Legal

Privacy Policy

Last updated: July 5, 2026

At Guilietta we understand that your personal data is especially sensitive. This policy explains clearly what information we collect, how we use it and how we protect it. Your privacy is not an option — it is part of the design of our service.

1. Who we are

Guilietta is a personal safety platform designed for women. We offer AI-powered conversation analysis, safe-travel mode with automatic alerts and emergency contact management. The data controller is Guilietta LLC, a company registered in the State of Florida, United States (hereinafter, "we" or "the platform").

2. Data we collect

  • ·Account data: full name, email address, password (stored encrypted), country and optional phone.
  • ·Google profile data: name and photo if you use Google sign-in (only with your explicit authorization).
  • ·Conversation fragments: when you analyze a text or screenshot, the content is sent to our third-party AI providers — Anthropic (Claude) and, as a fallback, OpenAI — which process it ephemerally to return your analysis and do not use it to train their models. We only store the first 500 characters as a reference excerpt, never the full text.
  • ·Location data: your physical address (optional) is used anonymized to show you relevant geolocated information. During safe travel mode, your real-time location is shared only with your designated emergency contacts.
  • ·Emergency contacts: name, phone and email of people you register. We only contact them to request their consent and to send the alerts you trigger.
  • ·Audit logs: security actions (sign-in, analysis, alerts) with IP anonymized via SHA-256 hash.
  • ·Safety map reports: areas or incidents you report anonymously or identified; we use them to show aggregated safety information to the community.

2.1 Consumer health data

Conversation analysis may infer information about your emotional or wellbeing state, which in the U.S. could be considered consumer health data. Guilietta does not track the menstrual cycle or reproductive data. How we handle that inferred information —transient processing, no sale or sharing, law-enforcement safeguards and your rights— is described in our separate Consumer Health Data Privacy Notice.

Read our Consumer Health Data Privacy Notice

3. How we use your data

  • ·Provide the conversation analysis and safe travel service.
  • ·Send SMS alerts to your emergency contacts when you trigger an alert or don't confirm your arrival.
  • ·Improve your account security through audit logs.
  • ·Communicate important service information (never marketing without consent).

3.1 SMS Communications

When you start a safe travel session or trigger a manual alert, Guilietta sends transactional SMS messages to your selected emergency contacts via Twilio. These messages are one-time, event-driven notifications — not recurring or marketing messages. Recipients may reply STOP to opt out of future messages at any time.

  • ·Before any alert is sent, each emergency contact receives a one-time confirmation message and must expressly agree (by replying YES / SÍ) to authorize the delivery of future alerts. Guilietta only sends alerts to contacts who have confirmed their consent. A contact may revoke that consent at any time by replying STOP.
  • ·Your mobile phone number and the mobile phone numbers of your emergency contacts collected through Guilietta will not be shared with or sold to third parties or affiliates for marketing or promotional purposes. SMS opt-in data and consent records are used solely to deliver safety alerts within the Guilietta platform.
  • ·Message frequency varies based on user activity (typically 1-5 messages per travel session). Standard message and data rates may apply. For support, contact hey@guilietta.com or reply HELP to any Guilietta SMS.

4. Use of the digital footprint tool

The digital footprint (digital exposure) analysis feature is designed solely for you to look up information associated with your own identity. By using it, you represent and warrant that the data you enter (name, email, phone, photograph or otherwise) relates to you, or that you have the explicit consent of the data subject or a valid legal basis to process it.

Using this feature to investigate, monitor, profile, harass, or locate other people without their consent is strictly prohibited. Guilietta is not liable for any misuse of the tool or for the entry of third-party information without proper authorization; such conduct is the sole and exclusive responsibility of the person performing it, who shall be answerable for any claim, damage, or penalty —including those arising under applicable data-protection law— resulting from that use. Guilietta may suspend or terminate access for anyone who breaches this provision.

