App Privacy Policy
Last updated: September 11, 2026
This policy applies to the InterSesh application and early-access product used by clinicians and clients. It explains the information involved in using the application and how to contact us about privacy.
Scope of this policy
InterSesh supports between-session information gathering and clinical workflow. This policy covers application accounts, information entered through application features, and related support communications. The public marketing website, its early-access interest form, and website analytics are covered separately by the Website Privacy Policy. Application use is also subject to the App Terms of Use.
Early access and synthetic client information
InterSesh is currently in early access. During the current testing phase, clinicians should use only synthetic or fictional client information. Production use with identifiable client information will be enabled as the applicable privacy, security, contractual, and jurisdictional safeguards are completed.
Do not enter real client names, contact details, health information, or other information that could identify a client during this phase. This restriction applies to client profiles, free-text fields, uploads, and other application content. Clinicians may use their own accurate professional account details; test client identities and client-related content must be fictional. If identifiable client information is entered by mistake, contact us without including that information in your email.
Information users provide
Information may be provided when you create or use an account, set up a practice or test client, enter information through available features, or contact us for help. The information involved depends on the features you use. Please limit support messages to what is needed to explain the issue and do not send passwords or identifiable client information.
Clinician and client account information
Account and profile information may include names, email addresses, professional roles, practice or organization details, account identifiers, organization memberships, and clinician-client assignments. These details support account administration and determine which practice, client, or clinician experience an account can access. Client account and profile details must remain synthetic during current testing.
Clinical and between-session information
Application features may hold client context, treatment-plan goals, commitments and their schedules, reported outcomes and barriers, check-ins, journal entries, worksheets, and clinician notes or reviews. The application may organize this information into summaries, performance views, and session-preparation material for clinician review. During early access, all client-related information, including any resulting summaries, must relate only to fictional clients.
Account roles and clinician-client assignments are intended to govern access to relevant information. This policy does not authorize uploading real clinical records or replace any privacy information or informed-consent process a clinician must provide for their practice.
Authentication and security information
The authentication service processes the sign-in and session information needed to authenticate accounts and maintain access. The application also uses account identifiers, role information, memberships, and assignments to apply access permissions. Keep credentials private and contact us if you suspect that someone else has accessed your account.
Technical and logging information
Operating the application can involve technical information such as IP addresses, browser or device information, request timestamps, service errors, and account or request identifiers associated with an event. This information may be processed by the application platform to deliver the service, troubleshoot faults, and investigate security issues. The separate Website Privacy Policy describes analytics on the public website; its analytics choices should not be taken as a description of application logging.
Purposes for processing information
Information is processed to provide account access, organize practice and client workflows, store and display information supplied through application features, and produce the summaries and views those features support. It is also used to administer early access, respond to support and privacy requests, diagnose problems, assess feedback, protect the service, and meet applicable legal obligations. The current testing phase is for evaluating the product with fictional client information.
Service providers and subprocessors
The early-access application is built on Base44, which provides the application platform, including hosting, authentication, and data services. Information involved in those functions may be processed by Base44 and the service providers or subprocessors it uses to deliver them. Correspondence sent to our contact address is also handled through the email service used to receive and respond to it.
For questions about the providers involved in your early-access use, including subprocessors, their roles, and the applicable processing arrangements, contact us before entering information. This policy does not establish a production data-processing agreement or authorize identifiable client data use. Information may also be disclosed where required by applicable law or a lawful request.
Cross-border processing
Processing through service providers may take place outside your province, territory, or country, where different laws and lawful government-access requirements may apply. This policy does not promise storage in a particular jurisdiction. Contact us for information about processing locations and applicable arrangements before assessing whether the service is suitable for your practice. Identifiable client information remains prohibited during the current testing phase.
Security safeguards
The application uses authentication and role- and assignment-based access controls intended to restrict access to authorized users. Privacy and security safeguards are being evaluated during early access. No online service or storage method can be guaranteed completely secure. Users should protect their credentials, sign out on shared devices, and report suspected access problems.
This policy does not assert healthcare compliance or regulatory certification. Production use with identifiable client information depends on completion of the applicable safeguards and arrangements described above.
Retention and deletion
Retention depends on the purposes for which information is held, account and early-access administration, and applicable legal or recordkeeping requirements. This policy does not set a fixed retention period for all information. You can request account closure or deletion by contacting us. We may need to verify your identity and clarify which information the request concerns.
Deletion of an account does not necessarily delete every related record immediately. Provider backups, security records, or information that must be retained for applicable obligations may be handled on a different schedule. If a request concerns information maintained for a clinician or practice, their authority and relevant recordkeeping duties may also need to be considered. We will explain relevant limitations when responding to a request.
Access and correction requests
You may contact us to request access to, or correction of, personal information associated with your account. We may need information to verify your identity and authority to make the request. Where appropriate, we may coordinate with the relevant clinician or practice. Requests are handled subject to applicable law and the rights of other people; contact us if you have a concern about our response.
Incident and breach handling
If we become aware of suspected unauthorized access, loss, or disclosure, we will assess the issue, take appropriate steps to contain and address it, and work with relevant service providers where needed. We will notify affected people, practices, or authorities when required by applicable law. To report a suspected incident, contact us promptly with a description of the issue, without including passwords or identifiable client information.
Changes to this policy
We may update this policy as the application and its information practices develop. The date above identifies the latest revision. We will provide additional notice or seek consent for material changes where required. Publication of an updated policy alone does not lift the synthetic-data restriction; production use with identifiable client information must be explicitly enabled.
Contact
For application privacy questions, access or correction requests, account deletion requests, or suspected privacy incidents, contact InterSesh at jamieson@getintersesh.com.