APP Chat Help Me - Privacy Policy

Privacy Policy

FR Cuidados de Saúde, Lda – ByronSystemDeveloper (“we”, “us”, or “our”) provides the Chat Help Me mobile application (the “Service”).

This Privacy Policy explains what information the Service collects, how it is collected and used, who it may be shared with, how long it is retained, and the choices and rights available to users.

Using the Service does not by itself constitute consent to share sensitive personal data with a third-party artificial intelligence provider. Before a user’s first message is sent to the AI chat, the app displays a specific disclosure and asks for explicit permission.


Nature of the Service

Chat Help Me provides two separate forms of communication:

  • Human support chat: private communication between the user and the app administrator or health professional. Users cannot communicate with each other.
  • AI chat: an automated conversation generated using OpenAI’s artificial intelligence service. AI responses are not written or reviewed in real time by a health professional.

The Service is intended to provide general emotional and psychological support. It does not provide psychotherapy, diagnosis, medical advice, or medical treatment.

⚠️ Chat Help Me, its AI chat, and its human support chat do not replace professional medical or psychological care and are not emergency services. If you are experiencing a mental health emergency or are at risk of harming yourself or another person, contact local emergency services or a qualified healthcare provider immediately.


Information We Collect

Depending on the features used, we may collect or process:

  • Name and email address when supplied during registration or use of the human support service;
  • Messages sent through the human support chat;
  • Messages submitted to the AI chat and the AI-generated responses;
  • Information voluntarily included in messages, which may contain personal data, health-related information, psychological information, or other sensitive information;
  • Anonymous or account identifiers used for authentication, security, rate limiting, and service operation;
  • App language and basic app interaction information;
  • Purchase information, such as the product purchased, transaction identifier, transaction date, and purchase validation data. We do not receive the user’s full payment-card details;
  • Advertising information, including ad interactions and reward completion;
  • Technical and diagnostic information, such as IP address, device and operating-system information, app version, crash reports, performance information, timestamps, and configuration information;
  • Push-notification tokens when notifications are enabled.

Information is collected when the user enters or sends it, uses app features, completes a purchase, views or interacts with an advertisement, enables notifications, or when our service providers automatically generate security, analytics, and diagnostic information.


AI Chat and Sharing with OpenAI

When a user chooses to send a message in the AI chat, the complete text of that message and the app’s preferred-language code are transmitted securely to our backend hosted using Google Firebase / Google Cloud. Our backend then sends the message to OpenAI, L.L.C., a third-party artificial intelligence provider, so that OpenAI can generate a response.

The text may contain personal data, health-related or psychological information, or other sensitive information that the user voluntarily enters. Users should not include names, contact details, or other identifying information that is not necessary for the requested response.

The AI message is used to:

  • Generate and return an AI response;
  • Apply safety instructions and detect misuse;
  • Protect the security, reliability, and integrity of the Service.

Before the first AI message is transmitted, the app identifies OpenAI, explains what information will be sent and why, and requests the user’s explicit permission. If permission is declined, the message is not sent. Consent may be withdrawn by ceasing use of the AI chat and contacting us using the details below. If the app asks for consent again, declining it will prevent further AI messages from being transmitted.

Data sent through the OpenAI API is not used by OpenAI to train its models by default unless the API account holder has explicitly opted in. OpenAI may retain API content for a limited period for abuse monitoring and legal compliance, subject to OpenAI’s applicable data controls and privacy terms.

For more information, see:


Sensitive Personal Data and Health Information

Messages may contain health-related and psychological information. Under the General Data Protection Regulation (“GDPR”), this may constitute special-category personal data.

We process information voluntarily entered in chat messages only for the purposes described in this Policy. Where required, sensitive personal data is processed on the basis of the user’s explicit consent. Users are free not to provide sensitive or identifying information.


Purposes and Legal Bases for Processing

We process information for the following purposes and legal bases, as applicable:

  • Providing requested app functionality: performance of the service requested by the user and, where applicable, performance of a contract;
  • Processing sensitive information in chat messages: explicit consent;
  • Authentication, fraud prevention, security, purchase validation, and service reliability: legitimate interests and performance of the Service;
  • Analytics, diagnostics, and app improvement: legitimate interests or consent where legally required;
  • Advertising and advertising privacy choices: consent or another lawful basis made available through the applicable consent interface;
  • Compliance with legal obligations and protection of users or others: compliance with law and protection of vital or legitimate interests where applicable.

Consent may be withdrawn at any time. Withdrawal does not affect processing that occurred lawfully before consent was withdrawn.


