Client Privacy Notice
Version v1.0-temp · Effective 12 July 2026
Last updated 12 July 2026
Version: v1.0-temp · Last updated: 13 July 2026 · Effective: from the date this version is published at cbtflow.com/legal/client-privacy
The most important points
This notice is for clients invited to use the CBT Flow Client app.
- Your therapist or therapy practice (your Practice) normally decides why and how your therapy and clinical information is used. It is the controller of that information.
- CBT Flow provides the app and normally handles that information for the Practice as its processor.
- CBT Flow is separately responsible as a controller for limited purposes such as protecting your account, managing support, preventing misuse and meeting legal obligations.
- Nobody — including a parent, guardian or family member — automatically gets access to your account or records through CBT Flow.
- The app is not continuously monitored and does not currently send automated risk alerts. Do not use the app for an emergency.
- Contact the Practice about your clinical record. Contact privacy@cbtflow.com about personal information for which CBT Flow is responsible. We will help route a request if you are unsure.
1. Who is responsible for your information?
Your Practice
The Practice named in your invitation and app normally controls your therapy record. It decides matters such as what clinical information to collect, what activities to assign, who in the Practice may see it, how it supports your care, and how long the clinical record must be kept.
The Practice should give you its own privacy information and contact details. Ask it about therapy confidentiality, clinical notes, disclosure, safeguarding, retention or access to your clinical record.
CBT Flow
The Client app is supplied by Digita1 OÜ, trading as CBT Flow, an Estonian company (registry code 17003669) with registered office at Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia.
Contact us at privacy@cbtflow.com. You can also contact legal@cbtflow.com or write to the registered office above. Our internal Privacy Lead is Paulius Alionis.
Digita1 OÜ has paid the UK data protection fee to the Information Commissioner's Office (ICO); our registration reference will be added to this page when the ICO issues it. We are appointing a UK representative under Article 27 UK GDPR; their details will be published here once confirmed.
2. Who can use the app, and access by others
The Client app is currently available only to clients aged 18 or over. We plan to support 16 and 17-year-olds in a future release, once dedicated safeguards for younger users are in place; this notice will be updated first.
Whatever your age, your privacy rights belong to you. A parent, guardian or family member does not automatically get access to your CBT Flow account, messages, measures, appointments, invoices or clinical record. If someone else asks CBT Flow for your information, we do not release it automatically: we check identity, authority and the legal basis for any disclosure, involving the Practice and, where appropriate, you.
Your Practice is responsible for discussing confidentiality with you, and may sometimes need to share information if you agree, for safeguarding, to prevent serious harm, or where the law otherwise permits or requires it.
3. Information handled through the app
The exact information depends on the features your Practice uses. It may include:
- identity and account details: name, date of birth or age/eligibility information, email or phone number, account identifiers and sign-in information;
- therapy and health information: Treatment Plans, session information, notes shared with you, homework, questionnaires, measures such as PHQ-9 or GAD-7, answers, scores, progress information, messages and files;
- appointments and communications: appointment details, reminders, messages and notification status;
- payment information: Practice identity, amount, currency, payment status, invoice/receipt information, Stripe identifiers, refunds and disputes — payment card details are collected by Stripe through its hosted payment components, and CBT Flow does not receive or store your full card number;
- device and technical information: app version, device/operating-system information, IP address, session, authentication, diagnostics, logs, security events, push token and permission state;
- support information: questions, communications, attachments and action taken; and
- legal and rights information: consent/terms version evidence, requests, complaints, disclosures, legal holds and audit records.
Information may come from you, your Practice, your device or app store, Stripe and other service providers, or from app activity and security logs.
4. Why information is used and who decides
| Purpose | Main information | Who decides / role | Legal basis where CBT Flow is controller |
|---|---|---|---|
| Provide the app, store the clinical record, show assigned activities, enable messages, measures, files and Practice workflows | Account, health, therapy, messages, files | Practice is normally controller; CBT Flow processes on its documented instructions | The Practice identifies its own UK GDPR Articles 6 and 9 bases |
| Set up and secure your Client app account | Identity, eligibility, credentials, device, sign-in and security events | CBT Flow controller for account security; processor for Practice-directed eligibility steps | Legitimate interests in account and service security; contract; legal obligation where applicable |
| Provide technical support | Contact, account, issue details, communications, limited diagnostic information | CBT Flow controller for its support case; processor if accessing clinical data only to assist the Practice | Legitimate interests in resolving issues and running a safe service |
| Facilitate a therapy payment and keep payment/security records | Amount, Practice, Stripe/payment identifiers, status, refunds/disputes and fraud signals | Practice supplies therapy; Stripe and CBT Flow have separate roles for parts of payment processing | Contract, legitimate interests in payment administration and fraud prevention, and legal obligations |
| Prevent misuse, investigate security incidents and establish or defend legal claims | Logs, account, device, support, incident and relevant content | CBT Flow controller to the limited extent it decides this purpose | Legitimate interests, legal obligations and the legal-claims condition where special-category data is strictly necessary |
| Prove acceptance and comply with regulators or courts | Identity, terms version, timestamp, requests, disclosures and records | CBT Flow controller | Contract, legitimate interests and legal obligations |
CBT Flow does not sell your personal information. It does not use therapist or client information to train general AI models. No third-party AI service receives clinical information unless a future feature is separately approved, risk-assessed, contractually governed and transparently explained — and any future clinical AI output must be reviewed by a therapist and must not make autonomous treatment decisions.
