Information We Collect & How We Use It

Last Updated: January 15, 2025

Introduction & Our Commitment

At In Therapy, your privacy and trust are foundational to the care we provide. This page outlines the types of personal and health information we collect, why we collect it, how we protect it, and the choices you have regarding your data.

We are committed to complying with all applicable privacy laws, including the Health Insurance Portability and Accountability Act (HIPAA), the California Consumer Privacy Act (CCPA), and other regional data protection regulations.

Important: Therapy involves sensitive health information. We have implemented strict technical, physical, and administrative safeguards to ensure your data remains confidential and secure at all times.

What Information We Collect

We collect information to provide safe, effective, and personalized mental health care. This includes:

  • Personal Identifiers: Full name, date of birth, contact information (email, phone, mailing address), and emergency contact details.
  • Health & Clinical Information: Mental health history, symptoms, treatment goals, session notes, assessment results, medication information, and progress reports (Protected Health Information under HIPAA).
  • Insurance & Billing Data: Insurance provider details, policy numbers, group numbers, claims information, payment history, and out-of-pocket billing records.
  • Account & Usage Data: Login credentials, session activity, platform interaction logs, and preferences for communication or scheduling.
  • Device & Technical Data: IP address, browser type, device identifiers, operating system, and connection logs to ensure secure access and troubleshoot technical issues.
  • Communication Records: Secure messages exchanged through our platform, email correspondence, and consent forms signed digitally.

How We Collect Information

We gather information through direct interactions, automated technologies, and trusted third parties:

  • Directly From You: Intake forms, questionnaires, consent documents, billing forms, and direct communications.
  • During Treatment: Clinical sessions (in-person or telehealth), progress assessments, and therapeutic evaluations conducted by licensed providers.
  • Automatically: Through our secure website and telehealth platform using encrypted tracking to maintain session integrity and system security.
  • From Third Parties: Insurance companies for eligibility/verification, referring physicians, legal guardians (for minors), and authorized healthcare providers sharing relevant medical history.

Why We Collect & How We Use It

Every piece of information we collect serves a specific, necessary purpose:

  • Deliver Clinical Care: Develop treatment plans, track progress, adjust therapeutic approaches, and ensure your safety.
  • Administrative & Billing: Process insurance claims, handle payments, manage appointments, and maintain accurate records.
  • Platform Security: Verify identity, prevent unauthorized access, and maintain HIPAA-compliant infrastructure.
  • Communication: Send appointment reminders, secure messages, policy updates, and emergency notifications.
  • Legal & Compliance: Fulfill mandatory reporting obligations, respond to lawful requests, and maintain standards of care.
  • Service Improvement: Anonymized, aggregated data may be used to improve platform functionality and clinical outcomes research (never tied to your identity).

Information Sharing & Disclosures

We do not sell, rent, or trade your personal or health information. We only share data when necessary, authorized, or legally required:

  • Healthcare Providers: Coordinating care with your psychiatrist, primary care physician, or other specialists (with your consent).
  • Business Associates: Secure cloud hosting, billing processors, and telehealth vendors bound by strict HIPAA Business Associate Agreements.
  • Insurance & Payers: For claims processing, pre-authorizations, and coverage verification.
  • Legal Obligations: Court orders, subpoenas, mandatory reporting (e.g., child/elder abuse, imminent harm), or law enforcement requests.
  • With Your Authorization: We will only share your information with third parties named in a signed release of information.

Data Security & Retention

We employ industry-leading safeguards to protect your information:

  • End-to-end encryption for all telehealth sessions and digital communications
  • HIPAA-compliant electronic health record (EHR) systems with role-based access controls
  • Multi-factor authentication, automatic session timeouts, and regular security audits
  • Physical security for any paper records stored in climate-controlled, access-restricted facilities

Retention Policy: We retain your records for a minimum of 7 years after your last session (or as required by state law, whichever is longer). After retention periods expire, data is securely deleted or permanently anonymized.

Your Rights & Choices

You have full control over your information. Depending on your location, you may have the right to:

  • Access and request a copy of your records
  • Request corrections or amendments to inaccurate information
  • Restrict certain uses or disclosures (where permitted by law)
  • Request deletion or de-identification of non-clinical data
  • Opt out of non-essential communications
  • File a complaint with us or a regulatory authority without retaliation

To exercise these rights, contact our Privacy Officer using the information below. We will respond within 30 days as required by applicable law.

HIPAA & Mental Health Privacy

Mental health records receive heightened protection under federal and state law. We strictly adhere to the HIPAA Privacy and Security Rules. Psychotherapy notes are kept separate from your general medical record and are never disclosed without your explicit written authorization, except in rare safety emergencies or as mandated by law.

Our telehealth platform is fully compliant with 42 CFR Part 2 (if applicable) and state-specific mental health confidentiality statutes. We regularly train staff on ethical boundaries, data minimization, and trauma-informed privacy practices.

Contact Us

If you have questions about this policy, wish to exercise your rights, or need to report a privacy concern, please reach out to our dedicated Privacy & Compliance team:

  • Email: privacy@intherapy.com
  • Phone: (555) 123-4567 (Press Option 2 for Privacy)
  • Mailing Address: In Therapy Privacy Office, 123 Wellness Blvd, Suite 200, New York, NY 10001
  • Hours: Monday–Friday, 9:00 AM – 6:00 PM EST

Have a Privacy Question?

Our team is here to ensure your data is handled with the utmost care and transparency.

📧 Email Our Privacy Team