‹ session-health.com

Privacy Policy

Session ("Session", "we", "us") · Effective 11 August 2026 · Last updated 11 August 2026

Session is a practice-management and teleconsultation platform for mental-health professionals ("therapists") and the people they care for ("clients"), available at session-health.com. This policy explains what we collect, why, and the choices you have. We keep it in plain language on purpose.

1. What we collect

Account information. Therapists: name, email address, profile photo, qualifications, registration number, clinic details, availability, services and rates, UPI ID, Instagram/website handles. Clients: name, phone number, a 6-digit PIN (stored only as a salted credential, never in plain text), optional profile photo, age and gender.

Care records. Appointment details, session notes, management plans, prescriptions, bills, chat messages, ratings, and payment screenshots that clients attach to booking requests. These records are created by the therapist or client in the course of care.

Verification documents. Therapists may upload their degree, certificates and a government identity document (Aadhaar/UID) to earn a verified badge. Identity images are reviewed by our team and permanently deleted from our servers immediately after review. We retain only the verification outcome.

Technical data. Standard server logs (IP address, timestamps, requested pages) kept briefly for security and debugging. We do not run third-party advertising or analytics trackers.

2. Google user data

If a therapist chooses to connect Google Calendar, we request the calendar.events scope and use it for exactly two things:

Limited Use disclosure. Session's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except with your explicit consent, for security purposes, or to comply with law.

You can disconnect Google Calendar at any time in Settings, and additionally revoke Session's access at myaccount.google.com/permissions. Disconnecting deletes the stored refresh token.

3. How we use information

We do not sell personal data. We do not use your data for advertising. Care records are visible only to the therapist who created them and the client they belong to.

4. Who processes data for us

Each processor receives only what it needs to perform its function.

5. Roles and responsibilities

For care records, the therapist acts as the data controller of their own practice's records and Session acts as a processor providing the tools. Therapists are responsible for meeting their professional obligations regarding client records. For account data, Session is the controller.

6. Retention and deletion

7. Security

All traffic is encrypted (HTTPS). Data access is scoped per account with row-level security. Secrets and API keys are held server-side only. Video calls require a profile photo on both sides and display a professional-conduct notice.

8. Not an emergency service

Session is not a crisis or emergency service. If you or someone you know is in immediate danger or crisis in India, call Tele-MANAS: 14416 (24×7, free) or your local emergency number 112.

9. Children

Session is intended for adults. Minors may be registered as clients only by their therapist in the course of care, with consent obtained by the therapist as required by law.

10. Changes

We will post any changes to this policy on this page and update the date at the top. Material changes will be announced in the app.

11. Contact

Session · [email protected] · session-health.com