Aletheia Lattice — Legal
GDPR & Your Data Rights
If you're in the UK or EU, you have specific legal rights over your personal data. Here's what they are and how to exercise them.
Last updated: May 2026
Your rights at a glance
Under the UK GDPR and EU GDPR, you have the following rights regarding your personal data held by Aletheia Lattice:
- Access — Request a copy of all personal data we hold about you
- Portability — Receive your data in a structured, machine-readable format
- Erasure — Request deletion of your personal data (right to be forgotten)
- Rectification — Have inaccurate data corrected
- Restriction — Limit how we process your data in certain circumstances
- Objection — Object to processing based on legitimate interests
- Withdraw consent — Remove consent for any consent-based processing at any time
We will respond to all exercised rights within 30 days (the legal maximum).
Right of access
You have the right to know what personal data we hold about you and why. This includes:
- Your account information (email, name, country, language)
- Your journal entries and emotional profiles
- Your intake questionnaire responses
- Session summaries and companion insights
- Analytics events associated with your account
- Email communication history
You can view your account data at any time while logged in. For a full data export, use the export feature in Settings → Privacy.
Right to portability
You can export all your personal data as a structured JSON file from Settings → Privacy → Export my data.
The export includes all your journal entries, intake responses, emotional profiles, and account data. It is formatted to be human-readable and machine-processable.
We will generate your export within 24 hours of request and send a download link to your registered email.
Right to erasure (right to be forgotten)
You have the right to request deletion of your personal data. You can do this in two ways:
- Self-service: From Settings → Privacy → Delete my account. This permanently deletes your account and all associated data immediately.
- Email request: Contact hello@aletheialattice.com with subject “Delete My Data”.
What gets deleted: All journal entries, intake responses, emotional profiles, companion sessions, account data, and analytics events.
What cannot be deleted: Payment transaction records are retained for 7 years as required by UK financial regulation (VAT Act 1994, HMRC guidance). These records do not contain your journal content — only payment confirmation data.
Right to rectification
If we hold inaccurate personal data about you, you have the right to have it corrected. Most account data (name, language preference) can be updated directly from your account settings.
For other corrections, contact us at hello@aletheialattice.com.
Right to object
You have the right to object to our processing of your data where that processing is based on legitimate interests. The processing activities we base on legitimate interests are:
- Anonymous analytics — tracking aggregated usage patterns. To opt out, email us and we will stop processing your (anonymised) events.
- AI personalisation — using your past entries to make future prompts more relevant. To stop this, you can delete your data and start fresh, or contact us.
- Crisis detection — monitoring for safety signals in Companion messages. This cannot be opted out of as it protects your safety.
Raising a complaint
If you are unhappy with how we handle your data or a rights request, you have the right to complain to the relevant data protection authority:
- UK: Information Commissioner's Office (ICO) — ico.org.uk
- EU: Your national supervisory authority — full list at EDPB
We always prefer to resolve issues directly. Please contact us first and give us the opportunity to address your concern.
Contact
For any data rights requests or questions:
hello@aletheialattice.com
Subject line: Data Rights Request
We will acknowledge your request within 5 working days and respond fully within 30 days (or notify you if we need more time).