Privacy is the foundation.
Therapy only works when you feel safe being honest. Every part of our infrastructure is built to protect that trust. Here's how.
HIPAA-aligned infrastructure
Our systems are architected to align with HIPAA safeguards for the storage, transmission, and access of protected health information.
PII redaction before AI processing
Personally identifiable information is redacted before any content is processed by AI systems, so automated tooling never sees who you are.
Aggregate-only organizational reporting
Employers and institutions receive anonymized, aggregate wellbeing trends only. Individual member data is never exposed.
Sovereign US-based data hosting
Member data is hosted within the United States on infrastructure we control, with encryption in transit and at rest.
Least-privilege access
Access to clinical records is limited to your care team, granted on a strict need-to-know basis and fully auditable.
You own your record
You can request a copy of your data or its deletion at any time, subject to the clinical record-keeping obligations of your providers.
The details
This page summarizes our approach to security and privacy. Full legal documentation — including our Privacy Policy, Terms of Service, and HIPAA Notice of Privacy Practices — is being finalized by our legal team and will be published here.
If you have questions about how your information is handled, or wish to exercise your data rights, contact us at hello@opencovewellness.com.
Placeholder notice: this content is a plain-language summary and does not yet constitute the final legal agreements.