Your privacy isn't a feature — it's the foundation

Privacy Policy

Privacy Policy

OutSession was built by a cybersecurity engineer. We designed the access model around the realities of therapy, not the conventions of SaaS. This policy explains exactly what we collect, what we don't, and why.

01

Anonymous by design

We believe therapy clients shouldn't need to hand over personal information to use a reflection tool. Therapist-connected clients are not asked for an email address, a real name, or any other identifying detail.

Your therapist sends you a private invite link. You open it once and set your own password, which only you know from that point on. No welcome emails. No app icon that needs explaining. Your therapist labels your studio with an alias they choose, and that alias is the only name we hold for you.

If you'd rather sign in with your own email address, you can switch to email sign-in from inside your studio, where your therapist has allowed it. That's the only route by which we'd hold your email.

Therapists sign up with an email address, and so do people using OutSession self-guided without a therapist. This section describes therapist-connected clients specifically.

02

What we collect

Studio codes and aliases

Every client studio has a code and an alias chosen by the therapist. We store both so worksheets and notes can be shared with your therapist. The alias is whatever your therapist typed, and it is the only name we hold for a therapist-connected client.

Content you create

Worksheets, notes, events, saved resources, whiteboards, and anything you write inside them. We store this so you and your therapist can return to it, to keep the tool working well, and for clinical safety audit.

Email addresses

Therapists and self-guided users sign up with one. A therapist-connected client only has an email on record if they choose email sign-in.

Technical records

IP address, browser user agent, and timestamps, recorded against sign-ins and against content you create. We keep these for security, abuse prevention, and clinical safety audit.

Cookies

HttpOnly, Secure, SameSite=Lax cookies for authentication, plus small cookies that remember your theme and layout. These are functional cookies required for the service to work, not advertising cookies.

Product analytics

We use PostHog, hosted in the EU, to understand how the product is used. It records page visits, clicks, and session recordings. Session recordings on studio and practice pages can capture text typed into forms.

03

What we don't collect

We've been deliberate about what we leave out. We don't sell your data. There are no advertising pixels on OutSession, no ad networks, no retargeting, and no marketing profiles built from what you write.

We don't ask therapist-connected clients for a real name, date of birth, address, phone number, or any health-service identifier such as an NHS number. We don't ask anyone for card details either. Therapist subscription payments are handled by Stripe, and the card never reaches us.

We do rely on a small set of processors to run the service. They are listed in section 05, and content you write does reach some of them.

04

Sharing and visibility

Worksheets and whiteboards stay private until the client shares them. Notes, events, and resources a client saves are visible to their therapist from the moment they're created, because those are the things a client makes in order to raise them in session. A client can turn that visibility off on any individual item.

The therapist can't sign in to the studio after handoff. The invite link works once, and the temporary password it carries is erased as soon as the client sets their own.

If a therapist invites a two-way connection, the client must explicitly accept. Content created before an upgrade can't be shared into it. Visibility is always the client's decision.

05

Data protection

Encryption

All data is encrypted in transit via SSL/TLS. Authentication cookies are HttpOnly, Secure, and SameSite=Lax. Infrastructure runs on Cloudflare's global network.

Who processes your data

Cloudflare hosts the service and stores the data. OpenAI generates worksheet, note, and event content from the text you write, reached through Cloudflare's AI Gateway; under OpenAI's API terms that content is not used to train their models. PostHog, hosted in the EU, handles product analytics. Resend sends sign-in codes and invite emails. Stripe handles therapist subscription payments. Separately, if you open a resource that embeds YouTube, Vimeo, Spotify, or SoundCloud, that provider sees your IP address and browser just as it would if you visited their site directly.

GDPR alignment

We are aligned with GDPR principles. We minimise data collection and process only what's necessary. You can ask us to delete your data at any time by contacting us, and we'll action it by hand. There's no self-serve delete button yet.

Not for sale

We don't sell your data, and we don't make it available to anyone beyond the processors listed above. Your reflections stay yours.

06

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for operational, legal, or regulatory reasons. Any update is published on this page.

We encourage you to review this policy periodically. If anything isn't clear, we'd rather you asked than assumed.

Questions?

Your privacy matters to us

If you have questions about this policy or how we handle your data, reach out. We'll answer directly.