1. Introduction

Extended Sessions AI ("we," "us," "our," or "Company") is committed to protecting your privacy and ensuring you have a positive experience on our platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our therapy AI platform, including our website, web application, and related services (collectively, the "Service").

Extended Sessions AI is a between-session companion for therapy patients, configured and supervised by licensed therapists. Our platform is designed to provide HIPAA-compliant support for patients between their therapy sessions while maintaining the highest standards of privacy and security.

Important: Please read this Privacy Policy carefully. By accessing or using Extended Sessions AI, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy.

2. Information We Collect

We collect information necessary to provide and improve the Service. This information may include:

Account Information

Chat Session Content

Usage Data

Device and Browser Information

Communication Information

3. How We Use Your Information

We use the information we collect for the following purposes:

Providing the Service

Generating AI Responses

Clinical Support

Crisis Detection and Safety

Communication

Service Improvement

Legal Compliance

4. AI and Your Data

Your conversations are not used to train our AI models. We use Vertex AI (Google Cloud's Gemini) for generating responses with a zero-data retention policy.

How AI Processing Works

Data Retention by AI Provider

Google Cloud's Vertex AI service operates under strict data retention policies:

Clinical Summaries

Clinical summaries created from your conversations are generated by the AI but stored on our secure servers so your therapist can review your progress. These summaries are covered under HIPAA protections like all your health information.

5. Data Storage and Security

HIPAA Compliance: Extended Sessions AI is covered under a Business Associate Agreement (BAA) with Google Cloud Platform (GCP), ensuring HIPAA-compliant data handling and storage.

Infrastructure

Encryption

Access Controls

Audit Logging

Email Security

6. Who Can Access Your Data

Patient Access

You can view your own data: You can access your chat history, account information, and any summaries generated from your sessions. You have full visibility into what information we hold about you.

Therapist Access

Your therapist can view: Conversations with the AI, clinical summaries of your sessions, and progress indicators. Your therapist configured your account and can see this information to better understand your needs and tailor your in-session therapy accordingly.

Data Sharing Policy

Legal Exceptions

We may disclose your information if required by law, court order, or government authority, such as:

7. Data Retention

Chat Session Data

Clinical Summaries

Audit Logs

Account Deletion

Upon request, you can request complete deletion of your account and associated data. To do so:

8. Cookies and Tracking

Firebase Authentication Cookies

Third-Party Tracking

Your Cookie Preferences

Most browsers allow you to refuse cookies or alert you when cookies are being sent. However, blocking functional cookies may prevent you from using the Service properly. We recommend keeping Firebase Auth cookies enabled.

9. Your Rights

You have the following rights with respect to your personal information:

Right to Access

You can request and download a copy of all personal information we hold about you in a machine-readable format.

Right to Deletion

You can request deletion of your account and associated data. Some information may be retained if required by law (e.g., audit logs for 6 years).

Right to Correction

You can update or correct inaccurate information in your account profile at any time.

Right to Withdraw Consent

For any optional data collection or use, you can withdraw consent at any time. This will not affect the legality of processing based on consent given before withdrawal.

Right to Data Portability

You can request a copy of your data in a standard, portable format that can be transferred to another service.

How to Exercise Your Rights

To exercise any of these rights, please contact us at bryan.leishman@gmail.com with your request. We will respond to your request within 30 days and may ask to verify your identity before proceeding.

10. Children's Privacy

Extended Sessions AI is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that a child under 18 has created an account or provided information, we will delete that account and information promptly.

If you are a parent or guardian and believe your child has used our Service, please contact us immediately at bryan.leishman@gmail.com.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by email or by prominently posting a notice on our website.

Your continued use of the Service following the posting of revised Privacy Policy means that you accept and agree to the changes.

12. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact us:

Email: bryan.leishman@gmail.com

Service: Extended Sessions AI — Therapy AI Platform

We will respond to your inquiry as promptly as possible, typically within 5-7 business days.

Privacy At a Glance