Data Storage and Retention

  • Human support chat: messages are stored in Google Firebase / Cloud Firestore so that the user and the professional or administrator can exchange and review messages. They are retained only for as long as reasonably necessary to provide the service, meet legal obligations, resolve disputes, protect users, or until a valid deletion request is completed.
  • AI chat on our backend: our AI backend processes message content to obtain and return a response and does not intentionally save AI message content in the app’s Cloud Firestore chat collection. Temporary technical processing and service-provider retention may still occur.
  • AI chat on the device: on supported devices, the app may store a limited recent AI conversation history locally on the user’s device. The user can clear this history using the app’s clear-history control. Local information may also be removed by uninstalling the app.
  • OpenAI: content may be retained for a limited period under OpenAI’s API data-retention and abuse-monitoring practices, unless different data controls apply to our API account.
  • Account, transaction, security, analytics, advertising, and diagnostic records: retained only for as long as necessary for the purposes described above, contractual requirements, fraud prevention, accounting, legal compliance, or the applicable service provider’s documented retention period.

When information is no longer required, we delete or anonymize it where reasonably possible. Backup copies and records required by law, security, fraud-prevention, accounting, or dispute-resolution obligations may remain for a limited additional period.


Third-Party Services and Data Recipients

We use service providers to operate the app. Depending on the features used, information may be processed by:

  • OpenAI, L.L.C. – AI response generation and AI-service safety;
  • Google LLC and its affiliates – Firebase Authentication, Cloud Firestore, Cloud Functions, App Check, Analytics, Crashlytics, Cloud Messaging, Google Play Services, Google Cloud infrastructure, and AdMob;
  • Apple Inc. – App Store distribution, in-app purchases, purchase validation, and related platform services;
  • Google Play – Android distribution, in-app purchases, purchase validation, and related platform services.

Relevant privacy information:

We require service providers that process information on our behalf to handle it under applicable contractual, confidentiality, security, and data-protection obligations. We select providers that commit to protections equivalent to, or no less protective than, those described in this Policy and required by applicable law.

Some providers may process information outside Portugal or the European Economic Area. Where required, international transfers are protected through legally recognized safeguards, such as adequacy decisions, standard contractual clauses, or other valid transfer mechanisms.


Advertising

The app may display advertisements provided by Google AdMob, including rewarded advertisements that users may choose to watch before sending a message. AdMob may process device identifiers, IP address, approximate location derived from IP, advertising interactions, and technical information in accordance with the user’s privacy choices and Google’s policies.

Where required, the app displays Google’s consent interface before requesting personalized advertising data. Available advertising privacy choices can be reviewed through the app’s privacy-options control. Permission to process advertising data is separate from permission to send a message to OpenAI.


Purchases

In-app purchases are processed by Apple or Google. We receive transaction and validation information necessary to confirm a purchase and grant the purchased app functionality. We do not receive or store complete payment-card details.


Analytics, Log Data, and Security

We and our service providers may process analytics, diagnostic, and security information, including IP address, anonymous or account identifiers, device type, operating-system version, app version, app interactions, ad events, crash information, performance data, configuration, and date and time of use.

This information is used to authenticate users, validate genuine app installations, prevent fraud and abuse, enforce usage limits, diagnose failures, improve stability, and protect the Service. We do not intentionally include the text of AI chat messages in analytics or crash reports.


Data Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal and sensitive information. These measures include encrypted network transmission, authenticated backend requests, app-integrity checks, access controls, and server-side purchase validation where applicable.

No transmission or storage system is completely secure, and absolute security cannot be guaranteed.


User Rights and Privacy Choices

Subject to applicable law, users may have the right to:

  • Request access to their personal data;
  • Request correction of inaccurate or incomplete data;
  • Request deletion of personal data;
  • Withdraw consent;
  • Object to or request restriction of certain processing;
  • Request data portability where applicable;
  • Request information about data processing and recipients;
  • Lodge a complaint with the Portuguese data-protection authority, the Comissão Nacional de Proteção de Dados (“CNPD”), or another competent supervisory authority.

Users can clear locally stored AI conversation history using the clear-history control in the app and can review available advertising privacy choices through the privacy-options control. Other requests, including withdrawal of AI data-sharing consent and deletion requests, can be made using the contact details below.

For security, we may need to verify the requester’s identity before completing a request. Certain information may be retained where required by law or necessary for security, fraud prevention, accounting, legal claims, or the rights of others.


Children’s Privacy

The Service is not intended for children under the age of 13, and we do not knowingly collect personal data from children under 13. If we learn that such information has been collected, we will take reasonable steps to delete it.

Users below the age at which they may independently consent to data processing under applicable local law should use the Service only with authorization from a parent or legal guardian.


Changes to This Privacy Policy

We may update this Privacy Policy when our practices, providers, legal obligations, or app features change. The updated version will be posted on this page with a revised effective date. Where required, we will provide additional notice or request renewed consent.

Effective date: 6 August 2026


Data Controller

FR Cuidados de Saúde, Lda – ByronSystemDeveloper
Portugal – European Union
Acts as the Data Controller under the GDPR.


Contact Us

For privacy questions, consent withdrawal, or requests relating to personal data, contact:

byronsystemdeveloper@gmail.com