5. Who we share your data with

  • ·Supabase (database and authentication infrastructure) — servers in the US, SOC 2 compliant.
  • ·Anthropic (AI processing for conversation analysis) — we send only a truncated excerpt, never the full conversation. Under Anthropic's Commercial Terms and Data Processing Addendum (with EU Standard Contractual Clauses), Anthropic acts as a data processor and is contractually prohibited from using this content to train its models. Content is processed transiently.
  • ·OpenAI (AI processing, fallback for analysis) — same safeguards. Under OpenAI's Services Agreement and signed Data Processing Addendum (with EU/UK Standard Contractual Clauses), OpenAI acts as a data processor and does not use this content to train its models.
  • ·Twilio (SMS alerts to emergency contacts) — only when you trigger an alert.
  • ·Resend (transactional email delivery) — sends account, security and service emails. Governed by a Data Processing Addendum with Standard Contractual Clauses.
  • ·Google (optional OAuth authentication) — only if you choose to sign in with Google.
  • ·Google Analytics (site usage metrics) — only activates if you accept analytics cookies in the cookie notice. It receives aggregated, pseudonymous usage data; we configure it without Google Signals or ad personalization, and it never receives conversation content or health data.
  • ·SerpAPI (digital exposure search) — when you use the digital exposure module, your name, email and phone are sent to query public search engines and assess your digital footprint. We do not use this for any other purpose.
  • ·HaveIBeenPwned (security breach check) — your email address is checked against public breach databases to alert you if your data has been compromised.
  • ·Google Maps Platform (address autocomplete and geolocation) — when you search for an address we use the Google Places API. Your address is not shared with Google for advertising purposes.
  • ·Stripe (payment processing) — payment data is handled directly by Stripe. Guilietta does not store credit card numbers. Stripe is PCI DSS Level 1 compliant.
  • ·We do not sell, rent or transfer your data to third parties for commercial purposes.
  • ·Business transfers: if Guilietta is involved in a merger, acquisition, reorganization or sale of assets (including an insolvency proceeding), your data may be transferred as part of the transaction. In that case, we will require the acquirer to handle it in accordance with this Policy or to notify you before making material changes, and we will maintain the heightened protections on health and location data.

6. Data retention

We retain your data only for as long as necessary to fulfill the purposes described. Concrete retention periods:

  • ·Account data: while the account is active and 30 days after deletion (for recovery and legal obligations).
  • ·Conversation analysis history: 30 days on the Free plan; while the account is active on the paid plans (Essential and Complete). On the Free plan we email you a few days before deletion so you can download your analyses as a PDF and keep them.
  • ·Conversation excerpts sent to AI processors (Anthropic, OpenAI): processed transiently to return an analysis; not retained by Guilietta beyond the analysis record, and retained by the processor only for a short abuse-monitoring window under their DPA.
  • ·Safe-travel data (location, notified contacts): 90 days after the trip ends.
  • ·Safety map reports: for as long as your account is active.
  • ·Audit logs: 1 year from the event.
  • ·Payment data: managed by Stripe per its retention policy.
  • ·You can request full deletion of your account and data at any time by writing to us.

7. Security

We implement technical and organizational measures to protect your data: in-transit encryption (HTTPS/TLS), secure authentication with Supabase, Row Level Security (RLS) in the database (each user only accesses her own data), rate limiting on all APIs, and IP anonymization in audit logs.

8. Your rights

  • ·Access: you can query all the data we have about you.
  • ·Rectification: you can correct your data from the profile section.
  • ·Erasure: you can request the deletion of your account and all your data.
  • ·Portability: you can request a copy of your data in a structured format.
  • ·Withdrawal of consent: you can deactivate the consents for analysis, safe travel, geographic location from your profile at any time. When you withdraw a consent, we stop processing that data immediately.

9. Cookies and local storage

We use strictly necessary cookies to keep your session authenticated (managed by Supabase). In addition, only if you accept them in the cookie notice, we use Google Analytics with analytics cookies to measure site usage in aggregate: they are off by default, we configure it without Google advertising signals or ad personalization, and you can withdraw your consent at any time by clearing the site data in your browser or writing to hey@guilietta.com. We do not use third-party advertising cookies.

10. Minors

Guilietta is intended for individuals 18 years or older (16 in the European Union with verifiable parental consent). We do not knowingly collect data from minors.

  • ·We do not have an active age-verification mechanism: we rely on the user's declaration when accepting the Terms of Use.
  • ·If a parent or legal guardian detects that a minor has an account on Guilietta, they may contact us at hey@guilietta.com to request immediate deletion.
  • ·Deletion timeframe after verification: 48 hours maximum.
  • ·If we discover by our own means that an account belongs to a minor below the applicable minimum age, we will delete it.

