Privacy Policy

Last updated: September 22, 2026

TL;DR

  • Clinical text is processed through Reframe's application on Amazon Web Services (AWS) and Amazon Bedrock, in US AWS Regions. The generation flow does not save that text in Reframe's main database.
  • Saved worksheets stay in your browser unless you export or share them. Optional sharing stores an encrypted copy and link metadata on the server.
  • We store the information needed to run your account and requested services. This can include your email, practice details, subscription status, assessment contact information, and limited pseudonymous usage events.
  • Provider settings and agreements matter. See our Security page for processing and storage boundaries.

Who We Are

Reframe Practice ("we," "us," or "our") provides practice visibility services and clinical workflow tools for mental health professionals. Our services include website and profile work; our software helps therapists draft worksheets, session guides and progress notes.

We are based in Ontario, Canada, and operate under Canadian privacy laws including PIPEDA (Personal Information Protection and Electronic Documents Act).

What We Collect

We collect the minimum information necessary to provide our services:

Account Information

  • Email address - for account access, password resets, important service notifications, and occasional emails about changes to the tools you use. Each of those emails includes an unsubscribe link.
  • Name and credentials - your professional name and credentials (optional, for worksheet branding)
  • Practice information - practice name and branding preferences (optional)

Usage Information

  • Generation counts - how many worksheets you have created (for subscription limits)
  • Feature usage - named actions, bounded counts, device category, and referring domain used to improve the product. Our anonymous first-party funnel uses a random browser-session identifier, not an email or a stable device fingerprint.
  • Subscription status - your current plan and billing cycle

Assessments and Service Requests

  • Contact and practice information - information you submit when requesting a visibility assessment, report, consultation, or service, such as your name, email, practice name, location, website, and public profile URLs
  • Assessment answers and results - the professional-practice answers and generated visibility findings needed to provide the report and related follow-up
  • Source information - referral source and campaign categories used to understand how a request reached Reframe

Payment Information

  • Billing details - processed securely by Stripe. We do not store your full credit card number.

Clinical Content and Storage

The generation flow does not create a clinical record in Reframe's main database. Local saving, optional encrypted sharing and provider processing have different boundaries:

  • xClient descriptions - The text you submit is processed through Reframe's application on AWS and Amazon Bedrock. The generation flow does not write that clinical text to Reframe's main database. On AWS, Reframe stores account usage counts and short audit records without note text in Amazon S3, encrypted with a Reframe-managed AWS KMS key.
  • xGenerated worksheets - Saved worksheets are stored in your browser (IndexedDB). If you choose a share link, an encrypted worksheet copy and link metadata are stored server-side. Clearing browser data can remove your local copy.
  • xSession notes or clinical content - The generation flow does not save readable clinical content in Reframe's main database. We do retain the account and usage records described above.
  • xAI conversation logs - Provider processing is governed by the service terms and account configuration. Do not interpret local saving or the absence of a clinical database write as proof that all provider logging and caching are disabled.

AI Processing

We use Amazon Bedrock, run by Amazon Web Services, to generate progress notes. The model is Anthropic's Claude, operated by AWS inside Bedrock. Here is what you should know:

  • Processing path - Your browser sends clinical text to Reframe's application at notes.reframepractice.com, which runs on AWS. The application requests generation from Amazon Bedrock and returns the draft to your browser. The text is not sent to Reframe's main website host (Vercel), our account database (Supabase), or any analytics or advertising service.
  • Where it is processed - Requests use Bedrock's US cross-Region inference profile, so processing happens in US AWS Regions.
  • Agreement - Reframe has accepted the AWS Business Associate Addendum for the AWS account that runs this path, and uses AWS services that AWS lists as HIPAA eligible. An agreement and eligible services do not by themselves make any particular use HIPAA compliant.
  • Retention and logging - Reframe's AWS account sets Amazon Bedrock's data retention mode to none and does not turn on model invocation logging. AWS describes these settings in its Amazon Bedrock data retention documentation, and states that model providers such as Anthropic do not have access to Bedrock prompts and completions (Bedrock data protection). Short-lived prompt caching inside the service may still occur. Reframe's own application logs record request metadata, not note text.
  • Training - Under the Anthropic terms that apply on Amazon Bedrock, Anthropic may not train models on content from the service. Reframe does not use your clinical text to train models.
  • Your workflow - Review the applicable agreements and processing requirements for your practice before entering clinical information. Architecture alone does not establish compliance.

For our Profile Optimizer tool (which helps you write your Psychology Today profile), we use a separate AI service. This tool only processes your own professional bio text, not client information.

Best practice: Use only the information needed for the task and avoid identifying details. Removing a name alone does not necessarily de-identify clinical information.

Third-Party Services

We use the following categories of service providers:

Service TypeProviderData Processed
AI ProcessingAmazon Web Services (Amazon Bedrock, running Anthropic's Claude model)Clinical text submitted for generation, processed in US AWS Regions with Bedrock data retention set to none
Clinical Tools HostingAmazon Web Services (notes.reframepractice.com)Clinical text in transit for generation; account usage counts and short audit records without note text; server logs without clinical text
Practice Visibility ProcessingAnthropic, OpenAI, OpenRouter, Perplexity, Jina, GooglePublic practice websites, profiles, locations, specialties, and professional copy only; never client descriptions or clinical text
Accounts and StorageSupabaseAccount and service records, usage metadata, and optional encrypted worksheet shares
PaymentsStripePayment information, billing address
EmailResendEmail address (for transactional emails)
HostingVercelServer logs, IP addresses
Analytics (cookieless)DataFast (cookieless; Google Analytics is currently disabled)Page URLs viewed, referral and device categories, approved conversion events, and a daily rotating pseudonymous visitor identifier
Analytics (cookieless)Ahrefs Web AnalyticsPublic-page views only, using query-free URLs and origin-only external referrers; no forms, clicks, assessment results, account pages, or private routes
Analytics (cookieless)Vercel Web AnalyticsAggregate page views with query strings and private route identifiers removed before sending
AdvertisingMeta PixelPage views on public marketing pages only; never account pages, clinical tools, or assessment result pages

Important: Clinical text submitted for generation is processed through Reframe's application on AWS and Amazon Bedrock. Worksheet sharing is currently paused; links shared earlier were stored as encrypted copies in Supabase. Analytics and advertising services do not receive clinical text or worksheet content.

