Privacy Policy
How Staid Health collects, uses, and protects your information.
Staid Health, Inc. Effective Date: 09/08/2026 Last Updated: 09/08/2026
1. OUR COMMITMENT TO YOUR PRIVACY
Your data is yours. Always. We exist to help therapists practice without burden, not to extract value from your data. This Privacy Policy explains how we collect, use, and protect your information.
Section 9 Compliance: Staid Health complies with the 21st Century Cures Act (42 U.S.C. § 300jj-52), which prevents information blocking and ensures you have full control, access, and portability of your health data. Your data is accessible to you and authorized individuals, without restrictions or additional fees.
2. INFORMATION WE COLLECT
Information You Provide:
- Name, email, address, phone number (account setup)
- Professional license information (verification)
- Clinical notes, session recordings, patient records, and treatment plans (Your Data)
- Billing and insurance information
- Communications with support (emails, chats)
Information Collected Automatically:
- IP address and device information
- Cookies and tracking data (usage analytics only)
- Log data (login times, features used, errors)
Information From Third Parties:
- Payment processors (Stripe) for billing
- Email providers for communication
3. HOW WE USE YOUR INFORMATION
To Provide the Service:
- Store and process Your Data (clinical notes, patient records)
- Generate clinical documentation via AI (Whisper, Claude)
- Manage scheduling, billing, and claims
- Provide customer support
- Ensure HIPAA and legal compliance
To Improve the Service:
- Analyze usage patterns (anonymized, aggregated)
- Fix bugs and improve features
- Monitor security and prevent fraud
We Do NOT:
- Sell Your Data to third parties
- Use Your Data for AI training or model improvement
- Share Your Data with marketing companies, insurers, or vendors (except as required by law)
- Use Your Data for purposes unrelated to providing the Service
- Monetize Your Data in any form
4. WHAT IS YOUR DATA?
Your Data Includes:
- All clinical information you input (session notes, treatment plans, progress notes)
- Patient/client information (names, diagnoses, treatment history)
- Session recordings and transcriptions
- Billing records and insurance information
- Practice management information (schedules, caseloads)
You Own Your Data. You retain all ownership, rights, and control. You can access, download, export, and delete Your Data at any time.
5. DATA WE DO NOT COLLECT OR USE
We Explicitly Do NOT:
- Collect biometric data or genetic information
- Track your location (except IP address)
- Monitor your communications outside the Service
- Collect data about your family or household
- Use cookies for behavioral tracking (only essential operations)
- Sell or share data with data brokers
6. WHO WE SHARE YOUR DATA WITH
We Share Your Data ONLY:
Service Providers (under data processing agreements):
- Supabase (cloud hosting and database)
- Vercel (application hosting)
- Stripe (payment processing)
- SendGrid/Resend (email delivery)
- These vendors are contractually bound to protect Your Data and use it only to provide services
Legal Requirements:
- Law enforcement or court order (with notice to you unless prohibited)
- Health oversight agencies (CMS, state boards, compliance audits)
- HIPAA regulatory requests
At Your Request:
- You explicitly authorize sharing with other providers or insurers
- You request export or transfer of Your Data
We Do NOT Share:
- Your Data with other practices or competitors
- Your Data with marketing companies
- Your Data with AI/analytics vendors
- Your Data with insurers or payers (unless you authorize or law requires)
- Your Data with any vendor for secondary purposes
7. YOUR RIGHTS & CONTROL OVER YOUR DATA
Access: You can view, download, and export Your Data at any time in standard formats (CSV, JSON, PDF).
Portability: You can request Your Data in a machine-readable format suitable for transfer to another provider.
Correction: You can correct inaccurate information in Your Data.
Deletion: You can request deletion of Your Data at any time. We will delete it within 30 days (longer only if required by law).
Restrict Use: You can restrict how we use Your Data, and we will comply.
Withdraw Consent: You can withdraw consent for specific uses of Your Data.
No Retaliation: We will not restrict your access to or use of the Service if you exercise these rights.
