SessionSteps

Privacy Policy

Last updated: September 20, 2026

What this policy covers

This policy explains how SessionSteps handles information when therapists, practice staff, and clients use the service. SessionSteps is designed for behavioral-health workflows and uses administrative, technical, and contractual safeguards appropriate to the information it processes.

Information we process

  • Account and practice information, such as names, email addresses, roles, and subscription details.
  • Information entered into the service, including assignments, worksheet responses, reflections, check-ins, and session-preparation content.
  • Security, audit, device, and service-usage information needed to operate and protect the platform.

How information is used

We use information to provide and secure the service, support users, process subscriptions, deliver requested notifications, troubleshoot problems, and improve reliability. We do not sell personal information or use clinical content for advertising.

Service providers

We use carefully selected providers for hosting, database services, secure email delivery, payments, and limited product operations. Access is limited to the purpose of providing the service, and healthcare vendors are covered by appropriate agreements where required.

Retention and choices

Practice administrators control their workspace and client records. Requests to access, correct, export, or delete information should first be directed to the relevant practice. We retain information only as needed to provide the service, meet contractual obligations, resolve disputes, and satisfy applicable law.

Contact

Privacy questions may be sent through the in-product feedback and support channel. This policy should be reviewed together with any privacy notice provided by your therapist or practice.