Company Perspective
Company Perspective
Privacy Is Not a Feature. It Is the Foundation.
April 2026 • Mentivox Team
In 2022, the Mozilla Foundation reviewed the data practices of 32 of the most popular mental health and prayer apps. Twenty-eight of these applications were flagged with a “Privacy Not Included” warning label, indicating significant concerns around data protection and user privacy. The study further found that 25 of the apps failed to meet minimum security standards, while several were identified as collecting and sharing highly sensitive user data, including emotional and behavioral information, with third parties and advertisers, often under opaque or poorly communicated consent mechanisms.
For anyone paying attention to that report, it raised a straightforward question: if the sector cannot protect the most sensitive personal data that exists, what happens to the users who trusted it with their most private thoughts?
That question was one of the reasons Mentivox was built the way it was.
What privacy-by-design actually means
The phrase privacy-by-design appears frequently in product documentation across the technology industry. In most cases, it describes a compliance posture: the company has read the relevant regulations, appointed a data protection officer, and added a consent screen to its onboarding flow. That is not what it means at Mentivox.
At Mentivox, privacy-by-design means that every architectural decision made during the product's development was assessed against a set of privacy principles before it was assessed against any commercial consideration. It means that AES-256 encryption for data at rest is not a feature added in response to a security audit. It is the default from which every other decision works outward. It means that the question “do we actually need to store this?” was asked at every stage, and in many cases answered with a deliberate decision not to store it at all.
You cannot retrofit privacy into a product that was built without it. That is not a technical limitation. It is a philosophical one.
Why it matters more in emotional AI
The data that a user shares with a mental health or companion application is categorically different from the data they share with a shopping app or a navigation tool. Disclosures about anxiety, family pressure, relationship difficulty, financial stress, or personal grief are not usage data. They are the innermost contents of a person's experience at a moment when they were vulnerable enough to share them.
For many of Mentivox's target users, particularly those from communities where emotional disclosure carries social and cultural weight, the consequences of a privacy failure extend well beyond inconvenience. A leaked conversation could affect relationships, employment, or standing within a community. That is not a theoretical concern. It is the lived reality of millions of people who have already learned to be cautious about what they share and with whom.
The Irish Data Protection Commission fined TikTok, a social media platform, 530 million euros and ordered corrective measures in 2025 for data protection failures. The U.S. Office for Civil Rights announced approximately twenty enforcement actions for unauthorised data sharing and related HIPAA violations in 2024, with penalties in several cases reaching into the millions of dollars. Mozilla's 2024 audit found that thirty-seven percent of iOS mental health apps were sending user identifiers to Facebook. This is the environment in which Mentivox operates, and the environment in which our privacy commitments take on meaning beyond good intentions.
Our specific commitments
Mentivox's privacy commitments are not a list of things we try to do. They are a list of things the product is structurally incapable of doing otherwise. Conversations are end-to-end encrypted. Sensitive processing happens on-device where technically possible. No user data is ever sold or shared with third parties for commercial purposes. Privacy policies are written in plain English, because privacy that cannot be understood cannot be trusted. The product is compliant with GDPR, UK GDPR, and Nigeria's National Data Protection Regulation from the first day of operation, not as a target to work toward but as a baseline the architecture was built to satisfy.
We believe that a mental health companion which cannot be trusted with your privacy cannot be trusted with anything. And we built Mentivox accordingly.
