Theramate Theramate
Back to home
§Index

Privacy Policy

Theramate is designed by and for mental health professionals. Privacy is not a feature: it is the foundation of our platform.

Last updated: May 2026
§ 01

Data Collected

  • Account data Email, name, billing information
  • Clinical data Session notes, reports, patient questionnaires
  • Technical data Login logs, device used (for support)
§ 03

Encryption

Core guarantee

All clinical data and PII are encrypted with AES-256 before storage. Audio files sent for transcription are encrypted during transient server processing, verified, then deleted after integration into the record. Keys are managed server-side in a secure environment, with restricted access, logging, and internal controls. This is not end-to-end encryption where you alone hold the key: technical access required for operations or security may exist. Our operational commitment is not to view users' clinical content; any technical intervention is limited, authorized, logged, and not used to read records, except under a valid legal obligation.

§ 04

Hosting

Core guarantee

Your data is hosted on Google Cloud infrastructure located in the European Union, including Belgium and Germany depending on the services used. Technical subprocessors are contractually governed. Theramate application data remains in the European Union.

§ 05

Subprocessors

To operate Theramate, we rely on technical subprocessors governed by contract. This list is reflected in our contractual documentation and may evolve in accordance with the DPA and applicable Terms.

  • Google Cloud (European Union) Primary hosting, database, serverless functions, authentication, and technical infrastructure. EU regions used include Belgium and Germany depending on the services.
  • Scaleway (France) European cloud used for selected technical processing or storage. Infrastructure and datacenters based in France.
  • Mistral (France) European AI provider for selected processing. No training on your data, no API-side retention for its own account.
  • Google Technical service provider and, depending on enabled features, provider for selected AI processing. No training on your data in Theramate's configuration.
  • Stripe (Ireland) Subscription management, payments, billing, and, where applicable, patient payments through Stripe Connect.
§ 06

Artificial Intelligence

  • No training Your data is never used to train or improve AI models
  • Controlled APIs AI processing goes through contractually governed providers. Data necessary for a request is not retained API-side for their own account.
  • Assistance, not automated decision-making AI suggestions are drafting, summarization, or organization aids. No clinical or therapeutic decision is made solely by AI: you remain responsible for reviewing, editing, accepting, or rejecting proposed content.
  • Transparency You know when AI is used, for what purpose, and you remain in control of clinical use of the results
§ 07

Your Rights (GDPR)

  • Access View all your data at any time
  • Rectification Correct your personal information
  • Portability Export your data in standard format (Word, PDF)
  • Deletion Request complete and irreversible deletion of your data
§ 08

Retention

Your data is retained for the duration of your subscription. Upon cancellation, you have 1 year to export your data before permanent deletion.

§ 09

Data Sharing

We never sell your data and do not use it for advertising. It may be processed by the technical subprocessors listed above, strictly to provide Theramate, or disclosed where a valid legal obligation requires it. Your professional and clinical content remains under your control.

§ 10

Google Calendar Integration

Core guarantee
  • Data Accessed Theramate accesses your Google Calendar events (title, time, location) and your Google email address for account verification. No other Google data is accessed.
  • Data Usage Google Calendar data is used exclusively to synchronize your appointments between Theramate and Google Calendar. Events are synchronized bidirectionally over a 90-day window. No clinical data (session notes, diagnoses, patient history) is ever sent to Google Calendar.
  • Data Sharing Your Google data is not shared with any third party. It remains strictly between Theramate and your Google account. Theramate does not use Google data for advertising purposes.
  • Data Storage & Protection Google authentication tokens are encrypted with AES-256 and stored exclusively server-side in a secure environment. No tokens are ever stored on your device. Synchronized appointment titles are configurable (generic, initials, or first name only) to protect your patients' privacy.
  • Data Retention & Deletion You can disconnect Google Calendar at any time from Theramate settings. Disconnection immediately revokes access, deletes all encrypted tokens from our servers, and stops all synchronization. Events already in your Google Calendar are not deleted.
§ 11

Google API Services Compliance

Theramate's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Theramate only uses Google data to provide the calendar synchronization functionality. The data is not used for advertising, is not sold to third parties, and is not used to train artificial intelligence models.

§DPO Contact

For any questions regarding your personal data:

privacy@theramate.pro

Playfields SPRL.Brussels, Belgium