Privacy Policy
This explains what personal data the esc. Android app, its server and this website use, why, who receives it, how long it is kept, and your rights. esc. has no accounts: you never give us your name or email to use the app.
Who is responsible
Vecti Tech Ltd is the controller of the data described here. It is a company registered in England and Wales with company number 16941866. Its registered office is at Unit A, 82 James Carter Road, Mildenhall, IP28 7DE, United Kingdom. ICO registration: ZC127524.
Contact for privacy questions and requests: support@enteresc.app, or see www.enteresc.app/support.
What stays on your device
- The apps you choose to keep closed, your modes, schedules and settings.
- A small local memory: counters (attempts, openings, stays, emergency uses, reflections), the last thing you said you needed, and a short note of what you said was pulling you in. No chat transcripts are stored. You can clear the notes and last-session summary in the app under Privacy.
- Emergency use is stored only as a local count and last-used time, never numbers, routes or searches.
- A random installation id made by the app. It is not taken from your phone’s hardware. Uninstalling the app removes it.
What esc. does not read or send
esc. uses Android Accessibility to detect which app is open while your mode is active, so it can bring you back to the conversation when a closed app opens. It does not read screen text, messages, notifications, passwords, contacts or content inside other apps. Your installed-app list, screen contents, notification text, contacts, messages, browsing history, raw location and raw motion history never leave your device. Version 1 does not request Android Usage Access.
When you talk to esc.
esc. replies are written by an AI model run by OpenAI. Before your first message is sent, the app tells you that your messages go to OpenAI and asks you to continue. After that, your current message and up to six recent messages from the current attempt are sent to our server, together with your mode and scope, session counters, the name of the app you tried to open, when available, and, if you turned on the driving check, a coarse label (in vehicle, not in vehicle or unknown). Our server passes this to OpenAI to write the reply. We do not send OpenAI your installation id, IP address or purchase details.
- We ask OpenAI not to store the request (
store: false). - OpenAI may still keep the content in abuse-monitoring logs for up to 30 days. OpenAI does not use it to train its models by default.
- Our own server does not keep your message text.
- Our server logs hold metadata only (for example message length and action types), never your message text, app names or purchase tokens, and are kept for at most 30 days.
- A compact summary of session counters is sent with chats only if you turn on “Send session counts with chats” under Privacy. It is off by default and never includes what you said.
- Crisis safety. esc. checks every message you type, on your phone, for words that suggest you may be in crisis. If one matches, esc. shows helpline numbers instead of a reply and does not send that message. If you’ve agreed to messages leaving your phone, our server’s crisis check also reads the messages esc. sends for a reply, and the ones it doesn’t answer (during a cooldown, without a subscription, at a message limit, while the chat is still opening or confirming your subscription, or when a reply fails). For a message esc. doesn’t answer, this check calls no AI model and receives only the message itself, with no install ID or other app identifier. Its text is not stored or logged. To pick the right helpline, esc. uses your phone’s network or SIM country (Android) or your region setting, and this stays on your phone.
What you tell esc. can include how you are feeling. If it says something about your physical or mental health, that is health information, a special category of personal data. We use it only to reply to you and to show helplines, and only after you agree on the screen shown before your first message. Please do not include details about other people.
Limits, abuse prevention and your installation id
- Our hosting provider, Cloudflare, sees your IP address when your phone connects. Our server turns the IP address into a one-way SHA-256 digest and uses it to count requests. Short-window counts are removed within about an hour; a daily usage count is removed after the end of that day (UTC).
- The app sends its installation id with requests. Our server keeps only a one-way digest of it, to count daily usage (removed after the end of that day).
- Once subscriptions are switched on, our server also keeps: a record that an installation has used its free first session (a digest of the installation id and two times, kept for up to 400 days), and a record linking a digest of your Google Play purchase token to the digests of the installations using it (kept until 90 days after it was last used). These stop a free session or a purchase being reused without limit.
