• Protected Health Information (PHI): Health information protected under the Health Insurance Portability and Accountability Act (HIPAA).
• User Data: Any data submitted by users to the Service, including Personal Data and PHI.
• Output Data: Reports and other documents generated by the Service based on User Data.
• Aggregate/Anonymized Data: Data that has been de-identified so it cannot reasonably identify an individual.
• Service Providers: Third-party vendors that process information on our behalf, including AWS (hosting), Stripe (payments), and Google Analytics (metrics).
• Cookies: Small text files placed on your device to support Service functionality.
• Account Data: Name, email, organization details, login credentials, and payment information.
• Client/Patient Data (PHI): Information uploaded by therapists regarding their clients for the purposes of generating clinical reports.
• Technical and Usage Data: IP address, browser type, device identifiers, session activity, error logs, and cookie data.
• Communications: Feedback, support inquiries, and other communications you send us.
• To provide, operate, and maintain the Service;
• To process payments and manage accounts;
• To generate reports and other outputs from User Data;
• To improve our algorithms and features in a de-identified or aggregated manner;
• To comply with HIPAA and other applicable laws;
• To communicate important notices, updates, and policy changes;
• To send marketing communications (with opt-out options).
• Authenticate sessions and maintain login security;
• Collect usage analytics via Google Analytics;
• Improve Service performance.
We do not use cookies for advertising or behavioral tracking. By using the Service, you consent to our use of cookies as described in this Policy. Google Analytics may set its own cookies; you can opt out of Google Analytics by installing the opt-out browser add-on available at: https://tools.google.com/dlpage/gaoptout. We do not send PHI to Google Analytics or any analytics provider.
• Service Providers: AWS for hosting, Stripe for payments, Google Analytics for metrics.
• Legal Compliance: To comply with applicable laws, regulations, subpoenas, or government requests.
• Business Transactions: In connection with mergers, acquisitions, or sales of assets.
• Aggregate Data: For analytics, research, and product improvements.
We do not sell personal data.
• Use and disclose PHI only as permitted by HIPAA and our Business Associate Agreement (BAA);
• Safeguard PHI in compliance with the HIPAA Security Rule;
• Report security incidents and breaches of PHI as required by law;
• Make available PHI as required for access, amendment, and accounting of disclosures.
• HIPAA Rights: Access, correct, or request an accounting of disclosures of PHI.
• CCPA Rights (California residents): Right to know what data we collect, request deletion, opt out of the sale of data (we do not sell data), and non-discrimination for exercising rights. We do not use sensitive personal information (such as health data) for purposes other than those permitted by law (e.g., providing the Service).
Requests may be submitted by contacting us (see Section 14).
Clinicians and other authorized users may, however, input information relating to clients who are minors in the course of providing clinical services. Any such information is treated as Protected Health Information (PHI) and is safeguarded in accordance with HIPAA and this Privacy Policy. We rely on our users to ensure that all necessary consents and authorizations from parents or legal guardians have been obtained prior to the entry of any child client information into the Service.