5. Health information, confidentiality and safeguarding
Information about mental health and therapy is special-category personal data. Your Practice must identify a lawful reason and a special-category condition for using it. CBT Flow handles it under the Practice's instructions, except where CBT Flow has a narrow separate legal purpose described above.
Therapy confidentiality is governed by the Practice's professional and legal duties, not by CBT Flow. The Practice may disclose information where you agree, where the law requires it, or where an appropriate safeguarding or serious-harm basis applies. CBT Flow may disclose information where legally required or strictly necessary to protect vital interests or establish or defend legal claims, after appropriate review.
6. What you share, and urgent situations
What you enter in the app is made available to your Practice as part of your care. CBT Flow does not continuously watch the app, and your therapist may not see what you submit immediately.
The app does not currently generate automated risk alerts: nobody is notified automatically based on your answers or scores. If we introduce such a feature in the future, it will only ever assist your therapist, will not notify anyone else automatically, and this notice will be updated first.
If you or someone else is in immediate danger, call 999. If you need urgent help with your mental health, call the NHS on 111 and select the mental health option. To talk to someone now, call the Samaritans on 116 123 (free, 24 hours a day) or text SHOUT to 85258.
7. Payments and Stripe
The Practice is the supplier of your therapy. Stripe provides payment processing and collects card details directly through its hosted components. CBT Flow facilitates the payment and receives limited payment and status information needed to operate the feature, support the Practice and meet legal obligations.
Stripe uses personal information under its own privacy notice (available on stripe.com) and may make independent decisions required for payment security, fraud prevention and legal compliance.
8. Who receives information?
Depending on the feature and the Practice's setup, information may be available to:
- the treating therapist and authorised people in the Practice;
- CBT Flow staff or contractors who need access for tightly controlled support, security or legal purposes;
- the service providers that host and support the app — listed, with their roles and locations, at cbtflow.com/legal/subprocessors (currently including Supabase for database/authentication/storage, Vercel for application delivery, Google Firebase for push notifications, Resend for transactional email and Stripe for payments);
- professional advisers, insurers, auditors and authorities where necessary; and
- a replacement provider or buyer in a genuine business reorganisation, subject to appropriate confidentiality and legal safeguards.
9. Where information is processed
CBT Flow is operated from Estonia, and the app's primary database and storage are hosted in the European Economic Area (Ireland region). Some providers or support arrangements may involve access from the UK, the EEA or other countries.
Where UK or EEA personal information is transferred to a country without an adequacy decision, the responsible controller uses an approved safeguard such as standard contractual clauses and, for UK transfers, the UK Addendum or the UK International Data Transfer Agreement, together with additional assessment where required. The supplier list at cbtflow.com/legal/subprocessors records locations and transfer routes.
10. How long information is kept
Clinical record
The Practice decides the retention period for its clinical record. Ending your app access does not necessarily delete that record, because the Practice may need to retain it for professional, safeguarding, insurance or legal reasons.
If the Practice's CBT Flow workspace ends, the Practice has a 30-day return/export window under its CBT Flow contract. The workspace is then deleted from active systems unless a documented extension or legal hold applies. Remaining backup copies expire through the documented backup lifecycle.
CBT Flow's own records
CBT Flow retains limited account-security, support, contract-acceptance, payment, fraud, complaint and legal-claims records only as long as needed for those purposes, including statutory accounting periods and the period during which a legal claim could be brought.
11. Your rights
Depending on the circumstances, you may have rights to:
- receive a copy of your personal information;
- correct inaccurate or incomplete information;
- ask for information to be deleted;
- restrict how information is used;
- object to some uses;
- receive certain information in a portable form; and
- withdraw consent where a specific use relies on consent.
These rights are not absolute. For example, a Practice may need to retain part of a clinical record or protect another person's information.
For your therapy or clinical record, contact the Practice first. For CBT Flow-controlled account, security, support or legal-compliance information, contact privacy@cbtflow.com. If you contact the wrong organisation, we will help route the request where appropriate. We may need to verify identity, and we do not treat a request from a parent, guardian or anyone else as automatic authority to receive your information.
You can also make a complaint:
- first to the Practice about its use of your clinical information;
- to CBT Flow at privacy@cbtflow.com about processing for which we are responsible — we will acknowledge your complaint within 30 days, keep you informed and tell you the outcome; and
- to the UK Information Commissioner's Office at ico.org.uk, or another data protection authority with jurisdiction.
More detail on raising requests and complaints is at cbtflow.com/legal/data-complaints.
12. Automated decisions
CBT Flow does not make solely automated decisions about you that have legal or similarly significant effects. Scores and trends shown in the app are there to assist, not replace, your therapist's judgement.
13. Security
CBT Flow uses technical and organisational measures intended to protect personal information, including access controls, encryption in transit, provider-managed encryption at rest, logging and regular backups. No system is completely secure.
Tell security@cbtflow.com promptly if you think your account or information is at risk.
14. App permissions, notifications and tracking
The app may request permissions needed for features such as notifications. You can change permissions in device settings, although some features may stop working. Notification previews can reveal sensitive information to someone who can see your screen; you can limit previews in your device settings.
We do not use advertising or marketing-analytics tools inside the Client app. Analytics and any advertising tools are limited to the public marketing website, with consent, as described in the Cookie Notice at cbtflow.com/legal/cookies.
15. Changes to this notice
This page shows the version and effective date. We will give clear notice of material changes, including in the app where appropriate. A privacy notice explains information use; accepting it is not the same as giving consent for a separate optional purpose.