8. DATA RETENTION
While You’re a Customer:
- We retain Your Data as long as your account is active and as necessary to provide the Service
After You Cancel:
- Your Data remains accessible to you for 30 days
- We delete Your Data within 60 days of cancellation (you can request longer retention)
- We may retain anonymized, aggregated data for analytics (cannot identify you)
- We may retain data as required by law (typically 6-10 years for healthcare records)
9. HIPAA COMPLIANCE
Business Associate Agreement: If you are a HIPAA-covered entity or business associate, you must execute a Business Associate Agreement (BAA) with Staid Health. The BAA is available upon request and specifies HIPAA-specific obligations.
HIPAA Requirements We Meet:
- Encryption of data in transit and at rest
- Access controls (authentication, authorization)
- Audit logs and monitoring
- Breach notification procedures
- Data integrity and availability controls
- Subcontractor agreements (our vendors are also bound)
HIPAA Breach Notification: If we discover a breach of unencrypted protected health information, we will notify you and affected individuals as required by law (typically within 60 days).
10. DATA SECURITY
Encryption:
- All data in transit uses TLS/SSL encryption
- All data at rest is encrypted using AES-256
- Backups are encrypted
Access Controls:
- Multi-factor authentication (MFA) for account access
- Role-based access (supervisors only see authorized data)
- Regular access audits
- Automatic session timeouts
Monitoring:
- 24/7 security monitoring and intrusion detection
- Regular penetration testing and security audits
- SOC 2 compliance (in progress for Year 1-2)
Incident Response:
- Documented breach response procedures
- Notification protocols
- Regular staff security training
Limits:
- No online service is 100% secure
- You are responsible for maintaining strong passwords and device security
- You are responsible for authorizing access to your account
11. COOKIES & TRACKING
Essential Cookies: We use cookies only for authentication and essential operations (session management, security).
Analytics: We use Google Analytics (anonymized, aggregated data only). You cannot be individually identified.
No Behavioral Tracking: We do not use cookies to track your behavior across the internet or build advertising profiles.
Do Not Track (DNT): We honor browser DNT signals; we do not track or advertise to you based on DNT signals.
12. CHILDREN’S PRIVACY
Staid Health is not intended for users under 18. We do not knowingly collect information from children. If we become aware of data from a child, we will delete it promptly.
13. THIRD-PARTY LINKS & SERVICES
Staid Health may link to third-party websites or services. We are not responsible for their privacy practices. Review their privacy policies before providing information.
14. INTERNATIONAL DATA
If you are located outside the United States, you acknowledge that data may be transferred to, stored in, and processed in the United States. By using the Service, you consent to this transfer.
15. MARKETING & COMMUNICATIONS
Service Communications: We may send you important updates about the Service, security, or your account.
Marketing Communications: We will not send marketing emails without your consent. You can opt out anytime via email or account settings.
Legal Communications: We may send legally required notices (Terms updates, policy changes).
16. CALIFORNIA PRIVACY RIGHTS (CCPA)
If you are a California resident, you have the right to:
- Know what personal information is collected
- Know how it’s used and shared
- Delete your personal information
- Opt out of “sales” of personal information (we don’t sell data, but you have this right)
- Non-discrimination for exercising privacy rights
California Requests: Contact us at [privacy email] to exercise these rights. We will respond within 45 days.
17. VIRGINIA & OTHER STATE PRIVACY LAWS
If you are a Virginia resident (Virginia Consumer Data Protection Act) or resident of another state with privacy laws (Colorado, Connecticut, Utah), you have similar rights to access, delete, and control your data. Contact us to exercise these rights.
18. CHANGES TO THIS POLICY
We may update this Privacy Policy. Changes are effective 30 days after posting. Continued use of the Service constitutes acceptance of updated Policy.
19. CONTACT US
For privacy questions, requests, or complaints:
Staid Health Privacy Team Email: [privacy email] Address: [your address] Phone: [phone]
Response Time: We will respond to all privacy inquiries within 10 business days.
Complaints: If you have concerns about our privacy practices, you may file a complaint with your state’s Attorney General or, if applicable, your healthcare regulator.
20. GOVERNING LAW
This Privacy Policy is governed by the laws of [YOUR STATE], without regard to conflict of law principles.