are aware of the situation. This occurs if:

  • Your life is at immediate risk due to your own actions.
  • You are at serious risk of harm from somebody else.
  • You pose a serious risk of harm to somebody else.

The Role of Consent and Override

Our practitioners will always seek your informed consent to share your details to refer you to the appropriate external services.

However, if you withhold consent and our practitioner determines that a serious and immediate safeguarding risk exists, our overriding legal Duty of Care, justified by Vital Interests and Substantial Public Interest, allows us to share the necessary information even without your consent.

Our Commitment When Action is Taken

In all cases where we must break confidentiality:

  1. We will only share the minimum necessary personal information and clinical context required to enable the relevant external agency to take appropriate action.
  2. We will let you know who we are passing details to and why.
  3. Where possible, we will work with you to agree on every step taken.

In extreme cases, if the situation is so serious that discussing the matter with you would increase the risk of harm or if you become unresponsive during a critical period, we may have to take immediate action by contacting emergency services or local safeguarding teams.

Data Sharing and Anonymisation

We share reports with the organisations that fund our service (our Commissioners) to demonstrate service usage and community outcomes.

  • De-Identification: Before any data leaves Kooth, it is de-identified and aggregated. This means data is grouped into large categories (for example, total registrations in a specific age range) and is stripped of any direct identifiers.
  • No Identification: This shared data will never identify a User or allow any commissioning organisation to trace or find you. It is used exclusively for strategic analysis, such as:
    • Total number of new registrations.
    • App usage and engagement levels.
    • Trends in issues faced by SUs.
    • Measurement of clinical outcomes achieved by the community.

Research and Third Parties

We use your data, and the data of our wider community, to continuously improve the quality and effectiveness of the Service.

We maintain a strict commitment to your privacy in all research activities:

  • All data provided to research partners is completely anonymised. It does not contain any Personal Data that could identify you.
  • No identifiable information is shared for research purposes without your separate, explicit written consent.

Researchers working with us (including those from universities) must obtain ethical approval for their work, and their projects are subject to strict data-sharing agreements to protect your privacy.

If you would like to learn more about how we use data for research, you can find our research team contact details in the Contract section below.

Data for Service Improvement and Research

We sometimes work with trusted external partners, including universities, NHS organisations, and other clinical bodies. These partners assist us in analysing trends and patterns within our data to improve clinical outcomes and service quality for all users.

Data Provided to Partners

The data we share with these partners is a mixture of statistical metrics and clinical usage information you have provided to us. This may include:

  • Statistics: Aggregated data on age, ethnicity, and gender of Users in specific regions.
  • Clinical and Usage Data: Information such as goals, assessments, usage metrics, and patterns of engagement.
  • Public Content: Information shared publicly within the Service (e.g., forum posts and comments) after it has been fully moderated.
  • Private Content: Pseudonymised communication with the counselling team through chat or messaging the team inbox.

Third-Party Service Providers

To provide a comprehensive service, we sometimes use third-party services to help us with functions we do not conduct internally, including but not limited to cloud hosting, specialised security monitoring, or surveys.

Each third-party service provider must pass our strict security and privacy assessments and is bound by legally enforceable contracts to ensure they handle your data in accordance with the UK GDPR and our internal standards.

Case Studies

We are committed to continuous improvement, which requires responsible data utilisation across two channels:

  1. Reporting: We create and share anonymous performance reports and case studies with the organisations that fund the Service to validate our effectiveness and demonstrate our impact.
  2. Training: Our team engages in mandatory professional development and training. Practitioners compile internal case studies to enhance their skills and ensure the highest quality of support.

We assure you that no case study, internal or external, will ever contain personal data that could identify you. Your anonymity is maintained throughout this process.

Where is Your Data Stored

All information is stored securely within the Kooth Practitioner Platform (Omega, our case management platform) and is only accessible to the Kooth Team Members. Our systems are encrypted (coded, which ensures your data is protected) both where data is stored and where it is transferred between the user and our systems and within our system. We use Google Cloud Platform's europe-west-2 region for hosting (London, UK). Our data is hosted in the Europe-West-2 region (London) of the Google Cloud Platform.