Checking the request comes from a genuine app
On Android, esc. asks Google Play Integrity to vouch for each request. Google receives a SHA-256 hash of the request (not your message text in readable form) plus Play’s app, licence and device-integrity information. Our server checks the result and does not store it. iPhone is not available in this release.
Feedback you send
If you send feedback or report a reply from the app, your message and its context (mode, scope, screen, the name of the app that was closed where relevant, or the id of the reply you reported) are sent to our server and kept there for at most 30 days, then deleted automatically. The stored copy does not include your installation id, your network address or the text of the reply you reported. When our feedback mailbox is switched on, the same message is also emailed to the esc. feedback inbox using Resend as the email service, and kept there for at most 30 days. Keep it free of anything you do not want us to read.
Crash reports
Release builds send crash reports to Sentry (EU ingest endpoint in Germany). Personal data collection is off. For crashes in the app’s own code, messages, user details, request data, logs, extra data and device context are stripped before sending; a report keeps the error type, a stack trace (file, function and line) and the type and time of recent app events. A crash in Android’s native code is reported on the next launch and can also include basic device details, such as the phone model and Android version. Crash reports are kept for at most 30 days.
Subscription
Payment is handled by Google Play; we never see your card details. To confirm your subscription, the app sends your Google Play purchase token and installation id to our server, which checks the token with Google. We do not log purchase tokens or store them in readable form.
This website and emails to us
This website sets no cookies. Its pages load fonts from Fontshare and Google Fonts, which see your IP address when a page loads. If you email support@enteresc.app, for example to ask for early access, we use your address and what you write only to reply and to tell you when an Android build is ready. We keep these emails only as long as we need them to deal with your request, and for no more than 12 months after that.
Why we are allowed to use this data
- To provide the service you asked for (contract): sending your messages to get a reply, and checking your subscription.
- Our legitimate interests in keeping esc. secure, fair and working: request limits, the installation id records, Play Integrity checks, server logs, crash reports, the crisis check on our server, and reading feedback and emails you send us. You can object to these uses; see “Your rights”.
- Your consent: the driving check and “Send session counts with chats”, which are off until you turn them on and can be turned off again at any time.
- Your explicit consent (UK GDPR Article 9(2)(a)) for any health information in the messages you send, including the crisis check on our server. You give it on the screen shown before your first message and can withdraw it at any time under Privacy in the app. Withdrawing stops your messages leaving your phone; the crisis check on your phone keeps working.
Who receives data
- OpenAI (United States): writes the replies.
- Cloudflare (United States, global network): runs our server and this website.
- Google (United States, global): Play Integrity checks, Google Play billing and purchase checks. Google acts as an independent controller for Google Play.
- Resend (United States): delivers feedback emails to our inbox.
- Sentry (Germany): crash reports.
- Fontshare and Google Fonts: fonts on this website only.
We do not sell your data and we do not share it with advertisers. esc. contains no advertising or analytics SDK.
Transfers outside the UK
Some of these providers process data in the United States or other countries. Where that happens we rely on the UK Extension to the EU-US Data Privacy Framework (the “UK-US data bridge”) for providers certified under it, or on the UK International Data Transfer Addendum to standard contractual clauses in our contract with the provider. Email us if you want more detail.
Automated decisions
The AI model decides what esc. says and whether to offer to open an app for a short time. Limits on messages and requests are applied automatically. None of this has legal or similarly significant effects on you, and you can always end a session yourself from the app.
Children
esc. is for adults aged 18 or over. We do not knowingly collect data from children. If you think a child has used esc., email us.
Your rights
Under UK data protection law you can ask us for a copy of your data, ask us to correct or delete it, ask us to restrict how we use it, object to uses based on our legitimate interests, ask for data you gave us in a portable form, and withdraw consent. These requests are free and we reply within one month. Because esc. keeps no account and no transcripts, we usually cannot tell which records are yours unless you give us details such as the email you wrote from. Email support@enteresc.app.
If you are unhappy with how we handle your data, please tell us first. You can also complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint or on 0303 123 1113.
Changes
We will update this page and its date when our practices change. Last updated: 5 October 2026.