Privacy Policy
TherapistAssist is operated by TherapyTools LLC. This policy explains what we collect from the therapists who use the product, what we deliberately never collect about their clients, who we share data with, and how to get your data deleted.
Last updated: August 2026
Who this policy covers
Our customer is the clinician. The people described in this policy are therapists and other visitors to this website. Clients of those therapists are not our users and do not have accounts.
What we collect from therapists
- Account data. Your email address and authentication credentials, handled by our managed identity provider. Passwords are stored as salted hashes by that provider, never in plain text.
- Clinical content you enter. Session notes, tool responses, worksheet entries, and client initials. This content is stored against your account.
- Billing data. Subscription status, plan, and payment records. Card details are entered directly with Stripe and never reach our servers.
- Email lead capture. If you request a worksheet PDF, join the newsletter, or join a waitlist, we store the first name and email address you provide, the source of the request, and the worksheet or page it came from.
- Usage events. Page paths, event names, timestamps, referral/campaign parameters from the link you arrived on, and your account ID when signed in. These events are used to understand which pages and tools are used.
- Technical data. Standard server and CDN request data such as IP address, user agent, and request time, which our hosting provider processes to serve and protect the site.
What we deliberately do not collect
The application is de-identified by design. There are no fields, prompts, or workflows that capture the following about a client. Clinicians who need to record this information should do so in their own EHR.
- Client full names
- Client email addresses or phone numbers
- Client mailing or physical addresses
- Client dates of birth or Social Security numbers
- Photos, biometrics, or government identifiers
- Insurance member IDs or claim numbers
- Emergency contact details
Because clients are identified by initials only, we do not hold Protected Health Information. See Security & HIPAA for the full posture and the technical safeguards behind it.
Cookies and local storage
- Sign-in session. Set when you log in, so you stay signed in. Required for the product to work.
- Worksheet lead cookie (
ta_lead). Set after you request a worksheet by email. It stores the first name and email you submitted for up to 365 days so returning visitors can download without re-entering them. Clearing your browser cookies removes it. - Browser storage. Used for in-progress tool drafts, the page to return to after signing in, and similar convenience state kept on your own device.
We do not run third-party advertising or cross-site tracking cookies.
How we use the data
- To provide the tools, worksheets, and your saved clinical content.
- To authenticate you and keep your account secure.
- To take payment and manage your subscription.
- To send the worksheets you requested, transactional email (authentication, receipts, notifications), and, if you opted in, our newsletter.
- To understand product usage in aggregate so we can improve the tools.
- To meet legal, accounting, and security obligations.
We do not sell your data, and we do not use your clinical content to train AI models.
AI features
Some features draft text with AI assistance. When you use them, the content you submit is sent through our AI gateway to a model provider to generate the response. Because the app holds client initials rather than identities, this content is de-identified. Requests are logged with timestamps for auditing.
Who we share data with
We use the following service providers, each processing data only to deliver their part of the service:
We may also disclose data where required by law or to protect our legal rights.
Retention
Account data and the clinical content you enter are kept while your account is active, and deleted on request. Lead and newsletter records are kept until you unsubscribe or ask for removal. Billing records are kept as long as required for tax and accounting purposes. Backups are retained on a rolling basis by our database provider and age out over time.
Your choices and rights
- Unsubscribe. Every marketing email has an unsubscribe link, and one click stops it.
- Access, correction, export, deletion. Email annie@emdrassist.com and we will action it for the account associated with your email address.
- Cancel. Subscriptions can be cancelled at any time from your account.
Depending on where you live, you may have additional rights over your personal data. Contact us at the address above to exercise them.
Security
Traffic is served over TLS, data at rest is encrypted by our cloud provider, and every table holding user data enforces row-level access policies so a clinician can only reach their own records. Full detail is on the Security & HIPAA page. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security.
International transfers
Our providers are primarily based in the United States, and data is processed there and at global edge locations used for hosting. By using TherapistAssist you understand your data is processed in the United States.
Children
TherapistAssist is intended for licensed mental-health practitioners. We do not knowingly create accounts for anyone under 18.
Changes to this policy
We will update this page when our practices change and revise the date above. Material changes will be communicated by email to account holders.
Contact
TherapyTools LLC — privacy questions, data requests, and security reports: annie@emdrassist.com.