Skip to main content
Soluna Logo
  • Explore
    CounsellingPeer SupportContent & ToolsSoluna Stories
  • Resources
    Parents & FamiliesSchools & DistrictsCommunity Partners
  • About
    About UsApproachTrust & SafetyImpact
  • Contact Center
  • EN
    English
    Spanish

Your Privacy and Saftey

Updated 30 July, 2026

Kooth Digital Health Limited (“Kooth”) offers an easy-to-access online mental health services platform designed to work alongside you, providing compassionate and effective support. Our goal is to create a welcoming space for personalised digital mental healthcare. Note that other Kooth Services may be governed by privacy notices containing different information practices applicable to those sites and Services.

What is this Document?

Kooth is proud to have developed the Soluna application (“App”), available on iOS, Android and Web (“Soluna”). This Privacy Policy outlines what information we collect about you, how we use it, and when we might share information about you, the service user (the ”Users”) on Soluna. It also details your options for managing your data. We also developed a website, solunaapp.com, in connection with the services we provide (collectively the “Services”).

When you use and access our Services, you accept and agree to the Terms of Use and this Privacy Policy, including that we may share certain data with Third-Party Service Providers. If you do not feel comfortable with any part of this Policy, you must not use or access our Services.

What Information do we Collect from You and Why?

When creating a Soluna account, you will have the option to either use a (“Guest Account”) or a “Full Account”). The type of account you choose directly determines what personal information we collect and store locally on your device. If you choose a Guest Account, you can access Soluna’s self-directed content and resources without providing any directly identifiable personal data. If you choose a Full Account, you unlock all the Soluna features, including 121 practitioner support, participation in the peer community, tracked goal-setting and journalling.

Below is the information we collect:

1. Guest Account

Data CollectedPurposeLegal BasisRequired
Terms of ServiceTo confirm your eligibility to access the Service (example: a region or employer).Contractual Necessity: Processing is necessary to deliver the service you sign up for.Yes
Your Location or ProviderTo confirm your eligibility to access the Service, we collect your Town and/or City.Contractual Necessity: Processing is necessary to deliver the service you sign up for.Yes
Full Date of BirthTo confirm you are within the age range is a critical safety and governance requirement (Day/Month/Year).Contractual Necessity: For service delivery and Legitimate Interests for internal safeguarding.Yes
Research ConsentTo allow anonymised, aggregated user behaviour and trend data to be used by Kooth's research teams to publish academic insights and improve systemic mental health frameworks.Explicit Consent: Completely optional and freely given, users can decline or change your mind at a later date without restrictions on app features.No
Heard AboutTo track the efficacy of our marketing campaigns and understand which outreach paths are successfully connecting vulnerable populations to the service.Legitimate InterestsNo
MarketingTo measure the effectiveness of our paid marketing campaigns and track how users discover and install the app.Explicit ConsentNo
Analytics and PerformanceTo monitor how the app performs for real users, record crashes and errors so our engineers can fix them, and collect anonymous data to inform future feature development.Explicit ConsentNo

2. Full Account

A Full Account will require all of the above Data Collections as well as the below:

Data CollectedPurposeLegal BasisRequired
Email Address (Gmail, Apple, or Manual)To uniquely identify the user account, enable secure cross-device synchronisation, facilitate password resets, and provide critical service or safeguarding updates.Contractual Necessity: Essential to create, secure, and maintain the account infrastructure requested by the user.Yes
UsernameTo provide a non-identifiable, pseudononymous handle for the user within the app, protecting their real-world identity during interactions with the platform.Contractual Necessity: Necessary to deliver the core pseudononymous service model defined in our Terms of Service.Yes
PasswordTo securely authenticate the user's identity upon login and protect their sensitive therapeutic history from unauthorised third-party access.Contractual Necessity: Necessary to fulfil our security obligations under the user agreement and enforce account safety.Yes
Your Gender IdentityTo analyse the Service uptake and ensure our digital content and clinical outreach are equal. Is Special Category DataExplicit ConsentYes
Your EthnicityTo measure diversity in service access and outcomes, helping us address potential health inequalities in the communities we serve. Is Special Category DataExplicit ConsentYes

"Special Category Data" is personal information so sensitive that it requires extra legal protection, as mishandling it could lead to discrimination or harm. This includes highly private details like your medical history, genetic info, race, religious beliefs, and sexual orientation. By providing this optional Special Category Data, you are giving us Explicit Consent to process it for the purposes listed above. You may withdraw this consent at any time by following the steps in the "Your Rights" section below.

