Last Updated: September 14, 2026
Intentioned.tech ("we", "our", "the application") is a proprietary, self-hosted social skills training platform. This privacy policy explains how data is collected, stored, and used when you use this application.
Local Processing: This application is designed to be self-hosted. Your practice conversations (the audio, the transcript, and the analysis of it) are processed on the machine running the application: your own computer or server if you self-host, or ours if you use the online demo (section 2a). Your voice recordings are never sent to a third-party service.
Connections made without any configuration. Some network connections happen by default, with no setting needed to turn them on: license validation with our license service (when the server starts, every two minutes while it runs, and when a practice session ends); a daily update check on installations with the automatic updater; and downloads of AI models from their publishers, such as Hugging Face, the first time each model is needed. None of these include your audio, transcripts, or analysis results. Sections 6b and 9 describe what they send. The remaining services in section 6 are used only when chosen: subscribing to the mailing list, or an operator turning on online text-to-speech.
No cloud AI providers. The application has no option to send your conversations to a cloud AI provider such as OpenAI, Anthropic, or Google. Speech recognition, the language model, and analysis all run on the machine running the application. The only AI step that can run elsewhere is optional online text-to-speech, which is off by default (section 6e).
The full application is designed to run locally on your own hardware. The online demo at app.intentioned.tech is hosted by us and is not fully local.
Online Demo Notice: When you use the online demo, your audio, transcripts, and prompts are transmitted to our servers to generate responses. Do not submit sensitive, regulated, or confidential information in the online demo. We may retain limited operational logs for security, abuse prevention, and service reliability. Your data is never used for training. Data may be deleted upon request.
"No Data Leaks" Clarification for Web Demo: The "no data leaks" claim does not apply to the web demo at app.intentioned.tech. As the owner of the demo infrastructure, Intentioned.tech necessarily has access to data processed on our servers. However, as an operator, we commit to not leaking, selling, or sharing your data with third parties. For true "no data leaks" protection, use the self-hosted version where you are both owner and operator of your data.
The application may collect and process the following types of data during your training sessions:
Important: Each message you send is checked by an AI moderation model running on the machine running the application. When a message is flagged, a record is created to help maintain platform safety and improve moderation accuracy.
Safety violation logs are stored on the machine running the application, in the Documents folder of the account the server runs as:
%USERPROFILE%\Documents\simulation_safety_violations\~/Documents/simulation_safety_violations/~/Documents/simulation_safety_violations/Each safety violation log contains:
Purpose: These logs are stored locally for your own review and to help improve the moderation system.
Reports for the host/administrator: A second AI check decides whether each flagged message
repeats an earlier flagged message in the same session, and rates its severity as severe, moderate, or mild.
When a session reaches its third distinct flagged message, and each time a message is rated severe, a report
containing the flagged messages is written to a separate "transmitted_to_host" folder for the host/administrator
to review. Despite the folder's name, nothing is sent over the network; the report stays on the same machine, in
[Documents]/simulation_safety_violations/transmitted_to_host/
Pausing a conversation: From the fifth distinct flagged message in a session, or once messages rated severe reach two, the conversation is paused: a pause notice is shown and flagged messages are no longer answered. Because each flagged message is currently rated twice, a single message rated severe can be enough. Reloading the page starts a new count. If a crisis signal was detected earlier in the conversation, the pause is not applied, so that crisis resources stay reachable. These thresholds are fixed; the operator of an instance can turn content moderation off or change what it flags.
How long logs are kept: When automatic deletion is on, which it is by default, logs and reports older than the retention period (30 days by default) are deleted. This check runs when the server starts, so on a server that runs for a long time without restarting, a log can be kept longer than the retention period.
Every session shows a notice that you are talking to an AI, not a human, when the session starts and again after each hour of practice. If something you say matches the application's crisis detection, which currently recognizes English only, crisis resources are shown, including the 988 Suicide and Crisis Lifeline. No setting turns either notice off.
This application uses cookies to remember your preferences across sessions:
Cookie Details:
Cookies used by this application:
intentioned_tts_engine - Your preferred text-to-speech engineintentioned_kokoro_voice - Selected Kokoro TTS voiceintentioned_vibevoice_voice - Selected VibeVoice voiceintentioned_stt_engine - Your preferred speech-to-text engineintentioned_max_tokens - LLM response length settingintentioned_temperature - LLM creativity settingintentioned_scenario - Last selected training scenariointentioned_mic_mode - Preferred microphone mode (VAD or Push-to-Talk)intentioned_tts_muted - Whether AI voice is mutedEverything in this section stays on the machine running the application: yours, if you self-host; ours, if you use the online demo. Live conversation audio is never written to disk; it is transcribed in memory and discarded. The conversation transcript is held in memory during a session and is not saved on its own, except where listed below. The following is written to disk:
session_results/ records the scores, the feedback and summary generated from your conversation, the scenario, a session identifier, and your username. It does not contain the verbatim transcript or any audio. Results are deleted automatically after the retention period (30 days by default).cold_storage/, indefinitely (section 6b-1).intnd_subject_id), not by your account, and are removed after 30 days without use. A record that the one-time suitability notice has been shown is kept indefinitely.The application may interact with external services for the following purposes:
The face-detection library used by the optional eye-contact feature (face-api.js) and its model files are served by the application itself. Nothing is loaded from a CDN, and the application's content security policy does not allow scripts to be loaded from other sites.
Three of the four text-to-speech engines (Kokoro, VibeVoice, pyttsx3) run completely offline on the machine running the application. The fourth, Edge-TTS, does not; see section 6e.
