Psyflo Platform Privacy Policy

Effective Date: June 20, 2026 | Last Updated: June 14, 2026

This Platform Privacy Policy explains how PsyFlo Corp. ("Psyflo," "we," "us," or "our") handles information through the Psyflo remote therapeutic monitoring platform available at app.psyflo.com and related platform services.

This Platform Privacy Policy applies to patients who use Psyflo through a participating mental health provider, and to authorized provider, practice, administrative, and billing users who access the Psyflo platform.

This Platform Privacy Policy does not apply to the public website at psyflo.com. Our public website is covered by a separate Website Privacy Policy.

1. Psyflo's Role

Psyflo provides a Remote Therapeutic Monitoring, or RTM, technology platform to mental health providers and their practices.

Psyflo is a technology platform. Psyflo is not a healthcare provider, does not provide medical or mental health care, and does not make clinical decisions. Your mental health provider, practice, clinician, or other authorized care team member, referred to in this policy as your Provider, is responsible for your care and treatment decisions.

Psyflo handles protected health information on behalf of your Provider as a business associate under a Business Associate Agreement, as required by HIPAA.

Your Provider has its own Notice of Privacy Practices that explains your Provider's privacy practices and your patient rights. This Platform Privacy Policy explains how Psyflo handles information as your Provider's technology vendor. If you have questions about your medical record, treatment, or your Provider's privacy practices, contact your Provider.

2. Important Safety Information

Psyflo is not an emergency or crisis service.

The Psyflo platform is not monitored in real time. Psyflo staff do not provide emergency support, crisis response, or clinical monitoring. Alerts in Psyflo are limited, rule-based, not continuous, not real-time, and not guaranteed. They are not a substitute for contacting emergency services or your Provider directly.

If you are experiencing a mental health crisis, are thinking about harming yourself or someone else, or believe you may be in danger, call or text 988 for the Suicide & Crisis Lifeline, call 911, or go to the nearest emergency room.

If you submit certain responses that may indicate possible risk, Psyflo may display emergency resources in the platform and may generate a rule-based alert for your Provider. This does not mean Psyflo is monitoring your use in real time or that your Provider will see or respond to the alert immediately.

3. Information We Collect Through the Platform

Information you or your Provider provide

We may collect contact, demographic, and account information, such as:

  • name
  • email address
  • phone number
  • emergency contact information
  • date of birth, if provided by your Provider
  • address, if provided by your Provider
  • insurance identifiers or related billing information, if provided by your Provider
  • account and login information

Health information you provide

We may collect health information you submit through the platform, including:

  • responses to symptom assessments, such as PHQ-9, GAD-7, and other assessments your Provider assigns
  • check-ins covering mood, symptoms, medication adherence, or similar topics
  • treatment goals and progress ratings
  • life events and updates you choose to flag
  • free-text reflections, journals, weekly reports, or similar entries
  • past or current treatment history submitted during onboarding or use of the platform
  • safety and risk-related information you provide through assessments, check-ins, onboarding, or other features assigned by your Provider

Health information created during your care

We may process health information created or entered by your Provider or practice, including:

  • treatment plan notes
  • clinical goals
  • intervention records
  • homework, exercises, therapeutic activities, and completion status
  • clinical notes created by your Provider
  • RTM monitoring and engagement information

Psyflo does not create clinical notes for your Provider using artificial intelligence. Clinical notes are created by your Provider.

Communication and notification information

The current Psyflo platform does not provide in-app secure messaging, SMS text messaging, push notifications, voice calls, or video calls.

We may process records related to platform notifications and communications, including:

  • generic email notification records
  • notification timestamps
  • account, service, and security communication records
  • Provider alert notification records

Email notifications are intended to be generic and not include protected health information, assessment names, symptoms, scores, risk details, treatment details, or other clinical content.

Technical and usage information

We may collect technical and usage information needed to operate, secure, troubleshoot, and improve the platform, such as:

  • IP address
  • device and browser information
  • operating system
  • device identifiers
  • authentication logs
  • audit logs
  • app usage data
  • crash logs
  • security logs
  • approximate location derived from IP address
  • similar technical information

Some technical information may be protected health information when connected to your use of the logged-in Psyflo platform.

4. How We Use Information

We use information through the Psyflo platform to:

  • provide the Psyflo platform to your Provider
  • display patient information in clinician dashboards, reports, and workflows
  • support your Provider's RTM services
  • support your Provider's RTM billing documentation and monitoring-time records
  • track progress and outcomes over time
  • generate limited rule-based alerts for your Provider, such as when certain assessment responses indicate possible risk
  • display emergency resources when certain risk-related responses are submitted
  • send generic service, account, security, platform, assignment, and Provider-alert emails
  • operate, maintain, secure, troubleshoot, and improve the platform
  • provide customer support and technical support
  • comply with legal obligations
  • enforce agreements and protect the rights, safety, and security of Psyflo, Providers, patients, and others

5. Current No-AI Status

The current Psyflo platform does not use artificial intelligence to analyze your information or generate clinical content.

Psyflo does not currently use artificial intelligence to:

  • generate clinical notes
  • generate clinical summaries
  • generate assessments
  • generate treatment-plan content
  • generate documentation
  • suggest interventions
  • suggest homework, exercises, or therapeutic activities
  • suggest treatment options
  • suggest care-plan changes
  • suggest clinical next steps
  • make clinical decisions

Psyflo does not use identifiable health information to develop or train artificial intelligence or machine-learning models.

If Psyflo introduces AI features in the future, Psyflo will update its disclosures and take any required legal, contractual, Provider, or patient-facing steps before those features are launched.

6. Rule-Based Alerts

Psyflo may generate limited rule-based alerts for your Provider based on fixed criteria configured in the platform.

For example, if a patient submits a nonzero response to a self-harm-related item in an assigned assessment, the platform may:

  • display emergency resources to the patient
  • create an in-platform alert for the Provider
  • send a generic email notification to the ordering Provider telling the Provider to log in to Psyflo

Provider alert emails are intended to be generic. They should not include patient names, PHQ-9 references, self-harm references, assessment names, scores, symptoms, diagnosis information, risk details, or treatment information.

These alerts are limited and rule-based. They are not continuous, not real-time, not guaranteed, and not a substitute for calling or texting 988, calling 911, going to an emergency room, contacting your Provider directly, or using any emergency or crisis service.

7. Emails and Platform Notifications

Psyflo may send generic email notifications related to the platform.

Required service, account, security, and platform emails may be necessary to provide the platform and may not be available for opt-out while you use Psyflo.

Optional notification emails, such as assignment-related notifications, may be managed through available in-app settings.

Psyflo does not currently send SMS text messages or push notifications.

Psyflo does not use platform information to market products or services to patients. Psyflo does not sell protected health information or share protected health information for advertising.

8. De-identified and Aggregate Information

Psyflo may create de-identified or aggregate information from information processed through the platform in accordance with HIPAA and the applicable Business Associate Agreement.

Once information has been de-identified in accordance with HIPAA, it is no longer protected health information. Psyflo may use de-identified or aggregate information for purposes permitted by law and by our Business Associate Agreements, including service improvement, product development, outcomes analysis or research, management, administration, and platform operations.

Psyflo does not attempt to re-identify de-identified information.

9. How We Share Information

With your Provider and authorized practice users

We share platform information with your Provider and authorized users at the practice where you are enrolled.

This may include treating clinicians, practice managers, administrative users, and billing users, depending on their role and the Provider's access settings.

Billing users generally access RTM billing-relevant engagement and monitoring information. A billing user or practice owner may access additional patient information only if assigned to the patient or otherwise authorized by the Provider or practice.

With Psyflo personnel and contractors

Authorized Psyflo personnel and contractors may access information only as needed to operate, secure, support, troubleshoot, and improve the platform.

Psyflo uses access controls and other safeguards designed to limit access to personnel and contractors with a need to know. Authorized personnel or contractors may access systems from outside the United States where permitted by our agreements and applicable law, subject to the same safeguard obligations as domestic access.

With technology vendors and service providers

We use a limited set of technology vendors and service providers to operate, secure, host, support, and improve the platform.

Any vendor that creates, receives, maintains, or transmits protected health information for Psyflo must sign a Business Associate Agreement or other HIPAA-required agreement.

We may use email service providers to send generic, non-PHI email notifications. These emails are not intended to include health information, assessment names, symptoms, scores, risk information, treatment information, or other clinical content.

As required by law

We may disclose information when required by applicable law, regulation, court order, subpoena, legal process, or government request.

In a business transfer

If Psyflo is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to this Platform Privacy Policy, applicable law, and applicable Business Associate Agreements.

In the event of a breach

If Psyflo discovers that protected health information may have been accessed, used, or disclosed improperly, Psyflo will notify your Provider as required by HIPAA and the applicable Business Associate Agreement so your Provider can notify you when required. Psyflo will also provide any notices required of Psyflo by applicable law.

10. How We Protect Information

Psyflo uses administrative, physical, and technical safeguards designed to protect information processed through the platform.

These safeguards may include:

  • encryption in transit and at rest
  • role-based access controls
  • authentication controls
  • audit logging
  • security monitoring
  • workforce and contractor confidentiality obligations
  • workforce and contractor security training
  • vendor contractual protections
  • policies and procedures designed to support HIPAA compliance

No system is perfectly secure. We work to protect information consistent with HIPAA's Security Rule and applicable law.

11. Data Retention, Return, and Deletion

Psyflo retains information for as long as needed to provide the platform to your Provider, as your Provider directs, as permitted by the applicable Business Associate Agreement, and as required or permitted by law.

When your enrollment ends or when your Provider's relationship with Psyflo ends, Psyflo returns, exports, or deletes protected health information in accordance with the applicable Business Associate Agreement, unless Psyflo is required or permitted to retain it by law, for audit logs, for legal purposes, for security purposes, for backup or archival purposes, or because return or deletion is not feasible.

Deleted information may remain for a limited period in backups, logs, or archival systems maintained for security, legal, continuity, or compliance purposes. Information retained in those systems remains protected until deleted according to applicable retention schedules.

Psyflo does not represent that all patient health information is retained for six years. Certain audit logs and compliance records may be retained for six years or another period required by law or contract.

12. No Payment Card Processing

Psyflo does not currently collect payment card information from patients through the platform.

13. Children and Adolescents

The Psyflo platform is not intended for patients under 18 years old.

Providers and practices should not enroll patients under 18 in Psyflo. If we learn that a patient under 18 has been enrolled, we will work with the Provider to address the issue.

14. Psychotherapy Notes

Psyflo does not store psychotherapy notes as that term is defined under HIPAA.

The platform may process treatment records, monitoring information, assessment responses, progress information, Provider-created clinical notes, and other health information used by your Provider to support your care.

15. Your HIPAA Rights

Because Psyflo handles protected health information on behalf of your Provider, you generally exercise your HIPAA rights through your Provider.

Your Provider's Notice of Privacy Practices describes your full HIPAA rights, which may include rights to:

  • access your health information
  • request amendments or corrections
  • request restrictions on certain uses or disclosures
  • request confidential communications
  • receive an accounting of certain disclosures
  • obtain a paper copy of your Provider's Notice of Privacy Practices
  • file a complaint

If you contact Psyflo directly at legal@psyflo.com, Psyflo will work with your Provider to respond within 30 days or within the timeframe required by HIPAA.

You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights, at www.hhs.gov/ocr/privacy or 1-800-368-1019.

Psyflo will not retaliate against you for filing a complaint.

16. Your State Privacy Rights

Your state may provide additional privacy rights.

Your state-specific rights as a patient are generally described in your Provider's Notice of Privacy Practices. For information Psyflo holds that is not protected health information, Psyflo does not sell it and does not use it for targeted advertising.

Psyflo provides breach notifications as required by applicable federal and state law.

If you have questions about state privacy rights, contact us at legal@psyflo.com.

17. Changes to This Platform Privacy Policy

We may update this Platform Privacy Policy from time to time.

When we do, we will update the Last Updated date above and, where appropriate, notify you or your Provider. Your continued use of the platform after an update means you accept the updated Platform Privacy Policy.

18. Contact Us

For questions about this Platform Privacy Policy or how Psyflo handles information through the platform, contact:

PsyFlo Corp. Email: legal@psyflo.com