11. Additional rights for California residents (CCPA / CPRA)

If you reside in California, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you additional rights over your personal information. Categories of personal information we collect under CCPA: identifiers (name, email, IP hash), commercial information (subscription plan), geolocation information (during safe-travel), internet activity (usage logs), and sensitive personal information (health data that conversation analysis may infer and precise location).

  • ·Right to know: you may request the categories and specific pieces of personal information we have collected, the sources, the purposes of processing and the parties with whom we share it.
  • ·Right to delete: you may request deletion of your personal information, subject to applicable legal exceptions.
  • ·Right to correct: you may request correction of inaccurate data.
  • ·Right to limit the use of sensitive personal information: you may request that we limit the use of the health data that conversation analysis may infer and your precise location to strictly necessary purposes.
  • ·Right to opt-out of sale or sharing: we explicitly declare that we DO NOT sell or share your personal information as defined by CCPA/CPRA. We do not engage in cross-context behavioral advertising.
  • ·Right to non-discrimination: we will not penalize you in any way for exercising your CCPA/CPRA rights.
  • ·To exercise these rights, write to hey@guilietta.com. We will respond within 45 days (extendable by an additional 45 days for complex cases, with prior notice).
  • ·"Do Not Sell or Share My Personal Information" notice: because we do not sell or share data under CCPA/CPRA, no opt-out is necessary — however, you may confirm this status by writing to us.
  • ·Residents of other U.S. states: if you reside in a state with a comprehensive privacy law (e.g., Virginia, Colorado, Connecticut, Texas, Oregon, Utah), we grant you equivalent rights of access, correction, deletion and limitation of sensitive data through the same channels.
  • ·We honor Global Privacy Control (GPC) signals and universal opt-out mechanisms recognized under applicable law.

12. Florida Digital Bill of Rights

For Florida residents (where Guilietta LLC is registered), under SB 262 (Florida Digital Bill of Rights): we declare that we do not process biometric data. Rights granted by this statute are exercised through the same channels described in Section 10 (CCPA/CPRA), since the scope of rights is equivalent for our operations.

13. Additional information for users in the European Union / EEA (GDPR)

If you are located in the European Union, the European Economic Area or the United Kingdom, the General Data Protection Regulation (GDPR / UK GDPR) grants you specific rights. Legal bases for processing:

  • ·Account data (email, name, password): performance of a contract (Art. 6(1)(b) GDPR).
  • ·Conversation analysis: explicit consent (Art. 6(1)(a) GDPR).
  • ·Location in safe-travel mode: explicit consent (Art. 6(1)(a) GDPR).
  • ·Health data that conversation analysis may infer: explicit consent for processing of special category data (Art. 9(2)(a) GDPR).
  • ·Audit logs and account security: legitimate interest (Art. 6(1)(f) GDPR).
  • ·Session cookies: strictly necessary for the provision of the service (consent exemption under Art. 5(3) ePrivacy).
  • ·Analytics cookies (Google Analytics): consent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy). Off by default until you accept them in the cookie notice.
  • ·International transfers: your data is transferred to the United States, where Supabase, Anthropic, OpenAI, Twilio, Stripe, Google, Resend, SerpAPI, HaveIBeenPwned and Google Maps Platform operate. The transfer basis is the Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, the EU-US Data Privacy Framework. Each of these processors operates under a Data Processing Addendum (DPA) incorporating SCCs and/or certification under the EU-US Data Privacy Framework, where applicable.
  • ·Your GDPR rights: access, rectification, erasure, restriction of processing, portability, objection and withdrawal of consent at any time.
  • ·Right to lodge a complaint with your national data protection authority (e.g., AEPD in Spain, CNIL in France, Garante in Italy, ICO in the UK).
  • ·Response time: we will respond to rights requests within one month, extendable by two further months where necessary, in which case we will notify you. We may charge a reasonable fee or refuse to act on requests that are manifestly unfounded, repetitive or excessive.
  • ·Data Protection Officer (DPO): we have not appointed a DPO as we do not meet the thresholds in Art. 37 GDPR. The contact for any privacy matter is hey@guilietta.com.
  • ·Minimum age in the EU/EEA: 16 years with verifiable parental consent.

