CBT Flow

Alongside the caseload you trained for, private practice hands you a second one: consent forms, retention rules, encryption questions, and the low hum of “am I doing GDPR right?”

Privacy & consent management

Their trust, protected by default.

Therapy runs on trust, so privacy isn't a feature here — it's the default posture of the whole platform.

Why it helps

Specifics, not reassurance

01

Consent with a paper trail

Send agreements to a client's app and watch their status — signed, pending, expired — from the client profile.

02

Encrypted where it matters most

Clinical free-text — session notes, clients' tool entries — is encrypted before it ever reaches the database.

03

Nobody browses your clients

Every record is scoped to the therapist–client relationship. CBT Flow staff functionally cannot read client data.

How it's built

The specifics, plainly

Specifics beat reassurance. Here is exactly how client data is protected in CBT Flow:

Encrypted at the application layer

Clinical free-text — session notes, clients' tool entries — is encrypted before it reaches the database, not just in transit.

Access enforced in the database

Every record is scoped to the therapist–client relationship, enforced per person at the database layer.

Staff can't browse

CBT Flow staff functionally cannot browse your clients' data.

UK GDPR, end to end

Clients can see their data; you keep control of your practice's records; deletion and export follow the rules.

Consent, documented

Send consent forms and agreements to a client's app, watch their status — signed, pending, expired — from the client profile, and keep the record for as long as regulation asks.

In writing

The paperwork behind the promises

Read them yourself: the privacy policy and the data processing agreement are public — one plain read, no small print theatre.

Join the CBT Flow launch list

Claim 60 days of Flow Pro now. Your 60 days begin when you activate your invitation.

60 days of Flow Pro · no card required to begin