Encrypted at the application layer
Clinical free-text — session notes, clients' tool entries — is encrypted before it reaches the database, not just in transit.
Alongside the caseload you trained for, private practice hands you a second one: consent forms, retention rules, encryption questions, and the low hum of “am I doing GDPR right?”
Privacy & consent management
Therapy runs on trust, so privacy isn't a feature here — it's the default posture of the whole platform.
Why it helps
Send agreements to a client's app and watch their status — signed, pending, expired — from the client profile.
Clinical free-text — session notes, clients' tool entries — is encrypted before it ever reaches the database.
Every record is scoped to the therapist–client relationship. CBT Flow staff functionally cannot read client data.
How it's built
Specifics beat reassurance. Here is exactly how client data is protected in CBT Flow:
Clinical free-text — session notes, clients' tool entries — is encrypted before it reaches the database, not just in transit.
Every record is scoped to the therapist–client relationship, enforced per person at the database layer.
CBT Flow staff functionally cannot browse your clients' data.
Clients can see their data; you keep control of your practice's records; deletion and export follow the rules.
Send consent forms and agreements to a client's app, watch their status — signed, pending, expired — from the client profile, and keep the record for as long as regulation asks.
In writing
Read them yourself: the privacy policy and the data processing agreement are public — one plain read, no small print theatre.
Claim 60 days of Flow Pro now. Your 60 days begin when you activate your invitation.
60 days of Flow Pro · no card required to begin