
Your privacy isn't a feature — it's the foundation
Privacy Policy
OutSession was built by a cybersecurity engineer. We designed the access model around the realities of therapy, not the conventions of SaaS. This policy explains exactly what we collect, what we don't, and why.
Anonymous by design
We believe therapy clients shouldn't need to hand over personal information to use a reflection tool. Therapist-connected clients are not asked for an email address, a real name, or any other identifying detail.
Your therapist sends you a private invite link. You open it once and set your own password, which only you know from that point on. No welcome emails. No app icon that needs explaining. Your therapist labels your studio with an alias they choose, and that alias is the only name we hold for you.
If you'd rather sign in with your own email address, you can switch to email sign-in from inside your studio, where your therapist has allowed it. That's the only route by which we'd hold your email.
Therapists sign up with an email address, and so do people using OutSession self-guided without a therapist. This section describes therapist-connected clients specifically.
What we collect
Studio codes and aliases
Every client studio has a code and an alias chosen by the therapist. We store both so worksheets and notes can be shared with your therapist. The alias is whatever your therapist typed, and it is the only name we hold for a therapist-connected client.
Content you create
Worksheets, notes, events, saved resources, whiteboards, and anything you write inside them. We store this so you and your therapist can return to it, to keep the tool working well, and for clinical safety audit.
Email addresses
Therapists and self-guided users sign up with one. A therapist-connected client only has an email on record if they choose email sign-in.
Technical records
IP address, browser user agent, and timestamps, recorded against sign-ins and against content you create. We keep these for security, abuse prevention, and clinical safety audit.
Cookies
HttpOnly, Secure, SameSite=Lax cookies for authentication, plus small cookies that remember your theme and layout. These are functional cookies required for the service to work, not advertising cookies.
Product analytics
We use PostHog, hosted in the EU, to understand how the product is used. It records page visits, clicks, and session recordings. Session recordings on studio and practice pages can capture text typed into forms.
What we don't collect
We've been deliberate about what we leave out. We don't sell your data. There are no advertising pixels on OutSession, no ad networks, no retargeting, and no marketing profiles built from what you write.
We don't ask therapist-connected clients for a real name, date of birth, address, phone number, or any health-service identifier such as an NHS number. We don't ask anyone for card details either. Therapist subscription payments are handled by Stripe, and the card never reaches us.
We do rely on a small set of processors to run the service. They are listed in section 05, and content you write does reach some of them.
Data protection
Encryption
All data is encrypted in transit via SSL/TLS. Authentication cookies are HttpOnly, Secure, and SameSite=Lax. Infrastructure runs on Cloudflare's global network.
Who processes your data
Cloudflare hosts the service and stores the data. OpenAI generates worksheet, note, and event content from the text you write, reached through Cloudflare's AI Gateway; under OpenAI's API terms that content is not used to train their models. PostHog, hosted in the EU, handles product analytics. Resend sends sign-in codes and invite emails. Stripe handles therapist subscription payments. Separately, if you open a resource that embeds YouTube, Vimeo, Spotify, or SoundCloud, that provider sees your IP address and browser just as it would if you visited their site directly.
GDPR alignment
We are aligned with GDPR principles. We minimise data collection and process only what's necessary. You can ask us to delete your data at any time by contacting us, and we'll action it by hand. There's no self-serve delete button yet.
Not for sale
We don't sell your data, and we don't make it available to anyone beyond the processors listed above. Your reflections stay yours.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for operational, legal, or regulatory reasons. Any update is published on this page.
We encourage you to review this policy periodically. If anything isn't clear, we'd rather you asked than assumed.
Your privacy matters to us
If you have questions about this policy or how we handle your data, reach out. We'll answer directly.
OutSession 2026|
Give Feedback