Your Data Rights

As the Data Subject of your personal information, you have specific rights under the General Data Protection Regulation (GDPR) regarding how we process your data. We are committed to helping you exercise these rights securely and efficiently.

Your RightDescriptionOur Application and Limitations
The Right to be InformedThe right to know how your personal data is collected and used.We satisfy this right by providing you with this complete Privacy Policy document.
The Right of AccessYou can ask us for a copy of the personal data we hold about you. This is known as a Data Subject Access Request (DSAR).We will provide this data free of charge and within the mandated legal timeframe.
The Right to RectificationYou can notify us if the data we hold is inaccurate or incomplete and ask us to correct it immediately.We will correct any factual errors as quickly as possible upon verification.
The Right to ErasureYou can request the deletion or removal of your personal data.We have a Legal Obligation and a Substantial Public Interest to retain certain data for a defined period for clinical safeguarding and legal accountability. We cannot delete this essential data until its required retention period expires. Further information can be found in the "Account Deletion" section below.
The Right to Restrict ProcessingYou can ask us to temporarily pause or limit the processing of your data while its accuracy is checked or if there is a legal dispute about our reason for processing it.We will flag your record and restrict processing immediately upon request while the dispute is resolved.
The Right to Data PortabilityYou can ask us to securely transfer the personal data you have provided to us to another service provider (Data Controller) in a commonly used format.This right only applies to data processed by automated means based on your Consent or Contractual Necessity.
The Right to ObjectYou can object to the processing of your data where we are relying on its Legitimate Interests or Public Task as the legal basis for processing.We will cease processing unless we can demonstrate compelling and overriding legal grounds for continuation.

Exercising Your Rights Securely

Where we rely on your consent to process your personal data (outlined above), you have the right to withdraw that consent at any time.

You can manage your preferences and withdraw your consent by:

  • In-App Controls: Navigating to your profile settings:
    1. Rescind research consent
    2. Deactivate your account
    3. Remove optional data sharing in the "about me" section of your profile
  • Contacting Us Directly: Send an email to our Data Protection Officer at (contact information found below). If you choose to contact us externally, we will just need to take a few secure steps to verify your identity before actioning your request.

Withdrawing your consent will not affect the lawfulness of any data processing we carried out before your withdrawal. Withdrawing your research consent or deactivating your account will not automatically result in the immediate erasure of all your data. Because we provide health and well-being services, we are under strict legal, regulatory, and contractual obligations to securely retain certain records (including your health data and clinical notes) for minimum specified periods. For full details on how long we are required to keep your information after you withdraw consent, please view our Retention Period below.

If you believe that we have failed to handle your data properly or have not respected the rights listed above, you can make a formal complaint to the Information Commissioner's Office (ICO).

External Sites

If you choose to follow links from Kooth to third-party websites, you should know that our Privacy Policy no longer applies. Since we have no control over these external sites, we strongly recommend that users consult the third party's own privacy policy before continuing.

Account Management

This section covers essential topics related to your account, including our forgotten login details, our data retention period, and the procedures for account deletion.

Forgotten Logins

Creating a Full Account requires an email address, which allows you to securely reset your password if you ever forget it. However, if you use a Guest Account, we cannot reset your login details. If you log out of a guest account, you will lose access completely and need to create a new one.

Retention Period

We only keep your personal data for as long as necessary to provide our services and ensure we meet our legal and safeguarding obligations. In most cases, records are kept from the Users last interaction with the Service. Below is a table of our retention period.

User Type and AgeRetention Period
Online and Face-to-Face Counselling records - under 1810 years after the User turns 18. Records are kept till the last day of the month.
Online and Face-to-Face Counselling records - under 18, where child sexual abuse has been notedIndefinite
Online counselling records - 18 plus10-year retention period starts at the point of the last interaction recorded on the Service user's account.
Online and Face-to-Face Counselling records - 18 plus, where child sexual abuse has been notedIndefinite
User accounts information10-year retention period starts at the point of the last interaction recorded on the Service user's account.