Referrals to Us from External Services or Third Parties

Sometimes, Users are referred to our service by an external organisation or professional, such as your General Practitioner (GP), a commissioned school, or other health and social care services you may have been working with. These organisations are the source of your data and provide us with limited information to ensure a safe clinical handover.

Categories of Data Received

Upon referral, we receive the following Personal Data and Special Category Data (Health Data) from the referring source:

  1. Identity: Your first name, surname, date of birth, NHS number, ethnicity, and gender.
  2. Source: The name of the specific organisation or User who made the referral.
  3. Context: A brief, high-level summary of the reason for the referral, your history and/or the service you were previously accessing.
  4. Contact: Your contact information (phone and/or email), if explicitly provided for the purpose of initiating contact with Kooth.

Legal Basis and Purposes of Processing

We process this referral data based on our legal and clinical obligations. We use this information to serve your best interests and ensure safety from the moment you access Kooth.

Data TypeLegal BasisPurpose of Use
Special Category Data (Health Data)Provision of Health CareTo ensure the Service is clinically appropriate and safe for your specific needs, and to support continuity of care.
General Personal DataContractual NecessityTo register your account, verify your eligibility under the specific commissioning contract, and manage the administrative record of your joining the service.

Storage and Access

This referral information is treated with the highest level of confidentiality. It is stored in a secure, restricted area of your account and our case management platform, visible only to authorised clinical and safeguarding team members who require this information for clinical and operational purposes. This information is used strictly for:

  • Clinical Handover: Providing our practitioners with the necessary context for the start of your care.
  • Registration and Eligibility: Finalising your sign-up and service confirmation.
  • Safeguarding: Enabling the quick and appropriate response to any immediate risks of harm to yourself or others, as detailed in our dedicated Safeguarding Policy.

What other Personal Data we may hold

This section details how we handle personal information that a SU shares with us beyond the mandatory registration or clinical data.

Loss of Pseudonymous Status

The Service is designed to allow you to engage with us pseudonymously (without revealing your true, real-world identity). Any Personal Data or internal website search queries you provide are stored against your confidential profile within our platform.

For example, when engaging with the community, if you voluntarily or involuntarily disclose your identifiable Personal Data while using the Services, our moderators will ensure this information is not published. They may message you to discuss how to amend the post to protect your privacy. If this happens, you will lose your pseudonymous status, meaning that:

  • Data Storage: This identifiable data remains linked to your profile, even if it is removed from public view.

Local Data Storage

How we use your local data storage and similar tracking technologies on our digital platforms and website.

Your Consent and Control

We divide this into categories based on their purpose.

CategoryConsent RequirementDefault Setting
Strictly NecessaryNo Consent RequiredAlways Active
Non-EssentialExplicit Consent RequiredOff by Default

Categories Used

Strictly Necessary (Essential for Safety and Service)

These are mandatory for the website to function correctly and securely. They are automatically set when you access the platform and cannot be turned off in our systems.

PackagePurposeLegal Basis
Auth0 (@auth0/auth0-spa-js, react-native-auth0)Enables user sign-in / sign-up and authenticationContractual Necessity (to provide the requested service); Legitimate Interests (to secure the platform)
Expo Updates (expo-updates)Delivers new versions of the app over the air. Required for security updates, etc.Legitimate Interests (maintaining the performance and security of the service)
Contentful (contentful)Delivers app contentContractual Necessity (necessary to deliver the content the user requested)
React Native Encrypted StorageStores app data securely on the device on iOS/AndroidContractual Necessity (necessary to safely provide the core app functionality)
AsyncStorageStores app data securely on the device on iOS/Android (used for non-secret items only)Contractual Necessity (necessary to provide the core app functionality)
@auth0/auth0-spa-js cache on web appHolds the user's sign-in tokens on the webContractual Necessity and Legitimate Interests (platform security)
Expo Device, Application, Localisation, NetworkReads device model, OS version, app version, language, network typeLegitimate Interests (understanding the technical needs of users to maintain performance)
Jail MonkeyDetects if the phone has been jailbroken/rooted (for safety & security)Legitimate Interests (maintaining the security of the app and safeguarding user data)
React Native WebViewRenders interactive tools (breathing exercises, etc.)Contractual Necessity (necessary to deliver the interactive service requested by the user)

Non-Essential (Performance and Analytics)

These track your activity to help us understand how the service is being used so we can improve it. These are only set if you affirmatively provide your consent.

