Tell Tilly — Privacy Policy

Last updated: 16 September 2026

1. Introduction and Data Controller

This Privacy Policy explains how Hennessy Media Group Ltd ("we", "us", "our") collects, uses, stores and protects personal data in connection with the Tell Tilly mobile application ("the App"). Hennessy Media Group Ltd is a company registered in England and Wales under company number 17285442 and is registered as a data controller with the Information Commissioner's Office under registration number C1968360.

By using the App you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this policy, you should not use the App.

For all data-related enquiries, contact us at info@hennessymediagroup.co.uk.

2. Legal Basis for Processing

We process your personal data on the following lawful bases under UK GDPR:

Consent: where you have provided explicit consent to the processing of health-related data, including Apple HealthKit data, and to the storage of crisis conversation records as described in Section 6.

Contract: where processing is necessary to provide the App's core functionality and to fulfil our obligations to you as a user.

Legitimate interests: where processing is necessary for the security of the App, for fraud prevention, and for the improvement of our services, provided such interests are not overridden by your fundamental rights.

Legal obligation: where processing is required to comply with applicable law.

3. Categories of Personal Data Collected

We collect and process the following categories of personal data:

Account data: email address, display name, country of residence, and subscription status. Collected at account creation and during onboarding.

Profile data: hormonal stage, HRT status, height, current weight, weight goal, and dietary restrictions. Collected during onboarding and updatable at any time via the App settings.

Health data: where you grant permission to connect Apple HealthKit, we collect sleep data, heart rate, heart rate variability, resting heart rate, steps, active calories, basal calories, workout sessions, weight, body fat percentage, SpO2, respiratory rate, and nutritional data. This data is sourced directly from your device and connected wearables.

Conversation-derived data: structured health observations, symptom extractions, journal entries, locket assessments and Tilly score derived from your conversations with Tilly. Raw conversation transcripts are not stored and are processed solely in the moment of the interaction.

Forum data: anonymous scroll submissions to the Tell Tilly forum. Submissions are not linked to your identity in the public feed. A private linking record is maintained solely to enable you to delete your own submissions.

Support data: where you submit a support request, we collect your name and email address solely for the purpose of responding to your enquiry.

Device and technical data: app version, device type, and session metadata required for the functioning of the App.

4. How We Use Your Personal Data

We use your personal data for the following purposes:

To provide and personalise the App's core functionality, including generating your journal, locket assessment, Tilly score and health data visualisations.

To enable Tilly to provide contextually relevant responses based on your stored profile and health data.

To generate GP reports where you request them.

To moderate forum submissions for compliance with our community standards prior to publication.

To respond to support requests.

To maintain the security and integrity of the App and its infrastructure.

To comply with our legal obligations, including ICO registration requirements and UK GDPR.

5. Data Sharing and Third Parties

We do not sell your personal data to third parties. We do not share your personal data with advertisers.

We use the following third party service providers to operate the App. Each is bound by appropriate data processing agreements:

Anthropic Inc: processes conversation data solely to generate Tilly's responses, Call 2 extractions, GP reports, locket assessments and forum moderation. Anthropic does not retain conversation data beyond the processing of each individual request.

Apple Inc: HealthKit data is accessed via Apple's HealthKit framework on your device in accordance with Apple's own privacy terms.

Resend: used to deliver transactional emails including support request notifications. Processes email addresses only.

We may disclose personal data where required to do so by law, by court order, or by a regulatory authority.

6. Crisis Conversation Retention

In the event that a conversation with Tilly triggers the crisis detection protocol, meaning the App detects language indicating a risk of serious harm to yourself, the full content of that conversation is retained as a confidential safety record. This is the sole exception to our general policy of not retaining raw conversation data.

You are informed of this exception during onboarding prior to providing any personal data. The legal basis for this processing is your explicit consent, obtained at onboarding, and our legitimate interest in maintaining a safeguarding record.

Crisis conversation records are retained for a period of 12 months from the date of the conversation and are then permanently deleted. Access to these records is strictly limited and is only permitted in connection with a genuine safeguarding matter or legal proceeding.

7. Data Storage and Security

All personal data is stored on servers located within the European Union. We apply encryption at rest and in transit across all data storage. Access controls and row-level security are applied to restrict access to personal data to authorised systems only.

Notwithstanding the above, no method of transmission or storage is completely secure. We take all reasonable steps to protect your data but cannot guarantee absolute security.

8. Data Retention

Account and profile data is retained for the duration of your account. Upon account deletion all personal data is permanently and irreversibly deleted immediately.

Health data, journal entries, symptom extractions, locket assessments and Tilly score data are retained for the duration of your account and deleted upon account deletion.

Anonymous forum submissions remain in the public feed until deleted by you or until they expire in accordance with our community moderation policy. Deletion via My Scrolls is immediate and permanent.

Crisis conversation records are retained for 12 months from the date of the conversation as described in Section 6.

Support request data is retained for 12 months from the date of the request and then deleted.

9. Your Rights Under UK GDPR

You have the following rights in relation to your personal data:

Right of access: you may request a copy of the personal data we hold about you.

Right to rectification: you may request that inaccurate or incomplete data be corrected.

Right to erasure: you may request deletion of your personal data. You may exercise this right directly within the App at any time via the Privacy and Data section in the App settings, which permanently deletes your account and all associated data immediately.

Right to restriction of processing: you may request that we restrict the processing of your data in certain circumstances.

Right to data portability: you may request a copy of your data in a structured, commonly used and machine-readable format.

Right to object: you may object to processing carried out on the basis of legitimate interests.

Right to withdraw consent: where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.

To exercise any of the above rights, contact us at info@hennessymediagroup.co.uk. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner's Office at ico.org.uk.

10. Children

The App is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that personal data has been collected from a person under 18, we will delete that data immediately.

11. International Users

The App is available in the United Kingdom, Ireland, Australia, New Zealand, the United States, Canada, France, Germany, Spain, Portugal, Italy, the Netherlands, Belgium, Luxembourg, Switzerland, Malta and Cyprus. If you are accessing the App from outside the United Kingdom, please be aware that your data is stored on EU servers and processed in accordance with UK GDPR. By using the App you consent to this processing.

12. Changes to This Policy

We reserve the right to update this Privacy Policy at any time. Where changes are material we will notify you within the App prior to the changes taking effect. Continued use of the App following notification constitutes acceptance of the revised policy. The date at the top of this policy reflects the date of the most recent update.

13. Contact

Hennessy Media Group Ltd
info@hennessymediagroup.co.uk
ICO registration number C1968360
Registered in England and Wales, company number 17285442