Account Deletion

When you request account deletion, due to the nature of our service we may be unable to fulfil your request at that time.

  • We Deactivate, Not Delete: For clinical safety, governance, and legal accountability, we do not immediately delete account data. Instead, we deactivate your account, making it immediately inaccessible.
  • Data Retention: Your personal data is then securely archived in accordance with the above data retention schedule, after which it will be permanently deleted. This process is required to ensure we meet our legal obligations and Substantial Public Interest requirements for health and safeguarding purposes.

How to Request Deactivation

  1. Log in to your Soluna account.
  2. Go to your profile, then settings, and click the Deactivate my account button.

Our team will then verify the request and process the deactivation.

Important Warning: Once this request has been made, you will no longer have access to your account.

Further Information

Data Minimisation

Processing your data is necessary for our legitimate interests or the legitimate interests of a third party, as long as your rights and interests do not outweigh those interests. Our legitimate interests include:

  • Communicating in response to enquiries
  • Communicating relevant information to existing or potential users
  • Understanding the interests and needs of our website users
  • Maintaining the performance and security of our website and other services

Rights in Relating to Automation

We may use Machine Learning (ML) or Artificial Intelligence (AI) to improve our processes and user experience. These technologies also help us better understand our service users and improve outcomes. AI/ML may make decisions automatically. Examples are:

  • Content suggestions based on a service user's previous usage or
  • Matching a service user with an available practitioner based on selected criteria or focus areas

We may use the data we collect to measure our performance and improve our service.

Contacts:

Kooth Digital Health Limited is a data controller. Our registered office is 5 Merchant Square, London, W2 1AY.

Contact DetailType of Request
dpo@kooth.comIf you have any data or privacy-related issues.
complaints@kooth.comIf you or anybody you care for or support is dissatisfied with our Service, please contact us here. We are always trying to improve our Service, and addressing and learning from feedback is one way we can do this.
safeguarding@kooth.comGet in touch with our safeguarding team here to raise concerns or report risks to users of our services (staffed 9-5 Mon-Fri; always use 999 for police/ambulance in emergencies).
contact@kooth.comHere for anything else, general questions or feedback.
research@kooth.comAny research-related inquiries.

Privacy Notice Changes

We will revise our Privacy and Safety Policy as necessary, for example, if the purpose of data collection changes. We encourage you to check back on the Privacy Policy for any future changes.

Tu espacio para desestresarse, recuperarte y recargar energías.

¿En crisis?

Llama al 988

para obtener ayuda urgente

Explorar

  • Counselling
  • Peer Support
  • Entrenamiento
  • Carreras profesionales

Resources

  • Parents & Families
  • Schools
  • Community Partners

About

  • About Us
  • Approach
  • Trust & Saftey
  • Impact
  • Careers

Legal

  • Política de privacidad
  • Términos y condiciones
  • Accessibility Statement

©2025 Kooth. Todos los derechos reservados.

Para obtener asistencia con la aplicación, preguntas o asesoramiento telefónico, utilice nuestro widget de chat o contáctenos por teléfono llamando al (844) 582-2111 (llamada gratuita). Los chats recibidos entre las 10 p. m. y las 10 a. m. PST serán respondidos al día siguiente. Si desea compartir comentarios, Nos encantaría saber de usted.

AICPA SOC for Service Organizations
ISO/IEC 27001 Certified - Information Security Management

Obtén la aplicación web de Soluna

Acabamos de lanzar la nueva versión web de nuestra aplicación. Puedes descargarla gratis desde tu navegador. ¡Solo tienes que hacer clic abajo!

Descarga la aplicación web ahora

Descarga la aplicación móvil de Soluna

Escanea el código QR para descargar la aplicación

Código QR de la aplicación

o busca en la tienda de aplicaciones de tu móvil:

Soluna: Atención a la salud mental

Descubre más