PackagePurposeTypeLegal Basis and Consent Required
AppsFlyer (react-native-appsflyer)Measurement of paid marketing campaign performance and attributionMarketingExplicit Consent — Yes
Braze (@braze/react-native-sdk)Sends push notifications and engagement messages, and in-app notifications displayed in notifications centreFunctional, e.g. appointment reminders and safety messages; Targeting, e.g. promoting new content/featuresExplicit Consent — No, only captures data if the user enables notifications in their device settings
Datadog (@datadog/mobile-react-native, session-replay, expo-datadog)Tells our engineers how the app is performing for real usersPerformance / AnalyticsExplicit Consent — Yes
Sentry (@sentry/react-native, @sentry/browser)Records crashes and errors so we can fix themStrictly necessary — crash reporting; Performance — performance tracingExplicit Consent — Yes, not possible to manage consent at a more granular level to enable crash reporting, but not performance tracing
Expo Calendar (expo-calendar)Adds scheduled chats to the user's calendarFunctionalExplicit Consent — No, optional feature is initiated by the user
Expo Local Authentication (expo-local-authentication)Lets the user unlock the app with Face ID / Touch ID / fingerprintFunctionalExplicit Consent — No, optional feature is initiated by the user
Expo Store ReviewAsks the user to rate the app - enables user feedback (positive and negative)FunctionalExplicit Consent — No, optional feature is initiated by the user

How We Share Your Personal Data

Our primary commitment is to confidentiality. However, as a clinical service, we have a legal and professional Duty of Care to safeguard your wellbeing. This means there are strict, legally defined circumstances where we must break confidentiality.

When a life is at risk, our legal duty allows us to override confidentiality and share your data without your consent. This action is justified under two conditions of the UK GDPR Article 9 (Processing of Special Category Health Data):

  1. Vital Interests (Article 9(2)(c)): Processing necessary to protect your life or the life of another person when you are physically or legally incapable of giving consent.
  2. Substantial Public Interest (Article 9(2)(g)): Processing necessary for reasons of public interest in the area of health and social care, in line with relevant UK legislation.

When Confidentiality Must Be Broken

If, following a clinical assessment, our practitioners determine there is a serious and immediate risk of harm, we will act to ensure appropriate services outside Kooth are aware of the situation. This occurs if:

  • Your life is at immediate risk due to your own actions.
  • You are at serious risk of harm from somebody else.
  • You pose a serious risk of harm to somebody else.

The Role of Consent and Override

Our practitioners will always seek your informed consent to share your details to refer you to the appropriate external services.

However, if you withhold consent and our practitioner determines that a serious and immediate safeguarding risk exists, our overriding legal Duty of Care, justified by Vital Interests and Substantial Public Interest, allows us to share the necessary information even without your consent.

Our Commitment When Action is Taken

In all cases where we must break confidentiality:

  1. We will only share the minimum necessary personal information and clinical context required to enable the relevant external agency to take appropriate action.
  2. We will let you know who we are passing details to and why.
  3. Where possible, we will work with you to agree on every step taken.

In extreme cases, if the situation is so serious that discussing the matter with you would increase the risk of harm or if you become unresponsive during a critical period, we may have to take immediate action by contacting emergency services or local safeguarding teams.

Data Sharing and Anonymisation

We share reports with the organisations that fund our service (our Commissioners) to demonstrate service usage and community outcomes.

  • De-Identification: Before any data leaves Kooth, it is de-identified and aggregated. This means data is grouped into large categories (for example, total registrations in a specific age range) and is stripped of any direct identifiers.
  • No Identification: This shared data will never identify a User or allow any commissioning organisation to trace or find you. It is used exclusively for strategic analysis, such as:
    • Total number of new registrations.
    • App usage and engagement levels.
    • Trends in issues faced by SUs.
    • Measurement of clinical outcomes achieved by the community.

Research and Third Parties

We use your data, and the data of our wider community, to continuously improve the quality and effectiveness of the Service.

We maintain a strict commitment to your privacy in all research activities:

  • All data provided to research partners is completely anonymised. It does not contain any Personal Data that could identify you.
  • No identifiable information is shared for research purposes without your separate, explicit written consent.

Researchers working with us (including those from universities) must obtain ethical approval for their work, and their projects are subject to strict data-sharing agreements to protect your privacy.

If you would like to learn more about how we use data for research, you can find our research team contact details in the Contract section below.

Data for Service Improvement and Research

We sometimes work with trusted external partners, including universities, NHS organisations, and other clinical bodies. These partners assist us in analysing trends and patterns within our data to improve clinical outcomes and service quality for all users.

