Privacy Policy
InterSession IQ handles health information. This page explains what we collect, why, where it goes, and what you can do about it.
Effective September 9, 2026
Business details not filled in
The legal entity name, mailing address, and support phone number in src/app/(marketing)/_components/legalContact.ts are still placeholders. Stripe checks these against the details registered on the account during activation.
Our role
Therapists and practices decide what data to collect from their clients and what to do with it. They are the controller of that data. We process it on their behalf, under their instructions, to run the service. Where a therapist or practice is a HIPAA covered entity, we act as their business associate under a Business Associate Agreement.
If you are a client and want your data corrected or deleted, your therapist is usually the right first contact. You can also write to us and we will help, in coordination with them.
What we collect
Account information
- Name, email address, and (optionally) phone number.
- Role, practice membership, and account settings.
- Authentication data. Passwords are stored only as salted hashes; we never see the plaintext.
Health and biometric data
- Biometric summaries from a connected wearable or an uploaded file: resting heart rate, heart rate variability, sleep, activity, stress, and mood.
- Intake responses, consent records, homework and reminder activity, and the reports and alerts generated from the above.
This data is collected only for clients who have been invited by a therapist and have given consent, and only for as long as that consent stands.
Billing information
Handled by Stripe. We store a Stripe customer identifier and subscription status. We never receive or store full card numbers.
Technical data
Standard server logs and security telemetry needed to operate the service. We deliberately keep health and personal data out of logs, error messages, analytics events, and URLs.
What we do with it
- Operate the service and provide the features you subscribe to.
- Generate reports and alerts for the therapist responsible for the client's care.
- Send transactional email: invitations, verification codes, reminders, and billing notices.
- Provide support when you ask for it.
- Keep the service secure and detect abuse.
- Meet legal and regulatory obligations.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use identifiable client health data to train machine learning models.
AI-generated report summaries
When a therapist enables AI report summaries, a language model writes the narrative section of a weekly report. The only thing sent to the model is the already-derived, de-identified report data: aggregated metrics, trends, and the algorithmic insight text the therapist already sees. No names, email addresses, dates of birth, or raw intraday samples are included.
Those requests go to a HIPAA-covered endpoint under a Business Associate Agreement, with zero data retention enabled, so the content is not stored by the model provider or used for training. Therapists can turn the feature off in Settings, in which case no data is sent to a model at all.
Who we share it with
We share data with service providers who process it on our behalf, under contract, and only for the purposes below:
- Convex — application database and backend. Holds account and health data, encrypted at rest.
- Vercel — application hosting and delivery.
- Anthropic — AI report summaries, as described above. De-identified aggregates only, zero retention.
- Stripe — payment processing. Receives your email address and opaque account identifiers. No health data is sent to Stripe, and none is placed in Stripe metadata.
- Resend — transactional email delivery. We keep clinical detail out of email content and subject lines.
- Oura and Apple Health — only when a client chooses to connect them, and only to read the biometric summaries they authorize.
Our public marketing site uses Metricool for visitor analytics. It runs only on the marketing pages, never on any signed-in page, so it never observes therapist or client activity.
We also disclose data when required by law, to protect someone's safety, or in connection with a merger or acquisition, in which case we would give notice before your data became subject to a different policy.
How it is protected
- Encrypted in transit and at rest. Traffic is served over TLS. Stored health and personal data is encrypted at rest, and third-party integration credentials are separately encrypted with a key held server-side.
- Least privilege.A therapist can reach only their own clients' data. Authorization is checked on every server-side data path, not just in the interface.
- Nothing sensitive in the browser. Health data is not kept in local storage, session storage, or browser caches. It is fetched from the backend when needed.
- Minimized surfaces. Health and personal data is kept out of logs, analytics, error reports, URLs, and third-party metadata.
No system is perfectly secure. If a breach affects your information we will notify you and the relevant authorities as the law requires.
How long we keep it
Account and health data is retained while the account is active and the therapeutic relationship continues, and afterwards for as long as the therapist's professional records-retention obligations require. Therapists are responsible for telling us when a record may be deleted.
When data is deleted we remove it from active systems promptly and from backups on their normal rotation. Billing records are kept as long as tax and accounting law requires.
Your choices and rights
- Withdraw consent. Clients can stop sharing biometric data at any time from their account, and can disconnect a wearable integration.
- Access and export. You can request a copy of your data.
- Correction and deletion. You can ask us to correct or delete your data, subject to the retention obligations above.
- Email preferences. Reminder emails can be turned off. Transactional messages about your account and billing cannot, while the account is open.
Depending on where you live, you may have additional rights under state or national privacy law, including the right not to be discriminated against for exercising them. We do not sell personal information or share it for targeted advertising, so there is nothing to opt out of on that front. To exercise any right, email support@intersessioniq.health. We will verify your identity before acting and respond within the time the applicable law allows.
Children
The service is not directed to children under 13 and we do not knowingly collect their information. Clients must be 18 or older, or have a parent or guardian act for them where the therapist's practice and applicable law allow it. If you believe a child has given us information, contact us and we will delete it.
Where data is processed
Data is processed in the United States. If you use the service from elsewhere, you understand it is transferred to and processed in the United States.
Changes to this policy
We may update this policy. If a change is material we will give notice by email or in the app before it takes effect. The effective date at the top of this page always reflects the current version.
Contact
Privacy questions, access and deletion requests, and anything else covered here: support@intersessioniq.health, or write to [Legal entity name, e.g. InterSession IQ, LLC], [Street address], [City], [State] [ZIP], United States.
See also our Terms of Service and Refunds & Cancellation policy.