The mailing list is a separate, optional service run from this website. It is not part of the Intentioned.tech application: subscribing to it does not connect to your practice sessions, transcripts, or analysis results in any way, and nothing from the application is ever added to it.
What we collect: your email address, and nothing else. The signup form sends only the address you type into it. We do not collect your name, your browser's language, your IP address, or any other field at signup.
Where it is stored, and in which country. Your address is stored by Resend, our email provider, as a contact in our mailing list. Resend is where the list actually lives — it is not merely a delivery pipe — so your address is held on Resend's systems, subject to Resend's privacy policy. We do not keep a separate copy of the list in a database of our own.
Those servers are in the United States. We are telling you this plainly because it is the kind of thing people assume is configurable and it is not: there is no European storage option, and we have not chosen the United States over an alternative. If you are in the UK, the EU, or Switzerland, your address is transferred to the United States under the data processing agreement we have in place with Resend, which is the legal mechanism that permits the transfer.
Why we are allowed to use it. We rely on your consent, given when you submit the signup form. You can withdraw that consent at any time, and withdrawing it is as easy as giving it — one click on the unsubscribe link in any email we send.
How long we keep it. If you unsubscribe, we stop mailing you immediately and delete your address within 30 days. We hold it for those 30 days and no longer, for two reasons: an unsubscribe clicked by accident can be undone, and a stale backup restored during that window cannot quietly put you back on the list. After 30 days nothing about you remains.
If you never unsubscribe, we keep your address until the launch you signed up for, and in no case longer than 24 months from the day you signed up. If we have not launched by then, we delete the list rather than email people about something they asked to hear about two years earlier and have every right to have forgotten. You can ask us to delete you sooner at any time, and we will.
Access and deletion. Write to contact@intentioned.tech and we will tell you what we hold for your address, or delete it, within 30 days. There is no automated self-service portal for this, and we are not pretending otherwise: it is a person reading email at a three-person company.
What These Claims Mean:
By default, your data is handled under Track A and is covered in full by the "No Data Leaks" guarantee described above. Track B is a separate, optional feature you must explicitly opt in to.
The application does not support cloud-based Large Language Model (LLM) providers. No setting sends your conversation to OpenAI, Anthropic, Google, or any other hosted AI service: the language models it uses run on the machine running the application.
The following data may be collected and stored outside the local application for service functionality:
How this data is handled:
The application can optionally use Microsoft's Edge-TTS service instead of an offline engine. When it is
used, the text of the AI character's spoken reply is sent to Microsoft's speech service
(speech.platform.bing.com) along with a voice identifier (e.g. "en-US-JennyNeural") that encodes
the selected language and voice. Your own audio and anything you typed are never sent, although the AI's reply
can repeat or paraphrase what you said. No account identifier, session identifier, or other identifying data
from this application is included; as with any network request, the server's IP address is visible to
Microsoft as the connecting party.
Off by default. Online TTS is disabled unless the operator of the instance turns it on: in the server's configuration, with an environment variable set before the server starts, or through a settings change that requires operator credentials. Ordinary signed-in users cannot turn it on. It is currently off on the online demo.
What triggers it. Once online TTS is turned on, it is used in three cases:
The application's own safety notices, such as the AI disclosure and crisis resources, are always synthesized offline.
No active notice when in use. The application does not currently display anything to a user indicating that a given reply's audio was generated online rather than offline. A tooltip describing this exists in the application's source code, but the control it is attached to is hidden in the current interface, so no user currently sees it.
Malwarebytes Browser Guard Detection: This application includes code to detect when Malwarebytes Browser Guard is flagging our domain as a "Risky TLD" (false positive). This detection is used solely to display a helpful warning banner explaining how to whitelist the site.
The detection works by:
This detection is entirely local and does not contact any external Malwarebytes servers.
No data is collected or transmitted through this detection. It exists purely to improve user experience by explaining false positive blocks on .tech domains.
This application uses the following AI models, which run locally on the machine running the application:
All AI processing occurs locally, except optional online text-to-speech (section 6e). Model weights are downloaded once and cached on the machine running the application.
License Validation: A licensed installation of Intentioned.tech communicates with our license service, which runs on Cloudflare, to confirm that its license is valid. It does this when the server starts, every two minutes while the server runs, and when each practice session ends. Installations with the automatic updater also check for updates once a day.
The license service receives:
IP address: as with any network request, your server's IP address is visible to Cloudflare, which hosts the license service. The license service does not record it in its database.
What is NOT collected:
Activation records are kept until the server is deactivated, or until you ask us to delete them (section 6d).
Since this is a self-hosted application, you have complete control over your data:
The mailing list and license records are the exceptions, because we hold them rather than you: they are not on your machine. Your access and deletion rights over them are described in sections 6a and 6d, and are exercised by writing to contact@intentioned.tech.
Data security depends on your deployment configuration. We recommend:
Intentioned.tech supports 28 EU languages. Language detection and preferences are:
Safety features are English-only. Crisis detection (section 3a) and the checks that block harmful AI output recognize English text only. In a conversation held in any other language, crisis detection does not fire and those checks will generally not match. The application is not restricted to English by default; the operator of an instance can restrict it to a single language. The hosted instance at app.intentioned.tech is restricted to English.
This privacy policy may be updated as the application evolves. Check the "Last Updated" date at the top of this document for the most recent version.
For questions about this privacy policy or the application, please contact us at contact@intentioned.tech or visit intentioned.tech.