Privacy Policy

    Last updated: April 10, 2026

    1. Introduction

    PsyenceFlow ("we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, and safeguard information when you visit our website, use our platform, or engage with our services. As a HIPAA-compliant platform, we maintain the highest standards for data protection.

    2. Information We Collect

    We may collect the following categories of information:

    • Personal Information: Name, email address, phone number, professional credentials, and practice information provided when you create an account, request a demo, or contact us.
    • Protected Health Information (PHI): Clinical assessment data, patient records, and related health information processed through our platform on behalf of healthcare providers, in accordance with HIPAA regulations.
    • Usage Data: Information about how you interact with our platform, including IP address, browser type, pages viewed, and features used.
    • Device Information: Hardware model, operating system, unique device identifiers, and network information.
    • Cookies & Tracking Technologies: We use cookies, web beacons, and similar technologies to enhance your experience and analyze usage patterns.

    3. How We Use Your Information

    • Provide, maintain, and improve our clinical assessment platform and services.
    • Process and manage your account, including authentication and access control.
    • Generate AI-powered clinical reports and assessments as requested by authorized healthcare providers.
    • Communicate with you regarding your account, product updates, and support requests.
    • Send marketing communications (with your consent), including information about new features and services.
    • Ensure compliance with legal, regulatory, and contractual obligations, including HIPAA requirements.
    • Detect, prevent, and address technical issues, fraud, and security concerns.

    4. HIPAA Compliance

    PsyenceFlow operates as a Business Associate under HIPAA. We enter into Business Associate Agreements (BAAs) with all Covered Entities using our platform. All Protected Health Information (PHI) is handled in strict accordance with HIPAA Privacy, Security, and Breach Notification Rules. Our platform employs end-to-end encryption, access controls, audit logging, and other administrative, physical, and technical safeguards to protect PHI.

    5. Data Sharing & Disclosure

    We do not sell your personal information. We may share information only in the following circumstances:

    • Service Providers: With trusted third-party vendors who assist in operating our platform, subject to confidentiality and data protection obligations.
    • Legal Requirements: When required by law, regulation, legal process, or governmental request.
    • Business Transfers: In connection with a merger, acquisition, or sale of assets, with appropriate notice and protections.
    • With Your Consent: When you have given explicit authorization for a specific disclosure.

    6. Data Security

    We implement industry-leading security measures, including AES-256 encryption at rest, TLS 1.2+ encryption in transit, role-based access controls, multi-factor authentication, continuous monitoring, and regular security audits. Our HIPAA compliance and internal security program reflect our commitment to security, availability, and confidentiality.

    7. Data Retention

    We retain personal information for as long as necessary to fulfill the purposes outlined in this policy, comply with legal obligations, resolve disputes, and enforce our agreements. PHI is retained in accordance with HIPAA requirements and applicable state laws. You may request deletion of your personal data by contacting us, subject to legal and regulatory retention requirements.

    8. Your Rights

    Depending on your jurisdiction, you may have the right to:

    • Access, correct, or delete your personal information.
    • Restrict or object to certain processing activities.
    • Request portability of your data.
    • Withdraw consent for marketing communications at any time.
    • For PHI, exercise rights under HIPAA including access, amendment, and accounting of disclosures through your healthcare provider.

    9. Third-Party Links

    Our website and platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any personal information.

    10. Children's Privacy

    Our services are designed for use by licensed healthcare professionals and authorized staff. We do not knowingly collect personal information directly from individuals under the age of 18. Any minor patient data processed through our platform is handled solely at the direction of the treating healthcare provider in compliance with applicable laws.

    11. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Last updated" date. Your continued use of our services after any changes constitutes acceptance of the revised policy.

    12. Contact Us

    If you have questions or concerns about this Privacy Policy or our data practices, please contact us: