Security & Privacy

Privacy is the foundation.

Therapy only works when you feel safe being honest. Every part of our infrastructure is built to protect that trust. Here's how.

HIPAA-aligned infrastructure

Our systems are architected to align with HIPAA safeguards for the storage, transmission, and access of protected health information.

PII redaction before AI processing

Personally identifiable information is redacted before any content is processed by AI systems, so automated tooling never sees who you are.

Aggregate-only organizational reporting

Employers and institutions receive anonymized, aggregate wellbeing trends only. Individual member data is never exposed.

Sovereign US-based data hosting

Member data is hosted within the United States on infrastructure we control, with encryption in transit and at rest.

Least-privilege access

Access to clinical records is limited to your care team, granted on a strict need-to-know basis and fully auditable.

You own your record

You can request a copy of your data or its deletion at any time, subject to the clinical record-keeping obligations of your providers.

The details

This page summarizes our approach to security and privacy. Full legal documentation — including our Privacy Policy, Terms of Service, and HIPAA Notice of Privacy Practices — is being finalized by our legal team and will be published here.

If you have questions about how your information is handled, or wish to exercise your data rights, contact us at hello@opencovewellness.com.

Placeholder notice: this content is a plain-language summary and does not yet constitute the final legal agreements.

Crisis support: call or text 988 · Text HOME to 741741