Privacy Policy
Last updated: March 2026
1. Information We Collect
We collect information you provide directly, including:
- Account information: name, email address, and password
- Profile information: pronouns, timezone, and optional profile photo
- Story content: personal stories and associated metadata you choose to share
- Therapist information: professional credentials, practice details, and availability (for therapist accounts)
- Booking information: appointment details and communication preferences
2. How We Use Your Information
We use collected information to:
- Provide and maintain the Platform
- Process therapy session bookings and payments
- Moderate and publish user-submitted stories
- Improve the Platform through analytics
- Send relevant notifications about your account and bookings
- Enable semantic search to help users discover relevant stories and therapists
3. PHIPA Compliance
As a Canadian health-related platform, we are committed to compliance with the Personal Health Information Protection Act (PHIPA). We implement safeguards including:
- Encryption of personal health information in transit and at rest
- Access controls limiting who can view personal health information
- Audit logging of access to sensitive data
- Secure deletion procedures for personal health information upon request
4. Information Sharing and Disclosure
We do not sell your personal information. We may share information with:
- Therapists you choose to book sessions with (limited to information necessary for the therapeutic relationship)
- Service providers who assist in operating the Platform (subject to confidentiality agreements)
- Law enforcement when required by law or to protect safety
5. Data Security
We implement industry-standard security measures including:
- Encrypted data transmission (TLS/SSL)
- Secure database infrastructure hosted on Supabase
- Row-level security policies ensuring users can only access authorized data
- Regular security audits and monitoring
6. Cookies and Tracking
We use analytics tools to understand how the Platform is used:
- PostHog for product analytics and feature flagging
- Essential cookies for authentication and session management
- No third-party advertising cookies
You can manage cookie preferences through your browser settings.
7. Third-Party Services
The Platform integrates with the following third-party services:
- Stripe for payment processing — subject to Stripe's Privacy Policy
- Supabase for database and authentication infrastructure
- OpenAI for generating story embeddings (anonymized text only, no personal identifiers)
8. Data Retention
- Account data is retained while your account is active.
- Story content may be retained after account deletion if published with consent.
- Booking records are retained as required for financial and legal compliance.
- You may request deletion of your personal data at any time.
9. Your Rights
You have the right to:
- Access the personal information we hold about you
- Correct inaccurate personal information
- Request deletion of your personal information
- Withdraw consent for story publication
- Export your data in a portable format
10. Children's Privacy
The Platform is not intended for users under 18 years of age. We do not knowingly collect information from children.
11. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with an updated effective date. We will notify registered users of significant changes via email.
12. Contact Information
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us through the Platform.