TheraBoard ← Back to site
Privacy

What we hold, and what we never touch

Last updated 22 July 2026

TheraBoard holds mental-health records. That is about as sensitive as data gets, so this policy is written to be read, not to be survived. If anything here is unclear, ask before you sign up: privacy@everythingpro.co.in.

Who is responsible for what

There are two different relationships here, and conflating them is how privacy promises get broken.

So if you are a client and want to know what is held about you, your therapist is the right person to ask. We will help them answer, and we describe your rights below.

What we store

CategoryWhat it includesWhy
Therapist account Name, email, password (hashed, never stored in readable form), booking page details, practice settings. To give you an account and a booking page.
Client records Name, contact details, age, presenting concerns, session notes, fees, and anything else the therapist chooses to record. Because that is the practice record the therapist is keeping.
Sessions Dates, times, attendance, mood and progress ratings, payment status. Calendar, billing, and the practice patterns the app reports back.
Questionnaires PHQ-9, GAD-7, WHO-5 and ORS answers and scores, where a client completes one. To track outcomes and detect reliable change.
Consent records The exact wording a client agreed to, with a timestamp and their typed signature. So consent is evidenced rather than assumed.
Operational logs Request logs kept briefly by our hosting provider, and an in-app log of exports, note signings and case packs. Security, debugging, and record integrity.

We do not run advertising, we do not sell data, and we do not build profiles for anyone other than the therapist whose practice the data belongs to.

Where it lives

Your records are stored in Supabase (PostgreSQL), in the Mumbai (ap-south-1) region, so the practice record itself stays in India. The application runs on Vercel. Both are subprocessors acting on our instructions. Row Level Security is enabled on every table, so one therapist's data is isolated from another's at the database itself, not only in application code.

One exception, stated plainly: email. Confirmations and reminders are delivered through Resend, whose nearest region to India is Tokyo, so an email containing a client's name and appointment time passes through servers outside India on its way to them. The message is in transit only and is not our stored copy of the record. If you would rather no client detail left the country at all, turn reminders off in Settings; the rest of the app is unaffected.

What AI can see

This matters more than anything else in this document, so it is stated plainly.

Client names, emails, phone numbers and addresses are never sent to an AI provider. When AI is used, it receives anonymous codes (like C-014) and aggregate numbers.

Every therapist controls this in Settings, with three positions:

A therapist may use their own OpenAI or Gemini key, in which case their provider's terms apply to that traffic. Where no key is set, we may use a free open-source model (Qwen) to answer; free tiers may retain inputs to improve their models, which is why only anonymised aggregates are ever sent, and why this too can be switched off in Settings. Any individual client can be excluded from all AI processing on their own record.

Who else can see it

Your rights

Under India's Digital Personal Data Protection Act, 2023, and comparable laws elsewhere, you can:

Therapists: you can export your entire practice at any time from Import / Export, as machine-readable JSON, optionally encrypted with a passphrase only you know. You can delete your account and everything in it from Settings; deletion is immediate and irreversible, so export first.

Clients: contact your therapist, who holds your record and can correct, export or delete it. If you cannot reach them, write to us and we will help them respond.

If you are a client

You may have reached a TheraBoard page through a link your therapist sent: to book, to fill in an intake form, or to complete a questionnaire. Those links are signed, expire, and are scoped to one purpose, so a questionnaire link cannot be replayed against a booking.

You do not need an account, and we do not create one for you. What you enter goes to your therapist's records. The consent wording you agree to is stored exactly as it was shown to you, with the time you agreed, so there is no argument later about what was asked.

If a questionnaire suggests you may be at risk of harming yourself, your therapist is notified promptly and you are shown support numbers immediately, including Tele-MANAS (14416), AASRA (9820466726) and 112. This is a deliberate exception to ordinary processing, and it exists to keep people safe.

How long we keep things

Security

No system is perfectly secure. If we discover a breach affecting personal data, we will notify the Data Protection Board and affected users without undue delay, and tell you what happened in plain language rather than euphemism.

Changes and contact

If we change this policy materially, we will say so in the app rather than quietly editing this page. Continued use after a change means acceptance, but we will not treat silence as consent for anything genuinely new.

Privacy questions and data requests: privacy@everythingpro.co.in

A note on this document. It describes accurately what the software does. It is not legal advice, and it is not a substitute for having a lawyer review your own obligations. If you are a therapist, you remain responsible for your professional body's record-keeping and confidentiality requirements, which may be stricter than anything here.