Back to Login

Privacy Policy

Last updated: August 16, 2026

1. Introduction

Welcome to Psynthia, an AI-powered psychology practice management platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.

IMPORTANT: Psynthia is a tool designed for healthcare professionals to manage their practice. As a user of this platform, you are responsible for obtaining proper consent from your patients before collecting, storing, or processing their personal and health information using this platform.

2. Information We Collect

2.1 User Account Information

When you create an account, we collect:

  • Full name
  • Email address
  • Password (encrypted)
  • Profile picture (optional)
  • Language preference

2.2 Patient Information You Store

Protected Health Information (PHI): As a healthcare professional using our platform, you may store the following patient information:

  • Patient Demographics: Name, age, gender, email, phone number
  • Clinical Context: Background information, medical history, clinical notes
  • Session Data: Therapy session recordings, transcriptions, notes, and timestamps
  • Clinical Observations: Symptoms, goals, interventions, progress notes, and observations
  • Reports: Clinical reports and assessments generated during treatment
  • AI Conversation History: Interactions with our AI assistant related to patient care

Your Responsibility: You must ensure that you have obtained appropriate consent from your patients to collect, store, and process this information. You are responsible for complying with all applicable healthcare privacy laws and regulations, including but not limited to HIPAA (if applicable).

2.3 Usage Information

  • Login activity and authentication logs
  • Features and tools used within the platform
  • Error logs and diagnostic information

3. How We Use Your Information

We use the collected information for:

  • Service Provision: To provide, maintain, and improve the platform functionality
  • AI Features: To power AI-assisted features such as transcription, report generation, and clinical assistance
  • Authentication: To verify your identity and secure your account
  • Communication: To send you important updates, security alerts, and support messages
  • Platform Improvement: To analyze usage patterns and improve user experience (using aggregated, de-identified data only)
  • Security: To detect, prevent, and address technical issues and security threats

4. Third-Party Services

We use the following third-party services to provide our platform:

  • Supabase: Database and authentication services (stores user accounts and patient data)
  • OpenAI: AI-powered features including GPT models for conversation and analysis
  • ElevenLabs: Speech-to-text transcription services for session recordings
  • Resend: Email delivery services for notifications and reminders

These services may have access to certain data to provide their functionality. We have selected providers that maintain high security standards and comply with relevant data protection regulations.

5. Data Security

We implement industry-standard security measures including:

  • Encryption: Data is encrypted in transit (SSL/TLS) and at rest
  • Access Control: Role-based access control and row-level security policies
  • Authentication: Secure password hashing and session management
  • Data Isolation: Each user's data is isolated and cannot be accessed by other users
  • Regular Backups: Automated backups to prevent data loss
  • Security Monitoring: Continuous monitoring for security threats

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security.

6. Data Retention

We retain your data for as long as your account is active or as needed to provide you services. You may request deletion of your account and associated data at any time by contacting support.

Patient Data: You are responsible for managing retention and deletion of patient data in compliance with applicable laws and professional requirements. You can delete patient records individually through the platform interface.

7. Your Rights

You have the right to:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your account and associated data
  • Export: Export your data in a portable format
  • Opt-out: Unsubscribe from marketing communications

8. HIPAA Compliance (U.S. Users)

If you are a covered entity under HIPAA, we act as a Business Associate. We implement appropriate administrative, physical, and technical safeguards to protect electronic protected health information (ePHI).

Business Associate Agreement (BAA): If you require a signed BAA for HIPAA compliance, please contact our support team.

9. Children's Privacy

Our platform is intended for use by healthcare professionals only. We do not knowingly collect personal information from children under 13 for account creation. If you store information about minor patients, you are responsible for obtaining appropriate parental/guardian consent.

10. International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence. We ensure that such transfers comply with applicable data protection laws through appropriate safeguards.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

12. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Email: privacy@psynthia.app

Address: [Your Company Address]

Acceptance of This Policy

By creating an account and using Psynthia, you acknowledge that you have read and understood this Privacy Policy and agree to its terms. You also acknowledge your responsibility as a healthcare professional to obtain appropriate patient consent and comply with all applicable healthcare privacy laws and regulations.