Data Provided to Partners

The data we share with these partners is a mixture of statistical metrics and clinical usage information you have provided to us. This may include:

  • Statistics: Aggregated data on age, ethnicity, and gender of Users in specific regions.
  • Clinical and Usage Data: Information such as goals, assessments, usage metrics, and patterns of engagement.
  • Public Content: Information shared publicly within the Service (e.g., forum posts and comments) after it has been fully moderated.
  • Private Content: Pseudonymised communication with the counselling team through chat or messaging the team inbox.

Third-Party Service Providers

To provide a comprehensive service, we sometimes use third-party services to help us with functions we do not conduct internally, including but not limited to cloud hosting, specialised security monitoring, or surveys.

Each third-party service provider must pass our strict security and privacy assessments and is bound by legally enforceable contracts to ensure they handle your data in accordance with the UK GDPR and our internal standards.

Case Studies

We are committed to continuous improvement, which requires responsible data utilisation across two channels:

  1. Reporting: We create and share anonymous performance reports and case studies with the organisations that fund the Service to validate our effectiveness and demonstrate our impact.
  2. Training: Our team engages in mandatory professional development and training. Practitioners compile internal case studies to enhance their skills and ensure the highest quality of support.

We assure you that no case study, internal or external, will ever contain personal data that could identify you. Your anonymity is maintained throughout this process.

Where is Your Data Stored

All information is stored securely within the Kooth Practitioner Platform (Omega, our case management platform) and is only accessible to the Kooth Team Members. Our systems are encrypted (coded, which ensures your data is protected) both where data is stored and where it is transferred between the user and our systems and within our system. We use Google Cloud Platform's europe-west-2 region for hosting (London, UK). Our data is hosted in the Europe-West-2 region (London) of the Google Cloud Platform.

Your Data Rights

As the Data Subject of your personal information, you have specific rights under the General Data Protection Regulation (GDPR) regarding how we process your data. We are committed to helping you exercise these rights securely and efficiently.

Your RightDescriptionOur Application and Limitations
The Right to be InformedThe right to know how your personal data is collected and used.We satisfy this right by providing you with this complete Privacy Policy document.
The Right of AccessYou can ask us for a copy of the personal data we hold about you. This is known as a Data Subject Access Request (DSAR).We will provide this data free of charge and within the mandated legal timeframe.
The Right to RectificationYou can notify us if the data we hold is inaccurate or incomplete and ask us to correct it immediately.We will correct any factual errors as quickly as possible upon verification.
The Right to ErasureYou can request the deletion or removal of your personal data.We have a Legal Obligation and a Substantial Public Interest to retain certain data for a defined period for clinical safeguarding and legal accountability. We cannot delete this essential data until its required retention period expires. Further information can be found in the "Account Deletion" section below.
The Right to Restrict ProcessingYou can ask us to temporarily pause or limit the processing of your data while its accuracy is checked or if there is a legal dispute about our reason for processing it.We will flag your record and restrict processing immediately upon request while the dispute is resolved.
The Right to Data PortabilityYou can ask us to securely transfer the personal data you have provided to us to another service provider (Data Controller) in a commonly used format.This right only applies to data processed by automated means based on your Consent or Contractual Necessity.
The Right to ObjectYou can object to the processing of your data where we are relying on its Legitimate Interests or Public Task as the legal basis for processing.We will cease processing unless we can demonstrate compelling and overriding legal grounds for continuation.

Exercising Your Rights Securely

Where we rely on your consent to process your personal data (outlined above), you have the right to withdraw that consent at any time.

You can manage your preferences and withdraw your consent by:

  • In-App Controls: Navigating to your profile settings:
    1. Rescind research consent
    2. Deactivate your account
    3. Remove optional data sharing in the "about me" section of your profile
  • Contacting Us Directly: Send an email to our Data Protection Officer at (contact information found below). If you choose to contact us externally, we will just need to take a few secure steps to verify your identity before actioning your request.

Withdrawing your consent will not affect the lawfulness of any data processing we carried out before your withdrawal. Withdrawing your research consent or deactivating your account will not automatically result in the immediate erasure of all your data. Because we provide health and well-being services, we are under strict legal, regulatory, and contractual obligations to securely retain certain records (including your health data and clinical notes) for minimum specified periods. For full details on how long we are required to keep your information after you withdraw consent, please view our Retention Period below.

If you believe that we have failed to handle your data properly or have not respected the rights listed above, you can make a formal complaint to the Information Commissioner's Office (ICO).

External Sites

If you choose to follow links from Kooth to third-party websites, you should know that our Privacy Policy no longer applies. Since we have no control over these external sites, we strongly recommend that users consult the third party's own privacy policy before continuing.

