Privacy Policy & Data Security Statement

How we handle
your data.

Last updated: September 16, 2026  ·  Version 1.0  ·  Rewire App LLC

Overview

Our commitment to data protection

Rewire Clinical is operated by Rewire App LLC ("Rewire", "we", "us"). We provide a modality-agnostic clinical documentation and between-session support platform for licensed mental health professionals and their clients. Because our platform is used in a clinical context, we treat data protection as a clinical governance obligation.

This policy applies to all users of the Rewire Clinical platform: licensed clinicians ("Clinicians") and their clients ("End Users") who access Rewire Clinical under a clinician's assignment.

For clinical governance review: Rewire's infrastructure is built toward the HIPAA Security Rule's Technical Safeguard requirements (45 CFR §164.312) — including access controls, audit logging, and encryption in transit and at rest. For organizations that are HIPAA Covered Entities (hospitals, treatment facilities, EAPs), a direct Business Associate Agreement (BAA) is available at the facility tier. We are committed to GDPR compliance for all European users under Regulation (EU) 2016/679. Our primary data processor, Supabase, maintains SOC 2 Type II certification and operates under a Business Associate Agreement. Data transfers to the US are governed by Standard Contractual Clauses (SCCs).

01 — Data Controller

Who is responsible for your data

Data Controller: Rewire App LLC

For all data protection enquiries, data subject rights requests, and Business Associate Agreement requests:
Email: privacy@rewire-emdr.com
Subject line: "Data Privacy Request — Rewire Clinical"

We will acknowledge all requests within 72 hours and respond in full within 30 days.

02 — Data We Collect

What we collect and why

Clinician accounts

Data typePurposeLegal basis (GDPR)
Email addressAccount authentication and platform communicationsContract performance — Art. 6(1)(b)
Practice / facility nameDisplayed within the clinician dashboard; identifies the practice to assigned clientsContract performance — Art. 6(1)(b)
Subscription and billing dataPayment processing via Stripe. Card details are not stored by Rewire. Stripe is PCI DSS Level 1 compliant.Contract performance — Art. 6(1)(b)
Client roster and account detailsClient account identifiers, email addresses, optional first names, clinician and facility links, and access or invitation codes used to provide and administer care access.Contract performance — Art. 6(1)(b)

End User (client) data

Data typePurposeLegal basis (GDPR)
Email addressAuthentication and service communications. Shared with service providers such as Supabase, Paubox/Resend, and Stripe only as needed to operate the service; not sold or shared for advertising.Contract performance — Art. 6(1)(b)
Session & progress dataRecords which exercises and assignments have been completed. Visible to the assigning clinician for care continuity.Legitimate interests — Art. 6(1)(f) (clinical care continuity)
Distress / state ratingsPre/post exercise ratings entered by the user. Shared with the assigning clinician for clinical review.Consent — Art. 6(1)(a)
Journal & reflection entriesOptional written reflections. Shared with the assigning clinician only if the user explicitly enables sharing. Constitutes potentially special category data.Explicit consent — Art. 9(2)(a)
AI conversation contentUsed in real time to generate personalised session content only. Not stored permanently. Not used for AI model training.Consent — Art. 6(1)(a)

Data we do not collect

03 — Data Storage & Security

How we protect your data

Infrastructure

User data is stored primarily in Supabase, a managed PostgreSQL-based platform operating under a Business Associate Agreement with Rewire. Data is stored on managed infrastructure that provides encryption at rest. Application traffic to Rewire's service providers is encrypted in transit using HTTPS/TLS.

Access controls and row-level security

Rewire Clinical implements row-level security (RLS) at the database layer. Each clinician can access only the data for clients they have directly assigned. No clinician can access data belonging to clients of a different clinician. No Rewire employee accesses user session data or journal entries in the ordinary course of operations.

Clinical free-text encryption

Clinical free-text — including journal entries and narrative notes — is protected with client-side end-to-end encryption (AES-256-GCM with X25519 key wrapping). This content is encrypted on the user's device before storage, so neither Rewire nor its database provider can read it.

AI processing safeguards

AI-generated content is routed through a Cloudflare Worker to a secure, HIPAA-covered third-party AI provider under a Business Associate Agreement. Rewire does not intentionally add account names or email addresses to AI requests, does not use AI conversation content to train models, and does not intentionally retain AI conversation logs server-side beyond the active request.

HIPAA-aligned controls

Organizations that are HIPAA Covered Entities may request a facility-level Business Associate Agreement at privacy@rewire-emdr.com.

Data retention

04 — Sub-Processors

Third-party processors we use

ProcessorPurposeJurisdictionCertification
SupabaseDatabase, authentication, file storageUS / EU (configurable)SOC 2 Type II · BAA
AI provider (HIPAA-covered, under BAA)Models used for AI session content generationUS (API processing)Business Associate Agreement and provider terms apply
CloudflareWorker proxy for AI requests; DDoS and edge securityGlobal edge networkSOC 2 Type II, ISO 27001
PauboxHIPAA-compliant transactional email (BAA)USBusiness Associate Agreement
StripePayment processingUS / EUPCI DSS Level 1

We review all sub-processor agreements for GDPR adequacy before engagement. Data transfers to the US are covered by Standard Contractual Clauses (SCCs) under GDPR Art. 46(2)(c). We will notify account holders of any material change to our sub-processor list at least 30 days in advance.

05 — Your Rights (GDPR)

Data subject rights

Users in the EEA, UK, Switzerland, and equivalent jurisdictions have the following rights under GDPR (or applicable equivalent legislation):

To exercise any of these rights: email privacy@rewire-emdr.com with the subject line "Data Subject Rights Request". We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority.

06 — Special Category Data

Sensitive data and mental health information

Journal entries and clinical narrative entered by users may constitute special category data under GDPR Art. 9, specifically data concerning health and mental wellbeing. We treat all such content as special category data by default and apply the following additional protections:

07 — Cookies & Analytics

Cookies and tracking

The clinical application and authenticated portals use browser storage and session technologies needed for authentication and application functionality. They do not load advertising trackers, behavioural analytics, or device-fingerprinting technology.

08 — Changes to This Policy

Policy updates

We will notify all active account holders by email of material changes to this policy at least 14 days before they take effect. The current version is always available at rewireclinical.com/privacy. Continued use of the platform after the effective date of a revised policy constitutes acceptance of the updated terms.

For questions about this policy: privacy@rewire-emdr.com