Privacy Policy
Last updated July 1, 2026
gototherapy.app (“gototherapy,” “we,” “us”) provides secure client-intake and practice-management software to licensed mental-health practices. This policy explains what information we handle and how we protect it. If you are a client of a therapy practice, the practice — not gototherapy — controls your health information; please direct requests about your records to your provider.
Our role
Practices that use gototherapy are the covered entities and data controllers for the client information they enter. We act as their service provider and, for protected health information (PHI), as a HIPAA Business Associate under a Business Associate Agreement (BAA). We use PHI only to provide the service to the practice, never for our own purposes.
Information we handle
- Practice & staff accounts:practice name and location, and each staff member’s name, email, and role.
- Client information entered by a practice:contact details, intake forms, appointment history, clinical/progress notes, insurance details, and documents the practice uploads. Payment card details are handled by Stripe — we store only a token, never full card numbers.
- Technical data: log data such as IP address, device / browser information, and audit records of access to client records.
How we use information
- Operate and secure the service and authenticate sign-in.
- Send transactional email only — sign-in links, appointment reminders, and intake invitations. We never send marketing email or sell data.
- Process subscription and client payments through Stripe.
- Maintain audit logs and investigate security or abuse.
Security
Data is encrypted in transit (TLS) and at rest (AWS KMS). Access is restricted by role and scoped so a provider sees only their own clients; access to client records is audit-logged; sessions log out automatically after inactivity. Uploaded documents and insurance cards are stored encrypted and served only through authenticated requests.
Service providers (subprocessors)
We rely on a small set of vetted providers:
- Amazon Web Services— hosting, encrypted storage, transactional email, and telehealth video (under a HIPAA BAA).
- Stripe— subscription and client payment processing.
Data retention
We retain information for as long as a practice’s account is active and as needed to provide the service. On account termination we return or delete client information at the practice’s direction, subject to any records-retention obligations that apply to the practice.
Your choices
Clients should contact their therapy practice to access, correct, or delete their records. Practices and staff can contact us at hello@gototherapy.app for questions about their account or this policy. We use only essential cookies needed to keep you signed in — no advertising or third-party tracking.
Changes
We may update this policy from time to time and will revise the date above. Material changes will be communicated to practice administrators.
Contact
Questions? Email hello@gototherapy.app.