CBT Flow

Privacy & Security

Their trust, protected by default.

Therapy runs on trust, so we treat privacy as the starting condition, not a feature. This page says exactly where data lives, what is encrypted, and who can see what — and how CBT Flow quietly keeps your own practice compliant along the way. In our experience the red flag isn't a hard question, it's a vague answer.

Principles

How we think about your clients' data

Private by default. The most protective setting is the starting setting — nothing clinical is shared, shown, or sent unless you choose it.

Least access, enforced in the database. Every record is scoped to the therapist–client relationship at the database layer — not by interface rules that can be bypassed.

Your practice's data is yours. Export it, move it, delete it. A platform that makes leaving hard is holding data hostage, not keeping it safe.

Compliance in the background. Consent status, audit trails, retention — the platform carries the bookkeeping so it isn't one more thing on your list.

Claims you can check. No badge-wall theatre: everything on this page is specific enough to verify, and we'd rather say “in progress” than overclaim.

Platform safeguards

Protection built into the product

Security that only lives in a data centre doesn't help mid-session. These are the protections built into the product itself — for the room, the waiting area, and the shared kitchen table.

  • Consent management. Agreements and consent forms tracked per client with signed / pending / expired status — re-consent is prompted when a document version changes.
  • Client-space isolation. Each client's app shows only what you've assigned to them — their tasks, their thread, their records, nothing else.
  • Quiet notifications. Push messages and emails never carry clinical content — lock screens and inboxes aren't confidential spaces.
  • Two-factor authentication. Authenticator-app codes for therapist accounts — optional, and two minutes to switch on in Settings.
  • Sleep mode with PIN. Leaving the app or going idle locks it behind a 4-digit PIN — for shared devices and laptops left open between sessions.
  • Privacy mode. One tap blurs names and clinical text — for screen-sharing, supervision, and over-the-shoulder moments.
  • Safety planning. A structured, always-reachable safety plan in the client's app, built with you in session.In progress

Encryption

What's encrypted — beyond the standard

Everything is encrypted in transit (TLS) and at rest. On top of that, the most sensitive clinical free text — session notes and clients' therapy-tool entries (thought records, experiment write-ups) — carries an extra layer of field-level encryption (AES-256-GCM) applied before it reaches the database. Even someone with direct database access sees ciphertext, not clinical content.

Identity and clinical content are kept apart: internal tooling works with anonymised identifiers and counts, so operating the platform never means reading a caseload. If a database were ever stolen, names would not sit next to readable notes — the clinical text is ciphertext without keys that are stored separately.

Access control

Who can see what

Access is enforced in the database, per person: every record is scoped to the therapist–client relationship. A therapist can never see another practice's clients; a client can never see another client's anything.

Staff functionally can't browse

CBT Flow staff functionally cannot browse client records. Internal admin surfaces show anonymised counts and system health — the encrypted clinical fields are unreadable even to us.

Private files, signed links

Files (worksheets, uploads) live in private storage; the app opens them through short-lived signed links — minutes, not forever-URLs.

Deliberately quiet notifications

Push messages and emails never contain clinical content — no measure names, no homework titles — because lock screens and inboxes aren't confidential spaces.

Risk alerts, minimal by design

Risk alerts reach only the treating therapist, and even those carry no answer details.

For your clients

Your clients' own access

Each client sees only their own space: their tasks, their check-ins, their sessions, their invoices, their private thread to you. Clients can download every invoice you issue them, any time.

Data residency

Where your data lives

Client records are stored in the EU (Ireland — AWS eu-west-1), encrypted in transit and at rest. UK GDPR applies end to end, and a Data Processing Agreement for your practice is available to every account. Daily encrypted backups protect against loss. Cookies follow the same philosophy — nothing non-essential is set without consent, as the Cookie Policy and the Cookies control in the footer make easy to check.

Portability

Leaving is allowed

Cancel monthly, no exit fee, no minimum term. Your records are portable because they're yours.

A one-click export of everything — clients, notes, measures, invoices, files — is being built into Settings; today, export is available on request and fulfilled promptly.In progress

Signed consent records download as court-ready PDFs — the exact wording signed, a typed-name signature block, timestamp and audit trail on one page.

Structured import, so moving to CBT Flow doesn't mean retyping a practice.In progress

Governance

Housekeeping we do for you

Compliance that depends on memory fails on busy weeks. The platform carries the routine so it isn't one more thing on your list.

  • Consent forms and agreements tracked per client, with status (signed / pending / expired) visible at a glance.
  • An audit trail behind consent and account changes — who did what, when.
  • Configurable retention with automatic purge of expired records.In progress
  • Compliance reminders — expiring consents, retention reviews, and your own renewals (insurance, registration, supervision), nudged before they're due.In progress

Client payments

Payments

Card details never touch CBT Flow — payments are processed by Stripe (PCI DSS Level 1).

Client payments settle directly to your own bank account through your practice's Stripe account, with your practice name on the client's statement.In progress

Incident response

If something ever goes wrong

Our commitment: affected practices notified without undue delay and within 72 hours of us becoming aware of a reportable breach, with a plain-English account of what happened, what data was involved, and what we've done — as UK GDPR requires.

Security researchers: we welcome responsible disclosure at security@cbtflow.com — see security.txt.

Subprocessors

Who we share data with

Only what each needs, nothing more.

01

AWS / Supabase

EU-Ireland database and storage.

02

Stripe

Payments.

03

Google Firebase

Push notification delivery — message routing only, no clinical content by design.

04

Resend

Transactional email.

05

Vercel

Application hosting.

06

Full list, with roles

Every subprocessor and exactly what it does, in the Data Processing Agreement.

Learn more

Registration

Registered with the ICO

CBT Flow's operator, Digita1 OÜ, is registered with the UK Information Commissioner's Office as a data controller — registration reference ZC196420, listed under the name CBT Flow, valid to 11 July 2027. Verify it yourself on the ICO register or download the registration certificate (PDF). Data protection contact: privacy@cbtflow.com.

Ask us anything specific.

Vague answers are the red flag, not hard questions. This page was last reviewed on 22 July 2026.