14. Information for users in Canada (PIPEDA and Quebec Law 25)

If you reside in Canada, we process your data in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, if you reside in Quebec, in accordance with Law 25.

  • ·Sensitive data (health inferred from conversation analysis, location): processing is based on your express consent.
  • ·Conversation analysis uses automated decision-making and artificial intelligence. You may request information about the logic involved in that analysis and ask for human review of the result.
  • ·Your rights: access, rectification, portability and withdrawal of consent at any time.
  • ·Breach notification: if a security breach creates a real risk of significant harm, we will notify the Office of the Privacy Commissioner of Canada (OPC) and affected users.
  • ·Privacy contact: hey@guilietta.com.

15. Information for users in Brazil (LGPD)

If you reside in Brazil, the Lei Geral de Proteção de Dados Pessoais (LGPD, Law 13.709/2018) applies to the processing of your data.

  • ·Primary legal basis: consent (Art. 7, I LGPD) and, for sensitive health data, specific and highlighted consent (Art. 11, I LGPD).
  • ·Data subject rights: confirmation of processing, access, correction, anonymization or deletion of unnecessary data, portability, deletion, information about data sharing, and withdrawal of consent.
  • ·Contact: hey@guilietta.com.

16. Information for users in Latin America

Guilietta complies with data protection laws in the main Latin American jurisdictions where we offer the service. In every case we honor the ARCO rights (Access, Rectification, Cancellation and Objection).

  • ·Mexico: we comply with the new Federal Law on Protection of Personal Data Held by Private Parties (in force since March 2025), whose supervisory authority is the Secretariat of Anti-Corruption and Good Governance (Secretaría Anticorrupción y Buen Gobierno). Our notice identifies the sensitive data we process (location and health data that conversation analysis may infer), distinguishes the purposes that require consent, and allows you to exercise your ARCO rights by writing to hey@guilietta.com.
  • ·Colombia: we comply with Law 1581 of 2012 and Decree 1377 of 2013. Sensitive data is processed only with prior, express and informed authorization. We are assessing registration of our databases with the National Database Registry (RNBD) of the Superintendence of Industry and Commerce (SIC). We respond to inquiries within a maximum of 10 business days and to complaints within a maximum of 15 business days.
  • ·Chile: we comply with Law 19.628 and are prepared for Law 21.719, which takes full effect on December 1, 2026 and creates the Personal Data Protection Agency (Agencia de Protección de Datos Personales).
  • ·Costa Rica: we comply with Law 8968 on the Protection of Individuals against the Processing of their Personal Data.
  • ·Argentina: we comply with Law 25.326. The transfer of your data to processors in the United States is based on your consent. You may exercise your ARCO rights with us and lodge a complaint with the Agency for Access to Public Information (AAIP).
  • ·Venezuela: we guarantee your right of habeas data (Constitution, art. 28): access, rectification and deletion of your data.
  • ·Peru, Uruguay and others: we apply the data protection principles recognized in their respective legislation.
  • ·To exercise your rights in any country in the region, write to hey@guilietta.com.

17. Identity verification

To protect your safety, before fulfilling an access, deletion or portability request we may ask you for additional information to verify your identity. We will not release personal data —especially location or health data— without reasonably confirming that the request comes from the account holder. This prevents impersonation by third parties.

18. De-identified and aggregated data

We may de-identify or aggregate data for lawful purposes such as statistics and service improvement. When we do, we will apply measures to prevent re-identification and will not attempt to re-associate it with an individual, except to verify that the de-identification process is effective.

19. Security incident notification

If a security breach affecting your personal data occurs, we will notify the competent data protection authority and the affected users without undue delay, within the timeframes required by applicable law (including the 72-hour deadlines provided under frameworks such as those of Chile and the EU), and we will apply mitigation measures.

20. Changes to this policy

We may update this policy occasionally. We will notify you by email at least 15 days in advance of any material changes. The last-updated date appears at the top of this page.

21. Contact

To exercise your rights or resolve any privacy question, write to: hey@guilietta.com. Data controller: Guilietta LLC, Florida, United States.