Psychera, Inc. ("Psychera," "we," "us," or "our") operates psychera.ai and provides an AI-powered clinical intelligence platform for behavioral health, including ambient clinical documentation, clinical decision support, and related workflow tools (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, and protect information when you use the Services or interact with us.
This policy applies to information we handle in our own capacity. When we process protected health information on behalf of a healthcare provider or organization, we act as their Business Associate and process that information under our agreement with them, as described in the Protected Health Information section below.
1. Scope of this policy
This policy covers information collected through our website, web and mobile applications, communications with us (including SMS and email), and administrative and account interactions. It does not cover third-party websites or services that we do not control.
2. Information we collect
Information you provide
- Account and contact details — name, email address, mobile phone number, organization or practice name, professional role, and login credentials.
- Communications — messages, support requests, and feedback you send us, and records of our correspondence.
- Billing information — where applicable, billing contact details and records; payment card data is handled by our payment processor and is not stored by us.
Information collected automatically
- Usage data — pages viewed, features used, actions taken, and timestamps.
- Device and technical data — IP address, browser type, operating system, device identifiers, and diagnostic logs.
Clinical information
- Content processed through the Services — audio, transcripts, clinical notes, and related information submitted by authorized users of a healthcare organization. This may include protected health information and is governed by the terms in Section 5.
3. How we use information
We use the information described above to:
- Provide, operate, maintain, and improve the Services;
- Authenticate users and secure accounts, including identity and phone verification;
- Send transactional and service-related communications, such as verification codes, appointment or visit notifications, and account notices;
- Respond to requests, provide customer support, and communicate with you about the Services;
- Monitor performance, detect and prevent fraud or abuse, and ensure security;
- Comply with legal, regulatory, and contractual obligations.
4. Mobile & SMS messaging data
If you provide your mobile phone number and consent to receive text messages, we may send SMS messages such as one-time verification codes, appointment and visit reminders, and service notifications. Message frequency varies. Message and data rates may apply. You can opt out at any time by replying STOP, and reply HELP for assistance. See our Terms & Conditions for the full messaging terms.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information may be shared with subprocessors that support our messaging operations (for example, a messaging service provider used to deliver messages), and only to the extent needed to provide the Services. Text messaging originator opt-in data and consent are not shared with any third parties.
5. Protected health information
When we process protected health information ("PHI") as defined by the U.S. Health Insurance Portability and Accountability Act ("HIPAA") on behalf of a covered entity or another business associate, we act as a Business Associate. Our handling of that PHI is governed by a Business Associate Agreement ("BAA") between us and the applicable healthcare organization, together with HIPAA's Privacy and Security Rules.
In that role, we use and disclose PHI only as permitted by the BAA and by law — principally to provide the Services to the organization, and for required operational, security, and legal purposes. Patients who wish to exercise rights over their health information should contact their healthcare provider, who is the covered entity responsible for that information.
6. How we share information
We do not sell personal information. We share information only in these circumstances:
- Service providers / subprocessors — vendors that perform services on our behalf (such as cloud hosting, messaging delivery, and analytics) under contractual confidentiality and data-protection obligations.
- Your organization — where you access the Services through a healthcare organization, information may be available to that organization's authorized administrators.
- Legal and safety — when required by law, regulation, legal process, or governmental request, or to protect the rights, safety, and security of Psychera, our users, or the public.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
7. Data retention
We retain information for as long as needed to provide the Services, comply with our legal and contractual obligations, resolve disputes, and enforce our agreements. Retention of PHI is governed by the applicable BAA. When information is no longer required, we delete or de-identify it using reasonable measures.
8. Data security
We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction. These include encryption in transit and at rest, access controls, and logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or restrict the processing of your personal information, to obtain a copy of it, and to opt out of certain processing. To exercise these rights, contact us using the details below. We will respond as required by applicable law and may need to verify your identity first. We will not discriminate against you for exercising these rights.
Requests concerning PHI held on behalf of a healthcare organization should be directed to that organization.
10. Cookies & tracking
We use cookies and similar technologies to operate the website, remember preferences, and understand how the Services are used. You can control cookies through your browser settings; disabling some cookies may affect functionality.
11. Children's privacy
The Services are intended for use by healthcare professionals and organizations, not by children, and we do not knowingly collect personal information directly from children through our website. Where the Services process health information about a minor patient on behalf of a healthcare organization, that information is handled under the applicable BAA and the organization's own privacy practices.
12. International users
Psychera is based in the United States, and the Services are operated from the United States. If you access the Services from outside the United States, you understand that your information may be transferred to, stored, and processed in the United States.
13. Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Services after changes take effect constitutes acceptance of the updated policy.
14. Contact us
If you have questions about this Privacy Policy or our privacy practices, contact us at:
Psychera, Inc.
Email: info@psychera.ai