Cross-Border Data Transfers

Reframe Practice is a Canadian company, but some of our service providers are based in the United States. When you use our AI generation features, your data is processed in the United States.

For Canadian users: By using our services, you consent to the transfer of your information to the United States for processing. We ensure a comparable level of protection through contractual safeguards (Data Processing Agreements) with our service providers, as required by PIPEDA.

For US users: Your data is processed domestically within the United States.

Note: Data processed in the United States may be accessible to US courts, law enforcement, or national security authorities under applicable US laws. Generation does not write clinical content to our main database. Optional encrypted sharing and provider-side retention are separate, as described above.

Analytics and Cookies

We use analytics tools to understand how our product is used and to improve it:

Cookieless analytics (no persistent analytics cookies or consent banner):

  • DataFast - Measures page views, referral sources, and approved conversion events. Its cookieless script sends events directly to DataFast and does not use cookies for visitor identification. It uses session-only browser storage and a pseudonymous identifier derived by DataFast from the visitor's IP address, browser User-Agent, the site domain, and a salt that rotates about every 24 hours. The identifier cannot follow a visitor across days.
  • Ahrefs Web Analytics - Measures page views on public pages only. Reframe sends a minimal cookieless pageview after removing query strings and reducing external referrers to their origin. Ahrefs does not receive clicks, forms, assessment results, account pages, private routes, names, or email addresses from this integration.
  • Vercel Web Analytics - Provides aggregate page statistics. Reframe removes query strings and replaces identifier-bearing paths with general route labels before an analytics event is sent.

Cookie-based analytics:

  • Microsoft Clarity - Session recordings and heatmaps on public marketing pages only (homepage, About, services, product, pricing, guides, answers, and the Practice Checkup landing page). It uses cookies. It does not load on account pages, login, dashboards, clinical tools, or assessment result pages. Input fields are masked. We do not use recordings of clinical or account activity.
  • Meta Pixel - Advertising measurement on public marketing pages only (homepage, About, services, product, pricing, contact, booking, guides, answers, and the Practice Checkup landing page). It uses cookies and Meta may match a visit to a Meta account. It does not load on account pages, login, dashboards, clinical tools, or assessment result pages, and it sends nothing from those pages if you navigate to them. We turn off Meta's automatic collection, so it does not scrape button clicks or form fields, and automatic advanced matching is off: we never send your name, email address, or phone number to Meta. The only signals we send are page views and two content-free milestones on the public assessment page (assessment started, assessment submitted), each sent without any answers, form data, or personal details. It never receives worksheet content, client descriptions, assessment answers, or generated clinical content.
  • Google Analytics 4 is currently disabled. If it is re-enabled, it will require consent and must pass our private-route and query-redaction verification first.

The clinical tools host, notes.reframepractice.com, loads none of these analytics or advertising services.

We also keep limited first-party event records in Supabase so we can measure activation and conversion. These records use named event categories and approved machine-readable properties. We do not send or store worksheet content, client descriptions, assessment answers, generated clinical content, names, or email addresses in analytics events.

Your Rights

You have the following rights regarding your personal information:

  • Access - You can request a copy of the personal information we hold about you.
  • Correction - You can update your account information at any time through your settings.
  • Deletion - You can request deletion of your account and associated data.
  • Data Portability - You can export your locally-stored worksheets at any time.

To exercise these rights, contact us at privacy@reframepractice.com.

For California residents: Under the CCPA, you have additional rights including the right to know what personal information we collect and the right to opt out of the sale of personal information. We do not sell your personal information.

Data Retention

  • Account information - Retained while your account is active. Deleted within 30 days of account deletion request.
  • Payment records - Retained as required by tax and accounting regulations (typically 7 years).
  • Client descriptions - The generation flow does not save clinical text in Reframe's main database. Provider processing is described above.
  • Generated worksheets - Saved locally in your browser unless exported or shared. Optional sharing stores an encrypted copy and link metadata with the selected expiry. An expired link stops serving the worksheet; this does not promise immediate deletion from every storage layer or backup.
  • Authenticated usage events - Retained while your account remains active and removed when the associated account is deleted.
  • Anonymous funnel events - Retained for product and business measurement. They use a random browser-session identifier and are not linked to your account or email.
  • Assessment and service-request records - Retained while needed to provide the requested report or service, maintain the business relationship, meet legal obligations, or respond to a valid deletion request.

Children's Privacy

Reframe Practice is a business tool for licensed mental health professionals. We do not knowingly collect personal information from children under 13. If you are a therapist working with minor clients, you are responsible for ensuring you have appropriate parental consent for any information you input into our system, as required by your professional obligations and applicable laws including COPPA.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a prominent notice on our service at least 30 days before they take effect. Your continued use of the service after the effective date constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or our privacy practices, contact us at: