Privacy Policy
Privacy policies can be dense and inaccessible. Because you are coming to us for unhurried, grounded care, we want to make understanding your privacy just as straightforward.
What is this document?
Privacy policies can be dense and inaccessible. Because you are coming to us for unhurried, grounded care, we want to make understanding your privacy just as straightforward. We have designed this Privacy Policy to be as easy to navigate and understand as possible. If you have any questions while reading it, please don't hesitate to reach out to privacy@therapyatnight.net.
For purposes of this Policy, "data" includes information that is linked to one person or household, including things like name, email address, phone numbers, device ID, contact information, and communications with the licensed clinicians using our digital communication platform (the "Platform") to provide services ("Therapists").
When you use and access our website or services, you accept and agree to both our Terms and Conditions and this Privacy Policy.
To the extent any data is considered protected health information (“PHI”) under The Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), we follow strict compliance standards to ensure your medical and therapy data remains entirely confidential.
Section 1: Data Collection and Processing
Do you collect, store, or process my data?
Yes. We process data to operate the Platform, facilitate your late-night and early-morning sessions, and ensure you can use our services effectively. We may also process data to send you periodic emails or text messages related to your appointments or, if you opt-in, marketing communications.
What specific data are you processing and why?
- Visitor Data: When you visit the website, we process information like the pages visited, time on site, device type, browser, and IP address. This helps us optimize our website for late-night mobile browsing and improve technical performance.
- Onboarding Data: To match you with a Therapist, we process the answers you provide in our intake micro-forms (e.g., preferred hours, reasons for seeking therapy).
- Account & Transaction Data: We process your name, email, phone number, emergency contact details, and payment information (via secure third-party processors like Stripe) to facilitate your session-based billing.
- Therapy Data (PHI): We process written communications, session scheduling, and related information shared with your Therapist to facilitate care. We do not record video or audio sessions unless you explicitly consent to such recording.
- Customer Service Data: We process communications you have with our Intake Coordinators (like our AI agent, James, or human staff) to ensure you get matched correctly.
How do we use Artificial Intelligence?
We use Artificial Intelligence (AI) to handle initial website inquiries, coordinate intake, and streamline administrative tasks. We do not use any Therapy Data—such as your actual session discussions, journal entries, or private Therapist messages—to train AI models.
Section 2: Data Sharing
Why do we share your data?
We never sell your personal data. We only share data under the following strict conditions:
- Service Providers: We share necessary data with trusted vendors that help us operate. Examples include our secure cloud hosting providers, payment processors (e.g., Stripe), and customer relationship management tools (e.g., GoHighLevel). These providers are legally bound to strict confidentiality and cannot use your data for their own purposes.
- Legal Compliance: We may share data if required by law, such as cooperating with a valid court subpoena. Therapists are also legally mandated to disclose information to authorities in specific cases: (a) reported or suspected abuse; (b) serious suicidal potential; (c) threatened harm; and (d) court-ordered treatment.
- Safety and Security: We may share data with emergency services if you or someone else is in immediate, life-threatening danger.
Are you using my data for advertising?
To reach people who need after-hours care, we run advertisements on platforms like Meta and Google. If you opt-in to advertising cookies, basic Visitor Data (like your device ID or IP address) may be shared so we can measure our ad effectiveness.
CRITICAL: We never share any PHI, intake answers, session data, or private Therapist communications with advertisers. Period.
Section 3: Data Retention and Erasure
How long do you retain my data?
We retain data only for as long as required to provide our services and comply with healthcare laws.
- If you started therapy: Your Clinical Health Record (intake forms, dates of service, Therapist notes) is legally required to be retained for up to 10 years after your last session, after which it is securely erased.
- If you created an account but never started therapy: Your data is retained for 3 years and then erased.
- Marketing/Visitor Data: If you request erasure of non-medical marketing or account data, it will be removed within 30 days of verifying your request.
How do I request data erasure or a copy of my data?
You may request a copy of your non-clinical data or ask for the deletion of marketing/account data by emailing privacy@therapyatnight.net. Please note that we cannot erase your Clinical Health Record if it is subject to mandatory state or federal medical retention laws.
Section 4: Security and Anonymity
How do you keep my data secure?
Even in the quiet hours of the night, your data is fiercely protected. We apply industry best practices, including:
- Encryption: All messages and data transfers feature 256-bit encryption.
- Secure Infrastructure: Our databases are encrypted and housed in secure, top-tier cloud environments.
- Payment Security: We do not store your full credit card information; it is safely tokenized by our payment processors.
Can I remain anonymous?
You may choose a nickname to identify yourself to your Therapist. However, to comply with telehealth regulations and ethical safety codes, we must collect an accurate emergency contact and verify your identity before clinical care begins.
Section 5: Cookies and Web Beacons
What is a cookie?
A "cookie" is a small data file used to enhance website performance, keep you logged in securely, and personalize your experience.
How do I opt out?
You can update your browser settings to reject cookies or prompt you before accepting them. Please note that disabling essential cookies may impact your ability to log into the patient portal or schedule sessions properly. You can opt out of marketing emails at any time by clicking the "unsubscribe" link at the bottom of our emails.
Section 6: Regional Privacy Rights
For California Residents (CCPA/CPRA)
Under the California Consumer Privacy Act, California residents have the right to request access to the personal information we have collected about them over the past 12 months, request correction of inaccurate data, and request deletion of their data (subject to healthcare retention exemptions). We do not "sell" your data for money, but our use of advertising cookies may be considered a "sale" under California law. You may opt out of this tracking via our cookie banner. To exercise your CCPA rights, email privacy@therapyatnight.net.
For UK, EU, and Swiss Residents (GDPR)
If you reside in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the right to access, rectify, or erase your data, as well as the right to data portability and to object to certain processing. Our servers are located in the United States, meaning your data will be transferred internationally. We comply with recognized data protection frameworks to ensure this transfer is secure. To exercise your GDPR rights, please contact our Data Protection Officer at privacy@therapyatnight.net.
Privacy Contact
If you have any questions while reading this Privacy Policy, please reach out to Therapy at Night.