Account Management

This section covers essential topics related to your account, including our forgotten login details, our data retention period, and the procedures for account deletion.

Forgotten Logins

Creating a Full Account requires an email address, which allows you to securely reset your password if you ever forget it. However, if you use a Guest Account, we cannot reset your login details. If you log out of a guest account, you will lose access completely and need to create a new one.

Retention Period

We only keep your personal data for as long as necessary to provide our services and ensure we meet our legal and safeguarding obligations. In most cases, records are kept from the Users last interaction with the Service. Below is a table of our retention period.

User Type and AgeRetention Period
Online and Face-to-Face Counselling records - under 1810 years after the User turns 18. Records are kept till the last day of the month.
Online and Face-to-Face Counselling records - under 18, where child sexual abuse has been notedIndefinite
Online counselling records - 18 plus10-year retention period starts at the point of the last interaction recorded on the Service user's account.
Online and Face-to-Face Counselling records - 18 plus, where child sexual abuse has been notedIndefinite
User accounts information10-year retention period starts at the point of the last interaction recorded on the Service user's account.

Account Deletion

When you request account deletion, due to the nature of our service we may be unable to fulfil your request at that time.

  • We Deactivate, Not Delete: For clinical safety, governance, and legal accountability, we do not immediately delete account data. Instead, we deactivate your account, making it immediately inaccessible.
  • Data Retention: Your personal data is then securely archived in accordance with the above data retention schedule, after which it will be permanently deleted. This process is required to ensure we meet our legal obligations and Substantial Public Interest requirements for health and safeguarding purposes.

How to Request Deactivation

  1. Log in to your Soluna account.
  2. Go to your profile, then settings, and click the Deactivate my account button.

Our team will then verify the request and process the deactivation.

Important Warning: Once this request has been made, you will no longer have access to your account.

Further Information

Data Minimisation

Processing your data is necessary for our legitimate interests or the legitimate interests of a third party, as long as your rights and interests do not outweigh those interests. Our legitimate interests include:

  • Communicating in response to enquiries
  • Communicating relevant information to existing or potential users
  • Understanding the interests and needs of our website users
  • Maintaining the performance and security of our website and other services

Rights in Relating to Automation

We may use Machine Learning (ML) or Artificial Intelligence (AI) to improve our processes and user experience. These technologies also help us better understand our service users and improve outcomes. AI/ML may make decisions automatically. Examples are:

  • Content suggestions based on a service user's previous usage or
  • Matching a service user with an available practitioner based on selected criteria or focus areas

We may use the data we collect to measure our performance and improve our service.

Contacts:

Kooth Digital Health Limited is a data controller. Our registered office is 5 Merchant Square, London, W2 1AY.

Contact DetailType of Request
dpo@kooth.comIf you have any data or privacy-related issues.
complaints@kooth.comIf you or anybody you care for or support is dissatisfied with our Service, please contact us here. We are always trying to improve our Service, and addressing and learning from feedback is one way we can do this.
safeguarding@kooth.comGet in touch with our safeguarding team here to raise concerns or report risks to users of our services (staffed 9-5 Mon-Fri; always use 999 for police/ambulance in emergencies).
contact@kooth.comHere for anything else, general questions or feedback.
research@kooth.comAny research-related inquiries.

Privacy Notice Changes

We will revise our Privacy and Safety Policy as necessary, for example, if the purpose of data collection changes. We encourage you to check back on the Privacy Policy for any future changes.

Welcome to your new space to destress, bounce back, and reset.

In crisis?

Call 999

for urgent support

Explore

  • Counselling
  • Peer Support
  • Content & Tools
  • Community

Resources

  • Parents & Families
  • Schools
  • Community Partners

About

  • About Us
  • Approach
  • Trust & Saftey
  • Impact
  • Careers

Legal

  • Privacy Policy
  • Terms & Conditions
  • Accessibility Statement

©2026 Kooth. All Rights Reserved.

For app support, questions or telecoaching, use our chat widget or contact us by phone by calling (844) 582-2111 toll-free. Chats received between 10pm and 10am PST will be responded to next day. If you would like to share feedback, we'd love to hear from you.

AICPA SOC for Service Organizations
ISO/IEC 27001 Certified - Information Security Management

Get the Soluna web app

We have just launched our new web version of the app, you can get it in your browser for free, just click below!

Get the web app now

Get the Soluna mobile app

Scan the QR code to download the app

App QR Code

or search in your mobile app store for:

Soluna: Mental Health Care

Find out more