Privacy Policy
We built TrustedPsych on the premise that your records and your clients' records are private. This policy explains what information we collect, why we collect it, and how we protect it.
Effective date: August 18, 2026
1. Who this policy covers
This Privacy Policy applies to TrustedPsych, LLC (“TrustedPsych,” “we,” “our,” or “us”) and the TrustedPsych platform. It covers:
- Therapists — licensed practitioners who register for an account and use the platform to manage their practice.
- Clients — individuals whose information therapists enter into the platform, and clients who access the client portal directly.
- Visitors — anyone who browses our marketing pages or public directory without an account.
For clients whose records are managed by a therapist, the therapist is the covered entity under HIPAA and controls how their clients' Protected Health Information (PHI) is used. TrustedPsych acts as a Business Associate. See our HIPAA Notice for more detail.
2. Information we collect
Therapist account information
When you register as a therapist, we collect:
- Name, email address, and password (bcrypt-hashed — never stored in plaintext).
- Professional information: license number, NPI, professional title, practice name, specialties, bio, and service fee.
- Payment information for your platform subscription, processed and stored by Stripe — we never see or store your raw card number.
- Profile photo (stored in AWS S3, publicly readable if you publish your directory listing).
- Integration tokens for Google Calendar, stored encrypted and used only to sync your schedule.
Client information (PHI)
When you enter client information into TrustedPsych, we store it on your behalf. This includes names, contact details, dates of birth, diagnoses, session notes, and billing information. All PHI fields are encrypted at rest using AES-256-GCM before they are written to our database. Decryption happens server-side only — plaintext never travels to the browser in list views.
Usage and technical data
We collect standard server logs, including:
- IP addresses, browser type, and operating system (for security and debugging).
- Pages visited and timestamps (to understand how the platform is used).
- Audit logs — every access to a client record is logged with a timestamp, action type, and therapist ID. Audit logs never contain PHI, only identifiers and action types. They are append-only and cannot be deleted.
Cookies and session data
We use a session cookie to keep you logged in. It contains your user ID and email — no PHI. We do not use advertising cookies or share cookie data with ad networks. Your session expires after 30 minutes of inactivity and you are automatically logged out.
3. How we use information
We use the information we collect to:
- Provide and improve the TrustedPsych platform.
- Process your subscription payment via Stripe.
- Send transactional emails (session reminders, document signing links, magic login links) via Resend.
- Sync your calendar schedule with Google Calendar (busy times only — client names are never sent).
- Process client card payments via Square (client nickname is used, never their real name).
- Verify your license and identity during the therapist verification process.
- Respond to your support requests.
- Comply with legal obligations.
We do not use your data or your clients' data for advertising. We do not sell data to anyone.
4. Third-party services and how PHI is protected
We share information with third parties only as necessary to operate the platform. Here is what each service receives:
AWS (Amazon Web Services)
Our database and file storage run on AWS. AWS stores encrypted PHI — they cannot read it without our encryption key. We maintain a BAA with AWS. Storage encryption (AES-256) is enabled on all RDS databases. TLS is required on every connection.
Stripe
Stripe processes your platform subscription payments. Stripe receives your name, email, and payment card data. Client PHI is never sent to Stripe. We maintain a BAA with Stripe (healthcare addendum).
Square
Square processes client session payments and stores cards on file. Square receives the client's nickname (a de-identified alias like “Cobalt Pine”), not their real name. No PHI is ever sent to Square. This design means no BAA with Square is required.
Google Calendar
When you connect Google Calendar, we sync session times and availability blocks. Client names are never sent to Google — we use client nicknames for any schedule entries. No BAA is required.
Resend (email)
We send transactional emails through Resend: session reminders, magic login links, document signing notifications, and superbill delivery links. Emails may contain a client's email address in the recipient field but are designed to minimize PHI in the email body. Signed document attachments are sent by link, not as attachments, unless a BAA with a HIPAA-compliant email provider is in place.
Audio transcription (Whisper)
If you record session audio for transcription, we transcribe it using a self-hosted Whisper model running inside our own AWS infrastructure. Audio and transcripts never leave our infrastructure and are not sent to any third-party AI service.
5. Data retention
We retain your account and client data for as long as your account is active and for as long as required by applicable law and professional standards. Many jurisdictions require mental health records to be retained for a minimum of seven years (or longer for minor clients). You are responsible for ensuring your retention practices comply with your jurisdiction's requirements.
If you close your account, we retain your data for 30 days to allow export, then delete it from our production systems. Backups may retain data for up to an additional 90 days before they are rotated and overwritten.
Audit logs are permanent and append-only — they cannot be deleted, even by us.
6. Security
We take security seriously because the data you entrust to us is sensitive:
- All PHI fields are encrypted at rest with AES-256-GCM before being stored.
- All data in transit is protected by TLS.
- Passwords are hashed with bcrypt — we cannot recover your password.
- Passkey (WebAuthn) authentication is available as an alternative to passwords.
- Every PHI access generates an immutable audit log entry.
- Sessions auto-expire after 30 minutes of inactivity.
- PHI-bearing query parameters are automatically stripped from URLs by our middleware.
No system is perfectly secure. If you discover a vulnerability, please report it to [email protected] before disclosing it publicly. We will respond promptly and work to fix the issue.
7. Your rights
As a therapist, you can access, correct, and export your account data at any time from your account settings. You can delete your account by contacting us.
Your clients' rights to access or request deletion of their PHI are governed by HIPAA and managed by you as the covered entity. If a client contacts us directly requesting access to their records, we will direct them to you.
If you are in the European Economic Area or the United Kingdom, additional rights under GDPR or UK GDPR may apply. Contact us to exercise those rights.
8. Children
TrustedPsych is not directed to individuals under 18. Therapists who treat minor clients are responsible for obtaining parental or guardian consent as required by applicable law before entering those clients' records into the system.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here and notify you by email at least 14 days before material changes take effect. Your continued use of the platform after the effective date constitutes acceptance.
10. Contact
Questions, concerns, or rights requests? Email us at [email protected] or write to:
TrustedPsych, LLC
Flagstaff, Arizona, USA
[email protected]